Sorry for the misunderstanding.
Back in the day when Apple had a product called OS X Server and it was what most of us would have said was a ‘proper’ server, it only ever had read only access to AD.
Over the last 5-6 years Apple have dumbed it down to what you see now. Strangely they’re still calling it a ‘server’ but we all know it isn’t really. At best it’s a management tool or MDM. Sadly and unfortunately not a very good one at that. With that in mind and unless anyone else knows any different, I doubt if its historic read-only ability has changed. If you’re being prompted to change an AD users password on login then I can’t see how that change can be made/written to a non-LDAP based schema such as AD.
Of course it will always work with a locally created user because that’s how Apple designed it.
What’s wrong with using Safari on a client Mac or IE on a PC to access PM’s web portal with diradmin’s credentials instead? Simpler and with less hassle. Especially true if you’re trying to approach this in a ‘Windows’ way. No need to log into anything, server or otherwise. Again this too, AFAIK, is by design.