Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
100 criteria
baselineWhich identity domains does the platform cover natively — workforce SSO/MFA, customer IAM (CIAM), privileged access (PAM), identity governance (IGA), and machine/non-human identity — and which require separate products?
baselineWhat authentication methods are supported (passwordless, passkeys/FIDO2, adaptive/risk-based MFA, biometrics), and how is phishing-resistant authentication enforced?
baselineDescribe automated joiner-mover-leaver lifecycle and provisioning/deprovisioning across applications: how many connectors, and which standards (SCIM, SAML, OIDC) are supported?
baselineWhat identity governance capabilities are included (access certifications, separation-of-duties policy, access requests, risk analytics), and are they native or add-on?
baselineHow does the platform secure privileged access — credential vaulting, session management/recording, just-in-time access, and secrets — and across which target systems?
baselineDoes the platform detect identity threats and excessive entitlements (ITDR, CIEM, identity security posture), and is that detection native or delivered via integration?
baselineDetail deployment options (SaaS / self-hosted), standards support (SAML/OIDC/SCIM/FIDO2), directory integrations, and API extensibility, with reference architectures.
baselineProvide availability SLAs, scale figures, and migration tooling/effort from an incumbent identity provider, citing customer-validated references.
baselineHow does the platform discover and govern machine/non-human identities (service accounts, API keys, workload identities) separately from human users, and what proportion of a typical customer's identity estate turns out to be non-human?
baselineDescribe session security beyond initial authentication — continuous/risk-based re-authentication, session hijacking detection, and automatic session revocation on anomalous behavior — and quantify detection latency with a customer reference.
baselineWhat is the incident response process and SLA if the identity platform itself has an outage or is compromised, given that an IdP failure can lock out an entire workforce — is there a documented break-glass procedure?
baselineDetail support for B2B/partner identity federation — external partner access without provisioning full accounts, cross-organization SSO, and how partner access is time-bounded or automatically expired.
baselineWhat is the actual migration path and typical timeline from a legacy on-prem directory (e.g., Active Directory) to this platform, including hybrid coexistence support during the transition, with a customer-validated timeline.
baselineHow does the platform detect and respond to credential-stuffing or password-spray attacks in real time, and what automated response (rate-limiting, step-up auth, account lock) triggers without requiring manual SOC intervention?
baselineExplain the pricing model across identity domains (SSO/MFA, PAM, IGA, CIAM) — are these bundled or does each require a separate SKU/contract, and what does a typical mid-market customer actually pay per user per month all-in?
baselineWhat developer/API experience is offered for building custom authentication flows outside the standard SSO login (e.g., embedding auth in a customer-facing app), and how mature is the SDK/API documentation and support?
baselineDescribe any standard discounting that you provide, such as GSA or educational discounts.
baselineProvide a copy of your standard contract, together with your typical SLA for availability or quality of customer service, or product capabilities.
baselineProvide a list of at least five (5) references where the Offeror has provided the services described in the RFP, preferably higher-education institutions of similar size, scope and complexity to the university.
baselineProvide a brief description of your product or service (Data Security Vendor Questionnaire).
baselineDescribe your on-line help.
baselineWhat is the procedure for handling customer requests for application modifications?
baselineHow often is the application modified and how do you notify your customers of an upcoming modification?
baselineDoes your application allow the customer to export application data into a standard format such as Excel?
baselineHave strong experience and expertise with cloud-based IAM.
baselineDo you work with regional partners/value-added resellers that can provide implementation support for your solution? If so, please provide your list.
baselineMaintain role-based access control for certain systems to ensure that users only have access to the data and resources necessary for their roles.
baselineSupport hybrid identity federation with Azure AD and Active Directory.
baselineImplement granular Role-Based Access Control (RBAC) for administrators, analysts, and auditors.
baselineOperate under least-privilege principles and use role-based access controls (RBAC) within the agency's tenant, with all access auditable and subject to agency approval.
baselineRequire Contract Staff to use Multifactor Authentication and maintain strict control of access credentials, immediately removing access for persons no longer authorized.
baselineMust support role-based access control (RBAC) to restrict SIEM access by role.
baselineBidder shall ensure that only its authorized employees/representatives access the financial institution's Data, Logs and configurations, and shall be responsible for protecting its network and subnetworks from which remote access is performed against unauthorized access, malware and other threats.
baselineSolution should provide a UBA dashboard highlighting risky users based on objective composite risk scoring, with organization-defined risk thresholds; solution should collect user data from Directory Services, IAM, VPN, Proxy, O365, and incorporate baseline behavioural models covering data exfiltration, malicious users, illicit behaviour, and compromised credentials.
baselineProposer must define connectivity/access method for MSSP SOC access to the Sentinel environment adhering to least privilege (Azure Lighthouse delegation generally preferred, dedicated VPN also acceptable), with access following agency-approved least-privilege principles.
