Wolverine Identity Program Progress

A lot has happened already in the Wolverine Identity, learn about the active projects below and check out the program’s successes page to learn more about what the program has accomplished so far.

Duo Retirement

In Progress - December 1, 2026 Deadline


As a part of the Wolverine Identity Program and our continuing efforts to transition to Okta, Duo will be retired and all systems integrated with Duo must transition to Okta by December 1, 2026.

See more details about the transition and find out if you need to take action on the Duo Retirement page.

Single-Sign On Application Migration to Okta

In Progress

 

No firm deadline at this time to be migrated off of Shibboleth for Single Sign On.  See more details about the transition from Shibboleth to Okta on the Single Sign On with Okta page.

Visitor Accounts and Sponsorships

In Progress

Visitors and sponsored accounts will be modernized in three phases.

Phase 1 

Timeline: Fall 2026

Status: In Development

Phase One will replace the existing sponsorship system with a new, modern backend system. This new system will:

  • Send automated, standardized lifecycle communications to alert sponsored individuals and unit contacts of account change. This aligns with current practices for other affiliations.
  • Streamline restricted status checks
  • Collect more required information for each sponsorship (description and admin contact)

Phase Two

Timeline: TBD

Status: In Design

The next phase will:

  • Provide a new Visitor Data Warehouse with current and historical information on sponsorships.
  • Require new unit-level approval for sponsorships. 

Phase Three

Timeline: TBD

Status: In Design

The final phase of the project aligns the program with the Covered Visitor policy by: 

  • Rebranding Sponsored Affiliates as Visitors
  • Introducing new sponsorship reasons
  • Allowing future sponsorship start dates
  • Support Covered Visitor SPG requirements
  • Enabling visitors to create their own uniqnames  

Account Lifecycle Implementation

In Design

With the adoption of Okta now complete, the new account lifecycle process will soon go into effect.  Detailed design work is underway with plans to begin initial notification to inactive accounts in the coming months.

Future Projects

  • Non-Person Accounts and Security Groups
    • Status: In Definition
    • Goal: Establish consistent governance, standardized processes, accountable ownership, and strong lifecycle management for all types of non-person accounts. Establish a distinction of groups that are used for security and access vs email and collaboration and apply similar governance and strong lifecycle management.
  • Privileged Access Management
    • Status: Not Started
    • Goal: Retire CyberArk and Passwordstate and migrate existing users to Okta Privileged Access Management
  • eDirectory Retirement and the Design the Future Service Offering for LDAP
    • Status: Not Started
    • Goal: Retire the legacy Open Text eDirectory platform that manages the identity store and identity data feeds. Design and implement a secure, sustainable LDAP service offering for the future.
  • Identity First
    • Status: Not Started 
    • Goal: Establish a single authoritative source for creating and managing all university digital identities, reducing synchronization complexity, access delays, and administrative effort across identity types and systems.