Our actions v2 will be able to help here (but there are not ready for primetime)
So I see two options:
1) You build your own UI that collects that password and verifies the policy 2) You use the new actions to hook into the api request who creates the user and verify the password in a cloud function of yours