I know that too but I want to delegate control over this in the AD to an restricted account operator. I know that if I delagete write all permissions or full control it works but I don't want to allow that much. You can for example delegate reset password and lock account but how do you delagate "User cannot change password"
Main Topics
Browse All Topics





by: EvilAardvarkPosted on 2004-06-09 at 09:21:08ID: 11271616
I know if you go into AD Users and Computers, select the username you want, secondary-click, properties, and account tab, and set them individually to "User cannot change password", that would work.
If you use group policy, you should be able to set it in there, too.