Fortified ID

Universities and higher education

The right access throughout university life

From the first course to the next research project. Fortified ID helps universities simplify identity management, govern access and give students and staff secure self-service.

JML and access managementSelf-service and password resetsSUNET, SWAMID and eduID
Students in a university lecture hall
Fortified ID Control

JML that follows studies, employment and assignments

New semesters, research projects and fixed-term contracts bring significant changes to university identities. Fortified ID Control lets you build Joiner–Mover–Leaver workflows using information from HR, student and directory systems, with integrations adapted to your data sources.

Joiner: create accounts and assign baseline access when a student registers, an employee starts or a visiting researcher receives an assignment. Mover: update groups and access when someone changes department, course or project.

Leaver: remove access when the underlying affiliation ends. A doctoral researcher may be both a student and an employee. Let each active affiliation govern its access so that ending one assignment does not close an account that is still needed.

Identity and access integrations

Access with clear ownership and expiry dates

Learning platforms, research environments and administrative systems need different access rules. Tie permissions to current roles, organizational affiliation and assignments, and grant only the access that is needed.

With Control, requests can go to the right resource owner for approval before a change is implemented. Delegate scoped administration to departments and project leads, set expiry dates for guests and temporary assignments, and follow up on inactive accounts and discrepancies.

Traceable requests, decisions and changes make it easier to understand who has access to what and why.

Self-service and delegated administration

Self-service that eases the start-of-semester workload

Let students and staff initiate account activation, request access or update permitted information through clear, guided workflows. Control Forms brings self-service and delegated administration together behind university sign-in.

For example, a project lead can initiate a visiting researcher’s account with a responsible owner and an expiry date. An employee can request access to a project group, while the resource owner approves and automation implements the change.

Fewer manual requests and shorter waiting times give IT more room for development. Central policies and approvals still apply when users initiate requests themselves.

Keys representing secure password recovery

A forgotten password should not interrupt learning

Fortified ID Password Reset lets students and staff reset their passwords through self-service, even outside service desk hours. Users verify their identity through an approved method before the password is changed in connected directories such as AD or Entra ID.

Use an existing identity provider or an electronic ID according to university requirements. An eduID workflow can be designed through federated sign-in, provided the required assurance level and a secure link to the local account are in place. Recovery needs to work even when users cannot sign in with their usual password.

For people who need assistance, selected staff can receive delegated reset permissions within their area of responsibility. Actions are logged and university password policies apply.

Fortified ID Integrity

Connect your university with SUNET, SWAMID and eduID

SWAMID is the identity federation operated by SUNET for research and higher education. eduID is SUNET’s digital identity service and can be used to sign in to connected services. Together, they provide building blocks for the university’s federated identity environment.

Fortified ID Integrity can serve as an IdP or broker between existing identity providers and SWAMID. We help you design connections for eduID, map identities and attributes, and adapt authentication workflows to service requirements.

A verified identity does not automatically grant access to university resources. Local account linking, current affiliation and access decisions need to work alongside federation assurance requirements and attribute release rules.

University lecture hall

Build on the environment you already have

Start where the need is greatest: password resets before a new semester, automated guest account offboarding or stronger sign-in to federated services. Control, Password Reset and Integrity can be combined step by step to suit your university.

In our university use case, Fortified ID extends an existing ADFS connection to SWAMID with on-premise MFA and self-service activation of the authenticator app. It shows how a university can strengthen sign-in within its existing environment.

Together, we can map your identity sources, roles and workflows and show how JML, self-service and federation can form a connected solution.