SurePassID Directory Sync Product Summary
SurePassID Authentication Server
SurePassID Directory Sync - Product Summary
Version: 2025.4 Date: January 2026 Product Category: Identity Provisioning & MFA Automation
Overview
SurePassID DirectorySync is an automated user provisioning tool that synchronizes users from enterprise identity sources into the SurePassID Multi-Factor Authentication (MFA) platform. It eliminates manual user creation, ensures consistent MFA configuration, and supports modern passwordless authentication methods including FIDO2 Passkeys and Security Keys.
DirectorySync runs as a Windows Service or console application, providing both scheduled batch synchronization and near real-time Active Directory change monitoring.
Key Capabilities
Automated User Provisioning
- Synchronize users from Active Directory groups, LDAP filters, XML files, or real-time AD change notifications
- Automatically create MFA accounts with pre-configured authentication tokens
- Assign administrative roles (User, Helpdesk, Helpdesk Manager, Administrator, Super Administrator)
- Group-based user assignment within SurePassID
Modern Authentication Support
- FIDO2 Passkeys - Passwordless authentication with discoverable credentials
- FIDO2 Security Keys - Second-factor hardware key authentication
- TOTP/HOTP - Time-based and event-based one-time passwords
- Push Notifications - Mobile app push authentication
- SurePassID Authenticator - Native mobile authenticator support
- Google Authenticator - Third-party TOTP compatibility
Flexible Deployment
- Windows Service - Runs continuously with configurable sync intervals
- Console Application - On-demand or scheduled task execution
- Profile-Based Configuration - Multiple sync configurations in a single deployment
- Multi-Tenant Support - Sync to multiple SurePassID instances simultaneously
Real-Time AD Monitoring (AD Live)
- Detect and process user additions, modifications, deletions, enables, and disables
- Configurable poll intervals (minimum 5 seconds)
- State persistence across service restarts
- OU and group-based monitoring scope
- Configurable actions for deleted users (Disable, Delete, or None)
Synchronization Sources
| Source | Use Case |
|---|---|
| AD Group | Sync all members of a specific Active Directory group |
| AD LDAP Filter | Sync users matching a custom LDAP query |
| XML File | Bulk import users from structured XML files |
| AD Live | Real-time monitoring of AD changes with immediate sync |
Operational Modes
| Mode | Description |
|---|---|
| Live | Creates and modifies user accounts in SurePassID |
| Preview | Logs what would happen without making changes |
System Requirements
- Windows Server 2016 or later
- .NET Framework 4.8
- Network access to SurePassID MFA REST API
- Network access to Active Directory (for AD sync modes)
- SurePassID API Key with FindUser, AddUser, and AddToken permissions
Architecture
Active Directory SurePassID DirectorySync SurePassID MFA Server
+----------------+ +------------------------+ +-------------------+
| | | | | |
| AD Groups |----------->| Sync Engine |---------->| User Accounts |
| LDAP Queries | LDAP/S | Profile Manager | REST API | MFA Tokens |
| Change Events | | Service Controller | | Roles & Groups |
| | | State Manager | | |
+----------------+ +------------------------+ +-------------------+
XML Files --------------------------^
Security
- API key-based authentication to SurePassID server
- Supports LDAPS (LDAP over SSL) for AD communication
- Credentials stored in encrypted configuration files
- Service runs under Network Service or configurable service account
- REST API trace logging available for troubleshooting (disable in production)
Installation
Installation Directory:
C:\Program Files\SurePassID\DirectorySync\
DirectorySync.exe - Main application
DirectorySync.exe.config - Configuration file
DirectoryClientLib.dll - Sync engine library
SurePassClientLibRest.dll - REST API client
Topshelf.dll - Windows Service framework
Profile Directory:
%ProgramData%\SurePassID\DirectorySync\Profiles\
Log Directory:
<Install Path>\Trace\
Configuration Highlights
- Single configuration file (
DirectorySync.exe.config) for simple deployments - Profile-based configuration for complex multi-source or multi-tenant environments
- Command-line parameter support for scripted execution
- All parameters documented with defaults and validation
Related Documentation
| Document | Description |
|---|---|
| User Guide | End-user configuration and operation guide |
| Administrator Guide | IT administrator deployment and management guide |
| Release Notes | Version history and change log |
The software and information contained herein are proprietary to, and comprise valuable trade secrets of, SurePassID Authentication, Inc., which intends to preserve as confidential trade secrets such software and information. Such software and information shall not be reproduced, published, or disclosed to others, or used for any purpose other than that for which it is expressly provided, without the prior written consent of SurePassID Authentication, Inc.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com