Reading Time: < 1 minute
Federal Agencies Banner

Streamline Authentication and Identity Assurance Through InCommon Federation

Enable secure researcher access to your systems while reducing costs and administrative overhead. Leverage InCommon Federation for trusted access for thousands of research institutions worldwide, comparable to NIST identity assurance and authentication standards for federal systems.

Reduce Costs and Complexity While Meeting Federal Security Requirements

By registering your systems in InCommon Federation, federal agencies can focus on their service-delivery mission while colleges and universities handle credential lifecycle management and multi-factor authentication deployment of their (and your) users.

How InCommon Addresses Federal Agency Needs

  • Cost Savings: Eliminate expenses for MFA deployment and identity vetting for external researchers.
  • Massive Scale: Access to 6,000+ identity providers from US and global institutions.
  • Enhanced Usability: Researchers use familiar university credentials, improving user satisfaction.
  • Credential Lifecycle Management: Universities manage account creation, updates, and deactivation.
  • NIST Comparable: REFEDS MFA Profile and Assurance Framework IAP-High comparable to AAL2 and IAL2 requirements.
  • Reduced Maintenance: Lower overhead with accounts managed by home organizations.
  • Identity Assurance: InCommon supports the REFEDS Assurance Framework and has released related implementation guidance.

NIST Standards Alignment

InCommon promotes the REFEDS MFA Profile and Assurance Framework, which Authorizing Officials can accept as comparable to AAL2 and IAL2 levels of risk mitigation. We provide documentation mapping REFEDS Assurance standards to NIST SP 800-63-3 IAL2 requirements.

Proven Federal Implementations

Join NIH’s eRA Commons and other federal systems already using InCommon. Our federation enables secure access for grant management, research collaboration, and data sharing while maintaining federal security standards.

Ready-to-Deploy Testing Tools

Use the InCommon Readiness Checker to validate your service provider configuration. Test MFA requirements, identity assurance levels, and attribute release policies before going live.

Featured Federal Implementations

A female individual sorting color coordinated stacks of paperwork.

An Update on the InCommon Community’s Readiness to Support NIH

By Tom Barton, InCommon Research Consultant, Internet2 In Fall of 2020, leaders from the National Institutes of Health (NIH) first addressed the InCommon community about how allowing researchers to use InCommon-enabled home credentials made it easier and faster for them to collaborate on the development of the COVID-19 vaccine.  At Internet2’s TechEX 2020, they highlighted three aspects of federated logins that help the agency manage risk: InCommon/NIH Community Update: MFA and Identity Requirements WebinarJoin us on Thursday, April 20 at 2 p.m. ET for a briefing on the InCommon Community’s readiness to support NIH. User Attributes from the Research & Scholarship Entity Category, which enable automatic enrollment of Identity Providers that support the R&S Entity Category into NIH’s federated login service and smooths the user experience. Multi-Factor Authentication (MFA), signaled by the use of the REFEDS MFA Profile, a security measure now required to access most NIH services. Identity Assurance Information, conveyed using the REFEDS Assurance Framework, (RAF) another security measure becoming required by NIH services that provide access to sensitive data as those services adapt to meet recent federal security requirements. Since then, NIH has provided tools and data and coordinated with Internet2 on outreach efforts aimed to help InCommon participants concerned with supporting their NIH researchers to enhance their identity and access management (IAM) processes and technology to enable these aspects of federated logins. Our Progress Thus Far So how’s it been going? There’s good news and bad news. First, the good news:  Automatic enrollment of campus Identity Providers, which enable researchers and research administrators to use their campus credentials through InCommon, has reduced previous cycle times from several weeks down to one day. In addition, support of MFA signaling by campus InCommon Identity Providers (IdP) increased by over 200%. The following graph shows how InCommon members responded strongly to the announcement by the electronic Research Administration (eRA), the NIH grants management system, of a September 2021 deadline for MFA. What’s the not-so-good news?  Across those 200+ schools, many campus researchers involved with NIH projects have chosen to use login.gov credentials over their campus credentials.  The following graph, based on login data gathered at the NIH Login Gateway, shows how often researchers at the top 40 research and education organizations, in terms of overall NIH grant funding, chose to use their campus credentials versus login.gov credentials to access eRA.  So why haven’t campuses taken full advantage of the investment they made to ease their researchers’ access to eRA and NIH data services? One theory is that researchers are unaware that they can use their campus credentials.   If your college or university is InCommon-enabled for NIH access, consider reminding your research community that they can use their campus credentials to access NIH resources through InCommon. You’ve already done the work! It’s time to get a return on your investment! Where to Next? Get Ready for Identity Assurance Requirements Given the sensitive nature of NIH data services, researchers will need to be adequately identity-proofed either to NIST standards or to the roughly equivalent global research and education federation standard, the REFEDS Assurance Framework. Identity proofing is checking that someone is who they claim to be, usually by comparison with government-issued identification like driver’s licenses or passports, similar to what institutions do when hiring employees. MFA and identity proofing together mitigate the risk that an unauthorized person is given access to sensitive data, as so much of NIH’s data is. Although specific deadlines have not been determined, it is prudent to begin your implementation of an identity-proofing process sufficient to cover researchers for their work with NIH data services. Consult the InCommon-community report REFEDS Assurance Framework Implementation Guidance for InCommon Participants for practical guidance suited to U.S. colleges and universities. Commercial identity proofing services also exist that you can integrate within your IAM processes. See the Kantara Initiative’s Trust Status List of Component Services for the latest information on which ones are approved. So, please continue supporting NIH’s requirements for MFA and identity proofing by implementing the standards referenced above, and consider how you can ensure that word gets out to affected researchers at your institution. It really makes a difference.

