Just thought I'd put my two cents in:
Already had OWA configured for change password window, but when password required to be changed at next logon set, users were getting an authentication error.
Based on this thread, I changed the application pool for IISADMPWD from Default to "ExchangeApplicationPool", restarted IIS, and now users receive the change password window with "Your password has expired. You can change it now" message.
THANK YOU!!!!