baselineZero Trust Phase 1: Contractor shall complete rollout/operationalization of the Microsoft 365 security suite including Microsoft Intune (device health/UEM), Defender for Endpoint (EDR/XDR), Microsoft Purview (DLP and sensitive data risk assessments), Mobile Access (ZTNA + Intune MAM), and Privileged Access Management (PAM) implementation using platforms including CyberArk, Microsoft Entra PIM, or Okta.
baselineSupport access to both internal and select external users (external contractors with restricted/limited access), supporting a user population of approximately 200 once fully scaled.
baselineEnable unique role-based permissions controlling access/authorization to both content and tool functionality.
baselineIntegrate with the organization's OKTA Identity and Access Management/MFA software for user authentication and provisioning, and provide MFA capabilities.
baselineSupport Single Sign On (SSO) capability through OKTA by using SAML based authentication, and provide create, update, and deactivate capabilities.
baselineThe vendor shall work with the organization's Identity Access Manager (and identity management engineers) for configuration of OKTA and MFA with the GRC environment, and ensure that GRC functions properly over user VPN.
baselineContractor shall ensure the ISSM approves user access privileges and that user access is validated periodically (at least quarterly) in coordination with the IAM team, ensure separation of duties is enforced through technical mechanisms, and ensure unused or inactive accounts are reviewed and deactivated monthly.
baselineDemonstrate strong familiarity with IAM challenges specific to higher education institutions and the current and future technologies that may be appropriate for the demands identified.
baselineBe familiar with compliance regulations that pertain to data collection, data storage, data governance, and data accessibility regarding students, employees, and non-affiliated users in the university's systems.
baselineHave expertise with pertinent technologies in scope for Access Management, such as Oracle, Banner, Microsoft Active Directory, Microsoft Office 365, Microsoft Exchange, Microsoft Teams, Duo Security, Salesforce and ServiceNow.
baselineHave a minimum of three years' experience as a strategic partner or Managed Service Provider for IAM implementations with large institutions and systems of Higher Education.
baselineProvide a resilient, high availability SSO system with little to no on-premise dependencies, with SSO IDP full participation in InCommon/EduGain federations.
baselineDevelop understanding of the university's current IAM data flows and procedures; develop a migration plan for existing users, connectors and SSO relying parties; migrate existing users and connectors from the existing system with no substantial downtime.
baselineProvide training for system administration, operation and any maintenance that the university may be required to perform.
baselineProvide Access Management: SSO (SAML/CAS/Oauth), MFA integration with DUO Security, modern self-service password reset, access auditing and attestation/recertification, and federated identity including native support for InCommon federation.
baselineProvide Identity Governance and Administration: complete identity lifecycle management, account/service provisioning and deprovisioning occurring in real-time or near real-time, new account claiming, self-service access requests, automated/self-service group management, ability to handle large changes in identity population efficiently, ability to accommodate multiple concurrent user roles/affiliations, and role-based provisioning/entitlement.
baselineHosted or IAAS solutions shall deliver an SLA of 99.99% uptime.
baselineProvide free on-demand and customizable training, and 24/7 customer support to the university's IT staff; detail available tiers of support and associated SLAs/costs.
baselineDescribe the overall architecture of your solution and its ability to support and integrate with our current environment.
baselineDemonstrate the operation of your solution. Describe how your product/service scales. What is the largest implementation for your product/service? Does your product/service automatically maintain performance with increased workload?
baselineIn general, what do you consider to be your top three differentiators from competitors?
baselineDescribe the end user/administrator training courses or options you offer, addressing location/method of delivery (live on-site, live online, on-demand online) and mentoring of individual end users by role.
baselineProvide a list of any security certifications you offer or support that is related to your product, and list any third parties authorized to administer the certification.
baselineDescribe your maintenance/update offerings: what services are included, your normal revision cycle for standard releases/updates, the normal distribution path for standard vs. emergency releases/hot fixes, and documentation provided with standard releases.
baselineDescribe your support offerings: services included, whether a knowledge base is accessible to end users and system administrators, levels of standard service in terms of category of users supported/response time/hours of availability, on-site support availability, and consulting services on process changes needed to adopt your tools.
baselineDo you provide any supplemental services in addition to your primary product offering, such as availability of a community platform for interaction with your client base?
baselineProvide overall statement of revenue with breakdown of percent attributable to IAM product(s) vs. percent attributable to IAM services.
baselineProvide the total number of years in business, with specific detail on the number of years providing IAM product(s) and the number of years providing IAM services.
baselineDescribe your IAM customer base: number of customers, number of user licenses, and industries served (products); number of customers, number of websites tested via the service, and websites tested per client (services).
baselineIndicate your industry involvement, including membership(s) in industry organizations, participation in standards bodies and participation in the threat intelligence community, and provide a list of your solution partners.
baselineDo you provide a community exchange for your customers? If so, describe your community platform, detailing how customers can interact, with whom, and what content/training materials are available.
baselineWhat is your perception of market direction, and how does this affect your technology road map? Describe your anticipation of industry/customer trends and your approach to ensure your solution can adapt and improve while continuing to provide value to an existing customer base.
baselineProvide a catalog of all items, including hardware, software and support services included in your solution, with a description of each item, whether it is optional, and its associated list price.
