Frequently Asked Questions
Find your most commonly asked questions, here.
General
For step-by-step instructions on how to use the IDM system, go to the IDM User Guide.
Most questions can be answered with the information on this page. If you need further assistance, you can find your Application Help Desk here.
MFA requirements are determined by your sign-in method.
If you use ID.me:
MFA is managed within your ID.me wallet, not IDM.
For instructions on how to enable MFA devices, go to ID.me Multi-Factor Authentication page.
If you use Login.gov:
MFA is managed within your Login.gov account, not IDM.
For instructions on how to enable MFA devices, go to the Login.gov Authentication Methods page.
If you use CMS Enterprise User Administration (EUA) or IDM credentials:
You can configure MFA devices directly in IDM. MFA options include:
- E-mail (slower delivery time)
- SMS (text message)
- IVR (phone call)
- Google Authenticator (browser extension or smart phone app)
- OKTA Verify (smart phone app)
- Yubikey (hardware security key)
Note: To add Google Authenticator, Okta Verify, and YubiKey as an MFA, please refer to the IDM User Guide.
For step-by-step instructions on how to perform ARC for manually approved roles, please refer to the Annual Role Certification Quick Reference Guide.
Signing In
A CSP is a trusted external service that allows you to securely sign in to IDM using an existing account or create a new account. You can also create a CSP account from the login page. IDM supports CSPs such as Login.gov to provide a secure, streamlined sign-in experience.
When using a CSP, you authenticate through the provider (e.g., Login.gov or ID.me) instead of entering your IDM User ID and password directly.
CSP credentials are used to sign into applications that are external to CMS. External applications are designed for use by the general public, healthcare providers, beneficiaries, insurers, or other external partners outside of CMS.
At this time, CSP credentials cannot be used to sign in to applications that are internal to CMS. Internal applications require a workforce ID (EUA ID), and are designed for use by CMS employees, contractors, and other authorized federal/state agency personnel who operate within the CMS Network environment.
CSPs are leveraged by multiple government agencies, including the Department of Veterans Affairs (VA), Social Security Administration (SSA), and the Internal Revenue Service (IRS).
CSPs in government offer secure identity proofing credential issuance, and authentication, resulting in reduced fraud, enhanced security, and an overall better user experience. CMS uses trusted CSP partners to keep your account secure and reduce the number of accounts and passwords for our users.
If you do not already have a Login.gov account or an ID.me wallet, you'll be guided to create one during sign-in. You only need to create a CSP account once. Once that is done, you will use the same email address and password, plus one of the two-factor authentication methods you set up, every time you sign into IDM.
Yes, once created, your CSP credentials can be used across participating government agencies.
Option 1: PIV Card
Within CMS, a Personal Identity Verification (PIV) card is a secure, federally issued smart card that is used by employees and some contractors for physical access to buildings and logical access to IT systems. It acts as a high-assurance ID credential ensuring both physical and digital security compliance.
NOTE: PIV Cards can only be used with your EUA ID.
To enable PIV as a login option on the Enterprise Login page, EUA users must first sign in (once) with their four-character EUA ID and password. For instructions, please see the section below EUA or IDM User ID & Password. After a successful sign in with an EUA ID and password, you will be able to leverage your CMS PIV Card for subsequent sign-ins using the steps below.
- Click Continue on the Personal Identity Verification tile on the Sign In Page.
- Follow the online instructions.
Option 2: ID.me
Users of CMS systems and applications should use ID.me credentials to sign in. If you already have an existing ID.me wallet, click Continue within the ID.me tile on the Enterprise Login page, and follow the instructions on the ID.me Sign-In Guide page.
If you do not have an ID.me wallet, you will need to create one. To create an ID.me wallet, complete the following, click Continue within the ID.me tile within the Enterprise Login page and follow the instructions on Create your ID.me Wallet page.
Option 3: Login.gov
Users of CMS systems and applications should use Login.gov credentials to sign in. If you already have existing Login.gov credentials, click Continue on the Login.gov tile on the Sign In page, and follow the instructions on the Login.gov Sign-In Help page.
If you do not have a Login.gov account, you will need to create one. To create a Login.gov account, click Continue within the Login.gov tile on the Enterprise Login page, and follow the instructions on the Login.gov Create Account page.
Option 4: EUA or IDM ID & Password
Users can sign in using either their EUA or IDM User ID. Access to different applications and functionalities is based on which ID they use to sign into the system. EUA IDs are used to sign into applications that are internal to CMS and require a workforce ID (EUA ID). Internal applications are designed for use by CMS employees, contractors, and other authorized federal/state agency personnel who operate within the CMS network environment.
IDM IDs (as well as CSP credentials) are used to sign into applications that are external to CMS. External applications are designed for use by the general public, healthcare providers, beneficiaries, insurers, or other external partners outside of CMS.
EUA or IDM ID & Password
- Click Continue within the EUA or IDM User tile on the Enterprise Login page.
