Reading Time: < 1 minute
nCommon higher education use case image of a student sitting on the library floor.

Higher Education 

Connect & Collaborate At Any Scale and Across Any Campus

 

Streamlined, Secure Access

Connect to the InCommon Federation for streamlined, secure access to a multitude of services for your students, faculty, researchers, and staff. Through dedicated community engagement, InCommon delivers secure, innovative IAM solutions while offering training, networking, and expert guidance to research and education institutions.

 

InCommon simplifies and secures digital access management, enabling broader collaboration across the higher education community while reducing IT complexity and improving the user experience for researchers, students, faculty, and staff.

InCommon offers these benefits to higher education

  • Identity and Access Management
  • Federated Identity Management via Trust Framework and Security
  • Global Wi-Fi Access with eduroam
  • Research Collaboration
  • Global Wi-Fi Access with eduroam
  • Cross-Institutional Collaboration

Features and Benefits

Identity and Access Management

InCommon provides integrated single sign-on, cloud access, and global collaboration for students, faculty, staff, and researchers through secure single sign-on access to cloud and local services, as well as global collaboration tools. This eliminates the need for multiple usernames and passwords across different systems.

Federated Identity Management

Rather than having separate credentials for each system, “federated identity management” allows you to use a single digital identity (i.e., username and password) to access all resources to which you are entitled. This streamlines the user experience and reduces password fatigue for campus communities.

Trust Framework and Security

InCommon provides a trust framework enabling secure and scaled single sign-on access to collaborations and resources across participating organizations, creating multilateral trust among all participants, understanding the research and education federation.

Cross-Institutional Collaboration

InCommon helps institutions understand and leverage the federation, learning its role in higher education and research, and its benefits within consortia and for cross-institutional collaboration. This enables seamless collaboration between different educational institutions and research organizations.

Global Wi-Fi Access

InCommon provides eduroam, which gives faculty, students, and staff seamless access to global roaming Wi-Fi. This allows campus users to connect automatically to secure wireless networks at participating institutions worldwide.

Scale and Reach

InCommon includes more than 500 universities in the U.S. Through its connection to eduGAIN, InCommon increases access to over 3,000 organizations across 60 countries. This massive scale enables unprecedented opportunities for collaboration.

Research Collaboration

Faculty and researchers instantly access participating services using campus credentials without IT involvement. The benefits of the research and collaboration entity category include convenience, on-demand collaboration, vetted services, and time and resource savings.

Implementation Support through Partnerships

The InCommon Accelerators help institutions participate in the InCommon Federation and tackle identity and access management challenges. This provides practical assistance for institutions looking to implement or improve their federated identity systems.

Specific Use Cases

InCommon enables access to critical services like NSF’s Research.gov, library databases, NIH resources, and various academic collaboration tools. Faculty, students, and staff at participating institutions can log into many external academic and research services using their university credentials without needing to create separate accounts.

Training and Workshops

TAP Software

The InCommon Trusted Access Platform  (TAP) is an identity and access management suite of software designed to integrate with existing systems. The software is packaged to simplify your installation and configuration so it’s easy for you to get started.

Learn More
BaseCAMP 2026

BaseCAMP is a unique, five-day, virtual event designed for those new to identity and access management (IAM), new to InCommon, or ready to boost their knowledge in this field. BaseCAMP is the perfect pathway to elevate your IAM understanding and capabilities.

Learn More
Identity Foundations Workshop

Dive deeper into understanding the core concepts of identity registry, authentication and authorization, grouping and access, and provisioning.

Learn More
RADIUS Training

Designed for IT professionals responsible for deploying and managing RADIUS infrastructure for eduroam, this technical workshop equips you with the skills to configure, optimize, and troubleshoot your environment.

You’ll learn how to catch and resolve common eduroam issues—from packet loss to UDP fragmentation—and align your implementation with U.S. best practices.

eduroam RADIUS Training
Thread Meetup

Explore our Community Gatherings to spark new ideas, share real-world experiences, and build lasting peer connections through Thread Meetups and more.

Learn More
More InCommon Workshops

Looking for professional development that combines expert insights with practical experience? From technical skills to visualization tools to effective communication, equip your team with the understanding to design, implement, and optimize your IAM solutions.

Learn More

Featured Resources

A group sits together near a white board.

