When you propagate the permissions on an object such as an organizational unit (OU), group, user, or computer in Active Directory, you may receive the following error:
Unable to save permission changes on ObjectName. A constraint violation occurred.
Every 30 minutes the following event may appear in the Directory Services log on the domain controller:
Event Type: Error
Event Source: NTDS SDPROP
Event Category: Internal Processing
Event ID: 1450
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: <computer name>
Description:
The security descriptor propagation task could not calculate a new security descriptor for the following object.
Object:
<distinguished name (DN) of object>
This operation will be tried again later.
User Action
If this condition continues, attempt to view the status of this object and manually change the security descriptor.
Additional Data
Error value:
1340 The inherited access control list (ACL) or access control entry (ACE) could not be built.
You may also see the following event:
Event Type: Error
Event Source: NTDS SDPROP
Event Category: Internal Processing
Event ID: 1450
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: <computer name>
Description:
The security descriptor propagation task could not calculate a new security descriptor for the following object.
Object:
<distinguished name (DN) of object>
This operation will be tried again later.
User Action
If this condition continues, attempt to view the status of this object and manually change the security descriptor.
Additional Data
Error value:
53c %3