CWS/CMS

CWS/CMS: Cancellation of CWS/CMS Release 9.7

All SPOCs and Technical Contacts:

As stated in the communication sent by CWDS Customer Relations on December 23, 2025, the CWDS Executive Leadership Team has decided to cancel the CWS-CARES Production Pilot. In place of the Production Pilot, CWS-CARES will implement a Production Simulation environment.

The primary focus of CWS/CMS Release 9.7 was to enable IBM to deliver the technical solution required for the planned CWS-CARES Production Pilot. Since this activity is no longer needed for the newly planned CWS-CARES Production Simulation environment, CWS/CMS Release 9.7 is no longer required.

The next scheduled CWS/CMS release will be Release 9.8. The primary focus of this release is to add a mechanism that will allow CWS/CMS to be placed in a read-only state when CWS-CARES is implemented in October 2026. The CWDS Project is currently working with IBM to determine how many, if any, Data Quality improvement System Change Requests (SCRs) can be included with this release.

Release 9.8 is the projected final release for CWS/CMS. It is tentatively scheduled for implementation in June 2026. Further information will be announced as the release details are finalized.

Action Required

No action is required. Please forward any questions to CWDS Customer Relations.

CDT Service Desk Bulletin – SAFE Cloud Service Scheduled Maintenance

ALL SPOCs, Technical Contacts and CAD Contacts:

The California Department of Technology (CDT) has scheduled maintenance of the SAFE Cloud service. The maintenance begins on Saturday, January 24, 2026, at 8:00 PM and concludes on Sunday, January 25, 2026, at 2:00 AM. The activity will cause interruptions in the SAFE Cloud service. Some Business Objects (BO) reports will fail to send, or automated scripts may fail to retrieve from SAFE during this scheduled maintenance.

Action Required

All users should logoff of the SAFE Cloud service prior to the start of the stated maintenance timeframe. Please check on your scheduled BO SAFE reports and automated FTP scripts. If needed, re-run the reports and scripts.

Contact the IBM Help Desk (800-428-8268) to report any issues with your Business Objects content in SAFE.

CWS/CMS: County Access Data (CAD) Business Objects - Issue

All SPOCs, Technical Contacts, and CAD Contacts:

A service on the CWS/CMS CAD BusinessObjects (BO) server did not start correctly last night, January 12, 2026. The service was restarted this morning, and all functionality has been restored.

However, all scheduled reports did not run last night. Please review and manually rerun the missing reports.


Action Required

Manually invoke the scheduled BO reports from last night.

Contact Chris Lovejoy if you require more information regarding this issue.

CWS/CMS: Business Objects Error When Retrieving Documents Resolved

All SPOCs, Technical Contacts, and CAD Contacts:

The CWDS Project received reports this morning of users receiving error messages when attempting to retrieve Business Objects reports. The CWDS Infrastructure team and IBM researched this issue and they determined that this issue began on December 28, 2025.

The reports issue is now resolved. Business Objects users should be able to access their reports without any issues.

Action Required

Review and validate your Business Objects reports.

If users experience any issues with CWS/CMS or with Business Objects, please follow your county process for reporting issues or you may contact the IBM Boulder Help Desk at 1-800-428-8268.

California Department of Education - Updated Providers List - UPDATE

All SPOCs:

December 24, 2025 UPDATE: The California Department of Education - Updated Providers List communication that was sent on Tuesday, December 23, 2025, included the wrong version of the List of Closed Schools. Please use the spreadsheet attached to today’s updated communication, dated “2025-12-19”, for your review.

We apologize for the miscommunication.

____________________________________________________________________________________________

On Friday, December 19, 2025, the list of Education Providers in the CWS/CMS application was updated with data obtained from the California Department of Education (CDE). During this update, several Education Providers in the application were end dated. This occurs whenever an existing CWS/CMS Education Provider no longer shows up as an active Education Provider in the data obtained from CDE.

Attached is a list of all closed Public Education Providers and all closed Private Education Providers that were end dated during this update. This information is being provided to assist counties with determining if any data corrections are needed.

Please contact CDE with any questions regarding the attached list:
Email: cdsadmin@cde.ca.gov
Phone: 916-327-4014

Action Required

Review the attached list of closed Education Providers; if the county determines a data correction may be needed, contact the CDE.

