1. Using the New MyID Password & Access Management Website
The new MyID.ocps.net web site is the entry to the RapidID Portal. RapidID is the new Identity Management system being rolled out.
Each tile/link has a specific purpose:
- Log In/Claim an Account – This link opens the RapidID portal enabling users to log in to the portal or to claim a new account.
- Create Consultant/Sponsored Account – Connects users with the Help Desk to open a ticket requesting a Consultant, or Sponsored Account.
- Reset Password – Opens the Login screen to start the reset password process.
- Check Account Status – enables users to check account status using a username. (Note: This screen is currently disabled!)
- Manage Membership Groups – enables users to check group membership and add or delete accounts within those groups.
- Documentation & FAQs – Details the processes used for each of the links on the Account Services page and answers Frequently Asked Questions.
2. Log In/Claim an Account Page
The Log In/Claim an Account page has multiple uses, logging in to an account, resetting a password, using a QR Code to access an account, and to claim a new account.
To Claim an Account
Claiming an account is the process of verifying your identity when logging into a new account. You, and your manager, will receive an email when you are hired. The email includes your name, OCPS email address, employee ID number, and a claim code.
Write down your email address, employee ID number, and claim code. Use the link in the email to go to the MyID website to start the claiming process. Once your account is claimed you will be able to log in to your account.
- Either click the link in the welcome email or open the MyID Password & Access Management website and click the Log In/Claim an Account tile. This displays the main Log In page.
- Click Claim My Account. This displays the Claim Account Step 1 page.
- Enter the District Email Address and the Claim Code for the employee. Both of these are required and will be in the Welcome Email sent you from RapidID. This email is sent whether you are a new staff member or consultant.
- Click Next. This displays the Claim Account Step 2 – Update Your Password page.
- Enter a password in New Password text box following the password rules listed.
- Enter the password a second time in the Verify Password text box to confirm the password.
- Click Next. This displays the Claim Account – Complete page.
- This page confirms you’ve successfully claimed your account. Please retain your User ID for future use.
- Click the Back link to return to the main Log in page. You can now log in to your account.
To Log In to an Account
- Open the MyID Password & Access Management website and click the Log In/ Claim an Account tile. This displays the main Log In page.
- Enter a username in the Username text box and click Go. This displays the RapidID Log In - Password page.
- Enter the password or pass phrase associated with the account in the Password text box and click Sign In.
- If you already have multi-factor authentication (MFA) configured, you will be logged into the RapidID dashboard.
- Once logged in to the dashboard you will be able to:
- Check your Profile Settings
- Change a Password
- Logout.
- Locate your name in the upper right of the RapidID toolbar and click the down arrow to display the options dialog box.
- Other toolbar options include: Alerts, Activity, Tasks. You can click each icon to open the pane, and either click it again to close the pane or click the X to close it.
- If you do not have MFA configured the system will prompt you to configure MFA. Click Next to proceed.
- Once you’ve completed configuring MFA the system you’ll be signed in to RapidID and the system displays the RapidID dashboard.
Note: These options are all configurable and may change over time.
3. Configuring Multi-Factor Authentication
OCPS uses Microsoft Entra as it’s default application for Multi-Factor Authentication (MFA). Entra allows you to select from a number of methods for MFA. The initial screen for setting up MFA defaults to the MS Authenticator app but offers other options.
Note: All Multi-Factor Authentication is completed through the mysignins.microsoft.com web site.
If you do not have MFA configured, logging in will prompt you to keep your account secure.
Click Next to proceed. This opens Microsoft Entra, the application within which you will configure your Multi-Factor Authentication.
Microsoft Authenticator is the default method OCPS uses, but you can select any of the others to use for MFA. Click the I want to use a different authenticator app link on the initial Start by getting the app screen to display the Choose a different method popup.
Configuring Microsoft Authenticator as MFA
Microsoft Authenticator is the OCPS default method for multi-factor authentication. These instructions are for downloading and configuring the Microsoft application on your phone.
- To use Microsoft Authenticator you must first download the application. Click Download now.
- Use the camera on your phone to scan the QR code and click the link. This opens Google Play or the Apple App Store (depending on your phone) asking you to download the Authenticator app.
- Download the application. Once you have downloaded the application return to the mysignins.microsoft.com screen and click Next. This displays the MS Set up your account screen.
