diff --git a/ldap_authentication/LdapAuthenticationConf.class.php b/ldap_authentication/LdapAuthenticationConf.class.php
index b9b7770..27d533e 100644
--- a/ldap_authentication/LdapAuthenticationConf.class.php
+++ b/ldap_authentication/LdapAuthenticationConf.class.php
@@ -107,6 +107,16 @@ class LdapAuthenticationConf {
    * @var int
    */
   public $emailUpdate = LDAP_AUTHENTICATION_EMAIL_UPDATE_ON_LDAP_CHANGE_DEFAULT;
+  
+   /**
+   * Password handling option
+   *   LDAP_AUTHENTICATION_PASSWORD_FIELD_SHOW -- show field disabled on user forms
+   *   LDAP_AUTHENTICATION_PASSWORD_FIELD_HIDE (default) -- disable password on user forms
+   *   LDAP_AUTHENTICATION_PASSWORD_FIELD_ALLOW -- allow editing of password on user forms
+   *
+   * @var int
+   */
+  public $passwordOption = LDAP_AUTHENTICATION_PASSWORD_FIELD_DEFAULT;
 
   public $ssoEnabled = FALSE;
   public $ssoRemoteUserStripDomainName = FALSE;
@@ -168,6 +178,7 @@ class LdapAuthenticationConf {
     'ldapUserHelpLinkText',
     'emailOption',
     'emailUpdate',
+    'passwordOption',
     'allowOnlyIfTextInDn',
     'excludeIfTextInDn',
     'allowTestPhp',
diff --git a/ldap_authentication/LdapAuthenticationConfAdmin.class.php b/ldap_authentication/LdapAuthenticationConfAdmin.class.php
index 5ebebec..d58bdd1 100644
--- a/ldap_authentication/LdapAuthenticationConfAdmin.class.php
+++ b/ldap_authentication/LdapAuthenticationConfAdmin.class.php
@@ -79,10 +79,19 @@ class LdapAuthenticationConfAdmin extends LdapAuthenticationConf {
       LDAP_AUTHENTICATION_EMAIL_UPDATE_ON_LDAP_CHANGE_ENABLE => t('Update stored email if LDAP email differs at login but don\'t notify user.'),
       LDAP_AUTHENTICATION_EMAIL_UPDATE_ON_LDAP_CHANGE_DISABLE => t('Don\'t update stored email if LDAP email differs at login.'),
       );
+    
+    /**
+    * 5. Password
+    */
 
+    $values['passwordUpdateOptions'] = array(
+      LDAP_AUTHENTICATION_PASSWORD_FIELD_SHOW => t('Display password field disabled (Prevents password updates).'),
+      LDAP_AUTHENTICATION_PASSWORD_FIELD_HIDE => t('Don\'t show password field on user forms except login form.'),
+      LDAP_AUTHENTICATION_PASSWORD_FIELD_ALLOW => t('Display password field and allow updating it. In order to change password in LDAP, LDAP provisioning for this field must be enabled.'),
+      );
 
     /**
-     * 5. Single Sign-On / Seamless Sign-On
+     * 6. Single Sign-On / Seamless Sign-On
      */
 
       $values['ldapImplementationOptions'] = array(
@@ -162,7 +171,7 @@ class LdapAuthenticationConfAdmin extends LdapAuthenticationConf {
   protected $allowTestPhpDescription;
 
    /**
-   * 4. Email
+   * 3. Email
    */
 
   public $emailOptionDefault = LDAP_AUTHENTICATION_EMAIL_FIELD_REMOVE;
@@ -170,6 +179,13 @@ class LdapAuthenticationConfAdmin extends LdapAuthenticationConf {
 
   public $emailUpdateDefault = LDAP_AUTHENTICATION_EMAIL_UPDATE_ON_LDAP_CHANGE_ENABLE_NOTIFY;
   public $emailUpdateOptions;
+  
+  /**
+   * 4. Password
+   */
+
+  public $passwordOptionDefault = LDAP_AUTHENTICATION_PASSWORD_FIELD_DEFAULT;
+  public $passwordUpdateOptions;
 
 
    /**
@@ -379,6 +395,20 @@ class LdapAuthenticationConfAdmin extends LdapAuthenticationConf {
       '#default_value' => $this->emailUpdate,
       '#options' => $this->emailUpdateOptions,
       );
+    
+    $form['password'] = array(
+      '#type' => 'fieldset',
+      '#title' => t('Password'),
+      '#collapsible' => TRUE,
+      '#collapsed' => FALSE,
+    );
+    $form['password']['passwordOption'] = array(
+      '#type' => 'radios',
+      '#title' => t('Password Behavior'),
+      '#required' => 1,
+      '#default_value' => $this->passwordOption,
+      '#options' => $this->passwordUpdateOptions,
+    );
 
