End-User Portal Guide
This guide is for end users — how to sign in, set up two-factor authentication, manage your profile, and change your password in the self-service portal. (Administrators: see Identity & Access Management → User Portal for the configuration view.)
Signing in
- Go to your organization's sign-in page (e.g.
https://idp.<adroitts>.com/auth/login). - Enter your email address. The broker routes you automatically:
- If your email domain is federated (e.g. to Microsoft Entra or Google), you're redirected to that provider to sign in.
- Otherwise you sign in with your local username and password.
- After a successful sign-in you land on your Dashboard (
/portal/dashboard).
Tip: choose Sign In (not Sign Up) unless you're creating a brand-new account.
Setting up two-factor authentication (MFA)
If your organization requires MFA, you'll be guided to enroll the first time you sign in
(/user/mfa-enroll).
Authenticator app (TOTP)
- On the enrollment screen, open your authenticator app (Microsoft Authenticator, Google Authenticator, Authy, 1Password, …).
- Scan the QR code (or type the manual key).
- Enter the 6-digit code the app shows to confirm. Your authenticator is now enrolled.
Passkeys (WebAuthn / FIDO2)
From MFA Settings (/portal/mfa-settings) you can register a passkey — Touch ID / Face ID,
Windows Hello, or a security key — for passwordless or step-up sign-in.
Face recognition
From MFA Settings (/portal/mfa-settings) → Face Recognition → Enroll, register your face as a
second factor. Give it a name, then capture in one of two ways:
- This device's camera — Open Camera, then Capture a clear, well-lit photo.
- No camera? Use your phone — choose Use your phone to show a QR code. Scan it with your phone: it opens a capture page, you take the photo on the phone, and the desktop dialog finishes automatically — no app to install.
The phone capture page must be opened over HTTPS (the QR uses your nexusID address, which is HTTPS) — browsers only allow camera access on a secure connection.
Face recognition requires your administrator to have enabled a face provider; if it's unavailable, contact your IT help desk.
Completing a challenge
When a sign-in needs verification, you'll be prompted for your authenticator code, passkey, or face on the challenge screen. Approve it to continue. For a face challenge on a device without a camera, choose Use your phone to scan a QR and verify from your phone — the desktop continues your sign-in automatically once it succeeds.
Recovery codes
Generate one-time recovery codes (/portal/recovery-codes) and store them somewhere safe. Use one if
you ever lose access to your authenticator.
Managing your profile
On Profile (/portal/profile) you can review and update your name, contact details, and preferences,
and see your linked identities and recent sign-in activity.
Changing your password
- Go to Change Password (
/portal/change-password). - Enter your current password, then your new password twice.
- Your new password must meet your organization's policy (length, complexity, history).
- Select Change Password.
In hybrid Microsoft environments, a password change here is also written back to your directory account so it stays in sync with the apps you use (this may take a short time to propagate).
Your applications
The Applications view (/portal/applications) lists the apps you can launch via single sign-on.
Select one to open it — you won't be asked to sign in again while your session is active.
Requesting access
Need access to something you don't have yet? Open Request Access (/portal/request-access). It has
three tabs:
- Access Packages — bundles of access (e.g. a "New Developer" package) you can request in one click.
- Roles — application roles you can request individually.
- Entitlements — single permissions from the catalog.
Pick an item, add a justification if prompted, and select Request. You'll get an email confirming the request, and another once it's approved or denied. Track everything under My Requests on the same page — each row shows Pending, Approved, or Denied. Approved access is granted automatically; you don't need to do anything else.
If a tab is empty, your organization hasn't published anything requestable there (or the feature isn't enabled on your plan) — ask your administrator.
Privacy & consents
Under Consents (/portal/consents) you can review which applications you've granted access to and
what information they receive, and revoke access you no longer want.
Signing out
Use Sign Out from the portal menu. For shared computers, always sign out when you're done.
Getting help
If you're locked out, can't complete MFA, or need a password reset, contact your organization's IT help desk — they can reset your password, unlock your account, or reset your MFA from the admin console.