Card Image

Honey, I shrunk our identity attack surface

Jul 21 2026, 11:05 - 11:35 (AEST)

Location image
Lyon 2

Deprovisioning Alumni student accounts appeared straightforward on the surface; however, beneath this simplicity lay a complex web of business processes and a lengthy pathway to safely “flick the switch.” The university’s cyber security posture recognised and supported the critical nature of this change in practice, enabling a shift from lifetime email accounts to email access limited to a student’s period of enrolment. Equally important, students’ digital footprints have fundamentally changed since these services were first introduced. What was once a high value offering is now commonplace, with email services readily and freely accessible beyond the university environment.

The journey began in 2022 with approval to move away from lifetime student email accounts. In 2023, a formal project was established, supported by multiple roadmaps and project plans that evolved as we progressively unpeeled the onion. Through this process, we uncovered deep connections and dependencies between student email accounts and core institutional processes, dependencies that were not fully understood until detailed analysis was undertaken. Overcoming this internal understanding was only the first hurdle. Equally critical was the need to understand and empathise with external users, those who relied on these accounts, and those who did not. This human centred insight proved to be a decisive factor, with the potential to make or break the success of the project. Join us to learn how we made it a success for the University and our students.