West Chester University

InCommon Collaboration Success Program Case Study Executive summary West Chester University (WCU) engaged with the Collaboration Success Program (CSP) to develop an identity and access management (IAM) roadmap. One of the university’s primary goals was to shift towards a unified identity system. To accomplish this goal, WCU needed to integrate three ERP systems, maintain support for both formal and informal regulatory reporting, facilitate swift onboarding, offboarding, and access adjustments as required, and grant access to individuals who undergo role changes. It was imperative for the WCU team to identify and implement an identity solution while minimizing disruptions to operations and user experiences. The CSP program played a pivotal role in helping WCU modernize its identity roadmap, and the university is well on its way to implementing its IAM solution, which will include COmanage, Grouper, midPoint, and Shibboleth.  Solution summary West Chester University participated in the 2023 cohort of the Collaboration Success Program (CSP) to explore identity and access management solutions.  Trusted Access Platform features supported Grouper, midPoint, MIM, Shibboleth SSO, Duo. The project West Chester University (WCU) engaged with the Collaboration Success Program (CSP) to develop an identity and access management (IAM) roadmap. This plan outlined how the university would move forward with the evaluation of technology products and processes, implementation, and training.   WCU hoped to:   Explore midPoint’s potential as an IAM solution.   Build a prototype midPoint environment capable of replacing current account management scripts and processes, provisioning downstream accounts, and successfully reconciling data from PeopleSoft, Banner, and SAP   Work with Internet2 community members and subject matter experts to obtain deployment guidance and best practices.  The challenge Presently, WCU faces challenges arising from the existence of separate accounts for students and employees, which leads to difficulties during account transitions. They sought to shift towards a unified identity system known as RamNetID, employing affiliations and establishing clear processes and policies for deactivating accounts with well-defined grace periods.  Furthermore, WCU had the following needs:  Integrate three ERP systems – PeopleSoft, SAP, and Banner. Essentially, these systems needed to operate in harmony to prevent duplication problems and ensure uninterrupted access while maintaining appropriate access levels for all stakeholders.  Maintain support for both formal and informal regulatory reporting.  Facilitate swift onboarding, offboarding, and access adjustments as required.  Grant access to individuals who undergo role changes, such as transitioning from student to employee or from employee to retired.  It was imperative for the WCU team to identify and implement an identity solution while minimizing disruptions to operations and user experiences.  The solution WCU is actively progressing toward the realization of its vision and is set to launch a “future state” IAM system in the summer of 2024. At this juncture, the data sourcing process will no longer be conducted within PeopleSoft. “We will employ the Microsoft Identity Manager to provision accounts for new identities using the revised logic that has been under discussion for the past 25 months… thus, we will utilize it for account provisioning,” stated Kevin Partridge, WCU’s executive director of IT Infrastructure Services and deputy CIO.  We’ve discerned that both alterations in business processes and technological advancements will be pivotal in attaining our envisioned end state. These modifications encompass shifts in student statuses and the management of their accounts throughout their academic journey, both before and after graduation. Additionally, the onboarding and offboarding of employees will be governed by an HR system. In the interim, we will implement Microsoft Identity Manager to deliver this solution as we enhance our expertise in midPoint.  Indeed, IAM will be supported by the following at WCU:  Systems of Record: SAP for employees, PeopleSoft/Oracle, Banner for students  IAM Solutions: COmanage, MIM, MidPoint, Grouper  Director & Cloud Services: Microsoft 365, Azure Active Directory (AD), Active Directory  Single Sign-On: Shibboleth, SAML, CAS, OpenID  SSO Apps: D2L, InCommon, and more than sixty additional SSO service providers   The result The WCU team expresses its appreciation for the ongoing feedback, valuable guidance, and best practices generously shared by the leaders and participants of the Collaboration Success Program (CSP). The CSP program has played a pivotal role in helping WCU modernize its Identity roadmap, and the university is well on its way to implementing its IAM solution, scheduled to go live in the Summer of 2024. JT Singh, WCU’s CIO/Sr. associate vice president of Information Services and Technology, shared that, “Participating in CSP helped WCU with its IAM modernization journey working with stakeholders, developing a framework of requirements, evaluating strategies, learning about different toolkits, and achieving tactical successes.”  The project team has already begun work to support the Banner General Person Go-Live, one of the initial modules launched at the university. They are effectively addressing the evolving identity requirements of the university and driving improvements to our existing IAM solution.  Lessons Learned Avoid assumptions: It’s crucial not to assume that common terms like “go-live,” “identity,” or “testing validation” have the same meaning for everyone involved. Delving deeper into discussions and clarifying terminology proved essential for achieving alignment.  Be precise in requirement gathering: Ensure you elicit precise requirements from the integration lead and your partners. Clear and detailed requirements are fundamental for successful project execution.  Be open to change: Don’t hesitate to change course if necessary. Flexibility and adaptability can be valuable assets in navigating complex projects and achieving optimal outcomes.  About West Chester University West Chester University is the largest member of Pennsylvania’s State System of Higher Education, which is comprised of 10 state-owned universities within the Commonwealth of Pennsylvania. Founded in 1871, West Chester University is a comprehensive public institution offering a diverse range of more than 180 academic opportunities in 40 fields of study across undergraduate, graduate and doctoral levels. In addition to the main campus in West Chester, the university offers programs through its graduate center, the campus in Philadelphia, and online. Six colleges and two schools comprise the university: University College, Colleges of Arts and Humanities, Business and Public Management, Education and Social Work, Health Sciences, and the Sciences and Mathematics as well as the Wells School of Music, and the Graduate School. The popular university maintains a consistent presence on both Money magazine’s The Best Colleges in America list and America’s Top Colleges list by Forbes. The university is also a Military Friendly Schools gold status member and has received the Higher Education Excellence in Diversity (HEED) Award from INSIGHT Into Diversity magazine for three years in a row.  Project Team: JT Singh, Kevin Partridge, Steve Safranek, Pete Calvert, Rashed Kabir, Bill Bi, Lisa Disney 

