Can powershell be used to provide a list of people with reset password ability?

We are trying to tighten our security, but thanks to the environment we are in this is a bigger task than it should be. As part of this I have been asked to get a list of users who have the ability to reset other users passwords. there are the obvious suspects,
domain admins, service desk etc., but we also appear to have random people who can do this because of a requirement during test or development stages way back. Is there a way to get this, I looked at using powershell but there doesn't seem to be much out there
to give me a pointer, things like ADManager+ do not work, when I try to search on permissions it sits there doing nothing then crashes so I have now turned to powershell.
Is there a way to build a function using powershell that can do this or is there some third party cmdlet or app that will provide me this info?
Any help gratefully accepted

I sounds to me like some users may have received the Reset Password delegated privilege.
There's a TechNet wiki page,
How to View or Delete Active Directory Delegated Permissions with a number of methods you could use to discover who has delegated control. One of the methods uses the
QUEST AD PowerShell cmdlets
Jason Warren
@jaspnwarren
jasonwarren.ca
habaneroconsulting.com/Insights

Similar Messages

  • How can I get a list of users with reset password ability?

    We are trying to tighten our security, but thanks to the environment we are in this is a bigger task than it should be. As part of this I have been asked to get a list of users who have the ability to reset other users passwords. there are the obvious suspects,
    domain admins, service desk etc., but we also appear to have random people who can do this because of a requirement during test or development stages way back. Is there a way to get this, I looked at using powershell but there doesn't seem to be much out there
    to give me a pointer, things like ADManager+ do not work, when I try to search on permissions it sits there doing nothing then crashes.
    Is there a way to build a function using powershell that can do this or is there some third party cmdlet or app that will provide me this info?
    Any help gratefully accepted.

    Hi,
    Based on my knowledge, except for those default groups users, such as domain admins and enterprise admins and so on, have reset password ability for other users, we can use delegation control to give other common users permissions to reset password for others,
    to view or delete Active Directory Delegated Permissions, please go through the below article:
    https://social.technet.microsoft.com/wiki/contents/articles/6477.how-to-view-or-delete-active-directory-delegated-permissions.aspx
    And if you were editing single user's security tab to give specific users reset password permissions, then I think we should create a script to get all those users, for scripting, please also post in the official scripting guys forum:
    https://social.technet.microsoft.com/Forums/scriptcenter/en-US/home?forum=ITCG
    Regards,
    Yan Li
    Regards, Yan Li

  • How to get list of users who reset password using FIM portal

    How to get list of users who reset password using FIM portal
    -Thanks Rakesh Sawant

    Hi Rakesh,
    I think you are looking for something like this:
    Using Powershell to list all users that had completed
    a password reset within the last 30 days
    If you found my post helpful, please give it a Helpful vote. If it answered your question, remember to mark it as an Answer.

  • Why can't i use the radio on my nano 7g with bluetooth

    why can't i use the radio on my nano 7g with bluetooth. i wanted to use wireless feature at work but i only use the radio at work , so i bought bluetooth stereo headphones by plantronics, got the backbeat 903, at wal-mart  . got home got it all set up and works fine but not for radio , i'm so dissaponted and am thinking i might take them back and continue using the wire ware , but then again i like listening to my podcast while doing dishes and chores at home so the bluetooth would be better for that .

    i have sent a feedback form to apple about this problem . i hope that they work on a sulotion for it .

  • HT4759 updated to Lion, from snow leopard after updating all necessary programs & system, recieved emails saying it was successful changing to icloud but can i access iclound No - nothing works! webmail & mail - also reset password.

    updated to Lion, from snow leopard after updating all necessary programs & system, recieved emails saying it was successful changing to icloud but can i access iclound No - nothing works! webmail & mail - also reset password.

    Ok 1st one. The warning restriction message relates to this line in main.cf:
    smtpd_helo_restrictions = permit_sasl_authenticated  permit_mynetworks  check_helo_access hash:/etc/postfix/helo_access  reject_non_fqdn_hostname  reject_invalid_hostname  permit reject_invalid_helo_hostname
    The last reject occurs after the single word "permit" and is ignored.
    However, that's not the problem.
    I'm not exactly sure what's happening, but this might be a clue.
    It would appear that either postfix is not being able to create the socket for private/policy or it's somehow created with the wrong permissions.  You might need to ramp up the debug level to get a better idea.
    You could check if it's being created by "netstat -a | grep private/policy" in terminal.
    My guess is that it's not being created because there is no setup statement in your master.cf file, but I don't understand why postfix would be looking for it if it isn't set up.  Private/policy I think relates to grey listing.  Maybe gives you a hint.

  • Can two macs use same disk for Time Machine backup with Airport Extreme?

