MARADMIN 453/26
GUIDANCE FOR THE TRANSITION OF DEFENSE AGENCIES INITIATIVE (DAI) USER ACCESS PROVISIONING TO DISA ENTERPRISE IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (E-ICAM)
R 251448Z SEP 26 MARADMIN 453/26 MSGID/GENADMIN/CMC WASHINGTON DC PR// SUBJ/GUIDANCE FOR THE TRANSITION OF DEFENSE AGENCIES INITIATIVE (DAI) USER ACCESS PROVISIONING TO DISA ENTERPRISE IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (E-ICAM)// REF/A/MEMO/DOW/26NOV2024// REF/B/DOC/DON/19DEC2025// REF/C/MARADMIN 091/25// REF/D/MARADMIN 136/25// NARR/REF A IS DON POLICY MEMORANDUM, "MODERNIZING SYSTEM ACCESS AUTHORIZATION REQUESTS (SAAR) AND ACCOUNT PROVISIONING THROUGH IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT WORKFLOWS." REF B IS DOW MEMORANDUM, "ACCELERATING ADOPTION OF IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT." REF C IS MARADMIN 091/25, PROVIDES GUIDANCE FOR DEFENSE AGENCIES INITIATIVE (DAI) INFORMATION OWNER (IO) APPOINTMENT AND VALIDATION OF ACTIVE INFORMATION OWNERS. REF D IS MARADMIN 136/25, DAI USER ACCESS PROCEDURES.// POC/HQMC, P&R, SDI/R. N. MCNAMEE: TEL: COM (703) 614-3473/ EMAIL:[email protected]// POC/HQMC, P&R, SDI/ J. A. STARK: TEL: COM (703) 697-5017/ EMAIL: [email protected]// POC/HQMC, P&R, SDI/C. J. SCHUMACHER: TEL: COM (703) 614-3498/ EMAIL: [email protected]// POC/HQMC, P&R, SDI/B. A. WASH: TEL: COM (703) 614-3498/ EMAIL: [email protected]// POC/HQMC, P&R, SDI/R. L. BURNAND: TEL: COM (317) 200-3534/ EMAIL: [email protected]// POC/HQMC, P&R, SDI/C. A. DABRIO: TEL: COM (703) 693-9379/ EMAIL: [email protected]// POC/HQMC, P&R, TSO/P. T. LAYMAN: TEL: COM (317) 200-3308/ EMAIL: [email protected]// GENTEXT/REMARKS/1. Situation. In accordance with references (a) and (b), the Department of War (DoW) continues to advance its zero trust architecture, audit-readiness posture and Identity, Credential, and Access Management (ICAM) adoption. As such, Defense Agencies Initiative (DAI) is transitioning its user access provisioning, authentication workflows and account lifecycle management to the Defense Information Systems Agency (DISA) Enterprise Identity, Credential, and Access Management (E-ICAM) framework. This transition replaces legacy provisioning pipelines with an automated, attribute- based framework designed to streamline user access, integrate cross application segregation of duties (SOD) compliance and satisfy federal financial audit mandates. 2. Mission. Effective 16 September 2026, the Marine Corps officially transitioned all DAI user access requests, account provisioning, modifications and recertifications to DISA E-ICAM. All Marine Corps DAI users, information owners (IOs) and supervisors must align with the new procedures outlined herein to ensure continuity of operations and prevent access disruptions. 3. Execution 3.a. Concept of Operations 3.a.1 Access Request Management Service (ARMS). Effective 16 September 2026, ARMS will no longer be used to initiate DAI access or role requests. ARMS will maintain read-only access to preserve historical supporting documentation until final decommissioning on 30 September 2027. 3.a.2. DAI role provisioning. DISA E-ICAM will be used to initiate and route DAI System Authorization Access Requests (SAAR/DD form 2875). Until DAI role auto-provisioning is implemented, currently scheduled for November 2026, the HQMC Systems Data Integration (SDI) User Access Management (UMX) team will manually provision approved roles within DAI. Users are responsible for monitoring their DISA E-ICAM requests through final approval. For new roles, users will complete the DISA E-ICAM SAAR and then request the role(s) within DAI as they do now. Requests to restore previously held roles, (end-dated), users will complete the DISA E-ICAM SAAR and shall contact their local io within their respective G-1, G-4, or G-8 to have the end-date removed. 3.a.3. ICAM instances. DAI utilizes the DLA instance of DISA E-ICAM. Users must verify they are using the correct E-ICAM site, which can be found within paragraph 4.c. of this MARADMIN. 3.a.4. Existing User Migration. Active users and approved DAI roles recorded as of 28 August 2026 were submitted for migration to DISA E-ICAM. A new DISA E-ICAM SAAR is required for arms SAARs submitted from 29 August through 15 September as those roles were not migrated via the bulk upload due to timing. All new or modified role requests will require a new DISA E-ICAM SAAR. 3.a.5. SAAR Effective Dates. As a result of the DISA E-ICAM bulk upload / migration, all current SAARs have a system generated effective date of 15 July 2026. This will be the date that triggers recertification requirement in DISA E-ICAM unless another key event occurs first, such as a change of supervisor. 