    Does anyone know how to do this, or if it is even possible?

    I want to be able to log into a user's domain account on a client, to the user's profile to set up Outlook, and other application settings. Without using the user's password (which I don't know). I don't want to change the user's password to do that. It doesn't have to have admin permissions. I'm running Windows Server 2012 R2 Essentials for AD.



    No, that is not possible. You cannot log into a user account with another user account. You need to log on as the user. Additionally, a user profile is specific to the user. In order to configure Outlook in the user profile you have to log on as the user.


      A few years ago, I thought I heard that a new win server version had the capability of having an administrator log into the the user's profile for just the purposes that I want.

      I guess I mis-heard. I suppose the best way is for me to change the user's password, log in, do what I need to do, and then give new password to the user. Setting it to require the user to change it.

      I have been not allowing users to change passwords, and I kept a secure list of user's passwords so I can support them. Not good security. I'd like to not do that.




        We did that at the school district where I worked for ~5000 users and it got to be a pain. So, we instituted a solution that gave the users the ability to change their own passwords without them having direct contact to their domain accounts.

        We used the Self Service Reset Password Management (SSRPM) system from Tools4Ever, and it worked out well. Users register for the service, set up their own security questions (according to a pre-determined format) and can change their password without bothering IT. That way you can change their password, do what you need to do and they can change their own password.