To ensure our systems are compliant with the security standards recommended by the NCSC (National Cyber Security Centre), Multi-Factor Authentication will be implemented for the NIHR Research Delivery Network Central Portfolio Management System (CPMS) and the Open Data Platform (ODP) on Tuesday 4th July 2023.
For information on what this means and how to prepare for this change, please read the detailed information below
The information below can be downloaded as a PDF document to share with CPMS and ODP users.
To ensure our systems are compliant with the security standards recommended by the NCSC (National Cyber Security Centre), we are implementing Multi-Factor Authentication (MFA) when logging into the NIHR Research Delivery Network Central Portfolio Management System (CPMS) and the Open Data Platform (ODP).
This will mean when you log in, the email address associated with your account will be sent a One Time Passcode (OTP).
This change is due to be implemented on Tuesday 4th July 2023.
When you log into CPMS or ODP for the first time from Tuesday 4th July 2023, you will be shown a screen where you will need to input a One-Time Passcode.
The Passcode will be sent via email from identity@nihr.ac.uk and it will be valid for 15 minutes.
In order to finish logging into CPMS (or ODP), you will need to copy the six character Passcode into the box on the login screen and click the Authenticate button. Once you have been authenticated, you will be able to use CPMS (or ODP) as normal.
Once you have logged into the system with your Passcode you will not need to do so again for CPMS, or any other system connected to the NIHR's Identity Gateway including ODP, for another 30 days, providing that:
Your account is accessed from the same browser and device
You have not cleared your browser cookies/cache
You are not logging through a private/incognito window
You are not logged in via a new browser profile
You are not logged in with a different account
You are not logged in via a different browser
After 30 days, or if you clear the cookies in your browser, you will be sent a new Passcode which will be good for a new 30 day period.
If you are logging into CPMS and/or ODP using a Virtual Machine, you may be prompted to enter a new Passcode every time since VMs may not be able to save cookies that record your previous logins.
Ensure that you have access to the email inbox associated with your CPMS and/or ODP account and can easily retrieve the passcode once sent. The passcode will only be valid for 15 minutes.
If you do not receive the code within 15 minutes of signing in, please contact your local IT team and ask them to add identity@nihr.ac.uk to the allowed list on the local IT mail gateway.
You may also need to check your Spam folder, in case the email has been marked as “spam”.
If you have any questions or concerns about these changes or any trouble using the One-Time Passcode, please contact the helpdesk by emailing crn.servicedesk@nihr.ac.uk