Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Anybody know of any existing web based tool to reset passwords on Active Directory accounts?

 

Currently have a customised Managment Console that just lists the Student OU in Active Directory and staff have permission to reset passwords for the kids.

 

Were having Sharepoint Server soon, so i'm wanting to make the staff portal be a one stop for any tasks they have to do, are there any web parts out there for this or any other web based tool that will do it.

 

I've attached a screen shot of our existing program to do it, so you can see what i'm trying to achive web based.

Posted

Self Service Password reset has a web based tool as part of it's admin pages.

 

This can be made available to staff based on membership of an AD group.

 

This tool will be updated hopefully soon'ish to make it's functionality better because at the moment you have to type in the username perfectly.

 

I wonder if Irazmus could seperate this as well so it could be used as a standalone tool in it's own right?

 

Ben

Posted

Hi I removed the screenshot as having screenshot of student names on public website is not a good thing.

 

Feel free to post image backup with student names removed.

 

Regards

 

Russell

Posted

I've got a PHP script that works on 2003 domains that allows staff to reset passwords users in a selected OU (PM me if wanted).

 

Only problem is that it can't do passthru authentication so you either need to code a generic account for reseting passwords (:eek:) or force the users to provide authentication details.

Posted (edited)

Here's the hta script I found. Sorry can't find the original source.



Simple Active Directory User Management
<br />
window.resizeTo(347,130)<br />
window.moveTo(330,220)<br />

ApplicationName="UserAdm.hta"
singleInstance="yes"
icon="c:\windows\msagent\agentsvr.exe"
minimizebutton="no"
maximizebutton="no"
border="thick"
borderStyle="sunken"
sysMenu="yes"
scroll="no"
>



<br />
Sub bt1Go_onclick()<br />
<br />
'** Declarations:'<br />
Dim OPR, DM, USR, strNTName, strUserDN, strNM, objUser, TNP, EROR, ABS<br />
Dim objNetwork, objShell, objFSO<br />
<br />
'** Objects:'<br />
Set objNetwork = CreateObject("WScript.Network")<br />
Set objShell = CreateObject("Wscript.Shell")<br />
Set objFSO = CreateObject("Scripting.FileSystemObject")<br />
<br />
'** User/Domain:'<br />
OPR = objNetwork.UserName<br />
DM = objNetwork.UserDomain & "\"<br />
<br />
'** Type username for the user that needs password change:'<br />
USR = InputBox("Username:", "Create Temporary Active Directory User Password", _<br />
"Write Username Here")<br />
<br />
'** Prevent run-time errors:'<br />
On Error Resume Next<br />
<br />
'** NameTranslate constants:'<br />
Const ADS_NAME_INITTYPE_GC = 3<br />
Const ADS_NAME_TYPE_NT4 = 3<br />
Const ADS_NAME_TYPE_1779 = 1<br />
<br />
'** Combine the user name and domain name:'<br />
strNTName = DM & USR<br />
strNT2 = DM & OPR<br />
<br />
'** Translate operator name into DN:'<br />
Set objTrans2 = CreateObject("NameTranslate")<br />
objTrans2.Init ADS_NAME_INITTYPE_GC, ""<br />
objTrans2.Set ADS_NAME_TYPE_NT4, strNT2<br />
strUserDN2 = objTrans2.Get(ADS_NAME_TYPE_1779)<br />
Set objUser2 = GetObject("LDAP://" & strUserDN2)<br />
strUS3 = Mid(strUserDN2,4)<br />
strUS4 = Split(strUS3, ",")<br />
For i = LBound(strUS4) to UBound(strUS4)<br />
strNM2 = strUS4(i)<br />
Exit For<br />
Next<br />
<br />
'** Translate username into DN:'<br />
Set objTrans = CreateObject("NameTranslate")<br />
objTrans.Init ADS_NAME_INITTYPE_GC, ""<br />
objTrans.Set ADS_NAME_TYPE_NT4, strNTName<br />
If Err <> 0 Then<br />
ABS = 1<br />
End If<br />
<br />
'** Execute if object is found:'<br />
If ABS <> 1 Then<br />
strUserDN = objTrans.Get(ADS_NAME_TYPE_1779)<br />
<br />
'** Do LDAP bind to object:'<br />
Set objUser = GetObject("LDAP://" & strUserDN)<br />
<br />
'** Get full name:'<br />
strUS1 = Mid(strUserDN,4)<br />
strUS2 = Split(strUS1, ",")<br />
For i = LBound(strUS2) to UBound(strUS2)<br />
strNM = strUS2(i)<br />
Exit For<br />
Next<br />
<br />
'** Assign password and parameters:'<br />
If strNM <> "" Then<br />
TNP = "changeme" & Mid(objFSO.GetTempName,4,4)<br />
objUser.SetPassword TNP<br />
If Err <> 0 Then<br />
EROR = 1<br />
End If<br />
objUser.Put "pwdLastSet", 0<br />
objUser.IsAccountLocked = False<br />
objUser.SetInfo<br />
End If<br />
<br />
'** If no error, show new temporary password:'<br />
If EROR <> 1 Then<br />
MsgBox "New temporary password for " & UCase(USR) & " (" & strNM & "):" & _<br />
vbCrLf & vbCrLf & TNP & vbCrLf, 64, "New Password, configured by " & strNM2<br />
End If<br />
<br />
End If<br />
<br />
'** End if object not found:'<br />
If ABS = 1 Then<br />
MsgBox UCase(USR) & " was not found. Please try again.", _<br />
48, "Unknown Username"<br />
End If<br />
<br />
'** If no permission, give message:'<br />
If EROR = 1 Then<br />
MsgBox "You can not change password for this user.", _<br />
48, "Permission Denied"<br />
Wscript.Quit<br />
End If<br />
<br />
End Sub<br />




