Skip to main content

News / Views / Clues


CALPADS Security Update

Multifactor Authentication Begins September 15 in CALPADS

Beginning September 15, 2026, all CALPADS users will be required to use multifactor authentication (MFA) when signing in.

Key dates

  • August 25–September 14: Users may activate MFA early by selecting the Activate MFA button when signing in.
  • Beginning September 15: MFA is required for all CALPADS users.

What this means for CALPADS users

MFA adds a second identity check to the CALPADS sign-in process. After entering a CALPADS username and password, the user will receive a code at the email address associated with that CALPADS User ID. The user must enter the code before CALPADS will complete the sign-in.

Each CALPADS account should be associated with a person-specific, non-generic email address, as required by the CALPADS Terms and Conditions. LEAs should make sure users can access the email account connected to their CALPADS User ID.

When CALPADS will request MFA

Users should expect an MFA prompt:

  • At the next sign-in after using the CALPADS Sign Out function
  • After browser storage, cookies, or site data have been cleared
  • When signing in with a different browser or device
  • Once each day if none of the conditions above occurs

Why CALPADS is making this change

CALPADS upgraded its authentication system on March 10, 2026, to support MFA and strengthen protection for student and staff data. The first phase required users to establish new usernames and passwords. The September 15 MFA requirement begins the second phase by adding email verification to the sign-in process.

Training and assistance

CSIS has published a short training video and an MFA video playlist for CALPADS users:

If an LEA experiences problems with MFA, use one of the following support methods:

Important: Delete bookmarks to the old service-request form, and submit each request through only one support method to avoid duplicate work.