Secure an Open Society

Web Accessibility Scanning — Siteimprove

Accessibility

ITS Accessibility launched and rapidly scaled Siteimprove to significantly expand U-M’s capacity to monitor and improve its web presence. The platform provides actionable, unit-level insights that help web teams identify barriers early, prioritize fixes, and manage content at scale. The team also accelerated adoption through targeted training, consultations, and enhanced support services.

  • User Growth: Increased from 355 to 4,234 (~10× growth)
  • Coverage: Sites tracked rose from 1,471 to 3,022
  • Scale: Pages monitored surged from 98,636 to 1,573,339
  • Training: 5 sessions delivered to 338 attendees/registrants
  • Responsiveness: Resolved support tickets increased 700%, from 40 pre-launch to 320 cumulative tickets in the first six months.

Human Resources — Digital Annual Review Tool Implementation

Administration & Operations

Human Resources partnered with Service Support to launch a digital performance evaluation platform and trained over 350 staff members on its deployment. This initiative standardizes performance workflows and ensures secure, responsible stewardship of personnel records and institutional data.

Strengthening Core AI Platforms

Emerging Technology

U-M GPT remains a cornerstone of the university’s AI ecosystem by providing secure, no-cost access to leading models. Over the past year, the platform has been enhanced with expanded capabilities, which include improved file handling, image generation, and access to a wider range of models. In December 2025, U-M GPT was approved for use with PHI (Protected Health Information), which greatly increased its capabilities for users at Michigan Medicine by providing a secure AI platform to meet their needs. These updates culminated in an upgrade to GPT-5.4, which strengthens performance across writing, analysis, and problem-solving tasks and supports more consistent, reliable outcomes.

These enhancements have reinforced U-M GPT as a trusted, flexible platform that supports a wide range of academic and administrative needs while maintaining a strong commitment to privacy and data protection.

Advancing AI Responsibly

Emerging Technology

Across all of these efforts, ITS has maintained a strong focus on responsible AI adoption.

University-supported AI services are designed to be secure and private by default, which ensures that institutional data is protected and not used to train external models. At the same time, ITS continues to emphasize equitable access by making advanced AI tools that are compliant with WCAG 2.1 AA web accessibility guidelines available to the entire university community at no cost.

This balanced approach enables innovation while reinforcing the university’s commitment to ethical and responsible use of emerging technologies.

Looking Ahead

Emerging Technology

The past year represents a meaningful step forward in the university’s AI journey. With continued investment in platforms, tools, and community engagement, Michigan is moving beyond early adoption toward sustained, institution-wide impact.

As these capabilities continue to evolve, ITS will remain focused on supporting practical, responsible uses of AI that enhance teaching, accelerate research, and improve the way the university operates.

Digital Experience and Web/Mobile Application Development

Enterprise Application Systems (EAS)

Model Context Protocol Standardization: Established Model Context Protocol as the team’s unifying standard for AI tool integration, sharing templates and server code across ITS to help accelerate AI adoption organization-wide.

Application Framework Upgrades: Completed major framework upgrades for VaxViewer, Transfer Credit, ServiceNow Archive Viewer, and the ARC Resource Management Portal, improving maintainability and long-term platform support.

Michigan App Releases: Delivered five Michigan App releases, continuing to improve the mobile experience for the U-M community.

Student Administration Enhancements

Enterprise Application Systems (EAS)

Recruiting and Admissions Data Retention Modernization: Replaced a 20-year-old custom Prospect Purge process with Oracle’s Archive Manager tool, enabling archive-before-purge capabilities and allowing records to be restored for up to one year. The first production run deleted 18.5M rows of data in approximately 60 minutes.

Access Validation Audit Report Modernization: Launched a new Tableau dashboard for the Access Validation Audit Report in collaboration with DSP, advancing the MReports Modernization initiative. The updated report gives ITS Unit Liaisons three enhanced reports to help ensure users maintain appropriate administrative access.

Department Transfer and Separation Reporting: Added reporting that identifies users who have transferred between departments or left the university, helping Unit Liaisons update access more accurately and efficiently.

Enterprise Application Security, Compliance, and Reliability

Enterprise Application Systems (EAS)

SSL/TLS Certificate Management Improvements: Strengthened certificate management processes by improving inventory visibility and advancing renewal and monitoring practices across the environment, reducing operational risk from expired or misconfigured certificates.

Certificate Automation Readiness: Positioned teams for increased automation as the industry moves toward shorter public TLS certificate lifetimes and evolving CA/Browser Forum requirements.

PeopleTools Security Patching: Applied quarterly PeopleTools security patches to 80 separate PeopleSoft systems, supporting continued enterprise application security and compliance.

PeopleTools 8.62 Upgrades: Completed seven major PeopleTools 8.62 system upgrades, improving platform currency and long-term supportability.

