Reset user password and force change at next logon
using delegate control wizard, i've delegated "reset user password , force change @ next logon" group called support-staff users under people container.
they able reset passwords on users, box force password changed @ next logon grayed out.
i have checked effective permissions of user password being reset , can confirm "reset password", "read pwdlastset" , "write pwdlastset" aces ticked group support-staff (and user trying reset password member of support-staff).
the user password being reset not member of adminsdholder. if user resetting password tries reset own password through same means, box forcing user reset password on next logon no longer grayed out.
the domain windows 2008 r2 , members of support-staff use windows xp machine administration tool pack 2003 sp1 installed.
cheers,
john
have checked if members of support-staff able set value of pwdlastset attribute via script (http://technet.microsoft.com/en-us/library/ee198797.aspx or powershell)?
if so, seeing same symptoms when using rsat vista/windows 7 computer?
hth
marcin
Windows Server > Directory Services
Comments
Post a Comment