SurePassID Compliance Manager Datasheet: HIPAA and CMMC 2.0

SurePassID Authentication Server

SurePassID Compliance Monitoring and Reporting Library


Overview

The SurePassID Compliance Monitoring and Reporting Library is a comprehensive .NET solution designed to help organizations achieve and maintain CMMC 2.0 and HIPAA Security Rule compliance for privileged user authentication. It provides automated collection, correlation, analysis, and reporting of authentication events to demonstrate MFA enforcement for privileged accounts.


Key Benefits

Benefit Description
Automated Compliance Scheduled compliance checks with cron-based scheduling
Audit-Ready Evidence Generate evidence packs with SHA-256 hashes for assessments
Real-Time Monitoring Streaming alerts for immediate response to security events
Multi-Format Reports Professional PDF, HTML, JSON, and CSV report generation
Flexible Integration Multiple event sources and identity providers
Multi-Framework Support Supports CMMC 2.0 and HIPAA Security Rule requirements
Event Aggregation Aggregate authentication events from multiple sources simultaneously
MFA Coverage Analysis Cross-source correlation proves every privileged Windows logon has a corresponding SurePassID MFA event
Cloud & On-Prem Support for both cloud (Entra ID, SurePassID) and on-premises (AD, Syslog) systems
Interactive Setup Configuration wizard for easy setup without editing JSON

CMMC 2.0 Controls Addressed

Control ID Control Name How We Address It
IA.L2-3.5.3 Multifactor Authentication Track and report MFA vs SFA usage for privileged users
AC.L2-3.1.1 Authorized Access Control Correlate events with AD privileged group membership
AC.L2-3.1.5 Least Privilege Identify users in multiple privileged groups
AU.L2-3.3.1 System Auditing Collect and store authentication audit trails
AU.L2-3.3.2 Audit Content Capture user, timestamp, result, method, IP address
SI.L2-3.14.6 Security Alerts Real-time alerting on security events

HIPAA Security Rule Controls Addressed

This solution also supports HIPAA Security Rule technical safeguard requirements for healthcare organizations:

Access Controls (§164.312(a)(1))

HIPAA Requirement Standard How We Address It
Unique User Identification §164.312(a)(2)(i) Correlates events with AD identities via UPN, SAMAccountName, canonical user ID
Automatic Logoff §164.312(a)(2)(iii) Monitors session events and tracks authentication timestamps

Audit Controls (§164.312(b))

HIPAA Requirement Standard How We Address It
Audit Controls §164.312(b) Comprehensive authentication event logging from multiple sources
Audit Trail §164.312(b) Captures user, timestamp, result, method, IP address, source system
Evidence Packs §164.312(b) Generates SHA-256 hashed evidence bundles for audits and assessments

Person or Entity Authentication (§164.312(d))

HIPAA Requirement Standard How We Address It
Authentication Verification §164.312(d) Tracks MFA vs SFA authentication classification
MFA Enforcement §164.312(d) Reports MFA adoption rates, alerts on SFA usage by privileged users
MFA Coverage Analysis §164.312(d) Cross-source correlation matches Windows SFA logons to SurePassID MFA events; identifies machines without MFA enforcement

Transmission Security (§164.312(e)(1))

HIPAA Requirement Standard How We Address It
Encryption §164.312(e)(2)(ii) TLS 1.2/1.3 for AD (LDAPS) and API communications

Security Incident Procedures (§164.308(a)(6))

Alert Type HIPAA Relevance Severity
Brute Force Detection Detect credential attacks against ePHI systems Critical
Suspicious IP Authentication Detect unauthorized access attempts High/Critical
Authentication Failures Track failed access attempts to systems with ePHI Warning/High
After-Hours Access Detect unusual access patterns Warning
MFA Bypass Detected Identify weakened authentication controls Critical

Workforce Security (§164.308(a)(3))

Feature HIPAA Control Description
Privileged User Tracking Authorization/Supervision Monitors users with elevated access to ePHI systems
Group Membership Correlation Access Management Links authentication events to AD group membership
Drift Detection Termination Procedures Identifies users with MFA coverage gaps

Information Access Management (§164.308(a)(4))

Feature HIPAA Control Description
Privileged Auth Report Access Authorization Documents who accessed systems with elevated privileges
SFA/MFA Summary Access Establishment Reports on authentication strength enforcement
Evidence Pack Generation Documentation Audit-ready evidence for HIPAA compliance assessments

Note: While this solution provides significant support for HIPAA technical safeguards, full HIPAA compliance requires additional administrative and physical safeguards, policies, and procedures.


