# 4. Password Management

User Type: **Super Administrator**
Source: *Mi Digital Academy - Education CRM Features Document*

---

## 4. Password Management

### 4.1 Password Creation with Security Requirements
**What it does:** Enforces password strength at the moments a password is set — during registration and during any password change. The system validates the proposed password against a configurable security policy (length, character composition, blocklists, reuse history, similarity to the email) and only accepts it when all requirements pass, providing real-time feedback so the user can correct weaknesses before submitting.

**Sub-features:**
- Minimum length requirement (configurable, e.g., 8+ characters)
- Character class requirements (uppercase, lowercase, number, symbol — each individually configurable on/off)
- Real-time strength meter with specific, actionable feedback ("Add a symbol", "Make it longer")
- Blocklist check against common passwords and known breached-password datasets
- No reuse of the last N passwords (configurable N, e.g., 10)
- Similarity check: password must differ significantly from the user's email address and name
- No dictionary-word-only passwords (configurable dictionary enforcement)
- Policy configuration screen in System Settings with live preview of the rules
- Compliance reporting: accounts with weak, aged, or reused passwords
- Platform-wide or role-scoped rotation notices to trigger proactive changes

**Super Administrator User Journey:**
1. Super Admin opens System Settings → Security Policy → Password Policy.
2. Reviews the current policy: minimum 8 characters, all four character classes required, blocklist on, no reuse of last 10, similarity check on.
3. Decides to raise the minimum length to 12 for all admin and staff roles. Uses the role-scoped override to apply the stricter length to privileged roles while keeping 8 for students and parents.
4. Uses the live preview to test sample passwords against the new policy, confirming the feedback messages are clear.
5. Saves the policy; it applies to all new and changed passwords from that point (existing passwords are not invalidated).
6. Later, Super Admin opens the password compliance report: it lists accounts with passwords older than the maximum age, accounts flagged weak by the strength model, and any reuse violations.
7. For the high-risk roles (Billing Administrator, Super Admin), Super Admin triggers a role-scoped password rotation notice: those users are prompted to change their password at next login, with the reason shown.
8. Super Admin reviews the rotation completion report a week later and follows up with any privileged-role account that has not rotated.

**Rules & Edge Cases:**
- Policy changes apply prospectively: existing passwords remain valid until changed, unless a rotation is explicitly triggered.
- The strength meter gives specific, actionable feedback rather than a vague score, so users know exactly what to fix.
- Breached-password checks run against known breach datasets; a match is a hard block, not a warning.
- The reuse window compares against the account's own password history only (hashed comparisons); it does not block a password used by a different account.
- Passwords are stored only as salted hashes with a strong adaptive algorithm; plain-text passwords are never stored, logged, or transmitted in clear.
- The similarity check prevents passwords that are trivially derivable from the user's email or name (e.g., "emailaddress1!").
- Role-scoped overrides always apply the stricter of the platform default and the role override.

### 4.2 Forgot Password / Password Reset Flow
**What it does:** Allows a user who has forgotten or lost their password to reset it without support intervention, through a verified, time-limited reset credential (link or OTP) delivered to a registered channel. The flow proves control of a registered channel before issuing reset capability, applies the full password policy to the new password, and invalidates all existing sessions on completion. A support-assisted path exists for users who have lost access to all channels.

**Sub-features:**
- "Forgot password" entry on the login screen
- Identity confirmation via a registered channel (email and/or phone OTP)
- Reset link issuance: single-use, time-limited (e.g., 30 minutes), bound to the account
- Reset OTP alternative for mobile-friendly flows
- New password entry with the full security policy applied (strength meter, blocklist, reuse)
- Rate limiting on reset requests per account and per IP
- Lock on the reset flow after multiple failed requests, with an alert in security monitoring
- Support-assisted reset: admin-initiated reset after identity verification, for users with no channel access
- Session invalidation: all existing sessions for the account end on reset completion
- Notification: the account owner is notified of the reset (self-initiated or admin-initiated)
- Audit logging of every reset event (initiated, link issued, completed, failed, admin-assisted)

