This was discussed in ENG-8070
Only the primary device should be able to change the password.
Perhaps there was some alternative to keep this for a while and disable this after the user migrated to Signed Device Lists (v2), but this is not easy and probably there is no need to complicate just to keep it for a ~month and then remove.
Hook with check was introduced in D14058