What? a red flag? why?
Sorry if i'm very surprised with the response.
aspro, of course you can change the password of the users in the domain, even you can change ANY properties from a web page.
All you need for this is a ActiveX control like "Priore NT User Manager Control 1.0", this control allow set some features on the domain, like create new user, SET PASSWORD (not read it), remove a user, etc, and is FREE.
For use it, all you need to know is work with CFObjects and is all.
I don't remember where i found the activex, but you can search on gooogle or any other.
I use NTSet ActiveX, it cost $62 but you can do more functions like set account status, set permisions on specific resources like printers, shared files/directories, view event log, etc. And came with the web-pages for personalize, but in ASP using VBScript. (
Other solution is .NET, but i don't know much about this, yet!
Wullie/csteinhilber: Why you think that is bad, just think about the aplications that can be developed.
In my company, we develop a web-based admin for the domain, to control it from anyware in the intranet. This tool are necesary because when i create a user from the cfm page, the user is not created only in the domain, also will be created in other 3 systems (finnancial, pay-roll and email). Just remember, doing this is
not hacking, 'cause you aren't breaking the system, and you can't view the existent password.