When you propagate the permissions on an object such as an organizational unit (OU), group, user, or computer in Active Directory, you may receive the following error message:
Unable to save permission changes on ObjectName. A constraint violation occurred.
Every 30 minutes, the following event may appear in the Directory Services log on the domain controller:
Event Type: Error
Event Source: NTDS SDPROP
Event Category: Internal Processing
Event ID: 1450
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: Computer Name
Description:
The security descriptor propagation task could not calculate a new security descriptor for the following object.
Object:
Distinguished Name (DN) of Object
This operation will be tried again later.
User Action
If this condition continues, attempt to view the status of this object and manually change the security descriptor.
Additional Data
Error value:
1340 The inherited access control list (ACL) or access control entry (ACE) could not be built.
You may also see the following event in the log:
Event Type: Error
Event Source: NTDS SDPROP
Event Category: Internal Processing
Event ID: 1450
User: NT AUTHORITY\ANONYMOUS LOGON
Computer: Computer Name
Description:
The security descriptor propagation task could not calculate a new security descriptor for the following object.
Object:
Distinguished Name (DN) of Object
This operation will be tried again later.
User Action
If this condition continues, attempt to view the status of this object and manually change the security descriptor.
Additional Data
Error value:
53c %3