Yeah... the thought is:

The built-in method also changes the password and when the user attempts to hit a resource which he/she has not already opened with his/her current Token would be denied access.

Does not matter if it happens via GUI or SCRIPT or COMMAND-LINE