SurePassID Authentication Server

Administration Guide

Home Page

Home — Common Tasks

HELP_HOME_TITLE

The Home folder is your starting point for account setup, system configuration, and the activity dashboard.

  • Account — open your tenant/account record to manage details and application keys
  • About — view product, version, and license information
  • Contact Support — find support contact details and phone numbers
  • Downloads — download client software, agents, and configuration files
  • Manage Dashboard — choose which dashboards appear on Home and their default display format

Using the dashboard

The Home page shows the dashboards you enabled in Manage Dashboard. Each panel summarizes a different area of activity:

  • System Alerts — recent system-level warnings and notifications
  • Users — user counts and status breakdown
  • Tokens — token/device counts by type and status
  • Authentications — authentication volume and success/failure totals
  • Authentications by Date Range — authentication trends over daily, weekly, and monthly periods
  • Authentications by API Key and IP — authentication activity grouped by application key and source IP

Display format (grid vs chart)

Each dashboard has a display-format selector so you can view the same data as a Grid or as a Chart:

  • Grid — an exact numeric table; best for precise values and copying figures
  • Chart — a visual view (bar, pie, or stacked column depending on the dashboard); best for spotting trends and proportions at a glance

Pick a format from the selector on each dashboard, then click Save Chart Type to remember your choices for the next visit. If charts are disabled for the installation, dashboards fall back to grid view.

Create an application key

  • Open Account from the Home folder
  • Click Create Application Key
  • Name the key and set its access rights
  • Copy the key value — all key usage is logged in the audit trail

Customize email or mobile delivery

  • Open Settings
  • Edit Email Settings or Mobile Settings (SMS/voice)
  • Set how long a temporary passcode stays valid
  • Save your changes

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Users

Users — Common Tasks

HELP_USERS_TITLE

The Users page lists the people who authenticate through SurePassID. From here you can add accounts, assign roles and tokens, group users, import in bulk, and run usage reports. Use the filters to narrow the list, then use the per-row action icons to manage an individual user.

  • Users — the page title; the header also shows the Delete Selected action for removing checked users
  • New — opens the user detail form to add a single user account (name, password, email, mobile phone, role, 2FA method, and token)
  • Import Users — bulk-loads users from a CSV file or from Active Directory/LDAP; map the columns and run an initial or incremental import (import any hard tokens first so serial numbers can be matched). SurePassID Active Directory Sync can automatically provision users (and tokens) and disable users as they are added, disabled, or deleted in Active Directory. You can download Active Directory Sync from the Downloads section
  • User Groups — create and manage groups of users, optionally synchronized from Active Directory/LDAP through the Local Agent
  • Usage Report — generates and downloads an Excel list of users and their status for audit and normal user-access reviews

Filters

  • Account — (super administrators only) selects which tenant/account’s users are listed
  • Filter Users — a comparator (contains, starts with, equals, etc.) plus a value to match users by name or login
  • User Role — limits the list to a specific role (administrator, user manager, help desk, user, etc.)
  • Show only VIPs — limits the list to VIP (or non-VIP) users
  • Rows to Display — the number of rows shown per page

Grid columns

  • Select (checkbox) — selects one or more rows; the header checkbox selects/clears all rows, used with Delete Selected
  • Action — the per-row action icons (see below)
  • Name — the user’s display name
  • Login Name — the user’s login identifier
  • Status — Enabled or Disabled; disabled users cannot authenticate
  • Disabled Date — the date the account was disabled (blank when active)

Grid action icons

  • Edit — opens the user detail page to view and update the account (administrators and user managers)
  • Delete — removes the user account after confirmation (administrators and user managers)
  • View — opens the user in read-only mode (help desk roles)

Common tasks

  • Click New to add a user, or use the filters to find an existing one
  • Use the row Edit icon to change details, role, or token
  • Change Status on the detail form to disable or re-enable an account, then Update
  • Select rows and use Delete Selected to remove multiple users at once

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Add User — Common Tasks

HELP_USERS_NEW_TITLE

This page creates one user account and its authentication settings.

Create the account

  • Enter User Name and Password
  • Add Email and Mobile Phone
  • Use Test SMS / Test Call to confirm delivery

Set access and 2FA

  • Choose the User Role
  • Set the 2FA requirement and assign a token
  • Click Add, then Email Login Info

Field glossary

  • Login Name — the unique user name used to sign in
  • Login Password — the account password; may be managed by your directory
  • First / Last Name — the person’s display name
  • Primary Email — where login info and email OTPs are sent
  • Alternate Email — a backup delivery address
  • Cell/Mobile Phone — used for SMS and voice OTP delivery
  • User Role — the privilege level assigned to the user (for example, standard user versus administrator). Raising a user from a lesser to a greater privilege may require a stronger, longer password
  • Time Zone — used to display dates/times for this user
  • Status — Enabled or Disabled; disabled users cannot authenticate
  • Disabled Date — when the account was disabled
  • User Added On Date — when the account was created
  • Failed Login Attempts — consecutive failures; lockout applies per policy
  • Bypass MFA — when checked, the user signs in with the first factor only (use sparingly)
  • VIP — flags a high-priority account for reporting/handling
  • SSO Mobile Activation Code — code used to activate the mobile SSO app
  • SSO Federation Name — the federated identity name used for SSO

Note: The user PIN size and digit type (numeric or alphanumeric) for non-administrative users is configured in Account Settings, not on this page.

Header actions

The links at the top-right of this page act on the current user:

  • New — start a new, blank user record
  • Update — save the current user’s changes (this reads Add when creating a new user)
  • Close — return to the user list without saving
  • Send Login Email — email the user their login information. You can specify which email template is used for the message. Note: if the user’s role is changed from a lesser privilege to a greater one, the password may need to be adjusted to meet a stronger/longer length requirement before the login can be sent
  • VPN Password Reset — reset the user’s VPN password/PIN. VPN password reset is set in Account Settings

Edit User — Common Tasks

HELP_USERS_UPDATE_TITLE

This page both adds a new user and updates an existing user selected from the grid, and manages the user’s tokens and status. When editing an existing user the action button reads Update; when creating a new user it reads Add.

Update details

  • Change the associated field — for example First Name, Last Name, Primary Email, Cell/Mobile Phone, User Role, Time Zone, or Status (see the field glossary for what each field does)
  • Click Update to save your changes

Manage the user’s tokens

  • Select the user’s token in the grid to use any of the grid actions (view, edit, delete, reset, and so on), or
  • Click Add New Token to add a new mobile or FIDO2 token to the user account

Note: Hard tokens must first be imported under Tokens and then assigned to the user.

Hint: If tokens already exist in the system, importing users via CSV can automatically assign hard tokens to those users.

Disable or re-enable

  • Change Status to enabled or disabled
  • Click Update

Field glossary

  • Login Name — the unique user name used to sign in
  • Login Password — the account password; may be managed by your directory
  • First / Last Name — the person’s display name
  • Primary Email — where login info and email OTPs are sent
  • Alternate Email — a backup delivery address
  • Cell/Mobile Phone — used for SMS and voice OTP delivery
  • User Role — the privilege level assigned to the user (for example, standard user versus administrator). Raising a user from a lesser to a greater privilege may require a stronger, longer password
  • Time Zone — used to display dates/times for this user
  • Status — Enabled or Disabled; disabled users cannot authenticate
  • Disabled Date — when the account was disabled
  • User Added On Date — when the account was created
  • Failed Login Attempts — consecutive failures; lockout applies per policy
  • Bypass MFA — when checked, the user signs in with the first factor only (use sparingly)
  • VIP — flags a high-priority account for reporting/handling
  • SSO Mobile Activation Code — code used to activate the mobile SSO app
  • SSO Federation Name — the federated identity name used for SSO

Note: The user PIN size and digit type (numeric or alphanumeric) for non-administrative users is configured in Account Settings, not on this page.

Header actions

The links at the top-right of this page act on the current user:

  • New — start a new, blank user record
  • Update — save the current user’s changes (this reads Add when creating a new user)
  • Close — return to the user list without saving
  • Send Login Email — email the user their login information. You can specify which email template is used for the message. Note: if the user’s role is changed from a lesser privilege to a greater one, the password may need to be adjusted to meet a stronger/longer length requirement before the login can be sent
  • VPN Password Reset — reset the user’s VPN password/PIN. VPN password reset is set in Account Settings

User Details (Read Only)

HELP_PAGE_PARTNERUSERDETAILREADONLY_TITLE

Header actions

The links at the top-right of this read-only page:

  • Close — return to the user list
  • Save — save any permitted changes
  • Send Login Email — email the user their login information
  • VPN Password Reset — reset the user’s VPN password/PIN

User Group Membership

HELP_PAGE_PARTNERUSERDETAILGROUPS_TITLE

The Groups page (Member Of) shows every user group in the account and lets you control which groups the selected user belongs to. Check a group to add the user to it, clear a group to remove the user, then save.

Managing membership

  • Review the list of available groups
  • Use the checkbox to include the groups the user should belong to
  • Click Update to save the membership changes, or Close to return without saving

Grid columns

  • Select (checkbox) — when checked, the user is a member of that group; the header checkbox selects/clears all rows
  • Group Name — the name of the user group
  • Group Description — a short description of the group’s purpose

Header actions

  • Update — saves the user’s group membership changes
  • Close — returns to the previous screen without saving

Import Users — Common Tasks

HELP_USERS_IMPORT_TITLE

Bulk-load users from a CSV file, either as an initial load or an incremental update.

Run an import

  • Upload your CSV file
  • Map the CSV columns to user fields
  • Start the import and review the results

Tips

  • Import any hard tokens first so serial numbers can be matched
  • Use incremental loads to add or update without duplicating accounts

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Import Users

HELP_PAGE_PARTNERUSERIMPORT_TITLE

This is the first step of the Import Users wizard. Choose where the user records come from — a CSV file or Active Directory (AD/LDAP) — provide the required details, then click Next to preview and map the fields.

