Re: Helpdesk rights to change passwords



1) Delegate "set password" permission to the group you need
2) Use AD Users&Computers to reset passwords.

--
Dmitry Korolyov [d__k@xxxxxxxxxxxxxxxxxxxxxx]
MVP: Windows Server - Directory Services


"Dean Colpitts" <dean.n_o_s_p_a_m.colpitts@xxxxxxxxxxxxxx> wrote in message
news:subeh1las4kfobipd7obaeal6ks4tveuhr@xxxxxxxxxx
>I have several differrent customers that have a single Windows 2003 DC
> with XP SP2 workstations. At each site, I'd like to take one person
> and give them rights to change/reset other user's passwords from a XP
> SP2 workstation. I've found the following commmand:
>
> net user username password /domain
>
> which works fine when run from an account with domain admin rights.
> When I run this as a standard domain user, obviously I get an error.
>
> I've run the delegation of control wizard, picked the account I want
> to have these rights, created a custom task to delegate, select an
> active directory object type of users and selected both change
> password and reset password.
>
> When running the above command as the user I've delegated as the
> password changer, on that person's workstation, I get:
>
> System error 5 has occurred.
>
> Access is denied.
>
> What am I doing wrong, and what is the best way around it? I only
> want this person to be able to change or reset passwords...
>
> dcc


.



Relevant Pages

  • Re: Password Reset
    ... you can use the Delegation of Control wizard on a domain ... or OU to delegate the ability to reset passwords - right-click on the domain ... Delegating the ability to force the user to change their password on next ... > in my office that needs the ability to reset passwords on the network. ...
    (microsoft.public.windows.server.general)
  • Re: Delegation issues
    ... How To Delegate the Unlock Account Right: ... > they can reset passwords in AD. ... > them to test and gave them the Reset Passwords rights, ...
    (microsoft.public.win2000.active_directory)
  • Re: Delegation issues
    ... >How To Delegate the Unlock Account Right: ... >> they can reset passwords in AD. ... >> them to test and gave them the Reset Passwords rights, ...
    (microsoft.public.win2000.active_directory)
  • Re: Junior Admin
    ... also in the administrators group or other elevated groups. ... You probably will find the entry in advanced/special permissions. ... > them to reset passwords and pretty much nothing else. ... I then used the delegate wizard and added this ...
    (microsoft.public.win2000.security)
  • Re: Delegation of Authority in an OU
    ... Delegate Administrative Authority in Windows 2000. ... The steps outlined here will also work within Windows Server 2003. ... > admin can have administrative rights to an OU? ...
    (microsoft.public.windows.server.active_directory)