The Identity & Access Management service provides reliable and cost-effective authentication services for access to business information through the use of WashU Connect (a.k.a. WashU Key). WashU Connect establishes a common ID and password that is used by students, faculty, staff, alumni and guests to access university information systems. It is a central system for users of Washington University resources.

The Identity & Access Management service uses systems that provide authentication, single sign-on, applies policies based on source system rules, integration services, data services, and limited access control. WashU Connect is a central system for users of Washington University resources.

Requirements & Considerations

Customer must exist in a System of Record (HR, SIS, ARCH, Connect Guests) before a WashU Key can be created.

Features & Options

  • Administrative credential management
  • API security solution design
  • Authentication support
  • Common username and password when accessing most university systems
  • Directory Synchronization
  • Duo integration
  • Group creation and management of automated groups
  • LDAP integration
  • Multi-factor Authentication
  • OAuth/OIDC
  • Privileged Access Management
  • RFP review
  • SAML (Shibboleth) integration
  • Self-service credential management
  • Solution design

Service Level Expectations (SLE)

Service RequestFulfillment Target
Identity & Access Management – OIDC/OAUTH2, SAML2, 2FA5 business days from request receipt for basic integration

Access Services After Leaving WashU

WashU Medical School Campus
Default image

Active Directory Groups

  • Active Directory groups are widely used to grant access to file shares and applications.
  • The Identity and Access Management system will automatically remove the WashU Key account from all active directory group memberships that are automatically provisioned based on data from the Workday employee record or that are manually provisioned.

Default image

Box

  • Access to Box for terminated faculty and staff is automatically removed based on the date of termination in Workday.
  • Departments may request the Box contents for former employees be transferred to their former manager for disposition.
  • If the former faculty or staff member is also a student Box access is retained.

    • Upon graduation students have 91 days to transfer their Box account and contents to a personal Box account.
    • If you were a student worker at any time, you will lose access to Box when you leave the institution. The 91 day rule no longer applies.

  • Retired Faculty who have received an approved Academic Services Access role get to keep their Box account with a 1 terabyte storage limit applied. Access is subject to being removed if not actively in use.
  • People with an Emeritus role in Workday retain their Box access indefinitely.

Default image

University Email – (user@wustl.edu)

The following notes do not include anything related to mailbox access or licensing. They refer to email address only:

  • WashU IT will automatically disable WashU email access for all departing Washington University Medical School School Campus faculty and staff on their final day of employment or if they are also alumni or students. Email sent to the disabled account will continue to be delivered for 90 days after separation.
  • The expiration date is set automatically, and no department intervention is required.
  • If the former faculty or staff member is also a student or alumni the wustl.edu email address is retained and supported by their current role.

    • The wustl.edu email address may be retained upon request of the departing department. This process requires the department to coordinate with the WashU IT Service Desk as well as the impacted individual as they will receive a new email address, WashU Key, and Office 365 mailbox.

  • Retired faculty who have received an approved Academic Services Access role keep their University Email.
  • People with an Emeritus role in Workday retain their wustl.edu address indefinitely.

Default image

WashU Key

WashU IT will automatically disable WashU Key accounts for some former Washington University Medical Campus faculty and staff who have been separated from the University for 2-years or more. If a former faculty or staff member is also an alumni or student, their WashU Key account will remain enabled.

WashU Danforth Campus and CFU Affiliates
Default image

Active Directory Groups

  • Active Directory groups are widely used to grant access to things like file shares and applications.
  • The Identity and Access Management system will automatically remove the WashU Key account from all active directory group memberships that are automatically provisioned based on data from the Workday employee record or manually provisioned.

Default image

Box

  • Access to Box for terminated faculty and staff is automatically removed based on the date of termination in Workday.
  • Departments may request the Box contents for former employees be transferred to their former manager for disposition.
  • If the former faculty or staff member is also a student Box access is retained

    • Upon graduation students have 91 days to transfer their Box account and contents to a personal Box account.
    • If you were a student worker at any time, you will lose access to Box when you leave the institution. The 91 day rule no longer applies.

  • People with an Emeritus role in Workday retain their Box access indefinitely
  • Retired Faculty who have received an approved Academic Services Access role get to keep their Box account with a 1 terabyte storage limit applied. Access is subject to being removed if not actively in use.

Default image

Microsoft 365 (M365)

  • Access to the M365 mailbox is not automatically removed for terminated faculty and staff.
  • Licenses applied that provide access to services such as Teams and OneDrive are automatically removed upon termination.
  • Email Distribution Group membership is not automatically removed for terminated faculty and staff.
  • Departments may contact the WashU IT Service Desk to request that M365 mailbox access and Distribution Group membership be removed.
  • People with an Emeritus role in Workday retain their M365 mailbox and access indefinitely.

Default image

University Email (user@wustl.edu)

University Email – (user@wustl.edu)

The following notes do not include anything related to mailbox access or licensing. They refer to email address only:

  • The wustl.edu email address will be set to expire 91 days from the date of termination in Workday.
  • The expiration date is set automatically, and no department intervention is required.
  • If the former faculty or staff member is also a student or alumni, the wustl.edu email address is retained and supported by their current role.
    • The wustl.edu email address may be retained upon request of the departing department. This process requires the department to coordinate with the WashU IT Service Desk and the impacted individual, as they will receive a new email address, WUSTL Key, and Office 365 mailbox.
  • People with an Emeritus role in Workday retain their wustl.edu address indefinitely.
  • Departments may request an extension of the wustl.edu email address expiration for a period not to exceed one year. Departments must request additional extensions to support business operations.

Default image

WashU Key

The WashU Key will remain active indefinitely and in many cases departments must identify application or system access that needs to be removed upon an employee termination or transfer event.

    • The WashU IT Service Desk can disable the WashU Key upon request of the department.
        • If the former faculty or staff member is also a student or alumni the WashU Key may be disabled for a short and defined period of time to allow for the department to coordinate removal of application and system access.

Training and How-To

WashU Connect How To – Find helpful guides and frequently asked questions to resolve common WashU Key issues.

Navigate the paths offered for WUSTLKey integration. Visit WashU Key Integration Portal.