New It doesn't even make sense
I can't think of any legitimate reason why one would need the user passwords to shift services providers. (My guess: they're planning on setting up the new AD service with the same passwords as the old one, but that is indeed just not done.)
If that was IT guys original idea, then it is time to find another one. However, if IT guys is also just another contractor, I wouldn't discount strongarming on part of the head of the firm.

And I agree with the others: it is CYA time.
New Should be a 2 factor anyway
Dunno how it is done in AD but in nix you can usually copy the encrypted passwords over and it will usually work
"Science is the belief in the ignorance of the experts" – Richard Feynman
