Administrative Policy returned an error when adding user to ou group via Active Roles

I received the following error when we try and provision a user to a specific group in AD. We use ARS in our implementation. Is this a fix we need to make on our side or does it relate to a permission on the AD side?

Method ( (Update)) could not be executed successfully.
[VI.Projector.ActiveRoles.Connector.Utils.SingleStepCommitExecutionException] Error during modification of object: CN=USB Write Access,OU=USB Access,OU=Groups,OU=Administration,DC=global,DC=xxx,DC=xxx
Modification 'Add' of property 'vrtMemberFPOResolved' value 'S-1-5-21-2000478354-838170752-1801674531-603522' failed with error:
[System.Runtime.InteropServices.COMException] Administrative Policy returned an error.
Attempted to perform an unauthorized operation.