{"id":9051,"date":"2018-07-31T15:00:53","date_gmt":"2018-07-31T19:00:53","guid":{"rendered":"https:\/\/michigan.it.umich.edu\/news?p=9051&#038;preview=true&#038;preview_id=9051"},"modified":"2024-07-08T06:05:49","modified_gmt":"2024-07-08T10:05:49","slug":"role-access-management-a-smarter-way-to-grant-access","status":"publish","type":"post","link":"https:\/\/michigan.it.umich.edu\/news\/2018\/07\/31\/role-access-management-a-smarter-way-to-grant-access\/","title":{"rendered":"Role &#038; access management: A smarter way to grant access"},"content":{"rendered":"<p><strong><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-4049\" src=\"https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-e1533060830254.jpg\" alt=\"An illustration depicts a digital access management system\" width=\"600\" height=\"514\" \/>10,456<\/strong><\/p>\n<p><span style=\"font-weight: 400;\">That\u2019s the number of permissions requested by the U-M community since January 2017 for just one system. In this case, it was to add or remove M-Pathways roles in Financials &amp; Physical Resources System. Countless more access requests for universitywide or unit-specific systems or resources happen daily.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Determining the correct level of access in multiple systems is an arduous task that needs to be done every time someone joins the university or takes on new responsibilities. It often requires in-depth knowledge of both the system and how the person will need to use it. Requesting access takes time, creates a great deal of administrative burden, and adds up to a staggering amount of effort spread across the entire university.<\/span><\/p>\n<h1><b>Creating a new tool to manage access<\/b><\/h1>\n<p><span style=\"font-weight: 400;\">The Role and Access Management Project, part of the Enterprise Identity and Access Management (EIAM) program, selected and began to create a tool to improve how access is granted and revoked at U-M. It is designed to accelerate start-up time for new employees, improve data security, replace some manual processes, increase the ability to track and report on access, and simply make it easier for authorized individuals to access the right U-M resources when they need them.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Over the last year, the project team members from Information and Technology Services (ITS) and Health Information Technology &amp; Services (HITS) worked with academic, clinical, and administrative partners to conduct a thorough request for proposal. In January 2018, the cross-campus team selected the Identity Governance tool to provide the new capability to all U-M campuses, including Michigan Medicine. \u00a0<\/span><a href=\"https:\/\/michigan.it.umich.edu\/news\/2017\/06\/30\/role-access-management\/\"><span style=\"font-weight: 400;\">Learn more about the team\u2019s selection process.<\/span><\/a><\/p>\n<div class=\"omsc-box omsc-with-title omsc-with-bg-color omsc-with-icon omsc-icon-style-border omsc-icon-shape-circle\" style=\"border-color:#000000;background-color:#eff0f1;text-align:left\"><div class=\"omsc-box-icon-wrapper\"><div class=\"omsc-box-icon\" style=\"border-color:#eff0f1;color:#eff0f1;border-color:#000000;color:#000000;\"><i class=\"fa fa-info\"><\/i><\/div><\/div><div class=\"omsc-box-inner\"><div class=\"omsc-box-title\">About the EIAM Program<\/div>Completed in June 2018, the\u00a0<a href=\"http:\/\/www.cio.umich.edu\/eiam-program\"><span style=\"font-weight: 400;\">Enterprise Identity and Access Management (EIAM) program<\/span><\/a> at U-M coordinated IAM efforts for all four U-M campuses to simplify and improve the technology and administrative processes that allow authorized individuals to access U-M resources. The multi-year initiative was jointly funded by the Office of the Provost and Michigan Medicine through the end of FY18.<\/div><\/div>\n<p>&nbsp;<\/p>\n<h1><b>Benefits of role-based access using Identity Governance<\/b><\/h1>\n<p><span style=\"font-weight: 400;\">When used with a system or application, Identity Governance will help make sure individuals can access the right resources for the right reasons. Additionally, the tool is designed to answer who has access to which resources, and when and why that access was provided. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">The two teams are working towards using the tool to demonstrate the following benefits:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><i><span style=\"font-weight: 400;\">Streamline access \u2013<\/span><\/i><span style=\"font-weight: 400;\">\u00a0Permissions in multiple systems and applications can be grouped together to assign to a person who needs them to perform a job function. Instead of requesting multiple system permissions, the permissions can be assigned as a group\u2014manually or automatically.<\/span><\/li>\n<li style=\"font-weight: 400;\"><i><span style=\"font-weight: 400;\">Automate access<\/span><\/i><span style=\"font-weight: 400;\">\u00a0\u2013 Permissions can be automatically assigned and unassigned when a person meets pre-defined criteria. The criteria is based on a person\u2019s digital identity at the university, and may be defined using relationship to the university, department, job title, enrollment data, and\/or other attributes. People with the specific identity attributes will receive the access, eliminating the need to manually manage access for each person and significantly reducing turnaround time.<\/span><\/li>\n<li style=\"font-weight: 400;\"><i><span style=\"font-weight: 400;\">Pre-approve access \u2013<\/span><\/i><span style=\"font-weight: 400;\">\u00a0Instead of approving individual permission requests for each person, the criteria and permissions are defined and approved in advance by business process owners, application owners, data stewards, and others responsible for managing access. Tailoring the permissions and criteria to fill specific business needs requires an in depth knowledge of the business processes and system permissions, and will require changing practices around access approval.<\/span><\/li>\n<li style=\"font-weight: 400;\"><i><span style=\"font-weight: 400;\">Enhance security and compliance<\/span><\/i><span style=\"font-weight: 400;\">\u00a0\u2013 The correct amount of access is easier to identify, providing an alternative to requesting too little or too much access by &#8220;modeling after&#8221; someone else. Flexible reports by user, role, group, or application are available for audits, governance, and user support. Access will automatically be updated when a person changes jobs, changes departments, or leaves the university. The tool can be also used to better meet required compliance regulations. <\/span><\/li>\n<\/ul>\n<h1><b>Next steps for Identity Governance<\/b><\/h1>\n<p><span style=\"font-weight: 400;\">Release and expansion plans for Identity Governance will be tailored to the unique needs of the academic campuses and Michigan Medicine. ITS and HITS will continue to collaborate, but plan to approach the tool adoption in different ways.