Join our Newsletter — 33% off our NHI Course
Home› Guides› Education Identity Security Guide
Guide Governance, Risk & Compliance

Education Identity Security Guide

← All guides
By Lalit Choda, NHI Mgmt Group Updated 27 September 2026 5 min read
On this page

Schools, colleges and universities manage some of the most complex identity populations anywhere. Tens of thousands of students join and leave every year, staff hold multiple roles, researchers collaborate across institutions through federations, alumni keep accounts for years, and teaching depends on a sprawling ecosystem of EdTech and SaaS tools connected to student data. Budgets and security teams are usually small, and attackers know it: education is regularly among the most targeted sectors for ransomware and data theft. This guide covers the identity controls that matter most in education and the regulations that apply. It is a practitioner summary, not legal advice.

Key takeaways

  • Automate the student and staff lifecycle: high churn makes manual provisioning and deprovisioning unworkable.
  • MFA for staff first, especially administrators and finance, then students, with inclusive methods.
  • EdTech and SaaS integrations hold large volumes of student data through OAuth grants and API keys. Govern them.
  • Federated research access needs clear assurance and incident response agreements.
  • Protect support and help desk processes against social engineering, particularly during peak enrolment periods.

Regulations and frameworks at a glance

Regulation / frameworkApplies toIdentity-relevant themes
FERPA (US)Educational institutions receiving US federal fundingProtecting student education records; controlling who can access them
COPPA (US)Online services collecting data from children under 13Parental consent and data minimisation for young students' services
GDPR and UK GDPRProcessing of student and staff personal dataSecurity, access limitation, children's data protections
UK Department for Education cyber security standardsSchools and colleges in EnglandIncludes MFA, account management and access control expectations
REFEDS and federation policiesInstitutions in research and education federationsAssurance profiles, MFA signalling, security incident response (Sirtfi)
PCI DSS and research security rulesPayment processing and funded research as applicableAccess control and MFA for in-scope systems

Lifecycle at scale

  • Drive student accounts from the student information system and staff accounts from HR, with clear rules for people who are both. See the Identity Data Quality Guide.
  • Automate provisioning into the learning platform, email and SaaS tools with SCIM or connectors. See the SCIM Provisioning Guide.
  • Define what happens at graduation, withdrawal and staff departure: which access ends immediately, which moves to an alumni state, and when accounts are deleted. See the Joiner-Mover-Leaver Guide.
  • Review guest, visiting researcher and contractor accounts, which accumulate quickly. See the Third-Party Access Guide.

Authentication

  • Require MFA for all staff, with phishing-resistant methods for IT administrators, finance and those with access to large volumes of student data. See the MFA Guide.
  • Roll out MFA to students with methods that work for people without a smartphone, and plan recovery for large populations. See the Account Recovery and Help Desk Security Guide.
  • Screen for breached passwords, as student credentials are widely reused and traded. See the Password Security Guide.
  • For young children, use age-appropriate methods such as picture passwords or QR badges on managed devices, controlled by staff.

Federated and research access

  • Research and education federations (such as national federations joined through eduGAIN) let staff and students use their home institution's identity at other institutions and services.
  • Release only the attributes each service needs, and use REFEDS profiles to signal assurance and MFA.
  • Commit to federation security incident response (Sirtfi) so compromised accounts can be dealt with across institutions.
  • Services such as eduroam provide federated network access; protect the credentials they use.

EdTech, SaaS and integrations

  • Inventory the applications connected to student data, and the OAuth grants, API keys and LTI integrations they use. See the SaaS and OAuth App Governance Guide.
  • Limit what staff and students can authorise, and review high-privilege apps.
  • Protect privileged support access into learning platforms. The Canvas Instructure breach showed how a hijacked support session can yield a token that pulls school data through APIs.
  • Include identity and data protection requirements in EdTech contracts.

Staff with limited security resources

  • Use the security features already included in education licences for identity platforms before buying new tools.
  • Share services and expertise through consortia, federations and regional networks.
  • Prioritise: MFA for staff, automated deprovisioning, admin account protection and help desk verification deliver most of the risk reduction.

AI in education

AI tutors, marking assistants and agents connected to learning platforms and student records need scoped access and oversight, and extra care where children's data is involved. See the Enterprise AI Copilot Security Guide and the Identity Data Privacy and Consent Guide.

Practitioner checklist

  • Drive accounts from the student information system and HR, and automate provisioning and deprovisioning.
  • Define graduation, withdrawal, alumni and staff departure rules.
  • Enforce MFA for staff, phishing-resistant for administrators, then extend to students.
  • Screen for breached passwords and harden help desk recovery.
  • Govern EdTech and SaaS integrations and the tokens they hold.
  • Join federation security frameworks and release minimal attributes.
  • Review guest and visiting researcher accounts regularly.

Standards and references

This guide summarises identity themes for security practitioners and is not legal advice. Related NHI Mgmt Group resources: Joiner-Mover-Leaver Guide · SCIM Provisioning Guide · SaaS and OAuth App Governance Guide · MFA Guide

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 27 September 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org