CSV vs. Active Directory

  • CSV file — upload a .csv/.txt file containing the user records. This is a one-time snapshot: it adds and updates users, but does not automatically disable accounts that are missing from the file. A CSV extract from Active Directory is a convenient way to perform the initial load. On the next step you map each column to a user field
  • Active Directory (AD/LDAP) — query your directory directly. You must supply the proper AD connection details shown on the form when AD is selected: Endpoint / Domain Controller, Username and Password with directory read rights, the OU to search, and an optional Filter or group. AD is the authoritative source: an AD-driven load (especially via SurePassID Active Directory Sync, downloadable from Downloads) can automatically provision users and tokens and automatically disable or remove users as they change in Active Directory

Fields on this step

  • Import Type — selects the source (CSV file or Active Directory); the form fields change to match

  • Import File (CSV) — the .csv/.txt file to upload

  • Endpoint / Domain Controller (AD) — the directory server to connect to

  • Username / Password (AD) — credentials with permission to read the directory

  • OU (AD) — the organizational unit to search

  • Filter (AD) — an optional LDAP filter or group to limit which users are returned

  • Learn more — How do I import users into SurePassID from a CSV file and Export the members of a specific AD group to a CSV file for importing into SurePassID

Header actions

  • Next — validates your entries and continues to the preview/mapping step to complete the import
  • Close — returns to the user list without importing

Import Users — Map Fields

HELP_PAGE_PARTNERUSERIMPORT2_TITLE

This is the second step of the Import Users wizard. It shows a sample of the incoming records and lets you map each source column to a SurePassID user field before the accounts are created or updated. Review the Sample Data, set the Map Fields drop-downs, then click Next to finish.

CSV vs. Active Directory on this step

Both import sources reach this mapping step, but they populate it differently:

  • CSV file — the columns come from the uploaded .csv/.txt file. Because the file has no fixed layout, you must manually map each column (for example Column 1, Column 2, ...) to the fields listed below
  • Active Directory (AD/LDAP) — the records come from your directory query. The page shows an Active Directory Import banner describing the group or filter used, and the directory attributes are typically pre-matched to user fields so little manual mapping is needed. AD is the authoritative source: unlike CSV, an AD-driven load (especially via SurePassID Active Directory Sync, downloadable from Downloads) can automatically provision users and tokens and automatically disable or remove users as they are added, disabled, or deleted in Active Directory

Field mapping

Every field below can be mapped from a CSV column. The fields marked (not available for AD import) have no corresponding Active Directory attribute, so they appear disabled when the source is AD.

  • User Name — the unique login identifier (required)
  • First Name — the user’s given name
  • Last Name — the user’s surname
  • Email — used for login information and email OTP delivery
  • Cell Phone — used for SMS and voice OTP delivery
  • Password — the user’s login password (not available for AD import)
  • PIN — the user’s VPN/OTP PIN (not available for AD import)
  • Serial Number — the serial number of a hard token to match to the user (not available for AD import)
  • SSO Name — the user’s SSO federation name (not available for AD import)
  • Token Alias — a friendly alias for the user’s token (not available for AD import)
  • Select — leave a column unmapped when it should be ignored; each field may be mapped only once

Active Directory note: For an AD import the first three columns (User Name, First Name, Last Name) are fixed and cannot be re-mapped, while Email and Cell Phone default to their matching AD attributes and can be adjusted.

Header actions

  • Next — validates your entries and continues to the preview/mapping step to complete the import
  • Close — returns to the user list without importing

Import Users - Select Options

HELP_PAGE_PARTNERUSERIMPORT3_TITLE

This is the Import Users - Select Options step of the wizard. Here you choose import options, decide whether to create soft tokens for the imported users, assign them to a group, and control the notifications that are sent. Click Import to run the load, or Close to cancel.

Import Options

  • Import the good records even if some records have errors — imports the valid rows even when some rows contain errors, instead of rolling back the whole batch
  • Merge existing users — when a matching user already exists, update that account instead of creating a duplicate. Merge is also a powerful maintenance tool: you can re-import the same users to update their information or to resend notification emails that some users never received. For example, if a user (or a whole group of users) reports they did not get their account and mobile-token activation email, you can re-import them with a Token Type of None, include any updated fields, and resend the account/token setup notifications. This is a convenient way to correct or notify a large number of users in a single pass — another common example is a company-wide email-domain change, where you re-import the affected users (in one round or several) to fix every address at once. There are other ways to send one-off notifications; this is simply one efficient bulk approach.
  • User Group — adds every imported user to the selected group
  • Create Group — creates a new group (for AD imports this defaults to the source AD group name) and assigns the imported users to it

Create Soft Tokens

Optionally issue a software token to each imported user. When enabled, set the token parameters:

  • Token Type — the kind of token to create for each imported user. The choice controls which OTP settings apply and what activation/notification options are available: None — do not create a token. Import or update user accounts only. Use this when users already have tokens, when you only need to update user fields, or when re-importing to resend notifications (see Merge existing users). The OTP settings are disabled for this type.
  • SurePassID Authenticator (mobile) — issue a SurePassID mobile soft token; users activate it from a setup link/QR code in their notification. Additional mobile-usage options apply.
  • Google Authenticator — issue a standard TOTP soft token compatible with Google Authenticator and similar apps.
  • Cell Phone / SMS — deliver one-time passcodes to the user's mobile number by SMS.
  • FIDO — provision a FIDO authenticator; OTP length/type/window follow FIDO rules and are set automatically.

Only soft tokens are created here; hard tokens must be matched from serial numbers imported under Tokens beforehand.

  • OTP Length — the number of digits in the one-time passcode
  • OTP Type — the OTP algorithm/type used by the token
  • OTP Window Size — for time-based tokens this is the validation window (in seconds, minimum 30) used when verifying codes. For event (counter) based tokens it is the number of successive OTP values that will be searched to find a match. It is also the size of the offline cache for offline and event-based tokens: a block of pre-computed one-time passcodes that is automatically downloaded to the calling application (for example the Windows Login Manager / endpoint management client) so the user can authenticate while offline. The offline cache is automatically refreshed when the user is back online.

Note: This creates soft tokens. Hard tokens are matched from serial numbers only when they were imported under Tokens beforehand.

Send Account & Token Notification Options

  • Send notifications to the user — the master switch that enables sending messages to imported users; the delivery and template options below apply only when this is on
  • Send user account login details — emails each user their new account/login information, using the selected email template
  • Send token setup instructions — sends token activation details to each user, using the selected activation email template
  • Send the notification via — how notifications are delivered (for example email or SMS)

CSV vs. Active Directory

The options on this step apply to both sources, but their effect differs. A CSV import is a one-time load: it adds and updates the users in the file (optionally merging duplicates and creating tokens/groups) but never disables accounts that are missing from the file. An Active Directory import treats the directory as authoritative; combined with SurePassID Active Directory Sync (from Downloads) it can keep provisioning users and tokens and automatically disable or remove users as they change in Active Directory, which a CSV import cannot do.

Header actions

  • Import — runs the import using the options selected on this page
  • Close — returns to the user list without importing

Import Users Results

HELP_PAGE_PARTNERUSERIMPORT4_TITLE

This is the Import Users Results screen. The import has already run — this page reports what happened, including record counts, notification results, and an import log for any rows that failed. Review the summary, then click Close to return to the user list.

Import Summary

  • Import File Name — the source that was imported (the uploaded CSV file name, or the Active Directory query for an AD import)
  • Import Started / Import Completed — when the import began and finished
  • Total records in file — the number of records processed from the source
  • Total records added — new user accounts created
  • Total records updated — existing accounts updated (duplicates merged)
  • Total records with errors — rows that could not be imported; see the import log below

Notification results

  • Emails sent — notifications successfully sent to imported users
  • Email send errors — notifications that failed to send
  • Emails not sent (no address) — users skipped because they had no email address

Import Log

When any rows fail, a grid lists them so you can correct and re-import:

  • Record Number — the position of the row in the source
  • Result — the outcome for that row (for example User Added, User Updated, or Failed)
  • Name — the login the row was attempting to create or update
  • Serial Number — the token serial number involved, if any
  • Additional Info — the error detail explaining why the row failed
  • Notification Status — whether the user notification for that row was sent

Note: If Import the good records even if some records have errors was not selected and errors occurred, all changes are rolled back and no records are imported.

CSV vs. Active Directory

The results shown are the same regardless of source, but reflect how each import behaves. A CSV import is a one-time load, so the counts cover only the rows in the uploaded file and no accounts are disabled for being absent. An Active Directory import reflects the directory query; for ongoing, automatic provisioning and deactivation as users change in AD, use SurePassID Active Directory Sync (downloadable from Downloads) rather than repeating this manual wizard.

Header actions

  • Close — finishes the wizard and returns to the user list

User Groups — Common Tasks

HELP_USERS_GROUPS_TITLE

Organize users into groups for policy, reporting, and SSO role assignment.

Create and populate a group

  • Click New and name the group
  • Add members from the user list
  • Save the group

Keep groups in sync

  • Optionally sync from Active Directory/LDAP using the Local Agent
  • Re-run the sync when directory membership changes

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Group Details

HELP_PAGE_GROUPDETAIL_TITLE

Header actions

The links at the top-right of this page:

  • New — start a new, blank group
  • Save — save the current group
  • Close — return to the group list without saving

User Reports — Common Tasks

HELP_USERS_REPORT_TITLE

Produce reports on user accounts, tokens, and enrollment status.

Generate a report

  • Choose the report type and any filters
  • Run the report
  • Export the results for auditing or distribution

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

License Acknowledgments

HELP_PAGE_PARTNERUSERLICENSEACKNOWLEDGMENT_TITLE

System-wide (multi-tenant) — requires Super Admin role

The License Acknowledgments page reports which users have acknowledged the license/terms of use, along with when they acknowledged it and when that acknowledgment expires. Use it to audit acceptance across an account.

Using the page

  • Select an Account to report on
  • Optionally narrow the results with the Filter Users comparator and text, then apply the filter
  • Adjust the Page Size to control how many rows are shown per page
  • Review the acknowledgment grid

Field glossary

  • Account — the tenant/client whose users are listed
  • Filter Users — a comparator and value used to narrow the list by user
  • Page Size — the number of rows displayed per page
  • Company — the account/company the user belongs to
  • User — the user's display name
  • Login Name — the user's login identifier
  • Acknowledgment Date — when the user acknowledged the license/terms of use
  • Expires Date — when the acknowledgment expires and must be renewed

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Tokens

Tokens

HELP_TOKENS_TITLE

Page actions

A token (also called a device) is the authenticator that generates or receives the one-time passcodes used for multi-factor authentication — hardware OTP fobs and display cards, soft tokens and mobile authenticator apps, and OATH TOTP/HOTP tokens. FIDO2/WebAuthn security keys and passkeys are also managed as tokens. Tokens in inventory can be unassigned until you assign them to a user. This page lists the tokens in your account so you can create, assign, import, filter, and maintain them.

SurePassID supports both SHA-1 and SHA-2 (SHA-256) OATH tokens, so hard and soft tokens using either hash algorithm can be imported, assigned, and validated.

Action bar

  • New — create a new token/device
  • Assign Devices — assign one or more unassigned tokens from inventory to users
  • Delete Selected — remove the tokens checked in the grid

Filters

Use the filters above the grid to narrow the list; they are remembered for the session.

