|
MCommunity Sponsor System Overview
R1458 October 2009
The MCommunity Sponsor System allows authorized U-M staff members to create online identities for people who are affiliated with the university but who do not appear in any of the official university data feeds. Sponsored individuals include, for example, conference attendees, contractors, incoming faculty who need access to U-M resources before the hiring process is complete, guests who need wireless access, and others.
This document provides an overview of the system, including details about uniqname types, identity types, sponsorship lengths, minimum data requirements, notifications sent by the system, what happens when a sponsorship expires, who can reset passwords for sponsored individuals under what circumstances, and more. For step-by-step instructions, see Using the MCommunity Sponsor System Via the Web (S4356). Table of ContentsWhat Is MCommunity?MCommunity is a central system will stores information about people that can be used to grant them access to various online resources at both the University and departmental levels. It is a flexible, centralized, identity management system that U-M campuses and units will be able to use in decentralized ways for provisioning information technology resources and services.MCommunity will replace the University's current uniqname management system and the U-M Online Directory. To learn more about MCommunity, see MCommunity Overview (R1457).
What Is the Sponsor System?The Sponsor System is the part of MCommunity that is used to create identities for sponsored affiliates, people who are affiliated with the university but who do not appear in any of the official university data feeds. Sponsored affiliates include, for example, conference attendees, contractors, incoming faculty who need access to U-M resources before the hiring process is complete, and others.U-M staff members who currently use Information and Technology Services's (ITS) uniqname system to create uniqnames via either WebUniq or the uns command-line tool will instead use the data in MCommunity Sponsor System to create sponsored identities (including uniqnames) via the web or via a command-line tool. The MCommunity Sponsor System is used for creating and managing digital identities (including uniqnames) in MCommunity for sponsored affiliates. Once a sponsored affiliate is included in MCommunity, U-M central units and departments will be able to use MCommunity to provide that person with access to information technology services and resources. Eventually, MCommunity will also handle provisioning of computing services. The Sponsor System basically allows units to sponsor people as members of the U-M community for specified periods of time. An individual may be sponsored by more than one unit.
Who Can Use It?Authorized U-M staff members can use the system. To use the system, you must become a sponsorship administrator.
Sponsor. A U-M unit that sponsors creation and/or management of identities in MCommunity. Sponsoring Authority. A person who authorizes sponsorship administrators for specified University units and/or departments. It is the responsibility of the sponsoring authority to oversee the sponsorship administrators s/he has authorized and ensure that appropriate policies and guidelines are followed. For more about sponsoring authorities, see MCommunity Sponsoring Authority Policies and Agreement (R1460). Requester. A person in the sponsoring department who initiates a request for creation of a sponsored identity. For example, a conference organizer might request a number of sponsored identities with uniqnames, or an administrative staff member might request a sponsored identity and uniqname for an incoming faculty member who needs early access to online resources. In some cases, the requester might be the sponsorship administrator. Sponsorship administrators. The people who enter information into MCommunity using the Sponsor System to create sponsored identities, including uniqnames. For more about sponsorship administrators, see MCommunity Sponsorship Administration Policies and Agreement (R1459). Departments can have their own sponsorship administrators to manage MCommunity identities for sponsored affiliates for their departments, or they can request that the ITS Accounts Office manage those MCommunity identities for them.
Uniqname Creation OptionsThe Sponsor System allows sponsorship administrators to request a uniqname. The administrator can request a specific uniqname, but if that uniqname has already been assigned, the system will generate a uniqname. If the administrator does not request anything specific, the system generates a uniqname.Uniqname self-registration will be added to the Sponsor System later. This will allow sponsored individuals to select a uniqname and password themselves via a web interface. This will be similar to the uniqname self-registration process already available to new staff, new Ann Arbor students, and alumni.
Uniqname Types—Regular and TemporaryThe Sponsor System can assign regular and temporary uniqnames. See the Sponsorship Components Chart below for details about who gets what type of uniqname.
Identity Types—Strong and WeakThe identity type is determined by the amount of data collected. See the Sponsorship Components Chart below for details about who needs what type of identity.
