Skip to main content
Kean University Account Management Standard Operating Procedure (SOP03)
Table of Contents
About
This Standard Operating Procedure (SOP03) defines how Kean University creates, manages, audits, and deactivates user and system accounts in alignment with the Account Management Policy (KU ID 03).
| Field |
Value |
| Version |
1.0 |
| Author |
Identity & Access Management Lead |
| Approver |
Chief Information Security Officer |
| Effective Date |
February 13, 2026 |
| Review Date |
February 13, 2027 |
Back to top
Security Control Summary
- All accounts must follow standardized naming conventions
- Accounts must be provisioned based on authoritative sources (HR, Registrar)
- Least privilege access must be enforced through role-based access control (RBAC)
- Vendor and service accounts must have defined expiration or review periods
- All account changes must be logged and auditable
- Accounts must be disabled within required timelines upon termination or inactivity
Back to top
Scope
- All staff, faculty, students, vendors, and contractors
- All account types including user, service, vendor, and privileged accounts
- All systems requiring account creation (Active Directory, Azure AD, Microsoft 365, Workday, Colleague)
Back to top
Definitions
-
User Account: Identity used to access University systems
-
Service Account: Non-human account supporting applications or services
-
Privileged Account: Account with elevated permissions
-
Vendor Account: Temporary account for external users

Back to top
Roles & Responsibilities
| Role |
Responsibility |
| IAM Lead |
Account lifecycle management and enforcement |
| Human Resources (HR) |
Provide onboarding and termination data |
| Registrar |
Manage student lifecycle events |
| Managers |
Approve vendor and privileged access requests |
| Security |
Monitor and audit account activity |
Back to top
Procedure Steps

1. Account Creation
Faculty/Staff Accounts
- HR must submit onboarding data
- Accounts must be automatically created from authoritative systems
- Naming convention: first initial + first 7 characters of last name
- Baseline RBAC roles must be applied
- All creation actions must be logged

Student Accounts
- Registrar systems must trigger account creation
- Naming convention: first 6 characters of last name + first 2 of first name
- Student RBAC roles must be assigned
Vendor Accounts
- Manager must submit request with business justification
- Accounts must follow "VND_" naming convention
- Accounts must expire after one year unless renewed
Service Accounts
- Must include documented justification
- Naming convention: "SVC_" + system name
- Credentials must be securely stored (vaulted)
- Annual review is required
2. Authentication Requirements
- All accounts must comply with password and multifactor authentication (MFA) standards
- Authentication requirements are governed by KU ID 02ST
3. Account Modification
- Managers must request role or access changes
- IAM must update account attributes and group memberships
- All changes must be logged in audit systems
4. Account Deactivation
Faculty/Staff
- Account disablement must be triggered by HR termination data
- Accounts must be disabled within 24 hours
- All access and group memberships must be removed
Students
- Accounts must be disabled after three inactive semesters
- Associated licenses must be removed
Vendors
- Accounts must expire annually unless renewed
Service & Privileged Accounts
- Accounts must be reviewed annually
- Accounts must be removed if no longer required

5. Account Auditing
- Account audits must be performed quarterly or biannually
- Orphaned, dormant, or excessive accounts must be identified
- Remediation must occur immediately
- Audit results must be logged
Back to top
- [Insert link: KU ID 03 – Account Management Policy]
- [Insert link: KU ID 01 – Identity & Authentication SOP]
- [Insert link: KU ID 02 – Access Control SOP]
- KU ID 02ST – Password & Authentication Standard
Back to top
Metrics & KPIs
- Account creation SLA compliance (measured via IAM system reports)
- Time to disable terminated accounts (target: ≤ 24 hours)
- Orphaned account remediation rate
- Audit completion rate
Back to top
Required Records
- Account creation logs
- Account modification logs
- Deactivation logs
- Audit reports
Stored in: Identity and Access Management systems and Scrut.io
Back to top
Exception Handling
- All exceptions must be approved by the Chief Information Security Officer (CISO)
- Exceptions must include documented business justification and risk assessment
- Each exception must have a defined expiration date
- Exceptions must be formally tracked in [Insert system, e.g., Scrut.io]
Back to top
Revision History
| Version |
Date |
Change |
Author |
| 1.0 |
February 13, 2026 |
Initial SOP |
IAM Lead |
Back to top