Authentication

AuthenticationAuthentication Authentication is the act of determining that a person is who they claim to be. For more information, see our Concepts page. is the process of verifying that a person is who they claim to be.

When an end user successfully logs in (e.g., using a username and password), the authentication system (the identity provider) certifies to a consuming service (the service provider) that the user is who they claim to be.

Important Note: Authentication is not the same as authorizationAuthorization Authorization refers to the act of determining whether an authenticated user is allowed to access a specific resource or take a specific action. For more information, see our Concepts page.. Authentication determines identity but does not decide whether an end user should have access to a resource. However, the identity provider may provide information to the service provider to assist in making an authorization decision.

Enterprise Authentication

The IAMIAM Identity and Access Management (IAM) is a set of policies, processes, and technologies designed to ensure that the right individuals (identities) have the right access to resources within an organization. IAM involves managing and securing digital identities, controlling access to systems and data, and maintaining the confidentiality, integrity, and availability of information. Team offers Enterprise Authentication, a campus-wide, web-based single sign-on service powered by:

  • Security Assertion Markup Language (SAMLSAML Security Assertion Markup Language (SAML) is a standard, XML-based language for exchanging authentication and authorization data between identity providers and service providers. This standard is currently used by Enterprise Authentication (as well as hundreds of service providers that integrate with our identity provider).) 2.0 Identity Provider (IdPIdP An Identity Provider (IdP) is a software tool or service that offers user authentication as a service. The IdP manages the user's primary authentication credentials and issues assertions derived from those credentials. At UT Austin, the primary IdP used to authenticate the UT EID and EID Password is Enterprise Authentication, which is managed by the IAM Team. For more information, see our Concepts page.)
  • OpenID Connect (OIDCOIDC OpenID Connect 1.0 (OIDC) is an authentication layer built on OAuth 2.0 where the identity provider that runs the authorization server also holds the protected resource that the third-party application aims to access.) 1.0

Benefits of Enterprise Authentication

For additional requests and support, consult the Authentication knowledge articles in UT ServiceNow.

Guest Authentication

Guest Authentication is a centralized service for low-risk web-based services and applications. It allows access without requiring a UT EIDUT EID The University of Texas Electronic Identity (UT EID or EID) is the public records identifier for principals at the university. See our Concepts page for more information..

Supported Accounts

  • Apple ID
  • Google Account
  • Microsoft Account
  • Accounts from identity providers in the InCommon Federation

Key Features

  • Existing UT EID holders can authenticate to resources protected by Guest Authentication through the Enterprise Authentication service.

For additional requests and support, consult the Authentication knowledge articles in UT ServiceNow.

Multi-Factor Authentication (MFAMFA Authentication makes use of one or more factors of authentication: something you know (e.g., a password), something you have (e.g., your smartphone), or something you are (e.g., a fingerprint). Multi-Factor Authentication (MFA) makes use of two or more factors when authenticating you. For more information, see our Concepts page.)

If your service or application requires Multi-Factor Authentication (MFA) but cannot use Enterprise Authentication, the IAM Team may be able to assist.

Benefits of MFA

For additional requests and support, consult the Authentication knowledge articles in UT ServiceNow.

Service Availability Metrics

The IAM Team has established the following Service Level Objectives (SLOs):

  • Multi-Factor Authentication (MFA): 99.795% availability
  • Enterprise Authentication: 99.491% availability

Historical Availability Metrics

YearEnterprise AuthenticationMulti-Factor Authentication (MFA)
Target 99.491% 98.900%
2025 99.779% 99.949%
2024 99.972% 99.983%
2023 99.818% 100.000%
2022 99.815% 99.795%
2021 99.968% 99.950%
2020 99.940% 99.256%
2019 99.989% 100.000%

For more data, visit our Metrics page.

Change Log

Duo Release Notes

RSS Error: Retrieved unsupported status code "403"