WORKAROUND 1Using ADSI Edit, as an Enterprise Admin, delegate access for the Active Roles domain management account so that it has:
- All objects - Read all properties
- List
- Read permissions
- Modify permissions
WORKAROUND 2Add the Active Roles domain management account to the Enterprise Admins Active Directory role group.