This issue was first thought to be a password change. However, using the PasswordUtils to get the password back into the registry had no effect.
The administrative user was removed from both Enterprise admits and Domain admits. Since such accounts are needed not just for administrative access, but for process function, the accounts must go back to the state before the change.
To resolve this issue, perform these steps:
Create a user with full administrative rights over Active Directory (AD).
Re-run the Cisco CallManager Active Directory plugin.