I've played with it a little at an individual ID-file level, but I haven't yet turned it on within a global policy. The process has gotten better (older versions were horrific at it), but it still can be confusing for an end user - the biggest issue I've seen is confusion over the "Generate Password" button; it really should be labeled "Generate my password for me" instead.