Skip to content

Signing in to the portal

For everyone

The portal lives at /login. What you see there depends on what your trust has set up.

If your trust uses Microsoft 365, Google Workspace, or another identity provider, the sign-in page shows a row of buttons — one per provider. Click the one your IT team told you to use. You’ll bounce out to that provider’s familiar sign-in page, then back to Keystone.

If you’re already signed into your work email in this browser, the round trip is silent — you’ll land straight on the portal home page.

Some trusts run a directory (LDAP) or have set up local accounts. In that case you’ll see a username/email and password form. Fill them in and submit.

If you mistype your password a few times in a row, the account locks for a short period. There’s no public timer — when the lockout expires, sign-in just starts working again. If you’re locked out and need access urgently, contact IT.

A fresh install with no identity provider configured shows a dev mode form that accepts any email address. That’s deliberate — it lets a system administrator get into the wizard to wire up real sign-in. If your production trust has slipped into this mode, contact IT immediately; the data is unprotected until they finish configuration.

There’s no “forgot password” link, because for most users your password is held by Microsoft, Google, or your school’s directory — not Keystone. Reset it where it lives. If you’re on a local account, ask IT to reset it for you.