 
     /**
@@ -504,7 +534,6 @@ class LdapAuthenticationConfAdmin extends LdapAuthenticationConf {
   }
 
   protected function populateFromDrupalForm($values) {
-
     $this->authenticationMode = ($values['authenticationMode']) ? (int)$values['authenticationMode'] : NULL;
     $this->sids = $values['authenticationServers'];
     $this->allowOnlyIfTextInDn = $this->linesToArray($values['allowOnlyIfTextInDn']);
@@ -517,6 +546,7 @@ class LdapAuthenticationConfAdmin extends LdapAuthenticationConf {
     $this->excludeIfNoAuthorizations = ($values['excludeIfNoAuthorizations']) ? (int)$values['excludeIfNoAuthorizations'] : NULL;
     $this->emailOption  = ($values['emailOption']) ? (int)$values['emailOption'] : NULL;
     $this->emailUpdate  = ($values['emailUpdate']) ? (int)$values['emailUpdate'] : NULL;
+    $this->passwordOption  = ($values['passwordOption']) ? (int)$values['passwordOption'] : NULL;
     $this->ssoExcludedPaths = $this->linesToArray($values['ssoExcludedPaths']);
     $this->ssoExcludedHosts = $this->linesToArray($values['ssoExcludedHosts']);
     $this->ssoRemoteUserStripDomainName = ($values['ssoRemoteUserStripDomainName']) ? (int)$values['ssoRemoteUserStripDomainName'] : NULL;
diff --git a/ldap_authentication/ldap_authentication.module b/ldap_authentication/ldap_authentication.module
index 3f92e6e..98ed7c6 100644
--- a/ldap_authentication/ldap_authentication.module
+++ b/ldap_authentication/ldap_authentication.module
@@ -29,6 +29,11 @@ define('LDAP_AUTHENTICATION_EMAIL_FIELD_DISABLE',      3);
 define('LDAP_AUTHENTICATION_EMAIL_FIELD_ALLOW',        4);
 define('LDAP_AUTHENTICATION_EMAIL_FIELD_DEFAULT',      3);
 
+define('LDAP_AUTHENTICATION_PASSWORD_FIELD_SHOW',       2);
+define('LDAP_AUTHENTICATION_PASSWORD_FIELD_HIDE',      3);
+define('LDAP_AUTHENTICATION_PASSWORD_FIELD_ALLOW',        4);
+define('LDAP_AUTHENTICATION_PASSWORD_FIELD_DEFAULT',      2);
+
 define('LDAP_AUTHENTICATION_RESULT_FAIL_CONNECT',      1);
 define('LDAP_AUTHENTICATION_RESULT_FAIL_BIND',         2);
 define('LDAP_AUTHENTICATION_RESULT_FAIL_FIND',         3);
@@ -246,12 +251,25 @@ function ldap_authentication_show_reset_pwd($user = NULL) {
   }
 
   if ($user->uid == 0) {
-    // hide reset password for anonymous users if ldap only authentication, otherwise show
-    return ($auth_conf->authenticationMode != LDAP_AUTHENTICATION_EXCLUSIVE);
+    // hide reset password for anonymous users if ldap only authentication and password updates are disabled, otherwise show
+    if ($auth_conf->authenticationMode != LDAP_AUTHENTICATION_EXCLUSIVE) {
+      if ($auth_conf->passwordOption == LDAP_AUTHENTICATION_PASSWORD_FIELD_ALLOW) {
+        return TRUE;
+      }
+      return FALSE;
+    }
+    return TRUE;
   }
   else {
-    // authenticated user.  hide if ldap authenticated otherwise show.
-    return (!ldap_authentication_ldap_authenticated($user));
+    // authenticated user.  hide if ldap authenticated and updating password is 
+    // not allowed, otherwise show.
+    if (ldap_authentication_ldap_authenticated($user)) {
+      if ($auth_conf->passwordOption == LDAP_AUTHENTICATION_PASSWORD_FIELD_ALLOW) {
+        return TRUE;
+      }
+      return FALSE;
+    }
+    return TRUE;
   }
 
