Inside Activate
...
How To Guides
Active Directory Permissions for Password Reset Only
4 min
the activate orchestrator (job) service account will need the following active directory (ad) permissions on the ou(s) where user accounts that you wish to use activate self service password reset reside active directory permissions required grant to activate orchestrator service account grant on ou and descendant user objects rights change password reset password read all user object properties write lockouttime write pwdlastset write useraccountcontrol write extensionattribute1 attribute, custom attribute 1 in the aduc console see note below modify permissions if possible, test the permissions by log on as the orchestrator service account reset the password on a test user in the target ou(s) to grant these permissions it is recommended to create an ad group in an ou that only the activate orchestrator service account can write to with a description like grant access to reset user passwords see kb docid\ r vqjz9ujecmdudgjh8gs for the rights required on the ou assign the rights listed above to the ad group create an activate service that adds users to the ad group grant access to reset user password ensure that a team with appropriate training to understand the access being requested are approvers for the activate service order the service for the orchestrator service account notes extensionattribute1 (custom attribute 1) is the default ad attribute used by activate to store activate specific information in the user object another unused attribute can be used instead (see docid 0ehxmzrahezkxblqbxrlv , and if it is, set the permission described above on that attribute the delegation of control wizard in ad users and computers makes it easier to set these permissions