Active Directory management & automation

Allow Users to Modify Specific Properties of Their Accounts

By default, all users are allowed to modify certain properties of their own accounts. This permission is granted by the built-in Security Role called User Self-Service. This role allows users to modify only the properties that belong to the Personal Information and Web Information property sets.

Personal Information property set

Property LDAP Name
Assistant assistant
Notes info
Picture thumbnailPhoto
Personal Title personalTitle
Street Address streetAddress
Home Address homePostalAddress
Country c
Country Code countryCode
Country Name co
City l
Office physicalDeliveryOfficeName
P.O.Box postOfficeBox
Home Address postalAddress
Zip/Postal Code postalCode
Registered Address registeredAddress
State/Province st
Street street
Preferred Delivery Method preferredDeliveryMethod
Telephone Number telephoneNumber
Telephone Number (Other) otherTelephone
Mobile Phone mobile
Mobile Phone (Other) otherMobile
Home Phone homePhone
Home Phone (Other) otherHomePhone
Fax facsimileTelephoneNumber
Fax (Other) otherFacsimileTelephoneNumber
IP Phone ipPhone
IP phone (Other) otherIpPhone
Pager pager
Pager (Other) otherPager
International ISDN Number internationalISDNNumber
Primary Telex Number primaryTelexNumber
Telex Number telexNumber
MSMQ Digests mSMQDigests
MSMQ Sign Certificates mSMQSignCertificates
Primary ISDN Number primaryInternationalISDNNumber
Teletex Terminal Identifier teletexTerminalIdentifier
User Certificate userCertificate
User-Cert userCert
User Shared Folder userSharedFolder
User Shared Folder (Other) userSharedFolderOther
User SMIME Certificate userSMIMECertificate
X121 Address x121Address

Web Information property set

Property LDAP Name
Web Page wWWHomePage
Web Page (Other) url

In this tutorial you will learn how to grant regular users the rights to modify specific properties of their own accounts, and how to configure Web Interface to allow users to edit those properties.

Grant Permissions

To allow users to modify properties of their own accounts, you need to add corresponding permissions to the built-in Security Role User Self-Service.

If some undesired changes were made to a built-in Security Role, you can discard all changes made to this role. For this purpose, right-click the role you need and click Restore to Initial State in the context menu.
Launch Adaxes Administration Console, expand Adaxes service \ Configuration \ Security Roles \ Builtin. Select the User Self-Service role. The permissions and assignments of this role will be displayed in the Result Pane (located to the right).

Select Security Role

In the Result Pane (located to the right), click Add.
Click Add Permission

To add a permission to modify a specific property:
  • Select User in the list of object types, to which permissions are applied.
  • Check the Allow option for the desired property in the Property-specific permissions section. For example, to allow modifying the Title property, check the Allow check box for the Write 'Title' Property permission.

    Selecting Permission

    If the property you need is not available in the Property-specific permissions section, enable the Show all properties option.

Click OK and then click Save changes below the Assignments list.
Distribution of permissions with the help of Security Roles does not modify native Active Directory permissions.

Customize Web Interface

The Web Interface for Self-Service allows users to modify only the properties for which they have the Write permission by default. If you want users to be able to modify other properties, you need to customize the form used to edit user accounts in the Web Interface.

To add a property to the Edit User form:

On the computer, where the Web Interface is installed, start the Web Interface Customization tool.

In the Interface type drop-down list, select Self-Service.

Activate the AD Management tab and click Customize Forms and Views.

Select User in the Object types list and activate the Modify tab.

Select the section to which you want to add a new field and click the Add button located under the Section fields list.

Select the property you want to add to the form, click OK and then click Apply.
For more details on how to customize forms and views in Web Interface, see
Customize Forms for User Creation and Editing.
? Waiting

Progress status: Checking...