University Research Network
Dexfense ReviewedMixed academic environment with federated identity, campus wireless, shared research storage, VPN and Linux research servers.
Overview
Represents a university or academic institution with a federated identity provider (SAML/OIDC via Shibboleth or Entra ID), wired and wireless campus networks, Active Directory for staff accounts, cloud storage for research data, VPN for remote research access, Linux research servers, shared file storage, mail servers and backup systems. Student devices are unmanaged BYOD; staff devices are domain-managed and MFA-protected.
Intended for
University IT security teams, research computing staff and higher-education security and compliance professionals.
Architecture Assumptions
This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.
- Identity federation uses SAML 2.0 via Shibboleth or Entra ID B2C
- Student devices are unmanaged BYOD; staff devices are domain-managed
- Research data may be sensitive or subject to export control regulations
- Campus wireless uses 802.1X authentication for staff and WPA2/WPA3 for students
Out of Scope
- HPC clusters and specialised research computing infrastructure are not modelled
- Visitor and conference Wi-Fi segments are not separately assessed
- Medical device or patient data environments are explicitly out of scope
- Classified research environments require a separate, more rigorous assessment
Architecture Components15 components selected
Endpoints
Windows Clients
Windows-based end-user devices
macOS Clients
macOS-based end-user devices
Linux Desktops
Linux-based end-user workstations
BYOD
Bring your own device environment
Auth & IAM
Active Directory
Directory service for user and resource management
Multi-Factor Auth
Additional authentication verification layer
Network
Wireless Networks
Wi-Fi networks and infrastructure
VPN Services
Virtual Private Network services
DNS Services
Domain name resolution services
Storage
File Servers
Network attached storage for file sharing
Cloud Storage
Cloud-based object or file storage
Backup Systems
Data backup and recovery systems
Monitoring
Logging Systems
Centralized log collection and management
Servers
Linux Servers
Linux-based backend servers
Mail Servers
Email servers and services
Security Preview
Based on this architecture's component selection
Indicative Risk Score
46/100
27 techniques identified
3 Critical · 2 High
Top Attack Techniques
- CriticalT1068Exploitation for Privilege Escalation
- CriticalT1003OS Credential Dumping
- CriticalT1486Data Encrypted for Impact
- HighT1133External Remote Services
- HighT1574Hijack Execution Flow
Top Recommended Controls
- 1Implement privileged access management and monitor for suspicious directory queries
- 2Focus on Attack Surface Reduction as your highest priority security initiative
The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.
Remix copies the components so you can add or remove items before generating your assessment.
Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.