In order to reset passwords, the functional account needs to be a member of the local "Administrators" group on the system. The user can be a local user on the system, or a AD domain user.
If using a local user, the UAC (User Account Control) restrictions will need be changed refer to
KB82461 for more information.