Security · Posture
Security center
Security score 84/100 · 2 factors need attention · last scan completed 14 minutes ago across 142 endpoints.
2 recommendations open
Audit logs
Recent security events
Last 24 hours · sorted by severity
Today · 14:48
New device sign-in · Sarah K.
Sign-in from Chrome on macOS · IP 76.14.224.10 (San Francisco, CA). 2FA challenge passed in 4 seconds.
Today · 11:22
Security scan completed · 84/100
Full posture scan across 142 endpoints. 2 recommendations open (one high, one medium). No critical findings.
Today · 09:14
API key rotated · Production Web App
Sarah K. rotated
aurora_live_••••8f2a. Old key revoked after 7-day grace period.Yesterday · 22:08
Blocked brute-force attempt
14 failed logins for admin@aurora.dev from IP 188.42.x.x (Frankfurt, DE). Account locked, IP added to denylist, alert sent to Slack #security.
Yesterday · 16:34
MFA disabled · Jordan A.
Jordan A. temporarily disabled MFA on their account. Auto-reminded to re-enable within 24h. Currently 6 users without MFA.
Yesterday · 10:02
SSO certificate renewed
Okta SAML certificate renewed 18 days before expiry. No user impact. Old cert retained for 30-day rollback.
Active sessions
4 of 38 shown · sorted by last activity
Chrome · macOS · SF office
IP 76.14.224.10 · Sarah K. · current session
Last activity: 2 sec ago
Started: Today 09:14
Mobile Safari · iOS 18
IP 98.222.18.140 · Sarah K. · iPhone 15 Pro
Last activity: 4 min ago
Firefox · Linux · unknown location
IP 188.42.118.22 · Diego R. · Frankfurt, DE
Last activity: 6 days ago
Edge · Windows · London office
IP 212.58.244.30 · Emily W. · Surface Laptop
Last activity: 18 min ago
Security recommendations
4 actionable items · sorted by impact
High
Enable MFA for 6 remaining users
Jordan A., Pieter B., and 4 others have not enrolled in 2FA. Auto-enforce on Aug 1, 2025.
Affects 6 users
Medium
Rotate legacy API key (aurora_live_••••22a1)
In production for 11 months · used by deprecated v1 API. Rotate by Aug 15 to avoid enforced revocation.
2 days to deadline
Medium
Review stale session · Diego R.
Active session from Frankfurt Linux device has been idle 6 days. Likely forgotten login on shared workstation.
1 session
Low
Enforce password rotation for 12 admins
12 admin accounts have passwords older than 90 days. Consider SSO migration to eliminate password rotation entirely.
No deadline