UTS Standard: Authentication and Access Control

Body

Overview

Controlled access to IT Resources is essential to support Oakland University’s academic, research, and clinical missions. Identification, authentication, and authorization controls ensure that access to IT Resources and University Data is appropriately granted, managed, and monitored to protect confidentiality and integrity.

Scope

This standard applies to all individuals who access, use or administer University Information Resources at the University, including faculty, staff, and students, contractors, consultants, and other agents of the University as well as individuals authorized through affiliated institutions and organizations.  It applies to all authentication mechanisms used to access Information Resources, including passwords, passkeys, and digital certificates,and encompasses, but is not limited to NetID, administrative systems, infrastructure services, and research computing resources.

Standard

Authentication is the process of ascertaining user identity.  System owners are responsible for ensuring Users are securely authenticated.  Appropriate role-based access controls and the principle of least privilege govern access to IT Resources and University Data.  University users are granted access only to those IT Resources and University Data they need to fulfill the responsibilities of their position.

Centralized Authentication

System owners must use University-provided centralized authentication services whenever possible.

Benefits include:

  • Consistent, secure authentication across the University
  • Automatic provisioning and deprovisioning tied to employee and student systems
  • Automatic termination of access when an individual’s affiliation ends

OU authentication credentials must never be entered into unapproved systems for storage or processing.

Authentication Integrity

Authentication involves both:

  • A public identifier (e.g., NetID)
  • A private credential (password, PIN, passkey, or digital certificate)

Users must:

  • Keep credentials confidential
  • Avoid sharing credentials with unauthorized persons
  • Never impersonate another user or entity
  • Understand that using University authentication services constitutes an official identification
  • Accept responsibility for all actions taken under an authenticated session

Shared or Service Accounts

Shared/service accounts may be approved only when justified by a business need.

Each account must have an Account Owner, responsible for:

  • Documenting the purpose of the account
  • Documenting all individuals who have access
  • Maintaining the account securely
  • Storing and sharing credentials safely
  • Updating passwords during staff turnover or when otherwise appropriate

Credential compromise must be reported immediately at https://support.oakland.edu or by calling (248) 370-4357.

Authorization

Authorization determines what resources a user can access based on their University role.

Requirements:

  • Assign only the minimal privileges necessary
  • Avoid granting privileged access to personal accounts when possible
  • Review access annually or upon job status change
  • Modify or revoke access when affiliation ends
  • Production data modifications must occur only through controlled processes
  • Privileged account information must not be entered into unapproved systems

Eligibility to Authenticate

A user must have an active entry in the central authentication environment.

University ID & Regular Personal NetID

  • Eligibility begins when an individual accepts an offer of employment or student registration
  • Eligibility ends when affiliation ends (termination, withdrawal, graduation without continuation)
  • A grace period may occasionally be applied

Sponsored Accounts

  • Valid for a defined sponsorship period

  • Must be renewed to remain active

  • Disable immediately when sponsorship ends

Service Accounts

Created only for applications or systems requiring automated or elevated functions, such as:

  • System lookups
  • Uptime monitoring
  • Application-specific authentication tasks

Shared NetID Accounts

Permitted only with clear justification.

Documentation must include:

  • Who has access
  • Why it is needed
  • Duration required

Reactivation

Accounts may be reactivated if the individual rejoins the University or obtains a renewed sponsorship.

Suspension

Access may be revoked for:

  • Policy violations
  • Security concerns
  • Administrative actions
  • Misuse of privileges
  •  

Client Digital Certificates

OU supports the use of University-issued digital certificates for stronger authentication on certain services (e.g., Grizznet-Secure).

Requirements:

  • Certificates identify both the device and the user
  • Private keys must not be shared
  • Keys may not be copied to unauthorized devices

Two-Step Verification (Two-Factor / Multi-Factor Authentication)

Multi-Factor authentication (MFA) provides enhanced security and is required for most IT Resources.

Requirements:

  • Users must configure at least one backup MFA method
    (through https://oakland.edu/uts/services/securityinfo/)

  • MFA mechanisms must never be shared with others

  • Sharing an MFA method is equivalent to sharing a password and is prohibited

Roles and Responsibilities

Chief Information Security Officer (CISO)

  • Administers and enforces this standard

  • Provides interpretation and oversight

Users

  • Individuals who use Information Resources must comply with authentication and access requirements

Definitions

Capitalized terms used within this article are defined in UTS Standard: IT Terminology.

Appendix A — Account Types and Access Levels

Account Type

Primary Users

Typical Access Level

Description

MFA Required (DUO)

Faculty

Professors, instructors

Moderate–High

Used for teaching, research, email, grading, and academic systems. May have elevated departmental access.

YES

Staff

HR, IT, Finance, Support Staff

Standard–High

Used for administrative tasks, internal systems, email, and job-specific tools.

YES

Students

Enrolled students

Standard/Limited

Access to email, Moodle, library systems, registration, software, and academic tools.

NO

Guest

Visitors, conference attendees

Minimal/Temporary

Limited access, usually internet only. Accounts deleted after 1 year.

YES

Shared

Departments, labs, project teams

Varies

Used for departmental functions or shared resources (e.g., a lab login or shared mailbox).

YES

Vendor

Contractors, service providers

Limited/Sponsored

Temporary access to systems required for contracted work. Requires University sponsor.

YES

 

Additional Support

  • OU Technology Center
  • 44 Oakland Center
  • Rochester, MI 48309-4479
  • Phone: (248) 370-4357
  • Email: support@oakland.edu
  • Office Hours: M-F 8:00am - 5:00pm

Last Modified: 2/6/2026
Authority: Approved by University Technology Services (UTS) Chief Information Officer
Category: Security Standards
Status: Approved

 

Details

Details

Article ID: 896
Created
Thu 12/11/25 8:33 AM
Modified
Thu 8/27/26 3:30 PM