Giving a user the right to change passwords

I am the admin for a relativley large Windows 2003 network in a school district.  I have 3 Tech aides who are not very thechnical but I would like to give them the ability to change and reset passwords in thier own buildings.  I would like for them to have a custom console so that they can browse AD and change passwords. What is the best way to do this whithout giving them too much access?
jp_techAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Krzysztof PytkoSenior Active Directory EngineerCommented:
Create an OU for that user and delegate permissions for him
0
SGrossmannCommented:
See this article.Delegating permissions within active directory.http://www.windowsecurity.com/articles/Implementing-Active-Directory-Delegation-Administration.html
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Krzysztof PytkoSenior Active Directory EngineerCommented:
Sorry, on OU where he should be able to chabge passwords, delegate him permissions :)
0
oBdACommented:
Right-click the OU in which the user objects are (NOT any domain admins!) and use the delegation of control wizard to allow a group(!) "PasswordReset" or whatever to change the password.
Allow the same group to change the "User must change password" attribute (on W2k3, you do NOT have to edit dssec.dat!), it's not included by default and usually *very* necessary:
Minimum permissions are needed for a delegated administrator to force password change at next logon procedure
http://support.microsoft.com/kb/296999

Create the taskpad (note that the ADUC MMC from adminpak.msi has to be installed on any admin clients, the MMC alone is not enough):
Create Taskpads for Active Directory Operations
http://www.petri.co.il/create_taskpads_for_ad_operations.htm
0
jp_techAuthor Commented:
Sgrossman prided a good link that provided instructions for giving the proper delegation and obda provided the information for creating the custom MMC. Thanks guys.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Active Directory

From novice to tech pro — start learning today.