LR

Ms. Latha Rao

Super Administrator · latha.rao@preskool.edu

Account active
Security statusGood 2 to fixNothing urgent, two items worth an hour of your time
AuthenticationPassword + authenticator appSingle sign-on is not in use on this account
Two-factorEnabledAuthenticator app, with 8 recovery codes unused
Last loginToday, 08:42 AMChrome on Windows · Chennai, India
Last password change112 days agoExpires in 68 days · 11 Apr 2026
Active sessions4 across 3 devicesOne has been idle for 9 days
78of 100

Security posture

Two-factor and a strong password carry most of this. Verifying the recovery email and clearing one stale device would take it past 90.

Section 01

Profile

Who this account belongs to, and what protects it.

Profile

How this account appears to everyone else

Verified
Display nameMs. Latha Rao
TitleSuper Administrator
Highest role
DepartmentAdministration · Head Office
PhotographInitials shown — no photograph uploaded
Visible toStaff directory and internal correspondence
5 settings

What protects this account

Four layers, three of them armed

1 gap
A password that meets every policy rule
An authenticator app, required at every sign-in
Eight unused recovery codes, printed and held offline
A verified recovery email outside the school domain

The last one matters more than it looks. If the school domain ever becomes unreachable, a recovery address on it is unreachable too.

Reviewed today
Security recommendations

Ordered by how much risk each one removes, not by how quickly it can be done.

1

Verify the recovery email

The address on file is latha.rao@preskool.edu, which sits on the same domain as the account it recovers. Add a personal address so a domain outage does not lock you out.

High priority +7 posture 2 minutes
2

Remove an unused device

A Samsung tablet last seen 94 days ago is still trusted, which means it can skip two-factor. If it has been retired, remove it.

Medium priority +5 posture 1 minute
3

Review active sessions

Four sessions across three devices. One on Safari has been idle for nine days and can safely be ended.

Medium priority +4 posture 1 minute
4

Rotate the personal API key

The key issued for the reporting integration is 214 days old. School policy asks for 180.

Medium priority +3 posture 5 minutes
5

Update the password

Changed 112 days ago and still inside policy. It expires in 68 days and will prompt automatically.

Not due No change Due 11 Oct
6

Enable two-factor authentication

Armed on 22 Feb 2026 with an authenticator app. Required at every sign-in, including on trusted devices.

Complete Already counted
7

Update security questions

Retired in March. Questions were replaced by recovery codes, which cannot be researched from a public profile.

Retired No longer used
Section 02

Account Information

What the school holds on record.

Identity

What the school holds on record

Confirmed
Full nameLatha Rao
Usernamelatha.rao
Cannot be changed
Employee IDPRSK-EMP-0114
Issued by HR
Date joined14 January 2019
7 years
4 fields

Contact

Where the school reaches this account

1 unverified
Email addresslatha.rao@preskool.edu Verified
Recovery emailNot set — the same address is being used
Phone number+91 98765 44710 Verified
Recovery phoneSame as the number above
4 fields · 1 needs attention

Role & placement

What this account is entitled to do

Highest role
RoleSuper Administrator
Changed by the Principal only
DepartmentAdministration
Reports toDr. Anitha Krishnan, Principal
Approver
Campus accessAll three campuses
4 fields

Account status

Whether this account may be used at all

Active
StatusActive since 14 January 2019
Active
Locked outNo — last lockout was 22 Feb 2026 after 5 failed attempts
Auto-cleared
Account expiryNone set — permanent staff
DeactivationSuspends sign-in without deleting any record
4 fields
Section 03

Authentication

Every way this account can prove who it is.

Every way this account can prove who it is. A factor that is armed is required at sign-in; one that is not is simply available.

Password

Armed

A 16-character passphrase, changed 112 days ago and inside every policy rule.

Strength Strong

Authenticator app

Armed

Google Authenticator on the primary phone. A six-digit code at every sign-in.

Strength Strong

Email verification

Armed

A one-time link when signing in from a device that has never been seen before.

