SurePassID Compliance Manager Audit and Continuous Monitoring Features

SurePassID Authentication Server

SurePassID Compliance Monitoring & Reporting

Audit and Continuous Monitoring Features

Version 1.2.0 | January 2025



Overview

The SurePassID Compliance Monitoring and Reporting Library provides comprehensive audit and continuous monitoring capabilities for privileged user authentication. It enables organizations to:

  • Collect authentication events from multiple sources
  • Correlate events with privileged user identities
  • Analyze MFA vs SFA authentication patterns
  • Generate compliance-ready reports and evidence packs
  • Monitor and alert on security events in real-time

Audit Features

Multi-Source Event Ingestion

Source Description Use Case
SurePassID REST API Real-time MFA events via FetchEventLogsAsync() Direct MFA server integration
SurePassID Event Sync Incremental sync via SyncEventLogAsync() with server-side date filtering, sync status control, and JSON bulk format Continuous monitoring with identity hints
Entra ID (Azure AD) Graph API + JSON import for Microsoft 365 sign-ins Cloud identity monitoring
JSON File Ingest SIEM exports (Splunk, Sentinel) Historical analysis
Syslog RFC 5424/3164/CEF formats Unix/Linux authentication
Windows Event Log Security events (4624, 4625, 4740) Windows Server auditing

Authentication Factor Classification

+----------------------------------------------------------+
|  Event Ingestion -> Factor Classification -> Correlation |
+----------------------------------------------------------+
|  MFA Methods Tracked:                                    |
|  - OTP (TOTP/HOTP)      - Push Notification              |
|  - FIDO2/Passkey        - SMS/Voice                      |
|  - Hardware Token       - Biometric (Windows Hello)      |
|  - Email OTP                                             |
+----------------------------------------------------------+
|  Classification Logic:                                   |
|  - MFA: Multiple factors verified                        |
|  - SFA: Single factor only (compliance violation)        |
|  - Unknown: Insufficient evidence (never inferred)       |
+----------------------------------------------------------+

MFA Method Mapping

Source Method Normalized Method Classification
Mobile app notification Push MFA
Microsoft Authenticator Push MFA
Mobile app code / TOTP OTP MFA
SMS one-time code SMS MFA
Phone call verification Voice MFA
FIDO2 security key FIDO2 MFA
Passkey / WebAuthn FIDO2 MFA
Windows Hello for Business Biometric MFA
Hardware OATH token HardwareToken MFA
Email one-time code Email MFA
Password only - SFA
MFA Bypass - SFA (violation)

Privileged User Correlation

  • Active Directory Integration with nested group resolution
  • Entra ID as Identity Provider for cloud-only or hybrid environments
  • Privileged Groups Monitored: Domain Admins, Enterprise Admins, Schema Admins, Entra ID Roles (Global Admin, Privileged Role Admin), custom groups
  • Identity Mapping: Correlates UPN, sAMAccountName, email across event sources
  • Point-in-Time Snapshots: Captures group membership at report time

Identity Provider Options

Scenario Identity Provider Event Sources
On-Premises AD Active Directory Windows Event Log, SurePassID, Syslog
Linux LDAP Active Directory Provider (OpenLDAP/FreeIPA) Syslog, SurePassID
Cloud-Only (Entra ID) Entra ID Graph API Entra ID Sign-Ins, SurePassID
SurePassID Standalone SurePassID REST API SurePassID events
Hybrid (AD + Entra) AD + Entra ID All sources
Hybrid (AD + SurePassID) AD (groups) + SurePassID (MFA status) All sources

Entra ID as Identity Provider:

When Active Directory is not available (cloud-only environments), Entra ID serves as both:

  1. Event Source - Sign-in logs via Graph API
  2. Identity Provider - Group membership and privileged role assignments
// Cloud-only: Entra ID provides both events AND identity
services.AddEntraIdGraphEventSource(eventOptions => { ... });
services.AddEntraIdIdentityProvider(identityOptions => 
{
    identityOptions.TenantId = "your-tenant-id";
    identityOptions.ClientId = "your-app-id";
    identityOptions.ClientSecret = "your-secret";
    
