Decommissioning IP-Based Authentication for Licensed E-Resources

Decommissioning IP-Based Authentication for Licensed E-Resources

Project Charter: Decommissioning IP-Based Authentication for Licensed E-Resources

Project Name

Decommissioning IP-Based Authentication for Licensed E-Resources

Project Goals

  • Transition all Harvard Library e-resource authentication from IP-based to credential-based authentication. User Impact: All users irrespective of location, including those on-campus from their wired connection, will now need to authenticate via Harvard Key prior to authorization via OpenAthen or EZproxy (HarvardKey + OpenAthens/cloud EZproxy).

  • Strengthen security, compliance, and operational efficiency across digital content systems.

  • Provide equitable and consistent access for all authorized users, regardless of location.

Problem and Value Statements

Problem Statement

Harvard Library currently maintains IP-based authentication for on-campus access to licensed e-resources. This model—introduced in 2011 to simplify faculty research workflows—has become increasingly risky and unsustainable:

  • Harvard can no longer reliably trace usage by IP, breaching vendor compliance requirements.

  • IP spoofing and misuse of on-campus ranges have created significant security vulnerabilities. 

  • Maintaining complex IP whitelists imposes high operational burden and fragility.

Solution and Business Value

Replacing IP-based authentication with credential-based access through HarvardKey and OpenAthens:

  • Enables vendor-compliant traceability and auditability.

  • Aligns with Harvard’s Zero Trust and modern identity management principles.

  • Reduces technical debt and administrative overhead.

  • Enhances user equity and experience across all campuses and affiliations.

Alignment with Harvard Library Multi-Year Goals and Objectives

  • Digital Access Strategy: Supports secure, seamless, and equitable digital access.

  • Operational Resilience: Simplifies infrastructure, reducing fragility and maintenance costs.

  • Compliance and Stewardship: Meets vendor and institutional security expectations.

Alignment with HUIT Objectives

  • Advances Harvard’s transition to passwordless, identity-driven security.

  • Supports the enterprise IAM modernization roadmap.

  • Reduces network-based authentication dependencies.

Vision

Decommissioning IP-Based Authentication for Licensed E-Resources

All Harvard Library e-resources are accessed through authenticated, user-based credentials, whether on campus or off campus—eliminating IP-based dependencies while ensuring secure, auditable, and equitable access for all authorized patrons.

Strategic Objectives 

Guiding Principles 

Key Performance Indicators 

  1. Fully decommission IP-based access.

  2. Improve guest access using managed OpenAthens credentials.

  3. Develop clear communication and training materials for staff, faculty, and guests.

  • User-Centered: Minimize disruption and maintain ease of access. 

  • Secure by Design: Align with Zero Trust principles.

  • Transparent: Communicate changes proactively to all affected stakeholders.

  • Collaborative: Engage ITS, LTS, IAM, and public service teams throughout transition. Maximize stability of platform for business continuity. 

  • 100% of licensed e-resources migrated to OpenAthens or cloud EZProxy.

  • 100% of vendors have updated their IP address lists to remove campus IP addresses.

In Scope/Out of Scope

In Scope

  • Retirement of IP-based access for Harvard-wide licensed resources across all Harvard-managed networks. 

  • Improved guest access implementation via time/location-based OpenAthens credentials. 

  • Faculty, staff, and user communication and training.

Out of Scope

  • Changes to locally digitized, open-access, or public-domain materials.

  • Network redesign beyond authentication dependencies.

  • Authentication/authorization for school-only electronic resources.

  • Vendor platform redesigns beyond authentication configuration.

Deliverables and Work Products

Task

Outcome

Responsible Parties

Vendor migration to OpenAthens (in process)

95% vendor coverage by Fall 2025

LTS / ITS

Guest access rollout

Improved OpenAthens guest credentials active in all libraries. Work, training, documention - Fall 2026. Rollout to libraries - January 2027.

LTS / Public Services

Communication campaign

Staff and faculty informed by Winter 2026

HL Communications / LTS / ITS

IP decommissioning

All campus IPs removed from vendor lists by Fall 2026

ITS with LTS support

Monitoring & stabilization

Verified post-cutover access integrity by Dec 2026

ITS / LTS

Definition of Done

  • All vendors transitioned to OpenAthens or cloud EZProxy.

  • All legacy campus IP-based access deactivated.

  • Guest access fully functional and documented.

  • Communications, signage, and training delivered.

  • Vendor confirmations obtained for IP list removal.

Stakeholders

Stakeholder

Title/Role

Participation

VPDR

Project Sponsor

Approval and oversight

LTS

Lead implementer

Project management, system migration, authentication, network, and IAM integration

ITS:ERS

Co-lead

Vendor Coordination; testing

IAM

Technical partner

HarvardKey and federation integration

HL Communications

Support

Communication and messaging development

Public Services Staff

Operational partner

Guest support and user guidance

Project Team

Portfolio

Key Member & Role

Affiliation

Library Technology Services

Project Manager, Laura Morse

LTS

Information Technology Services

Technical Lead, Amanda Schmidt

LTS

Information & Technical Services

Project team, Amy Dittman, Lauren Syer, Kasia Maciak

ITS

IAM Program

Integration Support

HUIT

Communications

Consultant, Clare O’Keefe

HL Communications

Cost and Estimated Schedule

Phase

Phase Start

Phase End

Completion Milestone

Planning & Vendor Coordination

Fall 2025

Jan 2026

75% vendor readiness

Communication & Training

Fall 2025

Winter 2026

Community awareness campaign complete

Decommissioning & Monitoring

Spring 2026

Summer 2026

IP-based access retired and verified stable

Assumptions, Constraints, Dependencies, and Risks

Assumptions

  • Vendors will complete IP access updates as requested. 

  • HarvardKey and IAM infrastructure remain stable and scalable.

Constraints

  • Resource availability across ITS and LTS teams.

  • Coordination across multiple vendor platforms.

Dependencies

  • Completion of OpenAthens project.

  • Vendor responsiveness to IP removal requests.

Risks

  • Delays in migration to OpenAthens for long tail of vendors.

  • Temporary user confusion or increased support load during transition.

  • Compliance risk if IP access persists during cutover.


We don't have a way to export this macro.