baselineDescribe your pricing/licensing model for enterprise solutions, including any discount tiers and limitations to your enterprise pricing; describe how each product is licensed (per user, per application, per authentication, etc.).
baselineFor SaaS solutions, describe how you price the service — by size of application, contract period, or pricing tiers for lightweight fully automated tests versus more complex testing requiring manual intervention. Do you provide penetration testing (which includes testing outside of the application under test)?
baselineWhat is your application/service available uptime? What is your scheduled maintenance window?
baselineHow do you scale your system during peak usage?
baselineWhat kind of authentication and access control procedures are in place?
baselineHow do you secure user IDs and access credentials?
baselineDo you support SSO and if so, which standards?
baselineDo you have a Voluntary Product Accessibility Template (VPAT) completed? If so, please upload a copy with this questionnaire.
baselineWhat has your company done to evaluate the accessibility of your product in accordance with either Section 508 of the Rehabilitation Act or WCAG 2.0 accessibility guidelines?
baselineDo you know of any problems or have you received any complaints regarding the accessibility of your product? Please explain.
baselineHas your product been evaluated using screen reading or voice recognition technology?
baselineCan your product be navigated by using the keyboard only?
baselineIf accessibility for users with disabilities has not been implemented, when is your company planning to incorporate accessibility into the product, and to what extent are you willing to work with the university to improve your product's accessibility?
baselineHow many years has your firm been continuously active in delivery of IAM solutions?
baselineHow many Higher Education IAM solutions has your firm delivered? Do you have experience with Higher Education institutions in Canada?
baselineWill you use 3rd party (external to your firm) resources for development/delivery of your proposed solution?
baselineHow large is your IAM practice in terms of revenue and FTE? What % of your overall firm's revenue does this represent?
baselineFor the proposed Project Manager and Technical Lead: total years of experience in the proposed role and in the IAM discipline, how long the individual has been employed at your organization, and how many similar projects the individual has performed.
baselineThe Offeror must provide their proposed license, maintenance and service agreements that may become part of the contract.
baselineIdentity and Entitlement Repositories: Design and establish data repositories for identity and entitlements, drawing from each source system to establish a centralized identity repository for the university.
baselineAccount Administration: Implement account administration services that allow the management of identities, roles, and access within the IAM systems.
baselineIAM Workflow Management: Implement workflow management that allows the definition and automation of business rules for the approval of requests along with provisioning, change, and deprovisioning of identities, accounts, and access.
baselineCoarse-Grained Access Management: Provide the ability to manage provisioning, change, and deprovisioning of access to downstream systems by managing accounts and basic privileges in the systems.
baselineAccess Reviews and Certification (Basic): Provide the ability to generate regularly recurring and on-demand reports to review and certify access, ensuring that only authorized access has been provided.
baselineRegistration Services: Provide the ability to register and proof new identities within the IAM system.
baselineSelf-Service: Provide the ability for end users to manage their own identities and access, including claiming accounts, resetting passwords, managing challenge/response questions, requesting new services, and updating select identity attributes.
baselineTransition Services and Decommission Legacy System: Transition from the current IAM system (Oracle Waveset) to the new IAM system, ensuring continuity of services, and decommission the existing IAM system.
baselineFederation: Provide internal enterprise single sign-on capabilities, including federated sign-on with third-party systems, and external federation bestowing access to identified users via InCommon, Canadian Access Federation (Canarie), eduGAIN, or another university/government body.
baselinePhase 2 roadmap: solution should support Role Mining, Fine-Grained Access Control, SIEM/DLP integration, integration with the Cherwell service management tool, Multi-Factor Authentication, advanced Access Review and Certification, and Privileged User Management.
baselineThe Offeror must identify at least one (1) past or current end user currently using a similar solution/system, willing to conduct a live Client Illustration of installed and operational system functionality (approximately one hour).
baselineProvide additional information on the configuration/capacity requirements for any major hardware components.
baselineCentralized identity repository supports multiple concurrent identity-related roles and affiliations and stores both current and historical data.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhich identity domains does the platform cover natively — workforce SSO/MFA, customer IAM (CIAM), privileged access (PAM), identity governance (IGA), and machine/non-human identity — and which require separate products?Answer key — what a strong answer shows
Strong answers map each domain to native vs a separate SKU and clarify whether it is one platform or a suite of acquired products sharing a brand. Probe where breadth comes at the cost of depth.
RFIWhat authentication methods are supported (passwordless, passkeys/FIDO2, adaptive/risk-based MFA, biometrics), and how is phishing-resistant authentication enforced?Answer key — what a strong answer shows
Look for passkeys/FIDO2 and adaptive MFA with explicit phishing-resistance, plus policy controls. Distinguish supported-but-optional from enforced-by-policy.
RFPDescribe automated joiner-mover-leaver lifecycle and provisioning/deprovisioning across applications: how many connectors, and which standards (SCIM, SAML, OIDC) are supported?Answer key — what a strong answer shows
Evidence-backed answers quantify connector coverage, state SCIM/SAML/OIDC support, and show real deprovisioning (not just create). Probe handling of apps without standard connectors.
