
In 1996 I started building an identity system at a small tech university in Arizona. We called it Login Manager: single sign-on, identity lifecycle, one unified access card, years before anyone said the words modern IAM. We thought we had solved identity, and I then spent two decades watching every other institution rebuild the same thing from scratch. But underneath every screen we ever shipped sat one assumption so obvious nobody wrote it down. An applicant is a person.
That assumption is now the single most exploited weakness in higher education. If your campus is scrambling to identify fraudulent students, start with California's numbers, read aloud at your next cabinet meeting. At the spring 2025 peak, 34 percent of applications to California's community colleges were suspected fraudulent, according to state reporting covered by CalMatters. In the Los Rios district around Sacramento, it hit 64 percent. Not a third of a percent. A third of the applicants. Socure's analysis of the same wave found some colleges flagging more than 70 percent of applicants as suspicious, and 146 applications running on Social Security numbers that belonged to dead people.
So let me answer the question in the title directly. QuickLaunch Smart Access helps you identify and stop fraudulent students by exposing the thing fraud rings cannot hide, which is where and how they connect. What it does not do is verify that an applicant is a real person. That is identity proofing, it is a separate federal obligation, and any vendor who blurs that line for you is doing you harm. I run the company, and I am going to keep the line sharp.
Ghost students are not a clever loner with a fake name. They are an industry. The economics work because enrollment fraud scales the way any software business scales: one operator, one script, thousands of applications, each one a shot at Pell dollars and a .edu identity worth reselling. California lost over $13 million in financial aid in 2024 alone by Socure's accounting, and nearly $5.6 million in federal aid plus another $900,000 in state aid walked out the door in just the first quarter of 2025, per CalMatters.
Your financial aid office cannot out-staff that. A human reviewer reads one file at a time. The operation on the other side submits at machine speed, around the clock, from infrastructure it rents by the hour. And the stakes are not just the disbursed dollars. Every ghost that draws Title IV funds through your institution becomes your program-integrity problem, your audit finding, and your name in the report.
But industrial fraud has an industrial signature. The traffic comes from IP ranges no legitimate student uses. It comes from countries where your institution has never enrolled a soul. It hits your authentication layer in patterns no drop/add week ever produced. The fraud is invisible one application at a time and obvious in aggregate, if your identity layer can see and act on the aggregate.
Smart Access is the enforcement point for exactly that signature. Released earlier this year, it gives your tenant administrators a unified web application firewall capability inside the QuickLaunch admin console, where access policies are built from three kinds of conditions.
IP address ranges. Geographic locations. Directory group membership.
Policies combine those conditions, so the rule matches your institution instead of a vendor's idea of your institution. Access decisions are evaluated automatically during authentication, which means enforcement happens at the front door, not in a report someone reads next month. Rules are enabled, modified, or retired from a streamlined management interface, so when the fraud pattern shifts, your response is a policy edit, not a change ticket to a consultant.
What does that look like against ghost students? You scope financial aid and registrar systems to the directory groups that actually work in them, so a compromised or fabricated student account cannot wander into the systems where the money moves. You put geographic conditions on populations you do not serve, so authentication attempts from countries where you have no students meet a locked door instead of a login page. You write IP-range rules that treat your campus networks, your residence halls, and your known partner networks differently from anonymous rented infrastructure. The fraud operator's cost just went up. Your helpdesk's ticket queue did not.
Locksmith work, in other words. QuickLaunch is your digital locksmith, and Smart Access is the most literal expression of that yet: stronger locks, on the right doors, keyed to who should be walking through them.
Now the part of the column that some marketing person somewhere wishes I would skip. Smart Access does not perform identity proofing. A web application firewall can tell you the connection is coming from a data center in a country you do not serve. It cannot tell you the human filling out the FAFSA is real, alive, and the person they claim to be.
That distinction is now federal, not philosophical. Federal Student Aid's June 2025 announcement on preventing fraud through identity verification invokes IAL2, the NIST identity assurance level that requires validated evidence like a government-issued photo ID checked against authoritative sources, and it requires institutions to retain documentation of when a student's identity was verified and by whom. NIST SP 800-63-4, which superseded the old guidance in August 2025, goes further and expects a documented, risk-based identity decision for each online service. FSA has already stood up Verification of Identity reporting in the FAFSA Partner Portal for students selected into the V4 and V5 tracking groups. The proofing floor exists, it is rising, and no access policy satisfies it.