Sponsorship Business ReasonsThe reason for a sponsorship is defined by the relationship the sponsored individual has with the university.
Sponsorship Components Chart
* Sponsorship administrators can change the suggested (default) sponsorship length when they set up sponsorships. The maximum length is 1 year. All sponsorships are renewable. ** Only the ITS Accounts Office can set up sponsorships for U-M Online subscribers.
Uniqname and Password NotificationsWhen a sponsorship administrator sets up sponsorships, including uniqnames and passwords, the Sponsor System generates the following confirmations and notifications:
See Appendix: Sample E-Mail Notifications below for the text of the messages.
Sponsorship ExpiryAll sponsorships have a start date and an end date. They expire on the end date. The maximum sponsorship duration is one year. However, sponsorship administrators can renew sponsorships as often as needed—as long as they have not yet expired.The sponsorship administrator receives an e-mail notification two weeks (14 days) before any sponsorship they set up will expire. No notice is sent for sponsorships lasting less than two weeks. The administrator can renew the sponsorship if needed by changing the end date. (See Appendix: Sample Notifications below for a sample of the e-mail notification.) What happens on expiry depends on the identity type—strong or weak. If there are multiple sponsorships, the expiry process happens when the last sponsorship ends. When Sponsorships with STRONG Identities ExpireIncludes contractors, incoming faculty/staff, temporary staff, and visiting researchers/scholars. These sponsorships require enough identity information to create an entry in M-Pathways/Wolverine Access.
NOTE: If a sponsored person with a strong identity becomes an employee or student, their uniqname and any associated ITS computing services will continue, even after their sponsorship expires, because of their new affiliation. When Sponsorships with WEAK Identities ExpireIncludes associates, VIPs, conference/program participants (including summer campers), wireless users, and other short-term guests. These sponsorships require minimal identity information and do not result in an M-Pathways/Wolverine Access entry.
Tips For Managing Sponsorship Expiry
Password Resets for Sponsored IndividualsSponsored individuals can change their own UMICH Kerberos passwords using the same password changing page (login required) used by all other members of the University community.Regular Uniqnames, Strong IdentitiesSponsored individuals with regular uniqnames and strong identities who forget their passwords must contact the ITS Accounts Office to have their passwords reset. There is enough information in MCommunity about these people for the Accounts Office to verify their identity over the phone or in person—and therefore to reset their passwords for them.This includes contractors, incoming faculty/staff, temporary staff, visiting researchers/scholars, and U-M Online subscribers. Regular or Temporary Uniqnames, Weak IdentitiesSponsored individuals with regular or temporary uniqnames and weak identities must go through their requester (the person who requested their sponsorship) for password resets. The requester can ask either a departmental sponsorship administrator or the ITS Accounts Office to do the actual password resetting, but it is the responsibility of the requester or departmental sponsorship administrator to verify the sponsored individual's identity and get the reset password to that person in a secure manner.This includes VIPs, conference/program participants, wireless users, and other short-term guests.
Transitioning Between Sponsorship and Identity TypesYou cannot change the business reason for a sponsorship after the sponsorship has been set up. You cannot, for example, change a contractor to an incoming staff member. However, you can add a new sponsorship with a different business reason (with some limitations depending on the uniqname type). An individual can have multiple sponsorships with different start and end dates. See Adding Sponsorships to an Already-Sponsored Person in Using the MCommunity Sponsor System Via the Web (S4356) for instructions.Sponsorships with Temporary UniqnamesSponsored people with temporary uniqnames can only have additional sponsorships that also use temporary uniqnames. If you want to create a sponsorship with a regular uniqname for a person who currently has a temporary uniqname, you must create a new sponsored identity—and uniqname—for the person. You can allow the sponsored identity with the temporary uniqname to expire on its own, or you can edit it to make it expire early if you wish.Sponsorships with Regular UniqnamesSponsored people with regular uniqnames can only have additional sponsorships that also use regular uniqnames. If you add a sponsorship that results in a strong identity to the entry for a sponsored person whose current sponsorship has a weak identity, you will be required to provide additional identity information during the sponsorship process.Some sponsored people, such as incoming faculty members, will transition from being sponsored to being regular members of the University community who are included in one of the authoritative data feeds, such as the feed of employee data from M-Pathways. MCommunity will reconcile the information from M-Pathways with that in the Sponsor System, and allow the person to keep the uniqname she or he is using—as long as there is enough identity information in the Sponsr System to match the two records. It is essential that enough identity data for a strong identity be provided for persons who will make this transition.
