The Application Management and Provisioning (AMP) self-service migration tool is now available to transition your services and apps to Okta (campus network or VPN required to access AMP). Additional information is available on the IAM service website.
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z
A
Assertion
See attribute assertion.
Assertion Consumer Service (ACS)
The service that uses assertions to initiate a session with a Service Provider. The ACS is an endpoint (URL) stored in the metadata of the Service Provider to which the assertions are sent. The Identity Provider uses the metadata to send the assertions to the proper URL.
Attribute
A single piece of information associated with an electronic identity database record, such as an MCommunity Directory profile. Some attributes are general; others are personal. Some subset of all attributes defines a unique individual. See U-M InCommon Attribute Release Policy and Procedure for more details about attributes at U-M.
Attribute Release Policy (ARP)
A defined set of attributes to be released by an Identity Provider to a Service Provider, functioning as an attribute filter for privacy and data protection. The attribute release policy can differ for each Service Provider. See U-M InCommon Attribute Release Policy and Procedure for more details about the attribute release policy at U-M.
Authentication
The process by which a person verifies or confirms their affiliation with an electronic identifier. Logging in successfully to a service using a uniqname (or Friend Account) and password is a form of authentication.
Authorization
The process by which a person is granted access to a service. A Single Sign-On (SSO) Service Provider could use various attributes to determine the access rights of a person.
E
Endpoint
A URL on an Identity or Service Provider that performs a specific function within the SAML authentication protocol. The two most commonly used endpoints are the Identity Provider's Single Sign-on Service and the Service Provider's Assertion Consumer Service.
Entitlement
The object in a set of attributes that can be granted or associated to a user account to enable that account to perform (or in some cases prevent the performance of) some set of actions in the service. Entitlements could be used to allow managers to have certain capabilities within a web application, but prevent their employees from having those same capabilities.
Entity ID
An entity ID is a globally unique name given to a SAML entity, either an Identity Provider (IdP) or a Service Provider (SP). An entity ID may or may not actually resolve to a web resource. (If it does, it is usually a page that describes the deployment.) An entity ID is a persistent identifier for the entity. Make every effort to choose a permanent name for your deployment that will persist indefinitely.
EPPN (eduPersonPrincipalName)
This identifier takes the form principal@domain and is the most common form of identity in higher ed. While it may resemble an email address, it is not one.
F
Friend Account
A Friend account is basically a U-M guest computing account. It allows someone who does not have a U-M uniqname and UMICH password to authenticate to the U-M computing environment. Providers of U-M computing services can then authorize Friend account holders to use certain services as appropriate. Friend accounts are used, for example, by parents and guardians to log in so they can pay student tuition.
I
Identity Provider (IdP)
The originating location for a user, which also provides identity attributes about a person. U-M is an example of an Identity Provider.
O
OpenID Connect (OIDC)
OpenID is an open standard and decentralized authentication protocol promoted by the non-profit OpenID Foundation. The OpenID standard provides a framework for the communication that must take place between the identity provider and the OpenID acceptor (the "relying party"). An extension to the standard (the OpenID Attribute Exchange) facilitates the transfer of user attributes from the OpenID identity provider to the relying party.
P
Persistent Identifier (eduPersonTargetedID)
This special identifier type serves as a permanent anonymized identifier for an identity. While they vary for each Service Provider to allow privacy to be maintained across systems, they are managed to allow for consistency of preferences and to control liability.
R
Relying Party
The provider (Service Provider or Identity Provider) that is receiving and using information from another provider. For example, when a Service Provider receives attribute assertions from the Identity Provider, the Service Provider would be the relying party.
S
SAML (Security Assertion Markup Language)
A technical standard issued by the OASIS organization defining a means of communicating authentication-related information between administratively disparate systems.
Service Provider (SP)
A resource hosted on a web server that uses Single Sign-On (SSO) to implement single sign-on. The resource redirects unauthenticated users to an Identity Provider and uses the attributes released by the IdP to determine whether or not to provide the features of the service to a user. U-M Google and U-M Dropbox are examples of service providers at U-M.
Shibboleth
Note: The U-M Shibboleth service is in containment as of Feb 2026.
An application that enables the sharing of web resources that are subject to access controls such as user IDs and passwords. Shibboleth uses institutional sign-on and directory systems to locally authenticate users with an Identity Provider and pass information about them to the Service Provider to enable that site to make an informed authorization decision.
Single Sign-On
A session or user authentication process that allows a user to use one username and password to access multiple applications without being prompted to log in separately at each one.
Okta at U-M supports both SAML and OIDC for Single Sign-On.
SSL (Secure Sockets Layer)
An encrypted transport protocol that uses a certificate and cryptographic keys to ensure secure transmission of data across networks. A URL beginning with https:// utilizes SSL encryption.
Support Contact
The support contact is the primary contact for the Service Provider. The support contact may be a help desk or a designated support person.
U
UMID
An eight-digit identification number given to most members of the U-M community. See About UMIDs.
Uniqname
A U-M login ID or username that is part of U-M email addresses. Uniqnames are made up of three to eight alphabetic characters (for example, bjensen).
X
XML (Extensible Markup Language)
A standards-based, electronic data format for transferring or organising information. Often used to transfer data between online services. The metadata and configuration files for Single Sign-On (SSO) are stored in xml.