<\/span><\/p>\n<h2><b>Academic campuses<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">ITS and three campus partners will conduct an early adopter phase through December as the Identity Governance Early Adoption project. T<\/span><span style=\"font-weight: 400;\">he College of Engineering, Shared Services Center, and UM-Dearborn will use the tool to automate access for off hours building access, M-Pathways FIN PeopleSoft Procurement roles, and Banner access for Financial Aid Administration, respectively. The team will demonstrate the Identity Governance tool\u2019s key features by automatically granting and revoking the right access at the right time for a targeted population of individuals in select systems.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">ITS will use our findings from the early adoption project to determine plans for further expansion of Identity Governance to more units and to integrate with more systems. Future rollout and availability of the tool will be prioritized based on amount of effort required to integrate systems and adjust business processes, addressing the most significant pain points, and improving the areas with the most manual effort required for managing access. <\/span><\/p>\n<p><a href=\"https:\/\/mcommunity.umich.edu\/#group:ITS%20Identity%20Governance%20Stakeholders\"><span style=\"font-weight: 400;\">Subscribe to updates<\/span><\/a><span style=\"font-weight: 400;\"> from the ITS Identity Governance Early Adoption project. <\/span><span style=\"font-weight: 400;\">If you have questions about the early adoption period for the academic campus, please contact the project team at <\/span><a href=\"mailto:its.identitygovernance@umich.edu\"><span style=\"font-weight: 400;\">its.identitygovernance@umich.edu<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n<h2><b>Michigan Medicine <\/b><\/h2>\n<p><span style=\"font-weight: 400;\">During the Role and Access Management Project, HITS partnered with MiChart and other service providers to connect systems with Identity Governance to standardize, enhance, organize, and simplify access. In doing so, they will build a framework to test and validate the tool\u2019s ability to streamline and automate access assignments and reduce manual effort while increasing accurate control.<\/span><\/p>\n<p><a href=\"https:\/\/cio.umich.edu\/eiam-program\/projects\/role-access-management\"><span style=\"font-weight: 400;\">Visit the Role and Access Management Project webpage<\/span><\/a><span style=\"font-weight: 400;\"> to learn more about Identity Governance. <\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Role and Access Management Project selected and began to create a tool to improve how access is granted and revoked at U-M. The tool is designed to accelerate start-up time for new employees, improve data security, replace some manual processes, increase the ability to track and report on access, and simply make it easier for authorized individuals to access the right U-M resources when they need them.<\/p>\n","protected":false},"author":27,"featured_media":4049,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","_umich_oidc_access":"","_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"_ef_editorial_meta_date_first-draft-date":"1531440000","_ef_editorial_meta_paragraph_assignment":"RAMP project update","_ef_editorial_meta_checkbox_needs-photo":"1","_ef_editorial_meta_number_word-count":"150","footnotes":""},"categories":[7,4],"tags":[251,531,530],"class_list":["post-9051","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-projects-services","category-features","tag-eiam","tag-governance","tag-ramp"],"uagb_featured_image_src":{"full":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-e1533060830254.jpg",600,514,false],"thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-117x100.jpg",117,100,true],"medium":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-233x200.jpg",233,200,true],"medium_large":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-768x658.jpg",665,570,true],"large":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-700x600.jpg",600,514,true],"1536x1536":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-e1533060830254.jpg",600,514,false],"2048x2048":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-e1533060830254.jpg",600,514,false],"excerpt-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-200x140.jpg",200,140,true],"themonic-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-60x42.jpg",60,42,true],"ioslider-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-658x300.jpg",658,300,true],"post-thumbnail":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-665x570.jpg",665,570,true],"400x250-crop":["https:\/\/michigan.it.umich.edu\/news\/wp-content\/uploads\/2017\/06\/noun_996158_164F86-e1533060830254.jpg",292,250,false]},"uagb_author_info":{"display_name":"Lindsay Hendricks, ITS Communications","author_link":"https:\/\/michigan.it.umich.edu\/news\/author\/lcsteele\/"},"uagb_comment_info":0,"uagb_excerpt":"The Role and Access Management Project selected and began to create a tool to improve how access is granted and revoked at U-M. The tool is designed to accelerate start-up time for new employees, improve data security, replace some manual processes, increase the ability to track and report on access, and simply make it easier&hellip;","_links":{"self":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/9051","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/comments?post=9051"}],"version-history":[{"count":14,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/9051\/revisions"}],"predecessor-version":[{"id":9884,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/posts\/9051\/revisions\/9884"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/media\/4049"}],"wp:attachment":[{"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/media?parent=9051"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/categories?post=9051"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/michigan.it.umich.edu\/news\/wp-json\/wp\/v2\/tags?post=9051"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}