Sources:
How vendors compare
balanced · vendor-sourced
Neutral strengths and gaps for each vendor in this category, drawn from vendors' own public materials — included so the questions above favor no single vendor. Gaps reflect capabilities not emphasized in public materials, not rankings.
Vendor
Strengths
Gaps / watch-outs
CyberArkAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Privileged access depth (vaulting, session management, secrets, machine identity) expanding into workforce and broader identity security.
PAM-anchored; customer identity (CIAM) is emphasized less than privileged and workforce access.
JumpCloudAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
RFIWhat identity governance capabilities are included (access certifications, separation-of-duties policy, access requests, risk analytics), and are they native or add-on?Answer key — what a strong answer shows
Strong answers detail certification campaigns, SoD/policy enforcement, self-service requests, and risk analytics, and state clearly which are native vs licensed add-ons.
RFIHow does the platform secure privileged access — credential vaulting, session management/recording, just-in-time access, and secrets — and across which target systems?Answer key — what a strong answer shows
Look for vaulting, session isolation/recording, JIT elevation, and secrets management, with explicit target coverage (servers, cloud, DBs, SaaS). Note what is agent-based vs agentless.
RFIDoes the platform detect identity threats and excessive entitlements (ITDR, CIEM, identity security posture), and is that detection native or delivered via integration?Answer key — what a strong answer shows
Strong answers clarify whether ITDR/CIEM/ISPM are native modules or integrations, what signals they use, and how findings drive remediation.
RFPDetail deployment options (SaaS / self-hosted), standards support (SAML/OIDC/SCIM/FIDO2), directory integrations, and API extensibility, with reference architectures.Answer key — what a strong answer shows
Prefer answers with concrete deployment models, a standards matrix, directory integrations (AD/LDAP/cloud), and documented APIs/SDKs — not just 'standards-based' claims.
RFPProvide availability SLAs, scale figures, and migration tooling/effort from an incumbent identity provider, citing customer-validated references.Answer key — what a strong answer shows
Prefer published SLAs, real scale numbers, and concrete migration tooling with customer references over marketing claims. Probe coexistence during phased migration.
RFIHow does the platform discover and govern machine/non-human identities (service accounts, API keys, workload identities) separately from human users, and what proportion of a typical customer's identity estate turns out to be non-human?Answer key — what a strong answer shows
Strong answers show dedicated non-human identity discovery/governance and cite a real proportion figure from customer data — machine identities are frequently the larger, under-governed population.
RFPDescribe session security beyond initial authentication — continuous/risk-based re-authentication, session hijacking detection, and automatic session revocation on anomalous behavior — and quantify detection latency with a customer reference.Answer key — what a strong answer shows
Look for continuous post-login risk evaluation (not just MFA at sign-in) and a real detection-latency figure, not a marketing claim of 'real-time.'
RFIWhat is the incident response process and SLA if the identity platform itself has an outage or is compromised, given that an IdP failure can lock out an entire workforce — is there a documented break-glass procedure?Answer key — what a strong answer shows
A vendor without a clear, tested break-glass/emergency-access procedure is a serious operational risk, since IdP downtime is total-lockout-severity, not a minor outage.
RFPDetail support for B2B/partner identity federation — external partner access without provisioning full accounts, cross-organization SSO, and how partner access is time-bounded or automatically expired.Answer key — what a strong answer shows
Strong answers describe genuine federation (not just guest accounts in the primary directory) with automatic expiry, reducing stale partner-access risk.
RFIWhat is the actual migration path and typical timeline from a legacy on-prem directory (e.g., Active Directory) to this platform, including hybrid coexistence support during the transition, with a customer-validated timeline.Answer key — what a strong answer shows
Look for a concrete hybrid-coexistence period and a real customer migration timeline; vendors who describe migration only in the abstract likely underestimate real-world complexity.
RFIHow does the platform detect and respond to credential-stuffing or password-spray attacks in real time, and what automated response (rate-limiting, step-up auth, account lock) triggers without requiring manual SOC intervention?Answer key — what a strong answer shows
Strong answers describe automatic, real-time mitigation; a platform requiring a human analyst to notice and respond to a credential-stuffing wave is materially slower than the attack.
RFPExplain the pricing model across identity domains (SSO/MFA, PAM, IGA, CIAM) — are these bundled or does each require a separate SKU/contract, and what does a typical mid-market customer actually pay per user per month all-in?Answer key — what a strong answer shows
Look for real all-in per-user economics; a vendor that can only quote the cheapest module's price while other domains are separate expensive add-ons is misleading on total cost.
RFIWhat developer/API experience is offered for building custom authentication flows outside the standard SSO login (e.g., embedding auth in a customer-facing app), and how mature is the SDK/API documentation and support?Answer key — what a strong answer shows
Strong answers point to real SDKs, current documentation, and a support channel for developers, not just admin-console configuration with no programmatic access.
RFPDescribe any standard discounting that you provide, such as GSA or educational discounts.