Zscaler Tool to Replace Current Cisco AnyConnect Virtual Private Network (VPN) Software – UPDATE #4

All Dedicated County SPOCs and Technical Contacts:

December 22, 2025 UPDATE: The CWDS Infrastructure team thanks everyone for their continued collaboration with the Zscaler implementation project. Below is the recount from the latest Zscaler User Group meeting on Friday, December 19, 2025:

Zscaler Release Date

The CWDS Infrastructure team plans to release Zscaler on Wednesday, January 21, 2026, at 12:00 Noon Pacific Time.

Q&A Highlight

Q: If new remote user credentials are needed, should counties delay requesting Cisco AnyConnect credentials and wait for Zscaler?

A: No. Please continue with your county’s standard process to request Cisco AnyConnect credentials. In addition, request Zscaler credentials for any users who do not already have them.

Next Steps & Holiday Message

The session on Friday, December 19, 2025, was the final Zscaler User Group meeting for 2025. The CWDS Infrastructure team looks forward to connecting again early in January as the Zscaler release date approaches. In the meantime, the team wishes you, your families, and your loved ones a safe and joyful holiday season.

_________________________________________________________________

December 15, 2025 UPDATE: The CWDS Infrastructure team expresses their appreciation for those who have joined the weekly Zscaler User Group meetings in November and December and for your continued engagement. Your participation helps keep our efforts on track to quickly identify and address any issues that arise.

Here are the newest questions and answers that arose from the most recent status meeting:

Q: When will the recordings of the previous Zscaler User Group meetings be saved to the CWDS website?

A: The CWDS Web team is working on receiving the necessary approvals. We will provide an update once the CWDS Infrastructure team receives word from the Web team.

Q: When will Zscaler be ready for customers to use?

A: Zscaler testing is nearly completed. An exact implementation date to use Zscaler should be provided by the next Zscaler User Group meeting on Friday, December 19, 2025.

Zscaler Client Connector Deployment Status

CWS Ops is nearing completion of the Zscaler Client Connector deployment across all workstations. Only a small number of workstations remain without the installation. For those machines, we kindly ask that you leave them powered on for an extended period to allow the deployment to complete. If you are a remote user and utilize Cisco AnyConnect, please ensure you are logged in so we can complete the installation successfully.

CWDS appreciates your cooperation and support for this project.

____________________________________________________________________

November 24, 2025 UPDATE: The CWDS Infrastructure team appreciates your continued participation and support during this Zscaler migration project. Following our last status meeting on Friday, November 21, 2025, the team is pleased to share that they have made steady progress and are now moving forward with this project, as expected. Your ongoing engagement and valuable contributions play an essential role in helping to maintain momentum to achieve these shared goals. We remain grateful for your commitment and look forward to the continued collaboration.

Here are the newest questions and answers that arose from the most recent status meeting:

Q: When will additional Okta authentication login options be available?

A: As of Friday, November 21, 2025, users should have the ability to not have to rely on the ‘Okta Verify’ option from a mobile device. Users now have the ability to obtain the multi-factor authentication (MFA) one-time-use code through their email.

Q: Does this effort involving Zscaler and Okta affect the Server Based Computing (SBC) users login?

A: SBC users will continue to login as they normally do; this Zscaler/Okta effort has no impact on SBC.

Q: When can users expect to receive the email to create the Zscaler/Okta account?

A: Users should have already received an Okta account email from the CWDS Infrastructure team. If users have not yet received the email, please inform the CWDS Infrastructure team at cwsoperationsteam@otsi.ca.gov with the list of users who need to receive the account creation email. Please include the first name, last name, and the email address for each user on the list.

Q: When will the Zscaler client be installed on the CWS workstations?

A: Starting at 6:00 PM on Wednesday, November 26, 2025, the CWDS Infrastructure team and IBM/Kyndryl will start deploying the Zscaler Client Connector to the CWS workstation, using the BigFix installer. The installation process will use a rolling deployment, so as not to cause too large of impact to the network at one time.

If possible, please leave the CWS workstations powered on over the Thanksgiving holiday. Note: please also be connected to the Virtual Private Network (VPN) if the workstation uses VPN. This process will occur silently in the background.

Once completed, the user will notice the Zscaler application loaded on the workstation. This is an automatic loading process; however, no further action is needed as of this time. The user can close the Zscaler application to continue to do their daily work. Further instruction will be provided when Zscaler is expected to be in use. For now, this current activity is only to load the Zscaler application onto the workstation.

Please direct any questions regarding this process to the CWDS Customer Relations mailbox at CWS_CustRel@otsi.ca.gov.

