I have delegated control on all containers and OU's containing user accounts to a group called IT-Helpdesk. At this point they should have full control but although they can check the "User must change password at next logon" and even apply the change, they cannot uncheck this box once its set even though seconds earlier it was they who set it in the first place.
The box is NOT gray'd out they simply get:
The following active directory error occured: Access Denied.
When they try to apply the change after deselecting the box.
I'm pretty sure there is no way to give them even more acces, I even tried to create a custom task to delegate and chose "full control" (which i need to strip out once I figure this out).
Please help.
Start Free Trial