We currently use Active Roles for AD account management and have our users set up security questions and answers in the account claiming process. Active Roles puts out a nice plugin for Windows machines that allows you to click "Forgot Password" at the login screen and pulls up a browser to access the website of our password manager allowing users to reset their own passwords and log in to the machine. From what I can find, I'm unable to duplicate this on OS X. Any ideas? All of our clients are 10.7 or higher.
Another idea that I had was to deploy a generic password account to all of the machines that would auto launch the website. Unsure of how feasible this is as I don't want it to have a full user home.