Strength Good

SMS verification

Not in use

Off by design. A code sent by text can be intercepted by swapping the SIM, so it is kept as a fallback only.

Strength Fallback

Biometric sign-in

Armed

Windows Hello on the office desktop. The fingerprint never leaves that machine.

Strength Strong

Passkey

Not in use

Available but unused. A passkey cannot be phished, because it will not present itself to the wrong site.

Strength Strongest

Single sign-on

Not in use

The school has not federated with an identity provider. Accounts are held here.

Strength Not in use

Recovery codes

Armed

Ten codes issued on 22 Feb, of which two have been spent. Held on paper in the safe.

Strength Good
Section 04

Password Policy

The one factor everybody has, and the rules it must satisfy.

Current password

Changed 11 April 2026

Strong
112 days oldexpires in 68 days
Strength 16 characters · not in any breach list

A prompt appears automatically seven days before expiry. There is no benefit to changing it early unless you believe it is known to someone else.

Next prompt 04 Oct 2026

Password policy

Applies to every administrator account

School-wide
At least 12 characters
Upper and lower case
At least one number
At least one symbol
Checked against known breaches
May not contain your name
May not repeat the last 5
No forced mix of character classes

ExpiryEvery 180 days
HistoryThe last 5 passwords may not be reused
Failed attemptsLock the account for 15 minutes after 5 failures
Minimum age1 day, so a password cannot be cycled back immediately
Length is weighted above complexity, which is what current guidance recommends
Section 05

Two-Factor Authentication

The second factor, and the way back in without it.

Authenticator app

The second factor in use

Armed
ApplicationGoogle Authenticator
Primary phone
Enrolled22 February 2026
160 days
Code lengthSix digits, rotating every 30 seconds
TOTP
Required onEvery sign-in, including trusted devices
Last usedToday at 08:42 AM
Accepted
5 settings

Other second factors

Available, and why they are or are not used

2 off
Security keyNo hardware key registered on this account
SMS codeOff — a text can be intercepted by swapping the SIM
Email codeUsed only for a device that has never been seen before
Push approvalNot offered by the current authenticator
Unavailable
Trusted device skipOff — two-factor is asked for every time
5 settings

Recovery codes

Ten codes issued 22 Feb 2026 · two spent

8 remaining

Each code works once. They are the only way back in if the authenticator app is lost, so they belong on paper somewhere the account holder can reach and nobody else can.

4K2M-91XD 8PQR-3A7C D14N-6BZE 7VYH-22LK QW38-5NRT B60F-8JMS X92C-14PD L5TA-70GV N83E-6WQY R21K-49HB

Generating a new set immediately invalidates all ten of these, including the eight that are unused.

Two spent: 14 Mar during a phone replacement, 02 Jun while travelling
Section 06

Recovery Options

How you get back in when the usual route is gone.

Recovery email

Where a reset link would be sent

Not verified
Current addresslatha.rao@preskool.edu — the account’s own address
Same domain
Why this mattersIf the school domain is unreachable, so is the recovery route
SuggestedA personal address outside preskool.edu
Notify on changeBoth the old and new address are told when this changes
The single highest-value fix on this account

Recovery phone

Where a reset code would be texted

Verified
Number+91 98765 44710
Verified 22 Feb
Use for recoveryA code is sent only after identity is confirmed another way
Use as a second factorOff — the authenticator app is stronger
Notify on changeThe old number is told when this changes
4 settings
Security questions

Security questions are no longer used

They were retired across the school in March 2026. The answers to most of them — a mother’s maiden name, a first school, a pet — can be found on a public profile, which makes them a weaker factor than the password they protect. Recovery codes replaced them.

Section 07

Login Sessions

Where this account is signed in right now.

Four sessions, one of which is the browser you are reading this in. Ending a session signs that device out immediately; it does not remove its trust.

