This page is part of NCEdCloudPro.com, an independent resource for North Carolina’s NCEdCloud platform. We are not affiliated with NCDPI, NCEdCloud, MCNC, or Identity Automation. Read our full disclaimer.
NCEdCloud LEA Administrator Roles, Requests, and Responsibilities
The NCEdCloud LEA Administrator is the highest-privilege role available within a Public School Unit (PSU) on the NCEdCloud platform. LEA Administrators manage user accounts, approve or deny requests for other privileged roles, configure district-wide settings, submit opt-in requests for platform features, and serve as the primary contact between the district and Identity Automation support.
For a brand-new PSU, such as a newly opened charter school, the very first LEA Administrator request is vetted directly by NCDPI before it’s granted; after that, an existing LEA Administrator approves future requests within their own PSU.
What is the LEA Administrator Role?
The LEA Administrator is a privileged account role assigned to district-level IT staff or designated administrative personnel, most commonly a Technology Director, CTO, principal, or assistant principal. It provides management authority over user accounts and settings across an entire LEA or PSU. Most districts have one primary LEA Administrator, though larger districts often maintain several.
This role is distinct from school-level roles. An LEA Administrator can act across every school within the district, while roles like School Help Desk and School Student Help Desk are scoped to a single campus.
Because privileged roles have access to student and employee data, NCDPI requires Multi-Factor Authentication for every LEA Administrator account, along with every other privileged role. This has been mandatory statewide since 2019, not an optional setting an administrator turns on.
How to Request the LEA Administrator Role?
The request happens inside the NCEdCloud platform itself, not through a separate support ticket:
- Log in at my.ncedcloud.org and click the dropdown arrow next to Applications.
- Select Requests, then go to Entitlements or Catalog.
- Choose LEA Administrator from the list of privileged roles and click Request.
- Enter your three-digit LEA code (charter school codes end with a letter).
- Submit the request.
What happens next depends on whether your PSU already has an LEA Administrator. If this is the very first LEA Administrator request for a new PSU, such as a newly opened charter school, NCDPI vets and grants the request directly. If your PSU already has an LEA Administrator, that person reviews and approves the request instead, the same way they’d approve any other privileged role request.
If a current LEA Administrator is leaving the district, they should coordinate a successor’s request before their own account is deactivated, so the PSU isn’t left without anyone able to approve requests or manage accounts.
What LEA Administrators Can Do?
LEA Administrators have broad authority across NCEdCloud for their PSU. Their capabilities include:
Account Management:
- View, search, and manage all user accounts within the LEA
- Enable and deactivate individual accounts
- Unlock locked accounts
- Reset passwords for any user in the LEA
- Regenerate student passwords in bulk
Role Management:
- Approve or deny requests for privileged roles submitted through the Requests module
- Assign the five roles below LEA Administrator: LEA Data Auditor, LEA Help Desk, LEA Student Help Desk, School Help Desk, and School Student Help Desk
- Immediately disable an account if a security concern arises; removing another user’s privileged role specifically, as opposed to disabling their account, requires a support ticket with Identity Automation rather than a simple in-platform revoke
Opt-In Features:
- Submit requests to opt in to Target Applications and other district-wide opt-in features
- Coordinate MFA rollout decisions for general staff and student accounts, separate from the MFA requirement that already applies to privileged-role holders themselves
Application Management:
- Work with Identity Automation to configure and troubleshoot application SSO integrations
- Assign applications to user groups or individual accounts
Reporting and Data:
- Access data files showing account status and sync information
- Review roster sync logs from PowerSchool and Home Base
- Identify accounts that haven’t synced or provisioned correctly
How the Requests Module Works?
NCEdCloud includes five privileged roles below LEA Administrator. The LEA Administrator approves and can effectively remove access for all of them.
Role | Scope | Can Reset Passwords For |
LEA Data Auditor | Entire PSU | View-only; no password reset |
LEA Help Desk | Entire PSU | All users |
LEA Student Help Desk | Entire PSU | Students only |
School Help Desk | Single school | All users at that school |
School Student Help Desk | Single school | Students only at that school |
The LEA Data Auditor role is aimed at data coordinators and managers who need to view account and data information across the PSU without the ability to make changes. Help Desk roles are the most commonly assigned, typically to IT staff, front office personnel, and school registrars.