  • Client — (super administrators only) limit the list to a specific tenant/account
  • Batch — show only tokens that belong to a specific import/provisioning batch
  • Type — filter by token/device type
  • Status / Device Status — filter by assignment or lifecycle status
  • Serial Number — match on serial number; the comparator dropdown controls how the text is matched (for example equals, contains, or starts with)
  • Assigned User — match on the assigned user; the comparator dropdown controls how the text is matched
  • Page Size — the number of tokens shown per page in the grid

Token grid

Each row is a single token. Click a column header to sort, and use the check box in the first column to select rows for assignment or deletion. Click a token to open its detail page.

  • (check box) — selects the row so it can be assigned or removed
  • Serial Number — the token's unique serial number
  • Status — the token's current status
  • Type — the token/device type
  • Assigned User — the user the token is assigned to, if any
  • OTP Type — the one-time passcode algorithm the token uses

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

New / Assign Token — Common Tasks

HELP_TOKENS_NEW_TITLE

Create a token or assign an existing device to a user.

Assign a hard token

  • Make sure the token’s serial number was imported first
  • Use Assign Devices and match the serial number
  • Bind it to the user and save

Provision a soft token

  • Create the token for the user
  • Deliver the enrollment (QR code or link)

Token Assignment

  • Assigned To — the user the token is assigned to

Token Information

  • Token Group — the group/batch the token belongs to
  • Status — New, Enabled, or Disabled. New tokens (created or imported) cannot be used until enabled; a token is disabled by the administrator or automatically after it exceeds the maximum failed authentication requests
  • Printed Serial Number — the serial number printed on the physical token
  • Internal Serial Number — the system’s internal serial number for the token
  • User Defined Token Name — a friendly alias for the token
  • Token Id — the unique identifier for the token; it can be used to manually add the token to an authenticator app. While the token has not yet been activated, activation icons appear to the right of the Token Id: Send activation email — email the activation to the assigned user
  • Send activation SMS — text the activation to the assigned user
  • Show/Hide QR code — display the activation QR code for the user to scan
  • Show/Hide Instant Activation link — reveal the Instant Activation Link the user can tap on the enrolled device

Token Type and Settings

  • Token Type — the kind of soft token (for example SurePassID Authenticator, Google Authenticator, Desktop, SMS)
  • Mobile Notification Service — the push notification service used by the mobile token
  • Mobile Device Name — the name of the mobile device the token is installed on
  • Manufacturer — the manufacturer of the token
  • OTP Type — the one-time passcode algorithm (Event/Time/Time+PIN/Challenge Response OATH, CSC, offline codes)
  • OTP Length — the number of digits in the passcode
  • OTP Window Size — the validation window; for event-based OATH tokens this is the rolling passcode window (typically 30)
  • PIN — the PIN used by Time + PIN tokens
  • Initial Counter — the starting event counter for event-based tokens
  • Provision Expiration Date — the date after which the token can no longer be provisioned (by default three days from creation); scanning the QR code after this date will not proceed
  • Time Drift (time step units) — the initial time drift (in seconds) for a time-based token; not used for event-based tokens
  • Shared From Token — the token this one was shared/linked from, if any

Status & history

  • Date Provisioned — when the token was provisioned
  • Failed Token Requests — the current number of failed validations, including failed or rejected push authentications
  • Last Authentication Date — when the token last authenticated successfully
  • Current Counter — the current event counter used to keep an event-based token in sync

Registered Security Keys

  • Register Security Key For Portal Access — enrolls a FIDO2/WebAuthn security key or passkey for signing in to the portal

Token Detail

HELP_TOKENS_DETAIL_TITLE

The Token Detail page creates a new soft token or views and edits an existing token. The header reads Add Token when creating and Update Token when editing. Fields are grouped into Token Assignment, Token Information, Token Type and Settings, and Registered Security Keys. Fill in the fields, then use Add/Update to save, or the other header actions to operate on the token.

Token Assignment

  • Assigned To — the user the token is assigned to

Token Information

  • Token Group — the group/batch the token belongs to
  • Status — New, Enabled, or Disabled. New tokens (created or imported) cannot be used until enabled; a token is disabled by the administrator or automatically after it exceeds the maximum failed authentication requests
  • Printed Serial Number — the serial number printed on the physical token
  • Internal Serial Number — the system’s internal serial number for the token
  • User Defined Token Name — a friendly alias for the token
  • Token Id — the unique identifier for the token; it can be used to manually add the token to an authenticator app. While the token has not yet been activated, activation icons appear to the right of the Token Id: Send activation email — email the activation to the assigned user
  • Send activation SMS — text the activation to the assigned user
  • Show/Hide QR code — display the activation QR code for the user to scan
  • Show/Hide Instant Activation link — reveal the Instant Activation Link the user can tap on the enrolled device

Token Type and Settings

  • Token Type — the kind of soft token (for example SurePassID Authenticator, Google Authenticator, Desktop, SMS)
  • Mobile Notification Service — the push notification service used by the mobile token
  • Mobile Device Name — the name of the mobile device the token is installed on
  • Manufacturer — the manufacturer of the token
  • OTP Type — the one-time passcode algorithm (Event/Time/Time+PIN/Challenge Response OATH, CSC, offline codes)
  • OTP Length — the number of digits in the passcode
  • OTP Window Size — the validation window; for event-based OATH tokens this is the rolling passcode window (typically 30)
  • PIN — the PIN used by Time + PIN tokens
  • Initial Counter — the starting event counter for event-based tokens
  • Provision Expiration Date — the date after which the token can no longer be provisioned (by default three days from creation); scanning the QR code after this date will not proceed
  • Time Drift (time step units) — the initial time drift (in seconds) for a time-based token; not used for event-based tokens
  • Shared From Token — the token this one was shared/linked from, if any

Status & history

  • Date Provisioned — when the token was provisioned
  • Failed Token Requests — the current number of failed validations, including failed or rejected push authentications
  • Last Authentication Date — when the token last authenticated successfully
  • Current Counter — the current event counter used to keep an event-based token in sync

Registered Security Keys

  • Register Security Key For Portal Access — enrolls a FIDO2/WebAuthn security key or passkey for signing in to the portal

Check One Time Passcode

HELP_TOKENS_CHECKOTP_TITLE

The Check One Time Passcode page lets you verify that a token is producing valid passcodes — for example when a user reports that their code is being rejected. Enter the code the user sees on their token and confirm whether it validates. Any result is also written to the Audit Trail.

Fields

  • Printed Serial Number — the serial number of the token being checked (read-only)
  • One Time Passcode — enter the one-time passcode from the token; the expected number of digits for this token is shown in the label

How to check a passcode

  • Enter the one-time passcode into the One Time Passcode field
  • Click Check
  • The page shows the result — OTP is valid on success, or OTP is NOT valid with a reason (see the Audit Trail for more detail)
  • Click Close to return to the token list

Tip: if the token repeatedly fails to validate, use Synchronize on the token to bring an out-of-sync event- or time-based token back into range.

Header actions

The buttons on this page act on the passcode you enter:

  • Check — validate the entered one-time passcode against the token and display the result
  • Close — return to the token list without checking

Create Temporary Passcode

HELP_TOKENS_TEMPOTP_TITLE

The Create Temporary Passcode page generates a one-time temporary passcode for the selected token that stays valid for a period you choose. Use it when a user cannot access their normal token — for example a lost phone or a hardware token left at home — so they can still sign in until the temporary passcode expires.

Fields

  • Password is valid for: — how long the temporary passcode remains usable, set as a combination of Hours, Minutes and Seconds. The total duration must be at least 30 seconds.

How to create a temporary passcode

  • Set the validity period using the Hours, Minutes and Seconds lists (30 seconds minimum)
  • Click Create Passcode
  • The generated passcode is displayed along with the date and time it is valid until
  • Click Copy OTP to copy the passcode to the clipboard so you can give it to the user
  • Click Close to return to the token list

Note: the temporary passcode works in addition to the token’s normal passcodes and stops working automatically once it expires.

Header actions

The buttons on this page create and share the temporary passcode:

  • Create Passcode — generate a temporary passcode valid for the selected duration
  • Copy OTP — copy the generated passcode to the clipboard
  • Close — return to the token list

Assign Tokens

HELP_PAGE_DEVICEASSIGN_TITLE

The Assign Tokens page binds a token to a user so it can be used for authentication. Enter the token serial number and the user to assign it to, choose the assignment options, and optionally email the activation details to the user.

Fields

  • Token Serial Number: — the printed serial number of the token to assign
  • Assigned To User: — the user who will own the token
  • Allow assigned tokens to be reassigned: — when checked, a token that is already assigned to another user can be reassigned; otherwise assigning an already-assigned token is blocked
  • Change token status to Enabled: — when checked, the token is enabled as part of the assignment so it can be used immediately
  • Email token activation to the user: — when checked, an activation email is sent to the user; selecting this reveals the Email Template option
  • Email Template: — the email template used for the activation message

How to assign a token

  • Enter the Token Serial Number and the Assigned To User
  • Optionally use Check Assignment to see whether the token is already assigned
  • Set the assignment options (reassignment, enable, email activation) as needed
  • Click Assign Tokens to complete the assignment, or Close to cancel

Note: assignment fails if the serial number is blank or invalid, or if the tenant has reached its maximum number of tokens. The assignment is recorded in the Audit Trail.

Header actions

The buttons on this page check and complete the assignment:

  • Assign Tokens — assign the token to the specified user using the selected options
  • Check Assignment — report whether the entered token is currently assigned and to whom, without making changes
  • Close — return to the previous page without assigning the token

Move Token

HELP_PAGE_DEVICEMOVE_TITLE

The Move Token page transfers a token from its current tenant to a different tenant. Moving a token preserves the token itself but disables it until it is assigned to a user and activated in the destination tenant. Optionally you can assign the token to a user in the destination tenant as part of the move.

Fields

  • Token Serial Number: — the printed serial number of the token being moved (read-only)
  • Source Tenant: — the tenant that currently owns the token (read-only)
  • Destination Tenant: — the tenant to move the token to. This must be different from the source tenant.
  • Assign To User: — optionally, the user in the destination tenant to assign the token to after the move

How to move a token

  • Confirm the Token Serial Number and Source Tenant are correct
  • Select a Destination Tenant different from the source
  • Optionally enter an Assign To User in the destination tenant
  • Click Move Token to complete the move, or Close to cancel

Note: after a successful move the token is disabled until it is assigned and activated in the new tenant. The move is recorded in the Audit Trail. A move fails if the destination tenant is the same as the source or if the destination tenant has reached its maximum number of tokens.

