Kudos to Tom...
Found the answer in another forum:
https://community.spiceworks.com/topic/2325216-domain-controller-replication-failing-replication-access-denied?page=1#entry-9404140
DENY permissions set on a group that my Administrator account was a member of. These DENY permissions were set on Properties > Security > Advanced on the root partition of the Default Naming Context.
Took these off (i.e. removed the DENY permissions that were set on the group that I was a member of) and, just like that, all is good!
Granted, this screenshot shows ALLOW - sorry, I'd already removed the DENY permissions before taking a screenshot! But, the DENY permissions were on the "DESKTOP ADMIN" group, which I'm a member of, hence, preventing my account from performing necessary actions that the domainprep wanted me to:
This was a nightmare to find the answer to, so I'm hoping this will help someone else. I actually found the answer while looking for the fix to another error (which DCDIAG threw up). I never actually found anything when searching for "Problem 4003 (INSUFF_ACCESS_RIGHTS) data 0".
Cheers,
Hutch.