- Click Next on the MS Set up your account screen. This displays the MS Scan the QR code screen.
- Open the Microsoft Authenticator app on your phone. Click the QR symbol in the application to scan the QR code. This pairs the application with your account.
- Once you’ve paired the application to your account click Next. This displays the authentication code screen.
- Enter the 2-digit code in the app on your phone and click Yes. This displays the Authenticator Success screen.
- Click Done to complete signing in to your account.
Configuring Email as MFA
- On the "Start by getting the app" screen, select the I want to set up a different method link.
- Select Email from the Choose a different method popup.
- Enter the email you’d like to use for MFA in the Enter email text box and click Next. (Note: This cannot be your work email.)
- The system will send a code to the email address you’ve entered. Retrieve that code from the email and enter the code in the Enter code text box on the Email Code screen.
- Click Next.
- Upon successful completion of setting up the email address the system displays a Success screen. This identifies email as the default sign-in method. Click Done to complete the configuration process and return to the MyID website to complete logging in.
Configuring Phone as MFA
- On the "Start by getting the app" screen, select the I want to set up a different method link.
- Select Phone from the Choose a different method popup.
- Enter the phone number you’d like to use for MFA in the Phone Number text box.
- Select how you’d like to receive the verification code. The Receive a code option entails a 6-digit code sent to your phone via SMS. The Call me option entails receiving a phone call with the code.
- In this example, the Receive a code option is selected. Click Next.
- The Phone Enter code screen is displayed. Enter the 6-digit code you received on your phone and click Next.
- This displays the Success screen, indicating you’ve successfully authenticated your account. Click Done to complete the configuration process.
- Selecting the Call me option and clicking Next displays the Phone We’re calling … screen. You will receive a call from Microsoft at the number you’ve entered asking you to press # to authenticate.
- Once you press # the system will tell you you’ve successfully authenticated and will display the Phone success screen. Click Done to complete the configuration process.
Configuring Hardware Token as MFA
To use a hardware token as a form of multi-factor authentication you will need to purchase your own token. OCPS will not supply tokens.
- On the "Start by getting the app" screen, select the I want to set up a different method link.
- Select Hardware token from the Choose a different method popup.
- The Hardware Token serial number screen is displayed. Enter the serial number of the token and click Next.
- This displays the Name your token screen. Enter a name you’ll remember and click Next.
- This displays a screen for you to enter the code displayed on the hardware token.
- Once you enter the code displayed on the hardware token and click Next, the system will tell you you’ve successfully authenticated and will display the Hardware Token success screen.
- Click Done to complete the configuration process and return to the MyID website to complete logging in.
4. Resetting a Password
Resetting a password uses the same process if the user is just completing a scheduled password reset, or if that user has forgotten their password and needs to reset their password.
Scheduled Password Reset
- Click on the Reset Password tile in the Account Services website. Enter your Username.
- Click Go, this displays the Microsoft Enter password screen.
- Enter your password or pass phrase in the Password text box and click Sign in.
- This displays the Stay Signed in? screen. Click Yes. This displays the RapidID dashboard.
- Locate your user name on the right side of the menu bar and click the down arrow to display your available profile options.
- Select Change Password from the menu. This displays the Change Password pane.
- Enter your current password in the Current Password text box.
- Then enter your new password or pass phrase in the New Password text box.
- Confirm the new password or pass phrase in the Confirm New Password text box.
- Remember to follow the requirements for OCPS passwords. Click Save.
- This displays the Change Password – Status pane confirming you have successfully changed your password.
- Close the pane to return to your dashboard.
Reclaiming a Forgotten Password
- Open the Account Services website and click the Log In/ Claim an Account tile.
- This displays the main Log In page. Enter a username in the Username text box and click Go.
- This displays the Microsoft Enter password page.
- Click the Forgot my password link. This displays the account authentication screen.
- Enter the characters in the text box and click Next. This displays an account verification screen.
- Select the Approve a notification on my authenticator app option and click Send Notification. This sends a notification to your authenticator app and displays a two digit code. Open your authenticator app and enter the code and click Yes.
- Selecting the Enter a code from my authenticator app option requires you to open your authenticator to retrieve the rotating code. Enter that code in the Enter your verification code text box and click Next.
- Click Yes or Next on either option displays the Choose a New Password screen.
- Enter and confirm your new password and click Finish.
