0 votes

We have a customized the help desk security role to allow only resetting passwords and unlocking accounts. We don't want them to be able to enable accounts that are disabled. I don't see an option for denying write of the property "Account is disabled" or "Useraccountcontrol" or "ms-ds-user-account-disabled". Is it possible to prevent the user from writing to certain "account options"? It seems that its an all or nothing setting.

by (1.5k points)

1 Answer

+1 vote
by (201k points)
selected by
Best answer

Hello Mark,

Unfortunately, it is not possible to disallow users to modify only specific Account Options flags as it is a single property.

As a solution, you can use a Business Rule triggering Before enabling a user account that will cancel the operation if it is performed by a Help Desk user. The rule will look like the following: image.png


Thanks! That will work!

Related questions

0 votes
1 answer

I have setup a form to allow HR to edit some details on AD accounts. Currently the scope is limted to only AD object under one pre-chosen OU. The other option is an ldap filter. How can I allow this action to display user accounts from two seperate OU

asked Nov 18, 2019 by ice-dog (170 points)
0 votes
1 answer

Can you please advise on the best way to do this? We have a forest with four domains. In one of those domains we keep consultants, partners, and vendors (lets call ... Adaxes users from adding users from Domain X to any groups outside of Domain X. Thanks

asked Jan 29, 2013 by jiambor (1.2k points)
0 votes
0 answers

Hi, how can I change Help Desk to something a little more specific like "Onboarding Portal"? Or a bit more catchy that our HR will like rather then see Help Desk in the left hand corner.

asked Oct 9, 2019 by 6FigureMission (140 points)
0 votes
1 answer

When a new user account is created by copying an existing one, is it possible to prevent the new account from becoming a member of security groups in a specific OU (when the ... same way as the account being added to the group, which I need for audit purposes.

asked Sep 28, 2020 by markcox (70 points)
0 votes
1 answer

I have an ADP Sync scheduled task that modifies and creates users from a csv file. I also have reports that show new users created and management history for user ... ADP Sync scheduled task so that they only run after the ADP Sync task is complete?

asked Jan 7, 2020 by barberk (60 points)
2,493 questions
2,240 answers
414,758 users