So the honest architecture has two distinct jobs in it. Proofing establishes that the applicant is a person. Access policy governs where and how that person's credential is allowed to operate, every single day after proofing. If your team is mapping this for the first time, the division of labor is easy to remember. Proofing answers who you are. Access policy answers where you may stand. Institutions get in trouble when they buy one and believe they bought both, and fraud thrives wherever a campus lets one of those answers substitute for the other.
Here is the most encouraging receipt in this whole story, and it is also the one that keeps me humble about my own product. By spring 2026, California's flagged-application rate had fallen from that 34 percent peak to about 12 percent, and quarterly losses dropped by roughly three quarters. What did it? Not one purchase. Improved filtering, AI-powered detection, and a mandatory ID verification policy, stacked together. Layers did that. No single vendor gets to claim it, QuickLaunch included.
The same logic is why the access layer belongs in your stack even after you deploy strong MFA. Reverse-proxy phishing kits in the Tycoon2FA family capture authenticated sessions after the user completes MFA, and security reporting is blunt that most institutions have not yet moved to phishing-resistant factors. I put a prediction on record in the spring that SMS and email one-time passwords would start being treated as a risk rather than a control, and the phishing-kit economy has spent the year making my argument for me. A stolen session still has to connect from somewhere. Where is precisely the question Smart Access asks.
Two weeks ago I wrote about auditing the AI agents on your campus, and the theme was the same one your grandmother taught you: know who has keys to your house. Fraudulent students are the front-door version of that problem. Fake applicants, phished sessions, ghost accounts that outlive their humans. Different doors. Same locksmith question.
So here is the path. Turn on Smart Access policies for your highest-risk systems first, financial aid and registrar, with geography and group conditions you can defend in a sentence. Map your IAL2 proofing obligations against FSA's current guidance and write down who verifies, and when, and where that record lives. Then walk the rest of the stack with fresh eyes. The institutions winning this fight did not find a silver bullet. They stacked ordinary, explainable controls until the fraud stopped penciling out.
That is work your team can start this week. Not a transformation. A Tuesday.
Primary: Take the On-Ramp Lifecycle AuditQuickLaunch's identity lifecycle assessment, to see where your enrollment front door stands today. Then pick one high-risk system and draft your first three Smart Access policies: one geographic, one IP-range, one group-scoped (capability detail in the release notes).
Secondary: Follow the weekly column on the QuickLaunch blog for next week's companion piece on External Authentication Methods.
What is QuickLaunch Smart Access?
QuickLaunch Smart Access is a web application firewall capability released in 2026 that helps institutions identify fraudulent students at the authentication layer. It lets tenant administrators define, manage, and enforce access policies based on IP address ranges, geographic locations, and directory group membership. Policies can combine conditions, are managed in the QuickLaunch admin console, and are evaluated automatically during authentication. Current capability detail lives in the QuickLaunch release notes.
Does QuickLaunch Smart Access verify a student's identity?
No. QuickLaunch Smart Access enforces access policy at the authentication layer; it does not perform identity proofing. Verifying that an applicant is a real person requires an identity verification process, such as IAL2-level proofing with a government-issued photo ID, which the U.S. Department of Education's Federal Student Aid office now expects institutions to perform and document in fraud-sensitive cases.
How big is the fraudulent student problem in higher education?
Large and industrialized. At the spring 2025 peak, 34 percent of applications to California community colleges were suspected fraudulent, and the Los Rios district near Sacramento flagged 64 percent, per CalMatters. Socure reported over $13 million in California financial aid lost in 2024 and identified fraudulent applications using Social Security numbers of deceased individuals. After California stacked filtering, detection software, and mandatory ID verification, the flagged rate fell to about 12 percent by spring 2026.
How should institutions combine access policy with identity proofing?
Treat them as two distinct layers. Identity proofing (IAL2 verification per NIST SP 800-63-4 and Federal Student Aid guidance) establishes that an applicant is a real person at enrollment. Access policy, such as QuickLaunch Smart Access rules on IP range, geography, and group membership, then governs where and how every credential may authenticate for the life of the account. California's fraud decline came from layering both kinds of control, not from either one alone.
Raymond Todd Blackwood is the President of QuickLaunch and writes about identity, agentic AI, and the messy reality of higher-ed IT. #ItsExistential