Would it be possible to have the password record appear in both locations, MDM and Active Directory? Why such and odd request? Our Active Directory will purge objects after a certain amount of inactivity and these passwords are no longer available, so having a secondary accessible location would be useful. While it is stored in a keychain, this can be difficult at best to access if the user's password is locked out.