Identity Federation Modernization Roadmap
The identity federation modernization roadmap provides transparency regarding the ongoing initiatives affecting our system identity federation.
Program Objectives
The identity federation modernization strategy is a collective effort to achieve the following outcomes:
Disseminate identity, credential and access management (ICAM) responsibility to system members and trusted third-parties (e.g., ID.me)
System members are best positioned to validate the identity of their active users (students, faculty, staff, contractors, and other affiliates). Effective ICAM makes the most sense when administered at this level.
Deprecate the system-level centralized identity stores used for authentication (e.g., TAMUS UIN)
Transferring ICAM to the member and trusted third-party level allows the A&M System to deprecate legacy username/password identity and authentication systems, reducing the attack surface, management overhead, and cost associated with administering multi-factor authentication for large constiuencies of users from across the system.
Leverage the leading research and education authentication federation--InCommon--to provide multi-lateral identity federation for the A&M System
The InCommon Federation has a robust infrastructure purpose-built to support research and education institutions engaging in federated identity transactions with other R&E institutions. The self-service provisioning and management, and dedicated support from Internet2, provides a resilient identity federation to support the A&M System for years to come.
Roadmap
TAMUS SSO Institution Login
Enable system members to use institutional SSO when accessing the TAMUS shared services portal (TAMUS SSO).
TAMUS SSO adoption of ID.me
Adopt ID.me for member affiliates--pre-hires, retirees and beneficiaries.
Transition TAMUFederation to InCommon Federation
Replace TAMUFederation metadata aggregate as system's identity federation with InCommon Federation.
Adopt InCommon Baseline Expectations
Replace TAMUFederation metadata aggregate as system's identity federation with InCommon Federation.