Learn more
InCommon Federation logo to be used for featured images.

One Federation, Many Agencies: How InCommon Simplifies Federal Compliance Requirements

In October 2024, the National Science Foundation (NSF)  announced new multi-factor authentication (MFA) requirements for Research.gov access. Those of you following along at home probably remember the National Institutes of Health (NIH) requiring MFA for access to their grants management system, eRA, in September 2021. It’s not uncommon for each federal agency to announce overlapping but related compliance requirements for access to different systems based on security and/or business needs. This leaves higher education IT to juggle these overlapping but slightly different needs, each released at different timelines for different campus groups. It also forces IT to create complex systems that can simultaneously satisfy the highest standards of multiple regulatory frameworks while still remaining usable, affordable, and efficient for their diverse campus communities. So How Do We Make It More Efficient and More Affordable? The solution requires a conversation with those wanting the change, and those needing to respond to it, to agree on a systematic but flexible approach that balances technical capabilities, operational efficiency, and risk management. That’s what the InCommon Federation, the U.S. community access framework for research and higher education operated by Internet2, is all about. To support the recent NSF and previous NIH changes, InCommon is working closely with these key federal agencies to ensure that:  What you support for one through InCommon will work for the other when the time comes.  The community can evolve the Framework to reflect the changing needs of its participants.  That’s the beauty of standards and a community-driven access framework. For instance, when NSF announced in its October 11 Dear Colleague Letter that Research.gov users would need to enroll in MFA, the impact was minimal for most of the 122 organizations integrated with Research.gov through InCommon. Seventy-seven percent (77%) had MFA support in place thanks to earlier work with NIH’s grants management system. For researchers at these institutions, the transition was seamless – their login experience remained unchanged before and after the NSF deadline. In the days before and after the deadline, InCommon staff worked with the remaining institutions and NSF to raise the total percentage to 95%. That means a week later, researchers at 116 institutions used their InCommon-enabled campus credential to sign into Research.gov., facilitating more time for discovery, less time for password management.  What’s in Store for the Future? More Change. As we all know, NSF and NIH both are working to increase their security while containing costs, just like higher education.   Federal agencies are increasingly pushing campuses to strengthen authentication beyond basic MFA with a growing focus on phishing-resistant MFA protocols and enhanced identity assurance measures.NSF is planning to leverage federation standards (REFEDS MFA Profile) to signal the need for MFA at the time of access (similar to NIH) through the InCommon Federation. Longer term, they are also requesting that InCommon-registered campus SSO systems be able to support phishing-resistant MFA. Other agencies are interested in this as well.  Building on the MFA rollout in 2021, NIH is also interested in campuses being able to signal identity assurance using the REFEDS Assurance Framework v2. InCommon is sponsoring a working group to update best practices around supporting this key standard.  We have work to do as a community and as professionals at our own organizations. Every step we take together strengthens not just our individual institutions, but our entire research and education community. What Can You Do Now to Prepare? 1. Participate in the community discussion.  At the Internet2 Technology Exchange, we’ll be hosting a conversation about federal agency compliance and the access management portions in particular: What does the community need to support the federation standards? You can do your part to help more campuses support the MFA standards through InCommon. We’ll also be discussing phishing-resistant MFA requirements and techniques that are implementable at the campus level.  We’d love to see you there! 2. Develop your organization’s action plan. If you haven’t already, implement MFA as a default for campus SSO credentials, connect it into your InCommon-registered identity provider, and implement the REFEDS MFA Profile to signal that to federated partners. Review your identity assurance practices and reflect them in federation following REFEDS Assurance Framework v2 and the guidance the InCommon working group is developing.  Stay engaged with InCommon and consider helping the community as we develop updated federation standards concerning phishing-resistant MFA. Level Up Your Campus IAM Security Here’s our challenge to you: Don’t wait for these changes to become mandatory. Make 2025 the year you level up your campus IAM security. Your researchers will do more discovery and less password management, and your IT security officer will thank you! Feel free to reach out to help@InCommon.edu if you have questions or would like to discuss your IAM and MFA needs. ICYMI MFA Required for NSF Research.gov Starting Oct. 27, 2024

Learn more

 

Review the Toolkit: Start Your Pilot Program

Join NIH and other federal agencies using and exploring InCommon Federation. We’ll help you design a pilot that demonstrates security compliance and operational benefits. Check out the tools below.

InCommon Trust Model Overview

This provides an overview of how InCommon works and integrates with the global community of Research and Education Federations.

Getting Help

CI Logon and RDCT both provide services to Federal Agencies looking to leverage the InCommon Federation and international research access.