SurePassID Compliance Manager Report Interpretation and Remediation Guide
SurePassID Authentication Server
SurePassID Compliance Monitoring - Report Interpretation & Remediation Guide
This guide explains how to read each report produced by the SurePassID Compliance Manager, what findings mean, and what actions to take.
1. Privileged Authentication Report
Purpose: Shows every authentication event by privileged users (Domain Admins, Enterprise Admins, etc.) during the reporting period.
Key Fields
| Field | What It Means |
|---|---|
EventId |
Unique identifier. Prefix indicates source:
winlog-DC01-123456 = Windows Event Log from DC01,
SP-AB12CD34 = SurePassID REST API |
EventTime |
When the authentication occurred (UTC) |
Username |
The account that authenticated |
AuthFactors |
Mfa = multi-factor, Sfa = single-factor
(password only), Unknown = could not determine |
Result |
Success, Failure, or
Denied |
IpAddress |
Source IP of the authentication request |
SourceSystem |
Where the event was collected from (e.g.,
WindowsEventLog:DC01:Security,
SurePassID:RestApi) |
MfaCoverage |
Cross-source verification status (see MFA Coverage Analysis) |
LinkedMfaEventId |
If MFA was verified, the ID of the matching MFA event |
MfaMatchMethod |
How the MFA event was matched: Username+Time+IP,
Username+Time, FindUser+Time+IP,
FindUser+Time |
Summary Section
| Metric | What It Means | Target |
|---|---|---|
TotalEvents |
Total privileged auth events in period | Informational |
MfaEvents |
Events classified as MFA | Higher is better |
SfaEvents |
Events classified as SFA (password only) | Should be 0 for compliance |
MfaAdoptionRate |
% of events using MFA | Target: 100% |
MfaCoverageRate |
% of Windows SFA logons with a matching SurePassID MFA event | Target: 100% |
MfaCoverageGaps |
Windows logons without matching MFA | Should be 0 |
What to Look For
SfaEvents > 0— A privileged user logged in with password only. This is a compliance finding.MfaCoverageGaps > 0— Windows logons occurred without a corresponding SurePassID MFA validation. Either MFA isn't installed on that machine or isn't being enforced.AuthFactors = Unknown— The system couldn't determine if MFA was used. Investigate the raw event.
Per-User Summary
Each user gets a breakdown showing their MFA vs SFA ratio and
coverage rate. Users with SfaEvents > 0 or
MfaCoverageGaps > 0 need attention.
2. SFA vs MFA Summary Report
Purpose: High-level view of MFA adoption across all users (privileged and non-privileged) with trend data.
Sections
| Section | What It Shows |
|---|---|
Overall |
All authentication events across all users |
PrivilegedUsersOnly |
Privileged user subset — this is the compliance-critical view |
NonPrivilegedUsers |
Non-privileged users — useful for organization-wide MFA rollout tracking |
MethodBreakdown |
Which MFA methods are being used (OTP, Push, FIDO2, etc.) |
DailyTrend |
Day-by-day MFA/SFA counts to spot trends |
What to Look For
PrivilegedUsersOnly.SfaPercentage > 0— Privileged users are still using password-only authentication.- Declining MFA percentage in
DailyTrend— MFA adoption may be regressing. Investigate if tokens were disabled or removed. MethodBreakdown— Shows which MFA methods are in use. A healthy environment should show modern methods (Push, FIDO2). Overreliance on SMS may indicate a security gap.
3. Privilege Drift Report
Purpose: Identifies privileged users whose MFA posture has drifted from the expected baseline — they should have MFA but something is wrong.
Drift Categories
| Category | Severity | What It Means | How to Fix |
|---|---|---|---|
| UsersWithoutMfaTokens | CRITICAL | Privileged user has no MFA token in SurePassID | Provision an MFA token (OTP, Push, or FIDO2) for this user immediately |
| UsersWithUnexpectedSfa | HIGH | User has MFA tokens but authenticated with SFA | Verify SurePassID agent is installed and enforcing MFA on the machine they logged into |
| UsersWithMfaBypass | HIGH | MFA bypass is enabled for this user | Disable bypass in SurePassID admin console unless there's a documented exception |
| UsersWithDisabledTokensOnly | MEDIUM | All assigned tokens are disabled | Re-enable at least one token or provision a new one |
| UsersNotInSurePassId | CRITICAL | AD privileged user doesn't exist in SurePassID at all | Create the user in SurePassID and provision an MFA token |
Key Metrics
| Metric | Target |
|---|---|
MfaCoveragePercentage |
100% — all privileged users should have active MFA |
DriftRate |
0% — no users should have drift issues |
TotalDriftIssues |
0 |
Recommendations
The report includes a Recommendations section with
specific, actionable steps. These are generated based on the actual
findings and are prioritized by severity.
