ADManager Plus, an IGA tool, offers purpose built features for Active Directory (AD), Microsoft 365, Exchange, and Google workspace management and reporting operations. To successfully perform the required operation in these platforms, ADManager Plus requires an admin account with sufficient privileges to carry out the desired operations in AD.
Possible reason
If you find that the technician or admin is unable to delete a user account through ADManager Plus, but can do so using the Active Directory Users and Computers (ADUC) console, it's likely due to permission issues. The admin account, which is a part of the domain configured in the Domain/Tenant Settings of ADManager Plus might not have effective permissions to delete subtree.
Steps to resolve this issue:
Log in to ADManager Plus.
Go to the Domain/Tenant Settings link in the top right corner.
Make a note of the first domain controller in the list, and also the credentials used for that domain controller.
Login to that domain controller using the credentials provided in the Domain/Tenant Settings section.
Open the ADUC console, and locate the admin account.
Right click that user account and click Properties > Security > Effective Access. Enter the name of the admin account provided in ADManager Plus' Domain/Tenant Settings and click the View effective access option.
If the Delete subtree permissions has been disabled, enable it.