This means that if a user's password is changed in the registry, he will still be able to authenticate using the old password until the cache expires (10 minutes by default).
We could make some cross-reference queries to look for domain administrators that have the Password never expires attribute set (a part of the userAccountControl attribute).