Unless options are set on the mailbox for "Cannot change password" then Dans is correct. User logs in, presses 7 for set-up, then 7 for password.

When viewing the mailbox as an Administrator in CoSessions, there will be a prompt near the bottom telling you how to check which options are set on the mailbox.