Use the following steps to create an access template to allow a delegated administrator to force user's to change the password at next logon:
- Launch the Active Roles Console
- Navigate to: Configuration | Access Templates
- Right-click on the Access Templates container and select New | Access Template
- Provide a name for the access template such as: Allow - Force password change at next logon
- Click Add, select Only the following classes and check off User, click Next
- Select Object property access, check off Read properties and Write properties, click Next
- Select The following properties and check off Show all possible properties, check off User Must Change Password At Next Logon, click Finish
- Click Next and then Finish
Once the access template is created, it can be assigned to the appropriate scope and users/groups to allow access to the 'Force password change at next logon' checkbox for user accounts