Well hopefully just a minor character escape issue or something along those lines.

Not as secure but your method would allow some delegation that the ADUC GUI would not easily allow delegation of.

Though one could also build a very secure delegation method using MS SQL as well which also provides an excellent audit trail. Not sure but I think it is Howard that does that and even changes the Windows account password for it quite often if not daily. But then you do need to know SQL pretty well also.

More fun to hand roll one if you have the time for sure.

There is also Desktop Authority for those that don't have time or desire to hand roll one. (better have some budget money though) \:D

http://www.scriptlogic.com/