to keep it all under control and avoid problems generated by users themselves we have a policy to distribute 2 id's, 1 to the user, 1 filed with an initial password. whenever users loose there password or laptop's get lost etc...
we have the id for the user whenever it's not stored in nab