AD delegation wizard permissions issue

Spaceace32 1 Reputation point
2020-07-29T22:38:08.557+00:00

Using the delegation wizard to allow the help desk to reset passwords

In one OU, there are 12 user accounts.
Only 1 of the 12 user accounts has the “User must change password at next logon” greyed out.

I can’t understand why its only greyed out on 1

Not using azure. I also tried adding the user to the OU with full control and the option is still greyed out.

I’m stumped

Any help is appreciated

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,149 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Daisy Zhou 20,791 Reputation points Microsoft Vendor
    2020-07-30T06:03:23.673+00:00

    Hello,
    Thank you for posting here.

    Based on the test in my lab.

    If I make domain Administrator deny the permission "write pwdLast" for one (www3)of five users (daisy1,daisy2,daisy3,daisy4 and www3), the option “User must change password at next logon” is changed to greyed out.

    14494-pwd1.png

    So we can check if the specific user (that we logon the DC) has deny the permission "write pwdLast" for this one user.

    1.Right click this user account\Properties\Security tab\Advanced
    2.Effective access tab\Select the specific user (that we logon the DC) and click view effective access.

    14474-pwd4.png

    1.Right click this user account\Properties\Security tab\Advanced
    2.Check if there is any Deny entry under Permission Entries.
    3.If this deny entry is inherited from its parent OU or domain.
    4.Check if there is deny the permission "write pwdLast" for this one user.

    14504-pwd2.png

    14464-pwd3.png

    If you find the deny permission, we can remove it. Then check if the option “User must change password at next logon” is changed.

    Best Regards,
    Daisy Zhou

    0 comments No comments