Architecture

+---------------------------------------------------------------------------+
|                       COMPLIANCE MONITORING SYSTEM                        |
+---------------------------------------------------------------------------+
|                                                                           |
|                               Event Sources                               |
|                                                                           |
|       +---------------+     +---------------+     +---------------+       |
|       |     JSON      |     |    Syslog     |     |    Windows    |       |
|       |     Files     |     |    RFC5424    |     |   Event Log   |       |
|       +---------------+     +---------------+     +---------------+       |
|               |                     |                     |               |
|               +---------------------+---------------------+               |
|                                     |                                     |
|                                     v                                     |
|  +---------------------------------------------------------------------+  |
|  |                         CORRELATION ENGINE                          |  |
|  +---------------------------------------------------------------------+  |
|  | - Identity matching (UPN, SAM, Email)                               |  |
|  | - Privileged group membership lookup                                |  |
|  | - MFA/SFA classification                                            |  |
|  | - MFA Coverage Analysis (Windows SFA | SurePassID MFA)              |  |
|  | - Username normalization (DOMAIN\user, UPN | login)                 |  |
|  | - FindUser enrichment via REST API                                  |  |
|  +---------------------------------------------------------------------+  |
|                                     |                                     |
|               +---------------------+---------------------+               |
|               |                     |                     |               |
|               v                     v                     v               |
|       +---------------+     +---------------+     +---------------+       |
|       |    Reports    |     |   Real-Time   |     |   Evidence    |       |
|       |   JSON/PDF    |     |    Alerts     |     |     Packs     |       |
|       +---------------+     +---------------+     +---------------+       |
|                                                                           |
|                                  Outputs                                  |
|                                                                           |
+---------------------------------------------------------------------------+

Components

Event Sources

Multiple event sources can be enabled simultaneously to aggregate authentication events from different systems.

Source Format Use Case
SurePassID REST API Real-time API Direct MFA event collection from SurePassID Server
Entra ID (Graph API) Microsoft Graph Azure AD / Entra ID sign-in logs via API
Entra ID (JSON Import) Azure Portal Export, Diagnostic Settings, Log Analytics Offline import of Entra ID exports
JSON File JSONL, JSON Array SIEM exports (Splunk, Sentinel)
Syslog RFC 5424, RFC 3164, CEF, SurePassID ELS Linux/Unix auth logs
Windows Event Log Security Log Windows Server authentication

Identity Providers

Provider Features
Active Directory Nested group resolution, SSL/TLS (LDAPS), Windows integrated auth
SurePassID MFA enrollment-based privilege detection, bypass user flagging, multiple privilege strategies

Report Types

Report Description Formats
Privileged Auth Report Authentication events for privileged users with IP-level MFA gap analysis JSON, PDF, HTML
SFA/MFA Summary MFA adoption statistics and trends JSON, PDF, HTML, CSV
Privilege Drift Report Users missing MFA coverage in SurePassID JSON, PDF, HTML
MFA Coverage Summary Cross-source MFA verification rate and coverage gaps JSON, PDF, HTML, CSV

Alert Types

Alert Severity Trigger
Privileged SFA Auth Critical Privileged user authenticates without MFA
MFA Bypass Detected Critical User has MFA bypass enabled
Brute Force Critical Multiple failed auth attempts
Suspicious IP High Authentication from flagged IP range
Privileged Auth Failure High Failed authentication by privileged user
After Hours Auth Warning Authentication outside business hours

Technical Specifications

Platform Requirements

Requirement Specification
Runtime .NET 8.0 or later
Operating System Windows Server 2016+, Linux, macOS
Memory 512 MB minimum, 2 GB recommended
Storage 100 MB for application, varies for reports

Integration Points

Integration Protocol/Method
Active Directory LDAP/LDAPS (ports 389/636)
SurePassID REST API (HTTPS)
SIEM Systems Webhook (HTTP/HTTPS)
Email Alerts SMTP (TLS)

