
Holistic IAM for Secure Collaboration
Managing identity and access in research and education is complex. InCommon provides tools and services that work together to enable your organization to collaborate securely and seamlessly.
Specialized Tools and Strategic Guidance by and for the Research and Education Community
Identity and Access Management to Enable Privacy, Trust and Security
InCommon Federation
With InCommon Federation, SAML-based single sign-on connects your users to thousands of trusted research and education services. Behind the scenes, vetted metadata builds the trust fabric that makes this possible. It simplifies integrations, reduces risk, and helps you meet evolving compliance requirements like REFEDS MFA and Assurance.
What’s Possible with the Federation:
Reduce friction, improve security for students, faculty, and researchers
Connect to thousands of services with one trusted framework
Easily connect to new partners and services via vetted SAML metadata instead of custom integrations
Stay aligned with evolving compliance needs through federation-supported standards
Who is Eligible?
- All accredited U.S. post-secondary institutions
- Research organizations
- Sponsored partners (organizations invited by participants to provide online resources or research services)
Participation Requirements, Fees, and Policies
- Sign the InCommon Participation Agreement
- Pay a one-time $700 registration fee, plus an annual fee based on Carnegie Classification, FTE, or revenue
- Register one identity provider (IdP) and up to 50 service providers (SPs) as part of the annual fee
- Adhere to InCommon’s Baseline Expectations for mature, secure, and privacy-protecting operations
Getting Started
- Evaluate your existing identity infrastructure and technical capabilities.
- Develop an implementation roadmap with stakeholder requirements.
- Check eligibility, complete the Participation Agreement, and join the Federation
- Set up your IdP (90% of organizations use Shibboleth) and share your metadata.
- Connect with federation resources and service providers.
Related Programs, Resources, and Opportunities
- The InCommon Federation Wiki
- The Research & Scholarship (R&S) Entity Category
- Baseline Expectations for Trust in Federation
- SIRTFI (Security Incident Response Trust Framework for Federated Identity)
- eduGAIN for international research collaboration
- InCommon Catalysts for expert implementation support
Get Started with the Federation
Join the InCommon Federation to give your community reliable, secure access to thousands of research and education services through a trusted framework.
eduroam
Give your students, faculty, and researchers Wi-Fi that travels with them. With eduroam, users log in with their home credentials for instant, secure access at thousands of campuses worldwide. Authentication happens quietly between institutions in the background, so your community can stay connected and focus on research and education.
What’s Possible with eduroam:
Offer secure Wi-Fi access to your community at thousands of sites worldwide
Welcome visitors and scholars without the hassle of setting up guest accounts
Strengthen wireless security with standards-based authentication
Expand your campus reach by joining a global network of institutions
Who is Eligible?
- U.S.-based colleges and universities (multi-campus universities can use group agreements)
- Research labs, libraries, and museums
- K–12 schools (through Support Organization partnerships in select states)
- Companies and organizations (as free hotspot/service providers)
Participation Requirements, Fees, and Policies
- An InCommon or Internet2 membership is NOT required to participate.
- Sign the eduroam Connector Agreement (one-time $700 setup fee, waived if signed without modifications)
- Pay annual fees based on enrollment: $0.10 per student (IPEDS headcount) or per FTE, with a $400 minimum
- Internet2 Higher Education members receive eduroam as a member benefit
- Implement standards-based Wi-Fi using IEEE 802.1X with WPA2/WPA3-Enterprise
- Deploy and maintain a RADIUS authentication infrastructure
Getting Started
- Check eligibility and choose the appropriate agreement type (single campus or multi-campus)
- Sign the agreement via DocuSign
- Register your organization and designate technical and administrative contacts
- Configure RADIUS infrastructure and enable 802.1X authentication
- Test connectivity with the eduroam network
- Broadcast the eduroam SSID across your wireless infrastructure
Related Programs, Resources, and Opportunities
As an eduroam participant, you can also benefit from:
- International eduroam connectivity (available in 100+ countries)
- The eduroam Advisory Committee
- The Support Organization program for K-12, libraries, and museums
- Hotspot/SP-only participation for organizations providing access only
- Integration with the InCommon Federation for enhanced services
Get Started with eduroam
Join the eduroam network and give your community Wi-Fi that works wherever learning and research take them, from your campus to thousands of sites worldwide.
Certificate Service
Protect your services with certificates built for research and education. The InCommon Certificate Service offers an unlimited-use model with simple deployment and lifecycle management, so you can secure servers, apps, and APIs at scale. Reduce manual effort, standardize practices, and keep your campus compliant and trusted.
