Login, Roles, Rights
= Identity and Access Management (IAM)
Identity and Access Management (IAM) is the process of bringing together personal data from different systems into a single identity. If, for example, a person's name changes, only the source HR system needs to be changed. This is then automatically synchronised with the IAM so that the target systems receive the most up-to-date information.
The university expects several benefits from the IAM, such as increased data security, improved data quality and constant up-to-dateness. In addition, other IT systems can be more easily integrated into the administrative and academic network, which results in an easier management of people and permissions.
User Account
In order to access the data services of the University of Bamberg, the IT-Service creates a user account in the user database with a user name (BA number) and personal password. With the help of the user name and the password, the user logs onto the data services and proves his identity.
The administration of the user accounts of university members is automated from the time they join the organisation until they leave (= user lifecycle).
[I’d like to know more! - Continue reading ... in German]
Data Services
On the basis of the access rights stored with the data services (email, data storage, etc.), the system grants or denies access to persons who are logged in and identified with their user account (BA number).
[I’d like to know more! - Continue reading ... in German]
Institutional Identification Code
For task-related data services, access rights are assigned by the institutions that own the data services. Data services are named using defined institute abbreviations (e.g. the email account sekretariat.its@uni-bamberg.de). Although the institute abbreviations, which are assigned according to a defined assignment procedure, were originally introduced only to standardise the naming of data services and to resolve naming conflicts (there are, after all, several secretariats), they also serve to assign the rights of use to the institutes and the responsible persons.
[I’d like to know more! - Continue reading ... in German]
Certificates
The IT-Service issues certificates for encrypting and signing emails and for secure communication with servers (https).
[I’d like to know more! - Continue reading ... in German]
Weblogin
The University of Bamberg often enters into agreements with external or commercial providers to allow members of the University of Bamberg to use their data services.
In the past, access to these external data services was often restricted to the university's data network (to which users can also "dial in" via VPN). Or it was tied to the possession of a University of Bamberg e-mail address through various "licensing mechanisms".
The login to such restricted services can be realised with the help of a weblogin via Shibboleth.
[I’d like to know more! - Continue reading ... in German]