Windows 11 · Chrome 127This device

Chennai, India103.21.58.14Signed in 08:42 AM todayTrusted device

Cannot end

Android 15 · Chrome Mobile

Chennai, India49.207.188.62Active 22 minutes agoTrusted device

macOS 15 · Safari 18Idle 9 days

Coimbatore, India117.204.11.8Last active 23 JulNot a trusted device

Reporting integration · API keyMachine

preskool-reports-0110.20.4.19Last call 4 minutes agoKey issued 214 days ago

Section 08

Trusted Devices

Machines this account recognises.

A trusted device is one this account has signed in from before and recognises. Because two-factor is required every time, trust here shortens nothing except the new-device email.

Office desktop · Dell OptiPlexThis device

Windows Hello enrolledTrusted since 22 Feb 2026Last seen todayHead office, Chennai

Primary phone · Pixel 9Authenticator

Holds the authenticator appTrusted since 22 Feb 2026Last seen 22 minutes agoChennai, India

Home laptop · MacBook Air

Two-factor still requiredTrusted since 11 Apr 2026Last seen 4 days agoChennai, India

Samsung Galaxy Tab S9Not seen in 94 days

Two-factor still requiredTrusted since 03 Mar 2026Last seen 29 Apr 2026Chennai, India

Section 09

Login History

Every attempt, successful or not.

The last 8 of 214 sign-in attempts. The five refusals on 18 July came from one address in a four-minute window and stopped when the account locked; nothing was reached.

Section 10

Privacy

What others can see, and where information travels.

Privacy controls

What others can see about this account

Restricted
Profile visibilityStaff directory only — not visible to guardians
Show email in the directoryColleagues can see the address to write to you
Show phone in the directoryOff — the office number is listed instead
Online statusOff — nobody is shown whether you are signed in
Read receiptsOff for internal messages
5 settings

Data sharing

Where information about this account travels

Minimal
Usage analyticsAggregate only — never tied to your name
Crash reportsSent with the page and the error, no record contents
Improvement programmeOff — no session recording of any kind
Export my dataEverything held about this account, as a downloadable file
RetentionSecurity logs are kept for 3 academic years
5 settings
Third-party access

No third-party application has access to this account

Nothing outside the school ERP can read or act on your behalf. If you ever authorise an external tool, it will appear here with the exact scopes it was granted and a button to withdraw them.

Section 11

Notifications

What this account is told about itself.

Security notices are deliberately hard to switch off. The four that matter most go to both the account address and the recovery address, so no change can be made quietly.

Section 12

Permissions

What this role is entitled to do.

Role permissions

Super Administrator · inherited from the role, not set here

Read-only
AreaViewEditCreateDelete
Students — records and admissions
Staff — records and payroll
Fees, invoices and collections
Examinations and results
Attendance
Financial settings
Email and SMS configuration
User accounts and roles
Security logs and audit history
Backup and restore
Granted Granted, but needs a second approver Not granted
Even the highest role cannot delete a security log — that is the point of one

API access

Keys that act as this account

1 overdue
Reporting integrationRead-only · issued 214 days ago
Rotate
Scopes grantedstudents.read, fees.read, attendance.read
Last used4 minutes ago from 10.20.4.19
Active
Rotation policyEvery 180 days
RevokeStops the integration immediately
One key, one integration
Section 13

Security Logs

The record that cannot be edited.

Every security-relevant event on this account, kept for three academic years. Entries here cannot be edited or removed by anyone, including a Super Administrator.

Section 14

Advanced

Sessions, sign-in protection, keys and account actions.

Idle timeout30 minutes without activity, then a re-prompt
Absolute lifetime12 hours, whatever the activity
Concurrent sessionsUp to 5 — currently using 4
Sign out on password changeEvery other session ends when the password changes

Failed attempt lockout5 attempts, then a 15-minute lock
Impossible travelRefuse a sign-in that could not physically follow the last one
Known-breach password checkRefuse a password that appears in a public breach list
New-device emailAlways sent, and cannot be switched off

Reporting integrationprsk_••••••••4dA2 · read-only · 214 days old
Maximum keys2 per account
Scope ceilingA personal key can never exceed the role it belongs to
On revokingCalls fail immediately; nothing is queued

Deactivating suspends sign-in and ends every session, but keeps every record this account created. Deleting is handled by HR through the leaver process and is not available here.

