Just my input on this (those who uses the user-level security wizard).
U can allow user to change the password in Access 2000 by letting user have administration right in database only using tools->security->user and group permission. They will be able to change their own password but still retain their settings e.g. read-only users still cannot delete or modify changes to the database.