---
title: "What can I do as an LEA Staff Help Desk user in NCEdCloud?"
slug: "what-can-i-do-as-an-lea-staff-help-desk-user-in-ncedcloud"
updated: 2026-07-29T12:16:06Z
published: 2026-07-29T12:16:06Z
canonical: "docs.ncedcloud.org/what-can-i-do-as-an-lea-staff-help-desk-user-in-ncedcloud"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ncedcloud.org/llms.txt
> Use this file to discover all available pages before exploring further.

# What can I do as an LEA Staff Help Desk user in NCEdCloud?

The **LEA Staff Help Desk** role allows approved staff to assist employee accounts within the LEA or PSU scope granted to them. This role does not provide access to student accounts.

## **Request the role**

1. Sign in to the NCEdCloud IAM Service at [my.ncedcloud.org](https://my.ncedcloud.org).
2. Open the module menu and select **Requests**.
3. Expand **Entitlements** in the left navigation and select **Catalog**.
4. Search for **LEA Staff Help Desk**.
5. Select the role, then select **Request**.
6. Enter your code in **PSU / CHARTER CODE (ALL CAPS)**. The screenshot below uses `ABC` only as an example.
7. Add request comments if needed, then select **Request**.

The request is sent to an NCEdCloud LEA Administrator for approval. After the role is granted, open **People** and check for the new delegation. If it does not appear in your current session, sign out and sign back in.

![Select LEA Staff Help Desk in the Requests catalog](https://cdn.document360.io/eb543933-4fe1-4b70-9680-59c16f2a6598/Images/Documentation/lea-staff-help-desk-01-request-catalog(1).png)

![Enter the LEA or PSU scope for the request](https://cdn.document360.io/eb543933-4fe1-4b70-9680-59c16f2a6598/Images/Documentation/lea-staff-help-desk-02-request-scope.png)

## **Access staff accounts**

After the role is granted:

1. Open the application menu and select **People**.
2. Select **Help Desk for Employees**.
3. Search for the staff account you need to assist.
4. Select the correct account before performing an action.

Search results are limited to staff accounts in the LEA or PSU scope granted to you. Only active employee accounts in that scope are included.

## **Available actions**

The **Help Desk for Employees** view provides these actions:

- **Change Password** — set a new password for the selected staff account.
- **Update Challenge Responses** — reset the selected staff member's saved challenge responses.
- **Reset TOTP** — clear the selected staff member's TOTP registration so they can set it up again at their next sign-in.
- **Edit Profile** — view or update only the profile fields made available to this role.
- **Manage WebAuthn** — view or add WebAuthn devices for the selected staff account.
- **Delete WebAuthn** — remove an existing WebAuthn device from the selected staff account.

The actions displayed can depend on the selected account and its current state.

## **Scope and limitations**

- Access is limited to staff accounts in the approved LEA or PSU scope.
- The role does not provide access to student accounts.
- It does not provide student QR-code or Pictograph actions.
- It cannot delete a staff account. **Delete WebAuthn** removes a registered WebAuthn device, not the person's NCEdCloud account.
- Always confirm that you selected the correct staff account before making a change.

## **Remove the role**

To remove your own LEA Staff Help Desk access:

1. Open **Requests**.
2. Select **Entitlements**, then **My Entitlements**.
3. Locate the LEA Staff Help Desk entitlement for the scope you no longer need.
4. Select **Revoke**.

If you have the role for more than one scope, revoke only the entitlement for the scope you no longer support.

For additional request and revoke guidance, see [Privileged Roles](/docs/privileged-roles).

## **Related guidance**

- [How do I change someone's password?](/docs/how-do-i-change-someones-password)
- [How do I reset someone's challenge question responses?](/docs/how-do-i-reset-someones-challenge-question-responses)
- [TOTP FAQ](/docs/totp-faq)
- [How to enable WebAuthn](/docs/how-to-enable-webauthn)
