[REFERENCE] How to set AD permissions more granular than "replicating directory changes" on a source active directory so they can be read the ADMA:
http://social.technet.microsoft.com/wiki/contents/articles/16874.reference-how-to-set-ad-permissions-more-granular-than-replicating-directory-changes-on-a-source-active-directory-so-they-can-be-read-by-a-fim-adma.aspx