ok, let's say (don't know about ad domain. you should test it) default password is "firstLogon".
then changing password on commandline is like this:
net user username firstLogon /domain

setting the flag for user to change password is little bit trickier.
I made some years ago a program that does that:
www.gwspikval.com/jooel/scripts/
mustikka.exe

the program needs to be run on DC. anyway, you can accomplish this with rcmd (reskit tool).

there probably is also adsi command for this. could grawl around a little bit...
_________________________
!

download KiXnet