Re: Help Please - Delegation not working on 2003 Server

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Joe Richards [MVP] (humorexpress_at_hotmail.com)
Date: 07/01/04


Date: Thu, 01 Jul 2004 11:36:18 -0400

You will need to check the permissions on the users themselves, sounds like they
may not be properly delegated or are not inheriting permissions from the OU that
is delegated.

--
Joe Richards Microsoft MVP Windows Server Directory Services
www.joeware.net
Jim wrote:
> I have recently finished migrating our users from a 
> Windows NT 4.0 domain to a Windows 2003 AD Domain.  Early 
> on in my testing phase I had setup delegation on 
> a "Windows 2000" AD server to allow our helpdesk to 
> change passwords, reset password, click the box to force 
> user to change password at next logon and unlock accounts 
> when users typed in the wrong password too many times.  
> In the test domain this worked very well.
> 
> My problem is that now I am live in a Windows 2003 AD 
> Domain and the helpdesk is not able to unlock accounts or 
> check the box to force users to change password at next 
> logon.
> 
> I have noticed that the helpdesk does not have the issues 
> when they manage a user that was created in Windows 2003 
> AD such as a couple of test users and some temp users.  
> So far it appears to happen only with the several hundred 
> users that were migrated from NT 4.0 to AD.
> 
> Can anyone shed some light on this for me.  It is really 
> driving me crazy as I have followed the Knowdege Base 
> articles to a T and still can't get this to work.
> 
> TIA for any help.


Relevant Pages

  • Re: Propagating caller identity across applications from a bare ASMX Service method to a WSE3 Servic
    ... Directory Domain as the server computer and the server App Pool run-as ... Windows 2003 Server mode -- they may be in Windows 2000 mixed mode. ... to be configured so as to use kerberos delegation. ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: "Account is trusted for delegation" is not shown
    ... Where SPN is the servicename/computername (MESSENGER/SERVERNAME for ... This will add the delegation tab to the useraccount you specified. ... account with the Setspn utility in the support tools on your CD. ... It should be caused by raising functional level to windows 2003. ...
    (microsoft.public.windows.server.general)
  • Re: kerberos sudenly stop working on an IIS server
    ... D_DebugLogClient %wZ sent AS request with no server name\n") ... Windows XP and Windows Server 2003 will recover from this automatically. ... For information about setting up service accounts for delegation, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Limiting Access Rights to AD from Windows 2000 Professional
    ... to do a customize delegation within the wizard. ... > to review user information and change password. ... > the user access her MMC console she can make changes to ... > overwriting the rights on a particular OU? ...
    (microsoft.public.win2000.active_directory)
  • RE: accessing WebService from asp.net App on load balanced Servers
    ... for intranet application within a windows domain ... For general info on ASP.NET delegation: ... Servers ... | | Subject: RE: accessing WebService from asp.net App on load balanced ...
    (microsoft.public.dotnet.framework.aspnet.security)