
Source: Own Illustration
Effective immediately, all members of RWTH Aachen University can view their own roles directly in the IdM Role and Group Management. The homepage displays all roles that have been assigned to you via Role and Group Management.
This makes it easier to access your own roles and groups: You no longer have to navigate through the IdM Selfservice to do so. Previously, access to the IdM Role and Group Management was only available to individuals with the “Role Management” role.
Why Are There Roles?
Based on your enrollment or employment status, you are assigned a role such as “Student” or “Employee”. Based on this, certain roles are automatically assigned to you in Identity Management (IdM). These roles determine which IT services and applications you can use at RWTH, such as VPN or eduroam. You can still view these automatically assigned roles in the IdM Selfservice.
In addition, some services require special roles that are not automatically assigned based on your status. For example, if you want to request a business trip, you’ll need the “Business Travel Request” role. Such roles are manually assigned by role administrators via the IdM Role and Group Management.
View Your Own Roles Directly on the Home Page
Until now, you’ve been able to view your manually assigned roles and groups in the IdM Selfservice. Starting August 26, 2026, you’ll also find this information directly on the homepage of the IdM Roles and Groups Management. After logging in, you’ll see all the roles and groups that have been assigned to you via Roles and Groups Management.
When Role managers access the IdM Roles and Groups Management, they will be taken directly to the “Roles” subpage, as before. To view your own assigned roles and groups, simply click the “Home” tab.
Permissions for specific systems and services may be associated with these roles and groups. You can find information and links to these systems under “Target System Links” in the respective row for each role.

Source: Own Illustration
Fewer Logins, Faster Access to Your Target System
The new homepage of the IdM Roles and Groups Management not only offers faster access to your roles but can also save you from having to log in repeatedly via RWTH Single Sign-On. Due to the highly sensitive data managed there, the IdM Selfservice enforces short Shibboleth session times. Once the session expires, you’ll need to complete multi-factor authentication (MFA) when logging in again.
In contrast, the IdM Role and Group Management does not require a new login as long as your existing Shibboleth session is still active. For example, if you want to view your roles or the associated target systems multiple times throughout the day, you can therefore access the IdM Role and Group Management directly. The new homepage makes accessing your own roles and groups easier and more intuitive.
Responsible for the content of this article are Leif Janissen, Thorsten Kurth and Hannah Loock.



Leave a Reply