Is there a way to prevent users from changing their passwords?

Imagine you roll out a central web based password system that utilizes the new 8.5 Resetuserpassword function:

Is there a way to prevent users from changing their passwords?

I know this sounds a bit odd for a pure Notes/Domino shop, but almost all other IT systems dealing with users like Windows AD, Linux, Solaris and alike have this ability:

Prevent users from setting the password on their own.

Can this be done in the Notes client too?

notes.ini setting?

policy

All ideas/suggestions/complaints are welcome.

Thanks,

Uwe