How to allow Password Reset Portal to reset users one time password which is set in AD?

Hi,

We are using verison 8.0 and we are trying to allow user to reset his/her one time password which was set when user was provisioned in AD. We are setting "User must change password" when we are provisioning user in AD and in password reset portal we are using authentication module "Active Directory user account (manual input/role based)" so we are able to reset the user's password who has logged in to the server in AD domain atleast once and forcefully it asked user to reset the password. But now we want to allow user to reset this one time password from Password Reset Portal itself. How can this be achieved? Please suggest. Thank you.