what previledges the ILM server admin account needs
what previledges the ILM server admin account needs to import user data from AD, and reset password for end user through portal?
July 14th, 2009 1:26pm

In order for the AD Management Agent to work against AD the minimum permissions required to the AD user object configured to run the MA is "Replicate Directory Changes" extended right on the domain NC head, i.e. allow "replicate directory changes" defined on the domainDNS object itself. This, in addition to the default permissions for user objects is enough to import data from AD.To reset passwords using SSPR you require two additional extended rights for the user and/or inetOrgPerson object classes, defined at a container of your choosing. These extended rights are "Change Password" and "Reset Password".Hope this helps?
Free Windows Admin Tool Kit Click here and download it now
July 14th, 2009 1:31pm

In order for the AD Management Agent to work against AD the minimum permissions required to the AD user object configured to run the MA is "Replicate Directory Changes" extended right on the domain NC head, i.e. allow "replicate directory changes" defined on the domainDNS object itself. This, in addition to the default permissions for user objects is enough to import data from AD.To reset passwords using SSPR you require two additional extended rights for the user and/or inetOrgPerson object classes, defined at a container of your choosing. These extended rights are "Change Password" and "Reset Password".Hope this helps? sounds a quite cool answer ! :-) I will study a digest before I dig for more details if I need. Thanks!
July 14th, 2009 1:48pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics