The Identity and Access Management (IdAM) service provides administration and support for University identities, accounts, access, and authentication integrations. Standard identity provisioning and automated account lifecycle processes are provided through centralized University of Missouri System (UM System) identity services. IdAM supports local account and access administration, manual lifecycle activities, exceptions, and integrations that are not handled through these automated processes.
When a request involves a centralized identity service or requires changes outside the scope of local administration, IdAM will coordinate with the appropriate UM System team for resolution. Changes to authoritative identity information, such as employment or other personnel information maintained by a system of record, may require action by the University office responsible for that information rather than IdAM.
Service Offerings
- Account Management - Provides manual administration of supported University accounts, including administrative account creation, summer camp account creation, account locking, decommissioning, and authorized decommission exceptions or deadline extensions. Most standard employee and student account lifecycle activities are automated through UM System identity services; IdAM provides assistance when authorized manual intervention or an exception to the normal lifecycle is required.
- Access Groups - Provides assistance with the creation, modification, ownership, membership, and management of supported groups used to control access to University systems and resources. Access is managed according to appropriate authorization and least-privilege principles.
- Service Accounts - Provides creation and management of supported non-person accounts used by applications, systems, services, integrations, or automated processes. Service account requests are evaluated based on business need, ownership, intended use, required access, and applicable security requirements.
- Application SSO Integration - Provides assistance integrating applications with University centralized authentication and Single Sign-On (SSO) services. IdAM works with application owners and appropriate UM System resources to configure supported authentication integrations and ensure access is implemented in accordance with University identity and security requirements.
Policies and Requirements
Identity and Access Management activities are performed in accordance with applicable University of Missouri System policies, standards, procedures, and security requirements. These requirements govern how University accounts and access are established, maintained, used, retained, restricted, and decommissioned.
Applicable policies include:
IdAM will also follow other applicable UM System information security, acceptable use, identity and access management, data protection, and technology policies, standards, and procedures when those requirements apply to a particular account, access request, or integration.
Account decommissioning, exceptions, and extensions will be processed according to established UM System eligibility, authorization, approval, and documentation requirements. IdAM implements appropriately authorized lifecycle exceptions and extensions but does not independently override eligibility requirements established by UM System policy or authoritative University processes.
Access to University systems and resources will be provided according to legitimate institutional need and applicable security requirements. IdAM will use established authorization processes and support the principle of least privilege, providing only the access necessary for the authorized purpose.
Where centralized UM System identity services, authoritative source information, or UM System-level administrative action is required, IdAM will coordinate with the appropriate UM System team or University office to resolve the request.
The service provides a consistent, secure, policy-aligned, and auditable approach to identity and access administration while supporting the University's centralized and automated identity lifecycle processes.