University of Wisconsin–Madison
People forming the shape of a secured lock with tech icons

Smart Access: September 2026 progress update

Since the July update, Smart Access work has moved from analysis to decisions. Two announcements lead this update:

  • Device compliance notifications will turn on for WiscVPN on November 11. [Read the full article]
  • Duo Desktop will be available in 2027 for application owners to opt into. A pilot with internal DoIT applications is up next. [Read the full article]

Recent progress also includes:

  • Log management requirements interviews are underway with IT units across the university, and the Elastic Cloud migration is moving into user acceptance testing
  • Feedback sessions on the draft UW-Madison Zero Trust framework and program roadmap are underway with IT leaders across divisions

Device compliance: WiscVPN notifications set for November 11

In July, the team was finishing a recommendation for DoIT leadership on next steps for HIP notifications. Since then, the team has:

  • Finalized the recommendation and incorporated reviewer feedback
  • Reviewed user experience survey responses from pilot participants and updated KB documentation based on them
  • Prototyped BigFix, and Qualys reporting on device compliance as evaluated in GlobalProtect
  • Developed a communications and support plan for the rollout
  • Shared the decision and timeline with ITCCC (September 1) and MIST (September 10)

The decision rests on pilot results and an impact assessment across 11 schools, colleges, and divisions. Devices that received a notification during the pilot were more than three times as likely to be updated as devices on WiscVPN, where no notification was shown. Notifications remain informational only: no one loses access, and departmental VPNs are unchanged. The full article covers what users will see, the timeline, and what IT staff can do to prepare.

Smart Access Service principle in action – Growth Through Measurable Impact: The WiscVPN decision was made on measured pilot outcomes, and the team will share aggregate compliance trends after notifications turn on so campus can see the change over time.

Duo Desktop: device health checks at application login

In April, initial planning was underway to explore opportunities to encourage device health with Duo. That work now has a charter and timeline approved by the Smart Access sponsors. Duo Desktop is an application, available through the university’s existing Duo contract, that checks a device’s health when a user logs in to a Duo-protected application. This change provides an additional tier of protection for higher risk applications. Application owners will be able to opt in by May 2027. 

Project Milestones: So far, the team has installed Duo Desktop on select DoIT-owned computers, configured NetID Login so an application can apply different security tiers by population, and started documenting Duo Desktop’s limitations.

End User Impacts: Only users of applications that opted into using Duo Desktop will be affected. People on university-managed devices will likely not notice a difference. People on unmanaged devices will need to install Duo Desktop and may need to update their device. Read the full Duo Desktop article for milestones and contacts.

Together, WiscVPN notifications and Duo Desktop evaluate a device’s health before accessing either the network connection or application login. Project teams are working towards consistently defining what constitutes a trusted device, aligning wherever possible.

Smart Access Service principle in action – Adapt with Purpose: The Duo Desktop project is upholding the Adapt with Purpose service principle. Piloting Duo Desktop on internal DoIT applications first lets the team learn how it interacts with endpoint management tools and what users experience before application owners across campus opt in.

Log management: interviews underway, Elastic Cloud moving to testing

Requirements gathering for the log management analysis moved from planning into conversations with campus IT. The team has:

  • Sent initial communications to the first groups of interviewees
  • Scheduled the initial analysis interviews and hosted the interviews with CALS, the School of Education, Academic Technology, and AIS
  • Completed a baseline document for the analysis based on interviews with DoIT teams

In parallel, the Cybersecurity Logging migration, powered by Elastic Cloud, is progressing on the timeline shared in June: log source migration targeted for completion September 7, CSOC user acceptance testing from September 7 through October 5, campus partner testing beginning in September, and project completion on October 25.

Smart Access Service principle in action – We’re All in This Together: Each interview adds a unit’s needs, constraints, and current practices to the analysis, so the recommendations due in February 2027 reflect how logging actually works across the university.

Zero Trust framework and program roadmap

In July we shared that a Zero Trust framework for UW-Madison, aligned with the CISA Zero Trust Maturity Model, was in development along with a roadmap of all in-flight program work. Through September the team has been reviewing both with IT leaders across divisions, and their feedback is shaping how the framework is organized. We plan to share more in the coming months.

What’s next

Through September and October, Device Compliance work will focus on:

  • Presenting at the Endpoint Management Community of Practice (September 16) and ITC (September 18) about device compliance notifications on WiscVPN.
  • Updating documentation and KB articles related to WiscVPN notifications
  • Investigating options for reporting non-compliant devices connecting to WiscVPN to SCD IT units
  • Preparing the SCD help desk support package for late October, followed by an email to all active WiscVPN users in early November and go-live on November 11

Log Management efforts will focus on:

  • Hosting the Academic Technology interview and continuing to schedule interviews with additional IT units
  • Supporting Elastic Cloud user acceptance testing with the CSOC and campus partners

Duo Desktop work will focus on:

  • Selecting two to three internal DoIT applications for the pilot
  • Documenting what constitutes a trusted device and what the end-user experience looks like
  • A sponsor decision on if Duo Desktop should be encouraged for devices not owned by UW-Madison

Stay connected

Sign up for Smart Access updates via the Smart Access website or contact the Smart Access team.