Privileged Account Credentials
Privileged Account Credentials are used for two things with the Password Reset Portal:
- To allow unlocks and resets of user's Active Directory Domain accounts
- To allow Passwordstate to query Event Logs on Domain Controllers for bad login attempts, or account lockouts
When adding a Privileged Account, please ensure it has sufficient permissions to perform the functions above - generally the account being used for resets/unlocks needs to be in the 'Account Operators' group at a minimum, but may require Domain Admin rights depending on the privilege set of the account being unlocked/reset, or if your admins have restricted access to certain accounts. Querying event logs generally requires a Domain Admin account, or the account needs to be in the 'Event Log Readers' built-in Security Group.
If you are also using the Password Reset features built into the core of the Passwordstate product, then you can also link this Privileged Account Credential to an account in an existing Password List to ensure the password for the account is always updated.

If you use any Fine Grain Password Policies in your organization, then you're privileged account credential also needs access to the policy in order to read certain attributes from it. Below is a screenshot of where this can be applied, if permissions do not already exist.
