Protected Users Group Project Communications

Protected Users Group Project Communications

Contents

Project Implementation Status Updates (June 16 - July 28, 2026)

  • TUE June 16, 2:20 PM: Department User Accounts were added

  • WED June 17, 11:20 AM: Department User Accounts were removed

    • Reported issues with vCenter connections.

  • TUE June 23, 2 PM: Department User Accounts added to the Protected Users group.

    • NOTE: vCenter users exempted while vCenter remediation continues.

  • TUE June 30, 9 AM - 3 PM: vCenter users temporarily added to the Protected User group, then excepted once again as vCenter updates are still in progress.

  • TUE July 7, 1:15 PM: vCenter users will remain temporarily excepted from the Protected Users group through July 14 at 2 PM because UT-V needed to roll back an upgrade affecting its most-used vCenter cluster. The UT-V team is working with the vendor on a fix. The project team will continue monitoring progress and will share updates if another extension or limited test period is needed. 

  • TUE July 14, 2 PM: vCenter users were added to the Protected Users group.

    • There was a delay getting the excepted users added via script.

  • WED July 15, 7 AM: vCenter users were added to the Protected Users group. All Department User accounts are now included in the Protected Users group unless a specific user has an exception request approved by the UTISO.

  • WED July 22, 5 PM: The project remains on track for the July 28 completion target, with no blockers identified. All 2560 Department User accounts, including 300+ vCenter users, are members of the Protected Users group.

  • TUE July 28, 3 PM: The Protected Users Group implementation project is now considered complete.

    • Rollbacks related to the Protected Users Group project are no longer available.

    • Requests to remove a department user account from the Protected Users group for any purpose now require an approved Information Security Office (ISO) exception request.

 

Project Begin Announcement Email – May 13, 2026

FROM: Walker, Stephen C
TO: it-updates@utlists.utexas.edu
DATE: May 13, 2026

ACTION REQUIRED: Update AD LDAP server for non-EID user applications by June 16, 2026

If you do not log in with a non-EID account e.g., DEPTCODE-EID, or you do not manage an application that authenticates users with non-EID accounts against Austin Active Directory, you may ignore this message.

INTRODUCTION

Enterprise Technology (ET) has initiated a project to address a Privileged Access Management (PAM) audit finding identified by Internal Audits in May 2022. The audit noted that the University lacked a centralized PAM solution to secure privileged account credentials. The associated risk was long-lived exposure of privileged credentials, particularly through cached credentials that could be exploited if compromised.

To remediate this finding, ET and the UT Information Security Office (UTISO) selected Microsoft Active Directory’s built-in Protected Users security group as the technical solution. Remediation actions may affect users authenticating with non-EID departmental accounts.

WHAT IS CHANGING

Department user accounts in Austin Active Directory will be added to the Protected Users group on June 16, 2026. A department user account is any non-service, non-EID user account created in the Department User Tools. After this change takes effect, these accounts will no longer be able to authenticate against the Austin Active Directory via either NTLM or LDAP simple bind.  

To support applications that require LDAP simple bind authentication against Active Directory, the Active Directory team has implemented an Active Directory Lightweight Directory Services (AD LDS) environment, ldap.austin.utexas.edu.

Department service accounts will NOT be impacted by this change, nor will authentication against TED, entdir.utexas.edu.

WHEN

You must act prior to June 16, 2026.

ACTION REQUIRED

Applications that authenticate department user accounts with LDAP against the Austin Active Directory must ensure that the application is updated with the new AD LDS server name prior to June 16, 2026.

Application owners must:

Reach out to the Active Directory team if your use case is not captured here or if you have other questions. 

ADDITIONAL INFORMATION

This approach mitigates credential theft risks by preventing privileged credentials from being cached or stored on Windows and macOS endpoints. However, a key technical constraint of Protected Users is that member accounts cannot authenticate using LDAP simple binds and must rely on Kerberos.

To support applications that require LDAP simple bind authentication without reintroducing credential caching risks, the Active Directory team implemented the AD LDS environment. This proxies simple bind authentication for users in the Protected Users group as Kerberos authentication requests against Active Directory.

TIMELINE  

  • Prior to June 16, 2026 

    • If an application has users that authenticate with non-EID accounts against Austin AD, application owners must ensure that their applications point to “ldap.austin.utexas.edu.”

  • June 16, 2026 – 2:00 PM

    • Every non-EID user will be placed into the Protected Users (PU) group

    • Application owners: test if your non-EID users can authenticate

    • If they can’t, ensure that you are pointing to “ldap.austin.utexas.edu.”

    • If you are pointing to the correct AD directory and your users cannot connect, contact the AD team.

  • June 16 – July 28, 2026

    • Testing, confirmations, rollbacks, and reinstatements

      • If there are issues, the changes will be rolled back and attempted each Tuesday at 2:00 PM until July 28, 2026:
        June 23, 2026
        June 30, 2026
        July 7, 2026
        July 14, 2026
        July 21, 2026

  • July 28, 2026

    • Final migration. No rollbacks or exceptions after this date.   

QUESTIONS?

If you have questions, please contact the Active Directory team via ad-requests@austin.utexas.edu

 

Thank you,  

 CAMPUS SOLUTIONS, Collaborative Platform Services 
The University of Texas at Austin | Enterprise Technology | tech.utexas.edu 

 

Project Complete Announcement – July 29, 2026

FROM: Walker, Stephen C
TO: it-updates@utlists.utexas.edu
DATE: July 29, 2026 (anticipated)

If you do not use a department user account (non-EID account, e.g., DEPTCODE-EID) or manage systems that authenticate users with department user accounts against Austin Active Directory, you may ignore this message.

INTRODUCTION

Enterprise Technology (ET) has completed the Protected Users Group implementation project, which began in response to a Privileged Access Management (PAM) audit finding from Internal Audits in May 2022. The project added department user accounts in Austin Active Directory to Microsoft’s Protected Users security group to reduce the risk of credential theft and misuse. Application owners using Lightweight Directory Access Protocol (LDAP) simple bind authentication for department user accounts were required to update their applications to use ldap.austin.utexas.edu and confirm that authentication continued to work as expected.

WHAT IS CHANGING

The Protected Users Group implementation project is now considered complete.

  • Rollbacks related to the Protected Users Group project are no longer available.

  • Requests to remove a department user account from the Protected Users group for any purpose now require an approved Information Security Office (ISO) exception request.

WHEN

As of July 28, 2026, Protected Users group membership is now the standard security configuration for department user accounts.

ACTION REQUIRED

No action is required for departments whose department user accounts are operating successfully with Protected Users group membership.

Departments that have a business or technical requirement to remove a department user account from the Protected Users group must request an Information Security Office (ISO) exception. Approved exceptions will be processed through established security governance procedures.

QUESTIONS?

If you have questions about Protected Users group membership, please review the Protected Users wiki page or contact the Active Directory team via ad-requests@austin.utexas.edu.

 

Thank you,

CAMPUS SOLUTIONS, Collaborative Platform Services 
The University of Texas at Austin | Enterprise Technology | tech.utexas.edu