_______________________________________________________________________

November 10, 2025 UPDATE: The CWDS Infrastructure team will be sending out emails to the Dedicated Counties to create their Zscaler accounts. The attached New User Guide Okta & Zscaler document will assist counties with solving any questions that Counties may have during the transition to Zscaler and Okta. The Infrastructure team will continue to leverage the Friday ‘CWS Ops Zscaler User Group’ meetings to communicate the next steps in this project and to answer any questions that the Counties may have.

Here are a couple questions and answers that arose from last week’s meeting:

Q: Will users that rely on Citrix to login into the CWS/CMS application be impacted when this Virtual Private Network (VPN) change occurs?

A: No impact will be reflected if a user is using Citrix to access the CWS/CMS application.

Q: Since Zscaler depends on the use of Okta, is it possible to receive directions outlining Okta verification process?

A: The attached New User Guide Okta & Zscaler document provides instructions on installing the “Okta verify application” function on iOS and Android mobile devices. The CWDS Infrastructure team is researching the possibility of installing the Okta application on the CWS/CMS workstations, but are currently requesting Dedicated Counties to allow the installation on mobile devices.

Action Required

The only action currently required of the Dedicated County is to create their Zscaler accounts when the email invite is delivered to their Outlook mailbox.

Please continue to attend the Zscaler meetings on Fridays in November and December to learn about the transition from AnyConnect VPN to Zscaler and to share any questions or concerns that you have regarding this project.

___________________________________________________________________

The CWDS Infrastructure team, along with IBM/Kyndryl, currently use AnyConnect Virtual Private Network (VPN) for Dedicated County remote access to the CWS/CMS application. In an effort to achieve higher security standards and to move away from obsolete technologies, CWDS is switching to the Zscaler tool for remote access. Additionally, Zscaler will replace the McAfee proxy that is used to whitelist specific websites for the Dedicated Counties. In collaboration with Zscaler, CWDS will also use the Okta identity management tool.

Zscaler is a cloud native security platform that allows users to connect to applications and surf the internet securely. Okta is an identify management platform that allows user to securely authenticate to services.

The CWDS Infrastructure team will create accounts for all Dedicated County users. On November 19, 2025, IBM/Kyndryl will use the BigFix tool to deploy Zscaler on the Dedicated County workstations. Users will receive emails from Zscaler and Okta as the accounts are created and are rolled out to the workstations.

In December 2025, CWDS will transition from Cisco AnyConnect VPN and McAfee Proxy to Zscaler and Okta. In January 2026, the transition will be completed. Cisco AnyConnect VPN and McAfee Proxy will no longer be used; Dedicated Counties will be fully using only Zscaler and Okta.

To help users with the transition to Zscaler and Okta, the CWDS Infrastructure team will hold weekly meetings every Friday afternoon at 1:00 PM, beginning on November 7, 2025, and running through to the end of the calendar year. The CWDS Infrastructure team will use these meetings to cover the Zscaler project, why it is occurring, the timeline and activities, and to answer questions and concerns regarding the project.

Action Required

Please attend the Zscaler transition meetings, Fridays in November and December, to learn about the transition from AnyConnect VPN to Zscaler and to share any questions or concerns that you have regarding this project.

CWS/CMS: Zscaler Tool to Replace Current Cisco AnyConnect Virtual Private Network (VPN) Software – UPDATE #3

December 15, 2025 UPDATE: The CWDS Infrastructure team expresses their appreciation for those who have joined the weekly Zscaler User Group meetings in November and December and for your continued engagement. Your participation helps keep our efforts on track to quickly identify and address any issues that arise.

Here are the newest questions and answers that arose from the most recent status meeting:

Q: When will the recordings of the previous Zscaler User Group meetings be saved to the CWDS website?
A: The CWDS Web team is working on receiving the necessary approvals. We will provide an update once the CWDS Infrastructure team receives word from the Web team.

Q: When will Zscaler be ready for customers to use?
A: Zscaler testing is nearly completed. An exact implementation date to use Zscaler should be provided by the next Zscaler User Group meeting on Friday, December 19, 2025.

Zscaler Client Connector Deployment Status
CWS Ops is nearing completion of the Zscaler Client Connector deployment across all workstations. Only a small number of workstations remain without the installation. For those machines, we kindly ask that you leave them powered on for an extended period to allow the deployment to complete. If you are a remote user and utilize Cisco AnyConnect, please ensure you are logged in so we can complete the installation successfully.

CWDS appreciates your cooperation and support for this project.

