Librarians and identity and access management (IAM) practitioners are solving the same problem; they just don’t know it yet. That was the impetus behind the March 3, 2026, InCommon Thread Meetup, where library staff, IAM teams, federation operators, and content vendors came together to talk honestly about why federated identity adoption in academic libraries remains so low.
Want to be a part of the conversation? Join us for the next InCommon Thread Meetup.
The Access Problem is Bigger Than You Might Think
The discussion began with Amanda Ferrante, principal product manager of Identity & Access Management at EBSCO, sharing a data point: Of the roughly 8,000 academic libraries that are EBSCO customers and belong to federation identity providers, about 70% are not using their federation for access.
The technology is available. However, organizational and cultural barriers persist. IP-based authentication became entrenched over the years, and its failures have since become nearly invisible.
Two Communities, One Problem
The Thread Meetup conversation highlighted that libraries and IAM teams have been operating in parallel silos, rarely sharing a seat at the same table.
Zhaneille Green, E-Access librarian at Duke University, noted that librarians often worry about losing control over access decisions and struggle to manage patron groups that don’t neatly fit into IAM systems, such as walk-in users. Many also lack the capacity to navigate federation terminology and vendor negotiations.
At the same time, IAM teams built federation infrastructure around research collaboration use cases that didn’t anticipate the needs of library licensing, patron privacy requirements, or multi-campus or multi-department access restrictions.
Privacy is a Feature, Not a Risk
During the Thread Meetup, speakers directly challenged a common misconception about federation — that it means giving vendors more data about your patrons.
Albert Wu, InCommon Federation Service manager at Internet2, made it clear that privacy is a foundational principle of research and education identity federation, and that identity providers retain control over what is released.
The REFEDS access entity categories (anonymous, pseudonymous, and personalized) offer a framework for automating those protections in ways that could address many library concerns. Getting more institutions and vendors to adopt these categories is one of the clearest near-term paths forward.
What Comes Next
While there is no quick fix for the gap between library workflows and federated identity adoption, the community identified several concrete steps for progress during the Thread Meetup.
Recommendations included building shared language for library-specific access entitlements, increasing IdP deployment of access entity categories, and bringing large content aggregators into the standards conversation.
Perhaps more importantly, collaborative sessions like Thread Meetups, where librarians and IAM practitioners are in the same room, are part of the solution.
InCommon will use feedback from this session to shape future programming. If you’re interested in joining the conversation, we invite you to sign up for the Federated Identity in Academic Libraries Slack Channel hosted by InCommon.