Reset user password and force change at next logon


using delegate control wizard, i've delegated "reset user password , force change @ next logon" group called support-staff users under people container.

they able reset passwords on users, box force password changed @ next logon grayed out.

i have checked effective permissions of user password being reset , can confirm "reset password", "read pwdlastset" , "write pwdlastset" aces ticked group support-staff (and user trying reset password member of support-staff).

the user password being reset not member of adminsdholder. if user resetting password tries reset own password through same means, box forcing user reset password on next logon no longer grayed out.

the domain windows 2008 r2 , members of support-staff use windows xp machine administration tool pack 2003 sp1 installed.

 

cheers,

john

have checked if members of support-staff able set value of pwdlastset attribute via script (http://technet.microsoft.com/en-us/library/ee198797.aspx or powershell)?

if so, seeing same symptoms when using rsat vista/windows 7 computer?

hth
marcin



Windows Server  >  Directory Services



Comments

Popular posts from this blog

some help on Event 540

WMI Repository 4GB limit - Win 2003 Ent Question

Event ID 1302 (error 1307) DFS replication service encountered an error while writing to the debug log file