Related Admin Roles
NCEdCloud includes six admin roles below the LEA Administrator level. The LEA Administrator is responsible for assigning and revoking all of them.
Role | Scope | Can Reset Passwords For |
LEA Administrator | Entire LEA | All users |
LEA Data Auditor | Entire LEA | View-only; no password reset |
LEA Help Desk | Entire LEA | All users |
LEA Student Help Desk | Entire LEA | Students only |
School Help Desk | Single school | All users at that school |
School Student Help Desk | Single school | Students only at that school |
The LEA Data Auditor role can access account and data information but cannot make changes. It is suited for data verification and compliance use cases. The Help Desk roles are the most commonly assigned and are typically given to IT staff, front office personnel, and school registrars.
Data Files and Reporting
LEA Administrators can pull data file exports from within the NCEdCloud platform. These files contain account-level information for the PSU, including provisioning status, role assignments, and sync timestamps. They’re useful for:
- Auditing which accounts have been claimed and which are still unclaimed
- Identifying sync errors between PowerSchool or Home Base and NCEdCloud
- Verifying that departing staff accounts have been deactivated
- Reviewing MFA enrollment status across privileged and general accounts
For automated reporting or integration with other district systems, contact Identity Automation support directly for available options.
Contacting Identity Automation Support
LEA Administrators are the primary PSU contact for escalated NCEdCloud issues. When something can’t be resolved through the platform’s built-in tools, such as a bulk provisioning failure, an application SSO integration error, or removing another user’s privileged role, the LEA Administrator opens a support ticket with Identity Automation, typically through the Customer Support Community accessible from the Applications menu.
Support resources available to LEA Administrators include the official NCEdCloud IAM Service documentation at ncedcloud.mcnc.org, Identity Automation’s Customer Support Community, and NCDPI’s channels for policy-level questions.
School-level staff and students should always contact their own school’s help desk first. LEA Administrators handle the escalations school-level staff can’t resolve.
Frequently Asked Questions
What is an NCEdCloud LEA Administrator?
The NCEdCloud LEA Administrator is the highest-privilege role within a PSU. They manage user accounts, approve privileged role requests, configure district settings, and serve as the primary contact for Identity Automation support.
How do I become an NCEdCloud LEA Administrator?
Request the role through the Requests module after logging in at my.ncedcloud.org. If your PSU already has an LEA Administrator, they approve the request. If it’s the very first request for a new PSU, such as a new charter school, NCDPI vets and grants it directly.
Can an LEA Administrator reset any password in the district?
Yes. LEA Administrators, along with LEA Help Desk users, can reset passwords for any account within their PSU, including staff and student accounts across every school.
What is the difference between LEA Administrator and LEA Help Desk?
Both operate at the full-PSU scope, but the LEA Administrator has additional capabilities: approving privileged role requests, managing opt-in features, accessing data files, and contacting Identity Automation support directly. LEA Help Desk is limited to account lookups and password resets.
What is the Requests module in NCEdCloud?
The Requests module is the in-platform workflow tool, found under the Applications dropdown, where users submit privileged role requests using their LEA or Campus code. LEA Administrators review, approve, or deny these requests.
How do I assign the School Help Desk role to a staff member?
The staff member submits the request themselves through Requests, entering their six-digit Campus Code. An LEA Administrator then approves it from their Tasks and Approvals queue, which activates the role.
What happens if an LEA Administrator leaves the district?
A departing LEA Administrator should coordinate with a successor to submit their own LEA Administrator request before the departing administrator’s account is deactivated, so someone remains able to approve requests. If a PSU is left with no LEA Administrator, contact NCDPI directly.
What can an LEA Data Auditor do in NCEdCloud?
The LEA Data Auditor can view account information, provisioning status, and data files across the PSU, but can’t make changes: no password resets, no role approvals, and no account modifications. It’s a read-only role.
