Re: Allowing a user to reset passwords

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



see:
http://blogs.dirteam.com/blogs/jorge/archive/2006/01/05/369.aspx


--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)

# Jorge de Almeida Pinto # MVP Windows Server - Directory Services

BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx
-----------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
-----------------------------------------------------------------------------


-----------------------------------------------------------------------------
"Jim Dykes" <JimDykes@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:F8C189A5-BAC1-4982-9EA7-03EEC5B2B505@xxxxxxxxxxxxxxxx
I want to create a group that has the ability to change passwords, reset
passwords, and unlock user accounts that have been locked out. The
Account
Operators group has these abilities, but members of that group can also
create and delete accounts and groups. I tried creating a group and
granting it the change password and reset password permissions for the OUs
containing our users. This allowed group members to do those 2 things, but
not unlock accounts. I also tried creating a group, denying it the
create/delete computer and user accounts permissions and placing it within
the Account Operators group. I had a group member test, but she was
unable
to unlock an account.

Any suggestions on a way to grant specific users only the ability to
unlock
user accounts and reset passwords in AD Users and Computers? Thanks in
advance for your help.


.



Relevant Pages

  • Re: 2003 Server Client/Delegation and Data Issues
    ... I want to delegate the ability to unlock user accounts to 3 ... Also, when I log in as one of the delegates, the unlock is grayed out ...
    (microsoft.public.windows.server.active_directory)
  • auto unlock feature for selected users
    ... Can we configure the system to enable "auto unlock account" for some ... all user accounts will be manually unlocked except ...
    (microsoft.public.win2000.security)
  • Re: AD USERs Unexpected locked out
    ... It means that user accounts will try to input the wrong password for three ... I need to unlock their account for ... virus definition files are up-to date. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Remote password change/account unlock
    ... Allowing users to change or reset their passwords or unlock their accounts ... There are security implications to having a service running as ...
    (microsoft.public.win2000.security)
  • Re: UserAccountControl Attribute
    ... specific user objects (enabled user accounts) that appear to be missing those ... How can I view the attributes of the user objects in question? ... foreach (string parameter in Parameters) ...
    (microsoft.public.win2000.active_directory)