SurePassID Hyper-V Image README
SurePassID On-Prem MFA
This Hyper-V image will install a proof-of-concept (POC) instance of SurePassID with Microsoft SQL Server Express.
What you need to know about your Hyper-V image
The POC license file has 5 not-for-resale user licenses that expire on a quarterly basis.
Generic secrets are used – cannot be put into production. If you choose to put your POC into production, SurePassID provides a tool that will rotate in new private secrets.
If you have questions or need technical support, please contact helpdesk@surepassid.com. We will be happy to assist you.
Initial login to the SurePassID Authentication Server (SPAS) administrator portal
When you first login to SurePassID, you will not have a second factor (2FA) authentication method provisioned for your account. Follow these steps to provision an OTP token for your account and turn on mandatory second factor (2FA) when logging in.
Login with the provided username and password at https://mfa.yourco.com.
First, provision an OTP token for your account. In this example we use a Google Authenticator Compliant soft token:
Go to the Users tab.
Click “Add New Token” link in the Tokens section.
Under Token Type, choose “Google Authenticator Compliant”.
If you wish to test Offline 2FA authentication, under OTP Type choose “Event (Oath)”.
Click “Add” button.
On the next screen, go to the Token ID line and click the QR code icon.
Scan the QR code presented in a compatible mobile authenticator app, such as our own SurePassID Authenticator App.
Now you have an OTP token for your account.
Next, turn on the requirement to use second factor (2FA) when logging into the admin portal:
Open NotePad++ as administrator.
Open the "C:\Program Files (x86)\SurePassID Corp\SurePassID Authentication Server 24.2\MfaServer\web.config" file.
Change line 180 from "<add key="System.AllowPortalSingleFactorLogin" value="true"/>" to "<add key="System.AllowPortalSingleFactorLogin" value="false"/>" and save it.
Now you will be required to provide a second factor on login.
To test, lock/unlock the Windows session and use your new OTP in the passcode field on the login screen.
Configuring other systems to authenticate with SurePassID Authentication Server (SPAS)
Now that your SurePassID admin portal (https://mfa.yourco.com) is secured with 2FA, you can configure other systems to authenticate with SurePassID. These systems can be Windows or MacOS/Linux devices; VPNs, firewalls, or other network devices; web, mobile, or custom applications; SCADA systems and OT equipment, and more. We encourage you to include all your use cases in the POC.
To find SurePassID components for other systems:
First, go to the Home tab in the SurePassID admin portal (https://mfa.yourco.com).
Click the “Get Started” sub-tab.
Now you can download the appropriate components for your other systems.
- EXCEPTION: MacOS PAM and Linux PAM must be obtained by emailing helpdesk@surepassid.com. Due to licensing reasons we cannot redistribute these files.
Adding our Windows Logon Manager (WLM) component to a Windows device for testing MFA
First, take the yourco.com cert.cer file from “C:\Installs” and put it in the trusted root certificates store on the Windows device.
Add a hosts file entry pointing to the IP of the SPAS so that both can resolve the DNS name without certificate errors. This will allow the Windows device to connect to the SPAS without prompts related to the certs.
Next, run our Windows Logon Manager installer on the Windows device.
- Directions can be found at: https://docs.surepassid.com/SurePassID_Windows_Logon_MFA_Guide.pdf
Configure the WLM on that Windows device to match the settings from the SPAS. The settings are visible in 2 places:
WLM Configuration Manager on the SPAS.
"C:\Users\Administrator\Desktop\Notes\Sp Reg Settings.reg" file on the server.
Next, add a user for that Windows device in the SurePassID admin portal (https://mfa.yourco.com).
- Directions can be found at:
https://docs.surepassid.com/SurePassID_Administration_Guide.pdf
- Directions can be found at:
Provision an OTP token for that user in the SurePassID admin portal. If you wish, you can use the Google Authenticator Compliant token process above.
Now that user can test signing into Windows using the Sign On Options link on the login screen. That user will use their normal Windows username and password (first factor) plus an OTP from their OTP token (second factor).
SurePassID provides advanced, deploy-anywhere multi-factor authentication (MFA) to top defense contractors, major public and private utilities, Fortune 10 healthcare companies, large financial services enterprises, federal and local government agencies, and military branches. Our team is comprised of industry visionaries, brilliant engineers, and dedicated customer servants, but we all share a passion for making the world a safer place through cybersecurity. Together we deliver solutions that protect the vital interests of America and our allies. For more information, please visit us at surepassid.com.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com