- Enter your EUA or IDM User ID and Password and click Sign In.
- If a Multi-Factor Authentication is required, select the Multi-Factor Authentication option you wish to use and follow the subsequent prompts.
For further instructions on signing in, download the CMS User Guide PDF on theCMS Documentation User Guides page.
ID.me Users
If you are locked out of your ID.me wallet, you'll need to recover access directly through ID.me. Visit the Unlock your ID.me Wallet page for step-by-step instructions or for other troubleshooting topics, go to ID.me Help Center .
IDM and Application Help Desks cannot unlock ID.me wallets. If you continue to experience issues, contact ID.me Contact Support for assistance.
Login.gov Users
If you are locked out of your Login.gov account, please wait 10 minutes and try again by clicking Continue within the Login.gov tile on the Enterprise Login page. If you cannot access the email linked to your account, please go to Login.gov Account Access and Recovery for assistance to recover your Login.gov account.
IDM and Application Help Desks cannot unlock Login.gov accounts. If you continue to experience issues, contact Login.gov Support for assistance.
CMS EUA Users
For users who login to IDM with their EUA credentials, please wait 60 minutes for your account to automatically unlock.If you need further assistance, please contact the CMS IT Service Desk at (800) 562-1963 or (410) 786-2580 or via email CMS_IT_SERVICE_DESK@cms.hhs.gov.
IDM User ID and password users
Users who login to IDM with their User ID and password will be automatically redirected to the Unlock Account page, if their account is locked. You can also access the Unlock Account page by selecting the Unlock IDM Account link at the bottom of the EUA or IDM User ID Sign In page. Additionally, if you wait 60 minutes, your account will unlock automatically.
To use the Self-Service feature you must meet the following conditions:
- You must remember the answer to the Security Question and Answer (SQA) that was generated when you created your account.
- You must have at least one recovery device registered and active in your user profile. A recovery device is an MFA device that is used to authenticate the user during the recovery process.
- You must also have the MFA device(s) with you when you unlock your account.
If you do not meet these conditions, you will not be able to use the self-service Account Unlock feature and must contact your Application Help Desk to have your account unlocked.
Once the above conditions are met, please use the following steps to unlock your account:
- Click the Unlock IDM Account link and the Unlock Account window will display.
- Enter your User ID and select your MFA device.
- Follow the online instructions.
Passwords
ID.me Users
If you sign in using ID.me, you must change your password through ID.me. Visit the Sign In & Security section of the ID.me Manage Your Wallet page. IDM does not manage ID.me passwords.
If you continue to experience issues, contact ID.me Help Center for assistance.
Login.gov Users
If you sign in using Login.gov, you must change your password through Login.gov. Visit the Login.gov Change My Password for full instructions. IDM does not manage Login.gov passwords.
If you continue to experience issues, contact Login.gov Support for assistance.
CMS EUA Users
EUA users must change their password within the EUA system. To change your EUA password, use the following steps:
- Navigate to the EUA Login Page and provide your EUA ID and password.
- Click Change My Password on the EUA Landing page.
- Select the Change My Password button.
- Follow the online instructions.
Users who login with an IDM User ID and password
IDM users can only change their own password once per 24-hour period using the self-service feature. If you require another password reset within the same 24-hour period, you must contact your Application Help Desk for assistance.
To reset the password for your IDM User ID:
- Click Continue within the EUA or IDM User ID tile on the Enterprise Login page.
- Enter your User ID and password and click Sign in.
- Complete the MFA challenge.
- Click the My Profile tile on the IDM Dashboard.
- Click Change Password on the My Profile page.
- Follow the online instructions.
ID.me Users
If you sign in using ID.me, you must change your password through ID.me. For full instructions, visit the ID.me Reset Your Password page. IDM does not manage ID.me passwords.
If you continue to experience issues, contact ID.me Help Center for assistance.
Login.gov Users
If you sign in using Login.gov, you must change your password through Login.gov. For full instructions, visit the Login.gov Forgot Password Guide help page. IDM does not manage Login.gov passwords.
If you continue to experience issues, contact Login.gov Support for assistance.
CMS EUA Users
EUA users must change their password within the EUA system. To change your forgotten EUA password, use the following steps:
- Navigate to the Forgot Password Reset page.
- Enter your User ID and verify your identity by answering the question to your Password Hint.
- Follow the online instructions to create a new password.
Users who log in with an IDM User ID and password
You can reset your password by using the Self-Service feature, which is located at the bottom of the EUA or IDM Sign In page. Please note, users can only change their own ID and password once per 24-hour period using the Self-Service feature.
Users must meet the following conditions:
- You must remember the answer to the Security Question and Answer (SQA) that was generated when you created your account.
- You must have at least one recovery device registered and active in your user profile. A recovery device is an MFA device that is used to authenticate the user during the recovery process.
