Jump to content

Recommended Posts

Posted

Hi,

 

I have a small network running 2008 r2 with windows 7 clients. I have been asked to give one of the teachers the ability to change passwords for students and I'm wondering what is the best way to go about this.

 

I have already delegated control of the ou to his account, it is now just a matter of how he gains access to active directory users and computers to change the passwords.

 

Is it best to install rsat on his workstation and just create a shortcut or is it best to create a custom mmc?

 

As I don't normally deal with windows 7 and 2008 r2 I find UAC annoying because I keep forgetting about it. This user does not have any admin rights, is this going to cause me a problem? I can't find a definite answer on whether or not he has to be a local admin to run either mmc or any of the rsat tools.

 

I am going to visit the site for a couple of hours and I would like to have a clear idea of what needs to be done, I got caught out by UAC a few weeks ago and no matter how much I tried I couldn't get a simple standalone flash application to run on anything but an admin account.

 

Any help would be much appreciated.

 

Thanks in advance

Posted

I just installed this wisesoft application on my test network and it seems to be exactly what I am looking for. Are there any issues running this with a non-admin account on a windows 7 workstation?

 

I see that this allows the user to enable and disable accounts, is the ability to do this covered by delegating the basic password reset using the delegation of control wizard or do I need to customise permissions to allow the teacher to do this too?

 

Thanks for your help.

Posted

When you delegated access to the OU you choose which rights to grant. If you use the Delegate Control wizard it has a checkbox for what to grant, if you only gave "Reset user password and force password change at next logon" that is all they can do.

 

I would also recommend only assigning this to groups rather than users (add user to group) otherwise if that user ever leaves you end up with unresolvable SIDs through your AD.

Posted
When you delegated access to the OU you choose which rights to grant. If you use the Delegate Control wizard it has a checkbox for what to grant, if you only gave "Reset user password and force password change at next logon" that is all they can do.

 

I would also recommend only assigning this to groups rather than users (add user to group) otherwise if that user ever leaves you end up with unresolvable SIDs through your AD.

 

Indeed. In the readme for my app, I detailed the permissions you'd need to delegate for password reset/change, unlocking an account and setting the account to force password change on next login. I believe the setting used to force password change also stores whether the account is enabled/disabled, so this would be the one you want to delegate for that capability.

 

As ruddj says, do this via a group, rather than to a user. That way you can drop people in there easily without having to repeat the action for others.

  • 5 years later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...