Delegation Control

From: Jerrald Noland (JerraldNoland_at_discussions.microsoft.com)
Date: 09/30/04


Date: Thu, 30 Sep 2004 06:29:04 -0700

Hi:

First, let me explain what I'm trying to do. I want to setup a particular
group with the right to be able to reset user passwords and enable user
accounts. Now, currently, I'm attempting to do this with the Delegation
Control Wizard. The reset password option is working, but I'm unable to get
the enable account portion of this to work. I've even printed out a
Microsoft KB article that I thought was related to this problem (KB Article
294952). I've done all the steps that the article says to do. I've modified
the DSSEC.DAT file accordingly. I've went in to the Delegation Control
Wizard and checked on the ReadLockOutTime and WriteLockOutTime boxes. Still
not able to enable any user accounts. Is there something else I need to do
that I'm overlooking or is this just not possible for users other than those
that have Admin priviledges?



Relevant Pages

  • Re: Delegation Control
    ... > allowing access to this allows more than just enabling/disabling accounts, ... >> group with the right to be able to reset user passwords and enable user ... >> Control Wizard. ... I've went in to the Delegation Control ...
    (microsoft.public.win2000.security)
  • Re: Delegation Control
    ... lockoutTime is for locked out accounts, not disabled accounts. ... > Control Wizard. ... I've went in to the Delegation Control ...
    (microsoft.public.win2000.security)
  • Re: Delegation wizard.......
    ... To reset user passwords you need the "Reset Password" extended right on the ... This is also available through the delegation of control wizard ... you need the "Reset Password" extended right on the user object and you need ...
    (microsoft.public.windows.server.active_directory)