Skip to main content

Identity Federation Modernization Roadmap

The identity federation modernization roadmap provides transparency regarding the ongoing initiatives affecting our system identity federation.

Program Objectives

The Identity Federation Modernization Strategy is a coordinated enterprise initiative designed to strengthen assurance, reduce systemic risk, and modernize authentication across the Texas A&M University System.

The program advances three core objectives.

🏛 Decentralize ICAM to Members and Trusted Providers

Identity, Credential, and Access Management (ICAM) responsibilities are best executed closest to the source of truth.

System members are optimally positioned to validate and manage the identities of:

  • Students
  • Faculty
  • Staff
  • Contractors
  • Affiliates

Where appropriate, trusted third-party providers (e.g., ID.me) may support assurance workflows.

Decentralizing ICAM:

  • Improves identity accuracy and accountability
  • Aligns authentication with local business processes
  • Reduces dependency on system-level credential management
  • Strengthens overall identity assurance posture

🗂 Retire Legacy Centralized Authentication Stores

Modern federation reduces the need for system-level centralized identity stores used solely for authentication purposes (e.g., TAMUS UIN-based username/password systems).

Transitioning ICAM responsibilities to members and trusted providers enables the system to:

  • Deprecate legacy authentication platforms
  • Reduce enterprise attack surface
  • Eliminate large-scale credential repositories
  • Lower MFA administration overhead
  • Decrease long-term operational cost

This objective reflects a deliberate shift away from broad centralized credential aggregation toward distributed, standards-based identity trust.

🌐 Leverage InCommon for Multi-Lateral Federation

The strategy leverages the InCommon Federation as the authoritative trust framework supporting multi-lateral identity transactions.

InCommon provides:

  • Purpose-built federation infrastructure for higher education
  • Standardized metadata and trust frameworks
  • Self-service provisioning and lifecycle management
  • Dedicated operational and security support from Internet2
  • Long-term sustainability aligned to the research and education (R&E) community

Adopting InCommon as the primary federation backbone ensures:

  • Interoperability with national academic partners
  • Secure cross-institutional collaboration
  • Reduced need for bilateral authentication agreements
  • A resilient federation model designed for long-term viability

Strategic Outcome

Collectively, these objectives transition the Texas A&M University System from legacy centralized authentication models to a modern, federated, standards-driven identity ecosystem — preserving member autonomy while strengthening enterprise-wide security.

Roadmap

TAMUS SSO Institution Login

Enable system members to use institutional SSO when accessing the TAMUS shared services portal (TAMUS SSO).

Plan
Pilot
Operate
Scale
Deprecate
FY24
Operate
Add member IdP metadata to TAMUFederation
Done
FY25
Scale
Transition active faculty and staff from UIN to institution login
Done
FY27
Deprecate
Current
Deprecate UIN login for all users
Planned

TAMUS SSO adoption of ID.me

Adopt ID.me for member affiliates--pre-hires, retirees and beneficiaries.

Plan
Pilot
Operate
Scale
Deprecate
FY25
Plan
Integrate ID.me as an authentication source for TAMUS SSO
Done
FY26 Q1
Pilot
Select members to pilot use of ID.me for pre-hires and retirees
Done
FY26 Q3-Q4
Scale
Current
Rollout ID.me availability to remaining system members
In progress
FY27 Q2
Deprecate
Deprecate UIN login for affiliates
Planned

Transition TAMUFederation to InCommon Federation

Replace TAMUFederation metadata aggregate as system's identity federation with InCommon Federation.

Plan
Pilot
Operate
Scale
Deprecate
FY26 Q1
Plan
Current
Enroll system member IdPs in InCommon Federation
Slipped
FY26 Q1
Pilot
Pilot member InCommon authentication with Cyber applications
Done
FY26 Q2
Pilot
Current
Test InCommon Federation metadata with TAMUS SSO Dev/Test
In progress
FY26 Q3
Operate
Transition member SSO buttons to InCommon Federation IdPs
Planned
FY26 Q4
Deprecate
Deprecate TAMUFederation for TAMUS SSO
Planned

Adopt InCommon Baseline Expectations

Evolve members' identity assurance posture to InCommon Baseline Expectations standards.

Plan
Pilot
Operate
Scale
Deprecate
FY27
Operate
Raise member awareness to adopt InCommon Baseline Expectations
Planned

Member InCommon Transition Status

 
Member
Status
East Texas A&M University Logo
East Texas A&M University
Not Started; Live on TAMUFed
Prairie View A&M University Logo
Prairie View A&M University
Not Started; Live on TAMUFed
Tarleton State University Logo
Tarleton State University
Live on InCommon
Texas A&M AgriLife Logo
Texas A&M AgriLife
Live on InCommon
Texas A&M Engineering Extension Service Logo
Texas A&M Engineering Extension Service
Live on InCommon
Texas A&M Forest Service Logo
Texas A&M Forest Service
In Progress; Live on TAMUFed
Texas A&M International University Logo
Texas A&M International University
Not Started; Live on TAMUFed
Texas A&M Transportation Institute Logo
Texas A&M Transportation Institute
Live on InCommon
Texas A&M University Logo
Texas A&M University
In Progress; Live on TAMUFed
Texas A&M University - Central Texas Logo
Texas A&M University - Central Texas
Not Started; Live on TAMUFed
Texas A&M University - Corpus Christi Logo
Texas A&M University - Corpus Christi
Live on InCommon
Texas A&M University - Kingsville Logo
Texas A&M University - Kingsville
Not Started; Live on TAMUFed
Texas A&M University - San Antonio Logo
Texas A&M University - San Antonio
Live on InCommon
Texas A&M University - Texarkana Logo
Texas A&M University - Texarkana
Not Started; Live on TAMUFed
Texas A&M University - Victoria Logo
Texas A&M University - Victoria
Not Started; Live on TAMUFed
Texas A&M University System Offices Logo
Texas A&M University System Offices
Live on InCommon
Texas Division of Emergency Management Logo
Texas Division of Emergency Management
Not Started; Live on TAMUFed
West Texas A&M University Logo
West Texas A&M University
Live on InCommon