IdExchange 1.9.1

Programming a badge with the HID CMS

This procedure guides you through programming a credential card for an existing user in the HID Credential Management System.

Prerequisites Checklist

Before beginning this procedure, ensure you have:

  • [ ] Access to the ActivID Credential Management System with Device Issuance privileges

  • [ ] Valid login credentials for the system

  • [ ] A compatible card reader connected to your computer (e.g., OMNIKEY CardMan 3x21)

  • [ ] Card reader drivers properly installed

  • [ ] A card ready for programming

  • [ ] The user's information (at minimum their last name for search purposes)

  • [ ] Knowledge of which device policy to apply

Step 1: Access the ActivID Credential Management System

  1. Open your web browser and navigate to the CMS portal URL:

  2. Log in with your authorized credentials.

  3. On the Welcome screen, review your last logon information and failed attempt count displayed at the bottom of the page.

  4. Click the Device Issuance tab in the top navigation bar.

Expected Result: The Device Issuance page loads, displaying options for new users and existing users.

Step 2: Search for the User

  1. In the User Search section, locate the search criteria fields.

  2. In the Last Name field, ensure the dropdown is set to starting with.

  3. In the text field next to Last Name, enter the user's last name (e.g., "Franecki").

  4. In the From groups: section, select the appropriate group(s) by checking the corresponding boxes:

    • Check ActiveDirectory if searching Active Directory users

    • Check other groups as needed based on your organization's structure

  5. In the Advanced Search section, ensure All users is selected (this is typically the default).

  6. In the Limit number of results to field, verify the value is set appropriately (default is 99 users).

  7. Click the Search button.

Expected Result: The system displays search results showing all users matching your criteria. The results include User ID, First Name, Last Name, and Email Address columns with user links.

Step 3: Select the User for Card Issuance

  1. Review the search results table to locate the correct user.

  2. Click on the user's User ID link (e.g., "Jessie39-A") in the search results.

Expected Result: The system navigates to the "Issuance to [Username]" page, displaying the user's information including their User ID, First Name, Last Name, Email Address, and photo.

Step 4: Configure Issuance Settings

  1. Review the user information displayed at the top of the page to confirm you have selected the correct user:

    • User ID

    • First Name

    • Last Name

    • Email Address

    • Photo

  2. In the section "2. Select the action you want to perform:", select the Local Issuance radio button.

  3. In the section "3. Choose the device reader for issuance:", click the dropdown menu.

  4. Select your connected card reader from the list (e.g., "ActivClient:OMNIKEY CardMan 3x21 0").

  5. Read the instruction in section "4. Insert the device to issue in the reader and click Next."

Expected Result: The form shows Local Issuance selected with your card reader device chosen.

Step 5: Insert the Card To Be Programmed

  1. Obtain the card that will be programmed.

  2. Insert the card fully into the selected card reader.

  3. Ensure the card is properly seated in the reader (you should feel it click into place).

  4. Click the Next button at the bottom of the page.

Expected Result: The system advances to the "Information Gathering" page, which displays device policy and PIN configuration options.

Step 6: Configure Device Policy and PIN

  1. In the section "1. Select the device policy for the device:", review the dropdown menu.

  2. Select the appropriate device policy from the dropdown (e.g., "Programming Policy").

  3. In the section "2. Choose a PIN for the device:", locate the Choose a PIN field.

  4. IMPORTANT: Instruct the applicant to create and enter their PIN in the field provided.

    • The PIN should only be known by the applicant

    • The PIN will be masked with dots for security

  5. In the Confirm the PIN: field, have the applicant re-enter the same PIN to confirm.

  6. Verify that both PIN fields display masked characters (dots).

  7. Review the instruction in section "3. Click Next to personalize the device."

Expected Result: Both PIN fields are filled with masked characters, and the device policy is selected.

Step 7: Begin Card Personalization

  1. Verify that all information is correct:

    • Device policy is properly selected

    • PIN has been entered and confirmed by the applicant

  2. Click the Next button at the bottom of the page.

Expected Result: The system navigates to the "Card Personalization" page and displays the message: "The system is personalizing the device. Please wait..." A progress indicator appears, along with the warning: "Please do not remove the device during the operation."

Step 8: Monitor Programming Progress

  1. Wait while the system programs the card. A progress bar will display the current status.

  2. CRITICAL: Do not remove the card from the reader during this process.

  3. Do not close the browser window or navigate away from the page.

  4. The programming process typically takes 30-90 seconds.

  5. A browser popup may appear asking "Save your password?" - you can click Not now or close this dialog as it is not related to the card programming.

Expected Result: The progress bar advances, and the page displays visual indicators (certificate and chip icons) showing the personalization is in progress.

