NCEdCloud Revoke Role — How to Remove Admin Roles From User Accounts
What is the NCEdCloud Revoke Role Process?
NCEdCloud revoke role is the action an LEA Administrator takes to remove an administrative permission from a user’s account. For example, removing the School Help Desk role from a staff member who has transferred to a different school or left the district. NCDPI’s RapidIdentity platform applies role changes immediately when saved.
This applies to all admin roles across all 115 NC school districts. The most important thing to know is that revoking a role removes only that elevated permission. The user’s standard NCEdCloud account and login remain active. If you also need to deactivate the account entirely, that is a separate action.
When to Revoke an NCEdCloud Admin Role?
Revoke admin roles in these situations:
- Staff member leaves the district or school
- Staff member changes position and no longer needs the Role
- The Role was assigned incorrectly
- Staff members’ access privileges need to be reduced for policy or compliance reasons
- Annual access review identifies accounts with unneeded elevated permissions
Regular access reviews — at least once per semester — are a best practice for managing admin role assignments across the LEA.
How to Revoke an NCEdCloud Role?
- Log in to ncedcloud.mcnc.org with your LEA Administrator credentials.
- Navigate to the admin console and open User Management.
- Search for the staff member by name or username.
- Open their account profile.
- Navigate to the Roles or Permissions section.
- Locate the Role to be removed and click the revoke or remove button next to it.
- Confirm the removal when prompted.
- The Role is removed immediately.
The staff member loses the elevated access immediately. They can still log in with their standard account.
NCEdCloud Revoke Role vs. Disable Account
| Action | What It Does | When to Use |
| Revoke Role | Removes elevated permission; account stays active | Staff changes position; role no longer needed |
| Disable Account | Prevents all login; account is inactive | Staff leaves the district; the account should be fully deactivated |
Verifying the Role Was Removed
After revoking a role, verify the change by opening the user’s account profile and confirming the Role no longer appears in the Roles or Permissions section. If the Role still shows after saving, refresh the page and check again. Contact NCDPI support if the Role persists after multiple attempts to remove it.
Frequently Asked Questions
Does revoking an admin role in NCEdCloud log the user out immediately?
Role changes take effect immediately at the system level, but the user’s active session may continue until it expires or they log out. For security-sensitive role removals, notify the user or ask them to log out and back in, so the session refreshes with the updated permissions.
Can a revoked role be re-granted later?
Yes. Role revocation is reversible. The staff member can resubmit a role request through the Requests module, or the LEA Administrator can re-assign the Role directly from the admin console. Previous approval history does not carry over — the new assignment is treated as fresh.
Who can revoke admin roles in NCEdCloud?
Only LEA Administrators can revoke admin roles. Help desk staff and data auditors cannot modify role assignments on other accounts. If the LEA Administrator account itself needs to be modified, another LEA Administrator must make the change.
What happens to work done by a user after their Role is revoked?
Revoking a role does not delete or modify any data the user created or modified while they held the Role. Password resets, role approvals, and account changes they performed are preserved in the system. The revocation only affects future access.
Should I revoke roles before or after deactivating an account for a departing employee?
Revoke the Role first, then deactivate the account. This order ensures the Role is clearly documented as removed in the audit log before the account is deactivated. Both steps should be completed on or before the employee’s last day.
Related Reading
NCEdCloud Disable Account Guide (/ncedcloud-disable-account/)
NCEdCloud Approve Role Guide (/ncedcloud-approve-role/)
NCEdCloud Request Role Guide (/ncedcloud-request-role/)
NCEdCloud LEA Administrator Role Overview (/ncedcloud-lea-administrator/)
NCEdCloud Data Files and Sync Guide (/ncedcloud-data-files/)