RFPProvide a copy of your standard contract, together with your typical SLA for availability or quality of customer service, or product capabilities.
RFPProvide a list of at least five (5) references where the Offeror has provided the services described in the RFP, preferably higher-education institutions of similar size, scope and complexity to the university.
RFPProvide a brief description of your product or service (Data Security Vendor Questionnaire).
RFPDescribe your on-line help.
RFPWhat is the procedure for handling customer requests for application modifications?
RFPHow often is the application modified and how do you notify your customers of an upcoming modification?
RFPDoes your application allow the customer to export application data into a standard format such as Excel?
RFPHave strong experience and expertise with cloud-based IAM.
RFPDo you work with regional partners/value-added resellers that can provide implementation support for your solution? If so, please provide your list.
RFPMaintain role-based access control for certain systems to ensure that users only have access to the data and resources necessary for their roles.
RFPSupport hybrid identity federation with Azure AD and Active Directory.
RFPImplement granular Role-Based Access Control (RBAC) for administrators, analysts, and auditors.
RFPOperate under least-privilege principles and use role-based access controls (RBAC) within the agency's tenant, with all access auditable and subject to agency approval.
RFPRequire Contract Staff to use Multifactor Authentication and maintain strict control of access credentials, immediately removing access for persons no longer authorized.
RFPMust support role-based access control (RBAC) to restrict SIEM access by role.
RFPBidder shall ensure that only its authorized employees/representatives access the financial institution's Data, Logs and configurations, and shall be responsible for protecting its network and subnetworks from which remote access is performed against unauthorized access, malware and other threats.
RFPSolution should provide a UBA dashboard highlighting risky users based on objective composite risk scoring, with organization-defined risk thresholds; solution should collect user data from Directory Services, IAM, VPN, Proxy, O365, and incorporate baseline behavioural models covering data exfiltration, malicious users, illicit behaviour, and compromised credentials.
RFPProposer must define connectivity/access method for MSSP SOC access to the Sentinel environment adhering to least privilege (Azure Lighthouse delegation generally preferred, dedicated VPN also acceptable), with access following agency-approved least-privilege principles.
RFPZero Trust Phase 1: Contractor shall complete rollout/operationalization of the Microsoft 365 security suite including Microsoft Intune (device health/UEM), Defender for Endpoint (EDR/XDR), Microsoft Purview (DLP and sensitive data risk assessments), Mobile Access (ZTNA + Intune MAM), and Privileged Access Management (PAM) implementation using platforms including CyberArk, Microsoft Entra PIM, or Okta.
RFPSupport access to both internal and select external users (external contractors with restricted/limited access), supporting a user population of approximately 200 once fully scaled.
RFPEnable unique role-based permissions controlling access/authorization to both content and tool functionality.
RFPIntegrate with the organization's OKTA Identity and Access Management/MFA software for user authentication and provisioning, and provide MFA capabilities.
RFPSupport Single Sign On (SSO) capability through OKTA by using SAML based authentication, and provide create, update, and deactivate capabilities.
RFPThe vendor shall work with the organization's Identity Access Manager (and identity management engineers) for configuration of OKTA and MFA with the GRC environment, and ensure that GRC functions properly over user VPN.
RFPContractor shall ensure the ISSM approves user access privileges and that user access is validated periodically (at least quarterly) in coordination with the IAM team, ensure separation of duties is enforced through technical mechanisms, and ensure unused or inactive accounts are reviewed and deactivated monthly.
RFPDemonstrate strong familiarity with IAM challenges specific to higher education institutions and the current and future technologies that may be appropriate for the demands identified.
RFPBe familiar with compliance regulations that pertain to data collection, data storage, data governance, and data accessibility regarding students, employees, and non-affiliated users in the university's systems.
RFPHave expertise with pertinent technologies in scope for Access Management, such as Oracle, Banner, Microsoft Active Directory, Microsoft Office 365, Microsoft Exchange, Microsoft Teams, Duo Security, Salesforce and ServiceNow.
RFPHave a minimum of three years' experience as a strategic partner or Managed Service Provider for IAM implementations with large institutions and systems of Higher Education.
RFPProvide a resilient, high availability SSO system with little to no on-premise dependencies, with SSO IDP full participation in InCommon/EduGain federations.
RFPDevelop understanding of the university's current IAM data flows and procedures; develop a migration plan for existing users, connectors and SSO relying parties; migrate existing users and connectors from the existing system with no substantial downtime.
RFPProvide training for system administration, operation and any maintenance that the university may be required to perform.
RFPProvide Access Management: SSO (SAML/CAS/Oauth), MFA integration with DUO Security, modern self-service password reset, access auditing and attestation/recertification, and federated identity including native support for InCommon federation.
RFPProvide Identity Governance and Administration: complete identity lifecycle management, account/service provisioning and deprovisioning occurring in real-time or near real-time, new account claiming, self-service access requests, automated/self-service group management, ability to handle large changes in identity population efficiently, ability to accommodate multiple concurrent user roles/affiliations, and role-based provisioning/entitlement.
