Some Windows AD user property cannot be changed by AD user himself, what controls it?

Posted by Jimm Chen on Server Fault See other posts from Server Fault or by Jimm Chen
Published on 2013-11-13T02:27:49Z Indexed on 2013/11/13 3:56 UTC
Read the original article Hit count: 427

Filed under:

I'm curious with a question I find. An Windows Active Directory user can change his own telephone number, street address etc, but can NOT change his own email-address registered on the AD.

Using Python+pywin32 I can also verify this behavior. When trying to change own EmailAddress, I got error General access denied error .

enter image description here

I'd like to know where in the AD this allow/deny behavior is defined. Thank you.

© Server Fault or respective owner

Related posts about active-directory