Thank you for reaching Microsoft Q&A!
Based on the error message it indicates Insufficient access rights to perform the operation.
To resolve this issue, please provide the necessary permission to the service account on the AD Connect Server by adding the service account into the Administrators Group (Built-in OU). It is recommended to let Azure AD Connect or you can specify a synchronization account with the correct permission.
Most times, this isn’t sufficient, you will have to add the service account as a member of the Administrator’s group in Active Directory.
You cannot use your Enterprise or Domain administrator account for your AD Forest account.
All the permissions are correctly set, please proceed to the Azure Synchronization Service Manager server and rerun the synchronization or run the full sync and check the Sync status whether it is completed without error.
If the issue persists, please refer How to fix Azure AD Connect permission-issue error code 8344.
Hope this helps. Do let us know if you any further queries by responding in the comments section.
Thanks.
Akhilesh.
If this answers your query, do click Accept Answer
and Yes
for was this answer helpful. And, if you have any further query do let us know.