Hello broonster27,
Thank you for posting in Microsoft Community forum.
You can try to give service account to write to the property on the AdminSDHolder object via GUI manually and check if it helps.
If it helps, maybe you did not give the permission successfully using "DSACLS 'cn=adminSDholder,cn=system,dc=domain,dc=com' /I:S /G $sGrp":WP;accountExpires;user".
I hope the information above is helpful.
If you have any question or concern, please feel free to let us know.
Best Regards,
Daisy Zhou