Active Directory management & automation

Grant Rights to Reset Passwords and Unlock Accounts

In order to allow specific users or groups to reset passwords and unlock user accounts, you need to grant them the following permissions:

  • Reset Password
  • Write 'Account Options' Property
  • Write 'Lockout-Time' Property

For this purpose, you need to create a Security Role that grants these permissions and assign the new Role to the users or groups, to which you want to allow resetting passwords and unlocking accounts.

1Launch Adaxes Administration Console, right-click your Adaxes service, point to New and click Security Role. The Create Security Role wizard will open.

Launching the Create Security Role wizard

2Enter the name for the new Role, and click Next.

3Here you need to specify permissions the new Role will grant. Click Add.

Create Security Role - Step 2

4 In the Add Permissions dialog that opens, do the following:

  • Select User in the list of object types, to which permissions are applied.
  • Check the Reset Passwords permission in the Allow column of the General permissions section.
  • Check the Write 'Account Options' Property permission in the Allow column of the Property-specific permissions section.
  • Check the Write 'Lockout-Time' Property permission in the Allow column. Click OK.

Add Permission


Optionally, add the Read permission

It is reasonable to specify the Read - All object types permission for every Security Role, as this permission allows browsing Active Directory. By default, this permission is granted by the Domain Users built-in Role, however, if that Role is disabled, users will not be able to view any objects in Active Directory.

Click the Add button to return to the Add Permissions dialog. Select the Read permission in the Allow column of the General permissions section. Click OK.

Specify additional permissions


5Click Next. Here, at the Assign Role page, specify users or groups to which you want to assign the new Role. To quickly find a user or group, type its name in the search field. Click Search button Search and select the object you need in the search results. Click the Assign button.

Role assignments

6In the Role Activity Scope dialog that opens, you need to select where the specified users or groups will be able to apply the permissions granted by this Security Role.

You can select one of the following items:

  • All Objects - select if you want to allow the users or groups specified at the previous step to reset passwords and unlock accounts of the users located in any AD domain managed by the Adaxes service.

  • Specific Domain - select a specific AD domain if you want to allow resetting passwords and unlocking accounts of all users in the AD domain you specify. When selected, you will need to specify the assignment scope in the Assignment Options dialog.

    Assignment Options

    Select All objects in this Domain. It means that users or groups specified at the previous step will be able to apply permissions of the new Role to all users in the selected domain.

    Assignment Options for a Specific Domain

  • OU or Container - select a specific organizational unit or container if you want to allow resetting passwords and unlocking accounts of all users located in the selected OU or container. Once selected, you will need to specify the assignment scope in the Assignment Options dialog.

    Assignment Options

    To allow resetting passwords and unlocking accounts of all users under the selected OU at any nesting level, click Child objects of this Organizational-Unit. To allow resetting passwords and unlocking accounts of the users that are direct children of the selected OU, check also Immediate child objects only.

    Assignment Options for an OU or Container

  • Group - select a specific group if you want to allow resetting passwords and unlocking accounts of the users that are members of the selected group. When selected, you will need to specify the assignment scope in the Assignment Options dialog.

    Assignment Options

    To allow resetting passwords and unlocking accounts of the users that are members of the selected group, select Members of this Group.

    To allow resetting passwords and unlocking accounts of the users that are direct members of the selected group, check also Direct members only.

    Assignment Options

  • Business Unit - select a Business Unit if you want to allow resetting passwords and unlocking accounts of the users that are members of a specific Business Unit. To view available Business Units, select the Business Units item in the Look in drop-down list.

    Viewing Business Units

    Once selected, you will need to specify the assignment scope in the Assignment Options dialog.

    Assignment Options

    In this case, the only applicable option is Members of this Business Unit. It means that the assignment will include all users that are members of the selected Business Unit. Select this option and click OK.

    Assignment Options

Select the object you need and click Add. When finished, click OK.

7When specified, the assignments will be displayed in the Assignments list. To add assignments to other users or groups, repeat steps 5 and 6. Click Finish.

Assignments

Distribution of permissions with the help of Security Roles does not modify Active Directory native permissions.
? Waiting

Progress status: Checking...