RFPHosted or IAAS solutions shall deliver an SLA of 99.99% uptime.
RFPProvide free on-demand and customizable training, and 24/7 customer support to the university's IT staff; detail available tiers of support and associated SLAs/costs.
RFPDescribe the overall architecture of your solution and its ability to support and integrate with our current environment.
RFPDemonstrate the operation of your solution. Describe how your product/service scales. What is the largest implementation for your product/service? Does your product/service automatically maintain performance with increased workload?
RFPIn general, what do you consider to be your top three differentiators from competitors?
RFPDescribe the end user/administrator training courses or options you offer, addressing location/method of delivery (live on-site, live online, on-demand online) and mentoring of individual end users by role.
RFPProvide a list of any security certifications you offer or support that is related to your product, and list any third parties authorized to administer the certification.
RFPDescribe your maintenance/update offerings: what services are included, your normal revision cycle for standard releases/updates, the normal distribution path for standard vs. emergency releases/hot fixes, and documentation provided with standard releases.
RFPDescribe your support offerings: services included, whether a knowledge base is accessible to end users and system administrators, levels of standard service in terms of category of users supported/response time/hours of availability, on-site support availability, and consulting services on process changes needed to adopt your tools.
RFPDo you provide any supplemental services in addition to your primary product offering, such as availability of a community platform for interaction with your client base?
RFPProvide overall statement of revenue with breakdown of percent attributable to IAM product(s) vs. percent attributable to IAM services.
RFPProvide the total number of years in business, with specific detail on the number of years providing IAM product(s) and the number of years providing IAM services.
RFPDescribe your IAM customer base: number of customers, number of user licenses, and industries served (products); number of customers, number of websites tested via the service, and websites tested per client (services).
RFPIndicate your industry involvement, including membership(s) in industry organizations, participation in standards bodies and participation in the threat intelligence community, and provide a list of your solution partners.
RFPDo you provide a community exchange for your customers? If so, describe your community platform, detailing how customers can interact, with whom, and what content/training materials are available.
RFPWhat is your perception of market direction, and how does this affect your technology road map? Describe your anticipation of industry/customer trends and your approach to ensure your solution can adapt and improve while continuing to provide value to an existing customer base.
RFPProvide a catalog of all items, including hardware, software and support services included in your solution, with a description of each item, whether it is optional, and its associated list price.
RFPDescribe your pricing/licensing model for enterprise solutions, including any discount tiers and limitations to your enterprise pricing; describe how each product is licensed (per user, per application, per authentication, etc.).
RFPFor SaaS solutions, describe how you price the service — by size of application, contract period, or pricing tiers for lightweight fully automated tests versus more complex testing requiring manual intervention. Do you provide penetration testing (which includes testing outside of the application under test)?
RFPWhat is your application/service available uptime? What is your scheduled maintenance window?
RFPHow do you scale your system during peak usage?
RFPWhat kind of authentication and access control procedures are in place?
RFPHow do you secure user IDs and access credentials?
RFPDo you support SSO and if so, which standards?
RFPDo you have a Voluntary Product Accessibility Template (VPAT) completed? If so, please upload a copy with this questionnaire.
RFPWhat has your company done to evaluate the accessibility of your product in accordance with either Section 508 of the Rehabilitation Act or WCAG 2.0 accessibility guidelines?
RFPDo you know of any problems or have you received any complaints regarding the accessibility of your product? Please explain.
RFPHas your product been evaluated using screen reading or voice recognition technology?
RFPCan your product be navigated by using the keyboard only?
RFPIf accessibility for users with disabilities has not been implemented, when is your company planning to incorporate accessibility into the product, and to what extent are you willing to work with the university to improve your product's accessibility?
RFPHow many years has your firm been continuously active in delivery of IAM solutions?
RFPHow many Higher Education IAM solutions has your firm delivered? Do you have experience with Higher Education institutions in Canada?
RFPWill you use 3rd party (external to your firm) resources for development/delivery of your proposed solution?
RFPHow large is your IAM practice in terms of revenue and FTE? What % of your overall firm's revenue does this represent?
RFPFor the proposed Project Manager and Technical Lead: total years of experience in the proposed role and in the IAM discipline, how long the individual has been employed at your organization, and how many similar projects the individual has performed.
RFPThe Offeror must provide their proposed license, maintenance and service agreements that may become part of the contract.
RFPIdentity and Entitlement Repositories: Design and establish data repositories for identity and entitlements, drawing from each source system to establish a centralized identity repository for the university.
RFPAccount Administration: Implement account administration services that allow the management of identities, roles, and access within the IAM systems.
RFPIAM Workflow Management: Implement workflow management that allows the definition and automation of business rules for the approval of requests along with provisioning, change, and deprovisioning of identities, accounts, and access.
RFPCoarse-Grained Access Management: Provide the ability to manage provisioning, change, and deprovisioning of access to downstream systems by managing accounts and basic privileges in the systems.
RFPAccess Reviews and Certification (Basic): Provide the ability to generate regularly recurring and on-demand reports to review and certify access, ensuring that only authorized access has been provided.
