What is this guide?
This guide explains how Kean IT supports your research and scholarly work — including how ThreatLocker application security is managed so it doesn't get in your way. If you have questions, contact Joe Pallante or schedule time with Keiron DeFreitas via Microsoft Bookings.
Table of Contents:
|
Research Computing Coordinator Joe Pallante [email protected] Office Hours: Mon–Fri, 8:30 AM – 4:30 PM |
IT Help Desk (908) 737-6000 Schedule via Microsoft Bookings |
Note on External Review
This framework is an interim guide developed in response to faculty concerns raised through the Research Infrastructure Working Group. It is intended as a starting point and will be reviewed and refined in conjunction with the external review process currently being scoped in collaboration with Dr. Bostian and the Provost's office. Faculty input into the final framework is expected and welcomed.
Step 1 — Which type of researcher are you?
Section 1 — Researcher
The SituationYou use one Kean laptop. ThreatLocker may be blocking applications you need for your day-to-day work. |
The Fix — We Sit With YouAn IT engineer sits with you in person to:
ThreatLocker in Secure Mode |
How to Get Help: Schedule a consultation via Microsoft Bookings (click here to schedule) or contact the IT Help Desk at (908) 737-6000. An agent will meet with you directly.
Section 2 — Regulated Data Researcher
Researchers who create or use data regulated by funding agencies or by law are classified into security tiers based on the requirements of each project. A VM and data storage are available to meet these requirements. The VM runs on Kean infrastructure and is accessed securely from your existing laptop — no second device required. The VM is hosted within the Research VLAN, with access provisioned on request.
Important: Tiers are project-scoped, not person-scoped. Your tier applies to the specific project and its associated data type — not to your entire research profile. You may operate at different tiers across different projects simultaneously. Having one project that requires Tier 3 treatment does not mean all of your research must go through Tier 3.
| Your Research / Data Type | Security Level | VM ThreatLocker Mode |
|---|---|---|
| Funded research, public data | Tier 1 | Monitor / Self-elevate (minimal friction) |
| Funded research, restricted data | Tier 2 | Monitor / Self-elevate + enhanced logging |
| Regulated data (HIPAA, FERPA, ITAR, CUI) | Tier 3 | Secure Mode / Application allowlisting (1-day review) |
| AI / ML / GPU workloads | Datacenter GPU node or physical workstation | Secure Mode / Self-elevation with path-based rules |
Section 3 — Advanced / Exception / Instrument Researcher
Who this applies to:
- Developers compiling code regularly (C++, Python, etc.)
- Researchers using package managers like pip, conda, or NPM
- AI/ML researchers running GPU workloads
- Devices that are sensitive to computing resource consumption
- Researchers working with regulated or sensitive data (HIPAA, FERPA, ITAR, CUI)
| Advanced Researcher | Exception Researcher | Instrument-dependent Lab Researcher |
|---|---|---|
|
For users who frequently compile or modify code, ThreatLocker applies path-based rules rather than blocking every new file hash. This allows execution within designated folders for known workflows, while still supporting self-elevation where needed. For most Advanced Researchers the configuration will be on a single computer. ✓ Self-elevation and self-approval ✓ Security controls (Ringfencing) remain active ThreatLocker in Secure Mode For Advanced Researchers with more complex developer needs, a second computer or VM will be hosted in the Research VLAN in Monitor / Self-elevate mode. ThreatLocker in Monitor Mode |
A small number of faculty will be configured as Exception Users — these have the highest level of flexibility and will be onboarded first to help refine the rollout. IT will reach out to you directly if you are in this group. You will be walked through the configuration in a dedicated Teams session. |
Certain Advanced / Exception Researchers will have dedicated physical workstations controlling scientific equipment where ThreatLocker and Remote Access are known to interfere with instrument software. These systems will either be: ✓ Off the internet and therefore cybersecurity without ThreatLocker No ThreatLocker ✓ Outside of the Kean network and not managed by IT No ThreatLocker ✓ Within the VLAN portion of the Kean network with a ThreatLocker configuration compatible with instrument software requirements ThreatLocker in Monitor Mode Remote Access will be configured according to the requirements of the instrument software. |
Physical Research Computers:
Where your workflow requires a dedicated physical research machine — including the ability to modify hardware, reinstall an OS, or work in environments incompatible with remote desktop access — that remains a fully supported option. The goal of this framework is not to eliminate research computers but to provide flexible paths depending on your needs. Speak with Joe Pallante to discuss the right configuration for your environment.
