I have a Windows 2008 domain and several administrators. I had successfully delegated the reset password, change password, and unlock account permissions to a group of admins. Over time, it appears that such functionality has stopped working. After checking the ACLs on the user accounts and container in question, all permissions look to be spot on, compared to how I had originally set them up. Any ideas on what may be wrong. It appears that members of my delegated admin group can still successfully unlock accounts in the delegated OU. They cannot, however, change passwords.