What’s Possible with Certificates:
Issue and renew certificates quickly with campus-wide coverage
Standardize certificate management to lower risk and outages
Support modern security practices for servers, apps, and integrations
Simplify compliance reporting with consistent processes and records
Who Is Eligible?
- U.S.-based higher education institutions (qualified for .edu domains)
- Not-for-profit regional research and education networks (with primary U.S. offices)
- Certain non-profit research organizations
- InCommon membership required to access the Certificate Service
Participation Requirements, Fees, and Policies
-
Sign both the InCommon Participation Agreement and the Certificate Service Subscriber Addendum
-
Commit to an initial three-year subscription with annual billing
-
Pay annual fees based on Carnegie Classification (ranging from $550–$11,000)
-
Regional networks pay a flat $2,000
-
Internet2 members receive a 25% discount
-
-
Designate Registration Authority Officers (RAOs) and follow CP/CPS policies
-
Use certificates only for organizational purposes (no reselling)
Getting Started
- Sign agreements via DocuSign (Participation Agreement + Certificate Service Addendum)
- Register your InCommon Executive and up to three RAOs
- Access the Certificate Manager interface to configure domains and workflows
- Appoint Department RAOs for distributed administration (if needed)
- Request, install, and test certificates through the Certificate Manager, API, or ACME automation
Related Programs, Resources, and Opportunities
- Single sign-on with MFA for Certificate Manager access via InCommon Federation
- ACME automation for large-scale certificate deployment
- Support for Extended Validation (EV) and code-signing certificates
- Community learning through the cert-users email list and regular webinars
- Sectigo technical support services for advanced troubleshooting
- InCommon Academy training courses on certificate management and automation
- Expert consulting from InCommon Catalysts for planning and deployment
Get Started with Certificates
Secure servers, apps, and APIs at scale with an unlimited certificate model that simplifies management and lowers risk.
InCommon Trusted Access Platform (TAP)
Managing identity and access across campus doesn’t have to be complicated. The Trusted Access Platform delivers community-built IAM software in easy-to-deploy containers, giving you single sign-on, group management, and identity lifecycle tools that streamline identity and access management. Backed by shared standards and vetted metadata, the TAP helps institutions simplify integrations, strengthen security, and meet compliance with confidence.
What’s Possible with the TAP:
Speed up IAM deployments with containerized software and community-tested patterns
Manage identities, groups, and roles from a single source of truth across your systems
Automate account provisioning and de-provisioning to reduce manual workload and errors
Adapt quickly to new requirements with flexible, open-source tools built by and for the research and education community
Who is Eligible?
The Trusted Access Platform is available to all research and education institutions. The software is free to use under an open source license, provided as-is, without warranty or support, and for non-commercial purposes only.
Participation Requirements, Fees, and Policies
- There are no fees for the software itself.
- Follow the Apache 2.0 open-source license
- Comply with non-commercial use restrictions
- Integrate TAP components with existing identity management systems
Getting Started
- Use IAM Sketch to visualize your IAM architecture
- Review the TAP software to see which components (Shibboleth, Grouper, COmanage, midPoint) fit your IAM needs
- Download the open source software from the TAP Library
- Use component-specific implementation guides for configuration
- Explore training programs, including InCommon Academy workshops, for hands-on learning
Related Programs, Resources, and Opportunities
- Visualize your IAM framework with IAM Sketch, a tool that puts each main component in the context of IAM architecture
- InCommon Academy training courses for each TAP component
- Component-specific working groups (midPoint, COmanage, Grouper)
- InCommon Catalysts for expert consulting and implementation guidance
- The Accelerators Program (formerly known as Collaboration Success Program) for structured implementation support
Get Started with the TAP
Modernize your identity and access foundation with tools and patterns for the research and education community.
InCommon Catalysts
Get expert help from partners who know InCommon’s services inside and out. Catalysts assist with planning, implementation, and operations for Federation, eduroam, Certificates, and the Trusted Access Platform. Accelerate projects, avoid common pitfalls, and build lasting capabilities on your team.
What’s Possible with Catalysts:
Plan and deploy faster with experienced implementation partners
Tailor Federation, eduroam, and TAP to your campus needs
Improve reliability with reference architectures and best practices
Upskill your staff through guided knowledge transfer
Who is Eligible?
Organizations that are current InCommon participants or eligible to join InCommon can utilize Catalyst services. This includes accredited U.S. post-secondary institutions, research organizations, and their sponsored partners.
