SurePassID Directory Sync Datasheet

SurePassID Authentication Server

SurePassID Directory Sync - Datasheet


Product At-A-Glance

SurePassID Directory Sync automates user provisioning from Active Directory and other identity sources into SurePassID MFA, eliminating manual account creation and ensuring consistent multi-factor authentication deployment across your organization.


Feature Matrix

Synchronization Sources

Feature Supported
Active Directory Group Membership Yes
Active Directory LDAP Filter Yes
Active Directory Real-Time Monitoring (AD Live) Yes
XML File Import Yes
Microsoft Entra ID (Azure AD) Planned

Authentication Token Types

Token Type OTP Push FIDO2
SurePassID Authenticator Yes Yes Yes - Push
Google Authenticator Yes - -
FIDO2 Passkey (Passwordless) - - Yes
FIDO2 Security Key (2FA) - - Yes

OTP Configuration Options

Option Values Default
OTP Algorithm Time-based (TOTP), Event-based (HOTP) Time
Time Drift Tolerance 1-60 steps 5
Event Window Size 1-100 30
Token Status on Creation Enabled or Disabled Enabled
Activation Notification None, Email, SMS None

User Provisioning Options

Option Values Default
User Role User, Helpdesk, Helpdesk Manager, Admin, Super Admin User
User Status Enabled, Disabled Enabled
User Group Any SurePassID group (none)
Token Creation Automatic or None Automatic

Deployment Modes

Mode Description
Windows Service Continuous operation with configurable intervals
Console Application On-demand or scheduled task execution
Preview Mode Dry-run - logs actions without making changes

AD Live Real-Time Sync Features

Feature Description
User Creation Detection Automatically provisions new AD users
User Modification Detection Updates user attributes on change
User Deletion Handling Configurable: Disable, Delete, or Ignore
User Enable/Disable Tracking Mirrors AD account status to MFA
OU Scope Filtering Monitor specific OUs only
Group Scope Filtering Monitor specific groups only
State Persistence Survives service restarts
Configurable Poll Interval 5 seconds minimum

Multi-Configuration (Profile) Support

Feature Description
Multiple Sync Sources Different AD groups/domains per profile
Multiple Target Tenants Sync to different SurePassID instances
Per-Profile Token Settings Different token types per user group
Per-Profile Role Assignment Different admin roles per profile
Independent Execution Profiles run sequentially with independent results

Technical Specifications

System Requirements

Component Requirement
Operating System Windows Server 2016, 2019, 2022, or Windows 10/11
Runtime .NET Framework 4.8
Memory 128 MB minimum
Disk Space 50 MB for installation
Network HTTPS access to SurePassID REST API
Directory Access LDAP/LDAPS access to Active Directory

API Requirements

Requirement Details
SurePassID Server Version 2022.3 or later
API Permissions FindUser, AddUser, AddToken (minimum)
Protocol REST over HTTPS
Authentication API Key ID + API Key

Performance Characteristics

Metric Value
Users per Sync Cycle Unlimited (tested to 10,000+)
AD Live Poll Interval 5-3600 seconds (configurable)
Service Sync Interval 1-1440 minutes (configurable)
Concurrent Profiles Limited by available memory

Security Features

Feature Details
API Authentication Key-based (no passwords in transit)
Directory Communication LDAP or LDAPS (SSL)
Credential Storage Windows configuration encryption
Service Account Configurable (default: Network Service)
Audit Logging Full trace logging with configurable verbosity
Sensitive Data Masking API keys masked in all log output

Integration Points

System Protocol Direction
Active Directory LDAP / LDAPS Inbound (read)
SurePassID MFA Server REST API (HTTPS) Outbound (read/write)
Windows Event Log Native Outbound (write)
File System (Trace Logs) File I/O Outbound (write)
Windows Service Manager SCM Bidirectional

Supported Workflows

Standard Batch Provisioning

  1. Administrator adds users to an AD group
  2. DirectorySync detects new group members on next sync cycle
  3. Users are created in SurePassID with configured tokens and roles
  4. Activation notifications sent (if configured)

Real-Time Provisioning (AD Live)

  1. User account created/modified/deleted in Active Directory
  2. DirectorySync detects change within poll interval
  3. Corresponding action taken in SurePassID (create/update/disable/delete)
  4. State file updated for restart resilience

Multi-Tenant Provisioning

  1. Multiple profiles configured for different tenants
  2. Each profile targets different SurePassID API endpoints
  3. Different AD groups route users to appropriate tenants
  4. Independent token and role configurations per tenant

Licensing

SurePassID Directory Sync is included with SurePassID MFA Server licensing. No additional license is required for Directory Sync itself.


For Support

Resource Details
Documentation Included User Guide, Administrator Guide, Release Notes
Support Portal https://support.surepassid.com
Email support@surepassid.com

The software and information contained herein are proprietary to, and comprise valuable trade secrets of, SurePassID Authentication, Inc., which intends to preserve as confidential trade secrets such software and information. Such software and information shall not be reproduced, published, or disclosed to others, or used for any purpose other than that for which it is expressly provided, without the prior written consent of SurePassID Authentication, Inc.

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com