Section 15

Audit History

Every change, with the name against it.

Audit history

Every change to this account, retained for 3 academic years

10 of 214 entries
01 Aug 202606:00
Security scan completed — posture 78System · scheduled daily
23 Jul 202614:11
Signed in from a new device and locationSafari on macOS · Coimbatore · verified by email
18 Jul 202603:02
Account locked after 5 failed sign-in attemptsFrom 185.220.101.44 · lock cleared automatically after 15 minutes
02 Jun 202611:26
Recovery code spentCode 6 of 10 · authenticator unavailable
11 Apr 202610:22
Trusted device added — MacBook AirBy the account holder after email verification
11 Apr 202610:04
Password changedBy the account holder · every other session ended
14 Mar 202609:48
Recovery code spent during a phone replacementCode 3 of 10 · authenticator re-enrolled the same day
03 Mar 202616:30
Trusted device added — Samsung Galaxy Tab S9Not seen since 29 Apr
22 Feb 202609:15
Two-factor authentication enabledAuthenticator app · 10 recovery codes issued
14 Jan 201911:00
Account createdBy Mr. R. Venkatesh · role Administrator, raised to Super Administrator in 2022
Entries cannot be edited or removed

Security activity

The moments that shaped how protected this account is today.

Account created

Opened by Mr. R. Venkatesh as an Administrator. Raised to Super Administrator in August 2022.

Password changed

A 16-character passphrase, checked against public breach lists. Every other session ended at the same moment.

Two-factor enabled

Authenticator app enrolled and ten recovery codes issued. Required at every sign-in since.

New device signed in

Safari on macOS from Coimbatore. Verified by email before it was allowed to do anything.

Permission updated

Backup and restore moved behind a second approver, following the term-end policy review.

Security scan completed

Posture scored 78 of 100. Two recommendations raised, neither of them urgent. No issues found.

Two-factor authentication

Armed 22 Feb 2026 · authenticator app · last used today at 08:42 AM

Armed
Configuration details
MethodTime-based one-time password (TOTP)
ApplicationGoogle Authenticator
Enrolled devicePixel 9 · primary phone
Enrolled on22 February 2026 by the account holder
Last acceptedToday at 08:42:11 AM
Failures in 90 daysNone
Current configuration
Required at sign-inEvery time, including trusted devices
Code lengthSix digits
RotationEvery 30 seconds
Clock drift allowanceOne window either side
Recovery codes8 of 10 unused
Healthy
Recent changes
Recovery code 6 spent02 Jun 2026 · authenticator unavailable while travelling
Authenticator re-enrolled on a new phone14 Mar 2026 · old enrolment revoked the same day
Trusted-device skip switched off01 Mar 2026 · two-factor now asked for every time
Security status
A second factor is required at every sign-inIncluding on trusted devices, which is stricter than most schools run.
Codes rotate every 30 secondsA code seen over someone’s shoulder is useless within half a minute.
Eight recovery codes unusedEnough to get back in if the phone is lost or replaced.
Only one enrolled deviceIf the phone is lost you would depend entirely on the printed codes. A second device or a hardware key would remove that dependency.
Recommendations
Register a hardware security keyIt cannot be phished, and it removes the single-device dependency above.
Keep the printed codes somewhere you can reach without the phoneA code in a note on the same phone protects nothing.
Leave SMS switched offA text can be redirected by swapping the SIM, which is a real and common attack.
Related settings
Recovery codes Trusted devices Password policy Security notifications
Audit history
02 Jun 202611:26
Recovery code spentCode 6 of 10
14 Mar 202609:48
Authenticator re-enrolledPhone replacement
01 Mar 202608:20
Trusted-device skip disabledMs. Latha Rao
22 Feb 202609:15
Two-factor enabledMs. Latha Rao · 10 codes issued