Back to BlogIT Helpdesk

How to Reset Active Directory Password: A Step-by-Step IT Helpdesk Guide

18 August 2026 6 min read
Photo by Samuel Bourke on Unsplash

Active Directory password resets are one of the most common tasks you'll handle as an IT helpdesk professional. Whether you're brand new to the role or transitioning into tech from a different career, understanding how to reset passwords safely and efficiently is essential. In this guide, I'll walk you through the process, cover security best practices, and share troubleshooting tips that'll make you confident handling these requests.

Why Active Directory Password Resets Matter

If you're moving into IT helpdesk from healthcare, education, or another field, you'll quickly discover that password resets account for roughly 30 to 40 per cent of first-line support tickets. Users forget passwords, they expire, or they get locked out. It's a fundamental part of the job.

Active Directory (AD) is Microsoft's directory service that manages user accounts, permissions, and security policies across networked organisations. When you reset a password in Active Directory, that change synchronises across the entire network, so it's critical to do it correctly.

According to 2026 data from IT industry benchmarks, organisations with strong helpdesk support reduce password-related downtime by up to 45 per cent, which means fewer frustrated users and higher productivity overall.

Prerequisites: What You'll Need

Before you start resetting passwords, make sure you have the following in place:

  • Active Directory Users and Computers (ADUC) installed on your workstation or accessible via a domain-joined machine
  • Appropriate admin credentials or delegated permissions to reset passwords
  • Clear identification of the user requesting the reset (never reset a password without verifying who you're talking to)
  • Your organisation's password policy documentation
  • Access to your ticketing system to log the action
  • If you don't have ADUC installed yet, your IT manager can help you set it up. It's a standard part of Windows domain administration tools.

    Step-by-Step: How to Reset an Active Directory Password

    Step 1: Verify the User's Identity

    This is non-negotiable. Before touching anything, confirm you're speaking with the right person.

  • Ask for their employee ID or full name and department
  • Verify their phone number against your internal directory
  • If it's a password reset request via email or ticket, call them back to confirm
  • Document the interaction in your ticketing system
  • This single step prevents unauthorised access and protects both the user and your organisation.

    Step 2: Open Active Directory Users and Computers

    On a domain-joined Windows machine with admin rights:

  • Press Windows Key + R to open the Run dialog
  • Type `dsa.msc` and press Enter
  • Active Directory Users and Computers will open
  • Navigate to the Organizational Unit (OU) where the user account is stored (often something like "Sales Users" or "Finance Users")
  • Step 3: Locate the User Account

    Once you're in the correct OU:

  • Scroll through the list or use Ctrl + F to search by username
  • Right-click the user account
  • Select "Reset Password" from the context menu
  • Some organisations use different naming conventions (john.smith, jsmith, or john_smith), so be precise with your search.

    Step 4: Set the New Password

    A dialog box will appear. Here's where you need to follow your organisation's password policy carefully.

    Most organisations require passwords to include:

  • At least 12 characters (some require 14 or 16)
  • Uppercase and lowercase letters
  • Numbers and special characters
  • No dictionary words or usernames
  • Key options in the reset dialog:

  • Generate a temporary password or set one manually (temporary is usually safer)
  • Tick "User must change password at next logon" (best practice for security)
  • Leave "Unlock the account" unchecked unless the account is currently locked
  • Once you've entered the password, click OK.

    Step 5: Communicate the New Password Securely

    Never email passwords in plain text. Instead:

  • Read the temporary password to the user over the phone
  • Use your organisation's secure password delivery system if you have one
  • Ask them to change it immediately upon first logon
  • Document that you've provided the password and confirmed receipt
  • Common Issues and Troubleshooting

    "Access Denied" Error

    If you're getting permission errors, you likely don't have the right privileges. Ask your IT manager to delegate password reset rights to your account or grant you membership in the "Account Operators" group (though this grants broader permissions, so check your security policy first).

    Account is Locked

    If the account shows as locked, you'll see an option to "Unlock the account" in the same dialog. Tick this box during the password reset. Locked accounts typically unlock automatically after 30 minutes, but resetting the password usually clears the lock faster.

    Password Won't Meet Complexity Requirements

    If your temporary password is rejected, you're likely not meeting your organisation's password policy. Check Group Policy settings in "Group Policy Management" by searching for "Password must meet complexity requirements." Increase the length and add more special characters if needed.

    Changes Not Syncing

    In larger organisations with multiple domain controllers, password changes can take a few minutes to synchronise. If a user says the new password isn't working immediately after reset, ask them to wait five minutes and try again, or try logging in on a different computer.

    Security Best Practices

  • **Never reuse passwords.** Each reset should be unique.
  • **Log every reset.** Your ticketing system should have a record of who requested it, when, and by whom.
  • **Use temporary passwords.** Force users to change their password on first logon.
  • **Never store passwords.** Don't write them down or keep them in plain text files.
  • **Enforce MFA.** If your organisation uses multi-factor authentication, remind users that password resets don't affect their MFA settings.
  • **Ask about suspicious requests.** If someone requests a password reset for an account they shouldn't need access to, escalate it to your manager.
  • Why This Skill Matters for Your IT Career

    Password management is foundational IT helpdesk knowledge. As you progress from helpdesk to systems administration or cloud infrastructure roles (like Microsoft 365 Administrator or Azure Administrator positions), understanding directory services becomes even more critical. In fact, Azure and cloud-based identity management build directly on Active Directory concepts.

    According to 2026 salary data, IT helpdesk professionals in the UK earn between £18,000 and £24,000 annually, but those who develop expertise in Active Directory and systems administration can progress to junior sysadmin roles paying £25,000 to £32,000 within two to three years.

    Ready to Build Your IT Helpdesk Career?

    If you're making the leap from healthcare, education, or another field into IT, password resets are just one of many practical skills you'll need. Our IT Career Programme covers Active Directory, Windows troubleshooting, networking, and CompTIA A+ exam prep in just three months (weekends only, 26 sessions). It's designed for career changers with no prior IT experience.

    [Explore the IT Career Programme](/courses/it-helpdesk) and start your path to a rewarding IT career today.

    Ready to start your IT career?

    SmoothOps 365 runs live instructor-led training every Saturday and Sunday. 3 months. 52 contact hours. Keep your job while you train.