adcli appears to be trying to update the userAccountControl when doing a kerberos ticket renewal, or "adcli update". While it doesn't appear to cause anything to fail, I don't think it should be trying to do this.
[root@localhost ~]# adcli update -D example.com -N bigumlvm -S dc.example.com -v
* Password not too old, no change needed
* Modifying computer account: userAccountControl
! Couldn't set userAccountControl on computer account: CN=bigumlvm,CN=Computers,DC=example,DC=com: Insufficient access
* Updated existing computer account: CN=bigumlvm,CN=Computers,DC=example,DC=com
Oh, after reading the man page it may appear you want to write some extra attributes if specifying a credentials cache, but the man page does not mention what in the userAccountControl attribute you are trying to modify. I still don't think it's a good idea though - you could give the account an unlimited password expiry time by modifying userAccountControl.
-- GitLab Migration Automatic Message --
This bug has been migrated to freedesktop.org's GitLab instance and has been closed from further activity.
You can subscribe and participate further through the new bug through this link to our GitLab instance: https://gitlab.freedesktop.org/realmd/adcli/issues/4.