Greetings,
I have done it many times and several years ago i came up with a policy
if someone changes their name. I make a new account and that User will have Two Accounts temporarily. This gives the user a chance to make changes and notify people and that they dont loose access to anything. Then we remove the old account.
The thing is,.. The lastname does not mean much but it is tied to AppleGenerated ID and all the information in that record. It is used to create the default account credentials. So the name becomes extremely unique to that user and all the permissions and variables Set.
If you really want to change the name. Open Directory editor under Directory utility and expand the menu to see all Attributes.
Replace the text string with the new name.
if the login name & aka RecordName email username is not being effected just changing the LastName Attribute wont really effect much.
i work with about 10,000 users. my process creates new user, run 90 days Nuke old account. Gives you 90 days to migrate.
and when that person gets divorced and they go back to the old name the system doesn't freak out. because each account is treated as different.
f00d for thought