Hello all,

with the upcoming need to simulate an ADS domain (for external user
authentication, Cross-Forest-Trust) we created a new tree and installed
DSfW into it.

The next step would be to merge our existing tree into the new one and
afterwards move the users into the DSfW context (OU).

To test the step of moving and (afterwards) authenticating against the
ADS I created some users outside of the DSfW OU and moved them inside...

Result: The ADS does see them users but they aren't able to log on until
they changed passwords...

Bug? Reported to engineering? Working as designed? Fix?