After changing the password in Active Directory, users are still able to authenticate using their old password. Why is this ?
Active Directory allows both the old password and the new password to be used for one hour, to allow for replication.
The following url helps explain this :
http://support.microsoft.com/kb/906305/en-us