Skip to content

Active Directory tool for super-users to reset password for other users in same OU

License

Notifications You must be signed in to change notification settings

carstengehling/AdPasswordReset

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

7 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

AdPasswordReset

Active Directory tool for super-users. This tool lists all users in running users OU, including sub OU's but not disabled users.

Usage

Use the "Delegation of Control Wizard" in Active Directory.

To allow a "Super" user to change others users password:

  1. Create a group in AD
  2. For the OU in question: Delegate "Reset user passwords and force password cange at next logon" to this group
  3. Add the "Super" user(s) to this group.

To give a "Super" user rights to unlock account(s):

  1. Create a group in AD (can be the same as above)
  2. For the OU in question:
  • On the Tasks to Delegate dialog box, click Create a custom task to delegate, and then click Next.
  • On the Active Directory Object Type dialog box, click Only the following objects in the folder:. In the list, click User objects (the last entry in the list), and then click Next.
  • On the Permissions dialog box, click to clear the General check box, and then click to select the Property-specific check box. In the Permissions list, click to select the Read lockoutTime check box, click to select the Write lockoutTime check box, and then click Next.
  • On the Completing the Delegation of Control Wizard dialog box, click Finish.

About

Active Directory tool for super-users to reset password for other users in same OU

Resources

License

Stars

Watchers

Forks

Packages

No packages published

Languages