Header actions

The buttons on this page complete or cancel the move:

  • Move Token — move the token to the selected destination tenant (and assigned user, if provided)
  • Close — return to the previous page without moving the token

Create Shared Token

HELP_PAGE_DEVICEDUPLICATE_TITLE

The Create Shared Token page lets you share an existing (real) token with another user so more than one user can authenticate with the same physical token. Choose the token to share and the user to share it with, then create the shared token.

Fields

  • Token To Share: — the printed serial number of the real token you want to share
  • Share Token With: — the user who will receive the shared copy of the token
  • Search: — type part of a user name to filter the Share Token With list and quickly locate the target user

Steps

  • Enter the Token To Share serial number
  • Use Search to find and select the user under Share Token With
  • Click Share to create the shared token, or Close to cancel

Note: the serial number must be a valid, existing token. You can only share a real token — if the token you select is already a shared token, it is automatically converted to a real token before sharing. On success a confirmation shows the new shared token serial number and the user it was assigned to.

Header actions

The buttons on this page complete or cancel token sharing:

  • Share — create the shared token and assign it to the selected user. On success a confirmation shows the new shared token serial number and the user it was assigned to.
  • Close — return to the token list without creating a shared token

Import Tokens — Common Tasks

HELP_TOKENS_IMPORT_TITLE

Load hard-token seed records so their serial numbers can be assigned to users.

Import a seed file

  • Upload the seed file from your token vendor
  • Confirm the token type and record count
  • Complete the import

Import tokens before importing users who already hold those tokens.

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Import Hard Tokens — Specify File

HELP_PAGE_DEVICEIMPORT_TITLE

This is the first step of the Import Hard Tokens wizard. Physical tokens such as display cards, key fobs, USB devices, and smart cards are manufactured with secret keys embedded at the factory. Those secrets are supplied separately with the tokens in a seed file (also called a key container), and must be imported into SurePassID before the tokens' serial numbers can be assigned to users.

Import a seed file

  • Select the seed file supplied with your tokens
  • Specify its format and encryption
  • Click Next to preview/map the records and complete the import

Fields

  • Import File — press Browse and select the seed file to import. Generic CSV files must use a .csv or .txt extension; OATH 1.2 PSKC files must use an .xml extension

  • Import File Format — the layout of the seed file: Generic CSV — a comma-separated file; after uploading you map each column to a SurePassID token field on the next step

  • OATH 1.2 PSKC — the OATH standard XML key-container format; fields are read directly from the file

  • Import File Encryption — the encryption format of the import file. The system assumes zero trailing padding. Choose the value that matches how your vendor encrypted the seed file: None, AES-128, AES-192, AES-256, PBE-AES-128, PBE-AES-192, or PBE-AES-256

Good to know

  • Import hard tokens before importing the users who will hold them, so the users' import file can reference the token serial numbers
  • Imported tokens start with a status of New and cannot be used until they are enabled
  • Token import can automatically create a token group for the imported tokens; if you set an import option incorrectly you can delete that group to remove all the tokens and import again

Header actions

  • Next — validates the file, format, and encryption and continues to the preview/mapping step
  • Close — returns to the token list without importing

Import Hard Tokens — Map Fields

HELP_PAGE_DEVICEIMPORT2_TITLE

This is the second step of the Import Hard Tokens wizard. The top Sample Data From Import File grid previews the rows from your seed file, and the bottom Map Import Data section lets you map each column of the file to a SurePassID token field. Set the drop-downs, then click Next to continue to the import options.

Sample Data grid

The grid shows a preview of the incoming records so you can see which data sits in each column before mapping it. Each grid column corresponds to one Column 1, Column 2, ... drop-down in the mapping section below. Long values are truncated in the preview for readability only; the full value is still imported.

Ignore first record checkbox

Ignore first record in the import file — enable this when the first row of your file is a header row (column titles) rather than token data, so it is skipped during the import.

Field mapping

For a Generic CSV file, map each column to one of the following SurePassID token fields (each field may be mapped only once):

  • ---Select--- — leave a column unmapped so it is ignored
  • RFID Tag — the token's RFID tag value, if present
  • Printed Serial Number — the serial number printed on the token, used to identify and assign it
  • Maximum Number Of Uses — an optional usage cap for the token
  • Secret Key (Hex) — the token seed in hexadecimal. A secret key column (Hex or Base64) is required, and only one of the two may be mapped
  • Secret Key (Base64) — the token seed in Base64. Use this instead of Hex when your vendor supplies the seed encoded in Base64
  • Starting Counter /T0 — the initial counter (event-based tokens) or T0 epoch start (time-based tokens)
  • Expiration Date — the date the token expires, if provided

For a Matrix CSV file the columns are fixed and pre-mapped to Printed Serial Number, Matrix Values, Matrix Rows, Matrix Columns, and Matrix Row Headers. For OATH 1.2 PSKC files the fields are read directly from the XML key container, so no manual mapping is required.

SHA-1 and SHA-2 tokens

SurePassID supports both SHA-1 and SHA-2 (SHA-256) OATH tokens. As long as the seed file provides the correct secret key and OATH parameters, tokens using either hash algorithm are imported and validated correctly.

Header actions

  • Next — validates your column mappings and continues to the import options step
  • Close — cancels the import and returns to the token list

Import Hard Tokens - Select Options

HELP_PAGE_DEVICEIMPORT3_TITLE

This is the final step of the Import Hard Tokens wizard. Here you set the token parameters that apply to every token being imported, then click Import to create the tokens (or Close to cancel). These settings must match how the physical tokens were manufactured; if they do not, the imported tokens will not generate matching one-time passcodes.

Fields

  • Account — (super administrators only) the tenant/account that will own the imported tokens
  • Manufacturer — the vendor that manufactured the tokens
  • Token Type — the kind of hard token being imported (for example FOB, Treo, or electronic display card)
  • OTP Type — the type of passcode the token produces (event/counter based, time based, etc.)
  • OTP Length — the number of digits the token displays
  • OTP HMAC Hash — the OATH hash algorithm the token uses. SurePassID supports SHA1, SHA256, and SHA512 (that is, both SHA-1 and SHA-2 tokens). This must match the algorithm the token was programmed with
  • OTP Window Size — for event (counter) based tokens this is the number of successive OTP values searched to find a match; for time based tokens it is the length of each time step in seconds (typically 30 or 60). The minimum allowed value is 30. The field defaults to 60
  • Time Drift (time step units) — the initial time drift for time-based tokens, expressed in time-step units. Not used for event-based tokens. It defaults to the system's configured token drift
  • Status — the initial status for the imported tokens (New, Enabled, or Disabled). Tokens cannot be used until they are Enabled
  • User Defined Token Name — an optional alias applied to the imported tokens to make them easier to identify
  • Notes — free-form information recorded with this import

Good to know

  • The OTP Window Size, OTP Type, and OTP HMAC Hash must match the token's factory programming or authentication will fail
  • Imported tokens start in inventory and can be assigned to users afterwards from the Tokens page
  • The import can create a token group; if an option was set incorrectly you can delete that group to remove all the tokens and import again

Header actions

  • Import — validates the options and imports the tokens using the settings above
  • Close — cancels the import and returns to the token list

Import Results

HELP_PAGE_DEVICEIMPORT4_TITLE

This is the final step of the Import Hard Tokens wizard. It summarizes what happened when the tokens in your file were processed. Review the summary and error log, then click Close to return to the Tokens page.

Import summary

  • Import Status — the overall outcome of the import: Success (all tokens added), success with errors, or errors. When errors prevent the import, all changes are rolled back and no tokens are imported
  • Import File Name — the name of the file that was processed
  • Records in import file — the total number of records read from the file
  • Tokens added — the number of token records that were successfully imported
  • Tokens with errors — the number of token records that could not be imported because of validation errors
  • Total tokens in file — the total number of token records the file contained

Import Error Log

When any records fail, the Import Error Log table lists each problem record so you can correct the source file and import again. Each row shows:

  • Record Number — the line/record in the import file that caused the error
  • Result — the outcome for that record
  • Serial Number — the token serial number from that record
  • Additional Info — the reason the record failed (for example, a duplicate serial number or an invalid secret key length)

Good to know

  • The import is all-or-nothing: if any record has errors, all changes are rolled back and no tokens are imported. Fix the records listed in the error log and run the import again
  • Successfully imported tokens are placed in inventory and can be assigned to users from the Tokens page
  • If the import created a token group with incorrect options, delete that group to remove all the tokens and import again

Header actions

  • Download Log — downloads the import error log so you can review or share the details of any failed records
  • Close — clears the import session and returns to the token list

Export Tokens — Common Tasks

HELP_TOKENS_EXPORT_TITLE

Export token inventory and assignment data for reporting or migration.

Export

  • Apply any filters for the tokens you want
  • Click Export
  • Save the file

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Token Groups

HELP_TOKENS_BATCHES_TITLE

The Token Groups page lists the token groups (batches) for the selected account. Token groups are a logical way of grouping physical tokens together so you can import, manage, report on, and decommission large numbers of tokens as a set. From here you can create a new group, open a group to view or edit the tokens it contains, and delete groups that are no longer needed.

Header actions

  • New — create a new, empty token group (opens the Token Group page)
  • Delete Selected — delete every group whose checkbox is ticked; a confirmation lists the groups (and shows how many tokens will be affected) before the delete runs

Filter

  • Account: — (super administrators only) choose which client/tenant's token groups to display; changing it reloads the grid for that account

Token Groups grid

Each row is a token group with these columns:

  • (checkbox) — select groups for Delete Selected; the header checkbox selects or clears all rows
  • Action — per-row Edit (open the group) and Delete (remove that single group) icons
  • Description — the name of the token group
  • Tokens — the number of tokens currently in the group
  • Created On — the date and time the group was created
  • Last Updated — the date and time the group was last changed
  • Last Updated By — the administrator who last changed the group

Common tasks

  • Click New to create a group, or click a row's Edit icon to open an existing group and manage its tokens
  • (Super admins) pick an Account to view another client's groups
  • Use a row's Delete icon, or tick several rows and click Delete Selected, to remove groups

Note: deleting a token group can also delete all the tokens in it. This is useful for correcting a bad import or decommissioning old tokens, but confirm the tokens are no longer needed before deleting the group.

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Token Group

HELP_PAGE_BATCHDETAIL_TITLE

The Token Group page lets you add or edit a token group and review the tokens it contains. Token groups are a logical way of grouping physical tokens; you do not have to use them, but they make it easier to manage large numbers of tokens — for example, to bulk-import tokens, decommission old tokens, or view all tokens from a particular manufacturer or of a particular type. Certain functions such as Token Import can automatically create a token group and place all imported tokens in it.

