Normally administrator should have the original of the ID file, which has the password that set by admin, user got a copy and change password on the copy, but you see, the original ID still not changed,so admin can do whatever when something happened.
If the admin doesn't have the ID, oh he/she is in trouble.