Of course directory needs to have password write capabilities.
This is useful for eg. if you have a disabled domain only for managing directory passwords.