Thanks for your responses. I've now pinned down what the problem was.
The instructions on the Internet said that the dsacls command should have the domain and suffix listed separately, e.g. dc=domainname,dc=local. It also said that the rest of the command should be /G "DOMAINNAME\BESadmin:CA;Send As".
This should be DOMAINNAME.local\BESAdmin......etc etc.
The command worked when I included the .local in that part of the command, something which wasn't clear to me.
(To be placed in Knowledgebase)