-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathtalks.html
More file actions
143 lines (125 loc) · 11.1 KB
/
Copy pathtalks.html
File metadata and controls
143 lines (125 loc) · 11.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
---
layout: default
title: "Talks"
description: "Conference presentations by Kellen Murphy on identity and access management, Grouper, and enterprise IAM."
markdown_url: /talks.md
last_modified_at: 2026-06-02
---
<div class="talks">
<h1 class="mb-3">{{ page.title }}</h1>
<section>
<h2 class="talks-conference"><a href="https://incommon.org/academy/camps-conferences/camp-week" target="_blank">Internet2 Technology Exchange</a></h2>
<div class="talk">
<div class="talk-header">
<span class="talk-title">Shibboleth Reborn: NetBadge Under New Stewardship at the University of Virginia</span>
<span class="talk-meta"><span class="talk-upcoming">Accepted</span> · TechEx 2026</span>
</div>
<p class="talk-abstract">
When the University of Virginia's Identity Services team assumed operational responsibility for UVA's long-running Shibboleth deployment in 2025, it inherited a stable but stationary service: SAML integrations were well tracked, reliably delivered, and semi-automated, but the service was also ripe for modernization. This session chronicles the first year of that transition: what we found, what we changed, and where we're headed.
</p>
<p class="talk-abstract">
We'll share practical lessons from efforts to tighten SAML attribute hygiene, reduce reliance on email-based identifiers for our Health System, and our custom tooling that makes SAML integrations easier than ever. We'll look ahead at how containerized deployment via Docker Swarm and the InCommon Trusted Access Platform container images will reshape our release pipeline. And lastly, we'll discuss how we're aiming to improve customer service by simplifying bulk integrations for technically adept users via Keycloak proxying.
</p>
<p class="talk-abstract">
Finally, we'll share how we're beginning to face the question every multitenant institution dreads: how do you converge Shibboleth and Microsoft Entra ID into a unified SSO experience when half of your users are in one (Academic) tenant and the other half are in a separate (Health System) tenant?
</p>
</div>
<div class="talk">
<div class="talk-header">
<span class="talk-title">Grouper Attestation in Action: UVA's Transition from MyGroups to Grouper</span>
<span class="talk-meta">TechEx 2025 · December 10, 2025</span>
</div>
<p class="talk-copresenters">With <strong>Shira Acosta</strong> — University of Virginia</p>
<p class="talk-abstract">
In Fall 2024, the University of Virginia transitioned from its custom group management solution, MyGroups, to Grouper. All existing MyGroups groups were migrated without modification, despite lacking compliance with new governance policies enabled by Grouper. Consequently, these legacy groups require thorough evaluation regarding their purpose, membership, and necessity. This talk explores how UVA is utilizing Grouper's Attestation functionality to systematically address these legacy groups, implement deprovisioning where needed, and ensure compliance with new group policies introduced with Grouper.
</p>
<a href="/assets/talks/techex25-grouper-attestation.pdf" class="talk-slides-link" target="_blank">Slides (PDF)</a>
</div>
<div class="talk">
<div class="talk-header">
<span class="talk-title">Grouper Chronicles: Success with ABAC and Legacy Challenges</span>
<span class="talk-meta">TechEx 2024 · December 11, 2024</span>
</div>
<p class="talk-copresenters">With <strong>Bruce Timberlake</strong>, <strong>Gail Lift</strong>, and <strong>Liam Hoekenga</strong> — University of Michigan</p>
<p class="talk-abstract">
The University of Michigan and the University of Virginia share experiences with Grouper and its evolving capabilities. At Michigan, the team implemented Grouper's new Attribute-Based Access Control (ABAC) features in April 2024, enabling efficient management of access control groups that were previously unsustainable. At Virginia, the second year of transitioning from a legacy group management system to Grouper brought both challenges and practical lessons. Together: a comprehensive overview of Grouper ABAC adoption, when reference groups are the right call versus when ABAC is the better fit, and the realities of retiring legacy systems.
</p>
<a href="/assets/talks/techex24-grouper-chronicles.pdf" class="talk-slides-link" target="_blank">Slides (PDF)</a>
</div>
<div class="talk">
<div class="talk-header">
<span class="talk-title">IAM Archaeology</span>
<span class="talk-meta">TechEx 2023 · September 19, 2023</span>
</div>
<p class="talk-copresenters">With <strong>Chris Bongaarts</strong> — University of Minnesota</p>
<p class="talk-abstract">
Valuable insights on retiring legacy systems, drawn from the experiences of the University of Minnesota and the University of Virginia. UMN's latest attempt to retire a 31-year-old identity system alongside UVA's journey replacing a home-built group management solution with Grouper — practical knowledge on retiring old systems and facilitating future retirements from both organizational and technical perspectives.
