When using the GUI you have artificial limitations and requirements put on you
which make it so you often have to delegate more than you should really need to.
If you use a script for instance, you will need to delegate proxyAddresses and
mail. You could start with those and see if the GUI works, if not, you will want
to get a network trace of the LDAP update request and see what else it may be
touching. If you don't see anything the GUI is doing the checking itself and you
will have to either slowly add more delegations or delegate everything necessary
for add user and then back it off until you find the minimum necessary.
--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
---O'Reilly Active Directory Third Edition now available---
http://www.joeware.net/win/ad3e.htm