- This displays a success message stating your password has been reset. Click the click here link.
- This displays the Microsoft Enter password page and allows you to log into your dashboard.
5. Creating a Ticket for a Consultant/Sponsored Account
Creating a sponsored account entails opening a ticket in the EasyVista ticketing system. This tile opens EasyVista so you can create and submit a ticket.
- Open the MyID Password & Access Management website and click the Create Consultant/Sponsored Account tile.
- This opens the OCPS Help Center website.
- Click the New Consultant Account button. This opens the Consultant Account Request form.
- Complete all the fields in the form and click OK. This will create an EasyVista ticket.
- If the manager of the new consultant is the one who created the ticket, approval is bypassed and the account created.
- Tickets created by a staff member go to that staff member’s manager for approval. Once approved the account is created.
6. Managing Group Membership
Managing group membership only allows you to view a list of members for a given group, add new members to that group, or delete members from that group. You must be the Group Owner or a Service Desk member to add or remove people from groups.
- Open the Account Services website and click the Manage Group Membership tile. This displays the Group Manager page.
- Enter the name of the group you want to manage membership for in the Group Name text box.
- Click the Magnifying glass to display possible groups with that name. In this example HTC was entered. This displays a list of groups including HTC.
- Select the group you wish to manage. This displays the Group Manager Membership screen.
- If this is not the correct group you can re-enter a group name in the Group Name text box and click the magnifying glass again, then select another group.
- You can add users to the group selected by entering their User ID to the Add User (ID) text box.
- Click the green Add button at the right of the text box to add the user.
- To remove a group member simply locate their name in the Group List and click the red Remove icon to the right of the individual’s name.
Note: If you are not the Group Owner or a Service Desk member you will not be able to add or delete members from the group. Trying to do so will result in an error message being displayed.
7. Assisting Others in Claiming an Account, Resetting a Password, or Unlocking an Account
To assist others in gaining access to their account, use the TSR Profile Management screen. This screen displays all staff and students for Help Desk and Area Team, and for TSRs staff and students assigned them by location code (Note: This does not include Principals or Assistant Principals).
- Open the Account Services website and log in to your account.
- Once logged in the RapidID People module is displayed. This module has two available options, either the TSR Profile Management screen or the Staff Whitepages screen.
- Select the TSR Profile Management tab in the left pane.
Note: The Staff Whitepages screen is simply a directory, there is no functionality in that screen other than searching through the entire district.
The TSR Profile screen has a number of usable columns, displaying the Staff Member’s or Student’s Last Name, First Name, Role, OCPS Email address, whether the account is locked, the date of the Last Password Reset, their Job Title, their Department, their Location Name, the Claim Code used to claim their account, and whether their account was Claimed.
The White Pages screen displays much less information and is useful simply for finding a staff member and their contact information. Columns include Last Name, First Name, OCPS Email address, Office Phone number, Job Title, and Location Name.
The TSR Profile Management tab provides access to those individuals for which you have responsibility.
- To find the staff member being assisted enter a name into the Search TSR Profile Management text box and click the magnifying glass search icon.
- If multiple names are returned, select the staff member being assisted.
- Click the 3 dots to the left of the staff member’s name to display the management options. The options available are Details, Change Password, Unlock.
Note: This options popup is configurable, and display may differ from what is shown.
- Details – Displays the Details pane and provides basic information for that staff member, including Name, Email Address, Office Phone (if applicable), Role, Usernames, whether the account is locked, Job Title, Department, Location Name, and Claim Code. (Note: Details pane is configurable, and we may add Groups to this list)
- Change Password – Displays the Change Password pane. This lists the OCPS Default Password Policy and Password Rules. Below the rules there are both a New Password and Confirm New Password text boxes. The rules next to those text boxes will be selected automatically as a new password is entered. There is also an option to select randomly generated passwords.
- Click Save to complete the Password change. This displays a second Change Password pane asking if you’re sure you want to change the staff member’s password. Click Yes.
- Unlock – Displays the Confirm Unlock pane, asking if you want to continue to unlock the selected staff member’s profile. Accounts are locked if the user fails to correctly enter the password 10 times within 10 minutes. It will automatically unlock after one hour. Click Yes to unlock the profile. (Note: It is possible to sort by locked accounts, select multiple accounts, and do a batch unlock.)