    // Privileged Entra ID roles to monitor
    identityOptions.PrivilegedRoles = [
        "Global Administrator",
        "Privileged Role Administrator", 
        "Security Administrator",
        "Exchange Administrator"
    ];
});

SurePassID as Identity Provider:

For environments where SurePassID is the primary user management system, it can serve as the Identity Provider:

// SurePassID as identity provider - credentials from environment variables
// Set: SUREPASSID_ENDPOINT, SUREPASSID_API_KEY_ID, SUREPASSID_API_KEY
services.AddSurePassIdIdentityProvider(options =>
{
    // Endpoint/credentials fall back to environment variables if not set
    options.Endpoint = configuration["SurePassID:Endpoint"]; // or null for env var
    
    // All users with active MFA tokens are considered privileged
    options.TreatMfaEnrolledAsPrivileged = true;
    
    // Flag users with MFA bypass enabled
    options.FlagBypassUsers = true;
});

SurePassID Environment Variables:

Variable Purpose
SUREPASSID_ENDPOINT REST API endpoint URL
SUREPASSID_API_KEY_ID API account login name
SUREPASSID_API_KEY API account key/password

Linux LDAP (OpenLDAP/FreeIPA):

The Active Directory provider supports Linux LDAP servers via configuration:

// Linux LDAP configuration
services.AddActiveDirectoryIdentityProvider(options =>
{
    options.Server = "ldap.example.com";
    options.Port = 636;  // LDAPS
    options.UseSsl = true;
    options.BaseDn = "dc=example,dc=com";
    
    // Simple bind (Linux doesn't support Windows integrated auth)
    options.UseIntegratedAuth = false;
    options.Username = "cn=admin,dc=example,dc=com";
    options.Password = "your-password";
    
    // Linux privileged groups
    options.DefaultPrivilegedGroups = [
        "cn=wheel,ou=groups,dc=example,dc=com",
        "cn=admins,ou=groups,dc=example,dc=com"
    ];
});

Entra ID Privileged Roles:

Role Risk Level Monitoring Priority
Global Administrator Critical Always monitor
Privileged Role Administrator Critical Always monitor
Security Administrator High Recommended
Exchange Administrator High Recommended
SharePoint Administrator Medium Optional
User Administrator Medium Optional

Cross-System Identity Correlation

A key challenge in compliance monitoring is correlating events across systems where users may have different identifiers:

System Primary Identifier Example
Active Directory sAMAccountName, UPN jsmith, jsmith@contoso.com
Entra ID (Azure AD) UPN (UserPrincipalName) john.smith@contoso.onmicrosoft.com
SurePassID Username (often alias) jsmith, john.smith
SurePassID SsoIdentity External IdP identifier john.smith@contoso.com (UPN from Entra ID)

SsoIdentity and UserEmail Fields

The SurePassID REST API and Event Sync include two critical fields for cross-system correlation:

{
  "username": "jsmith",
  "ssoIdentity": "john.smith@contoso.onmicrosoft.com",
  "userEmail": "john.smith@contoso.com",
  "action": "OTPValidation",
  "result": "Success"
}
Field Purpose Correlation Use
Username SurePassID login name (may be alias) Primary lookup key
SsoIdentity External IdP identifier (e.g., Entra ID UPN) Cross-reference with Entra ID events
UserEmail User's email address Fallback correlation to AD/Entra ID

How This Affects Correlation

Scenario: User "jsmith" in SurePassID maps to "john.smith@contoso.com" in Entra ID

                        Identity Correlation Flow

  +---------------------------------+     +----------------------------+
  |        SurePassID Event         |     |       Entra ID Event       |
  +---------------------------------+     +----------------------------+
  | username: "jsmith"              |     | userPrincipalName:         |
  | ssoIdentity: "john.smith@..."   |     |   "john.smith@contoso.com" |
  | userEmail: "john.smith@..."     |     |                            |
  +---------------------------------+     +----------------------------+
                   |                                     |
                   |        +-------------------+        |
                   +------->|    Correlation    |<-------+
                            |      Engine       |
                            +-------------------+
                                      |
                                      v
                            +-------------------+
                            | Active Directory  |
                            |      Lookup       |
                            +-------------------+
                            | UPN: john.smith@  |
                            | SAM: jsmith       |
                            | Email: john...    |
                            | Groups: Domain    |
                            |         Admins    |
                            +-------------------+