Participation Requirements, Fees, and Policies
-
InCommon membership required (current or prospective participants)
-
No additional fees for Catalyst consultation services
-
Subject to InCommon policies and participation agreements
-
Catalyst availability may vary based on demand and expertise areas
Getting Started
- Contact InCommon to request Catalyst assistance
- Describe your project and technical requirements
- Get matched with an appropriate Catalyst based on expertise
- Schedule consultation to discuss implementation approach
- Receive ongoing support throughout your project timeline
Related Programs, Resources, and Opportunities
- InCommon Academy for training and workshops to build internal expertise
- TAP (Trusted Access Platform) for open source software and implementation guides
- InCommon Federation for core identity federation services
- Community forums and working groups for peer collaboration
Get Started with Catalysts
Connect with a vetted partner to launch or mature your IAM services with confidence.
InCommon Academy
Build skills that make IAM work at your organization. The InCommon Academy provides training and learning pathways for identity practitioners, IT administrators, and organizational leaders, with offerings that map to implementing Federation, managing eduroam, deploying the Trusted Access Platform, and supporting IAM strategy. Learn from community experts, explore real-world use cases, and apply proven approaches that strengthen your organization’s IAM capabilities.
What’s Possible with the Academy:
Strengthen IAM skills through guided training, real-world examples, and practical implementation strategies
Train your team with expert-led courses on Shibboleth, Grouper, COmanage, and midPoint
Accelerate IAM progress with community-vetted approaches and cohort-based programs like Accelerators
Stay current with IAM trends and solutions through IAM Online webinars
Connect with peers through webinars, conferences, and meet-ups to exchange ideas and strategies
Who is Eligible?
- IAM implementers, identity practitioners, and information security professionals
- System administrators supporting access and infrastructure
- IT leaders and technology decision-makers
- Staff and cross-functional teams from research and education institutions—at any experience level
Enrollment Details and Access
- Registration is required for each course, event, or program offering.
- Fees vary by offering; discounts may be available through InCommon or Internet2 memberships and bundled programs.
- Course access includes learning materials, participation in live sessions via Zoom, and recordings (when applicable).
- Many offerings include extras such as live office hours, peer collaboration through Slack channels, and digital badges to recognize course completion.
Getting Started
- Browse available trainings, events, and programs
- Register for offerings that match your goals or role
- Receive a welcome email with access to our learning platform (where offered)
- Access virtual machine environment (where applicable) for hands-on experience
- Engage with instructors, peers, and content through office hours, Slack channels, and guided discussions
Related Programs, Resources, and Opportunities
- IAM Workshops, BaseCAMP, and CAMP Week for foundational and advanced topics in identity and access management
- Software Training on Trusted Access Platform components—Shibboleth, Grouper, COmanage, and midPoint
- Accelerator Programs (formerly Collaboration Success Program) for guided implementation support and cohort-based collaboration
- Thread Meet-Ups, Roundtables, and Bonfires for informal, community-led peer exchange
- Peer networks and community channels to connect with fellow learners, Academy alumni, and IAM practitioners
- IAM Online Webinars for continued learning and insights into emerging trends and community practices
Questions about Academy Offerings?
Our team is here to provide guidance and help you navigate your options. Reach out to us directly!
Community Leadership
Our community-driven leadership structure is built for the community, by the community. It brings together diverse perspectives from IAM professionals across institutions to drive innovation, establish best practices, and solve tomorrow’s identity challenges. By participating in leadership opportunities, you’ll help ensure that InCommon services evolve to meet the unique needs of research and education communities while building valuable professional connections.
How You’ll Make an Impact:
Influence the strategic direction of InCommon services and initiatives
Connect with peers tackling similar IAM challenges across institutions
Develop professional skills while contributing to community-driven solutions
Drive innovation that addresses the unique needs of research and education
Who Can Contribute?
- IAM professionals from InCommon member institutions
- Technical architects, security specialists, and implementation experts
- International participants from global research and education organizations
- Professionals with diverse experience levels and perspectives
Participation Requirements, Fees, and Policies
- No additional fees beyond InCommon membership
- Time commitment varies from minimal email participation to leading working groups
- Most committee meetings are one hour, held bi-weekly
- New terms typically begin in January with nominations opening in the fall
Getting Started
- Review available committees and working groups to find your area of interest
- Contact the Community Liaison for questions about specific opportunities
- Browse meeting minutes to understand current initiatives and discussions
Related Programs, Resources, and Opportunities
- Technical Advisory Committee (TAC)
- Working groups focused on specific IAM challenges
- Committee charters and bylaws
- Leadership training and professional development
Start Contributing
No matter where you are in your IAM journey, your unique expertise can significantly contribute to our community. From joining email discussions to chairing committees, flexible participation options make it easy to get involved and make a meaningful impact.