Well, that is bad all over. And also can be seen as an evidence towards “if someone requires access that does not look suspicious, give it to them”: he wasn’t given access, so he went another way and fucked up spectacularly. On the other hand, though:
if it is a company machine, then not having admin access can be expected
I would expect that “do not ever use personal accounts for work and vice versa” does not need reminding, but here we are
yeah, the rules should account for malicious behaviour, intended and not
Well, that is bad all over. And also can be seen as an evidence towards “if someone requires access that does not look suspicious, give it to them”: he wasn’t given access, so he went another way and fucked up spectacularly. On the other hand, though: