Project Portfolio
Active Projects
The project list contains the current work in progress. For more information about the projects, contact the project manager.
Onyen Deprovisioning in midPoint
- SPONSOR(S): Dennis Schmidt, Ethan Kromhout
- DEPT OR DIVISION: ITS Information Security and Identity Management
- TECHNICAL LEAD: Celeste Copeland
- STATUS: Behind Schedule
The ITS Identity Management team receives frequent requests from groups around campus for centralized and automated provisioning and deprovisioning of user accounts. We currently use a home-grown utility known as IMPROV for this purpose, but it only provisions Onyens and Guest IDs, not other forms of accounts. IMPROV also does not do deprovisioning, so the team uses perl scripts for this purpose.
This project will implement midPoint, an open source identity management and identity governance solution, as our deprovisioning engine. This project is necessary for follow-on projects such as deprovisioning Zoom and other applications, which are waiting for this work to be completed.
Remedy Decommissioning
- EXECUTIVE SPONSOR(S): Mike Barker
- SPONSOR(S): Kate Hash, John Mack
- DEPT OR DIVISION: ITS Customer Experience and Engagement
- TECHNICAL LEAD: David Smith
- STATUS: In Progress
The Remedy application infrastructure has been running on unsupported versions of BMC Remedy AR Server, Oracle DB, Java, and Linux OS, which is a risk for ITS while also consuming team resources to maintain. The purpose of this project is to transition all remaining Remedy applications to other supported ServiceNow applications or application platforms. This project needs to be completed by mid-October at the latest to prevent renewal of the Unix Support contract for another year.
Enterprise Firewall Migration
- SPONSOR(S): Mike Barker
- DEPT OR DIVISION: ITS Information Security and Identity Management
- TECHNICAL LEAD: Larry Fritsche
- STATUS: In Progress (on schedule for June 2022 closure)
This project will migrate approximately 250 unprotected VLANs (“virtual local area networks”) to campus enterprise firewalls. Migrating these VLANs will prevent attacks and also limit the scope of attacks across the University. Onboarding the rest of campus will significantly expand the range and depth of the University’s defenses. It will also give ITS unprecedented awareness of which mission-critical systems we need to protect.
New NIH Requirements for Identity Assurance
- EXECUTIVE SPONSOR(S): Mike Barker
- DEPT OR DIVISION: ITS Information Security
- CHANGE MANAGER: Rebecca Jones
- STATUS: ON TRACK
The National Institutes of Health (NIH) is requiring stronger proof that a person logging into their system is who they say they are. Starting in September 2021 multifactor authentication will be required when logging in to their system, and by December 2022, appropriate levels of identity assurance will also be required.
The National Institute of Health (NIH) is increasing security for their systems. The University met the first of their requirements last September, when the NIH began requiring multi-factor authentication for those logging in to their systems. For the next phase, the NIH will require identity assurance, which means stronger proof that a person is who they say they are.
The NIH uses the criteria defined in the REFEDS Assurance Framework to define levels of assurance. REFEDS, which stands for “Research and Education FEDerations,” is an organization that represents the requirements of research and education related to access and identity management.
REFEDS defines four levels of identity proofing assurance: low, medium, high, and “enterprise equivalency.” Each level answers the question, “How well does your identity proofing process let you be sure that the person is actually who they claim to be?”
Project Phases
- September 2021: Multifactor Authentication
- June 30, 2022: Local Enterprise Equivalency
- December 31, 2022: Low, Medium, High Level of Assurance
Identity Assurance Key Points
Visit the New NIH – Identity Requirements for Identity Assurance website to learn more about phase requirements, next steps and links to resources.
NIH: New Requirements for logins – September 2021
Project Website for New NIH Requirements for Identity Assurance
Completed Projects
Carolina Talent Performance Appraisals
Phase I of Carolina Talent Performance was implemented last year, but the performance appraisals were still being done on paper forms. For the 2021-2022 performance period we are implementing online performance … Continued
Decommission ADFS Infrastructure for M365 Authentication
When UNC migrated to Microsoft 365, we implemented an on-premises infrastructure called “Active Directory Federation Services” (ADFS) to support authentication into Microsoft 365. ADFS addressed security concerns around syncing passwords … Continued
Background Check Phase Two
Phase one of the Background Check project went live in May 2021, but a second phase is needed. Phase two has multiple parts. First, our contract with CastleBranch, the existing … Continued
Operational Excellence Student Registration Changes
This project supported a new registration process for undergraduate students designed by the Operational Excellence Registration Changes committee. The changes provided more equitable and consistent processes for assigning registration appointments. … Continued
Upgrade and Transition of Software Distribution
The PHP platform that the Software Distribution service operated on was no longer supported by the vendor, so this project upgraded the platform. The project also transitioned support of the … Continued