An FSA audit finding on GLBA
Increasingly common, and often the first time a campus learns it is a financial institution.
A university provisions and deprovisions tens of thousands of identities every semester, across departments that each run their own systems, for a population that includes students, faculty, staff, alumni, contractors and parents — several of whom are the same person. No other sector has that churn, and no other sector has that many people with a reason to be on the network and no clear owner.
The accounts that survive graduation are the ones an attacker finds.
Access from four different populations, and none of those populations knows about the others.
FERPA governs access to student education records, and it turns "who can see this student's record and why" into a legal question rather than a convenience one. Less well known: under the GLBA Safeguards Rule, institutions of higher education that handle federal student aid are treated as financial institutions, with the same requirements for access controls, MFA and a designated program lead that a bank carries. The Department of Education's FSA audits check for it.
Research-active institutions add NIST 800-171 for federally funded research data, and HIPAA where there is a medical school or a clinic. The CIO or CISO owns the program; the registrar owns FERPA. Where an FSA finding or a research compliance deadline is the trigger, that starts with a compliance readiness assessment.
The answer to cohort churn is automation driven by the student information system and the HR system, so that enrollment creates access and withdrawal removes it without a ticket. That is IGA implementation, and the education-specific part is the role model: a student is not one role, a faculty member is not one role, and the affiliations have to be modelled as they actually overlap. Connectors into the SIS, the LMS and the research systems are IAM integration work, and it is where most of the technical effort goes.
The systems we secure. Student information systems. Learning management systems. Research computing and grant systems. Library and identity federation. Campus directories and cloud tenants. Financial aid systems, which is where GLBA bites.
Increasingly common, and often the first time a campus learns it is a financial institution.
Graduated students, departed faculty, ended contracts — still active, still on the network.
A grant requiring NIST 800-171 that the existing controls cannot evidence. Privileged access to research systems brought under PAM implementation; broader access governed through managed IAM services where the campus team is stretched.
Higher education identity management starts from a different shape than corporate IAM. A company assumes one person holds one role. A university holds students, faculty, staff and alumni who are often the same person at once, and whole cohorts that arrive and leave in the same week.
Student identity management means access that follows enrollment, changes as majors, campus jobs and research roles change, and ends at graduation without removing what alumni keep. Faculty identity management adds adjuncts on term contracts, visiting researchers and emeritus staff. IAM for higher education has to handle all of it, whichever IAM software a college or university runs, with the small IT team most campuses have.
By driving it from the student information system. Enrollment creates access, withdrawal or graduation removes it, and affiliations change automatically as the record changes. The volume is the argument for automation, not against it.
If you handle federal student aid, yes. The Safeguards Rule treats you as a financial institution, and FSA audits check for the controls it requires: access controls, MFA, a designated program lead and a written security program.
It has to, or it does not work at all. Governance runs centrally; application ownership stays with the departments. The role model is the bridge, and building it with the departments rather than for them is most of the project.
Sponsored identities with an owner, an expiry and a review cycle, so access ends when the grant does rather than when someone notices.

The two pages that rank highest for this question are written by SailPoint and by Saviynt. Here is the version from people who deploy identity governance for a living.
Aug 31, 2026
Owning PAM and IGA is not the same as knowing your identity risk. What identity security posture management actually measures.
Jul 27, 2026
Managers approve 400 entitlements in eleven minutes and the campaign passes. Here is what makes an access review genuinely work.
Jul 27, 2026A free audit is a 30-minute review of your privileged and orphaned accounts by a certified engineer, with the findings in writing. The Education blind spot brief covers the largest breach of student data in US history and the access gap behind it.
Needed for the site to work — page delivery, and the spam protection on our forms. These do not track you and cannot be switched off.
Google Analytics and Microsoft Clarity, so we can see which pages are useful and which are confusing. Clarity hides anything you type into a form. We use this to improve the site, not to identify you.
ZoomInfo WebSights, which tells us which organisation a visit is likely to have come from and which pages were read. With this on, ZoomInfo may also set third-party cookies that help it recognise a visit across other websites, and may share that with its own partners. Turning this off stops all of it.