Identity and Access Management (IdAM)

What Is It? 

The Identity and Access Management (IdAM) service provides administration and support for University identities, accounts, access, and authentication integrations. Standard identity provisioning and automated account lifecycle processes are provided through centralized University of Missouri System (UM System) identity services. IdAM supports local account and access administration, manual lifecycle activities, exceptions, and integrations that are not handled through these automated processes.

When a request involves a centralized identity service or requires changes outside the scope of local administration, IdAM will coordinate with the appropriate UM System team for resolution. Changes to authoritative identity information, such as employment, student, or other personal information maintained by a University system of record, may require action by the University office responsible for that information rather than IdAM.

Service Offerings

  • Account Management – Provides manual administration of supported University accounts, including administrative account creation, summer camp account creation, account locking, decommissioning, and authorized decommission exceptions or deadline extensions. Most standard employee and student account lifecycle activities are automated through UM System identity services; IdAM provides assistance when authorized manual intervention or an exception to the normal lifecycle is required.
  • Access Groups – Provides assistance with the creation, modification, ownership, membership, and management of supported groups used to control access to University systems and resources. Access is managed according to appropriate authorization and least-privilege principles.
  • Service Accounts – Provides creation and management of supported non-person accounts used by applications, systems, services, integrations, or automated processes. Service account requests are evaluated based on business need, ownership, intended use, required access, and applicable security requirements.
  • Application SSO Integration – Provides assistance integrating applications with University centralized authentication and Single Sign-On (SSO) services. IdAM works with application owners and appropriate UM System resources to configure supported authentication integrations and ensure access is implemented in accordance with University identity and security requirements.

Centralized Identity Services

Standard University identity provisioning and lifecycle processes are primarily managed through centralized UM System identity services and authoritative University systems of record. These automated processes establish and maintain many standard employee and student identities based on information supplied by systems such as Human Resources and student information systems.

Local IdAM does not normally replace or manually override authoritative identity information or centralized lifecycle processes. When an issue originates with authoritative information, the individual may need to work with the University office responsible for that information. When the authoritative information is correct but an identity or account has not been provisioned, updated, synchronized, or decommissioned as expected, IdAM can investigate and coordinate with the appropriate UM System team.

This distinction allows IdAM to provide a local point of assistance while maintaining the integrity of centralized University identity processes.

Account Lifecycle and Exceptions

Most standard employee and student account lifecycle activities are automated by central identity services. Account Management provides the path for authorized manual intervention when the normal automated process does not address a legitimate University need.

This may include creating supported administrative accounts, creating temporary summer camp accounts, locking an account when immediate restriction is required, manually processing a decommission when appropriate, or implementing an authorized exception or extension to an established decommission date.

Account decommissioning exceptions and extensions will be processed according to established UM System eligibility, authorization, approval, and documentation requirements. IdAM implements appropriately authorized lifecycle exceptions and extensions but does not independently override eligibility requirements established by UM System policy or authoritative University processes.

Access and Least Privilege

Access to University systems and resources will be provided according to legitimate institutional need and applicable security requirements. IdAM will use established authorization processes and support the principle of least privilege, providing only the access necessary for the authorized purpose.

Requests involving administrative or elevated access may require coordination with other Information Security or IT services when an administrative account is not the most appropriate method of accomplishing the requested task.

Coordination with Other University Services

Identity and Access Management works with other University and UM System services when fulfillment requires action outside the scope of local IdAM.

For example:

  • Human Resources, Registrars, International Student and Scholar Services, or other authoritative offices may be responsible for correcting underlying identity or affiliation information.
  • UM System identity teams may be required to resolve issues involving centralized provisioning, synchronization, authentication, or automated lifecycle processes.
  • Information Security may establish security requirements or require account restrictions as part of Security Incident Response, Security Compliance, or other security activities.
  • Application owners may be responsible for authorization and application-specific roles after IdAM establishes authentication or identity integration.
  • Email and collaboration services may be responsible for mailbox or collaboration resources associated with an identity but not directly managed through IdAM.

Customers are not expected to determine which University or UM System team ultimately needs to perform the work. IdAM may coordinate or appropriately route requests when additional teams are required when possible, but may need to direct customers to University and UM System services when necessary.

Policies and Requirements

Identity and Access Management activities are performed in accordance with applicable University of Missouri System policies, standards, procedures, and security requirements. These requirements govern how University accounts and access are established, maintained, used, retained, restricted, and decommissioned.

Key policies include:

  • Email Management Policy – Establishes requirements for management of University electronic mail accounts and associated lifecycle activities. IdAM follows applicable requirements when administering account eligibility, lifecycle, decommissioning, retention-related account actions, and authorized exceptions or extensions.
  • Electronic Mail Use and Management – Establishes requirements governing the appropriate use and management of University electronic mail. IdAM follows applicable account management and access requirements associated with this policy when performing account lifecycle activities.
  • HR-513 Volunteers & Other Unpaid Appointments – Establishes requirements applicable to volunteers and other unpaid appointments. Where an individual's University identity or continued access depends upon an eligible appointment or affiliation, IdAM will administer account actions in accordance with eligibility and authorization established through University processes.

Additional information security policies and standards may apply depending on the account, access, application, or information involved. The complete collection is available in the UM System Information Security Policies Library.

IdAM will follow applicable UM System policies and established procedures when provisioning and managing accounts and access. Account lifecycle actions will be based on established eligibility criteria and appropriately authorized requests, approvals, exceptions, and extensions.

The Identity and Access Management service provides a consistent, secure, policy-aligned, and auditable approach to identity and access administration while supporting the University's centralized and automated identity lifecycle processes.

Who Is Eligible To Use It? 

Eligibility for specific accounts, access, groups, or authentication services depends on the individual's University affiliation, institutional need, applicable policies, and authorization requirements.

Some requests, such as administrative accounts, service accounts, access-group changes, decommission extensions, or SSO integrations, require an authorized business need, sponsorship, system or resource owner approval, or other appropriate authorization before IdAM can fulfill the request.

Requests may also be initiated by Human Resources, University departments, Information Security, IT staff, application or resource owners, or UM System teams when an account or access change is required as part of an authorized University process.

How Much Does It Cost? 

There is no charge to students, faculty, or staff for standard Identity and Access Management services provided as part of University IT services.

Costs associated with applications, licensing, specialized authentication technologies, third-party services, or other resources required to fulfill a particular request may be the responsibility of the requesting department or unit, as applicable.