SurePassID Compliance Manager Audit and
Continuous Monitoring Features
SurePassID Authentication Server
SurePassID Compliance
Monitoring & Reporting
Audit and Continuous
Monitoring Features
Version 1.2.0 | January 2025
Overview
The SurePassID Compliance Monitoring and Reporting Library provides
comprehensive audit and continuous monitoring capabilities for
privileged user authentication. It enables organizations to:
Collect authentication events from multiple sources
Correlate events with privileged user identities
Analyze MFA vs SFA authentication patterns
Generate compliance-ready reports and evidence packs
Monitor and alert on security events in real-time
Audit Features
Multi-Source Event Ingestion
Source
Description
Use Case
SurePassID REST API
Real-time MFA events via FetchEventLogsAsync()
Direct MFA server integration
SurePassID Event Sync
Incremental sync via SyncEventLogAsync() with
server-side date filtering, sync status control, and JSON bulk
format
Continuous monitoring with identity hints
Entra ID (Azure AD)
Graph API + JSON import for Microsoft 365 sign-ins
Active Directory Integration with nested group
resolution
Entra ID as Identity Provider for cloud-only or
hybrid environments
Privileged Groups Monitored: Domain Admins,
Enterprise Admins, Schema Admins, Entra ID Roles (Global Admin,
Privileged Role Admin), custom groups
Identity Mapping: Correlates UPN, sAMAccountName,
email across event sources
Point-in-Time Snapshots: Captures group membership
at report time
Identity Provider Options
Scenario
Identity Provider
Event Sources
On-Premises AD
Active Directory
Windows Event Log, SurePassID, Syslog
Linux LDAP
Active Directory Provider (OpenLDAP/FreeIPA)
Syslog, SurePassID
Cloud-Only (Entra ID)
Entra ID Graph API
Entra ID Sign-Ins, SurePassID
SurePassID Standalone
SurePassID REST API
SurePassID events
Hybrid (AD + Entra)
AD + Entra ID
All sources
Hybrid (AD + SurePassID)
AD (groups) + SurePassID (MFA status)
All sources
Entra ID as Identity Provider:
When Active Directory is not available (cloud-only environments),
Entra ID serves as both:
Event Source - Sign-in logs via Graph API
Identity Provider - Group membership and privileged
role assignments
// Cloud-only: Entra ID provides both events AND identityservices.AddEntraIdGraphEventSource(eventOptions =>{...});services.AddEntraIdIdentityProvider(identityOptions =>{ identityOptions.TenantId="your-tenant-id"; identityOptions.ClientId="your-app-id"; identityOptions.ClientSecret="your-secret";// Privileged Entra ID roles to monitor identityOptions.PrivilegedRoles=["Global Administrator","Privileged Role Administrator","Security Administrator","Exchange Administrator"];});
SurePassID as Identity Provider:
For environments where SurePassID is the primary user management
system, it can serve as the Identity Provider:
// SurePassID as identity provider - credentials from environment variables// Set: SUREPASSID_ENDPOINT, SUREPASSID_API_KEY_ID, SUREPASSID_API_KEYservices.AddSurePassIdIdentityProvider(options =>{// Endpoint/credentials fall back to environment variables if not set options.Endpoint= configuration["SurePassID:Endpoint"];// or null for env var// All users with active MFA tokens are considered privileged options.TreatMfaEnrolledAsPrivileged=true;// Flag users with MFA bypass enabled options.FlagBypassUsers=true;});
SurePassID Environment Variables:
Variable
Purpose
SUREPASSID_ENDPOINT
REST API endpoint URL
SUREPASSID_API_KEY_ID
API account login name
SUREPASSID_API_KEY
API account key/password
Linux LDAP (OpenLDAP/FreeIPA):
The Active Directory provider supports Linux LDAP servers via
configuration:
// Linux LDAP configurationservices.AddActiveDirectoryIdentityProvider(options =>{ options.Server="ldap.example.com"; options.Port=636;// LDAPS options.UseSsl=true; options.BaseDn="dc=example,dc=com";// Simple bind (Linux doesn't support Windows integrated auth) options.UseIntegratedAuth=false; options.Username="cn=admin,dc=example,dc=com"; options.Password="your-password";// Linux privileged groups options.DefaultPrivilegedGroups=["cn=wheel,ou=groups,dc=example,dc=com","cn=admins,ou=groups,dc=example,dc=com"];});
Entra ID Privileged Roles:
Role
Risk Level
Monitoring Priority
Global Administrator
Critical
Always monitor
Privileged Role Administrator
Critical
Always monitor
Security Administrator
High
Recommended
Exchange Administrator
High
Recommended
SharePoint Administrator
Medium
Optional
User Administrator
Medium
Optional
Cross-System Identity
Correlation
A key challenge in compliance monitoring is correlating events across
systems where users may have different identifiers:
System
Primary Identifier
Example
Active Directory
sAMAccountName, UPN
jsmith, jsmith@contoso.com
Entra ID (Azure AD)
UPN (UserPrincipalName)
john.smith@contoso.onmicrosoft.com
SurePassID
Username (often alias)
jsmith, john.smith
SurePassID SsoIdentity
External IdP identifier
john.smith@contoso.com (UPN from Entra ID)
SsoIdentity and UserEmail
Fields
The SurePassID REST API and Event Sync include two critical fields
for cross-system correlation:
The correlation engine uses multiple lookup attempts:
// Correlation priority order:1. Match by UPN(john.smith@contoso.com)2. Match by sAMAccountName(jsmith)3. Match by Email(john.smith@contoso.com)4. Strip domain and retry(jsmith from john.smith@contoso.com)
With SsoIdentity/UserEmail available:
Lookup Attempt
SurePassID Event
Entra ID Event
Match?
