CALPADS Login¶
The CALPADS “Login” page allows an authorized user, who has been assigned a User ID and Password, to log in to CALPADS. The role(s) assigned to users determine which interface the user has permission to access and which functions the user has permission to perform. The user system roles and system access levels are set according to the CDE specifications and are assigned to each user by a system administrator. The user may use the Forgot your Password link to retrieve his/her password. Upon successful login, the CALPADS “Home Page” is displayed, allowing the user to navigate to specific applications throughout CALPADS.
The system also uses multi-factor authentication (MFA) to verify a user’s identity during the login process (See MFA Training Video). MFA adds an additional layer of security to protect CALPADS data from unauthorized access. However, MFA is not required everytime a user attempts to login due to a 24-hour Conditional Access window. But, even if the 24-hour Conditional Access window has not expired, certain user actions or technical events break the trust established by Entra, forcing an immediate MFA prompt.
These triggers include:
Explicit Logout:
- Action: The user clicks "Sign Out" within an enterprise application or the Microsoft 365 portal.
- Result: Entra revokes the active session tokens on the server side, terminating the 24-hour grace period instantly.
Clearing Browser Cookies and Cache:
- Action: The user (or an automated script, privacy extension, or browser policy) clears local browser storage, cookies, or site data.
- Result: Entra session cookies (which prove the user has already satisfied the MFA requirement) are deleted. Without these cookies, Entra cannot validate the existing session and demands a new MFA code.
Changing Browsers or Devices:
- Action: The user authenticates in Google Chrome, and then attempts to access the resource using Microsoft Edge, Safari, or a different device.
- Result: Entra session tokens and Primary Refresh Tokens (PRTs) are strictly bound to the specific device and browser profile context. A new browser environment lacks the necessary cryptographic identifiers, triggering a fresh MFA challenge.
Login for existing user accounts¶
Step 1. Go to the CALPADS login page (https://www.calpads.org/). Click on Sign in.
Step 2. Enter provided username (username@calpads.org). Click on Next.
Step 3. Enter password. Click on Next.
Step 4. The multi-factor authentication will require the verification of your identity. Click on the "Email code to username@calpads.org box. CALPADS will send a verification code to the user's email address.
Step 5. Copy the provided account verification code from the received email.
Step 6. Return to the log in page and paste code. Click on verify.
Step 7. Indicate preferrence to stay signed in and wether or not the pop-up message appears in future sign ins.
Step 8: Read and Accept Terms and Conditions.
Review and accept the User Agreement.
Step 9: User is directed to Homepage.
Once the User Aggrement has been accepted, the user is then directed to the CALPADS Homepage. User should be able to see the Organization associated with (A) as well as the Username (B).
Login for new user accounts¶
Step 1: Receive Email Notification of Account
New User receive email notification that a CALPADS account has been created for the California Department of Education's CALPADS system. It includes the created user name and temporary password.
Step 2: First-time Log in
Go to the CALPADS login page (https://www.calpads.org/). Click on Sign in.
Enter provided username (username@calpads.org)
Enter provided temporary password.
Update temporary password to preferred password.
Indicate preferrence to stay signed in and wethere or not you this message appears in future sign ins.
Step 3: Read and Accept Terms and Conditions
Review and accept the User Agreement.
Step 4: User is directed to Homepage
Once the User Aggrement has been accepted, the user is then directed to the CALPADS Homepage. User should be able to see the Organization associated with (A) as well as the Username (B).