RFPRegistration Services: Provide the ability to register and proof new identities within the IAM system.
RFPSelf-Service: Provide the ability for end users to manage their own identities and access, including claiming accounts, resetting passwords, managing challenge/response questions, requesting new services, and updating select identity attributes.
RFPTransition Services and Decommission Legacy System: Transition from the current IAM system (Oracle Waveset) to the new IAM system, ensuring continuity of services, and decommission the existing IAM system.
RFPFederation: Provide internal enterprise single sign-on capabilities, including federated sign-on with third-party systems, and external federation bestowing access to identified users via InCommon, Canadian Access Federation (Canarie), eduGAIN, or another university/government body.
RFPPhase 2 roadmap: solution should support Role Mining, Fine-Grained Access Control, SIEM/DLP integration, integration with the Cherwell service management tool, Multi-Factor Authentication, advanced Access Review and Certification, and Privileged User Management.
RFPThe Offeror must identify at least one (1) past or current end user currently using a similar solution/system, willing to conduct a live Client Illustration of installed and operational system functionality (approximately one hour).
RFPProvide additional information on the configuration/capacity requirements for any major hardware components.
RFPCentralized identity repository supports multiple concurrent identity-related roles and affiliations and stores both current and historical data.
RFPUnique identifier — the solution has the ability to assign a unique, unchangeable identifier to each identity maintained, and if a user leaves and later returns in a former or new role, the same original unique identifier is used.
RFPThe solution provides the ability for a requestor or approver to enter effective dates (start and end) for the requested access.
RFPThe solution allows a limited administrator role that enables delegated access request/oversight of request status, and delegated management of roles and entitlements, within a department or other constituency group.
RFPThe solution has the ability to connect and provision users to multiple target systems.
RFPThe solution has the ability to be fully installed and configured in a public cloud provider by the university (as opposed to a SaaS model), and/or to be installed, configured, and operated fully or in-part as a SaaS offering.
RFPProactive availability/incident monitoring is provided (if SaaS, through a publicly available service); the solution includes a mechanism for strong authentication/MFA for administrators.
RFPRespond to evaluation criteria categories: Pricing, Workflow and Access, Deployment and Administration, Identity and Entitlements, Fulfillment and Connectors, Dynamic Password Administration and Management, and Vendor Information and Higher Education Experience.
RFPVendor History — provide a brief history of vendor organization, including prior experience, a total of three (3) references, and recommendations as a vendor for higher education (comparable size/distribution of current higher-ed customers, length of support with existing customers, amount of business dedicated to higher education).
RFPCorporate Information — form of ownership and state of ownership, legal address, number of employees, etc.
RFPProposed Team — provide names of individuals who will be directly involved with the university and explain their experience, qualifications, and certifications.
RFPRelevant Experience — describe vendor history and experience in working with clients that are similar to the university.
RFPFor each requirement, indicate if it is a) base functionality, b) configurable, c) custom, d) on the future road map, e) an add-on feature, and/or f) not applicable to your solution/products, with a brief explanation of the deliverable functionality.
RFPAddress compliance with WCAG 2.1 AA and Section 508 of the Rehabilitation Act, for both user and administrator/staff functionality; provide your VPAT (Voluntary Product Accessibility Template) or WCAG 2.1 Conformance Statement.
RFPHas your product been verified for accessibility with assistive technologies for all functionality? If so, was verification through in-house testing or via third tester/vendor? List OS, assistive technologies and applications (browsers) tested, including version numbers.
RFPDiscuss where and how accessibility is included in your product development process.
RFPIf you are designing digital content such as email, Web-based or Social Media content, discuss your efforts to ensure accessibility.
RFPWill you accept payment via credit card? Do you offer an early payment discount, and if so what is your offer? Would the university receive the discount if paying by credit card?
RFPProvide three (3) customer references, from comparable institutions for similar products or services specified in this RFP, including company names, contact names, telephone numbers and emails.
RFPVendor will maintain role-based permissions for access to University Data (principle of minimization), restrictions on copying/removing data from an authorized network/system, strong password protocols, and multi-factor authentication for any remote access to Vendor's network or systems.
RFPIf Vendor is a Cloud Software provider: warrant Services fully available 99.9% of each month (except scheduled maintenance with 30 days' notice), provide 24/7/365 telephone and online support, conduct quarterly support reviews, and respond to Priority One Issues within one hour of University's call for assistance.
RFPStore 'directory' attributes about users (First Name, Last Name, Preferred Name(s), Email, College, Cell Phone, Job Title, Department, Office Location) and application-specific/custom attributes (RFID badge, physical building access, account identifiers in disparate systems).
RFPMaintain relationships between a unique person across the system's colleges and their identifiers/roles in integrated systems: Microsoft 365, Anthology Student, Anthology Reach, a state workforce-training platform, Lumens (ModernCampus), SAML-integrated web apps (BetterMynd, EZProxy, Statista, GivePulse), and Access Control Systems.