____________________________________________________________________

November 24, 2025 UPDATE: The CWDS Infrastructure team appreciates your continued participation and support during this Zscaler migration project. Following our last status meeting on Friday, November 21, 2025, the team is pleased to share that they have made steady progress and are now moving forward with this project, as expected. Your ongoing engagement and valuable contributions play an essential role in helping to maintain momentum to achieve these shared goals. We remain grateful for your commitment and look forward to the continued collaboration.

Here are the newest questions and answers that arose from the most recent status meeting:

Q: When will additional Okta authentication login options be available?
A: As of Friday, November 21, 2025, users should have the ability to not have to rely on the ‘Okta Verify’ option from a mobile device. Users now have the ability to obtain the multi-factor authentication (MFA) one-time-use code through their email.

Q: Does this effort involving Zscaler and Okta affect the Server Based Computing (SBC) users login?
A: SBC users will continue to login as they normally do; this Zscaler/Okta effort has no impact on SBC.

Q: When can users expect to receive the email to create the Zscaler/Okta account?
A: Users should have already received an Okta account email from the CWDS Infrastructure team. If users have not yet received the email, please inform the CWDS Infrastructure team at cwsoperationsteam@otsi.ca.gov with the list of users who need to receive the account creation email. Please include the first name, last name, and the email address for each user on the list.

Q: When will the Zscaler client be installed on the CWS workstations?
A: Starting at 6:00 PM on Wednesday, November 26, 2025, the CWDS Infrastructure team and IBM/Kyndryl will start deploying the Zscaler Client Connector to the CWS workstation, using the BigFix installer. The installation process will use a rolling deployment, so as not to cause too large of impact to the network at one time.

If possible, please leave the CWS workstations powered on over the Thanksgiving holiday. Note: please also be connected to the Virtual Private Network (VPN) if the workstation uses VPN. This process will occur silently in the background.

Once completed, the user will notice the Zscaler application loaded on the workstation. This is an automatic loading process; however, no further action is needed as of this time. The user can close the Zscaler application to continue to do their daily work. Further instruction will be provided when Zscaler is expected to be in use. For now, this current activity is only to load the Zscaler application onto the workstation.

Please direct any questions regarding this process to the CWDS Customer Relations mailbox at CWS_CustRel@otsi.ca.gov.

_______________________________________________________________________

November 10, 2025 UPDATE: The CWDS Infrastructure team will be sending out emails to the Dedicated Counties to create their Zscaler accounts. The attached New User Guide Okta & Zscaler document will assist counties with solving any questions that Counties may have during the transition to Zscaler and Okta. The Infrastructure team will continue to leverage the Friday ‘CWS Ops Zscaler User Group’ meetings to communicate the next steps in this project and to answer any questions that the Counties may have.

Here are a couple questions and answers that arose from last week’s meeting:

Q: Will users that rely on Citrix to login into the CWS/CMS application be impacted when this Virtual Private Network (VPN) change occurs?
A: No impact will be reflected if a user is using Citrix to access the CWS/CMS application.

Q: Since Zscaler depends on the use of Okta, is it possible to receive directions outlining Okta verification process?
A: The attached New User Guide Okta & Zscaler document provides instructions on installing the “Okta verify application” function on iOS and Android mobile devices. The CWDS Infrastructure team is researching the possibility of installing the Okta application on the CWS/CMS workstations, but are currently requesting Dedicated Counties to allow the installation on mobile devices.

Action Required

The only action currently required of the Dedicated County is to create their Zscaler accounts when the email invite is delivered to their Outlook mailbox.

Please continue to attend the Zscaler meetings on Fridays in November and December to learn about the transition from AnyConnect VPN to Zscaler and to share any questions or concerns that you have regarding this project.

___________________________________________________________________

The CWDS Infrastructure team, along with IBM/Kyndryl, currently use AnyConnect Virtual Private Network (VPN) for Dedicated County remote access to the CWS/CMS application. In an effort to achieve higher security standards and to move away from obsolete technologies, CWDS is switching to the Zscaler tool for remote access. Additionally, Zscaler will replace the McAfee proxy that is used to whitelist specific websites for the Dedicated Counties. In collaboration with Zscaler, CWDS will also use the Okta identity management tool.

Zscaler is a cloud native security platform that allows users to connect to applications and surf the internet securely. Okta is an identify management platform that allows user to securely authenticate to services.

