Re: Changing User Password - Credential Problem

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: - Steve - (sevans_at_foundation.sdsu.edu)
Date: 04/02/04


Date: Fri, 2 Apr 2004 10:42:07 -0800

This is for admins to reset users forgotten passwords, etc. So I don't know
the existing password of the account.

How can I impersonate another account? Preferably how do I get it to
execute under the context of the user that logged into IIS (it's protected
with basic authentication)

-- 
Steve Evans
Email Services
SDSU Foundation
"bruce barker" <nospam_brubar@safeco.com> wrote in message
news:%23UbfICOGEHA.1180@TK2MSFTNGP09.phx.gbl...
> you should have the user pass the old password, then impersonate them,
then
> change password to new password., otherwise you need to impersonate a
domain
> admin
>
>
> -- bruce (sqlwork.com)
>
>
> "- Steve -" <sevans@foundation.sdsu.edu> wrote in message
> news:eC4VE#NGEHA.2732@tk2msftngp13.phx.gbl...
> > I'm trying to change a user's password using
objUser.Invoke("setPassword",
> > "newpassword")
> >
> > It works fine as a console application if I'm logged in with someone
with
> > the correct permissions.  If I'm logged in as a normal user it doesn't
> work,
> > even though call before that,
> >
> > objUser.Username = "admin@domain.com"
> > objUser.Password = "adminpassword"
> >
> > Obviously the ASP.NET account doesn't have permissions to change
passwords
> > so how can I escalate my permissions for this one task?
> >
> > -
> > Steve Evans
> > Email Services
> > SDSU Foundation
> >
> >
>
>


Relevant Pages

  • Re: Problem managing accounts in protected groups
    ... we have two domain admins: ... that someone will give more security permissions to users then to the admins. ... I think you have realized that the account management group is able to reset ... Most members of OU A are either members of Domain ...
    (microsoft.public.windows.server.active_directory)
  • Re: Problem managing accounts in protected groups
    ... For you administrator accounts create an own OU directly under the domain name and place there the domain admin accounts without any restrictions through policies or whatever. ... And create for them a normal domain user account for the daily work with normal restrictions like any other user. ... If now the account under the Administrators OU is locked another one from that OU can easily unlock them without any problem, because they all are domain admins in that OU. ... heard about that someone will give more security permissions to users ...
    (microsoft.public.windows.server.active_directory)
  • RE: Help: SBS 2003 Exchange Send As permissions not working (and disappearing!)
    ... It seems to be related to the AD AdminSDHolder resetting the permissions ... 318180 AdminSDHolder Thread Affects Transitive Members of Distribution ... Schema Admins ... You have mentioned that one account can work well with "send as". ...
    (microsoft.public.windows.server.sbs)
  • Re: Problem managing accounts in protected groups
    ... "Meinolf Weber" wrote: ... For your admins, you should think about using this way. ... they can choose RUN AS option for that and use the domain administrator account. ... heard about that someone will give more security permissions to users ...
    (microsoft.public.windows.server.active_directory)
  • Re: AD User Objects & Permission Inheritance
    ... I went ahead and granted the Account Operators built in group rights on the ... adminSDholder object according to what I want the OU admins to have. ... > later all user objects began to inherit permissions again. ...
    (microsoft.public.win2000.active_directory)