Ms. Latha Rao
Super Administrator · latha.rao@preskool.edu
Security posture
Two-factor and a strong password carry most of this. Verifying the recovery email and clearing one stale device would take it past 90.
Signed in from Chennai on Chrome. This session expires after 30 minutes idle.
Profile
Who this account belongs to, and what protects it.
Profile
How this account appears to everyone else
What protects this account
Four layers, three of them armed
The last one matters more than it looks. If the school domain ever becomes unreachable, a recovery address on it is unreachable too.
Ordered by how much risk each one removes, not by how quickly it can be done.
Verify the recovery email
The address on file is latha.rao@preskool.edu, which sits on the same domain as the account it recovers. Add a personal address so a domain outage does not lock you out.
Remove an unused device
A Samsung tablet last seen 94 days ago is still trusted, which means it can skip two-factor. If it has been retired, remove it.
Review active sessions
Four sessions across three devices. One on Safari has been idle for nine days and can safely be ended.
Rotate the personal API key
The key issued for the reporting integration is 214 days old. School policy asks for 180.
Update the password
Changed 112 days ago and still inside policy. It expires in 68 days and will prompt automatically.
Enable two-factor authentication
Armed on 22 Feb 2026 with an authenticator app. Required at every sign-in, including on trusted devices.
Update security questions
Retired in March. Questions were replaced by recovery codes, which cannot be researched from a public profile.
Account Information
What the school holds on record.
Identity
What the school holds on record
Contact
Where the school reaches this account
Role & placement
What this account is entitled to do
Account status
Whether this account may be used at all
Authentication
Every way this account can prove who it is.
Every way this account can prove who it is. A factor that is armed is required at sign-in; one that is not is simply available.
Password
ArmedA 16-character passphrase, changed 112 days ago and inside every policy rule.
Authenticator app
ArmedGoogle Authenticator on the primary phone. A six-digit code at every sign-in.
Email verification
ArmedA one-time link when signing in from a device that has never been seen before.
SMS verification
Not in useOff by design. A code sent by text can be intercepted by swapping the SIM, so it is kept as a fallback only.
Biometric sign-in
ArmedWindows Hello on the office desktop. The fingerprint never leaves that machine.
Passkey
Not in useAvailable but unused. A passkey cannot be phished, because it will not present itself to the wrong site.
Single sign-on
Not in useThe school has not federated with an identity provider. Accounts are held here.
Recovery codes
ArmedTen codes issued on 22 Feb, of which two have been spent. Held on paper in the safe.
Password Policy
The one factor everybody has, and the rules it must satisfy.
Current password
Changed 11 April 2026
A prompt appears automatically seven days before expiry. There is no benefit to changing it early unless you believe it is known to someone else.
Password policy
Applies to every administrator account
Two-Factor Authentication
The second factor, and the way back in without it.
Authenticator app
The second factor in use
Other second factors
Available, and why they are or are not used
Recovery codes
Ten codes issued 22 Feb 2026 · two spent
Each code works once. They are the only way back in if the authenticator app is lost, so they belong on paper somewhere the account holder can reach and nobody else can.
Generating a new set immediately invalidates all ten of these, including the eight that are unused.
Recovery Options
How you get back in when the usual route is gone.
Recovery email
Where a reset link would be sent
Recovery phone
Where a reset code would be texted
Security questions are no longer used
They were retired across the school in March 2026. The answers to most of them — a mother’s maiden name, a first school, a pet — can be found on a public profile, which makes them a weaker factor than the password they protect. Recovery codes replaced them.
Login Sessions
Where this account is signed in right now.
Four sessions, one of which is the browser you are reading this in. Ending a session signs that device out immediately; it does not remove its trust.
Windows 11 · Chrome 127This device
Android 15 · Chrome Mobile
macOS 15 · Safari 18Idle 9 days
Reporting integration · API keyMachine
Trusted Devices
Machines this account recognises.
A trusted device is one this account has signed in from before and recognises. Because two-factor is required every time, trust here shortens nothing except the new-device email.
Office desktop · Dell OptiPlexThis device
Primary phone · Pixel 9Authenticator
Home laptop · MacBook Air
Samsung Galaxy Tab S9Not seen in 94 days
Login History
Every attempt, successful or not.
The last 8 of 214 sign-in attempts. The five refusals on 18 July came from one address in a four-minute window and stopped when the account locked; nothing was reached.
Privacy
What others can see, and where information travels.
Privacy controls
What others can see about this account
Data sharing
Where information about this account travels
No third-party application has access to this account
Nothing outside the school ERP can read or act on your behalf. If you ever authorise an external tool, it will appear here with the exact scopes it was granted and a button to withdraw them.
Notifications
What this account is told about itself.
Security notices are deliberately hard to switch off. The four that matter most go to both the account address and the recovery address, so no change can be made quietly.
Permissions
What this role is entitled to do.
Role permissions
Super Administrator · inherited from the role, not set here
API access
Keys that act as this account
Security Logs
The record that cannot be edited.
Every security-relevant event on this account, kept for three academic years. Entries here cannot be edited or removed by anyone, including a Super Administrator.
Advanced
Sessions, sign-in protection, keys and account actions.
Deactivating suspends sign-in and ends every session, but keeps every record this account created. Deleting is handled by HR through the leaver process and is not available here.
Audit History
Every change, with the name against it.
Audit history
Every change to this account, retained for 3 academic years
Security activity
The moments that shaped how protected this account is today.
Account created
Opened by Mr. R. Venkatesh as an Administrator. Raised to Super Administrator in August 2022.
Password changed
A 16-character passphrase, checked against public breach lists. Every other session ended at the same moment.
Two-factor enabled
Authenticator app enrolled and ten recovery codes issued. Required at every sign-in since.
New device signed in
Safari on macOS from Coimbatore. Verified by email before it was allowed to do anything.
Permission updated
Backup and restore moved behind a second approver, following the term-end policy review.
Security scan completed
Posture scored 78 of 100. Two recommendations raised, neither of them urgent. No issues found.