The CWDS Infrastructure team will create accounts for all Dedicated County users. On November 19, 2025, IBM/Kyndryl will use the BigFix tool to deploy Zscaler on the Dedicated County workstations. Users will receive emails from Zscaler and Okta as the accounts are created and are rolled out to the workstations.

In December 2025, CWDS will transition from Cisco AnyConnect VPN and McAfee Proxy to Zscaler and Okta. In January 2026, the transition will be completed. Cisco AnyConnect VPN and McAfee Proxy will no longer be used; Dedicated Counties will be fully using only Zscaler and Okta.

To help users with the transition to Zscaler and Okta, the CWDS Infrastructure team will hold weekly meetings every Friday afternoon at 1:00 PM, beginning on November 7, 2025, and running through to the end of the calendar year. The CWDS Infrastructure team will use these meetings to cover the Zscaler project, why it is occurring, the timeline and activities, and to answer questions and concerns regarding the project.

Action Required

Please attend the Zscaler transition meetings, Fridays in November and December, to learn about the transition from AnyConnect VPN to Zscaler and to share any questions or concerns that you have regarding this project.

Delayed Initial CWS/CMS Application Login - RESOLVED

All Dedicated County SPOCs and Technical Contacts:

December 12, 2025 UPDATE: The CWDS Infrastructure team successfully deployed the second of two network changes last night. Validation testing confirmed that the degraded initial login to the CWS/CMS application has been resolved. Users should not experience longer than usual connection time when connecting to the CWS/CMS application.

Please contact the IBM Help Desk (800-428-8268) to report any issues with CWS/CMS.

___________________________________________________________________________

The CWDS Infrastructure team deployed the first of two network changes last night. This change is causing a delay for users in some Dedicated Counties when they initially login to the CWS/CMS application. The extended login process takes impacted users an average of three to 25 seconds longer than a standard initial connection to CWS/CMS. The delayed connection occurs only during the initial connection; there is no observed delay with CWS/CMS following the login.

The CWDS Infrastructure is deploying the second part of the network change tonight. The initial login delay is expected to be removed following this second change.

Action Required

No action is needed for this activity.

If users experience any issues with CWS/CMS, please follow your county process for reporting issues or you may contact the IBM Boulder Help Desk at 1-800-428-8268.

Delayed Initial CWS/CMS Application Login

All Dedicated County SPOCs and Technical Contacts:

The CWDS Infrastructure team deployed the first of two network changes last night. This change is causing a delay for users in some Dedicated Counties when they initially login to the CWS/CMS application. The extended login process takes impacted users an average of three to 25 seconds longer than a standard initial connection to CWS/CMS. The delayed connection occurs only during the initial connection; there is no observed delay with CWS/CMS following the login.

The CWDS Infrastructure is deploying the second part of the network change tonight. The initial login delay is expected to be removed following this second change.

Action Required

No action is needed for this activity.

If users experience any issues with CWS/CMS, please follow your county process for reporting issues or you may contact the IBM Boulder Help Desk at 1-800-428-8268.

CWS/CMS: System Change Request (SCR) for Proposed Automated CWS/CMS User ID Clean Up

All SPOCs and Technical Contacts:

To assist counties with cleanup of CWS/CMS user accounts and to correctly determine the number of accounts needed in CWS-CARES, an automated approach to deactivate inactive CWS/CMS user accounts has been proposed with System Change Request (SCR) 9039. To align with CWS-CARES user account administration, the SCR will deactivate user accounts that have not logged into CWS/CMS within the previous 90 days. Of the current 30,700 active user accounts in CWS/CMS, approximately 8,900 accounts have not logged in within the previous 90 days.

Important notes regarding this proposed automated process:

  • All User IDs (active and inactive) will be migrated from CWS/CMS to CWS-CARES;
  • The SCR will be developed outside of traditional CWS/CMS Release timelines;
  • It is expected that a large first-run for deactivating CWS/CMS User IDs will be followed by a smaller run prior to moving to CWS-CARES;
  • A county can change a user from inactive to active within CWS-CARES once migrated (provided a valid current email is used);
  • Once CWS-CARES is live, the user accounts will automatically be deactivated if the user has not logged in a 90-day period.

Exact details on the functionality of the SCR are still being developed. Design and development is expected to be completed by the end of December 2025. After internal testing, the change is anticipated to run in the CWS/CMS production application by the end of January 2026. Updates will be provided as the details and schedule are finalized.

Action Required

Send questions and/or concerns regarding this automated process to the Data Quality portal’s mailbox at CWSDataQuality@otsi.ca.gov.