Reading Time: 4 minutes

Signal #5 in our “6 Signals from ACAMP” Series

InCommon is publishing a series of blogs to recap what we learned from the IAM community during Advance Camp at the 2025 Internet2 Technology Exchange. This blog is the fifth installment in the series.

What is ACAMP?

Advance CAMP is held at the end of every Internet2 Technology Exchange.

Every year, IAM professionals — from IAM novices to late-career IT professionals — gather to pitch their own topics, run demos of tools, and participate in breakout discussions. Attendees build the agenda live and on the spot. Each session is collaborative and conversational, and dedicated scribes take notes to capture the conversations for the broader IAM community.

Read the 2025 ACAMP Scribing Notes

At the end of 2025, identity and access management (IAM) professionals from all corners of the world gathered at Advance Camp (ACAMP) at the 2025 Internet2 Technology Exchange. Together, they led and participated in sessions on a range of IAM topics, including lifecycle management, security solutions, IAM architecture, and more.

Following ACAMP, the InCommon team reviewed scribing document notes and identified six distinct signals that emerged from the conversations. These signals offer insight into what is shaping IAM and what is likely to drive focus and action for the research and higher education (R&E) community in 2026.

InCommon is running a blog series to share these insights. We will share the discussions that took place at ACAMP and connect them to past or ongoing efforts from InCommon and the broader IAM community.

This blog, the fifth installment in the series, recaps conversations about identity lifecycles and identity management that took place at ACAMP. 

These talks explored how cost pressures, security risks, and stakeholder conflicts are forcing institutions to rethink lifecycle management, particularly for populations whose accounts often outlast their active need for access.

What We Learned About Identity Lifecycle Mangement at ACAMP

IAM practitioners in R&E must manage accounts for more than just staff and faculty. External populations now account for a significant and growing share of accounts at some institutions. 

Even with that growth, many of those external identities are managed through informal processes and unclear ownership.

So, what are institutions doing in 2026 to tackle these complex identity scenarios? Here is a snapshot of what we learned during ACAMP:

Ending “Email for Life”

Cloud storage costs continue to rise. At the same time, unmanaged email accounts pose significant security risks for institutions. These factors are driving institutions to end “email for life.” 

Some practitioners recommended using Grouper to automate offboarding while preserving authentication-only access, or to provide limited system access to former employees who still need it.

External Identity Registries Prevent Clutter

IAM practitioners from different institutions shared their experiences with identity registry solutions. 

COmanage, midPoint, and Fischer Identity mint unique identifiers for guest populations without overwhelming HR and student information systems. MidPoint also handles provisioning and lifecycle management for these populations. 

Sponsors sometimes gravitate toward account types that grant the broadest access — a pattern attendees called “affiliation shopping.”

Grouper, midPoint, and COmanage are all part of the InCommon Trusted Access Platform suite of IAM tools. Learn to harness the power of these open source software solutions with flexible training options from InCommon Academy.

Learn More

Account Sprawl Requires Consolidation

External identities — contractors, affiliates, parents, lifelong learners — have accumulated into many distinct account types at some institutions.

What are institutions doing to manage this sprawl? An emerging approach prioritizes fewer flexible core types with entitlement add-ons over rigid buckets that lose utility as people shift roles.

Every external account should carry a designated sponsor and an end date.

Multi-factor Authentication is Based on Resource Risk, Not User Type

Loosely affiliated users who access financial aid or student records now require multi-factor authentication, regardless of how often they log in. 

Time-based one-time passwords can be unreliable for infrequent users whose authenticator apps go stale between logins. Email-based one-time codes were proposed as a possible middle ground.

One framework from the session groups users into two buckets — those who behave like staff or students, and those who behave more like visitors — and sets multi-factor authentication requirements accordingly.

Identity proofing ensures that someone really is who they say they are. The InCommon Academy Identity Proofing Accelerator is a collaborative program for teams charged with improving identity proofing at their institutions. Sign up for our next cohort today.

Protect Against Financial Aid Fraud

Vendor Scale Assumptions Don’t Line Up with Reality

SaaS vendors consistently underestimate R&E data throughput and population churn. One attendee suggested telling vendors to think of it like a Fortune 100 company doing two mergers a year. That is the level of population change and data throughput they need to be ready for. 

Navigate’s hosted ITAP approach emerged as a solution with per-component (rather than per-account) costs.

Stakeholder Misalignment Blocks Progress

Registrars want frictionless enrollment, but don’t own the security risk. HR resists managing non-employees. Benefits offices promise lifetime institutional access without first consulting IT.

Successful approaches require escalating to executive levels early, including the right stakeholders from the start, and using cost and risk data to drive accountability.

Presenting the costs of past incidents to leadership was one tactic teams suggested for securing policy support.

It’s Not Just You – Identity Lifecycle Management Isn’t Easy Work

At ACAMP, we heard from many different institutions about the increasingly complex field of lifecycle management.

IAM isn’t about creating perfect categories. It’s about protecting resources as real people move through changing roles. 

Sponsorship models can help; every account needs an owner and an end date. But meaningful progress requires getting IT, HR, and institutional leadership aligned not just on tools, but on who owns the risk.

Stay Connected for More from ACAMP 2025

There is one more blog in this series about everything we learned about the IAM landscape during ACAMP. Please return to the InCommon site to finish this series with us.

You can find InCommon blogs on our social media channels. Want to get the news delivered directly to your inbox? Sign up for the monthly InCommon Newsletter.

Note from the author:These signals were informed by a review of ACAMP session notes, with artificial intelligence used to help summarize themes and surface patterns. We encourage you to explore the 2025 ACAMP scribing documentsand draw your own insights from the community’s discussions.