Another option, in case your policy in Segura® matches with AD GPO, is to check if you are not using a secure connection (SSL/TLS).
Active Directory strictly forbids changing or resetting passwords over unencrypted plaintext connections. Take a look at your Domain Controller in Devices page by editing and adding LDAPS (port 636) to it under Connectivity tab.