SurePassID Directory Sync Datasheet
SurePassID Authentication Server
SurePassID Directory Sync - Datasheet
Product At-A-Glance
SurePassID Directory Sync automates user provisioning from Active Directory and other identity sources into SurePassID MFA, eliminating manual account creation and ensuring consistent multi-factor authentication deployment across your organization.
Feature Matrix
Synchronization Sources
| Feature | Supported |
|---|---|
| Active Directory Group Membership | Yes |
| Active Directory LDAP Filter | Yes |
| Active Directory Real-Time Monitoring (AD Live) | Yes |
| XML File Import | Yes |
| Microsoft Entra ID (Azure AD) | Planned |
Authentication Token Types
| Token Type | OTP | Push | FIDO2 |
|---|---|---|---|
| SurePassID Authenticator | Yes | Yes | Yes - Push |
| Google Authenticator | Yes | - | - |
| FIDO2 Passkey (Passwordless) | - | - | Yes |
| FIDO2 Security Key (2FA) | - | - | Yes |
OTP Configuration Options
| Option | Values | Default |
|---|---|---|
| OTP Algorithm | Time-based (TOTP), Event-based (HOTP) | Time |
| Time Drift Tolerance | 1-60 steps | 5 |
| Event Window Size | 1-100 | 30 |
| Token Status on Creation | Enabled or Disabled | Enabled |
| Activation Notification | None, Email, SMS | None |
User Provisioning Options
| Option | Values | Default |
|---|---|---|
| User Role | User, Helpdesk, Helpdesk Manager, Admin, Super Admin | User |
| User Status | Enabled, Disabled | Enabled |
| User Group | Any SurePassID group | (none) |
| Token Creation | Automatic or None | Automatic |
Deployment Modes
| Mode | Description |
|---|---|
| Windows Service | Continuous operation with configurable intervals |
| Console Application | On-demand or scheduled task execution |
| Preview Mode | Dry-run - logs actions without making changes |
AD Live Real-Time Sync Features
| Feature | Description |
|---|---|
| User Creation Detection | Automatically provisions new AD users |
| User Modification Detection | Updates user attributes on change |
| User Deletion Handling | Configurable: Disable, Delete, or Ignore |
| User Enable/Disable Tracking | Mirrors AD account status to MFA |
| OU Scope Filtering | Monitor specific OUs only |
| Group Scope Filtering | Monitor specific groups only |
| State Persistence | Survives service restarts |
| Configurable Poll Interval | 5 seconds minimum |
Multi-Configuration (Profile) Support
| Feature | Description |
|---|---|
| Multiple Sync Sources | Different AD groups/domains per profile |
| Multiple Target Tenants | Sync to different SurePassID instances |
| Per-Profile Token Settings | Different token types per user group |
| Per-Profile Role Assignment | Different admin roles per profile |
| Independent Execution | Profiles run sequentially with independent results |
Technical Specifications
System Requirements
| Component | Requirement |
|---|---|
| Operating System | Windows Server 2016, 2019, 2022, or Windows 10/11 |
| Runtime | .NET Framework 4.8 |
| Memory | 128 MB minimum |
| Disk Space | 50 MB for installation |
| Network | HTTPS access to SurePassID REST API |
| Directory Access | LDAP/LDAPS access to Active Directory |
API Requirements
| Requirement | Details |
|---|---|
| SurePassID Server | Version 2022.3 or later |
| API Permissions | FindUser, AddUser, AddToken (minimum) |
| Protocol | REST over HTTPS |
| Authentication | API Key ID + API Key |
Performance Characteristics
| Metric | Value |
|---|---|
| Users per Sync Cycle | Unlimited (tested to 10,000+) |
| AD Live Poll Interval | 5-3600 seconds (configurable) |
| Service Sync Interval | 1-1440 minutes (configurable) |
| Concurrent Profiles | Limited by available memory |
Security Features
| Feature | Details |
|---|---|
| API Authentication | Key-based (no passwords in transit) |
| Directory Communication | LDAP or LDAPS (SSL) |
| Credential Storage | Windows configuration encryption |
| Service Account | Configurable (default: Network Service) |
| Audit Logging | Full trace logging with configurable verbosity |
| Sensitive Data Masking | API keys masked in all log output |
Integration Points
| System | Protocol | Direction |
|---|---|---|
| Active Directory | LDAP / LDAPS | Inbound (read) |
| SurePassID MFA Server | REST API (HTTPS) | Outbound (read/write) |
| Windows Event Log | Native | Outbound (write) |
| File System (Trace Logs) | File I/O | Outbound (write) |
| Windows Service Manager | SCM | Bidirectional |
Supported Workflows
Standard Batch Provisioning
- Administrator adds users to an AD group
- DirectorySync detects new group members on next sync cycle
- Users are created in SurePassID with configured tokens and roles
- Activation notifications sent (if configured)
Real-Time Provisioning (AD Live)
- User account created/modified/deleted in Active Directory
- DirectorySync detects change within poll interval
- Corresponding action taken in SurePassID (create/update/disable/delete)
- State file updated for restart resilience
Multi-Tenant Provisioning
- Multiple profiles configured for different tenants
- Each profile targets different SurePassID API endpoints
- Different AD groups route users to appropriate tenants
- Independent token and role configurations per tenant
Licensing
SurePassID Directory Sync is included with SurePassID MFA Server licensing. No additional license is required for Directory Sync itself.
For Support
| Resource | Details |
|---|---|
| Documentation | Included User Guide, Administrator Guide, Release Notes |
| Support Portal | https://support.surepassid.com |
| support@surepassid.com |
The software and information contained herein are proprietary to, and comprise valuable trade secrets of, SurePassID Authentication, Inc., which intends to preserve as confidential trade secrets such software and information. Such software and information shall not be reproduced, published, or disclosed to others, or used for any purpose other than that for which it is expressly provided, without the prior written consent of SurePassID Authentication, Inc.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com