domain users are unable to change the password in sophos encryption profile
What do you mean sorry?
Is AD the primary directory? What happens when they try to change their password?