Fields

  • Description: — the name of the token group; this is the value you edit and save
  • Notes: — free-form comments describing the group’s purpose
  • Tokens In Group: — the number of tokens currently in the group (read-only)
  • Created On: — the date and time the group was created (read-only)
  • Last Updated On: — the date and time the group was last changed (read-only)
  • Last Updated By: — the administrator who last changed the group (read-only)

Tokens grid

When editing an existing group, the Tokens grid lists the tokens in the group with these columns:

  • Serial Number — the printed serial number of the token
  • User Defined Name — the friendly name assigned to the token
  • Status — the current token status
  • Token Type — the type of OTP device
  • Last OTP Validation — the last time the token successfully validated an OTP
  • OTP Type — the one-time password algorithm the token uses
  • Digits — the OTP length (number of digits)

Common tasks

  • Enter or update the Description and Notes
  • Click Add or Update to save the group, or Close to return without saving
  • In an existing group, use the grid row actions to edit or delete individual tokens, or check tokens and use Delete Selected to remove several at once
  • Use Add New Token to create a token directly in this group

Note: deleting a token group can delete all the tokens in it. This is useful when correcting a bad import or decommissioning old tokens, but be sure the tokens are no longer needed before deleting the group.

Header actions

The links at the top-right of this page:

  • New — start a new, blank token group
  • Add New Token — create a token directly in this group (shown when editing an existing group)
  • Add / Update — save the token group (Add for a new group, Update for an existing one)
  • Close — return to the list without saving

Token Reports — Common Tasks

HELP_TOKENS_REPORT_TITLE

Report on token inventory, assignments, and usage.

Generate a report

  • Choose the report type and filters
  • Run the report
  • Export the results

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Audit

Audit Trail — Common Tasks

HELP_AUDIT_TITLE

The audit trail records every authentication and administrative action, tagged Success, Warning, Informational, Action Required, or System Error.

Investigate a failed login

  • Set Filter Users to the affected account
  • Set Severity to Warning or Action Required
  • Pick a Start/End Date range
  • Read the Result Message, Result Code, and IP columns

Export the log

  • Apply the filters you want to capture
  • Click Export Audit Log in the action bar
  • Save the file for reporting or archival

Control retention

  • Check the items to remove in the list
  • Click Delete Checked Items, or Empty Log to clear everything

Note: Audit records you delete here are removed from the live log, but they can still be recovered at a later date from database backups. Deleting entries from this page does not permanently destroy them if a backup of the database exists.

Filter section

Use the filters at the top of the page to narrow the audit records. Filters are remembered for the session; click Reset Filters to clear them.

  • Start Date / End Date — limit the log to actions that occurred within the selected date range
  • Severity — show only records of a given severity (Success, Warning, Informational, Action Required, or System Error)
  • Filter Users — match a user account; the accompanying comparator dropdown controls how the text is matched (for example equals, contains, or starts with)
  • Action — restrict the log to a specific audited action (for example a login, a token operation, or an administrative change)
  • API Key — show only records generated by a specific API key
  • IP Address — show only records originating from a specific IP address
  • Account — (super administrators only) limit the log to a specific tenant/account
  • Page Size — the number of records shown per page in the grid
  • Reset Filters — clears all filters and returns to the default view

Audit grid

Each row is a single audited event. Click a column header to sort, and use the check box in the first column to select rows for deletion. Columns can be reordered and resized.

  • (check box) — selects the row so it can be removed with Delete Checked Items
  • Severity — the severity indicator for the event
  • Full Name — the display name of the user associated with the event
  • Login Name — the login name of the user associated with the event
  • SSO Identity — the single sign-on identity involved (hidden by default; can be shown by reordering columns)
  • Date — the date and time the event occurred, adjusted to the display time zone
  • Action — the audited action that was performed
  • Result — the result message describing the outcome of the action
  • Result Code — the numeric/status code returned for the action
  • IPv4 / IPv6 — the IP address the request originated from
  • API Key Name — the name of the API key used, when the event came through an API call
  • Request Data — additional request detail captured for the event

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Export Audit Log — Common Tasks

HELP_AUDIT_EXPORT_TITLE

Export audit records for reporting, archival, or SIEM ingestion.

Export the log

  • Apply the filters you want to capture (user, severity, date range)
  • Click Export Audit Log
  • Save the file for reporting or archival

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

SSO

Single Sign-On — Common Tasks

HELP_SSO_TITLE

SurePassID SSO is role- and policy-based. You register SAML 2.0 apps, group users into roles, and attach policies that govern access app by app.

Add an application

  • Click New in the applications grid
  • Start from a preloaded template (50+ ship built in) or a custom app
  • Enter the SAML settings the app requires
  • Save the application

Grant a group access to an app

  • Create a role for the user group
  • Attach a policy that permits that role on the app
  • Assign users to the role

Remove access

  • Open the application
  • Remove the role from its policy, or delete the app entirely

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

SSO Policies — Common Tasks

HELP_SSO_POLICIES_TITLE

SSO policies govern access to your SAML 2.0 applications by binding apps and roles together and specifying what happens when a policy rule is violated. This page lists the SSO policies defined for the account. Use it to create, edit, copy, or delete policies.

Header actions

  • New — creates a new SSO policy
  • Delete Selected — deletes all policies whose check box is selected in the grid; a confirmation prompt lists what will be removed

Policies grid

Each row is one SSO policy. Grid columns:

  • (check box) — selects the policy so it can be removed with Delete Selected; the header check box selects or clears all rows
  • Action — per-row actions to Edit, Delete, or Copy the policy
  • Policy Name — the name of the policy
  • Policy Violation Action — the action taken when a policy rule is violated: Log (access permitted, violation logged in the audit trail), Enforce (access denied, violation logged), or Ignore (access permitted and the policy is ignored)

Good to know

  • Open a policy (Edit) to set its Policy Violation Action, Time Restriction, Access IP rules, and the apps and roles bound to it
  • Use Copy to base a new policy on an existing one
  • Policies work together with Roles; a role grants access to an app only when a policy binds them

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

SSO Policy Details

HELP_PAGE_CLIENTSSOPOLICYDETAIL_TITLE

Create or edit an SSO access policy. A policy binds apps and roles together, controls when and from where users may sign in, and specifies what happens when a policy rule is violated. Click Add (new policy) or Update (existing policy) to save, or Close to leave without saving.

Policy Settings

  • Policy Name — the name of this policy (required and must be unique)
  • Policy Violation Action / App Policy Enforcement — the action taken when a policy rule is violated: Log (user is permitted access, but the violation is logged in the audit trail), Enforce (user is not permitted access and the violation is logged), or Ignore (user is permitted access and the policy is ignored)

Access Restrictions (Time Restriction Policy)

Set the allowable times this policy may be used. For each day of the week (Monday through Sunday) choose an Access Type. When the access type is set to a specific time range, the Start Time and End Time (hours, minutes, AM/PM) become enabled so you can define the permitted window for that day.

IP Restrictions (Access IP Policy)

  • Restrict IP / Limit access — when unchecked, access is allowed from any IP; when checked, access is limited to only the IP addresses you specify
  • IP addresses — enter the allowable IP addresses, one per line. You can use wildcards by limiting the trailing octets, and specify multiple addresses by putting each on its own line

Apps and Roles Restrictions

Specify the apps and roles that are bound to this policy.

  • Policy Apps grid — check the SSO applications this policy applies to; the header check box selects or clears all rows. Columns: the select check box and Apps (the application name)
  • Policy Roles grid — check the roles this policy grants access to; the header check box selects or clears all rows. Columns: the select check box and Roles (the role name)

Good to know

  • A role grants access to an app only when a policy binds the two together, so a policy needs at least one app and one role to be effective
  • Use the time and IP restrictions to further limit when and from where members may access the bound apps

Header actions

The links at the top-right of this page:

  • New — start a new, blank SSO policy
  • Add / Update — the action button reads Add when creating a new policy and Update when editing an existing one; it saves the current policy
  • Close — return without saving

SSO Roles — Common Tasks

HELP_SSO_ROLES_TITLE

SSO roles group users by function so that policies can grant those users access to your SAML 2.0 applications. This page lists the SSO roles defined for the account. Use it to create, edit, copy, or delete roles.

Header actions

  • New — creates a new SSO role
  • Delete Selected — deletes all roles whose check box is selected in the grid; a confirmation prompt lists what will be removed

Roles grid

Each row is one SSO role. Grid columns:

  • (check box) — selects the role so it can be removed with Delete Selected; the header check box selects or clears all rows
  • Action — per-row actions to Edit, Delete, or Copy the role
  • Role Name — the name of the role
  • Role Description — a short description of the role's purpose

Good to know

  • Open a role (Edit) to assign the users that belong to it
  • Use Copy to base a new role on an existing one
  • A role grants app access only when a Policy binds the role to an application

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

SSO Role Details

HELP_PAGE_CLIENTSSOROLEDETAIL_TITLE

Create or edit an SSO role. A role groups users by function so that policies can grant those users access to your SAML 2.0 applications. Click Add (new role) or Update (existing role) to save, or Close to leave without saving.

Role Settings

  • Name — the name of the role (required, must be unique, and validated for allowed characters)
  • Description — a short description of the role's purpose

Role Users grid

The Role Users grid lists the users that belong to this role. Check the users to include; the header check box selects or clears all rows. Grid columns:

  • (check box) — selects the user as a member of this role; the header check box selects or clears all rows
  • Role Users — indicates the user's membership in the role
  • Login Name — the user's login name
  • Status — the user's account status

Good to know

  • A role grants app access only when an SSO Policy binds the role to an application
  • Add the members here, then reference this role from a policy to give those members access to the policy's apps

Header actions

The links at the top-right of this page:

  • New — start a new, blank SSO role
  • Add / Update — the action button reads Add when creating a new role and Update when editing an existing one; it saves the current role
  • Close — return without saving

Application Settings — Common Tasks

HELP_SSO_APPSETTINGS_TITLE

Configure the SAML 2.0 settings for a single sign-on application.

Configure an application

  • Start from a preloaded template or a custom app
  • Enter the SAML endpoints, identifiers, and certificate settings
  • Map user attributes the app requires
  • Save, then attach roles and policies

Field glossary

  • Application Name — the display name of the SSO application
  • Entity ID / Issuer — the SAML identifier for the service provider
  • ACS URL — the Assertion Consumer Service endpoint the SAML response is posted to
  • Name ID Format — the identifier format sent to the app (email, persistent, etc.)
  • Certificate — the signing certificate used for SAML assertions
  • Attribute Mapping — which user attributes are sent as SAML claims
  • Relay State — the optional deep-link target after login

Header actions

The links at the top-right of this page:

  • Save — save the SSO application settings
  • Close — return without saving

Tenant Settings

Client — Account Details

HELP_CLIENT_DETAIL_TITLE

Tenant setting — requires Admin or Super Admin role

This form holds the core account record for a client/tenant: its name and domain, application keys, product license, IP-based authentication rules, portal MFA options, and status.

