Re: Force password change permission



Does anyone know where all these are documented?

"Joe Richards [MVP]" wrote:

> That would have to be a bug in the GUI then. You only need WP to pwdLastSet to
> force an account to have to change its password (make it expired).
>
> Write Account Restrictions gives far more rights than that, last I looked it
> gave you all of these
>
> > accountExpires
> > msDS-User-Account-Control-Computed
> > pwdLastSet
> > userAccountControl
> > userParameters
>
> which is far more rights than reset password and force to change on next logon.
>
> joe
>
> --
> Joe Richards Microsoft MVP Windows Server Directory Services
> www.joeware.net
>
>
> Todd J Heron wrote:
> > Nick wrote:
> >
> >>Hi there,
> >>
> >>I'm having trouble delegating control of an OU to a user. I want this user
> >>to be able to reset passwords and force the user to change their password
> >>upon their next login. I've used the delegation control wizard to give the
> >>user these permissions, and the permissions appear correct in the ACL (has
> >>permission to reset password and to write pwdlastset) - the result is that
> >>although they can reset the password successfully, the 'user must change
> >>password upon next logon' checkbox is greyed out.
> >>
> >>Any help is much appreciated!
> >>
> >>Cheers,
> >>Nick
> >
> >
> > The user needs "Write Account Restrictions" to be able to make this happen.
> > http://support.microsoft.com/default.aspx?scid=KB;en-us;296999
> >
>
.



Relevant Pages

  • Re: Force password change permission
    ... You only need WP to pwdLastSet to force an account to have to change its password. ... to be able to reset passwords and force the user to change their password ... user these permissions, and the permissions appear correct in the ACL (has ...
    (microsoft.public.windows.server.active_directory)
  • Re: Adding computer to domain does not see all local profiles
    ... I fixed it by choosing none for the local profiles and it picked my profile ... > open ADUC find your computer account - right click and RESET PASSWORD ...
    (microsoft.public.windows.server.sbs)
  • Re: User must change password at next logon for local account
    ... pwdLastSet is not exposed by the WinNT provider. ... local account, and the local SAM account database is not LDAP compliant, you ... Microsoft MVP Scripting and ADSI ...
    (microsoft.public.scripting.vbscript)
  • Re: Password Settings
    ... change the parameters on the types of characters they are required to use - ... account tab select user must change password on next log in? ... They wont notice a thing until they try to change their password then your ... account and select reset password? ...
    (microsoft.public.windows.server.active_directory)
  • Re: Force Password change (Delegate control)
    ... Granting WP to pwdLastSet should be enough. ... Joe Richards Microsoft MVP Windows Server Directory Services ... What sub-set of attribute can be selected to make this "User must change password at Next Logon" option availabe in the Reset password windows. ...
    (microsoft.public.win2000.active_directory)