Inside Activate
...
How To Guides
How to prevent a set of users from using Activate Password Reset
3 min
some customers may have sensitive ad accounts that they do not wish their passwords to be reset via activate these type of accounts may include privileged accounts such as service accounts or external accounts options 1\ turn on 'user cannot change password' for these users in active directory users and computers this option should be enabled for sensitive accounts to prevent the user changing their own password this disables any change functionality via normal windows and ad mechanisms and well as activate self service password reset 2\ disable activate self service password reset using an activate role it is also possible to disable password reset functionality for these accounts by following the steps below steps open the activate administrator application navigate to roles system roles create a new role under named disable password reset either add a new parameter named members and set this group reference to a group in ad or add members to the new role directly by selecting the new role right mouse button show members click the + button to add users to the new role if a user is added to the “disable password reset” role the following applies the user cannot use the activate credential provider to reset their password or unlock their account the user cannot register for password reset the user cannot reset their password via the activate web portal internally or through activate anywhere the activate service desk role is still able to reset passwords for users in the disable password reset role via the activate admin reset task