Oracle 26 AI Upgrade Support: Supported 20 Oracle 26 AI upgrades on PeopleSoft systems.

Bomgar Remote Application Upgrades: Completed eight major Bomgar Remote Application upgrades and converted the service to full Okta client authentication.

DOJ Blocking Rules Implementation: Implemented DOJ blocking rules for seven countries of concern across 17 PeopleSoft systems.

Okta Proxy Authentication Migration: Migrated more than 30 EAS systems to Okta Proxy authentication.

Vulnerability Remediation: Remediated 562 vulnerabilities and completed 102 changes, improving the security and reliability of the enterprise application environment.

Expanding Privacy Awareness Programming

Information Assurance & Office of Privacy

In FY26, the ITS Office of Privacy remained focused on education and outreach for the U-M community and the public. The 2026 Privacy@Michigan event series, co-sponsored with the School of Information, ran from January 28 through late March. The five speaker events featured academics, artists, activists and community organizers, litigators, authors, and leaders sharing their unique perspectives on pressing issues at the intersection of privacy, surveillance, technology, civil liberties and human rights.

Throughout the academic year, the office collaborated with students on new programming and exciting initiatives:

  • Engagement toolkit for resident advisors, which was piloted at North Quad in April and is set for broader adoption in the fall.
  • A concept for a privacy game app for pre-teen kids that is set to transition to development by summer interns.

We further expanded outreach to students by hosting an inaugural art contest: Unveil. The contest culminated with a celebration on March 27 of the winning artists and an exhibition of their works as they explored privacy, surveillance, civil liberties, and individual rights through literary and visual arts. Winners came from a wide variety of academic disciplines. Families, friends, and members of the U-M arts community attended the event (featured in the “Michigan Daily”). The Unveil Winners Gallery on Safe Computing showcases the winning artworks.

Helping Units Meet Compliance and Reduce Risk

Information Assurance & Office of Privacy

The Information Assurance (IA) Responsive Information Security for Campus (RISC) team is committed to safeguarding information security and achieving regulatory compliance. RISC also serves as liaisons between various U-M departments assisting with security consulting, vendor/contract reviews, and risk remediation. In FY26, IA performed detailed risk assessments to help Inter-university Consortium for Political and Social Research (ICPSR) and other units to achieve an Authority to Operate (ATO) from relevant federal agencies. ICPSR hosts government information which requires compliance with the Federal Information Security Management Act (FISMA). 

The IA team also helps units identify appropriate mitigations if they don’t meet regulatory requirements. For example, they worked closely with various Dentistry teams post-audit to mitigate findings for multiple systems. IA provided Dentistry with their risk assessment findings, helped them understand what needed to be addressed, and connected them with relevant resources. 

In addition to their ongoing work with various units to help form and draft CUI related programs and tasks, IA is spearheading AI compliance across the university through solutions being proposed by faculty, staff, and students to ensure university and student data is not misused or profited from. 

Risk Management FY26 program metrics

  • 45 Risk Assessments
    • 20 completed
    • 15 in progress
    • 6 not started
    • 4 under review by compliance partners (i.e., HIPAA-related reviews may require approval from Michigan Medicine Corporate Compliance)
  • 313 risk registry items closed
  • 127 additional risks identified and added

Maintaining a Credible, Implementable, Enforceable, and Sustainable IT Policy Environment

Information Assurance & Office of Privacy

Several university policies and IT standards in FY26 were released by the Office of Privacy and Information Assurance: 

Providing Effective and Engaging Training Courses

Information Assurance & Office of Privacy

In FY26, the ITS Office of Privacy team developed a new Information Assurance-driven cybersecurity and data protection training course for university faculty and staff. The training course, DCE 101: Cybersecurity and Data Protection at U-M, is designed to help every member of our campus community recognize evolving threats and strengthen their daily security habits. Today’s cyber threats are increasingly sophisticated, and incidents have the potential to disrupt teaching, research, university operations, and even personal privacy. The training underscores U-M’s commitment to safeguarding sensitive information and supporting uninterrupted academic and operational excellence.

  • “This is one of the best-designed information security courses I have ever been required to complete.”
  • “This was well designed and to-the-point, thanks for creating such a short and straightforward overview of data security for staff!”

DCE 101 empowers U-M employees to recognize risks early, respond effectively, and uphold the university's reputation as a leader in research, teaching, and stewardship of data. 

The Office of Privacy also launched new courses for those with specific data protection responsibilities at the university: 

  • For Security Unit Liaisons - a new series of four self-directed, modular short training courses that provide key information and guidance about performing the SUL Role and Responsibilities at U-M.
  • For Data Stewards and Custodians - a new “Introduction to Data Stewardship at U-M” course covering U-M’s data governance program, the data stewardship framework, and the roles and responsibilities of Data Stewards and Custodians.
  • For faculty and staff who work with Protected Health Information (PHI) - a new, streamlined “HIPAA and Protected Health Information” course.

