# 1. Institute Login & Access — Test Cases

User Type: **Training Institute**
Source: *Mi Digital Academy - Education CRM Features Document*
Spec: institute_login_access.md — every feature, sub-feature, and rule covered

## Test Execution Policy

- Zero tolerance: any deviation from the documented behavior is a defect.
- Every failed test is logged with a Bug ID, the feature, the sub-feature, the expected vs actual result, and the severity; 100% of bugs are fixed before the group passes.
- 100% pass rate is required for the group to be marked complete.

## Coverage Matrix

| Feature | Sub-feature / Rule | Test IDs |
|---------|--------------------|----------|
| 1.1 | Institute portal login screen | TC-TI-1-01-001 |
| 1.1 | Sign in with registered email and password | TC-TI-1-01-002 |
| 1.1 | Redirect to the institute dashboard on success | TC-TI-1-01-003 |
| 1.1 | Failed attempts limited with lockout | TC-TI-1-01-004 |
| 1.1 | Reason shown on failed sign-in | TC-TI-1-01-005 |
| 1.1 | Login available on web and mobile | TC-TI-1-01-006 |
| 1.1 | Login event logging (success, failure) | TC-TI-1-01-007 |
| 1.1 | Audit logging of the institute portal login | TC-TI-1-01-008 |
| 1.1 | Rule: The failed attempts are limited with lockout. | TC-TI-1-01-001 |
| 1.1 | Rule: The reason is shown on a failed sign-in. | TC-TI-1-01-002 |
| 1.1 | Rule: Login events (success, failure) are logged with the account and the timestamp. | TC-TI-1-01-003 |
| 1.1 | Rule: The institute portal login is audit-logged with the account and the timestamp. | TC-TI-1-01-004 |
| 1.2 | SSO login option on the login screen | TC-TI-1-01-009 |
| 1.2 | Redirect to the organization's SSO provider | TC-TI-1-01-010 |
| 1.2 | Automatic sign-in on success | TC-TI-1-01-011 |
| 1.2 | SSO session mapped to the institute account | TC-TI-1-01-012 |
| 1.2 | SSO available on web and mobile | TC-TI-1-01-013 |
| 1.2 | SSO event logging (initiated, success) | TC-TI-1-01-014 |
| 1.2 | Audit logging of the single sign-on login | TC-TI-1-01-015 |
| 1.2 | Rule: The SSO session is mapped to the institute account. | TC-TI-1-01-009 |
| 1.2 | Rule: The SSO sign-in is automatic on success. | TC-TI-1-01-010 |
| 1.2 | Rule: SSO events (initiated, success) are logged with the account and the timestamp. | TC-TI-1-01-011 |
| 1.2 | Rule: The single sign-on login is audit-logged with the account and the timestamp. | TC-TI-1-01-012 |
| 1.3 | Enable two-factor authentication | TC-TI-1-01-016 |
| 1.3 | One-time code after the password | TC-TI-1-01-017 |
| 1.3 | Code sent to the registered device or email | TC-TI-1-01-018 |
| 1.3 | Disable two-factor authentication | TC-TI-1-01-019 |
| 1.3 | Re-register the 2FA device | TC-TI-1-01-020 |
| 1.3 | 2FA available on web and mobile | TC-TI-1-01-021 |
| 1.3 | 2FA event logging (enabled, code verified) | TC-TI-1-01-022 |
| 1.3 | Audit logging of the two-factor authentication | TC-TI-1-01-023 |
| 1.3 | Rule: The one-time code is required after the password. | TC-TI-1-01-016 |
| 1.3 | Rule: The 2FA device can be re-registered. | TC-TI-1-01-017 |
| 1.3 | Rule: 2FA events (enabled, code verified) are logged with the account and the timestamp. | TC-TI-1-01-018 |
| 1.3 | Rule: The two-factor authentication is audit-logged with the account and the timestamp. | TC-TI-1-01-019 |

## 1.1 Institute Portal Login

### TC-TI-1-01-001 — Institute portal login screen
**Type:** Positive
**Covers:** 1.1 → Institute portal login screen; Rule: The failed attempts are limited with lockout.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Institute portal login screen.
2. Observe the result and verify the full behavior: Institute portal login screen.
**Expected Result:** Institute portal login screen — delivered exactly as documented.
**Priority:** Critical

### TC-TI-1-01-002 — Sign in with registered email and password
**Type:** Positive
**Covers:** 1.1 → Sign in with registered email and password; Rule: The reason is shown on a failed sign-in.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Sign in with registered email and password.
2. Observe the result and verify the full behavior: Sign in with registered email and password.
**Expected Result:** Sign in with registered email and password — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-003 — Redirect to the institute dashboard on success
**Type:** Positive
**Covers:** 1.1 → Redirect to the institute dashboard on success; Rule: Login events (success, failure) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Redirect to the institute dashboard on success.
2. Observe the result and verify the full behavior: Redirect to the institute dashboard on success.
**Expected Result:** Redirect to the institute dashboard on success — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-004 — Failed attempts limited with lockout
**Type:** Edge
**Covers:** 1.1 → Failed attempts limited with lockout; Rule: The institute portal login is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Failed attempts limited with lockout.
2. Observe the result and verify the full behavior: Failed attempts limited with lockout.
**Expected Result:** Failed attempts limited with lockout — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-005 — Reason shown on failed sign-in
**Type:** Positive
**Covers:** 1.1 → Reason shown on failed sign-in
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Reason shown on failed sign-in.
2. Observe the result and verify the full behavior: Reason shown on failed sign-in.
**Expected Result:** Reason shown on failed sign-in — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-006 — Login available on web and mobile
**Type:** Positive
**Covers:** 1.1 → Login available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Login available on web and mobile.
2. Observe the result and verify the full behavior: Login available on web and mobile.
**Expected Result:** Login available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-007 — Login event logging (success, failure)
**Type:** Positive
**Covers:** 1.1 → Login event logging (success, failure)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Login event logging (success, failure).
2. Observe the result and verify the full behavior: Login event logging (success, failure).
**Expected Result:** Login event logging (success, failure) — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-008 — Audit logging of the institute portal login
**Type:** Positive
**Covers:** 1.1 → Audit logging of the institute portal login
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the institute portal login action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The institute portal login action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 1.2 Single Sign-On (SSO) Login