If you do not meet these conditions, you will not be able to use the Self-Service feature and must contact your Application Help Desk.
Once the above conditions are met, please use the following steps to reset your password:
- Click Continue within the EUA or IDM User ID tile on the Enterprise Login page.
- Click on the Forgot IDM password link, and the Reset password window will display.
- Enter your User ID and click Sign in.
- Complete the MFA challenge.
- Answer the SQA.
- Follow the online instructions to create a new password.
If you continue to experience issues, contact your Application Help Desk for assistance.
ID.me Users
ID.me passwords do not expire in the same way IDM passwords do. For full instructions, visit the ID.me Password Reset page.
If you continue to experience issues, contact ID.me Support for assistance.
Login.gov Users
Login.gov passwords do not expire in the same way as IDM passwords do. For full instructions, visit the Login.gov Password Help page. If you continue to experience issues, contact Login.gov Support for assistance.
CMS EUA Users
When your password expires, you must contact the CMS IT Service Desk at (800) 562-1963 or (410) 786-2580. The CMS ID Service Desk will provide instructions on how to update your password.
Users who log in with an IDM User ID and password
When you attempt to log in to the IDM system with an expired password, the IDM Self-Service window will display to notify you that your password has expired. You must enter your old password, then follow the online instructions.
CMS Enterprise Portal
The CMS Enterprise Portal now uses the CMS Enterprise Login Page for authentication. This is a centralized login experience designed to streamline access to CMS applications and systems. Portal users will be redirected to the Enterprise Login page automatically when you attempt to log into your application from the CMS Enterprise Portal. Your access and permissions remain the same— only the login experience has changed.
You may have heard the term “Portal ID” used when referring to the credentials you use to log in to the CMS Enterprise Portal. While this term is commonly used by users, the official name for this credential type is an “IDM ID”. The CMS Identity Management (IDM) system is the enterprise-level service that sits behind the CMS Enterprise Portal UI, providing identity verification and authentication services.
The login option for Portal users who now authenticate via the Enterprise Login page depends on whether you are a new user or an existing user:
New Users:
Create or use an existing Credential Service Provider (CSP) account (Login.gov or ID.me) for first-time access.
Existing users:
Existing users have two sign-in options:
- Use an Existing IDM ID: Returning users can use their CMS IDM ID and password to login. For more information on how to sign in, please refer to the “Signing In” section on this page.
- Link a CSP Account to your IDM ID: To link your IDM ID with your CSP account, sign in with your CSP credentials. If an existing IDM account with profile attributes that match your CSP account (e.g., email address or Social Security Number), you will be prompted with the option to link that existing IDM account to your CSP credential. For more information on account linking, please refer to the “Account Linking” section on this page.
Account Linking
Account linking is an IDM feature that allows you to map multiple CSP credentials — such as Login.gov and ID.me — to a single IDM account. Once linked, all credentials are the same access permissions, meaning you can sign in using any of your linked credentials and still access the same resources.
Users are prompted with the option to link an existing IDM account to a CSP credential after signing in with that CSP. The system automatically checks if any existing IDM accounts contain profile attributes (e.g., email address or Social Security Number) that match your CSP profile. If a match is found, you will be prompted with the option to link your incoming CSP credential to that existing IDM account.
When prompted, follow these steps:
- After signing in with your CSP, if a matching account is found, you will see a notification indicating an existing account was identified.
- Click Start linking new Sign-in option to begin the linking process.
- Select and complete the sign-in process for the existing account you wish to link.
- Review the comparison of profile attributes that will be updated. Click Confirm and link to complete the process or Cancel account linking and continue to IDM home if you do not wish to proceed.
Note: Once linked, your IDM profile attributes, like your email address, will be inherited from your CSP credential. They cannot be directly changed in IDM; they must be changed in the CSP. - Once linking is complete, click Continue to IDM Home on the final confirmation page. The application name shown here may vary depending on which application you were originally trying to access.
When you confirm the account link, the profile attributes of your existing IDM account will be overwritten by the profile attributes from your incoming CSP credential.
Important: This action is permanent and cannot be undone. Please carefully review the attribute comparison screen before clicking Confirm and link.
If the system indicates that your login account has already been linked to a different IDM account, you have two options:
- Click Sign in using a different account to attempt linking your CSP credential to a different IDM account.
- Click Cancel account linking and continue to Okta dashboard to return to the sign-in page and sign in using a different method; this option cancels the linking process entirely.
Yes, at any point during the linking process, you may click Cancel account linking and continue to IDM Home (or Cancel account linking and continue to Okta Dashboard) to stop the process. The exact button label may vary depending on the application you’re accessing. No changes will be made to your account if you cancel.
After successfully linking your credentials, you will be redirected to the application you were originally trying to access. From this point forward, you can sign in using your linked CSP credentials (Login.gov and/or ID.me) or your IDM credentials and access the same account with the same permissions.