Reading Time: 4 minutes

By Kenneth Lewis, Communications Specialist

Of the many conversations being held about security on campus, one consistently rings the alarm and cannot be ignored. 

Identity proofing — the practice of gathering information and verifying that a user is truly who they claim to be before granting them access — has risen to the top of many checklists across research and education (R&E), and for good reason. 

Fraud recovery costs universities more than $100 million each year, while outlets like ABC have warned and reported on ghost student scams, announcing more than 200 open federal fraud investigations at universities.

As fraud grows more sophisticated, assurance expectations are rising, too.

Internet2 commex26 logo

Federal agencies such as the National Institutes of Health and the Department of Education are moving to a higher identity assurance level that makes it more difficult for bad actors to pass as legitimate users, deceive service desk staff, and gain access to payroll and financial aid funds.

Beyond Authentication: When Secure Access Demands Identity Proofing unpacked identity proofing at the 2026 Internet2 Community Exchange, explaining the state of play for identity proofing and what it means to those in R&E. The presenters included Kyle Lewis, vice president of cybersecurity strategy at Research Data and Communication Technologies, Jack Suess, vice president of information technology and chief information officer at the University of Maryland, Baltimore County (UMBC), and Ann West, senior director of strategic partnerships & research for InCommon at Internet2.

Kyle Lewis hosting a CommEx 26 session
Session attendees taking notes

Revisit the session’s main takeaways and review what you might have missed. These three insights reveal what we know to be true: constant delay won’t solve the issue, and the sooner we act, the better.

1: Identity Proofing is an ‘Everybody Problem.’

Though security may be central to an institution’s IT department, it is not exclusive to it. Identity proofing occurs across campuses and in a variety of contexts: during employee and e-verification processes, student verification and registration, in financial aid offices, during initial credential issuance, and at many other common data points across institutions. 

According to Lewis, this makes identity proofing a practice that stretches across the entire ecosystem, making it what he calls a “business problem” and one that should not be charged to IT alone. Campus stakeholders should own their respective pieces in the identity proofing process and work together to raise identity assurance levels to sustain consistent practices in verification and authentication.

2: You Can Begin Today

Though finding a solution to meet federal requirements may seem tedious, Suess offered three practical ways for institutions to begin their work in achieving higher identity assurance right away. 

First, he urged the R&E community to document their identity management processes, the roles responsible for those processes, and the services associated with those roles. He encouraged attendees to share this documentation with the appropriate security and IT leaders at their institutions. “This gives visibility and makes the security process on campuses formal,” he said. 

Second, Suess mentioned a customized, but flexible scoring system based on the level of assurance needed for the type of user. For instance, applicants and alumni might require a lower level of assurance than students or faculty. However, depending on the risk of the services that they will be using, the applicant or alumnus might need a higher level of assurance to access sensitive data, for example. In this case, the institution would step up the assurance level of the user through an already established institutional process.

Third, Suess suggested mitigating risk by limiting the number of services students can access upon matriculation. “The more services a student is able to access increases institutional risk,” Suess said. 

Suess concluded by sharing his preference for granting matriculated students access to only four core services, rather than the more than 10 they are able to use now. This would help reduce the risk to the institution without having to up the identity proofing level for this key user group.

3: Community and Peer Discussions are Key

Institutions find the best identity proofing strategies through collaboration, conversations, and feedback. “Understanding how to implement a campus-wide identity proofing strategy takes a lot of conversations with stakeholders around campus. Learning strategies from peers at other institutions is key to saving time and being more effective,” said West. “When we can collaborate on what good business processes and solutions are, we can strengthen our collective practices across R&E.”

Afterward, West detailed the resources InCommon is offering to help the community grow and learn from each other in identity proofing best practices: a search for an identity proofing service provider, an 8-week collaborative identity proofing training, and workshops at future Internet2 and EDUCAUSE events.

Put These Key Insights Into Practice

The strongest message from this conversation is also its simplest: identity proofing is a community-based strategy, and meaningful progress begins with practical steps. This includes documenting processes, defining roles, limiting unnecessary access, and building alignment across campus.

Fortunately, institutions do not have to figure this out alone. By engaging peers, learning from shared experience, and using community-shaped resources, campuses can be better equipped not only to meet rising expectations but to build more consistent, resilient practices to reduce fraud going forward.