RFPManage the identity lifecycle: Joiners (create from HRIS/Paycom and SIS/Anthology Student, provision access based on lifecycle rules), Movers (role/college changes, reconcile app/group/role assignments), Leavers (disable access per policy, delegate employee data access to supervisor), and complex identity scenarios (multi-function, multi-college, multi-role).
RFPProvide tools that synchronize identities with common business applications (Microsoft 365 Education, Microsoft Dynamics 365 CRM/F&O, Adobe Admin Console, Zoom), and optionally with niche higher-education applications (Anthology Student, Lumens, OnCourse, Rave Mobile Safety, Watermark SSE, GivePulse, Maxient, Brightspace/D2L, Vector Solutions).
RFPProvide extensibility features (SCIM, API, SAML, automated CSV export) to send/receive identity information to current and future partners, aligned with a real-time, event-based architecture with near-real-time provisioning and available event triggers.
RFPProvide a 'MyApp' one-stop-shop page for application access, supporting custom/college-specific branding.
RFPProvide self-service password reset allowing end users to unlock/reset password after proving identity ownership via alternate email, security questions, or pre-registered MFA options.
RFPProvide an account claim flow: send a Welcome Email to new persons, guide them through account setup (password, MFA options, account recovery info), and link to important resources.
RFPProvide self-service access request (app access, additional permission access, group access) using approval chains to manager or application owner.
RFPProvide fine-grained administrative roles: User Support Technician (assist users claiming identity), Integration Developer (onboard applications, configure integrations), and Information Security (audit log review, investigate accounts, security statistics).
RFPProvide logging: audit logs for all administrative role actions and all user events (claimed account, reset password, added MFA devices, authenticated to application), with support for log export to SIEM, Azure App Insights, or other logging facility.
RFPProvide access review capabilities: annual access reviews organized by department/manager/college, attestations and compliance, and separation of duties reporting.
RFPProvide an overview of the Organization's experience, highlighting experience within public higher education and clients of similar size/scope to the system; identify experience working with a higher-education system with multiple colleges plus a system office; identify the project team and key personnel qualifications; provide 3 references (at least 1 higher-education client).
RFPProvide a Product Overview (description of platform/software, architecture, key features/functionalities, track record of solving complex identity problems), Implementation Plan (work required, timeline/milestones, transition plan, expected data migration duration and vendor role), Training Plan (knowledge transfer, system management training for ITS roles, future training options), Security and Privacy Considerations (protocols, encryption methods, FERPA/NIST 800-171 compliance, disaster recovery/backup procedures), and Support/Maintenance Considerations.
RFPProvide a detailed breakdown of costs associated with the software solution, including licensing, implementation, data migration, training, and ongoing support, with a payment schedule tied to project milestones or deliverables.
RFIWill the vendor sign or request changes to the agency's Information Technology Data Rider, included in Exhibit 1 of this RFI?
RFIDoes the vendor solution support the uses of SSO/MFA?
RFIProvide company background and previous successful relevant experience in PAM solutions.
RFIDescribe experience working with municipalities.
RFIProvide a quote/estimated cost to be used to help develop a budget.
RFIVendor shall ensure that all access by Vendor's employees, agents, representatives, and contractors requires strong passwords/passphrases or multi-factor authentication for users, and multi-factor authentication for all remote access; privileged accounts must use dedicated accounts and Vendor must maintain an inventory of privileged accounts.
Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.
Cloud directory platform unifying identity, device, and access management, well suited to SMB and mid-market.
Positioned for SMB/mid-market; enterprise-scale governance and PAM depth are less central.
MicrosoftAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Entra ID delivers deep workforce IAM integrated with Microsoft 365/Azure — SSO, MFA, conditional access, governance, and PIM.
Deepest value lands within the Microsoft ecosystem; heterogeneous/multi-cloud depth is emphasized less.
OktaAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Broad workforce and customer identity cloud with a large app-integration network and strong SSO, MFA, and lifecycle automation.
Public materials emphasize access-management breadth; deep PAM and fine-grained governance are less central than SSO and lifecycle.
Ping IdentityAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Standards-rich workforce and customer IAM (SSO, MFA, authorization, identity verification, ForgeRock heritage) with flexible deployment.
Breadth and configurability can mean integration complexity; governance depth is less central than access.
SailPointAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Identity governance (IGA) depth — certifications, provisioning, access modeling — with data access and CIEM add-ons.
Governance-anchored; native access management (SSO/MFA) and PAM are less central than governance.
SaviyntAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
A broad converged platform can add deployment complexity, and some depth depends on configuration.
Transmit SecurityAI-generated from public sourcesThe starting point for every profile: auto-generated by 0-Doubt from public vendor materials, and not yet confirmed by the vendor or an independent analyst. Nothing here is hidden or overstated — it simply has not been reviewed yet.Where every profile starts, before the vendor or an analyst has reviewed it. A higher label means a more independent source — not a better product.How trust works →(source)
Developer-first CIAM with orchestration, passwordless authentication, fraud detection, and identity verification.
Customer-identity and fraud focus; workforce governance (IGA) and PAM are not the emphasis.