### TC-TI-1-01-009 — SSO login option on the login screen
**Type:** Positive
**Covers:** 1.2 → SSO login option on the login screen; Rule: The SSO session is mapped to the institute account.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: SSO login option on the login screen.
2. Observe the result and verify the full behavior: SSO login option on the login screen.
**Expected Result:** SSO login option on the login screen — delivered exactly as documented.
**Priority:** Critical

### TC-TI-1-01-010 — Redirect to the organization's SSO provider
**Type:** Positive
**Covers:** 1.2 → Redirect to the organization's SSO provider; Rule: The SSO sign-in is automatic on success.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Redirect to the organization's SSO provider.
2. Observe the result and verify the full behavior: Redirect to the organization's SSO provider.
**Expected Result:** Redirect to the organization's SSO provider — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-011 — Automatic sign-in on success
**Type:** Positive
**Covers:** 1.2 → Automatic sign-in on success; Rule: SSO events (initiated, success) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Automatic sign-in on success.
2. Observe the result and verify the full behavior: Automatic sign-in on success.
**Expected Result:** Automatic sign-in on success — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-012 — SSO session mapped to the institute account
**Type:** Positive
**Covers:** 1.2 → SSO session mapped to the institute account; Rule: The single sign-on login is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: SSO session mapped to the institute account.
2. Observe the result and verify the full behavior: SSO session mapped to the institute account.
**Expected Result:** SSO session mapped to the institute account — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-013 — SSO available on web and mobile
**Type:** Positive
**Covers:** 1.2 → SSO available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: SSO available on web and mobile.
2. Observe the result and verify the full behavior: SSO available on web and mobile.
**Expected Result:** SSO available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-014 — SSO event logging (initiated, success)
**Type:** Positive
**Covers:** 1.2 → SSO event logging (initiated, success)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: SSO event logging (initiated, success).
2. Observe the result and verify the full behavior: SSO event logging (initiated, success).
**Expected Result:** SSO event logging (initiated, success) — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-015 — Audit logging of the single sign-on login
**Type:** Positive
**Covers:** 1.2 → Audit logging of the single sign-on login
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the single sign-on login action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The single sign-on login action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical


## 1.3 Two-Factor Authentication (2FA)

### TC-TI-1-01-016 — Enable two-factor authentication
**Type:** Positive
**Covers:** 1.3 → Enable two-factor authentication; Rule: The one-time code is required after the password.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Enable two-factor authentication.
2. Observe the result and verify the full behavior: Enable two-factor authentication.
**Expected Result:** Enable two-factor authentication — delivered exactly as documented.
**Priority:** Critical

### TC-TI-1-01-017 — One-time code after the password
**Type:** Positive
**Covers:** 1.3 → One-time code after the password; Rule: The 2FA device can be re-registered.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: One-time code after the password.
2. Observe the result and verify the full behavior: One-time code after the password.
**Expected Result:** One-time code after the password — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-018 — Code sent to the registered device or email
**Type:** Positive
**Covers:** 1.3 → Code sent to the registered device or email; Rule: 2FA events (enabled, code verified) are logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Code sent to the registered device or email.
2. Observe the result and verify the full behavior: Code sent to the registered device or email.
**Expected Result:** Code sent to the registered device or email — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-019 — Disable two-factor authentication
**Type:** Positive
**Covers:** 1.3 → Disable two-factor authentication; Rule: The two-factor authentication is audit-logged with the account and the timestamp.
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Disable two-factor authentication.
2. Observe the result and verify the full behavior: Disable two-factor authentication.
**Expected Result:** Disable two-factor authentication — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-020 — Re-register the 2FA device
**Type:** Positive
**Covers:** 1.3 → Re-register the 2FA device
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: Re-register the 2FA device.
2. Observe the result and verify the full behavior: Re-register the 2FA device.
**Expected Result:** Re-register the 2FA device — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-021 — 2FA available on web and mobile
**Type:** Positive
**Covers:** 1.3 → 2FA available on web and mobile
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: 2FA available on web and mobile.
2. Observe the result and verify the full behavior: 2FA available on web and mobile.
**Expected Result:** 2FA available on web and mobile — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-022 — 2FA event logging (enabled, code verified)
**Type:** Positive
**Covers:** 1.3 → 2FA event logging (enabled, code verified)
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, set up the precondition and perform: 2FA event logging (enabled, code verified).
2. Observe the result and verify the full behavior: 2FA event logging (enabled, code verified).
**Expected Result:** 2FA event logging (enabled, code verified) — delivered exactly as documented.
**Priority:** High

### TC-TI-1-01-023 — Audit logging of the two-factor authentication
**Type:** Positive
**Covers:** 1.3 → Audit logging of the two-factor authentication
**Preconditions:** A Training Institute account is active and the Training Institute is in the state required for this behavior.
**Steps:**
1. As a Training Institute, perform the two-factor authentication action.
2. Open the audit log and verify the entry for the action.
**Expected Result:** The two-factor authentication action is recorded in the audit log with the account and the timestamp.
**Priority:** Critical
