We have collectively taken significant steps to improve the security profile of the university, but there remain certain cybersecurity risks and inconsistencies in digital experiences and service levels. While each school or unit has unique IT needs, we will be at greater risk for cybersecurity incidents without a more unified approach. Our collective goal is to ensure that all U-M technology remains as secure as possible. IT security is a shared responsibility for everyone at U-M.
The Regents, President, Provost, VPIT-CIO, and Executive Officers of the University of Michigan.
This effort is sponsored by U-M leadership and is built on the foundation of a shared partnership with every college, school and unit at the university. The discovery and implementation planning is being coordinated and managed by the Office of the VPIT-CIO and Information and Technology Services (ITS). Andrew Palms, ITS Executive Director, Infrastructure, is the program director.
Yes, several other higher education institutions have initiated similar efforts in the past two years, including Penn State, UCLA, and Purdue, among others. While many of those efforts focused on centralizing all university IT staff under one unit, U-M’s IT Transformation was designed to prioritize security while also accommodating the talent and culture of local IT staff.
The 21 schools/units identified for U-M’s IT Transformation are: A. Alfred Taubman College of Architecture & Urban Planning; College of Engineering; College of Literature, Science, and the Arts; College of Pharmacy; Gerald R. Ford School of Public Policy; Institute for Social Research; Law School; Life Sciences Institute; Marsal Family School of Education; Penny W. Stamps School of Art & Design; Rackham Graduate School; School for Environment and Sustainability; School of Dentistry; School of Information; School of Kinesiology; School of Music, Theatre & Dance; School of Nursing; School of Public Health; School of Social Work; Stephen M. Ross School of Business; and University Library.
Administrative units, Michigan Medicine, UM-Dearborn, and UM-Flint are not currently included in this initiative. However, each is coordinating with us on ongoing projects to improve security measures, training, and other efforts.
This initiative focuses on the foundational technologies that pose the most institutional risk and benefit most from consistent standards. Those technologies and services primarily focus on:
- Endpoint devices (laptops & desktops)
- Enterprise server, compute, and storage
- Identity, privileged account management, and access management
- Network & telecommunications
Where not already in use, core areas within units will transition to adopting standardized IT Services. Standardizing the implementation and management of core security services such as VPNs and firewalls is essential to protecting U-M from future digital threats. All of the IT Transformation recommendations are informed by industry-standard information security best practices and well-known vectors for cyberattacks.
A comprehensive discovery process was completed over several months, ending in August 2025. As part of the discovery process, unique unit support information as well as core service information was captured. Those discovery reports will be shared in October 2025. In addition, an IT Transformation Advisory Committee has been formed to help shape priorities and ensure that unit CIOs and IT leaders will continue to play a central role in guiding the work ahead.
- Dan Maletta, Executive Director of Information Technology and CIO, College of Engineering (Chair)
- Cassandra L. Callaghan, Chief Information Officer, School of Dentistry
- Kerry Flynn, Chief Information Officer, Stephen M. Ross School of Business
- Ted Hanss, Chief Information Officer, College of Literature, Science, and the Arts
- Andy Palms, Executive Director of Infrastructure, Information and Technology Services
- Mashon Allen, Chief of Staff, VPIT-CIO, Information and Technology Services
CIOs, IT Directors, and identified Unit IT staff from each impacted college, school, or unit were included in the discovery process.
We do not anticipate that this initiative will impact existing IT staffing. Unit IT staffing needs are determined by each unit, and that will continue.
- Students and Staff: Very little will visibly change in how you interact with U-M IT solutions, but the underlying systems will become more user-friendly, robust, and secure.
- IT Staff: You will begin working with new services as you support your school, college, or unit. You will receive training on those services and on enhancing security more broadly.
- Faculty: Most faculty will not experience any significant IT changes. However, due to evolving federal mandates and requirements, those involved in research may find that some services will require additional controls and procedures to protect data. We are committed to working collaboratively with unit IT staff to minimize any impact on how you access and use those services.
Enabling teaching, learning and research by our students and faculty motivates this initiative's overall vision. IT Transformation recognizes that each school and unit at U-M has unique priorities and ways of working. Our goal is to provide a secure, consistent foundation for information security that supports these differences rather than replaces them. Partnership among units is expected and encouraged with active involvement in the planning and transition process. Input gathered through discovery and ongoing engagement will continue to shape how required services are implemented. Standards will focus on reducing institutional risk and ensuring core consistency, while units retain flexibility in areas where local mission, culture, and values require distinct approaches.
Yes. Schools/units will be presented with training and change management options when entering the Implementation phase of the initiative.
It is understood that various schools, colleges, and units may have a specific business and/or technical reason that might prevent them from using certain required IT services. The IT Transformation initiative is actively engaging with units to understand their individual requirements.
U-M has a robust series of standards and policies related to information technology and information security, which apply to all faculty, staff, affiliates, and vendors. Please note that, as it is made clear in SPG 601.27, all individuals at U-M bear a responsibility to protect the university’s digital assets.
ITS is committed to financial transparency. The IT Transformation initiative will involve adopting both new and existing services, and we will work closely with the Office of Financial Analysis (OFA) to determine the rates that units will be responsible for. The initial implementation phases will be used to assess costs and inform rate setting. Through our efforts and with the support of the President and executive leadership, one-time funding has been secured to support the university’s initial transition to more standardized IT services. This funding will provide time to conduct these financial assessments.
Key Financial Information
MiWorkspace Core Charge Estimate
The unit’s estimated charge for MiWorkspace Core is based on data as of November 2024 of full-time equivalent (FTE) in your unit. The estimated rate per FTE is approximately $300 per FTE. Official FTE counts, inclusive of graduate student employees, are provided by University Human Resources (UHR).
U-M Net In-Building Upgrades
Units will continue to fund the networks in their buildings as they do today. In particular, units must submit orders and fund upgrades for end-of-support network switches because they pose a security risk.
Temporary Financial Support for Required Services
For units not currently using the following required services, charges will be supported through one-time funding from the Provost and President until FY28.
- Units will continue paying for Windows, Mac, and MPrint a la carte services. MiWorkspace Core charges begin in FY28.
- MiServer, MiDatabase, MiStorage, and MiDesktop charges are based on actual usage. Estimates will be provided after requirements are gathered and onboarding activities are completed. The cost of these services incurred due to the transition will be covered until FY28.
MiServer Rates and Billing
MiDatabase Rates and Billing
MiDesktop Rates and Billing
MiStorage Rates and Billing
Questions or Feedback?
You can send any questions or concerns to [email protected].