Correlation Engine Lookup Strategy

The correlation engine uses multiple lookup attempts:

// Correlation priority order:
1. Match by UPN (john.smith@contoso.com)
2. Match by sAMAccountName (jsmith) 
3. Match by Email (john.smith@contoso.com)
4. Strip domain and retry (jsmith from john.smith@contoso.com)

With SsoIdentity/UserEmail available:

Lookup Attempt SurePassID Event Entra ID Event Match?
UPN match ? jsmith ? UPN ? john.smith@... = UPN Partial
SAM match ? jsmith = SAM ? john.smith@... ? SAM Partial
Email match ? userEmail = Email ? (no email field) Yes!
SsoIdentity ? ssoIdentity = UPN ? UPN = UPN Yes!

Configuration for Cross-System Correlation

var correlationOptions = new CorrelationOptions
{
    CaseInsensitiveMatching = true,
    TryUpnFallback = true,
    TryEmailFallback = true,      // Critical: enables UserEmail matching
    StripDomainPrefix = true,     // DOMAIN\user ? user
    StripDomainSuffix = false,    // Keep @domain.com for UPN matching
};

Best Practices for Identity Alignment

Practice Benefit
Configure SsoIdentity in SurePassID Enables direct UPN matching with Entra ID
Maintain consistent email addresses Provides fallback correlation path
Use UPN format in SurePassID usernames Simplifies correlation without SsoIdentity
Include nested AD groups Captures users in sub-groups of privileged groups

Impact on Compliance Reporting

Report Without SsoIdentity With SsoIdentity
Privileged Auth Report May miss events if username differs Full coverage via UPN match
SFA/MFA Summary Incomplete if events uncorrelated Accurate MFA adoption rates
Privilege Drift May show "User not found" errors Complete user matching
Real-time Alerts SFA violations may not trigger Proper privileged user detection

Handling Legacy Format

The SurePassID Event Sync API supports both modern JSON and legacy piped formats:

Format SsoIdentity Available? UserEmail Available?
Modern JSON ? Yes ? Yes
Legacy Piped ? No ? No

Note: Legacy piped format only contains: EventTime|Tenant|Username|Action|Severity|ResultCode|Description|IP|...

To ensure full correlation capabilities, use the modern JSON format by specifying format: "json" in API calls, or upgrade older MFA servers that only support piped format.

Audit Reports Generated

Report Content Format
Privileged Auth Report All auth events for privileged users JSON, CSV, PDF
SFA/MFA Summary MFA adoption rates, SFA violations JSON, CSV, PDF
Privilege Drift Report Group membership changes over time JSON, CSV, PDF
Evidence Pack Bundled reports + metadata for auditors ZIP archive

Continuous Monitoring Features

Real-Time Event Streaming

The system supports continuous event polling from multiple sources:

// SurePassID REST API - polls MFA server
var events = await restApiSource.FetchAsync(new EventQuery {
    StartTime = DateTimeOffset.UtcNow.AddMinutes(-5),
    EndTime = DateTimeOffset.UtcNow,
    MaxResults = 1000
});

// Entra ID Graph API - queries Microsoft Graph
// Supports pagination via @odata.nextLink for large result sets
var entraEvents = await entraIdSource.FetchAsync(query);

Event Sync API

The SurePassID client library provides two methods for event retrieval:

Method Description Use Case
FetchEventLogsAsync() Time-range based query Compliance reporting
SyncEventLogAsync() Incremental sync with date filtering and sync status control Continuous monitoring

Sync Features:

