Identity and Access management (iAM)
Details
Project Status
On Target
Last Reported
Project Manager
Project Sponsor
Vice Provost Info Tech & CIO
Business and Financial Affairs
Description
Western Washington University has hundreds of separate systems that have their own username and password management. Most of these systems are integrated by Enterprise Application Services (EAS) and must be manually maintained. Because of the manual entry, permissions don't always get updated or removed with employee status changes.
With the exponential increase in Software as a Service (SaaS), it is critical/crucial that identity management is kept in sync across disparate systems. The interrelationship between systems creates the need for tighter integration of identity management.
The existing account management method was home-grown 30 years ago. Because additional capabilities and features have been added organically over the years, these efforts have not been documented fully. There are aspects of the current process that are only known by one person. This is a huge risk.
Why is this important now? We now have over 100 SaaS systems, each with some form of username/password management. The number of SaaS systems increases annually and makes the control of usernames and passwords unmanageable. The knowledge required to manage all the disparate systems has grown exponentially. Additionally, Federal and State laws now mandate that we perform security audits and keep records.
Status Summary
The required licensing is now in place within Western's Microsoft365 tenet and the access management work group will continue their learning and testing of the functionality. They have also begun the process of inventorying all Microsoft Groups and understanding their properties and uses. The identity work group has drafted an architecture document and diagram and are working to refine both as well as comparing the identity creation processes for students and employees.