SurePassID Offline Authentication Cheat Sheet

SurePassID Authentication Server

Offline Authentication — Cheat Sheet

Quick reference for administrators and end users. For the full technical detail see the full line of offline documenation included in this folder.


What it is

When the SurePassID MFA server can't be reached, you can still complete MFA at the Windows login/unlock screen using data cached on the machine:

  • Offline OTP — use a one-time passcode from your authenticator.
  • Offline FIDO2 — tap/insert your security key.

The offline cache is created the last time you signed in online. If you've never signed in online on this machine, offline sign-in won't work yet.


Online vs. offline at a glance

flowchart TD
    A[Enter username + password] --> B{Server reachable?}
    B -- Yes --> C[ONLINE: verify with server]
    C --> C2[On success: refresh offline cache]
    C2 --> OK[Signed in]
    B -- No --> D[OFFLINE]
    D --> E{What's available?}
    E -- Security key cached --> F[Tap key -> verify locally]
    E -- OTP cache present --> G[Enter OTP -> check next code]
    E -- 1FA mode --> H[Password only]
    E -- Nothing set up --> X[Cannot sign in offline<br/>go online]
    F --> OK
    G --> OK
    H --> OK

When does the offline cache update?

  • Only when you sign in online successfully. There is no background refresh.
  • Each online sign-in replaces the cache with fresh data.
  • OTP: new codes are saved only when offline mode is AllowOffLineAuth = 0 and the server returns codes. Using an offline code marks it used (it never comes back until your next online sign-in).
  • FIDO2: your key's descriptor + public key are cached on a successful online security-key sign-in (when AllowOfflineFido2 = 1). Using it offline bumps its replay counter.
  • Reconnect and sign in online to refill/refresh the cache.

Reading the status line

The login tile shows a status line telling you if you're online and, when offline, what you can use:

You'll see Meaning
Server: Online Normal online MFA.
Offline: Security key or passcode Use your security key or an OTP code.
Offline: Security key Use your security key.
Offline: Passcode required Enter an OTP code from your authenticator.
Offline: Single-factor access Password only (offline 1FA mode).
Offline: No access available No offline method set up — sign in online.

End-user quick steps

Offline OTP

  1. Enter your username and password.
  2. Open your authenticator app and read the current OTP code.
  3. Enter the OTP and submit.

If it says the cache is exhausted or the code can't be verified:

  • Reconnect to the network and sign in online once to refresh your codes.

Offline FIDO2 (security key)

  1. Enter your username and password.
  2. When prompted, insert/tap your security key and touch it.

If your key isn't accepted offline:

  • Reconnect and sign in online once so the key is cached, and confirm your admin has enabled offline FIDO2.

Admin settings (at a glance)

Set locally at HKLM\SOFTWARE\SurePassId\CredProv or via Group Policy (recommended — see docs/GPO_SETUP_GUIDE.md). Policy values override local.

Setting Values Meaning
AllowOffLineAuth 0 Offline 2FA using cached OTP codes.
1 (default) Online 2FA only (no OTP offline fallback).
2 Offline 1FA (password-only when offline).
AllowOfflineFido2 1 Offline security-key sign-in on.
0 / unset (default) Offline security-key sign-in off.
TraceOfflineCache 1 Verbose offline-cache logging (troubleshooting).

OTP offline and FIDO2 offline are controlled separately.


Security in one line

  • Caches are DPAPI-encrypted and machine-bound (can't be copied to another PC).
  • Caches hold only future OTP codes / FIDO2 public keys — never passwords or private keys.
  • OTP codes are single-use; FIDO2 counters must increase (replay/clone protection).
  • Disabling offline auth auto-clears the matching cache on next logon.

Monitoring (Event Log → source SurePassID WLM, category Security)

Event Watch for Action
Offline cache exhausted User out of offline codes Have them sign in online to refresh.
Offline cache invalidated Policy disabled offline auth Expected after a policy change; investigate if unexpected.
MFA server unreachable Connectivity loss Check network / server health.
DPAPI encryption failed Platform/DPAPI issue Investigate the machine.
FIDO2 counter regression Possible cloned key Investigate the security key.

Troubleshooting quick table

Symptom Likely cause Fix
"Offline code can't be verified" Wrong code or exhausted cache Use current OTP; if exhausted, sign in online.
No OTP prompt when offline AllowOffLineAuth not 0 Set AllowOffLineAuth = 0.
Security key rejected offline AllowOfflineFido2 off, or key not cached Enable AllowOfflineFido2 = 1; sign in online once.
Offline never works on a PC No prior online sign-in Sign in online once to build the cache.
Setting change ignored Overridden by Group Policy Change it in the GPO.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com