Learn more
A group working with sticky notes on a white board.

Transforming Access Chaos: How Three Universities Are Solving Authorization Complexities with Innovative IAM Approaches

“Who can access what and why?” This simple question costs higher education institutions thousands of staff hours, creates endless frustration for users, and remains one of the most persistent operational headaches across campuses. Behind the scenes of every university’s digital ecosystem is a complex web of access decisions that directly impact daily operations, compliance requirements, and user experience. The Authorization Problem Everyone Feels Think about the last time someone at your institution needed access to a specialized resource. How many emails, approvals, and manual checks were required? How long did it take? And on leaving the university, did that person’s access get properly revoked? Was it revoked immediately?  The reality is this: while authentication (proving who users are) has been generally solved through systems like single sign-on, authorization (determining what they should access) is broken up across hundreds of individual applications. Each service ends up implementing its own authorization rules, creating an unsustainable patchwork that IT departments struggle to manage. This leads to very real daily challenges: The “Ghost Access” Problem: When faculty, staff, or students leave, their access rights often persist for weeks or months because deprovisioning happens at the application level rather than through Central IT.  Training Verification Gridlock: Staff manually check and re-check training certifications before granting access to specialized resources like research environments or sensitive data repositories, creating bottlenecks that delay legitimate work. License Management Burden: Without centralized authorization, enforcing licensing to applications becomes a manual, error-prone process that either wastes money on unused licenses or creates access conflicts. Departmental Request Overwhelm: IT teams field endless access requests that require multiple approvals and manual configuration, taking away resources from more strategic initiatives. Three Institutions Leading the Way The IAM Online webinar on Wednesday, June 18, at 1 p.m. ET entitled “Bridging the Gap: Integrating Authentication with Authorization to Solve Critical Access Challenges in Higher Ed” showcases how three forward-thinking institutions—University of Pennsylvania, Harvard University, and University of Alaska—have tackled these everyday challenges by implementing “front door authorization” approaches. By moving authorization decisions to the entry point of access rather than leaving them to individual applications, these universities have transformed their access management from a constant struggle into a streamlined, policy-driven process. The webinar will showcase effective solutions: University of Pennsylvania’s Front-Door License Management – Penn has revolutionized license management with a “front door” approach that validates access before users reach applications. Their Grouper-based system blocks unauthorized attempts with customized error pages that guide users to self-service options, dramatically reducing help desk tickets. Harvard’s Frictionless Authorization Framework – Harvard has centralized authorization decisions through a Grouper-powered “front door” system, ensuring that only users with current Harvard affiliations can access resources. This approach provides seamless access to the right tools while removing authorization burdens from individual applications University of Alaska’s Real-Time Training Verification – U Alaska integrates certification tracking directly with Shibboleth authentication, stopping sign-in attempts at the identity provider level if training requirements aren’t met. Their system even enables instant access provisioning when training is completed, eliminating manual verification entirely. Speakers Chris HyzerApplication ArchitectUniversity of Pennsylvania Alpha SannehAssociate DirectorIdentity and Access ManagementHarvard University David BantzIdentity and Access ManagementUniversity of Alaska Garick HamlinIAM ArchitectUniversity of Pennsylvania Erin RankinSenior Software EngineerHarvard University Orlandis BrownIdentity and Access ManagementUniversity of Alaska Q&A Ahead of the webinar, our speakers offer these valuable insights into the challenges and strategies for navigating authorization at their institutions: What was one big challenge your institution faced