Applied IAM

Identity Security for Education

A university provisions and deprovisions tens of thousands of identities every semester, across departments that each run their own systems, for a population that includes students, faculty, staff, alumni, contractors and parents — several of whom are the same person. No other sector has that churn, and no other sector has that many people with a reason to be on the network and no clear owner.

FERPAGLBA Safeguards RuleNIST 800-171Decentralized ITSemester churn
One academic yearSemester churn
CreatedAccount neededStill active, still on the network

The accounts that survive graduation are the ones an attacker finds.

The campus problem

Why campus identity is a different problem

  • Whole cohorts join and leave at once. Thousands of accounts created in August and thousands more that should be closed in May. Manual processes cannot keep up, and the accounts that survive graduation are the ones an attacker finds.
  • Decentralized IT. Central IT runs the directory. Individual colleges and research groups run their own applications, often with their own administrators. Governance that only covers what central IT can see covers a fraction of the estate.
  • One person, five roles. A graduate student who teaches, works in the library and is also an alumnus holds access from four different populations, and none of those populations knows about the others.
  • Research and third-party access. Grant-funded collaborators, visiting faculty and external partners with access to research systems and, increasingly, sensitive data — granted for a project and rarely removed when it ends.
Campus identity
HolderOne personGraduate student
AffiliationsStudentTeachesLibraryAlumnus
Access it brings
  • StudentStudents
    Student information systemsLearning management systems
  • TeachesFaculty
    Learning management systems
  • Works in the libraryStaff
    Library and identity federation
  • AlumnusAlumni
    An account that survived graduation

Access from four different populations, and none of those populations knows about the others.

The rules

FERPA, GLBA and the rules education is actually held to

FERPA governs access to student education records, and it turns "who can see this student's record and why" into a legal question rather than a convenience one. Less well known: under the GLBA Safeguards Rule, institutions of higher education that handle federal student aid are treated as financial institutions, with the same requirements for access controls, MFA and a designated program lead that a bank carries. The Department of Education's FSA audits check for it.

Research-active institutions add NIST 800-171 for federally funded research data, and HIPAA where there is a medical school or a clinic. The CIO or CISO owns the program; the registrar owns FERPA. Where an FSA finding or a research compliance deadline is the trigger, that starts with a compliance readiness assessment.

The answer

Lifecycle automation that survives the semester

The answer to cohort churn is automation driven by the student information system and the HR system, so that enrollment creates access and withdrawal removes it without a ticket. That is IGA implementation, and the education-specific part is the role model: a student is not one role, a faculty member is not one role, and the affiliations have to be modelled as they actually overlap. Connectors into the SIS, the LMS and the research systems are IAM integration work, and it is where most of the technical effort goes.

The systems we secure. Student information systems. Learning management systems. Research computing and grant systems. Library and identity federation. Campus directories and cloud tenants. Financial aid systems, which is where GLBA bites.

Triggers

Where a program usually starts

An FSA audit finding on GLBA

Increasingly common, and often the first time a campus learns it is a financial institution.

Orphaned accounts found after an incident

Graduated students, departed faculty, ended contracts — still active, still on the network.

Research compliance

A grant requiring NIST 800-171 that the existing controls cannot evidence. Privileged access to research systems brought under PAM implementation; broader access governed through managed IAM services where the campus team is stretched.

Higher education

Identity and access management for higher education

Higher education identity management starts from a different shape than corporate IAM. A company assumes one person holds one role. A university holds students, faculty, staff and alumni who are often the same person at once, and whole cohorts that arrive and leave in the same week.

Student identity management means access that follows enrollment, changes as majors, campus jobs and research roles change, and ends at graduation without removing what alumni keep. Faculty identity management adds adjuncts on term contracts, visiting researchers and emeritus staff. IAM for higher education has to handle all of it, whichever IAM software a college or university runs, with the small IT team most campuses have.

FAQs

What campus IT asks first

By driving it from the student information system. Enrollment creates access, withdrawal or graduation removes it, and affiliations change automatically as the record changes. The volume is the argument for automation, not against it.

If you handle federal student aid, yes. The Safeguards Rule treats you as a financial institution, and FSA audits check for the controls it requires: access controls, MFA, a designated program lead and a written security program.

It has to, or it does not work at all. Governance runs centrally; application ownership stays with the departments. The role model is the bridge, and building it with the departments rather than for them is most of the project.

Sponsored identities with an owner, an expiry and a review cycle, so access ends when the grant does rather than when someone notices.

See which accounts survived graduation

A free audit is a 30-minute review of your privileged and orphaned accounts by a certified engineer, with the findings in writing. The Education blind spot brief covers the largest breach of student data in US history and the access gap behind it.