UPN match
? jsmith ? UPN
? john.smith@... = UPN
Partial
SAM match
? jsmith = SAM
? john.smith@... ? SAM
Partial
Email match
? userEmail = Email
? (no email field)
Yes!
SsoIdentity
? ssoIdentity = UPN
? UPN = UPN
Yes!
Configuration for
Cross-System Correlation
var correlationOptions =new CorrelationOptions{ CaseInsensitiveMatching =true, TryUpnFallback =true, TryEmailFallback =true,// Critical: enables UserEmail matching StripDomainPrefix =true,// DOMAIN\user ? user StripDomainSuffix =false,// Keep @domain.com for UPN matching};
Best Practices for
Identity Alignment
Practice
Benefit
Configure SsoIdentity in SurePassID
Enables direct UPN matching with Entra ID
Maintain consistent email addresses
Provides fallback correlation path
Use UPN format in SurePassID usernames
Simplifies correlation without SsoIdentity
Include nested AD groups
Captures users in sub-groups of privileged groups
Impact on Compliance
Reporting
Report
Without SsoIdentity
With SsoIdentity
Privileged Auth Report
May miss events if username differs
Full coverage via UPN match
SFA/MFA Summary
Incomplete if events uncorrelated
Accurate MFA adoption rates
Privilege Drift
May show "User not found" errors
Complete user matching
Real-time Alerts
SFA violations may not trigger
Proper privileged user detection
Handling Legacy Format
The SurePassID Event Sync API supports both modern JSON and legacy
piped formats:
Format
SsoIdentity Available?
UserEmail Available?
Modern JSON
? Yes
? Yes
Legacy Piped
? No
? No
Note: Legacy piped format only contains:
EventTime|Tenant|Username|Action|Severity|ResultCode|Description|IP|...
To ensure full correlation capabilities, use the modern JSON format
by specifying format: "json" in API calls, or upgrade older
MFA servers that only support piped format.
Audit Reports Generated
Report
Content
Format
Privileged Auth Report
All auth events for privileged users
JSON, CSV, PDF
SFA/MFA Summary
MFA adoption rates, SFA violations
JSON, CSV, PDF
Privilege Drift Report
Group membership changes over time
JSON, CSV, PDF
Evidence Pack
Bundled reports + metadata for auditors
ZIP archive
Continuous Monitoring
Features
Real-Time Event Streaming
The system supports continuous event polling from multiple
sources:
// SurePassID REST API - polls MFA servervar events = await restApiSource.FetchAsync(new EventQuery { StartTime = DateTimeOffset.UtcNow.AddMinutes(-5), EndTime = DateTimeOffset.UtcNow, MaxResults =1000});// Entra ID Graph API - queries Microsoft Graph// Supports pagination via @odata.nextLink for large result setsvar entraEvents = await entraIdSource.FetchAsync(query);
Event Sync API
The SurePassID client library provides two methods for event
retrieval:
Method
Description
Use Case
FetchEventLogsAsync()
Time-range based query
Compliance reporting
SyncEventLogAsync()
Incremental sync with date filtering and sync status control
Continuous monitoring
Sync Features:
Server-side date filtering via
startDateUtc and endDateUtc parameters,
limiting data returned to the requested time range
Sync status control
(IgnoreSyncStatus): When true, re-reads all
events in the range (for compliance reports). When false,
only returns new/unsynced events (for continuous monitoring), avoiding
duplicate processing
JSON bulk format
(PreferJsonBulkFormat): Requests structured JSON
records array with additional fields (Tenant, AuthMethod,
SsoIdentity, UserEmail) not available in legacy piped format
Automatic format fallback: If the server does not
support JSON format, gracefully falls back to legacy piped format and
logs a warning recommending a server upgrade
Format negotiation caching: After detecting the
server's format capability, the client caches the result to avoid
repeated failed format requests
Supports legacy piped format (backward compatibility with older MFA
servers)
Response size tracking (ResponseBytes property)
Compliance vs. Monitoring Sync Behavior:
Setting
Compliance / On-Demand Reports
Continuous Monitoring
IgnoreSyncStatus
true -- Re-read all events in the requested time
range