When having a Password Data value set to 0 by a provisioning server, and when authenticating, the Password Data was not updated. Deleting the Password Data attribute solved the issue, and the user can authenticate again. Why the Password Data should never be set to 0?
The Password Data attribute must be a binary value, as the Policy Server encrypts it (1). So if a third party changes the value, the Policy Server will not be able to check the value and therefore will be unable to update it accordingly.