Supported Event Sources

Source Description Use Case
JSON Files JSONL or JSON Array formats SIEM exports (Splunk, Sentinel)
Syslog RFC 5424, RFC 3164, CEF Linux auth logs, network devices
Windows Event Log Security log events 4624, 4625, 4740, 4672 Windows Server authentication
SurePassID REST API Real-time MFA event streaming Direct MFA server integration

Supported Event Formats

Format Description
JSONL Newline-delimited JSON (one event per line)
JSON Array Array of event objects
RFC 5424 Modern syslog format
RFC 3164 BSD syslog format
CEF Common Event Format
Windows Security Log Event IDs 4624, 4625, 4740, 4672
SurePassID API OTP, Push, FIDO, SMS, Voice, Bypass events

Feature Matrix

Feature Standard Enterprise
JSON File Event Source X X
Syslog Event Source X X
Windows Event Log Source X X
SurePassID REST API X X
Active Directory Integration X X
Privileged Auth Report X X
SFA/MFA Summary Report X X
JSON Export X X
PDF Export X X
HTML Export (Interactive) X X
CSV Export X X
Real-Time Monitoring X X
Webhook Alerts X X
Email Alerts X X
Evidence Pack Generation X X
SurePassID Integration - X
Privilege Drift Detection - X
MFA Coverage Analysis - X
Scheduled Service - X
Priority Support - X

Sample Output

Console Summary

=== CMMC 2.0 Compliance Check Results ===

Report Period: 2024-01-08 to 2024-01-15
Privileged Groups: Domain Admins, Enterprise Admins

--- Authentication Summary ---
  Total Privileged Auth Events: 1,250
  Successful: 1,198 (95.8%)
  Failed: 52 (4.2%)
  MFA Events: 1,235 (98.8%)
  SFA Events: 15 (1.2%)
  Unique Privileged Users: 23

--- Compliance Status ---
  [!] NON-COMPLIANT: 15 SFA events detected

--- Users with SFA Violations ---
  • admin@contoso.com: 8 SFA events
  • svc_backup@contoso.com: 4 SFA events
  • dba_admin@contoso.com: 3 SFA events

PDF Report Preview

Professional, formatted reports include:

  • Executive summary with compliance status
  • Statistics dashboard with key metrics
  • User-by-user breakdown tables
  • Event audit trail
  • Recommendations for remediation

Deployment Options

Option 1: Interactive Configuration Wizard

Use the built-in wizard to configure the service without editing JSON manually:

compliance-cli configure
compliance-cli configure --quick     # Only required settings
compliance-cli configure --test      # Test configuration after saving

Option 2: Console Application

Run on-demand compliance checks from command line or scripts.

Option 3: Windows Service

Scheduled compliance checks using cron expressions with automatic evidence pack generation.

Option 4: Docker Container

Containerized deployment for cloud or Kubernetes environments.

Option 5: MCP Server (AI Agent Integration)

Pre-built MCP server for GitHub Copilot, Claude Desktop, and Cursor. Build and register -- all nine compliance tools are available in your AI assistant immediately.

Option 6: Library Integration

Embed compliance checking into existing applications via NuGet packages.


Configuration Example

The configuration wizard generates a JSON configuration file automatically. You can also configure manually:

{
  "EventSources": {
    "SurePassID": { "Enabled": true },
    "WindowsEventLog": { "Enabled": true },
    "EntraIdGraph": { "Enabled": false },
    "EntraIdJson": { 
      "Enabled": false,
      "DirectoryPath": "./EntraIdLogs",
      "FilePattern": "*.json",
      "Format": "AzurePortalExport"
    },
    "JsonFile": { "Enabled": false, "DirectoryPath": "./Events" },
    "Syslog": { "Enabled": false, "Path": "/var/log", "Format": "Rfc5424" }
  },
  "SurePassID": {
    "Endpoint": "https://mfa.yourcompany.com/api/mfa/v1",
    "ApiKeyId": "your-api-key-id",
    "ApiKey": "your-api-key",
    "UseHttpHeader": true,
    "MaxEventsPerRequest": 1000,
    "IgnoreSyncStatus": true,
    "PreferJsonBulkFormat": true
  },
  "EntraId": {
    "TenantId": "your-tenant-id",
    "ClientId": "your-client-id",
    "ClientSecret": "your-client-secret"
  },
  "ActiveDirectory": {
    "Enabled": true,
    "Server": "dc01.contoso.com",
    "BaseDn": "DC=contoso,DC=com",
    "UseIntegratedAuth": true,
    "UseSsl": false
  },
  "WindowsEventLog": {
    "LogName": "Security",
    "ComputerNames": [],
    "IncludeSuccessfulLogons": true,
    "IncludeFailedLogons": true,
    "ExcludeMachineAccounts": true,
    "ExcludeSystemAccounts": true,
    "MaxEventsPerQuery": 10000
  },
  "SurePassIdIdentityProvider": {
    "Enabled": false,
    "PrivilegeStrategy": "MfaEnrolled"
  },
  "MfaCoverage": {
    "Enabled": true,
    "TimeWindowMinutes": 5,
    "RequireIpMatch": false,
    "EnableFindUserLookup": true,
    "PrivilegedUsersOnly": true
  },
  "PrivilegedGroups": ["Domain Admins", "Enterprise Admins"],
  "OutputDirectory": "./Output",
  "ComplianceService": {
    "Enabled": true,
    "CronSchedule": "0 2 * * *",
    "LookbackHours": 24,
    "RunOnStartup": false
  }
}