  • Server-side date filtering via startDateUtc and endDateUtc parameters, limiting data returned to the requested time range
  • Sync status control (IgnoreSyncStatus): When true, re-reads all events in the range (for compliance reports). When false, only returns new/unsynced events (for continuous monitoring), avoiding duplicate processing
  • JSON bulk format (PreferJsonBulkFormat): Requests structured JSON records array with additional fields (Tenant, AuthMethod, SsoIdentity, UserEmail) not available in legacy piped format
  • Automatic format fallback: If the server does not support JSON format, gracefully falls back to legacy piped format and logs a warning recommending a server upgrade
  • Format negotiation caching: After detecting the server's format capability, the client caches the result to avoid repeated failed format requests
  • Supports legacy piped format (backward compatibility with older MFA servers)
  • Response size tracking (ResponseBytes property)

Compliance vs. Monitoring Sync Behavior:

Setting Compliance / On-Demand Reports Continuous Monitoring
IgnoreSyncStatus true -- Re-read all events in the requested time range false -- Only fetch new events since last sync
PreferJsonBulkFormat true -- Richest data for audit reports true -- Same benefit; format negotiated once
Date filtering startDateUtc/endDateUtc from report time range startDateUtc/endDateUtc from last poll time
Bandwidth Full data set for time range Incremental -- only new events per poll cycle

Configurable Alert Rules

Alert Type Trigger Response
SFA Violation Privileged user authenticates without MFA Webhook/Email alert
Account Lockout Multiple failed auth attempts Security incident
Bypass Event MFA bypass used Compliance violation flag
Risk Sign-In High risk level from Entra ID Immediate notification
Failed Auth Spike Unusual number of failures Anomaly detection

Scheduled Compliance Runs

{
  "ComplianceService": {
    "Enabled": true,
    "CronSchedule": "0 2 * * *",
    "LookbackHours": 24,
    "PrivilegedGroups": ["Domain Admins", "Enterprise Admins"],
    "OutputDirectory": "./ComplianceReports"
  }
}

Monitoring Dashboard Metrics

Metric Description Update Frequency
Events Ingested Total events processed Per run
Privileged Events Events from privileged users Per run
MFA Rate Percentage using MFA Per run
SFA Violations Count of non-MFA auth Per run
Correlation Rate Events matched to identities Per run

Compliance Benefits

CMMC 2.0 Level 2 Controls

Control Requirement How This System Addresses It
IA.L2-3.5.3 MFA for privileged accounts Tracks MFA usage, flags SFA violations
AC.L2-3.1.1 Authorized access control Correlates events to privileged identities
AC.L2-3.1.5 Least privilege Privilege drift reports show group changes
AU.L2-3.3.1 System auditing Multi-source event collection with retention
AU.L2-3.3.2 Audit content Full event details including IP, method, result
SI.L2-3.14.6 Security alerts Real-time alerting on violations

HIPAA Security Rule

Section Requirement How This System Addresses It
§164.312(a) Access Controls Privileged user identification and monitoring
§164.312(b) Audit Controls Comprehensive authentication logging
§164.312(d) Entity Authentication MFA verification and tracking
§164.308(a)(6) Security Incidents Automated detection and alerting

Evidence Pack Contents

evidence-pack-2025-01-15/
+-- metadata.json              # Run parameters, timestamps, version
+-- privileged-auth-report.json
+-- privileged-auth-report.csv
+-- privileged-auth-report.pdf
+-- sfa-mfa-summary.json
+-- sfa-mfa-summary.csv
+-- privilege-snapshot.json    # Point-in-time group membership
+-- event-sources.json         # Source configuration (sanitized)
\-- attestation.txt            # SHA-256 hash verification

Security Best Practices

Practice Implementation
Defense in Depth Multiple event sources provide redundant visibility
Zero Trust Verification Continuous auth monitoring, not just perimeter
Separation of Duties Reports distinguish privileged vs. regular users
Audit Trail Integrity Raw event data preserved, timestamps in UTC
Least Privilege Monitoring Tracks group membership changes over time
Incident Response Real-time alerts enable rapid response
Data Minimization Configurable field inclusion in reports
Secure Configuration Credentials in HTTP headers, not request body

Authentication Security

Feature Benefit
HTTP Header Auth Credentials not logged in request payloads
Certificate Auth Supports X.509 certificates for Entra ID
Retry with Backoff Prevents account lockout from transient failures
Connection Validation TestConnectivityAsync() before operations

