Skip to main content

End-User Portal Guide

This guide is for end users — how to sign in, set up two-factor authentication, manage your profile, and change your password in the self-service portal. (Administrators: see Identity & Access Management → User Portal for the configuration view.)

Signing in​

  1. Go to your organization's sign-in page (e.g. https://idp.<adroitts>.com/auth/login).
  2. Enter your email address. The broker routes you automatically:
    • If your email domain is federated (e.g. to Microsoft Entra or Google), you're redirected to that provider to sign in.
    • Otherwise you sign in with your local username and password.
  3. After a successful sign-in you land on your Dashboard (/portal/dashboard).

Tip: choose Sign In (not Sign Up) unless you're creating a brand-new account.

Setting up two-factor authentication (MFA)​

If your organization requires MFA, you'll be guided to enroll the first time you sign in (/user/mfa-enroll).

Authenticator app (TOTP)​

  1. On the enrollment screen, open your authenticator app (Microsoft Authenticator, Google Authenticator, Authy, 1Password, …).
  2. Scan the QR code (or type the manual key).
  3. Enter the 6-digit code the app shows to confirm. Your authenticator is now enrolled.

Passkeys (WebAuthn / FIDO2)​

From MFA Settings (/portal/mfa-settings) you can register a passkey — Touch ID / Face ID, Windows Hello, or a security key — for passwordless or step-up sign-in.

Face recognition​

From MFA Settings (/portal/mfa-settings) → Face Recognition → Enroll, register your face as a second factor. Give it a name, then capture in one of two ways:

  • This device's camera — Open Camera, then Capture a clear, well-lit photo.
  • No camera? Use your phone — choose Use your phone to show a QR code. Scan it with your phone: it opens a capture page, you take the photo on the phone, and the desktop dialog finishes automatically — no app to install.

The phone capture page must be opened over HTTPS (the QR uses your nexusID address, which is HTTPS) — browsers only allow camera access on a secure connection.

Face recognition requires your administrator to have enabled a face provider; if it's unavailable, contact your IT help desk.

Completing a challenge​

When a sign-in needs verification, you'll be prompted for your authenticator code, passkey, or face on the challenge screen. Approve it to continue. For a face challenge on a device without a camera, choose Use your phone to scan a QR and verify from your phone — the desktop continues your sign-in automatically once it succeeds.

Recovery codes​

Generate one-time recovery codes (/portal/recovery-codes) and store them somewhere safe. Use one if you ever lose access to your authenticator.

Managing your profile​

On Profile (/portal/profile) you can review and update your name, contact details, and preferences, and see your linked identities and recent sign-in activity.

Changing your password​

  1. Go to Change Password (/portal/change-password).
  2. Enter your current password, then your new password twice.
  3. Your new password must meet your organization's policy (length, complexity, history).
  4. Select Change Password.

In hybrid Microsoft environments, a password change here is also written back to your directory account so it stays in sync with the apps you use (this may take a short time to propagate).

Your applications​

The Applications view (/portal/applications) lists the apps you can launch via single sign-on. Select one to open it — you won't be asked to sign in again while your session is active.

Requesting access​

Need access to something you don't have yet? Open Request Access (/portal/request-access). It has three tabs:

  • Access Packages — bundles of access (e.g. a "New Developer" package) you can request in one click.
  • Roles — application roles you can request individually.
  • Entitlements — single permissions from the catalog.

Pick an item, add a justification if prompted, and select Request. You'll get an email confirming the request, and another once it's approved or denied. Track everything under My Requests on the same page — each row shows Pending, Approved, or Denied. Approved access is granted automatically; you don't need to do anything else.

If a tab is empty, your organization hasn't published anything requestable there (or the feature isn't enabled on your plan) — ask your administrator.

Privacy & consents​

Under Consents (/portal/consents) you can review which applications you've granted access to and what information they receive, and revoke access you no longer want.

Signing out​

Use Sign Out from the portal menu. For shared computers, always sign out when you're done.

Getting help​

If you're locked out, can't complete MFA, or need a password reset, contact your organization's IT help desk — they can reset your password, unlock your account, or reset your MFA from the admin console.