Humboldt-Universität zu Berlin - Computer and Media Service

HU-IAM

Central identity management system of the Humboldt University

 

HU-IAM (Identity and Authorization Management) is the central identity management system (IdM) of Humboldt-Universität zu Berlin. It ensures that personally identifying data is kept correct, consistent and persistent, and made available to other IT services of the HU.

 

In Focus

Apply for an HU account Apply for an HU account

An account for access to the HU's federation network.

 

 

Two-Factor Authentication (2FA) Two-Factor Authentication (2FA)

Additional protection for your HU account: in addition to a password, a one-time password from the 2FA app or a hardware token.

Authentication as a Service

Instead of every web service at the HU developing and maintaining its own user management and password verification, HU-IAM provides authentication centrally as a service. Connected services (so-called service providers) do not query the username and password themselves during login, but rely on the HU's central login service.

This has several advantages:

  • Users log in everywhere with the same HU account and password.
  • Passwords are only processed at one central, secured location and are never passed on to the individual service.
  • New services can be connected without developing their own login logic.
  • Security mechanisms such as two-factor authentication (2FA) automatically apply to all connected services.

Technically, this authentication service at the HU is implemented via the Shibboleth system.

Authorization as a Service

Authentication clarifies who is logging in – authorization determines what that person is actually allowed to do within a service. Instead of every service maintaining its own permission management, service-specific attributes can be worked out together with the HU-IAM team. To do so, please get in touch with us via Contact

Emails to this address are processed using an electronic ticket system. This is our main address, and it is reachable 24/7.
Please note the data protection notice: https://otrs.hu-berlin.de/hinweis-extern.html

Federation

Within the HU, all connected services form a shared trust federation: every service that belongs to this federation trusts the HU's central login service and accepts your HU account. A separate account for each service is not necessary – one login is enough for all connected HU services.

In concrete terms, this means: you log in with the same HU account to, for example, services offered by the HU. Here is a small selection:

  • Moodle – learning platform
  • AGNES – course catalog and exam registration
  • HU intranet – internal communication network of Humboldt-Universität

Further Information