Scenario:
Person A's normal computer account is personA. They have locked this out with too many bad password attempts. The user is part of the IT group, so they also have an admin account: personA-admin.
They use this admin account to unlock their standard account. On the windows event log, it shows as personA-admin unlocked personA
Question: Is this ok?
I say no because someone else should be unlocking it. I'm thinking along the lines of separation of duties, privilege escalation maybe etc. My colleague says yes because they're not gaining any additional privilege over what they have right now...