    Hi
    I use a Western Digital disk as a wireless Time Machine backup connected to the USB port on my Airport Extreme and it works great. My question is: can my girlfriend use that same disk for Time Machine backup from HER computer too? (I don't mind formatting the disk if needed.)
    If she can't, is it then possible to connect a USB hub and have two disks hooked up to the Airport Extreme?
    Thanks for helping. I am constantly in awe of all the help people like you give people like me. Thanks!!!
    Jakob

    I've gone through the manual setup and the assisted setup and can't seem to get my MacBook to use the Time Machine. Any thoughts or help would be greatly appreciated.
    Well, as the Jolly Giant points out....+this type of configuration is not supported by Apple+, so it's difficult, if not impossible, to provide a fix for something that Apple says that you cannot do. Reference these Apple Support documents regarding this topic:
    http://support.apple.com/kb/HT2038
    http://docs.info.apple.com/article.html?path=Mac/10.6/en/15139.html
    Your situation is not unlike other users who try this and find that one computer may backup...(usually for a limited time before corruption issues start to creep in)...but another computer cannot backup. Count me as one of those users who thought that because things seemed to work that I had somehow "beat the system".
    I started getting the corruption error messages after 4-5 weeks of successful backups, so I figured that it did not make sense to continue to try to get a second computer to backup (yes, I too could not setup a second Mac to backup).
    Sorry, I could not get a second machine to backup, so can't tell you how to accomplish that goal. If you want to continue to try backing up this way, you might want to also think about a second backup strategy...just in case backups become corrupted on the WD drive.
    Maybe if Apple says you cannot do this, they just may be right?
    Message was edited by: Bob Timmons

  • TS1543 my mac wont stop at single user it continues to root, how can i get to single user to enter info needed to reset password

    I my mac wont recognise my password, i have tried to reset password using single user but my mac wont stop at single user it just continues to root, how do i get it to stop at single user so i can add info needed to reset password?

    Are your sure that wasn't a Verbose boot (Cmd-V) you were trying? That would go on to a regular boot.
    Try a PRAM Reset, then try the single user, Cmd-S, at the startup chime. For the PRAM Reset, hold down Option - Cmd - P - R all together until it chimes a total of three times, then let go to finish booting.

  • Can't reconnect to sync from work - firefox login fails with "Incorrect password" when I know it is correct

    I can happily connect my home computers and phone to sync and I have confirmed they sync between themselves. However, my work computer has recently stopped being able to sync where it has previously been fine for well over a year. I am on the latest version of sync and Firefox 35.0.1 (both at home and work).
    When I try to reconnect to sync I am directed to the "Sign in to continue" page. It has my correct email address/account name. I enter my password (clicking "Show" to make sure it's correct) but then it always fails with "Incorrect password" in a red banner at the top. I have checked the password is correct and logged out and back in from home using the same password so I know that is correct. I have tried this logged in to work via remote desktop so I could do both at the same time to make sure there isn't just a prevailing sync server problem.
    Obviously my work computer is behind a proxy/firewall. I have recently had to add a new certificate as a result of proxy changes to get internet connectivity working. Anecdotally, I think sync stopped working at a similar time - but it's always easy to remember these things differently when you're looking for a solution. So this could be a red herring.
    Your help in getting this fixed would be much appreciated!

    Thanks for your reply.
    i've deleted all cookies, although I don't really understand how that relates. I have also spoken to our sysadmin who says we don't block access to firefox accounts per se, we do block all file-esque uploads. However, I am not sure this would make any difference to the exact problem I am seeing which is that I can't sign in to my firefox sync account. But maybe signing in to this account is different to a "normal" account - maybe there is more of a two way handshake which relies on sending some encrypted data which appears to our proxy like a file being uploaded out of the company.
    I got a slightly different error on my latest clear down and retry, in that the sign in just waited forever (overnight) without success.
    Any further help gratefully received...

  • How can I access user accounts on Macbook running 10.4 without resetting passwords

    Is it possible to access the desktop without resetting passwords?

    Not if if you don't have auto log-in turned on.
    Resetting or changing a password:
    For Snow Leopard or earlier:  http://support.apple.com/kb/HT1274
    If it's running Mac OS X 10.6.8 or earlier, insert a Mac OS X install DVD, restart with the Option key held down, click on it, and use the Reset Password utility.