HPC & National Computing Resources
If your research workload exceeds what a VM or local workstation can support, Kean IT can help you connect to broader computing resources.
- Local HPC: If you have or are acquiring local HPC hardware, IT will work with you to integrate it into a secure, research-compatible network configuration.
- National resources: Kean faculty are eligible to apply for allocations through ACCESS (formerly XSEDE) and the National AI Research Resource (NAIRR). IT can assist with account setup, data transfer workflows, and connectivity. Contact Joe Pallante to discuss your needs.
AI/ML Researchers — Advanced Network Configurations
Researchers running agentic AI workloads, autonomous systems, or large-scale distributed training may require more container or customizable network environments beyond the standard Research VLAN. Custom subnet configurations are available by request for projects with specific network isolation requirements. Contact Joe Pallante to discuss your workload and we will identify the right network architecture for your research.
Step 2 — Your Onboarding Appointment
Onboarding appointments are available upon request, ensuring your environment is fully operational before you leave.
| First 15 min | Needs Assessment — we ask about your software, hardware, data type, OS, GPU needs, and storage requirements. |
| Middle 45–60 min | Provisioning — your VM or environment is stood up, software installed, and BeyondTrust access tested end-to-end. |
| Final 15 min | Handoff — two-account walkthrough, data storage overview, ThreatLocker self-elevation demo, and Q&A. |
Schedule Your Appointment: Appointments are booked via Microsoft Bookings. Contact Joe Pallante ([email protected]) or reach IT at (908) 737-6000.
Common Questions
| Do I need a second laptop? | No. You use one laptop with two accounts — one for your regular Kean work, one connecting to your research VM or environment. Both from the same device. |
| Where does my research data live? | On Kean's own on-premises datacenter — not a public cloud. It is backed up automatically and retained for your grant period. |
| ThreatLocker is blocking my tools. What do I do? | Schedule a consultation with IT. We will identify and whitelist your applications during that session. Contact Joe Pallante or book via Microsoft Bookings. |
| I need a GPU for AI/ML work. Can Kean IT help? | Yes — two options: datacenter GPU nodes accessed the same way as a VM, or a dedicated physical workstation budgeted into your grant. IT will help you spec and justify the hardware. |
| What if my research needs don't fit this framework? | Contact Joe Pallante directly. No researcher will be left without a path forward — we work with you individually to find the right configuration. |
| Where are the VMs stored? | All research VMs are hosted in Kean's on-premises datacenter — not a public cloud. Your data stays on Kean infrastructure. |
| Will there be latency issues when using a VM? | On-campus access is low-latency. Off-campus access is available via BeyondTrust or VPN, providing a stable, secure connection to the datacenter. For graphics-intensive or time-sensitive work, a dedicated physical workstation may be a better fit. |
| Is this a terminal or a full remote desktop? | It depends on your user type. Most faculty access their VM via RDP — a full remote desktop experience. Researchers who prefer a command-line environment (SSH/terminal) can be accommodated as well. Your IT engineer will configure the right access method during onboarding. |
| How much will a VM cost? | Base research VM access is provided at no direct cost to faculty or departments. For high-performance or GPU-enabled environments, hardware costs can be scoped into grant budgets. IT will help identify the right option during your onboarding appointment. |
| Can I use ACCESS or NAIRR for my research? | Yes. Kean faculty are eligible to apply for allocations through ACCESS and NAIRR. IT can assist with account setup and connectivity. Contact Joe Pallante to get started. |
| I have local HPC hardware. Can IT support it? | Yes. If you have existing or planned local HPC hardware, IT will work with you to integrate it into a secure, research-compatible network configuration. Contact Joe Pallante to discuss your setup. |
This guide will be updated as the research computing framework evolves. For questions or feedback, contact Joe Pallante at [email protected] or via Microsoft Bookings for consultation. | Kean University Information Technology | April 2026