**Super Administrator User Journey:**
1. A user contacts support saying they cannot log in and have forgotten their password. Super Admin opens the user's record in the user directory.
2. Super Admin checks the password reset activity log for the account: it shows a self-service reset started 20 minutes ago, a link issued, but not completed (link expired).
3. Super Admin advises the user to start the self-service flow again from the login screen ("Forgot password?"), confirming the user still has access to their registered email.
4. The user completes the self-service reset: enters their email, receives the reset link, clicks it within 30 minutes, sets a new password that passes the strength meter, and is logged in. All their previous sessions are invalidated.
5. In a harder case, a second user has changed jobs and lost access to both their registered email and phone. Super Admin opens that account and initiates a support-assisted reset.
6. Super Admin verifies the user's identity through the support verification process: confirming registered details (full name, registration date, last four of phone) and an OTP delivered to an alternate verified channel or document verification per the standard.
7. Satisfied, Super Admin issues an admin-authorized password reset for the account, entering the reason ("Lost access to all channels — identity verified").
8. The user sets a new password at next login (forced-change prompt). The event is audit-logged as support-assisted, all sessions are invalidated, and the user is notified of the reset.
9. Super Admin reviews the reset audit log: both resets are recorded with type (self-service/admin-assisted), actor, timestamp, and outcome.

**Rules & Edge Cases:**
- Self-service reset requires control of at least one registered channel; if all channels are unavailable, only the support-assisted path works.
- Reset links are single-use and expire; a used or expired link shows a clear message with a "request a new link" option (subject to rate limits).
- Multiple failed reset requests from one account or IP trigger a temporary lock on the reset flow and an alert in security monitoring (possible account-takeover attempt).
- Every reset — self-service or admin-assisted — invalidates all existing sessions for the user, ending any attacker-held sessions.
- The account owner is always notified of a reset; an unexpected-reset report routes to support and security monitoring as a potential compromise.
- Admin-assisted resets require a recorded reason and are audit-logged with the acting admin; they are visible in the security audit trail.
- Reset requests are rate-limited per account and per IP to prevent enumeration and abuse.

### 4.3 Password Change
**What it does:** Lets an authenticated user change their password voluntarily from their profile settings. The change requires verifying the current password (proving the requester is the account holder), validates the new password against the full security policy, and offers to end all other sessions so that any device using the old password loses access.

**Sub-features:**
- Change password from profile settings (Security section)
- Current password verification before the change is accepted
- New password validated against the full security policy with real-time strength feedback
- Reuse check: new password cannot match any of the last N used passwords
- Optional "sign out all other sessions" checkbox on change (recommended, shown as such)
- Security notice email to the account owner on change (with device/location context)
- Forced-change prompt: accounts flagged for rotation (policy, compromise, admin action) must change at next login
- Audit logging of every change with timestamp and initiating device

**Super Administrator User Journey:**
1. Super Admin opens profile settings → Security → Change Password, as part of their quarterly credential hygiene.
2. Enters the current password for verification. The system accepts it and reveals the new-password fields.
3. Enters the new password; the strength meter validates it in real time against policy (length, character classes, blocklist, reuse, similarity) and shows specific feedback until it passes.
4. Re-enters the new password to confirm; the two match.
5. Ticks "Sign out all other sessions" so that any other device still authenticated with the old password is ended.
6. Submits. The system applies the change, invalidates all other sessions as chosen, and sends the security-notice email ("Your password was changed on [date] from [device/location]. If this wasn't you, contact support.").
7. Super Admin's current session continues; the next login from any device uses the new password.
8. In the admin capacity, Super Admin later reviews the password-change audit log for privileged roles to confirm all quarterly rotations were completed, and follows up on any account that missed the window.

**Rules & Edge Cases:**
- If the current password is wrong, the change is rejected — this prevents someone with only partial access (e.g., a session on a shared device without the password) from changing it.
- The new password cannot match any of the last N used passwords for the account (reuse window).
- A password change always notifies the account owner; a report of an unexpected change routes to support and security monitoring as a potential compromise.
- Choosing "sign out all other sessions" ends every session except the current one immediately (on next request).
- Forced-change accounts cannot access the platform beyond the change screen until the password is changed.
- The change is audit-logged with timestamp, initiating device, and (for admin-initiated forced changes) the triggering reason.