Common tasks

  • Enter the Name and Domain that identify the tenant
  • Set the License Key and confirm the License Type
  • Restrict access with Authenticate Calling IP Address rules if required
  • Choose the allowed MFA Options For Portal Login
  • Click Update to save, or New Application Key to generate an API key

Section glossary

The form is divided into collapsible sections:

  • Account Information — the tenant’s display name, domain name, printed serial-number prefix, and encryption type used to identify and route the account
  • Application Keys — the API/application keys the tenant uses to access the authentication server, including creating new keys and removing existing ones
  • Product License — the license key that sets the tenant’s capacity and enabled features
  • SurePassID Licensing — the license type that determines the tenant’s licensing model
  • Authenticate Calling IP Address — optional server IP address rules that are validated when authenticating
  • MFA Options For Portal Login — which second-factor methods (SMS, email, voice OTP and push) users of this tenant may use on the portal
  • Status — the tenant’s state plus the last-updated date and administrator

Header actions

The links at the top-right of this page:

  • Update — save the client/tenant (shows Add when creating a new client)
  • Close — return to the client list without saving
  • New Application Key — create a new API key for this client

Clients — Common Tasks

HELP_CLIENTS_TITLE

Tenant setting — requires Admin or Super Admin role

As a super administrator you manage tenant (client) accounts, each isolated with its own users, tokens, and settings.

Onboard a new tenant

  • Click New Account Wizard to create a client
  • Configure its account and security settings
  • Open the client and add its first administrator
  • Provision that tenant’s users and tokens

Switch into a client

  • Select the client in the list
  • Drill in to manage its users, tokens, and settings directly
  • License Acknowledgments — review and record acknowledgment of the product license terms
  • Edit Terms of Use — edit the Terms of Use presented to users of your tenants
  • True Up Report Generator — generate a license true-up report that reconciles licensed vs. actual usage across clients

Grid columns

  • Select (checkbox) — selects one or more rows; the header checkbox selects/clears all rows, used with Delete Selected and Broadcast Message
  • Action — the per-row action icons (see below)
  • Client Name — the tenant/account display name
  • Domain Name — the tenant’s login domain used to route users to the correct account
  • License Type — the licensing model assigned to the tenant
  • Last Updated — the date the account record was last changed

Grid action icons

  • Edit — opens the client detail page to view and update the account
  • Delete — removes the tenant account (and its data) after confirmation
  • Users — drills into the tenant to manage its users
  • Import Tokens — imports authentication tokens for the tenant

Section glossary

Settings are grouped into collapsible sections. Expand a section to edit the fields it contains:

  • Account Limits — maximum users and devices and the account expiration date that cap the tenant’s capacity
  • Culture & Time Zone — the default language/locale and time zone used to display dates and messages
  • User Security Settings — lockout thresholds, password expiration, and related account-protection controls
  • OTP Lifetime — how long one-time and temporary passcodes remain valid
  • First Factor Authentication — how the primary credential is verified (local, directory/LDAP, endpoint)
  • Event Log Sync — settings that forward audit/event log data to an external system
  • FIDO2 Settings — passwordless and second-factor FIDO2/WebAuthn options for the tenant
  • Token Management — defaults that govern how tokens are issued and managed
  • User Authentication Settings — the authentication type and endpoint used to validate users
  • PIN Management — rules for user PIN creation, length, and reset
  • Push & IVR Settings — push notification and voice (IVR) delivery configuration
  • System Log Settings — logging level and retention for the tenant’s system logs

Header actions

The links at the top-right of this page:

  • Update — save changes to the client settings
  • Close — return without saving

File Configuration

HELP_PAGE_FILECONFIGURATION_TITLE

Tenant setting — requires Admin or Super Admin role

Page actions

Select and edit one of the tenant’s file-based configuration files. Choose a File Type from the drop-down and click Choose to open that configuration for editing.

Field glossary

  • File Type — the configuration file to work with (the available files depend on the tenant’s enabled features)
  • Choose — opens the selected configuration file for editing

Header actions

The link at the top-right of this page:

  • Back — return to the client account details page

Client API Keys

HELP_PAGE_CLIENTDETAILKEYS_TITLE

Tenant setting — requires Admin or Super Admin role

Page actions

Create or edit an application (API) key that this client/tenant uses to call the SurePassID APIs. The top section holds the key’s login credentials and usage details; the lower section sets the access rights the key is granted. Treat the API Key Identifier and API Key as secrets and rotate them if they may be compromised.

When creating a new key you can Copy the generated API Key Identifier and Key to the clipboard to be pasted into any SurePassID app such as RADIUS, Windows Login Manager (endpoint protection), or your custom application. Generate a fresh API Key with Add Security Key / New Password. The API Key is only shown while creating or resetting the key, so copy it before leaving the page.

Login credentials

  • Key Name — a friendly name that identifies this key (set when the key is created)
  • Key Identifier — the public identifier (client id) used on API calls
  • Key — the secret paired with the Key Identifier; shown only when generated
  • Created Date — when the key was created
  • Last Used — when the key was last used to call the API
  • Last Used From — the source IP address of the most recent API call

Access rights

The Access Rights grid controls what the key is permitted to do, granting or restricting permissions by device type/operation. Grant only the permissions the integration requires (least privilege). All key usage is recorded in the audit trail.

Header actions

The links at the top-right of this page:

  • Update — save the API key (shows Add when creating a new key)
  • Close — return without saving

Customize Email Messages

HELP_PAGE_CLIENTCUSTOMIZE_TITLE

Tenant setting — requires Admin or Super Admin role

Page actions

Customize how this tenant sends email. The top section holds custom SMTP settings (host, port, credentials) so mail is sent from your own server, and the lower section manages the tenant’s email notification templates.

Specifying your own SMTP server is optional. Leave Use Custom SMTP Settings unchecked to send email using the SMTP settings defined in the application’s web.config file — if you have access to web.config you can change the SMTP configuration there instead.

Notification templates

The grid lists the email notification templates used for this tenant. Each row represents a message sent for a specific action (for example, account or token events). Rows may be system default templates or custom templates you create to override the defaults. Use the grid actions to add, edit, or delete templates.

Header actions

The links at the top-right of this page:

  • Update — save the message customization
  • Close — return without saving

Customize SMS Messages

HELP_PAGE_CLIENTCUSTOMIZESMS_TITLE

Tenant setting — requires Admin or Super Admin role

Page actions

Customize how this tenant sends text messages and voice calls. The top section holds the SMS Provider Settings (provider, login, and credentials) so messages are sent through your own SMS/voice gateway, and the lower sections manage the tenant’s SMS and IVR/Voice notification templates.

Configuring a provider is optional. If you leave the provider settings blank, messages are sent using the default SMS/voice provider defined for the installation — if you have access to web.config you can change that configuration there instead.

SMS provider settings

  • SMS Provider — the gateway/service used to deliver text messages and voice calls
  • SMS Server Login — the account/username for the provider
  • SMS Server Password — the password/API key for the provider
  • Provider Specific — extra provider-specific values (such as a sender ID or endpoint) required by the selected provider

Notification templates

The SMS Notification Templates grid lists the text messages sent for specific actions (for example, OTP delivery or account events), and the IVR/Voice Notification Templates grid lists the spoken messages used for voice-call delivery. Rows may be system default templates or custom templates you create to override the defaults. Use the grid actions to add, edit, or delete templates.

Header actions

The links at the top-right of this page:

  • Update — save the message customization
  • Close — return without saving

Customize Single Sign On

HELP_PAGE_CLIENTCUSTOMIZESSO_TITLE

Tenant setting — requires Admin or Super Admin role

Page actions

Configure Single Sign-On (SSO) for this tenant. SurePassID acts as the identity provider (IdP) for three protocols: SAML 2.0, OpenID Connect (OIDC), and the Microsoft Entra External Authentication Method (EAM). The top section holds the SSO Settings that control whether SSO is enabled and how users authenticate, the Identity Provider Endpoints section exposes the metadata/discovery URLs relying parties use to trust SurePassID, the Certificate Management section manages the signing certificate, and the SSO Applications grid manages the registered applications.

SSO Settings

  • Allow SSO — enables Single Sign-On for this tenant
  • Allow Single Factor — permits SSO logon with a single authentication factor
  • Allow Change Password — lets users change their password from the SSO login screen
  • Company Logo For Login — the logo URL shown on the SSO login screen
  • User Authentication (1FA) Engine / Endpoint and 2FA Authentication Endpoint — the authentication engines and endpoints used to validate the first and second factors

Identity Provider Endpoints

Each endpoint has a Copy button so you can paste the URL into a relying party's configuration:

  • SAML2 Login Endpoint — the IdP-initiated SSO start URL where users begin a SAML 2.0 login; provide it to service providers that support IdP-initiated sign-on
  • Identity Provider SAML2 Meta Data — the SAML 2.0 metadata URL service providers use to auto-populate IdP parameters such as EntityID and signing certificate
  • OIDC Discovery Endpoint — the OpenID Connect discovery document (.well-known/openid-configuration) that OIDC relying parties use to discover the authorization, token, userinfo, and JWKS endpoints
  • Entra ID Discovery Endpoint — the discovery URL used when registering SurePassID as a Microsoft Entra External Authentication Method (EAM) provider for Entra ID Conditional Access MFA

Certificate Management

The SSO Public Certificate (.cer) is the certificate relying parties use to validate assertions/tokens signed by SurePassID. Use these buttons to view, distribute, and rotate it:

  • Show Certificate — toggles the public certificate text, thumbprint, and properties on the page so you can inspect it
  • Download Certificate — downloads the public certificate as a .cer file for your service providers
  • Renew Cert — generates a new certificate for periodic rotation. Limited to super administrators (and to account administrators only when the system setting that allows admin certificate renewal is enabled). Renewing replaces the current certificate, so relying parties that pinned the old one must be updated

Secondary (Next) Signing Key

A secondary signing key enables zero-downtime certificate rotation: you publish the next key alongside the current one, let relying parties pick it up, then promote it. The status line shows whether a secondary key is configured.

  • Add Secondary Key — generates and publishes a new next-generation signing key while the current key stays active
  • Promote to Current — makes the secondary key the active signing key (the old key is retired)
  • Remove Secondary — deletes the pending secondary key without promoting it

SSO Applications

The SSO Applications grid lists the applications configured for this tenant across all protocols. Use the Login Type filter above the grid to narrow the list. Add applications with the action links at the top of the grid:

  • New — add a SAML 2.0 application (choose from 50+ preloaded templates or a custom app)
  • New OIDC — register an OpenID Connect relying party (client id/secret, redirect URIs, scopes, grant types, PKCE)
  • EAM Configuration — configure the Microsoft Entra External Authentication Method integration for this tenant

Grid columns: the select check box (the header check box selects or clears all rows), Action, SSO App Name, SSO Application Library, SSO Application Type (SAML2, OIDC, or EAM), and SSO Application Policies.