4. MFA Coverage Analysis
Purpose: Cross-source verification. For every privileged Windows logon (SFA), the system looks for a corresponding SurePassID MFA validation event within a configurable time window.
How It Works
- A privileged user logs into Windows (Event ID 4624) — this is an SFA event
- The system searches SurePassID events for an MFA validation (OTP, Push, FIDO2, etc.) by the same user within ±N minutes
- If found, the logon is marked
MfaVerified; if not, it's markedNoMfaCoverage(a gap)
Coverage Statuses
| Status | Meaning | Action Required? |
|---|---|---|
MfaVerified |
A matching MFA event was found | No — MFA is working |
NoMfaCoverage |
No matching MFA event found | YES — investigate |
IntrinsicMfa |
The event itself had MFA evidence | No |
NotEvaluated |
Not an SFA source or analysis disabled | N/A |
Match Methods (from strongest to weakest)
| Method | Confidence | Meaning |
|---|---|---|
Username+Time+IP |
Highest | Same user, within time window, same IP address |
FindUser+Time+IP |
High | User resolved via SurePassID FindUser API, same IP |
Username+Time |
Good | Same user and time but IPs differ (only when
RequireIpMatch=False) |
FindUser+Time |
Good | User resolved via FindUser, time match only |
Configuration That Affects Results
| Setting | Effect |
|---|---|
TimeWindowMinutes (default: 5) |
How close in time the Windows and MFA events must be |
RequireIpMatch (default: false) |
If true, IPs must also match — stricter but may cause
false gaps with NAT/VPN |
EnableFindUserLookup (default: true) |
Uses SurePassID FindUser API to resolve alternate usernames |
5. Understanding MFA Coverage Gaps
When the report shows MfaCoverage: NoMfaCoverage, it
means a privileged user logged into Windows but no MFA event was found.
This is the most important finding to investigate.
Common Causes
| Cause | How to Identify | Remediation |
|---|---|---|
| SurePassID agent not installed on the machine | The Windows logon IP doesn't appear in any SurePassID events | Install the SurePassID credential provider or network agent on that machine |
| SurePassID agent installed but not enforcing MFA | The machine IP appears in SurePassID events for other users but not this one | Check SurePassID policy configuration for this user/machine |
| User not in SurePassID | Debug log shows
FindUser: user not found in SurePassID |
Create the user in SurePassID and provision an MFA token |
| IP mismatch (NAT/VPN) | Debug log shows
IP mismatch: Windows=192.168.x.x vs MFA=70.x.x.x |
Expected with NAT. Set RequireIpMatch=false or verify
both IPs belong to the same session |
| Time window too narrow | Debug log shows candidate MFA events just outside the window | Increase TimeWindowMinutes |
| Service/batch logon (not interactive) | Logon type is 3 (Network) or 5 (Service) | Filter these out with LogonTypes: [2, 10] to focus on
interactive/RDP logons |
Debug Logging
Run with --verbose or set
"Logging": { "LogLevel": { "Default": "Debug" } } to see
detailed correlation decisions:
[MFA-GAP] Event winlog-DC01-59344656 by 'DOMAIN\admin' NO MFA COVERAGE
Windows: UTC=2026-05-13 03:54:46 Local=2026-05-12 20:54:46 IP=192.168.50.154
Searched: names=[DOMAIN\admin, admin], window=±5min, requireIp=True
Reason: MFA event SP-118AB7B5 matched by username+time (delta=00:00:10) but IP mismatch: Windows=192.168.50.154 vs MFA=70.125.9.165 (RequireIpMatch=True)
FindUser: user resolved (LoginName=admin, Email=admin@company.com)
The Reason line tells you exactly why the match
failed.
6. SFA-Only IP Address Analysis
Question: Which machines/IPs are allowing privileged users to log in without MFA?
The Privileged Authentication Report contains the data to answer this. Look at events where:
AuthFactors = SfaorMfaCoverage = NoMfaCoverage- The
IpAddressfield identifies the machine
How to Extract SFA-Only IPs from the Report
From the JSON report output, filter for gap events:
# Parse the JSON report and find IPs with MFA coverage gaps
$report = Get-Content "Output\PrivilegedAuthReport.json" | ConvertFrom-Json
$sfaIps = $report.Events |
Where-Object { $_.MfaCoverage -eq "NoMfaCoverage" } |
Group-Object IpAddress |
Sort-Object Count -Descending |
Select-Object @{N="IP";E={$_.Name}}, Count,
@{N="Users";E={ ($_.Group | Select-Object -ExpandProperty Username -Unique) -join ", " }}
$sfaIps | Format-Table -AutoSizeExample output:
IP Count Users
-- ----- -----
192.168.50.154 12 DOMAIN\admin, DOMAIN\svcadmin
192.168.50.201 5 DOMAIN\admin
10.0.1.50 3 DOMAIN\dbadmin
These are the machines where SurePassID MFA is not installed or not enforcing. They are your highest-priority remediation targets.
