How to set Active Directory to force password change on first logon

Is it possible to configure IDM to reliably force all new users to change password on first loggon when they logging into AD?


A password change request for existing users (reset user password in IDM) propagates correctly to AD endpoint, but password change request when creating user (checked box Password Must Change) works just for users who log into IDM.