Hi Gerhard
I'd be monumentally surprised if the UI was filtering it based on the fact the AD was a different domain - the UI should have no visibility of it. It's much more likely to be the password attribute / policy.
Try doing it with a temporary attribute and a subtask that copies the attribute value into MX_PASSWORD. This should get you some decent errors in the log if nothing else.
Peter