no, CUCM synchronizes it's own user database with AD LDAP. this is neccessary because CUCM needs additional user information which is not stored in LDAP attributes. if the user is valid in AD it is marked as "active".
however, the password is not synchronized, the user authentication is done against LDAP.