All SFA Events by IP (Including SurePassID SFA)
$report = Get-Content "Output\PrivilegedAuthReport.json" | ConvertFrom-Json
$report.Events |
Where-Object { $_.AuthFactors -eq "Sfa" } |
Group-Object IpAddress |
Sort-Object Count -Descending |
Select-Object @{N="IP";E={$_.Name}}, Count,
@{N="Users";E={ ($_.Group | Select-Object -ExpandProperty Username -Unique) -join ", " }},
@{N="Sources";E={ ($_.Group | Select-Object -ExpandProperty SourceSystem -Unique) -join ", " }} |
Format-Table -AutoSizeNote: A future version may include a dedicated SFA IP Summary section directly in the report. For now, the data is available in the event-level detail and can be extracted as shown above.
7. Remediation Playbook
Priority 1: CRITICAL (Address Immediately)
| Finding | Action |
|---|---|
| Privileged user not in SurePassID | 1. Create user in SurePassID admin console 2. Provision MFA token (Push or FIDO2 recommended) 3. Verify user can authenticate with MFA |
| Privileged user has no MFA tokens | 1. Provision token in SurePassID 2. Send enrollment instructions to user 3. Verify activation |
| Machine/IP with MFA gaps | 1. Identify the machine from its IP address 2. Install SurePassID credential provider or network agent 3. Test MFA enforcement 4. Re-run compliance check to verify |
Priority 2: HIGH (Address Within 48 Hours)
| Finding | Action |
|---|---|
| MFA bypass enabled | 1. Review if bypass was intentional (documented exception?) 2. If not, disable bypass in SurePassID admin console 3. Verify user can still authenticate |
| Unexpected SFA usage | 1. Verify SurePassID agent is installed on the machine 2. Check SurePassID policy — is MFA enforced for this user? 3. Check for agent errors in SurePassID server logs |
| All tokens disabled | 1. Investigate why tokens were disabled 2. Re-enable or provision new tokens |
Priority 3: MEDIUM (Address Within 1 Week)
| Finding | Action |
|---|---|
| IP mismatch causing false gaps | 1. If NAT/VPN, set RequireIpMatch=false2. If legitimate concern, investigate network path |
| Low MFA adoption rate (non-privileged) | 1. Plan MFA rollout for remaining users 2. Enable SurePassID enrollment self-service |
Ongoing
| Activity | Frequency |
|---|---|
| Run compliance check | Daily (via Windows Service) or before each audit |
| Review MFA coverage gaps | Weekly |
| Review privilege drift report | Weekly |
| Full remediation audit | Monthly or per compliance cycle |
8. Compliance Framework Mapping
HIPAA (45 CFR § 164.312)
| Requirement | Report Section | What to Check |
|---|---|---|
| Access Control (a)(1) | Privileged Auth Report | All privileged access events are logged |
| Unique User ID (a)(2)(i) | Privileged Auth Report | Each event has a unique username |
| Automatic Logoff (a)(2)(iii) | Not directly covered | Use Windows GPO settings |
| Authentication (d) | SFA/MFA Summary, Coverage | MFA adoption rate = 100%, no SFA gaps |
| Audit Controls (b) | All reports | Complete audit trail of privileged access |
CMMC 2.0 (NIST SP 800-171)
| Practice | Report Section | What to Check |
|---|---|---|
| IA.L2-3.5.3 (MFA for privileged) | MFA Coverage Analysis | MfaCoverageRate = 100%,
MfaCoverageGaps = 0 |
| IA.L2-3.5.1 (Identify users) | Privilege Drift Report | No UsersNotInSurePassId |
| AC.L2-3.1.1 (Limit access) | Privileged Auth Report | Review who has privileged access |
| AU.L2-3.3.1 (Audit events) | All reports | Events from all DCs are collected |
Key Audit Evidence
When presenting to auditors:
- Privileged Auth Report — proves every privileged logon is logged and tracked
- MFA Coverage Analysis — proves MFA is enforced on every machine (gaps = machines without MFA)
- Privilege Drift Report — proves proactive monitoring of MFA posture
- SFA/MFA Summary — proves MFA adoption rate with trend data
- SFA-Only IP list — identifies exactly which machines need MFA remediation
Appendix: Report File Locations
Reports are written to the output directory (default:
./Output):
| File | Report |
|---|---|
PrivilegedAuthReport.json |
Privileged Authentication Report |
SfaMfaSummary.json |
SFA vs MFA Summary |
PrivilegeDriftReport.json |
Privilege Drift Report |
EvidencePack_*.zip |
All reports bundled with metadata (use
--evidence-pack) |
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com