Hi there,
The user password is tied to the user's ID file. When logging on, the user inputs his password and the server he is logging into authenticates it. Once that state is passed, the user will be able to freely access all servers that allow him access.
The question is, how was the password reset ? I'm guessing that you reset it on a local copy of the ID and did not send him that ID.
Side question : what version of Domino is the server running ?
I've got nothing to hide, and I demand that you justify what right you have to ask.