Summary
- The new academic year concentrates account creation, device enrolment and application changes into a short operational window.
- Keeper warns that service accounts, API tokens, machine certificates and AI agents are widening the identity estate beyond students and staff.
- Department for Education standards increasingly treat access control, cyber governance, patching, filtering and resilience as core technology requirements.
The start of the academic year concentrates thousands of identity and technology changes into a short period for schools, colleges and universities, as new accounts, devices and applications are provisioned while old access and previous-year integrations still need to be controlled.
Keeper Security has used the back-to-school period to highlight the growing identity estate behind education technology, including not only staff and student accounts but service accounts, application programming interface tokens, digital certificates, cloud workloads and AI agents.
The guidance is seasonal rather than a new incident disclosure, and several of Keeper’s supporting statistics come from earlier research. The underlying operational conditions are current, however: September onboarding routinely combines bulk account creation, device enrolment, timetable and learning-system changes, payment services and third-party applications within the same narrow administrative window.
Those changes create opportunities for stale access to persist. Departed staff accounts may survive longer than intended, previous-year applications can retain tokens, and new integrations may receive permissions that are broader than their practical purpose while administrators focus on getting services working before teaching starts.
Keeper has placed particular emphasis on non-human identities. A modern education environment can rely on service accounts synchronising student records, API keys linking learning applications, certificates authenticating devices and cloud identities running automated backup or reporting tasks.
Darren Guccione, CEO and co-founder of Keeper Security, said: “The conversation about education cybersecurity has historically focused on human accounts: students, teachers and administrators. But the real blind spot is the vast ecosystem of machine identities that power modern EdTech. Back-to-school is the right moment for education IT teams to take stock of every identity on their network, human and non-human alike.”
The government’s own technology framework gives the identity issue a broader basis than vendor guidance. The Department for Education’s digital and technology standards require schools and colleges to work towards six core standards by 2030, including cyber security, digital leadership and governance, filtering and monitoring, and resilient network infrastructure.
The cyber security standard specifically covers controlling and securing user accounts and access privileges. It also expects annual cyber risk assessment, regular review, security updates, backup planning and incident reporting, placing access management within wider operational governance rather than treating it as an IT helpdesk function.
The Department for Education updated the cyber security standard on 24 June to reflect technical requirements introduced through Cyber Essentials 2026. It separately updated filtering and monitoring guidance in June to address risk assessment around generative AI.
AI introduces both another application category and another identity problem. A school or university can encounter AI through public tools used directly by students, assistants embedded in existing platforms, or institutionally managed agents connecting to internal information. The security implications depend on which model is used and what data and privileges the automated service receives.
Machine identities are not new, but their growth makes informal management increasingly difficult. A staff account usually has an owner and a leaving date. An API token created for a timetable integration or a service identity attached to a cloud workload can remain active after the person who configured it has moved role or the original application has been replaced.
Education adds structural complexity because support models vary widely. Universities can operate large distributed technology estates, while schools may depend heavily on managed service providers or small internal teams. In both environments, external applications and cloud services can extend the access boundary beyond the institution itself.
Back-to-school season therefore acts as an operational stress point rather than creating a new category of cyber threat. The security problem lies in ensuring that the identities and permissions created rapidly in August and September remain inventoried, owned and reviewable once the immediate onboarding pressure has passed.




