Grant Rights to Reset Passwords and Unlock Accounts
In order to allow specific users or groups to reset passwords and unlock user accounts, you need to grant them the Reset Password and Write 'Account Options' Property permissions. For this purpose, you need to create a Security Role that grants these permissions and assign the new Role to the users or groups, to which you want to allow resetting passwords and unlocking accounts.
Launch Adaxes Administration
Console, right-click your Adaxes service, point to New and click Security
Role. The Create Security Role wizard will open.
Enter the name
for the new Role, and click Next.
Here you need to
specify permissions the new Role will grant. Click Add.
In the Add Permissions dialog that opens, do the following:
- Select User in the list of object types, to which permissions are applied.
- Check the Reset Passwords permission in the Allow column of the General permissions section.
- Check the Write 'Account Options' Property permission in the Allow column of the Property-specific permissions section. Click OK.
Optionally, add the Read permission
Click the Add button to return to the Add Permissions dialog. Select the Read permission in the Allow column of the General permissions section. Click OK.
Click Next.
Here, at the Assign Role page, specify users or groups to which you want
to assign the new Role. To quickly find a user or group, type its name in the search
field. Click
Search and select the object you need in the search results. Click the Assign
button.
In the Role Activity
Scope dialog that opens, you need to select where the specified users or
groups will be able to apply the permissions granted by this Security Role.
You can select one of the following items:
-
All Objects - select if you want to allow the users or groups specified at
the previous step to reset passwords and unlock accounts of the users located in
any AD domain managed by the Adaxes service.
-
Specific Domain - select a specific AD domain if you want to allow resetting
passwords and unlocking accounts of all users in the AD domain you specify. When
selected, you will need to specify the assignment scope in the Assignment Options
dialog.
-
OU or Container - select a specific organizational unit or container if you
want to allow resetting passwords and unlocking accounts of all users located in
the selected OU or container. Once selected, you will need to specify the assignment
scope in the Assignment Options dialog.
-
Group - select a specific group if you want to allow resetting passwords
and unlocking accounts of the users that are members of the selected group. When
selected, you will need to specify the assignment scope in the Assignment Options
dialog.
-
Business Unit - select a Business Unit if you want to allow resetting passwords
and unlocking accounts of the users that are members of a specific Business Unit.
To view available Business Units, select the Business Units item in the Look
in drop-down list.
Once selected, you will need to specify the assignment scope in the Assignment Options dialog.
Select the object you need and click Add. When finished, click OK.
When specified,
the assignments will be displayed in the Assignments list. To add assignments
to other users or groups, repeat steps 5 and 6. Click Finish.
