Case study: Identity & Access Management
Rebuilding identity for an entire university.
How a leading Australian university is replacing 16 years of identity infrastructure, and the Move FWD team at the centre of it.
Client
A leading Australian university
Engagement
Multi-year identity & access management transformation
Move FWD role
The core program team: project manager, program architect, senior business analyst and identity specialist
The challenge
Untangling 16 years of embedded logic, while the university kept running.
The university manages identity for hundreds of thousands of people. Staff, students, higher degree researchers, alumni, affiliates and external partners. Each of them needs the right access on the right day, and none of it on the day after they leave.
That was running on a legacy in-house identity platform that had been built, extended and patched over 16 years. It worked. But it was doing two very different jobs at once. It decided who a person was, and it enforced what they could reach. Those two things had grown into each other, and only a handful of people understood how.
Replacing it was never a lift and shift. It was untangling 16 years of embedded logic while the university kept running.
What we did
What the program has done since 2024.
No technology was deployed in 2024. That was a decision, not a delay.
The first year went into governance, procurement and team. A program structure with clear roles. A steering committee cadence at executive level. An open market process that selected a Gartner Leader platform and an implementation partner. Discovery ran alongside it: current state documentation, stakeholder mapping, and a full review of the legacy platform and everything hanging off it. A transformation of this size fails quietly if the governance and the contract are wrong. Getting that year right is the reason the rest of the program has held.
Small footprint, real users, real production
The platform went in. Test and production environments, base configuration, directory integration, self-service password reset. A small set of pilot applications on single sign-on. Adaptive multi-factor authentication for a pilot staff cohort with behaviour detection and risk scoring. Enough to prove the platform without betting the institution on it.
The number that moved every week
Adaptive MFA extended to every cohort. Passwordless enrolment for students, researchers, alumni and externals. Device trust. Bulk user migration into the new directory using an inline password hook, so no one was forced through a reset they did not ask for. We built a live adoption dashboard tracking legacy versus new MFA prompts by cohort, published straight into the steering committee. That one artefact changed the conversation. Decommissioning the legacy MFA product stopped being a date on a slide and became a number that moved every week.
The current phase, and the hard one
Application migration. Discovery surfaced close to 1,500 service provider entity IDs. Analysis reduced those to close to 300 applications that genuinely need migrating. That reduction is the work. More than 200 of the remainder share an identical attribute pattern, so they are a factory, not 200 separate projects. Everything else is grouped into tranches by integration pattern and attribute complexity, not by who shouted loudest.
Joiner, mover, leaver. This is the part people feel. A new starter used to wait on manual steps. Someone changing roles kept old access alongside new access. Someone leaving lingered longer than they should. The program automates the full cycle. Accounts provisioned before day one. Role changes that drop old access as new access lands. Departures that run a defined sequence instead of a ticket, with grace periods, archival and staged deletion. Failed events route to a human, not a log file.
Decommission. The legacy platforms come out. Everything in this phase is sequenced backwards from that date.
Outcomes
The numbers that mattered.
- Close to 1,500 entity IDs analysed and reduced to close to 300 migrations.
- More than 200 sites consolidated into a single repeatable migration pattern.
- 18 identity capabilities assessed, average maturity moving from 1.4 to a target of 3.9 on a five point scale.
- Legacy MFA replaced across every user cohort in the institution.
Move FWD's role
Making sure the program knows where it is going, and can prove it.
Move FWD provided the core program team into the transformation: the Principal Project Manager, the Program Architect, the Senior Business Analyst and the Senior Identity Specialist. Program structure and governance, procurement and contract shaping, phase planning, architecture direction, business analysis, and executive reporting into steering committee.
The delivery is the university's. The platform build sits with the university and its implementation partner. Our work is making sure the program knows where it is going, and can prove it.
Contact
Planning an identity program of your own?
Talk to the people who have run one at this scale.
Book a conversation →