3.a.6. DISA E-ICAM SAAR workflows and restrictions. SAARs route based on the requested role, command Unit Identification Code (UIC)/ Department of Defense Activity Address Code (DoDAAC), and DD Form 577 approval workgroup if applicable. Certain roles require additional documentation or approval steps, e.g., DD Form 577 appointment documentation, SOD waivers, and training certificates. Currently, the only specialized approval workgroup established is for roles requiring a DD Form 577. Supervisors and IOS are responsible for ensuring required supporting documentation are submitted by the users . Users must adhere to the following submission rules to prevent routing errors: 3.a.6.a. Do not combine Oracle Time and Labor (OTL) and full financials roles on a single SAAR. 3.a.6.b. Within full financials roles, do not combine Supply Chain Management (SCM) and Financial Management (FM) roles on the same SAAR. 3.a.6.c. Roles may be combined on a SAAR only when they follow the same approval workflow. Roles requiring different approval workgroups or supporting documentation must be submitted on separate SAARs, e.g. roles that require a DD Form 577 and ones that do not. 3.a.6.d. For roles requested that will impact multiple UICs/DoDAACs, users should request the DAI role only once using the UIC/DoDAAC associated with their organization. Supporting multiple UICs/DoDAACs does not require duplicate requests for the same DAI role. 3.a.6.e. When reviewing DISA E-ICAM SAARs, supervisors must enter the email address and name of an applicable security manager prior to routing the SAAR to ensure proper delivery. 3.a.7. DISA E-ICAM document repository. DISA E-ICAM does not retain supporting documentation after final approval. HQMC established the ICAM Documentation Repository (IDR), a Microsoft power app stored on the SDI SharePoint. Historical ARMS documentation will migrate to the IDR using automation. No user action is required for the documentation migration. For new requests, HQMC SDI UMX will store required supporting documentation in the IDR on behalf of the users. 3.a.8. New DAI Users. First-time DAI users must complete DAI self- registration before access can be granted. For instructions, refer to the DAI smart pack via the link provided within paragraph 4.c. of this MARADMIN. 3.a.9. Segregation of Duties. DISA E-ICAM does not currently prevent users from selecting conflicting DAI roles. USMC SOD requirements will be enforced through supervisor and IO reviews, HQMC SDI UMX controls, and the USMC SOD governance process. HQMC will continue to work with DISA for future SOD system enhancements. 3.a.10. Supervisor Responsibilities. When reviewing DISA E-ICAM SAARs, supervisors must: validate user information; ensure the requested access is appropriate for the user's duties; and validate required documentation, to include any applicable sod requirements. Supervisors are required to enter applicable dates denoted by a red asterisk, including cyber awareness and contractor period of performance, and review required DD Form 577 documentation. Supervisors are responsible for selecting an appropriate security manager for the organization to ensure proper routing of the SAAR. Note: supervisors must first log in to DISA E-ICAM before a user can successfully identify/select that individual as their supervisor. 3.a.11. Information Owners. When reviewing DISA E-ICAM SAARs, IOs must validate requested access to ensure compliance with applicable USMC SOD and supporting documentation requirements, including required training certificates, appointment letters, and DD Form 577 documentation. 3.a.12. Security Managers. When reviewing DISA E-ICAM SAARs security managers must review Defense Information System for Security (DISS) and annotate the security clearance level and active status within the SAAR. 3.a.13. Cyber Awareness Training Verifications. Despite recent OSW guidance, DISA requires an annual cyber awareness training date. Currently, a cyber awareness certificate must be uploaded for each SAAR request. Future enhancements will connect learning management systems to DISA E-ICAM to auto-populate cyber awareness training information and certificates. 3.b. Coordinating instructions: 3.b.1. Phase 1: User Access Review (UAR). UAR 1.0 and 2.0 complete as of 17 August 2026. 3.b.2. Phase 2: cutover and go-live effective 16 September 2026. 3.b.2.a. All users with active DAI roles as of 28 August 2026 were submitted for migration to DISA E-ICAM and will retain their current roles and responsibilities. 3.b.2.b. As of 16 September 2026, new DAI role requests must be submitted through the DISA E-ICAM portal in lieu of ARMS. Upon final SAAR approval, users must complete the applicable DAI role- request steps until auto-provisioning is implemented. All ARMS E- SAARs that were not fully provisioned in DAI by 28 August 2026 must be re-submitted through DISA E-ICAM. HQMC SDI will release a formal task with the list. 3.b.2.c. The DISA E-ICAM uniform resource locator (URL) is provided within paragraph 4.c. of this MARADMIN. 3.b.2.d. A DAI DISA E-ICAM smart pack was developed to guide users through the request process and includes a comprehensive list of all DAI roles available to request. USMC specific DAI roles will include “USMC” in the role title; however, some global roles used by USMC will not. To ensure the correct role is selected, users should reference the USMC DAI smart pack and enter the role title exactly as listed when searching in DISA E-ICAM. The smart pack is available on The HQMC SDI SharePoint site via the link within paragraph 4.c of this MARADMIN. 