</p>
<a href="/assets/talks/techex23-iam-archaeology.pdf" class="talk-slides-link" target="_blank">Slides (PDF)</a>
</div>
</section>
<section>
<h2 class="talks-conference"><a href="https://incommon.org/academy/camps-conferences/basecamp" target="_blank">Internet2 BaseCamp</a></h2>
<div class="talk">
<div class="talk-header">
<span class="talk-title">XBAC: An Overview of Access Control</span>
<span class="talk-meta">BaseCamp 2026 · June 2, 2026</span>
</div>
<p class="talk-abstract">
A practical walk through the modern access control landscape. From RBAC and ABAC to newer policy and relationship-driven approaches, this session will unpack how they can fit together instead of competing. Come see how access control within the larger higher-ed IAM context can integrate governance, grouping, and federated authentication into a model that's both flexible and defensible.
</p>
<a href="/assets/talks/basecamp26-xbac.pdf" class="talk-slides-link" target="_blank">Slides (PDF)</a>
</div>
<div class="talk">
<div class="talk-header">
<span class="talk-title">Core Concepts of Access & Grouping</span>
<span class="talk-meta">BaseCamp 2025 · June 5, 2025</span>
</div>
<p class="talk-abstract">
An overview of access and grouping — learn about why grouping is critical for IAM and how access decisions are made. Plus see real-world examples of how institutions use groups and roles to improve security and efficiency. We'll also introduce the concepts of role-based access control (RBAC), attribute-based access control (ABAC), and group-based access management.
</p>
<a href="/assets/talks/basecamp25-access-and-grouping.pdf" class="talk-slides-link" target="_blank">Slides (PDF)</a>
</div>
<div class="talk">
<div class="talk-header">
<span class="talk-title">Data in Practice: Understanding the Role of Data in IAM</span>
<span class="talk-meta">BaseCamp 2025 · June 5, 2025</span>
</div>
<p class="talk-copresenters">With <strong>Chris Bongaarts</strong> — University of Minnesota</p>
<p class="talk-abstract">
IAM data — where does it come from, how is it used, and who is responsible for maintaining its accuracy? This session introduces the critical role of data in IAM, from sourcing identity information to managing entitlements and audit logs. Attendees will learn how IAM systems rely on campus data practices, why data consistency is key to access control, and what happens when bad data flows through IAM systems. Whether you're managing identity sources, troubleshooting inconsistencies, or improving data quality, this session provides the foundational knowledge you need.
</p>
<a href="/assets/talks/basecamp25-iam-data.pdf" class="talk-slides-link" target="_blank">Slides (PDF)</a>
</div>
</section>
<section>
<h2 class="talks-conference"><a href="https://incommon.org/academy/iam-webinars" target="_blank">Internet2 IAMOnline</a></h2>
<div class="talk">
<div class="talk-header">
<span class="talk-title">Community As a Verb: Mapping the Paths from Concepts to Collaboration</span>
<span class="talk-meta">IAMOnline 2026 · May 20, 2026</span>
</div>
<p class="talk-copresenters">With <strong>Claire Chance</strong> — Colorado State University; <strong>Clay Cooper</strong> — Rochester Institute of Technology; and <strong>Grady Bailey</strong> — Internet2</p>
<p class="talk-abstract">
Much like digital identity isn't merely a collection of attributes, the InCommon Community isn't just a collection of people. Threads of connection and collaboration are constantly being woven into a living, breathing, problem-solving tapestry. A conversation with community leaders about their lived experiences, unique perspectives, and the fabric of the InCommon Community — getting started, navigating common challenges, and how to leverage the power of community to accomplish major feats in research and higher education.
</p>
<a href="https://www.youtube.com/watch?v=NxG5asPD9ss" class="talk-slides-link" target="_blank">Recording (YouTube)</a>
</div>
<div class="talk">
<div class="talk-header">
<span class="talk-title">Change Afoot: Navigating the Hybrid IAM Landscape</span>
<span class="talk-meta">IAMOnline 2025 · March 19, 2025</span>
</div>
<p class="talk-copresenters">With <strong>Tommy Doan</strong> — Southern Methodist University</p>
<p class="talk-abstract">
Many institutions operate in a hybrid state, juggling on-premises identity systems with cloud-based IAM solutions. As the shift toward cloud infrastructure and SaaS services accelerates, institutions making these transitions must weigh greater scalability, flexibility, and integration options with challenges like licensing costs, integration complexity with legacy systems, and vendor dependence. With no one-size-fits-all approach, each institution must navigate its own path forward.
</p>
<p class="talk-abstract">
SMU recently transitioned its primary identity provider from on-premises (Shibboleth) to the cloud (Entra ID) while maintaining a hybrid environment — offering insights into their motivations, lessons learned, and strategies for process, stakeholder communication, and user education. UVA will discuss its approach to fully leveraging Entra ID while unifying two separate SSO solutions, sharing key considerations behind their decisions and how they are managing change.
</p>
<a href="/assets/talks/iamonline25-change-afoot.pdf" class="talk-slides-link" target="_blank">Slides (PDF)</a>
·
<a href="https://www.youtube.com/watch?v=hci1SsXqi54" class="talk-slides-link" target="_blank">Recording (YouTube)</a>
</div>
</section>
</div>