<br />
Sub bt2Go_onclick()<br />
<br />
'** Declarations:'<br />
Dim OPR, DM, USR, strNTName, strUserDN, strNM, objUser, TNP, DENY, POS, NEG<br />
Dim objNetwork, objShell<br />
<br />
'** Objects:'<br />
Set objNetwork = CreateObject("WScript.Network")<br />
Set objShell = CreateObject("Wscript.Shell")<br />
<br />
'** User/Domain:'<br />
OPR = objNetwork.UserName<br />
DM = objNetwork.UserDomain & "\"<br />
<br />
'** Write username for the user that needs to be enabled or disabled:'<br />
USR = InputBox("Username:", "Enable or Disable Active Directory User", _<br />
"Write Username Here")<br />
<br />
'** Prevent run-time errors:'<br />
On Error Resume Next<br />
<br />
'** Declare NameTranslate constants:'<br />
Const ADS_NAME_INITTYPE_GC = 3<br />
Const ADS_NAME_TYPE_NT4 = 3<br />
Const ADS_NAME_TYPE_1779 = 1<br />
<br />
'** Combine the user name and domain name:'<br />
strNTName = DM & USR<br />
strNT2 = DM & OPR<br />
<br />
'** Translate operator name into DN:'<br />
Set objTrans2 = CreateObject("NameTranslate")<br />
objTrans2.Init ADS_NAME_INITTYPE_GC, ""<br />
objTrans2.Set ADS_NAME_TYPE_NT4, strNT2<br />
strUserDN2 = objTrans2.Get(ADS_NAME_TYPE_1779)<br />
Set objUser2 = GetObject("LDAP://" & strUserDN2)<br />
strUS3 = Mid(strUserDN2,4)<br />
strUS4 = Split(strUS3, ",")<br />
For i = LBound(strUS4) to UBound(strUS4)<br />
strNM2 = strUS4(i)<br />
Exit For<br />
Next<br />
<br />
'** Translate name into DN:'<br />
Set objTrans = CreateObject("NameTranslate")<br />
objTrans.Init ADS_NAME_INITTYPE_GC, ""<br />
objTrans.Set ADS_NAME_TYPE_NT4, strNTName<br />
strUserDN = objTrans.Get(ADS_NAME_TYPE_1779)<br />
<br />
'** Do LDAP bind to object:'<br />
Set objUser = GetObject("LDAP://" & strUserDN)<br />
<br />
'** Get full name:'<br />
strUS1 = Mid(strUserDN,4)<br />
strUS2 = Split(strUS1, ",")<br />
For i = LBound(strUS2) to UBound(strUS2)<br />
strNM = strUS2(i)<br />
Exit For<br />
Next<br />
<br />
'** If no error, enable or disable user:'<br />
If Err = 0 Then<br />
Const ADS_UF_ACCOUNTDISABLE = 2<br />
intUAC = objUser.Get("userAccountControl")<br />
objUser.Put "userAccountControl", intUAC XOR ADS_UF_ACCOUNTDISABLE<br />
objUser.SetInfo<br />
If intUAC AND ADS_UF_ACCOUNTDISABLE Then<br />
POS = 1<br />
Else<br />
NEG = 1<br />
End If<br />
Else<br />
objShell.Popup UCase(USR) & " was not found. Please try again.", _<br />
5, "Unknown Username", 48<br />
Wscript.Quit<br />
End If<br />
<br />
'** If no permission, give message:'<br />
If Err = "-2147024891" Then<br />
DENY = 1<br />
objShell.Popup "You can not enable or disable this user.", _<br />
5, "Permission Denied", 48<br />
Wscript.Quit<br />
End If<br />
<br />
'** If no error, show result:'<br />
If DENY <> 1 Then<br />
If POS = 1 Then<br />
MsgBox UCase(USR) & " were successfully enabled.", _<br />
64, "User enabled by " & strNM2<br />
End If<br />
<br />
If NEG = 1 Then<br />
MsgBox UCase(USR) & " were successfully disabled.", _<br />
64, "User disabled by " & strNM2<br />
End If<br />
End If<br />
<br />
End Sub<br />




</pre><table border="1" id="table1" bgcolor="#EEEEEE" bordercolorlight="#C0C0C0" bordercolordark="#666699" bordercolor="#C0C0C0">

Change User Password



Enable or Disable User


</table><br><b

Edited by cjohnsonuk
added code tags
  • Thanks 1
Posted

cool, nice little script.

 

however if you put code in the CODE tags (see the post editor) you can put it in a frame to take up less room.

Posted

Next step I want to do is extend the web page the script creates so that they can type in search options (eg surname, first name, year or form) then click submit and it shows a list of student accounts from the AD that match the above. I'll probably use "location" for the class/form field and populate that in AD from an export in sims.

 

I'd also like it to check when the password was last reset. We're planning on keeping that and "misdemeanors" stored in the notes part of the AD so that staff will get notification of "previous form" before confirming the password reset. Then once confirmed a new record/line for that password reset will be made in the notes field to try and stop time wasters or at least identify them.

 

 

ChrisJ

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...