I would like to see a way for Administrators to log into a user's account on their desktop to help configure profiles or troubleshoot issues without needing to reset or utilize their password. A sort of admin over-ride for a user account to proxy the user account. It Could be formatted in the username box like this:
This would be helpful for providing assistance. If privacy or audit is a concern Microsoft can have the system generate a pop-up message that the user sees the next time the account is logged into by the actual user not the proxy admin.
There have been a number of times where I have had to do support for a user and don't have their password and end up having to reset it and waste a perfectly good password that can then no longer be used for X amount of passwords because of our regulatory requirements where a simple fix could have been implemented without the need for resetting the password.
Alex, by implementing LAPS you will have a random password for each client (you might already have this). You could then retrieve the password for LAPS, use it for elevating on the users computer and then force the computer to reset the password on next Group Policy update.