with authorization management before you implemented your current solution? How did you know it was time to make a change? (Chris Hyzer, Penn): I’ve been interested in this since hearing (over 10 years ago at a TechEx conference) about a California school doing a similar thing. A few years back, we learned about Harvard’s success with it and kicked off our own project. We took our time carefully deciding scope, the number of reference groups and their population, a gradual roll-out, and prioritizing “gold-tier” apps. (Harvard): There was an assumption that when users left the University, their access was automatically removed, so application owners were inconsistent in taking action to proactively remove access. This left some terminated employees and other departed affiliates to access sometimes sensitive systems and data. (U Alaska): Departments and administrators with responsibility for compliance with training and certification requirements could not readily enforce, report, or document compliance; a strategic initiative mandated development of tools to do so across the entire institution. How has your approach impacted end users in terms of experience, administrative efficiency, or security? (Penn): We’ve not seen any negative issues. It takes time to explain the new function to service teams and carefully pick the right group to use. (Harvard): During the initial rollout of authorization filters for applications integrated with our SSO system, there was friction when an application owner misjudged the populations accessing their app and applied overly restrictive filters. This resulted in blocked access for legitimate users. We partnered with application teams to better understand their user populations and refine their filters to enable the right access for the right populations. For institutions that are just starting to explore better authorization control, what advice would you give them? Are there any critical first steps or common pitfalls to avoid? (Penn): Try to get a mandate from the top since it is difficult and time consuming to motivate service teams. (Harvard): A mandate from the top is key. We had been offering authorization filters as a service for several years but it wasn’t until our ISDP team instituted a requirement for all applications to have a filter that we got traction with application teams. (U Alaska): Stop ignoring or offloading authorization to services or to “provisioning” scripts. Start building the infrastructure for “front door” authorization in your IAM infrastructure. Looking ahead, how do you see authorization management evolving? Are there any new challenges you anticipate or enhancements you plan to implement? (Penn): Self-service licensing use cases require real-time entitlements from Grouper to Shibboleth, and we are excited to roll out a solution for that in the coming weeks. (Harvard): We are migrating to Grouper v5 and plan to leverage ABAC groups to base access decisions on user attributes, streamlining both group management and policy enforcement. (U Alaska): We’ve had a mantra for many years that identity providers assert identity and attributes, but authorization is the distributed responsibility of services; that has not been deployed at scale. The deployments described today provide an alternative that preserves distributed authority but is represented and managed centrally. Join Us for IAM Online Interested in learning more about how these institutions are handling complex authorization challenges? Don’t miss our upcoming webinar, “Bridging the Gap: Integrating Authentication with Authorization to Solve Critical Access Challenges in Higher Ed,” on Wednesday, June 18, at 1 p.m. ET. Attendees will gain practical insights into how these institutions transformed their IAM systems from basic authentication gateways to comprehensive authorization engines. Whether your organization needs training-based qualification verification or robust group-based access control, this session will provide valuable implementation strategies, lessons learned, and architectural blueprints to address similar challenges. Please note: We’ve introduced a new, improved registration process for our webinars. You’ll now register individually for each webinar, which allows us to deliver content that’s even more aligned with what you want to see. Get ready for more engaging, community-driven webinars designed with you in mind! Do you have ideas for IAM Webinars you would like to attend? Fill out this form and let us know what you’d like to see.

Learn more