Signal #4 in our “6 Signals from ACAMP” Series
InCommon is publishing a series of blogs to recap what we learned from the IAM community during Advance Camp at the 2025 Internet2 Technology Exchange. This blog is the fourth installment in the series.
In late 2025, identity and access management (IAM) professionals from around the world gathered at Advance Camp (ACAMP) at the 2025 Internet2 Technology Exchange. Together, they led interactive sessions on a range of IAM topics, including federation challenges, learning opportunities, IAM architecture, and more.
What is ACAMP?
Advance CAMP is held at the end of every Internet2 Technology Exchange.
Every year, IAM professionals — from IAM novices to late-career IT professionals — gather to pitch their own topics, run demos of tools, and participate in breakout discussions. Attendees build the agenda live and on the spot. Each session is collaborative and conversational, and dedicated scribes take notes to capture the conversations for the broader IAM community.
Following ACAMP, the InCommon team reviewed scribing document notes and identified six distinct signals that emerged from the conversations. These signals offer insight into what is shaping IAM and what is likely to drive focus and action for the research and higher education (R&E) community in 2026.
InCommon is running a blog series to share these insights. We will share the discussions that took place at ACAMP and connect them to past or ongoing efforts from InCommon and the broader IAM community.
This blog, our fourth in the series, recaps ACAMP discussions around federation.
Federation was the defining conversation at ACAMP 2025. A dozen sessions touched on topics such as onboarding barriers, protocol coexistence, identity attribute transitions, and catalog gaps.
What We’re Hearing About Federation in R&E
Federation’s technical foundations are sound. The friction is felt around the human and organizational systems built around them.
While technical solutions are available, institutions still wrestle with business models, cultural knowledge, and organizational capacity.
The following hurdles and solutions were surfaced during conversations at ACAMP:
Pain Points Mapped Out
IAM practitioners put federation challenges into the following buckets:
- People – Institutions face understaffed Identity Providers (IdPs), expertise drain, and vendors lacking federation competence. Even federations themselves are stretched thin, risking falling behind on what the community needs.
- Process – When something goes wrong, it’s rarely clear who owns the fix. Practitioners reported issues with inconsistent documentation, wide variation in metadata quality, unclear authorization responsibilities, and finger-pointing instead of collaborative troubleshooting.
- Technology – Technical issues include identifier transitions, Service Providers (SPs) failing to refresh metadata from federation URLs, and confusion over certificate management.
This is informing the InCommon Technical Advisory Committee’s work on formalizing federation expectations.
OpenID Federation Isn’t Replacing SAML
Discussions across multiple sessions cautioned against building OpenID Federation infrastructure ahead of demand. InCommon Federation grew from killer applications, not the other way around.
The community identified two potential drivers worth watching: federated trust for agentic AI and the American Science Cloud. The American Science Cloud is a Department of Energy initiative that brings new research communities into the picture who have yet to engage with federation.
IAM teams should plan for dual protocols long-term. The question isn’t when SAML goes away, but rather how to run both responsibly.
Cultural Knowledge Is Eroding
The cultural knowledge that has reliably existed in R&E leadership is disappearing at many institutions. CIOs who come from industry may not bring that knowledge, and vendors may lack a fundamental understanding of the value of multilateral federation.
The community identified the following needs to help address the problem:
- Documentation
- Video content specifically aimed at rebuilding federation literacy among R&E CIOs
- Stronger support for multilateral federation at the technical and executive levels
IDEA Report Out – A Strategy for Cross Institutional Course Sharing
Architecture Blocks Relying Party Onboarding
Vendor systems use email as a primary identifier and lack federation-compatible tech stacks. Their architecture fundamentally isn’t built for multilateral federation.
The sponsorship model meant to address this has its own “chicken and egg problem.” Education contracts incentivize Relying Parties (RPs) to join, but the institutions best positioned to offer them have leadership who increasingly don’t understand what they’re being asked to offer.
The community is exploring solutions, including pooled resources for developer-friendly federation libraries. In the long term, OpenID Federation may offer an opportunity to get the architecture right from the start.
SP Retention Is Fragile
RPs join InCommon to win college contracts and then disengage, often without understanding what they’re leaving behind.
Several solutions were suggested by practitioners at ACAMP:
- Onboarding toolkits
- RFP guidance for IAM teams
- CEO-level messaging
- InCommon Catalyst promotion
Practitioners are also building dashboards that show InCommon integrations essentially don’t break, while bilateral ones do.
InCommon Catalysts share key trends in federation, trust management, and more.
Subject Identifiers Face Real Adoption Barriers
New identifiers such as subject-id and pairwise-id exist, but many SPs still use legacy identifiers, and resistance is increasing.
As one co-author of the subject identifier spec observed, vendors once agreed that email wasn’t an appropriate identifier; some now argue that it is.
Another concern is that as library resources federate, certain vendors are quietly shifting toward collecting Personally Identifiable Information, often without libraries realizing it.
Any progress will require major SPs like Elsevier and EBSCO to demand new identifiers, such as pairwise-id, and create market pressure that makes the migration worthwhile.
Discovery Gaps Block Progress
The IAM community can’t easily answer these questions:
- What services are available to use on campus?
- Which integrations support which standards?
Service catalog needs, MFA capability signaling, and federation reliability dashboards were all mentioned as critical missing infrastructure.
Research Communities Need a New Framework
Another important conversation that happened at ACAMP centered on whether to write the Federated Identity Management for Research (FIM4R) version 3.
The FIM4R framework has shaped global R&E IAM requirements since 2012. Two forces are driving the case for an update: smaller research communities that lack dedicated IAM staff and are now subject to increasingly mandated assurance requirements, and a funding landscape shifting faster than infrastructure can keep pace.
The community agreed to move forward with a goal of a skeleton document that would be ready for discussion at the Trust and Internet Identity Meeting Europe (TIIME) in February 2026. At TIIME, attendees worked through an exercise to determine whether a new version was needed and what topics it might include. The group brainstormed potential enhancements, with each suggestion requiring a sponsor to lead the discussion.
Stay Connected for More From ACAMP 2025
Keep your eyes open for more blogs in this series about everything we learned about the IAM landscape during ACAMP.
You can find InCommon blogs on our social media channels. Want to get the news delivered directly to your inbox? Sign up for the monthly InCommon Newsletter.
Note from the author: These signals were informed by a review of ACAMP session notes, with artificial intelligence used to help summarize themes and surface patterns. We encourage you to explore the 2025 ACAMP scribing documentsand draw your own insights from the community’s discussions.