 }
@@ -304,7 +322,15 @@ function ldap_authentication_user_pass_validate(&$form_state) {
       'account' => $account,
       'auth_conf' => ldap_authentication_get_valid_conf(),
     );
-    form_set_error('name', theme('ldap_authentication_user_pass_validate_ldap_authenticated', $vars));
+    $error = TRUE;
+    if (is_object($vars['auth_conf'])) {
+      if ($vars['auth_conf']->passwordOption == LDAP_AUTHENTICATION_PASSWORD_FIELD_ALLOW) {
+        $error = FALSE;
+      }
+    }
+    if (!empty($error)) {
+      form_set_error('name', theme('ldap_authentication_user_pass_validate_ldap_authenticated', $vars));
+    }
   }
 }
 
diff --git a/ldap_authentication/ldap_authentication.theme.inc b/ldap_authentication/ldap_authentication.theme.inc
index 500133e..15bd646 100644
--- a/ldap_authentication/ldap_authentication.theme.inc
+++ b/ldap_authentication/ldap_authentication.theme.inc
@@ -44,7 +44,7 @@ function theme_ldap_authentication_user_login_block_links($variables) {
  */
 function theme_ldap_authentication_user_pass_message($variables) {
   extract($variables);
-  if ($auth_conf->authenticationMode == LDAP_AUTHENTICATION_EXCLUSIVE) {
+  if ($auth_conf->authenticationMode == LDAP_AUTHENTICATION_EXCLUSIVE && $auth_conf->passwordOption != LDAP_AUTHENTICATION_PASSWORD_FIELD_ALLOW) {
     $msg = t('This page is only useful for the site administrator.  All other users
       need to reset their passwords');
     if ($auth_conf->ldapUserHelpLinkUrl) {
diff --git a/ldap_servers/ldap_servers.tokens.inc b/ldap_servers/ldap_servers.tokens.inc
index 19439a4..111a6a8 100644
--- a/ldap_servers/ldap_servers.tokens.inc
+++ b/ldap_servers/ldap_servers.tokens.inc
@@ -390,8 +390,11 @@ function ldap_servers_token_tokenize_user_account($user_account, $token_keys = '
 
         if ($user_entered_password_available && $attr_name == 'user-random') {
           $value = ldap_user_ldap_provision_pwd('get');
+          if (empty($value)) {
+            $skip = TRUE;
+          }
         }
-        elseif ($attr_name == 'random' || $attr_name == 'user-random') {
+        elseif ($attr_name == 'random') {
           $value = user_password();
         }
         else {
diff --git a/ldap_user/ldap_user.module b/ldap_user/ldap_user.module
index 0396358..708883b 100644
--- a/ldap_user/ldap_user.module
+++ b/ldap_user/ldap_user.module
@@ -479,11 +479,17 @@ function ldap_user_form_password_policy_password_tab_alter(&$form, &$form_state)
  * for use in provisioing to ldap
  */
 function ldap_user_grab_password_validate($form, &$form_state) {
-
+  // This is not a login form but profile form and user is insertingpassword to update email
+  //watchdog('ldap_user', 'ldap_user_grab_password_validate');
+  
+  if (!empty($form_state['values']['current_pass_required_values'])) {
+    if (!empty($form_state['values']['current_pass']) && empty($form_state['values']['pass'])) {
+      ldap_user_ldap_provision_pwd('set', $form_state['values']['current_pass']);
+    }
+  }
   if (!empty($form_state['values']['pass'])) {
     ldap_user_ldap_provision_pwd('set', $form_state['values']['pass']);
   }
-
 }
 
 
@@ -886,6 +892,14 @@ function ldap_user_user_update(&$user_edit, $account, $category) {
   if ($category == 'ldap_user' || (is_object($account) && property_exists($account, 'uid') && $account->uid == 1)) {
     return; // do not provision or synch user 1
   }
+
+  // Remove password so it doesn't get double hashed
+  if (isset($user_edit['pass'])) {
+    if ($user_edit['pass'] == $account->pass) {
+      unset($user_edit['pass']);
+    }
+  }
+
   $ldap_user_conf = ldap_user_conf();
   // check for provisioning to LDAP; this will normally occur on hook_user_insert or other event when drupal user is created.
   if ($ldap_user_conf->provisionsLdapEntriesFromDrupalUsers &&
@@ -1150,4 +1164,4 @@ function ldap_user_token_tokenize_entry($account, $token_keys, $pre = LDAP_SERVE
 
     return array($account, $user_entity);
 
-  }
\ No newline at end of file
+  }