Step 9: Complete Card Programming

  1. Wait for the progress bar to reach completion.

  2. Once programming is complete, the system will display a completion message or advance to the next screen.

  3. Only when explicitly instructed, remove the card from the reader.

  4. Verify the card was successfully programmed by checking for any error messages.

Expected Result: The card is successfully programmed with the user's credentials and PIN, ready for use.


Card Programming Completion Checklist

Confirm the following before distributing the card to the user:

  • [ ] The correct user was selected for card issuance

  • [ ] The appropriate device policy was applied

  • [ ] The applicant created and confirmed their own PIN

  • [ ] The card remained in the reader throughout the entire programming process

  • [ ] The programming progress bar reached 100% completion

  • [ ] No error messages were displayed during programming

  • [ ] The card was removed only after programming completed

  • [ ] The applicant understands they must keep their PIN confidential

Troubleshooting

Issue: Card Reader Not Detected in Dropdown

Solution:

  • Verify the card reader is properly connected to the computer via USB

  • Check that the card reader drivers are installed correctly

  • Try unplugging and reconnecting the card reader

  • Restart the browser and log back into the system

  • Contact IT support if the reader still doesn't appear

Issue: "Insert Card" Prompt Won't Advance

Solution:

  • Remove the card and reinsert it firmly into the reader

  • Ensure you're using a compatible blank card

  • Verify the card is not damaged or previously programmed

  • Try using a different blank card

  • Ensure the card is fully inserted (should click into place)

Issue: PIN Fields Won't Accept Input

Solution:

  • Click directly in the PIN input field

  • Ensure the field is active (should show a cursor)

  • Verify you're entering only numeric characters (if required by your system)

  • Check that the PIN meets minimum length requirements

  • Refresh the page and start over if the field remains unresponsive

Issue: PIN Confirmation Doesn't Match

Solution:

  • Clear both PIN fields

  • Have the applicant carefully re-enter the PIN in both fields

  • Ensure the applicant is typing the same value in both fields

  • If the applicant is uncertain, have them choose a new PIN they can remember

Issue: Programming Fails or Stalls

Solution:

  • Do NOT remove the card if the process appears stalled

  • Wait at least 2-3 minutes before taking any action

  • If the progress bar hasn't moved after 3 minutes, note the error message (if any)

  • Contact your system administrator with the error details

  • If instructed, cancel the operation and start the process over with a new blank card

Issue: Card Was Removed During Programming

Solution:

  • The card is likely corrupted and cannot be used

  • Obtain a new blank card

  • Restart the programming process from Step 1

  • Emphasize the importance of not removing the card during programming

Issue: Browser Password Save Popup Blocking View

Solution:

  • Click Not now or the X to close the password save dialog

  • This popup is a browser feature and doesn't affect card programming

  • Continue monitoring the programming progress

  • You can disable password save prompts in your browser settings if this is a recurring issue

Best Practices

For the Operator:

  • Always verify you have selected the correct user before beginning card programming

  • Double-check that the applicant understands the PIN must be kept confidential

  • Never handle the PIN entry yourself - always have the applicant enter their own PIN

  • Ensure a stable internet connection before beginning the process

  • Keep the work area organized to avoid confusion when processing multiple users

For the Applicant:

  • Choose a PIN that is memorable but not easily guessed

  • Do not share the PIN with anyone, including the operator

  • Do not write the PIN on the card or store it with the card

  • Remember that the PIN will be required each time the card is used

  • Report a lost or stolen card immediately

General:

  • The entire card programming process takes approximately 2-4 minutes per user

  • Ensure adequate lighting to read on-screen instructions clearly

  • Maintain a quiet environment to minimize distractions during PIN entry

  • Document any recurring issues and report them to your system administrator

Quick Reference: Key Actions Summary

  1. Login → Navigate to Device Issuance tab

  2. Search User → Enter last name → Select group → Click Search

  3. Select User → Click user's User ID link

  4. Configure → Select Local Issuance → Choose card reader

  5. Insert Card → Place card in reader → Click Next

  6. Set PIN → Applicant enters PIN (twice) → Select device policy

  7. Program → Click Next → Wait for completion → Do not remove card

  8. Complete → Verify success → Remove card when instructed

Security Reminders

  • PIN Confidentiality: The PIN must only be known by the card holder

  • Operator Responsibility: Never view, record, or handle the applicant's PIN

  • Physical Security: Keep blank cards in a secure location when not in use

  • Card Handling: Programmed cards should be immediately handed to the authorized user

  • System Access: Only authorized operators should have access to the Device Issuance function

  • Audit Trail: The system logs all card programming activities for security auditing