Skip to main content

The Wizards Behind the Curtain

Today

One superstar UITS department works in the background, connected to nearly every campus technology. 

Image
IAM Banner Graphic

University IT Services teams are constantly implementing improvements—from network speed, to application updates, to reducing phishing emails. Almost all campus technologies, though, rely on identification, authentication and authorization. Every time you log in with your NetID and password, campus systems verify your identity and affiliation (student, employee, retiree, etc.). This architecture is the domain of the Identity & Access Management (IAM) team.  

Technology projects often require the active participation of IAM for large or small portions of its work. In the past year, IAM supported: 

Mandatory Annual Information Security Training. To meet the university’s new security requirements, a whole new process was added within WebAuth and IIQ to check whether the person logging in had completed their required training and to link them to EDGE Learning if they were overdue.  

The NetID Portal redesign. The new portal was part of a larger project to simplify the onboarding process for new students and employees. It required extensive application development on the back end to change the system for creating NetIDs, passwords and Duo setup.  

CatCard for Mobile. The CatCard team worked with an IAM developer to create a process to identify eligible users, and to create a new attribute that identifies what CatCard option every user on campus is using. 

IAM also gets called on to identify groups of users to support project needs. Examples include: lists of all student, alumni and retiree CatMail users when they were migrated to Outlook, and lists of uarizona Slack users when communications were transitioned to Teams.  

A Major In-House Initiative 

IAM is undertaking a big lift of its own—implementing a new, streamlined identity and access architecture. Started in September 2024, this project is making SailPoint the foundation for the university’s identity management system.  

IT staff have added various applications over the years to meet the needs of the time. Identity and access are no exception—the diagram for authenticating logins from different systems and information sources looked like a plate of spaghetti noodles before this streamlining work began. Implementing SailPoint cleans up the diagram and improves security visibility and access control.  

The SailPoint service is part of the university-wide push to improve information security. It provides more visibility into data governance (who has access to what systems) and reduces risk through better monitoring. It also optimizes developer time with automated workflows and modeling.  

This central system also makes reacting to changes easier. When the university ended its NetKernel license, the team successfully migrated those processes to Boomi. Currently Microsoft is planning to sunset its Microsoft Identity Manager (MIM). IAM is coordinating with the UITS Microsoft team to migrate numerous MIM functions to SailPoint.  

Redesigning and implementing the new identity and access architecture has been a multi-year project. The needs of other university projects, vendor changes and security audits take precedence. However, the team is looking forward to completing the final implementation step—moving IIQ to ISC—at the end of the summer. Then next steps include UAGC integration and transitioning UA's AccessFlow access request system into SailPoint.  

The Teams Within the Team 

Rhonda Royse is the assistant director of identity, access, and integrations. Under her, three groups manage different facets of her purview.  

Systems, Integration & Applications (SIA). Under lead Mark Fischer, this is the team responsible for much of the foundational systems architecture and service operations described above. They manage 80 core university systems, including SailPoint, Enterprise Data Service (EDS), NetID, Duo and WebAuth 

Enterprise Integration Platform Services (EIPS). Under lead Brett Bendickson, this team is primarily responsible for developing integrations with Salesforce as well as offering Boomi as a service to other units in UITS. 

Access Management Team (AMT). Under lead David Drozd, this team goes deeper than the authentication provided by basic affiliation (student vs. employee, current vs. former, etc.) to approve requests from employees who work in a role that requires access to more protected information within Trellis, Analytics and other UAccess systems. They also support audits that ensure no one has access to protected information who shouldn’t.  

Together these teams touch the campus community daily with every login. Behind the scenes, they protect access to university systems and information. They continually work to improve the campus identity architecture for the campus community. And when a department or project team needs them? IAM is there to help 

24/7 Chat Now