We help IT Professionals succeed at work.
Get Started

Attribute permission - unicodePwd?

325 Views
Last Modified: 2016-03-08
Does anyone know of an easy way to delegate permission to modify the unicodePwd attribute?

Third-party is trying to assist with LDAP based password resets, and they are insisting permission to this attribute is needed. I don't even see that attribute in the Security tab for User Objects in Active Directory when I go to check available permissions.

Or is there another minimum list of permissions needed for carrying out password resets in Active Directory via LDAP?

I delegated typical permissions:

•      Change Password
•      Reset Password
•      Read userAccountControl
•      Write userAccountControl
•      Read lockoutTime
•      Write lockoutTime
 
But they get the following error when trying to carry out a password reset:

error: [LDAP: error code 53 - 0000052D: SvcErr: DSID-031A12D2, problem 5003 (WILL_NOT_PERFORM), data 0
Comment
Watch Question
Technical Systems Analyst
CERTIFIED EXPERT
Commented:
This problem has been solved!
Unlock 1 Answer and 2 Comments.
See Answer
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE