Since Bug #39181, the SAML login shows an info about the expired password: "Password change required. An LDAP password change is required before login is possible" The message is shown to end users and I think it is not clear for them what to do. We should either add a password change dialog or add a link to the password self service.
*** This bug has been marked as a duplicate of bug 49336 ***