If you apply security by design, it is logical to enforce that when creating a new user, the password must be immediately replaced.