3.b.3. Phase 3: Auto-provisioning. Auto-provisioning is currently scheduled for November 2026. With this update and upon approval of a DISA E-ICAM SAAR, roles will be auto-provisioned within DAI. 3.b.4. Phase 4: Continuous Recertification. Two UARs will be conducted in fiscal year 2027. An immediate, limited UAR will be completed NLT 30 January 2027. The annual UAR will be completed NLT 15 July 2027. 3.c. Tasks 3.c.1. DAI Users 3.c.1.a. Navigate to the DISA E-ICAM URL and verify that you have a profile. Utilizing the DAI DISA E-ICAM smart pack, located via the link within paragraph 4.c of this MARADMIN, reference the ‘manage identity/edit identity’ section to navigate how to verify your personal information and supervisor. If a user logs in and does not see a menu on the left when attempting to access the list icon near the home button, the user should close their browser and reattempt login. If the error is not resolved, access the virtual DISA E-ICAM support center via Microsoft Teams via the link within paragraph 4.c of this MARADMIN. 3.c.1.b. Attend DAI DISA E-ICAM training via the link located within paragraph 4.c. 3.c.1.c. Complete annual DoD cyber awareness training. DISA requires a current annual cyber awareness training date. 3.c.1.d. Review the DAI DISA E-ICAM smart pack and attend a training session. A list of training sessions are located within paragraph 4.c. of this MARADMIN. 3.c.2. Supervisors 3.c.2.a. Navigate to the DISA E-ICAM URL and verify that you have a profile. Utilizing the DAI DISA E-ICAM smart pack, reference the ‘manage identity/edit identity’ section to navigate how to verify your personal information. Supervisors must log in prior to being selected as a supervisor. Note- if supervisors log in and experience a blank screen, close the browser and reattempt login. 3.c.2.b. Review the DAI DISA E-ICAM smart pack. 3.c.2.c. Attend DAI DISA E-ICAM training. A list of training sessions is located within paragraph 4.c. of this MARADMIN. 3.c.2.d. Review and action automated provisioning requests routed through the DISA E-ICAM workflow within 21 days of submission. 3.c.2.e. Enforce SOD requirements by ensuring applicable waivers are present and signed by the proper authority in accordance with reference (d). 3.c.2.f. Validate the email address of the security manager prior to approving the SAARs to ensure proper delivery. 3.c.2.g. Immediately revoke access for personnel executing permanent Change of Station / Assignment (PCS/PCA) orders, separating from the USMC, or no longer requiring the applicable DAI role/s. 3.c.3. Information Owners (IOs) 3.c.3.a. Navigate to the DISA E-ICAM URL and verify that you have a profile. Utilizing the DAI DISA E-ICAM smart pack, reference the ‘manage identity/edit identity’ section to navigate how to verify your personal information. 3.c.3.b. Review the DAI DISA E-ICAM smart pack. 3.c.3.c. Attend DAI DISA E-ICAM training. A specific, mandatory io training will be developed and delivered to IOs. A certificate will be produced as proof of training and provided with the new DISA E-ICAM IO appointment letter. 3.c.3.d. Update the IO appointment letter and provide it to HQMC SDI. An Enterprise Task Management Software Solution (ETMS2) tasker will be released requiring all IOs to submit their DISA E-ICAM IO appointment letter and, upon completion of dedicated IO training, the associated training certificate no later than 30 November 2026. current ARMS IO appointment letters are valid through 30 November 2026. 3.c.3.e. Review and action automated provisioning requests routed through the DISA E-ICAM workflow within 21 days of submission. 3.c.3.f. Enforce SOD requirements by ensuring applicable waivers are present and signed by the proper authority in accordance with reference (d). 3.c.3.g. Coordinate with supervisors to ensure immediate access revocation for personnel executing PCS/A orders, separating from the USMC, or no longer requiring the applicable DAI role/s. 4. Administration and Logistics 4.a. Training and Documentation. Detailed Standard Operating Procedures (SOPs), user migration details, and training materials are hosted within the DAI confluence website and the HQMC, SDI SharePoint via the links provided within paragraph 4.c. of this MARADMIN. 4.b. Help Desk Support. For technical support regarding DISA E-ICAM, users should first contact their local IO and then the DISA E-ICAM Support Center Teams Channel. HQMC, SDI UMX will host an open support channel transition through November 2026. The link for the support channel is located within paragraph 4.c. of this MARADMIN. 4.c. Resources and URLs. Navigate to the ICAM transition resources via SharePoint: https:(slash)(slash)usmc.sharepoint-mil.us /sites/dcpr/sitepages/sdi.aspx 5. Command and Signal 5.a. Command. This MARADMIN is applicable to the Marine Corps Total Force. 5.b. Signal. Ensure the widest dissemination of this message to all comptrollers, supply and logistics personnel, system administrators and active DAI account holders. 6. Release authorized by Edward C. Gardiner, Assistant Deputy Commandant for Programs and Resources.//