  • How can I add new user in sharepoint list column (people or group) or in sharepoint group using loginName only

    Hi
    If I have only login name of any user like - "Donamin\login_name".
    If this user is not present in sharepoint portal.
    How can I add this user to people or group column of any list or in any  sharepoint group with permission?

    hi
    got the issue
    it should be  like this -
    string userloginname = @"DOMAIN001\vyankatesh_mujumdar"
    using (SPSite oSpSite = new SPSite(site.ID))
    using (SPWeb web = site.OpenWeb())
    try
    { SPList lst = web.Lists["TestList"];
    string userloginname = @"DOMAIN001\vyankatesh_mujumdar";
    web.EnsureUser(userloginname);
    SPUser oSPUser = web.SiteUsers[userloginname];
    SPFieldUserValue FieldValueName = new SPFieldUserValue(web, oSPUser.ID, oSPUser.LoginName);
    SPListItem oSPListItem = lst.Items.Add();
    oSPListItem["Title"] = userloginname;
    oSPListItem["People"] = FieldValueName;
    oSPListItem.Update();
    catch (Exception ex)
    ExceptionManager.LogErrorInFile("--------Exception -------", bIsLogEnabled);
    ExceptionManager.LogErrorInFile(ex.Message, bIsLogEnabled);
    ExceptionManager.LogErrorInFile(ex.Source, bIsLogEnabled);
    ExceptionManager.LogErrorInFile(ex.StackTrace, bIsLogEnabled);
    ExceptionManager.LogErrorInFile("-------------------------------------------------------", bIsLogEnabled);
    Thanks for all for the reply

  • Answer to my question: Why can I not use Premiere Elements 12 on my PC with WIndows 8.1 when the video is done with the same software on a PC with Windows 7?

    i got an answer to use archive function from Mr. Romano:
    I did as you said, but it did not work, I get the dummy video with no real video.
    I had no menu yet on the video.
     What came in my mind when I read your e-mail, on one PC is WIndows 8.1 64 bit and on the other Windows 7 32 bit.
    When I load the videos from the camrecorder (tape) with Premiere Elements without doing something, I can switch to the other PC and it works. 
    Regards
    N. Singer

    Vaihingen
    How did you go about transferring the Premiere Elements 12 project on Windows 7 64 bit to Premiere Elements 12 on Windows 8.1 64 bit.
    Therein is what I believe is your problem. You in all likelihood do not have a codec problem of any kind, rather Premiere Elements 12 project on Windows 8.1 64 bit with disconnect between it source media and the project file. Here is how it goes.
    When you import a file into Premiere Elements project, what you have in Premiere Elements is a copy of the original which is still at its hard drive save location. But the project must trace back to that original on its hard drive save location.
    You may have the project.prel (project file) opening in Premiere Elements 12 on the second computer, but what I suspect to be the case is that you do not have the project media on that second computer.
    If so....On the first computer, archive the project with File Menu/Project Archiver and its Copy Project option. Transfer the resulting saved Copied Folder to a USB Flash Drive which will be used to transfer the Copied Folder to the second computer. In the second computer, open the Copied Folder, right click the project.prel file in the Copied Folder, select Open With, and then Premiere Elements 12.
    Did you set up disc menu in the Premiere Elements 12 Windows 7 64 bit project?
    Please review and consider the above and let us know if any or all of that applies to your situation.
    Thank you.
    ATR

  • HT201493 can 2 pepole use find my friends on 2 devices with the same apple id

    My wife and I are connected to the same Apple ID we would like to use Find My Friends to follow each other but only one of use shows up on the map,

    The app should locate both phones if they are using the same iCloud account and the app is signed into the account.  If they are using different account, sign out, then sign back in with the other account to track the other phone.
    If one of them isn't showing and you're signed into the correct iCloud account, go to Settings>iCloud on the phone in question and turn Find My iPhone Off, then back On.

  • Why can't I use SIRI and dictation on my iPad2 with release 6.1?

    Why is SIRI and dictation not available on Ipad2?  I have the latest release of IOS 6.1.

    Siri requires at least an iPad 3.
    Here's an explanation of what features require which hardware.
    iOS 6: Which software features does my iPhone, iPad, or iPod touch support?

  • Can I delete an icloud account from apple's system with out password

    My mom is 88..  Apple help desk got her set up for an icould account she did not need becuse they misunderstood the nature of help she needed. It is a second uncessary account and is wreaking havoc with her iPad.  My mom can not remember her password.  How can I permanantely remove the account from Apple's system. 

    Apple IDs (which are used to establish various types of accounts like icloud and itunes store) cannot be permanently deleted, nor can the accounts.  Just don't use the account in question if you don't want it.
    If this is about icloud, then on her ipad, Go to Settings>icloud, scroll to bottom of screen and tap Delete Account.  In the future she can always log back in.  If she needs to do this, then to deal with a forgotten password...
    Try the following link to reset your password.
    https://iforgot.apple.com

  • How do I get a list of the websites with their passwords that Firefox fills in

    There used to be a list of websites with their passwords listed. I can't find it now. I need the information because I have forgotten some of the pass words that are filled in

    hello cellardweller221, you can access that list when you go to ''firefox > options > security > saved passwords''.

Maybe you are looking for