Install Active Directory Users and Computers on Desktop PC with Password reset and unlock access

Our Servers are
Windows Server 2008 R2 Starndard 64 bits

All Desktops are
Windows 7 32 bits

I want to Install Active Directory Users and Computers on Desktop PC with Password reset and unlock rights only on one of my staff's machine.

How can i do it?

Thanks in advance.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Hi, install AD tools on the computer.  In the AD group policy modify it to limit the staff to password reset and unlock rights.
You will have to install RSAT to get ADUC on a workstation.

As for the password reset, delegate control on the OU and grant a user or security group "Reset user passwords and force password change next logon" permissions."
Active Protection takes the fight to cryptojacking

While there were several headline-grabbing ransomware attacks during in 2017, another big threat started appearing at the same time that didn’t get the same coverage – illicit cryptomining.

propertyozadminAuthor Commented:
Thanks Guys,

I have mananged download RSAT and installed on my desktop.( My login is member of domain admin group)

I think i will have no problem installing it on user's PC who is not domain administrator.
I am still not sure how to restrict that user to be able to just reset password and unlock account of other users. (really need to make sure he can't delete users and make other changes)

Do i need to set it up on domain Group policy ??
How do i set it up?

Help pls
I would shy away from installing RSAT on users desktops and giving them ANY access to ADUC. There are plenty of affordable and free Password Self Service solutions available.

If you enable users in AD to be able to change their own passwords, they can do it right from the login screen by clicking on 'Reset Password' (unlocking an account does not work).

If I may reccomend a product, I've been using Anixis Password Reset. It's definitely affordable.
You do not need a GPO. Delegate control on the OU and grant a user or security group "Reset user passwords and force password change next logon" permissions.
propertyozadminAuthor Commented:
Hi robdl / motnahp00,

Thanks for your suggestions.

I think i didn't make myself clear. I want to install RSAT on just 1 user's computer so he can reset/unlock account for all users with our organisation. I want him to be point of contact for all our staff in case of account lock out or if password reset requied. But i need to make sure he can't make any other changes through Active directory uses and computer.

Suggestions Please....
Only install the necessary components through RSAT and give him the permissions on each container through Delagate Control. Here is a link that applies to 2008 also:

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Microsoft Legacy OS

From novice to tech pro — start learning today.