Key Metrics

Target Metrics for Privileged Users

Metric Description Target
MFA Adoption Rate % of privileged auth events using MFA 100%
SFA Violation Count Number of single-factor auth events 0
Bypass Events MFA bypass usage Minimize
Failed Auth Rate Failed attempts / total attempts Monitor trends
Event Correlation Rate Events matched to privileged users High coverage

Operational Metrics

Metric Description Threshold
Event Latency Time from auth to report < 5 minutes
API Response Time Graph/REST API calls < 30 seconds
Report Generation Time to produce evidence pack < 2 minutes
Data Retention Event storage duration 90+ days

Architecture Summary

+-----------------------------------------------------------------------------+
|                                Event Sources                                |
+------------+------------+------------+------------+------------+------------+
| SurePassID | Entra ID   |    JSON    |   Syslog   |  Windows   |   Future   |
| REST API   | Graph API  |   Files    |  RFC5424   |  EventLog  |  Sources   |
|            | & JSON     |   (SIEM)   |  CEF/ELS   |   4624+    |            |
+------------+------------+------------+------------+------------+------------+
      |            |            |            |            |            |
      |     +-------------+     |            |            |            |
      |     |  Entra ID   |     |            |            |            |
      |     |   Mapper    |     |            |            |            |
      |     +-------------+     |            |            |            |
      |     | UPN -> User |     |            |            |            |
      |     | MFA Method  |     |            |            |            |
      |     | Risk Level  |     |            |            |            |
      |     +-------------+     |            |            |            |
      |            |            |            |            |            |
      +------------+------------+----+-------+------------+------------+
                                     |
                                     v
                              +-------------+
                              |  AuthEvent  |
                              | Abstraction |
                              +-------------+
                              | - EventId   |
                              | - Username  |
                              | - Result    |
                              | - MfaMethod |
                              | - Telemetry |
                              +-------------+
                                     |
                 +-------------------+-------------------+
                 |                   |                   |
                 v                   v                   v
         +---------------+   +---------------+   +---------------+
         |   Identity    |   |  Correlation  |   |     Alert     |
         |   Provider    |   |    Engine     |   |    Engine     |
         +---------------+   +---------------+   +---------------+
         | - AD Groups   |   | - UPN         |   | - SFA Alerts  |
         | - Entra ID    |   | - SAM         |   | - Lockout     |
         |   Roles       |   | - Email       |   | - Bypass      |
         | - UPN / SAM   |   |               |   | - Risk        |
         | - Email       |   |               |   |               |
         +---------------+   +---------------+   +---------------+
                 |                   |                   |
                 +-------------------+-------------------+
                                     |
                                     v
                              +-------------+
                              | Compliance  |
                              |   Runner    |
                              +-------------+
                              | Orchestrates|
                              | all phases  |
                              +-------------+
                                     |
                 +-------------------+-------------------+
                 |                   |                   |
                 v                   v                   v
         +---------------+   +---------------+   +---------------+
         |    Reports    |   |   Evidence    |   |    Alerts     |
         |               |   |     Packs     |   |               |
         +---------------+   +---------------+   +---------------+
         | - Priv Auth   |   | - ZIP         |   | - Webhook     |
         | - MFA / SFA   |   | - Hash        |   | - Email       |
         | - Drift       |   | - Metadata    |   | - Custom      |
         |               |   |               |   |   Handlers    |
         +---------------+   +---------------+   +---------------+

