Web Active Directory recommends that you create an account in your domain dedicated to resetting passwords in PeoplePassword. PeoplePassword uses this account to bind to your Active Directory to perform password reset operations instead of passing the PeoplePassword user’s credentials to Active Directory for binding. Web Active Directory has chosen to implementa proxy account model instead of passing user credentials to simplify the Active Directory configuration required to run PeoplePassword. You only need to configure Active Directory permissions that delegate reset password permissions to the PeoplePassword account.
Notes:
PeoplePassword requires that your account have permissions to reset passwords and force password reset at next logon as well as to unlock AD accounts. Once you create the PeoplePassword account in your domain, use the procedures below to grant the necessary permissions to 1) reset Active Directory passwords, 2) change Active Directory passwords, and 3) unlock Active Directory accounts using PeoplePassword. Each procedure uses the Delegation of Control wizard to delegate administrative password resets and Windows account unlocks to your service account.
Procedure 1: To grant Microsoft Active Directory password reset permissions to your PeoplePassword account:
You need to run the Delegation of Control wizard one more time to delegate the AD unlock account privilege. Follow Procedure 2 to complete this action. This privilege is controlled by the AD lockoutTime attribute and you cannot delegate it using a common task like you did for the reset password privileges.
Notes:
The change password privilege is granted to Everyone automatically since you are required to know your old password in order to change it.
Procedure 2: To grant Active Directory unlock account permissions to your PeoplePassword account:
You should now be ready to run PeoplePassword to reset and change Active Directory passwords and unlock Active Directory accounts.
Resources