Delegate Permissions on OU

  • Thread starter Thread starter RDH
  • Start date Start date
R

RDH

We have added a new domain to our Windows 2000 forest. I
tried to give the help desk from the root domain
premissions to change password and reset accounts. Went
through the delegation wizard and it worked fine - we can
change passwords and reset new accounts but the old
accouts that were already defined in the User container
failed. When the help desk tries to reset an account for
a user that already existed - they get insufficient
privledges. Works great on accounts that were created
after I ran the delegation wiz. Any ideas on how to force
the permissions on the old accounts?
 
I figured this out, we ended up burning a call on premier
support but I thought I would post a reply so the next
poor soul wouldn't have to.

These are the KB articles you want to look at.

Minimum Permissions Are Needed for a Delegated
Administrator to Force Password Change at Next Logon
Procedure (296999)

How to Grant Help Desk Personnel the Specific Right to
Unlock Locked User Accounts (279723)
 
Back
Top