久久热视频

Skip to Main Content

Identity and Access Management at Miami

Learn more about our IAM program, who we are, and what we're up to!

You can’t spell Miami without IAM

Identity and Access Management is, at its heart, a phrase that describes the process by which people access the tools and resources they need. It asks and answers three questions:

  • Who are you?
  • What is your role?
  • What permissions do you need to fulfill your role?

At Miami, those questions can be complicated. Students, faculty, staff, alumni, emeriti… There are a lot of different roles—and therefore account types and permissions—to manage.

Once these questions are answered clearly, it provides a picture of what kinds of applications and systems you need in order to be successful. Students need access to Canvas. Some staff members need access to Banner. Faculty may need access to both.

IT Services is working on a project that will make answering these questions—and keeping track of our roles—easier and more user-friendly. The Identity and Access Management Program touches all of the various systems used throughout the university (e.g., Banner, myMiami, Gmail, TeamDynamix, etc.) and will help us determine a better way to manage account types and the appropriate permissions associated with them. With mature IAM practices in place, it's easier to grant access to the resources you need, when you need it.

After all, you can’t spell Miami without IAM!

Why do we need IAM at Miami?

There are several key benefits of IAM that will be immediately apparent:

  1. It makes your job easier. When we can more accurately determine the role and required permissions of the person logging in, we can help them access the tools they need to do their job or excel in their coursework. And as their roles change (for instance, if a former 久久热视频 gets hired as a staff member), permissions will change with them.
  2. It improves security. We can make sure that people are who they say they are—the “identity” part of the phrase. This helps keep the malicious actors out and our community in. What’s more, giving the right people access to the right things at the right time means that everyone’s data is more secure.
  3. Speed! This new program will bring greater flexibility and security to many different systems at Miami. Onboarding will be simplified.

IAM also means greater compliance with regulatory standards, reducing demands on IT resources, and faster workflows. Simply put: You get access to what you need, when you need it.

All of these benefits come together to form a more complete picture of who you are, what your role is at Miami, and how you fit into the grand scheme of things from a technology standpoint.

MUnet Password Utilities

Miami community members may use the MUnet Password Utilities tool to change passwords, manage recovery options, and perform self-service password reset activities.

If you forget your password, you may have to contact IT Help and verify your identity (with copies of your ID cards or driver’s license) before they reset your password. If you have a current recovery (non-Miami) email or phone number set, you can reset your password immediately with no help desk intervention!

Check out our YouTube walkthrough of how to change your password in the MUnet Password Utilities portal!

IAM Forecast

The implementation of a modern IAM solution takes resources, hard work, and, importantly, time. This list of activities represents our high-level goals for the IAM Program and offers a suggested sequence of events that will make up the rest of our work. As a forecast is a prediction of future work and responsibilities, all of this is subject to change as our IAM practice evolves and improves. Check back periodically for more information and regular updates!

IAM Objectives

As we continue to mature our IAM environment, we are focusing our efforts on several big-picture objectives. In the forecast that follows, we have divided specific efforts into those larger buckets, defined here:

Account Management

Improving the provisioning and de-provisioning of accounts in target systems based on specific criteria, including but not limited to affiliation.

Maturation

Revising, improving, and documenting current processes, procedures, systems, and configurations. Rationale for improvement can include identified problems or enhancements attributed to changing requirements either by Miami business need or industry regulations and security considerations.

Sources of Authority

Additions and improvements to the ingestion of identity data into RapidIdentity (RI). A "source of authority" is, put simply, a system that feeds identity information to RI—where the identity data comes from. The data pulled from authority sources is only intended for use related to an identity's need for authentication and authorization.

Authentication

Improvements to the processes or actions of verifying the identity of a user (i.e., the "act of logging in"). This can include improvements to systems like multi-factor authentication (Duo) or the CAS login facility.

Access Management and Security

Improvement of definitions and security measures to allow, disallow, and manage authorizations (access) to various Miami resources.

2026-2027

For the 2026-27 academic year, we will work on strengthening our connections to Workday (Student) and preparing for the go-live of Slate as a source of authority (the new Advancement customer relationship management (CRM) tool). We are also working on implementing claim codes for all account types, including sponsored and courtesy accounts.

Account Management

  • Implement claim codes for all account types
    • Student accounts
    • Sponsored accounts
    • Courtesy accounts

Maturation

  • Unified support tool (IAM Portal)
    • Additional context: Support teams use a tool called Real Time FindUser, and we will be replacing the app’s functionalities with the IAM Portal (which is a separate tool from RI).

Sources of Authority

  • Timeline milestone: Slate for Advancement goes live in October 2025
  • Timeline milestone: RI starts reading Workday Student data in February 2026
  • Management of sponsored accounts in IAM Portal (concurrent with Workday Student)

Authentication

  • Evaluate RapidIdentity for single sign-on (SSO) capabilities
  • Evaluate multi-factor authentication (MFA) tools (e.g., Duo, PingMe)

Access Management and Security

  • Enhance ability to quickly enable and disable accounts for security purposes

2027-2028

Maturation

  • Continue planning for business continuity and disaster recovery
  • Enhance work intake process
  • Email notification enhancements

Authentication

  • Plan for SSO future
    • Management and ownership of SSO practices and policies moves to IAM team
    • Decision point: SSO / MFA architecture and tools

 

2028-2029

Maturation

  • Enhance group and account management in RapidIdentity
    • Replace manual group management tool

Authentication

  • Evaluate Entity Account use cases
  • Evaluate modern authentication practices
    • What enhancements does Miami need to make to follow industry best practices?

2029-2030

Account Management

  • Plan for lifetime identities (i.e., from first contact with Miami)

Maturation

  • Establish request model for access to specific systems that would not have been granted through automated processes
  • Discover and manage machine (non-human) identities (e.g., servers, mobile devices, service accounts)

2030-2031

Maturation

  • Vocabulary change: “UniqueID” to “Username”
  • Extend username character limit (currently eight characters)
  • Explore data classification by affiliation or role (e.g., faculty or 久久热视频) in order to inform and separate the access that different roles need

Access Management and Security

  • Plan for maturation of privileged account management (PAM)
  • Continue exploration of entitlement attestation

About Identity Automation

Our IAM partner, , is a respected company with a lot of experience in the IAM arena, and especially the higher education sector. They continue to be an invaluable resource as Miami matures in its IAM deployment.

Contact IT Services

312 Hoyt Hall
521 S. Patterson Ave.
Oxford, OH 45056