Getting Started

# Run the configuration wizard
compliance-cli configure

# Run a compliance check with your configuration
compliance-cli run --config appsettings.json

Option B: Manual Setup

1. Install

dotnet add package SurePassID.Compliance.Runner
dotnet add package SurePassID.Compliance.Events.RestApi        # For SurePassID API
dotnet add package SurePassID.Compliance.Events.EntraId        # For Entra ID
dotnet add package SurePassID.Compliance.Events.FileIngest     # For JSON/Syslog
dotnet add package SurePassID.Compliance.Identity.ActiveDirectory
dotnet add package SurePassID.Compliance.Identity.SurePassId   # For SurePassID IdP

2. Configure

// Multiple event sources can be enabled simultaneously
services.AddSurePassIdEventSource(o => {
    o.Endpoint = "https://mfa.yourcompany.com/api/mfa/v1";
    o.ApiKeyId = "your-api-key-id";
    o.ApiKey = "your-api-key";
});

services.AddEntraIdEventSource(o => {
    o.TenantId = "your-tenant-id";
    o.ClientId = "your-client-id";
    o.ClientSecret = "your-client-secret";
});

services.AddJsonFileEventSource(o => o.DirectoryPath = "./Events");

// Choose identity provider
services.AddActiveDirectoryIdentityProvider(o => {
    o.Server = "dc01.contoso.com";
    o.BaseDn = "DC=contoso,DC=com";
});
// OR
services.AddSurePassIdIdentityProvider(o => {
    o.PrivilegeStrategy = "MfaEnrolled";
});

services.AddComplianceRunner();

3. Run

var result = await runner.RunAsync(new ComplianceRunRequest {
    Start = DateTimeOffset.UtcNow.AddDays(-7),
    End = DateTimeOffset.UtcNow,
    PrivilegedGroupNamesOrDns = ["Domain Admins"],
    Reports = [ReportType.PrivilegedAuthReport]
});

Documentation

Document Description
User Guide Complete documentation
Quick Start Scenarios Copy-paste examples
Configuration Reference All options

For Support

Resource Contact
Documentation docs/ folder
Email Support support@surepassid.com
Website https://surepassid.com

Version History

Version Date Changes
1.3.0 2025-07 Interactive HTML reports (Chart.js, sortable tables, responsive layout), expanded SFA IP gap analysis (total events, MFA gaps, sources, first/last seen timestamps), PDF report parity with HTML
1.2.0 2025-06 MFA Coverage Analysis (cross-source Windows SFA ? SurePassID MFA correlation), Windows Event Log multi-source support in MCP server, FindUser REST API enrichment, username normalization (DOMAIN\user, UPN), UTC timestamp normalization across sources
1.1.0 2025-01 Multi-source event aggregation, SurePassID REST API source, Entra ID integration (Graph API & JSON import), SurePassID identity provider, Interactive configuration wizard
1.0.0 2024-01 Initial release

The software and information contained herein are proprietary to, and comprise valuable trade secrets of, SurePassID Authentication, Inc., which intends to preserve as confidential trade secrets such software and information. Such software and information shall not be reproduced, published, or disclosed to others, or used for any purpose other than that for which it is expressly provided, without the prior written consent of SurePassID Authentication, Inc.

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com