I know the AD driver has a read-only pseudo attribute called
dirxml-uACPasswordCantChange that allows reading of this value from AD.
But I have a need to set it on new user creates.

Is there a way to do this? What about with the Powershell functionality
in the AD driver? It looks to be Exchange specific, and I don't have
Exchange in this case. There is a way to do this in Powershell:

set-aduser -CannotChangePassword $True

Would this be possible with the limited PS support in the AD driver or
would I need the scripting driver to do it? Anyone got an example?



