Diarrhea from PR mouths is of course of no value here, so let’s skip Microsoft’s explanation. What could be the line of thinking behind this decision, though? I have three guesses.
One is that user-initiated password changes, with no administrators’ intervention, are mostly password change policies. From this perspective the password change is without any value, meaning there is no technical reason to make any changes. Just give people their illusion of control. An actual security breach would be handled by admins, who clear the local credentials cache.
Another is, that caches are caches for a reason. They are used to not poll upstream constantly. The removal of caches means additional, and in most cases pointless, load. It also means any network issue or misconfiguration cuts off everybody from the RDP. Timeouts may be implemented, but any reasonable timeout is almost useless with threat models observed in 2020s. I’m not saying I would vote for not changing that, because I probably would. But I can see it’s not a clear situation and I can understand reasoning behind taking a different option.
Finally, this may be an organisational issue. Changing the protocols may involve two independent developer teams. You know, how many levels each message would need to go up and down
the chain of command, how many meetings would need to be held?

I must also note, that nobody asked for customers’ opinions. I may value security, Wade may be security-focused, and so may you. But most people don’t share our beliefs, our values, and our mindsets. We see fixing a potential vulnerability. Customer ACME Inc. management sees a worker not being able to log in, causing $1M losses to the company.