The team also refreshed the quiz-style Safe Computing challenge for students with updated, real-world scenarios featuring pithy tips and fun graphics to promote engagement. The students had positive feedback on the new experience:

  • “I think the scenarios were very relevant (especially the football tickets and job offers) and I liked the animal puns :)”
  • “I thought that it did a really good job of explaining all of the ways to prevent being hacked or being scammed. I am now much more informed about device security and will use all of these tips in the future.”
  • “I really liked how the information and tips provided are relevant to common scam and issues students run into, especially when new to the university.”

Expanding security visibility into cloud, containers, and web 

Information Assurance & Office of Privacy

In FY26, IA paired Tenable web application scanning with an internally developed tool called Web Store. Web Store helps identify web servers across U-M campuses and cloud environments by using DNS data, scanning common web ports, and collecting HTTP responses. The process allows IA to:

  • Identify where web servers are running across millions of IP addresses.
  • Narrow the scope quickly to a much smaller number of active web servers.
  • Determine which technologies are likely running based on HTTP headers and response content.
  • Identify where a vulnerable technology may be present.
  • Use web application scanning to verify whether systems have been fixed.

Without this system, identifying affected systems during a zero-day event could take days. With Web Store and scanning, IA can often reduce that work to roughly an hour.

Tenable also empowers units to conduct and manage their own scans, streamlining the process and reducing wait times for results. Web application scans help units meet their responsibilities for secure coding and vulnerability management. Web application scans are part of a larger toolkit of scanning capabilities that IA provides that include network vulnerability scans and penetration tests.

The on-premise Splunk environment, including the existing data, was migrated to Splunk Cloud in FY26. This allowed IA to increase their ability to analyze and consume security logs from 1 terabyte per day to 1.5 terabytes per day. Moving to Splunk Cloud also reduced the physical footprint of campus machines by more than 50%.

Strengthening of the Network

Infrastructure

The network infrastructure was substantially strengthened through a firewall and VPN modernization and the continued evolution of a high-capacity 100 Gbps campus backbone supporting advanced research. Strategic consolidation efforts reduced legacy complexity and generated over $300K in cost savings, while large-scale management of more than 17,300 wireless access points ensured seamless, ubiquitous connectivity across campus.

Additional Highlights

  • Maintained 100% uptime of the core U-M Net Wi-Fi network.
  • Total Access Points (APs): 16,788
  • Relocated fiber hub & decommissioned Wolverine Tower infrastructure.
  • Upgraded Central Firewalls
  • Upgraded Data Center Firewalls
  • Installed new Site-to-Site VPN hardware (cutover completed).
  • Installed new Remote Access VPN hardware.

Building a Safer, Smarter Campus

Infrastructure

Significant progress was made in public safety and infrastructure improvements. Over 1,000 security cameras were deployed, new emergency systems were planned, and extensive cabling and fiber projects supported both academic and safety needs. These upgrades directly contributed to safer, smarter campus operations.

Additional Highlights

  • Emergency kiosk Wi-Fi/AP design.
  • Designed and integrated A/V intercom calling paths for Emergency Kiosks, including DPSS MiServer consultation.
  • Housing access control engineering support.
  • Participation in MCard Advisory Board.

MiWorkspace: Future-Proofing Computing Infrastructure

Support Services

MiWorkspace Core was conceived, built, and fully operationalized in just four months, from September through December 2024. The service extends Mac, Windows, and MPrint platform services to remaining campus units outside the full MiWorkspace service.

With onboarding underway, 9 of 11 academic units are complete and 2 are in progress. The MiWorkspace family of services will soon manage 34,000+ campus endpoints, making it one of the largest centrally managed endpoint programs in U-M’s history.

This expansion strengthens endpoint security, standardizes support, improves lifecycle management, and provides campus units with access to scalable platform services.

Tech Shop: Supporting Secure Access with Okta

Support Services

Okta continued to serve as the secure front door to U-M systems, with more than 175,000 users signing in each week. The platform enforces security policies and manages access decisions across thousands of applications for faculty, staff, students, researchers, and affiliates.

As U-M transitioned from Duo to Okta for two-factor authentication, Tech Shop played a key operational role by distributing 4,358 Okta security tokens to faculty and staff across the Ann Arbor campus. The team coordinated procurement, inventory management, custom U-M branding, and customer support to meet increased demand and help ensure uninterrupted access to critical systems supporting teaching, research, healthcare, and administrative operations.

Tokens were distributed through multiple service channels: 1,057 to walk-in customers, 643 through curbside and counter service, 347 shipped directly to customers, and 2,311 hand-delivered through the Campus Delivery Program. This coordinated effort helped the university meet adoption timelines and maintain business continuity throughout the transition.