Hi Jeff -
You might check with Cisco TAC to see if other 3rd party AD tools are supported to run on the Unity server in your configuration. You could use LDIFDE.exe (LDAP Data Interchange Format Directory Synchronization Tool) to export your admin accounts to an external file and then modify the password information. Here is a link that might be of assistance - you can use ADSIEdit on the Unity server to obtain the account password attribute name. http://www.serverwatch.com/tutorials/article.php/1470981
I believe once you get both forests to Windows 2003, you will be able to create a forest-to-forest trust that would then enable your admins to run ADUC snapin from their own PCs.
Regards, Ginger