Additional ResourcesThe MCommunity Project website provides information about the project status, timeline, history, and more.Visit ITS's Information System to obtain ITS computer documentation and other resources. A list of relevant documents follows:
MCommunity Sponsorship Administration Policies and Agreement (R1459) MCommunity Sponsoring Authority Policies and Agreement (R1460) We welcome your comments; please send e-mail. ITS's Online Help Desk provides a variety of computing help resources. Please direct questions about the MCommunity Project to the MCommunity leads at MCommunity.Leads@umich.edu.
Appendix: Sample E-Mail NotificationsHere are samples of the automated e-mail notifications sent by the MCommunity Sponsor System.E-Mail Notification of Uniqname to Sponsored IndividualNOTE: E-mail notifications are not sent to people sponsored using file import.This is the text of the message sent: To: the newly sponsored individual Subject: Your U-M uniqname and password Welcome! You are now a sponsored member of the University of Michigan Community. You may use the uniqname below, in conjunction with a password, to log in to the U-M computing services and resources that your sponsoring department has authorized you to use. The sponsoring department will contact you and provide you with your password.
Sponsorship Start Date: Month DD, YYYY
Uniqname: xxxxxxxx You can change your password to something that is easier for you to remember at this web page: https://accounts.itcs.umich.edu/kpasswd-bin/kpasswd.cgi By using the University's technology services, you agree to follow U-M information technology policies and guidelines for responsible use. Inappropriate use of U-M technology resources may result in termination of access, disciplinary review, expulsion from the University, termination of employment, legal action, or other disciplinary action. For information about responsible and appropriate use, see http://www.itcs.umich.edu/security/policies.html If you have questions about your sponsorship or your uniqname and password, you can contact the ITS Accounts Office at 734-764-8000, Option 3, or itcs.accounts@umich.edu. (This is an automated message sent by the University of Michigan MCommunity Sponsor System to inform you of your U-M sponsorship and your uniqname and password.)
E-Mail Confirmation to RequesterThis is the text of the message sent:To: Requester Subject: MCommunity Sponsorship(s) Created The sponsorship(s) below has/have been created in the MCommunity Sponsor System at your request:
Sponsorship Start Date: Month DD, YYYY
Sponsored People: Full Name, uniqname If you have questions about this or need any changes made, please contact the sponsorship administrator listed above. You can also contact the ITS Accounts Office (itcs.accounts@umich.edu or (734) 764-8000, Option 3).
If you need computing services set up for the sponsored individual(s), please contact the ITS Accounts Office. You can use the Computing Services for Sponsored Persons Request Form, which is available on the Accounts Office webpage, to request services.
Please note that wireless access is provided automatically to all sponsored individuals at no charge; you do not need to request it. (This is an automated message sent by the University of Michigan MCommunity Sponsor System to confirm sponsorship creation.)
E-Mail Notification to Sponsorship Administrator of Sponsorship ExpirationThis is the text of the message sent:To: Sponsorship Administrator Subject: MCommunity Sponsorship(s) to Expire [Month DD, YYYY]
The MCommunity sponsorship(s) listed below will expire on:
Unless these sponsored individuals have other active sponsorships, they will lose the ability to use their uniqname and password when the sponsorships expire. You can use the MCommunity Sponsor System to extend the end date of the sponsorships if necessary.
Sponsoring Department: Department Name
Sponsorships expiring:
Name, uniqname
(This is an automated message sent by the University of Michigan MCommunity Sponsor System to inform you about sponsorships that will expire soon.)
|