Header actions

The links at the top-right of this page:

  • Update — save the message customization
  • Close — return without saving

SSO Partner Application Details

HELP_PAGE_CLIENTCUSTOMIZESSOPARTNERAPPDETAIL_TITLE

Tenant setting — requires Admin or Super Admin role

Page actions

Create or edit a SAML 2.0 partner (service provider) application for SSO. This page defines how SurePassID (the identity provider) issues SAML assertions to the service provider. Click Save to store the application settings, or Close to return without saving.

Import service provider metadata

Instead of entering the service provider settings by hand, you can import them from standard SAML 2.0 service provider metadata. The two buttons next to SP Issuer open an import dialog:

  • Import Metadata — opens the Import Service Provider Metadata dialog where you enter the service provider's metadata URL. Use Verify to retrieve and validate the metadata (a check mark confirms success), then Confirm to populate the SP configuration, or Cancel to dismiss
  • Upload Metadata — opens the Upload Service Provider Metadata dialog where you upload the service provider's SAML2 metadata .xml file, then Confirm to populate the SP configuration
  • Use App Name from Metadata — when checked in either dialog, the application name is set from the service name found in the imported/uploaded metadata

IdP Settings

  • App Name — the application's display name (populated from metadata during import)
  • IdP Issuer — the identity provider issuer (EntityID) SurePassID presents to the service provider
  • SSO Subject Type — the format/type of the subject (NameID) sent in the assertion
  • SSO Subject Source — the user field used as the subject value
  • Assertion Valid For — the assertion lifetime, entered as Days, Hours, Minutes, and Seconds

SP Settings

  • SP Issuer — the service provider issuer (EntityID)
  • Assertion Consumer Service (ACS) URL — the SP endpoint that receives the SAML assertion
  • Audience URI — the intended audience (recipient) of the assertion
  • App Start Options — how the application is started (for example IdP-initiated vs SP-initiated)
  • SP Login URL — the service provider's SSO login endpoint
  • SP Logout URL — the service provider's single logout endpoint
  • SP Logout Binding — the SAML binding used for logout requests/responses
  • SP Logout Requires Signed Requests — when set, logout requests must be signed
  • SP Sign Logout Response — when set, the logout response is signed

Attribute Settings

The attributes grid defines the SAML attributes sent in the assertion. Columns: Action, Attribute Name, and Attribute Value.

Header actions

The links at the top-right of this page:

  • Save — save the SAML 2.0 partner application settings
  • Close — return without saving

OIDC Client Details

HELP_PAGE_CLIENTCUSTOMIZESSOOIDCAPPDETAIL_TITLE

Tenant setting — requires Admin or Super Admin role

Page actions

Create or edit an OpenID Connect (OIDC) client (relying party) for SSO. This page defines how SurePassID (the OpenID Provider) issues tokens to the application. Use Import next to Client Id to pre-populate the form from a client's published metadata, then Save to store the client.

Client Settings

  • Client Id — the unique identifier the application presents when it requests tokens (required). Import pulls client metadata to fill in the remaining fields
  • Client Name — a friendly display name for the client
  • Client Type — Confidential clients can keep a secret (server-side apps); Public clients cannot (SPAs, mobile/native apps) and rely on PKCE instead of a secret
  • Redirect URIs — the exact callback URLs allowed to receive the authorization response, one per line (required, exact match)
  • Post-Logout URIs — URLs the user may be returned to after signing out, one per line
  • Back-Channel Logout URI — an optional HTTPS URL the provider calls server-to-server to notify the app that a session ended
  • Front-Channel Logout URI — an optional HTTPS URL loaded in the browser (via a hidden iframe) so the app can clear its session during logout

Scopes and Grants

  • Allowed Scopes — the OIDC scopes this client may request: openid, profile, email, phone, and offline_access (required for refresh tokens)
  • Custom Scopes — additional space-delimited scopes beyond the standard set
  • Allowed Grant Types — the OAuth 2.0 grants the client may use: authorization_code and refresh_token

Options

  • Require PKCE (S256) — requires the Proof Key for Code Exchange extension (recommended, and mandatory for public clients)
  • Require Consent — prompts the user to consent to the requested scopes on first authorization
  • Access Token Lifetime (secs) — how long an issued access token stays valid; keep short (5–60 min). Default 3600
  • Id Token Lifetime (secs) — how long the id_token is accepted; keep brief. Default 300
  • Refresh Token Lifetime (secs) — sliding lifetime of a refresh token, renewed on each rotation; issued only when offline_access is granted. Default 1209600 (14 days)
  • Absolute Session Lifetime (secs) — a hard cap from first sign-in after which the user must re-authenticate; blank means no cap. Default 604800 (7 days)

Client Secret

Shown for Confidential clients. The secret is a credential the application uses to authenticate to the token endpoint.

  • Status — indicates whether a secret is currently configured
  • Generate New Secret — creates a new secret. The value is shown once in the New Secret field; use Copy to save it before leaving the page, because it cannot be retrieved again
  • Clear Secret (make public) — removes the secret, converting the client to a public client that relies on PKCE

Header actions

The links at the top-right of this page:

  • Save — save the OIDC client settings
  • Duplicate — create a copy of the current client as a starting point for a new one
  • Close — return without saving

Entra External Authentication Method (EAM)

HELP_PAGE_CLIENTCUSTOMIZESSOEAMCONFIG_TITLE

Tenant setting — requires Admin or Super Admin role

What is an External Authentication Method (EAM)?

An External Authentication Method (EAM) is a Microsoft Entra ID capability that lets Entra delegate the multi-factor authentication (MFA) challenge to a third-party provider such as SurePassID. When a user signs in to a Microsoft or Entra-protected application and a Conditional Access policy requires MFA, Entra redirects the user to SurePassID to satisfy the second factor, then trusts the signed result. EAM is the successor to the older custom controls feature and is built on standard OpenID Connect.

Why is it needed?

Organizations that have standardized on Microsoft Entra ID for sign-in often still need MFA options that Entra does not provide natively — for example hardware OTP tokens, FIDO2/passkeys managed outside Entra, SMS/voice through a specific carrier, or an existing SurePassID deployment already issued to users. EAM lets you keep Entra ID as the primary identity provider while using SurePassID as the MFA authority, so you do not have to re-issue authenticators or run two disconnected MFA systems.

Benefits

  • Unified MFA — one set of SurePassID authenticators works for both Entra ID apps and your other SurePassID-protected applications
  • Broader authenticator support — use OTP hardware tokens, FIDO2/passkeys, push, SMS/voice, and more as the Entra second factor
  • Conditional Access integration — MFA is triggered by your existing Entra Conditional Access policies, so administration stays in Entra
  • Standards-based — uses OpenID Connect, avoiding proprietary integrations
  • Compliance — satisfy assurance/ACR requirements (possession, inherence, or full MFA) with an auditable external provider

EAM Settings

Complete these fields, then click Save. The values here must match the SurePassID external authentication method you register in the Entra admin center (see the steps below).

  • Enabled — turns EAM on or off for this tenant
  • Client Id (token aud) — the client/application id Entra presents; SurePassID validates it as the token audience. It must match the App ID configured on the Entra side
  • Cloud Environment — your Azure cloud: Azure Commercial, Azure Government, or Azure Government (DoD). Selecting an environment fills in the matching OpenID config URL template and redirect URI
  • Entra ID OpenID Config URL — the Entra discovery document, for example https://login.microsoftonline.com/{tenant-id}/v2.0/.well-known/openid-configuration. Replace {tenant-id} with your Entra tenant (directory) id. Click the help icon next to the field to see where the tenant id appears in your Entra app registration
  • Redirect URI — the Entra external authentication provider endpoint that receives the response (populated from the selected cloud environment)
  • ACR — the Authentication Context Class Reference that states which assurance SurePassID attests: possessionorinherence (default), possession, inherence, or mfa. It must align with the requirement expressed by your Entra Conditional Access policy
  • Last Updated — shows when the configuration was last saved

Steps: add SurePassID as an external authentication method in Entra ID

  • In the Microsoft Entra admin center, first register an application (Identity > Applications > App registrations > New registration). On the app's Overview blade, copy the Application (client) ID and the Directory (tenant) ID — you need both below
  • On this SurePassID page, enter the Application (client) ID as the Client Id, and paste the Directory (tenant) id into the Entra ID OpenID Config URL (replacing {tenant-id}), then Save
  • Back in Entra, go to Protection > Authentication methods > Add external method
  • Give the method a Name and enter the same Client ID and a Discovery endpoint that points at SurePassID's OpenID configuration
  • Set the method's target to the users or groups that should use SurePassID for MFA, and Enable the method
  • Ensure a Conditional Access policy requires MFA for the targeted users/apps so the external method is invoked
  • Test with a pilot account: sign in to an Entra-protected app, confirm you are redirected to SurePassID for the second factor, and that sign-in completes

Field names and menu paths in the Entra admin center may change over time; consult Microsoft's current documentation for "external authentication methods" if the wording differs.

Good to know

  • Why should I use this? What is SurePassID MFA for Microsoft Entra EAM
  • How do I set this up? How to set up SurePassID MFA for Entra ID

Header actions

The links at the top-right of this page:

  • Save — save the EAM configuration for this tenant
  • Close — return to the Customize SSO page without saving

Edit Notification Template

HELP_PAGE_CLIENTEDITNOTIFICATIONTEMPLATE_TITLE

Tenant setting — requires Admin or Super Admin role

Edit a notification message template for a tenant. A single editor is used for all three delivery channels — Email, SMS (text), and Voice/IVR — and the fields shown adapt to the notification type of the template you are editing. Both Admins and Super Admins can edit tenant templates; system/global default templates can only be edited by a Super Admin.

