There is a user account (not a domain admin account) that cannot be changed by normal user admins.
When the user admins try to change the password through ADUC, the box for “user must change password” at next login cannot be checked and if the admin tries to change the password anyway, they get an access denied error.
It isn’t delegated permissions on the OU since other accounts in the same OU do not have this issue.
How can we see what permission is set on the account that is breaking password change access?
The user has forgotten their password and cannot change it them