PwdMustChange specifies with a value of "TRUE" that the entry MUST change their passwords when they first bind to the directory after a Password Reset.

If this attribute is not present, or if the value is "FALSE", users are not required to change their password upon binding after the password administrator sets or resets the password.

PwdMustChange attribute is not set due to any actions specified by draft-behera-ldap-password-policy, it is typically set by a password administrator after resetting a user's password.

PwdMustChange is an implementation of Password MUST Change condition.

The PwdMustChange AttributeTypes is defined as:

