LANSING, Mich. — A new state audit found significant weaknesses in security and user-access controls for the Michigan Department of Natural Resources system used by millions of people to purchase hunting, fishing and recreational licenses.
The Michigan Office of the Auditor General rated the DNR’s security and user-access controls over its MiConnect system as only “moderately effective,” identifying what auditors classified as a material condition involving the management of user accounts.
MiConnect is used to sell hunting, fishing, snowmobile and off-road vehicle licenses and for hunting lottery applications, fuelwood permits and other DNR programs. The system processed 2.4 million transactions totaling $86.4 million during fiscal year 2025. As of July 2025, it had nearly 4,000 active accounts belonging to DNR employees, vendors and retailers.
Like my reporting? I can’ do it without you. If you are not yet a paid subscriber consider becoming one for less than $1 per week. Click button below to support my work.
The audit found hundreds of accounts that should have been automatically disabled under state security standards remained active.
Auditors reviewed 376 internal accounts and 3,545 external point-of-sale accounts and found 43 internal accounts and 565 external accounts had not been disabled despite being inactive for more than 60 days. Some accounts had not been used for as long as 1,988 days.
Auditors also identified 609 external accounts and nine internal accounts that had never been used after they were created but remained active. On average, those accounts had been created more than three years earlier.
The report said the weaknesses could increase the risk of “unauthorized access, disclosure, modification, or destruction of customer data.” The audit did not report that such a breach actually occurred.
Auditors also found problems with removing access for former DNR employees. Of 12 former employees sampled, managers failed to promptly notify the system administrator about 11 of them. Those accounts were deactivated an average of 178 days late, according to the report. State standards generally require access to be removed within three business days after employment ends.
Another issue involved documentation for newly created accounts. Auditors sampled 22 users granted access during the audit period and found the DNR did not have documentation showing the required approval for any of the 22 accounts. Three lacked an access authorization form altogether, while forms for the other 19 did not document approval from the system or security administrator. Auditors also found one user had been given inappropriate access to privileged functions.
The Auditor General classified the overall access-control problem as a “material condition,” citing the number of inactive accounts, missing approvals, shortcomings in periodic reviews of user access and delays in removing access after employees left the department.
The DNR agreed with the recommendation and said it would implement controls to ensure inactive accounts are disabled in accordance with state technical standards.
The audit identified additional problems beyond account security.
MiConnect is hosted by a third-party vendor and contains customers’ personally identifiable and financial information. Auditors concluded the DNR’s monitoring of the outside service provider was “sufficient, with exceptions.” Among other issues, the department did not review and test 12 responsibilities identified in a third-party security report. In one instance, the DNR obtained a required report 300 days after it was issued.
The DNR told auditors the problem resulted from an internal misunderstanding about its responsibilities for reviewing the reports. The department agreed to make changes to improve its oversight of the vendor.
Auditors also raised concerns about duplicate customer accounts, which could potentially allow someone to get around restrictions on the number of licenses that can be purchased.
An analysis of 1.9 million customers identified 176 driver’s license numbers associated with more than one customer account. Auditors sampled 18 of those driver’s license numbers and determined six involved the same person having multiple accounts.
Auditors separately identified 4,110 instances in which the same name and date of birth were associated with multiple accounts. Of 33 combinations examined more closely, seven involved the same person having multiple accounts. Some of the duplicates were caused by relatively minor differences such as misspelled city names or variations in addresses.
The report did not conclude that all 4,110 cases were duplicate accounts or that customers had actually used the accounts to improperly obtain additional licenses.
The DNR acknowledged its existing processes were not sufficient to ensure customers did not have multiple accounts and said it would develop better methods for detecting and consolidating duplicates.
Auditors additionally found shortcomings in documentation surrounding changes to the MiConnect software. Of 44 system changes examined, the DNR lacked documentation of user acceptance testing and post-implementation validation for all 44. For 31 of the 44 changes, auditors also could not find documentation showing the DNR approved the requirements before development began.
The department agreed to work with its vendor to improve that documentation.
Despite the problems, the audit also identified areas where the system performed well.
Auditors found customer information materially matched Michigan driver’s license records and sampled customers received the appropriate resident or nonresident purchasing restrictions. They also rated controls governing the transfer of MiConnect revenue as “effective.” Auditors found all revenue transactions tested successfully transferred to the state’s cashiering system and that MiConnect revenues materially reconciled with amounts recorded in the state’s accounting system.
The audit generally covered DNR operations from Oct. 1, 2023, through Sept. 30, 2025.

