Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

September 27, 2007 12:00 AM

Granting Users the Authority to Unlock Other Users' Accounts

Windows IT Pro
InstantDoc ID #96594
Rating: (0)

Q: Users frequently lock themselves out of our high-security network because of the strict lockout policies and long passwords our security requirements mandate. We want certain trusted users to be able to unlock other user’ accounts, but we don’t want to grant them the authority to reset users' passwords because that would enable them to impersonate those users. I've found permissions for resetting passwords (Set Password), but I can’t find any permissions corresponding to the Account is locked out check box on the Account tab in the Microsoft Management Console (MMC) Active Directory Users and Computers snap-in. How can I delegate this permission?

A: The property that controls the lockout status of a user account is lockoutTime. Here’s how to delegate write access to this property. In the Active Directory Users and Computers snap-in, open the properties of the organizational unit (OU) that contains the user accounts that you want trusted users to have the authority to unlock. Select the Security tab and click Advanced. Click Add and enter the name of the group whose members are the trusted users and click OK. Then, select the Properties tab on the Permission Entry dialog box. In the Apply onto drop-down menu, select User objects, locate the Write lockoutTime property in the Permissions list, and select the Allow check box. Now, users in the trusted group will be able to open other user accounts in this OU and clear the Account is locked out check box without being able to modify these accounts.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.