Regarding:
Create an AD account for the ADDS connectorYou need an account in each forest the Sync Service can use to communicate with Active Directory.
The account will only need the default read permissions. A regular user account in ADDS already fulfills this requirement.
What about permissions for Hybrid Write-back ?