SurePassID Directory Sync Product Summary

SurePassID Authentication Server

SurePassID Directory Sync - Product Summary

Version: 2025.4 Date: January 2026 Product Category: Identity Provisioning & MFA Automation


Overview

SurePassID DirectorySync is an automated user provisioning tool that synchronizes users from enterprise identity sources into the SurePassID Multi-Factor Authentication (MFA) platform. It eliminates manual user creation, ensures consistent MFA configuration, and supports modern passwordless authentication methods including FIDO2 Passkeys and Security Keys.

DirectorySync runs as a Windows Service or console application, providing both scheduled batch synchronization and near real-time Active Directory change monitoring.


Key Capabilities

Automated User Provisioning

  • Synchronize users from Active Directory groups, LDAP filters, XML files, or real-time AD change notifications
  • Automatically create MFA accounts with pre-configured authentication tokens
  • Assign administrative roles (User, Helpdesk, Helpdesk Manager, Administrator, Super Administrator)
  • Group-based user assignment within SurePassID

Modern Authentication Support

  • FIDO2 Passkeys - Passwordless authentication with discoverable credentials
  • FIDO2 Security Keys - Second-factor hardware key authentication
  • TOTP/HOTP - Time-based and event-based one-time passwords
  • Push Notifications - Mobile app push authentication
  • SurePassID Authenticator - Native mobile authenticator support
  • Google Authenticator - Third-party TOTP compatibility

Flexible Deployment

  • Windows Service - Runs continuously with configurable sync intervals
  • Console Application - On-demand or scheduled task execution
  • Profile-Based Configuration - Multiple sync configurations in a single deployment
  • Multi-Tenant Support - Sync to multiple SurePassID instances simultaneously

Real-Time AD Monitoring (AD Live)

  • Detect and process user additions, modifications, deletions, enables, and disables
  • Configurable poll intervals (minimum 5 seconds)
  • State persistence across service restarts
  • OU and group-based monitoring scope
  • Configurable actions for deleted users (Disable, Delete, or None)

Synchronization Sources

Source Use Case
AD Group Sync all members of a specific Active Directory group
AD LDAP Filter Sync users matching a custom LDAP query
XML File Bulk import users from structured XML files
AD Live Real-time monitoring of AD changes with immediate sync

Operational Modes

Mode Description
Live Creates and modifies user accounts in SurePassID
Preview Logs what would happen without making changes

System Requirements

  • Windows Server 2016 or later
  • .NET Framework 4.8
  • Network access to SurePassID MFA REST API
  • Network access to Active Directory (for AD sync modes)
  • SurePassID API Key with FindUser, AddUser, and AddToken permissions

Architecture

Active Directory                SurePassID DirectorySync             SurePassID MFA Server
+----------------+             +------------------------+           +-------------------+
|                |             |                        |           |                   |
| AD Groups      |----------->| Sync Engine            |---------->| User Accounts     |
| LDAP Queries   |  LDAP/S    | Profile Manager        |  REST API | MFA Tokens        |
| Change Events  |            | Service Controller     |           | Roles & Groups    |
|                |             | State Manager          |           |                   |
+----------------+             +------------------------+           +-------------------+

XML Files --------------------------^

Security

  • API key-based authentication to SurePassID server
  • Supports LDAPS (LDAP over SSL) for AD communication
  • Credentials stored in encrypted configuration files
  • Service runs under Network Service or configurable service account
  • REST API trace logging available for troubleshooting (disable in production)

Installation

Installation Directory:
  C:\Program Files\SurePassID\DirectorySync\

  DirectorySync.exe           - Main application
  DirectorySync.exe.config    - Configuration file
  DirectoryClientLib.dll      - Sync engine library
  SurePassClientLibRest.dll   - REST API client
  Topshelf.dll                - Windows Service framework

Profile Directory:
  %ProgramData%\SurePassID\DirectorySync\Profiles\

Log Directory:
  <Install Path>\Trace\

Configuration Highlights

  • Single configuration file (DirectorySync.exe.config) for simple deployments
  • Profile-based configuration for complex multi-source or multi-tenant environments
  • Command-line parameter support for scripted execution
  • All parameters documented with defaults and validation

Document Description
User Guide End-user configuration and operation guide
Administrator Guide IT administrator deployment and management guide
Release Notes Version history and change log

The software and information contained herein are proprietary to, and comprise valuable trade secrets of, SurePassID Authentication, Inc., which intends to preserve as confidential trade secrets such software and information. Such software and information shall not be reproduced, published, or disclosed to others, or used for any purpose other than that for which it is expressly provided, without the prior written consent of SurePassID Authentication, Inc.

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com