in order to register with PWM / create QA profile, AD\user must authenticate via AD\DC. Based on the authentication, the user is allowed to create 2nd alternative "narrow" door called "PWM / QA profile, which allows to bypass AD authentication step to execute very narrow pwd-related activities only: pwd reset based on QA, unlock.
The user is an authenticate user in AD, it just that she did use the account for quite some time and it had expired. Now, she have not register with QA profile, so she cannot reset her password, right?