The action links at the top of the page:

  • Save — validate and save the template
  • Close — return to the previous page without saving

Field glossary

  • Tenant — the account the template belongs to (read-only). When a Super Admin creates a new template, a partner/tenant selector is shown instead so the template can be assigned to a specific tenant
  • Template Name — a descriptive name for this template (required)
  • Template Code — the event/message this template is used for (required). The available codes depend on the notification type — for example Send OTP via SMS, Push Yes/No Question SMS, and Device Activation SMS for SMS, or IVR OTP Delivery, IVR Authentication Success, and IVR Authentication Failure for Voice. This is fixed when editing an existing template
  • Notification Type — the delivery channel (Email, SMS, or Voice), shown read-only
  • Set as Default — when checked, this template is used whenever no specific template is requested for its template code
  • Active — when checked, the template is available for use; clear it to disable the template without deleting it
  • Content Format — the body format. This is editable only for Email templates (Plain Text or HTML); SMS and Voice templates are always plain text

Email Settings

These fields appear only for Email templates:

  • From Name — the display name shown as the sender (required)
  • From Address — the sender email address (required)
  • Subject — the email subject line, which may contain placeholders (required)

Message Body

  • Body — the message content sent to the recipient (required). For Email this is the email body (plain text or HTML); for SMS it is the text message; for Voice/IVR it is the spoken message text
  • Character count — shown below the body, it displays the current length against the maximum allowed for the notification type (SMS/Voice have tighter limits than Email) and turns orange/red as you approach or exceed the limit
  • Insert Placeholder — select a merge field from the dropdown and click << Insert to insert it at the cursor position in the body. Placeholders use the {{placeholder.name}} format and are replaced with real values (user name, OTP, tenant name, activation URL, etc.) when the notification is sent

Action buttons

  • Save — validate and save the template
  • Cancel — discard changes and return
  • Reset to Default — restore the template content to the system default (all customizations are lost; you are prompted to confirm)
  • Send Test — send a test notification using the current template content to verify how it renders and delivers
  • Preview — for HTML email templates only, opens a new window that renders the body with sample placeholder values so you can see the formatted result before saving

Header actions

The links at the top-right of this page:

  • Save — save the notification template
  • Close — return without saving

System-Wide Settings (Multi-Tenant)

Clients — Common Tasks

HELP_CLIENTS_TITLE

System-wide (multi-tenant) — requires Super Admin role

As a super administrator you manage tenant (client) accounts, each isolated with its own users, tokens, and settings.

Onboard a new tenant

  • Click New Account Wizard to create a client
  • Configure its account and security settings
  • Open the client and add its first administrator
  • Provision that tenant’s users and tokens

Switch into a client

  • Select the client in the list
  • Drill in to manage its users, tokens, and settings directly
  • License Acknowledgments — review and record acknowledgment of the product license terms
  • Edit Terms of Use — edit the Terms of Use presented to users of your tenants
  • True Up Report Generator — generate a license true-up report that reconciles licensed vs. actual usage across clients

Grid columns

  • Select (checkbox) — selects one or more rows; the header checkbox selects/clears all rows, used with Delete Selected and Broadcast Message
  • Action — the per-row action icons (see below)
  • Client Name — the tenant/account display name
  • Domain Name — the tenant’s login domain used to route users to the correct account
  • License Type — the licensing model assigned to the tenant
  • Last Updated — the date the account record was last changed

Grid action icons

  • Edit — opens the client detail page to view and update the account
  • Delete — removes the tenant account (and its data) after confirmation
  • Users — drills into the tenant to manage its users
  • Import Tokens — imports authentication tokens for the tenant

Header actions

The links at the top-right of the Clients list:

  • Broadcast Message — send a message to all tenants/clients at once
  • New Account Wizard — launch the guided wizard to create a new client account
  • Delete Selected — permanently remove the client accounts checked in the list

New Account Wizard

HELP_PAGE_CLIENTSETUPWIZARD_TITLE

System-wide (multi-tenant) — requires Super Admin role

The New Account Wizard creates a new tenant (client) account in the system in a single pass: the account’s identity, its first administrator’s login, an initial API access key, and the welcome email. Complete each section below and click Add Account to provision the tenant.

Requires a multi-tenant license. Creating additional tenants is only available when the server is licensed for multi-tenancy. On a single-tenant license this wizard is unavailable.

General Information

Identifies and secures the new tenant.

  • Name — the display name of the tenant/client account
  • Domain Name — the login domain that uniquely identifies the tenant; administrators and users sign in against this domain
  • Device Type — the default token/device type provisioned for the account
  • License Type — the license/edition assigned to the new tenant
  • Encryption Type — the encryption method used to protect the tenant’s sensitive data

User Credentials

Creates the tenant’s first administrator account. This person receives the welcome email and can sign in to finish configuring the tenant.

  • First Name / Last Name — the administrator’s name
  • Login Name — the administrator’s sign-in name for the tenant
  • Login Password — the administrator’s initial password
  • Email — used to deliver the welcome/setup notification and for email OTP delivery
  • Cell Phone — used for SMS and voice OTP delivery

API Access Control Keys

Optionally creates an initial application (API) key so the new tenant can integrate immediately. If the key cannot be created automatically, you can add one later from the account’s API Keys page.

  • Key Name — a friendly name for the API key
  • Key Identifier — the generated login name (client id) for the key; use the Copy button to copy it
  • Key Token — the generated secret (password) for the key; use the Copy button to copy it
  • Access Permissions — the permission template that determines what the key is allowed to do. The grid lists each API permission with its Allow state, Method, and Category

Email Preview

Shows a preview of the welcome/setup email that will be sent to the new administrator. After the account is created you can use Send Email to (re)send this notification. If no email template exists, create one first so new administrators receive their setup instructions.

Header actions

The buttons at the top-right of this page:

  • Add Account — creates the new tenant/client account from the information entered
  • Send Email — (re)sends the welcome/setup email to the new administrator; available after the account is created
  • Close — returns to the Clients list without saving

Other Pages

Terms of Use Editor

HELP_PAGE_TERMSOFUSEEDITOR_TITLE

Edit the Terms of Use text that users must accept when signing in to the portal. The editor holds the full terms document; changes take effect for new acknowledgments after you save.

Working with the terms

  • Edit the terms text in the large editing area
  • Click Preview to see how the terms will appear to users before publishing
  • Click Download to save a copy of the current terms to a file
  • Click Save to publish your changes

Page buttons

The buttons below the editor:

  • Preview — show how the terms will appear to users
  • Download — save a copy of the current terms to a file
  • Save — publish your changes
  • Cancel — discard changes and return

True Up Report Generator

HELP_PAGE_TRUEUPREPORT_TITLE

Generate a True Up report that reconciles a tenant’s actual user counts against its licensed maximum for billing/compliance. Pick an account, set the reporting date and options, then download the report as a file.

Generating a report

  • Select the Account to report on
  • Review the Account Details (licensed maximum and expiration date)
  • Choose the Report Options and Column Options to include
  • Click Download to produce the report

Field glossary

  • Account — the tenant/client the report is generated for
  • Maximum Users Licensed — the licensed user ceiling for the account
  • Account Expiration Date — the reporting/expiration date used for the true up calculation
  • Include New / Existing / Disabled Users — which user populations to count in the report
  • Monthly Fee — the per-user monthly fee used to calculate charges
  • Column Options — the per-user columns to include (login name, user role, created date, last login date, username, disabled date, prorated months)

Page buttons

The button at the bottom of the page:

  • Download — generate the True Up report and save it to a file using the selected account and options

Downloads

HELP_PAGE_DOWNLOADS_TITLE

The Downloads page is a central directory of SurePassID software, agents, and documentation. Each row provides an Install Guide (opens the PDF documentation in a new tab) and a Download link (retrieves the installer/package). Use the guide to install and configure each component.

Sections

  • Authentication Server — the core SurePassID MFA server plus its administration and install guides
  • Desktop & Server MFA — Windows logon MFA, Linux/macOS PAM modules, and the LDAP gateway
  • Remote Access — RADIUS and FreeRADIUS integrations for VPN and network access
  • Federation — SSO/federation connectors
  • Automation — automation and provisioning utilities
  • Mobile Authentication Tokens — the mobile authenticator apps for end users
  • Desktop Software Token — the desktop authenticator app
  • Support — support tools and resources
  • Developers — SDKs, API references, and developer resources

Links open the latest published versions on the SurePassID documentation and download sites.

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session

Manage Dashboard

HELP_PAGE_MANAGEDASHBOARD_TITLE

The Manage Dashboard page lets you choose which dashboard cards (widgets) appear on your Home screen. The grid lists every available dashboard item; check the ones you want to show and clear the ones you want to hide, then save.

Managing your dashboard

  • Review the list of available dashboard items
  • Use the Include checkbox to select the items to display on your Home screen
  • Click Update to save your selection, or Close to return without saving

Field glossary

  • Include — when checked, the dashboard item is shown on your Home screen
  • Name — the title of the dashboard item
  • Description — a short summary of what the dashboard item displays

Your selections are saved per user, so each administrator can tailor their own Home dashboard.

Header actions

  • Update — saves your dashboard card selection
  • Close — returns to the Home screen without saving changes

Contact Support

HELP_PAGE_CONTACTSUPPORT_TITLE

The Contact Support page gives you quick ways to reach the SurePassID support team and lets you send a support request directly from the console.

  • Support Portal — opens the SurePassID support/help website in a new tab
  • Email Direct — the support email address you can write to directly

Sending a message

  • Select the Issue that best matches your problem area
  • Enter a Phone number and Email address where support can reach you
  • Describe your Question in as much detail as possible
  • Click OK to send the request to the support team

Field glossary

  • Issue — the problem area/category for your request
  • Phone — a contact phone number for follow up
  • Email — the email address support should reply to
  • Question — a detailed description of your issue or question

Header actions

  • OK — sends your support request to the SurePassID support team
  • Close — returns to the previous screen without sending a request

About

HELP_PAGE_ABOUT_TITLE

The About page is a read-only summary of your SurePassID installation: the product version and, for administrators, the details of the installed site license. Use it to confirm which version you are running and to review your licensing and usage.

Product Version

  • Product — the SurePassID Identity Management Solution product name
  • Version — the installed product/build version number

Site License

This section is shown to super administrators (and to on-premises, non-hosted installs). It summarizes the license file that is currently active:

  • License Path / File Name — the location and name of the active license file
  • Status — whether the license is valid/active
  • License Version — the license format version (for example, 1.0 or 2.0)
  • Tenancy — whether the installation is multi-tenant (hosted) or single-tenant
  • Community — indicates a community/free edition license
  • Maximum Users — the licensed user ceiling
  • Active Users — the current number of active users counted against the license
  • Expiration — the date the license expires
  • Usage — current consumption relative to the licensed limits
  • License Details (JSON Format) — for version 2.0 licenses, the raw license payload for detailed review

The www.surepassid.com link opens the SurePassID website in a new tab.

Header buttons

The buttons in the top-right of every page do the following:

  • SurePassID Admin Console — opens the SurePassID website in a new tab
  • Settings — system/account settings such as email, mobile (SMS/voice), and security policies
  • Person (My Settings) — your own administrator profile: password, time zone, and preferences
  • Take the tour — replays the guided walkthrough for the current page
  • Help — opens this help panel; use the pin to keep it open while you work
  • Sign out — ends your admin session
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com