Identity Provider Scenarios

+---------------------------------------------------------------------------+
|                         Identity Provider Options                         |
+---------------------------------------------------------------------------+
|                                                                           |
|  +---------------+ +---------------+ +---------------+ +---------------+  |
|  |  Windows AD   | |  Linux LDAP   | |  Cloud-Only   | |  SurePassID   |  |
|  +---------------+ +---------------+ +---------------+ +---------------+  |
|  | +-----------+ | | +-----------+ | | +-----------+ | | +-----------+ |  |
|  | |  Active   | | | | OpenLDAP  | | | |  Entra ID | | | |SurePassID | |  |
|  | | Directory | | | |  FreeIPA  | | | | Graph API | | | | REST API  | |  |
|  | +-----------+ | | +-----------+ | | +-----------+ | | +-----------+ |  |
|  |       |       | |       |       | |       |       | |       |       |  |
|  | - Domain      | | - posixGroup  | | - Global      | | - MFA         |  |
|  |   Admins      | | - wheel       | |   Admin       | |   Enrolled    |  |
|  | - Enterprise  | | - sudo        | | - Privileged  | | - User Groups |  |
|  |   Admins      | | - admins      | |   Role Admin  | | - Bypass Flag |  |
|  | - Schema      | |               | | - Security    | |               |  |
|  |   Admins      | |               | |   Admin       | |               |  |
|  | - Custom      | | - Custom      | | - Custom      | |               |  |
|  |   Groups      | |   Groups      | |   Roles       | |               |  |
|  +---------------+ +---------------+ +---------------+ +---------------+  |
|                                                                           |
|  +---------------------------------------------------------------------+  |
|  |                          Hybrid Scenarios                           |  |
|  +-----------------------+----------------------+----------------------+  |
|  |  AD + Entra ID        |  AD + SurePassID     |  All Three Combined  |  |
|  |  (synced users)       |  (MFA enrichment)    |  (full coverage)     |  |
|  +-----------------------+----------------------+----------------------+  |
|                                                                           |
+---------------------------------------------------------------------------+

Data Flow Detail

+---------------------------------------------------------------------------+
|                        Cross-System Identity Flow                         |
+---------------------------------------------------------------------------+
|                                                                           |
|  +--------------------------------+   +--------------------------------+  |
|  |        Entra ID Sign-In        |   |        SurePassID Event        |  |
|  +--------------------------------+   +--------------------------------+  |
|  | userPrincipalName:             |   | username: "jsmith"             |  |
|  |   "john@contoso.com"           |   | ssoIdentity:                   |  |
|  |                                |   |   "john@contoso.com"           |  |
|  |                                |   | userEmail:                     |  |
|  |                                |   |   "john@contoso.com"           |  |
|  +--------------------------------+   +--------------------------------+  |
|                  |                                     |                  |
|                  +------------------+------------------+                  |
|                                     |                                     |
|                                     v                                     |
|                             +---------------+                             |
|                             |  Correlation  |                             |
|                             |    Engine     |                             |
|                             +---------------+                             |
|                                     |                                     |
|                     +---------------+---------------+                     |
|                     |               OR              |                     |
|                     v                               v                     |
|          +---------------------+         +---------------------+          |
|          |  Active Directory   |         |  Entra ID (cloud)   |          |
|          +---------------------+         +---------------------+          |
|          | UPN: john@contoso   |         | UPN: john@contoso   |          |
|          | SAM: jsmith         |         | Roles:              |          |
|          | Groups:             |         | - Global Admin      |          |
|          | - Domain Admins     |         | - Security Admin    |          |
|          +---------------------+         +---------------------+          |
|                     |                               |                     |
|                     +---------------+---------------+                     |
|                                     |                                     |
|                                     v                                     |
|                             +---------------+                             |
|                             |  Correlated   |                             |
|                             |   AuthEvent   |                             |
|                             +---------------+                             |
|                             | Privileged:   |                             |
|                             |      Yes      |                             |
|                             +---------------+                             |
|                                                                           |
+---------------------------------------------------------------------------+

Quick Reference

Event Query Parameters

Parameter Type Description
StartTime DateTimeOffset Beginning of time range (inclusive)
EndTime DateTimeOffset End of time range (inclusive)
Usernames string[] Filter to specific users
EventTypes string[] Filter by event type
Results AuthResult[] Filter by outcome (Success/Failure/Denied)
MaxResults int Limit number of results
Skip int Pagination offset

Result Classifications

AuthResult Description
Success Authentication succeeded
Failure Authentication failed (wrong credentials)
Denied Authentication blocked (policy, lockout)
Unknown Result cannot be determined

Factor Classifications

AuthFactorClassification Description
Mfa Multi-factor authentication confirmed
Sfa Single-factor authentication only
Unknown Cannot determine (never inferred as MFA)

Support

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com