SurePassID Compliance Manager Report Interpretation and Remediation Guide

SurePassID Authentication Server

SurePassID Compliance Monitoring - Report Interpretation & Remediation Guide

This guide explains how to read each report produced by the SurePassID Compliance Manager, what findings mean, and what actions to take.



1. Privileged Authentication Report

Purpose: Shows every authentication event by privileged users (Domain Admins, Enterprise Admins, etc.) during the reporting period.

Key Fields

Field What It Means
EventId Unique identifier. Prefix indicates source: winlog-DC01-123456 = Windows Event Log from DC01, SP-AB12CD34 = SurePassID REST API
EventTime When the authentication occurred (UTC)
Username The account that authenticated
AuthFactors Mfa = multi-factor, Sfa = single-factor (password only), Unknown = could not determine
Result Success, Failure, or Denied
IpAddress Source IP of the authentication request
SourceSystem Where the event was collected from (e.g., WindowsEventLog:DC01:Security, SurePassID:RestApi)
MfaCoverage Cross-source verification status (see MFA Coverage Analysis)
LinkedMfaEventId If MFA was verified, the ID of the matching MFA event
MfaMatchMethod How the MFA event was matched: Username+Time+IP, Username+Time, FindUser+Time+IP, FindUser+Time

Summary Section

Metric What It Means Target
TotalEvents Total privileged auth events in period Informational
MfaEvents Events classified as MFA Higher is better
SfaEvents Events classified as SFA (password only) Should be 0 for compliance
MfaAdoptionRate % of events using MFA Target: 100%
MfaCoverageRate % of Windows SFA logons with a matching SurePassID MFA event Target: 100%
MfaCoverageGaps Windows logons without matching MFA Should be 0

What to Look For

  • SfaEvents > 0 — A privileged user logged in with password only. This is a compliance finding.
  • MfaCoverageGaps > 0 — Windows logons occurred without a corresponding SurePassID MFA validation. Either MFA isn't installed on that machine or isn't being enforced.
  • AuthFactors = Unknown — The system couldn't determine if MFA was used. Investigate the raw event.

Per-User Summary

Each user gets a breakdown showing their MFA vs SFA ratio and coverage rate. Users with SfaEvents > 0 or MfaCoverageGaps > 0 need attention.


2. SFA vs MFA Summary Report

Purpose: High-level view of MFA adoption across all users (privileged and non-privileged) with trend data.

Sections

Section What It Shows
Overall All authentication events across all users
PrivilegedUsersOnly Privileged user subset — this is the compliance-critical view
NonPrivilegedUsers Non-privileged users — useful for organization-wide MFA rollout tracking
MethodBreakdown Which MFA methods are being used (OTP, Push, FIDO2, etc.)
DailyTrend Day-by-day MFA/SFA counts to spot trends

What to Look For

  • PrivilegedUsersOnly.SfaPercentage > 0 — Privileged users are still using password-only authentication.
  • Declining MFA percentage in DailyTrend — MFA adoption may be regressing. Investigate if tokens were disabled or removed.
  • MethodBreakdown — Shows which MFA methods are in use. A healthy environment should show modern methods (Push, FIDO2). Overreliance on SMS may indicate a security gap.

3. Privilege Drift Report

Purpose: Identifies privileged users whose MFA posture has drifted from the expected baseline — they should have MFA but something is wrong.

Drift Categories

Category Severity What It Means How to Fix
UsersWithoutMfaTokens CRITICAL Privileged user has no MFA token in SurePassID Provision an MFA token (OTP, Push, or FIDO2) for this user immediately
UsersWithUnexpectedSfa HIGH User has MFA tokens but authenticated with SFA Verify SurePassID agent is installed and enforcing MFA on the machine they logged into
UsersWithMfaBypass HIGH MFA bypass is enabled for this user Disable bypass in SurePassID admin console unless there's a documented exception
UsersWithDisabledTokensOnly MEDIUM All assigned tokens are disabled Re-enable at least one token or provision a new one
UsersNotInSurePassId CRITICAL AD privileged user doesn't exist in SurePassID at all Create the user in SurePassID and provision an MFA token

Key Metrics

Metric Target
MfaCoveragePercentage 100% — all privileged users should have active MFA
DriftRate 0% — no users should have drift issues
TotalDriftIssues 0

Recommendations

The report includes a Recommendations section with specific, actionable steps. These are generated based on the actual findings and are prioritized by severity.


4. MFA Coverage Analysis

Purpose: Cross-source verification. For every privileged Windows logon (SFA), the system looks for a corresponding SurePassID MFA validation event within a configurable time window.

How It Works

  1. A privileged user logs into Windows (Event ID 4624) — this is an SFA event
  2. The system searches SurePassID events for an MFA validation (OTP, Push, FIDO2, etc.) by the same user within ±N minutes
  3. If found, the logon is marked MfaVerified; if not, it's marked NoMfaCoverage (a gap)

Coverage Statuses

Status Meaning Action Required?
MfaVerified A matching MFA event was found No — MFA is working
NoMfaCoverage No matching MFA event found YES — investigate
IntrinsicMfa The event itself had MFA evidence No
NotEvaluated Not an SFA source or analysis disabled N/A

Match Methods (from strongest to weakest)

Method Confidence Meaning
Username+Time+IP Highest Same user, within time window, same IP address
FindUser+Time+IP High User resolved via SurePassID FindUser API, same IP
Username+Time Good Same user and time but IPs differ (only when RequireIpMatch=False)
FindUser+Time Good User resolved via FindUser, time match only

Configuration That Affects Results

Setting Effect
TimeWindowMinutes (default: 5) How close in time the Windows and MFA events must be
RequireIpMatch (default: false) If true, IPs must also match — stricter but may cause false gaps with NAT/VPN
EnableFindUserLookup (default: true) Uses SurePassID FindUser API to resolve alternate usernames

5. Understanding MFA Coverage Gaps

When the report shows MfaCoverage: NoMfaCoverage, it means a privileged user logged into Windows but no MFA event was found. This is the most important finding to investigate.

Common Causes

Cause How to Identify Remediation
SurePassID agent not installed on the machine The Windows logon IP doesn't appear in any SurePassID events Install the SurePassID credential provider or network agent on that machine
SurePassID agent installed but not enforcing MFA The machine IP appears in SurePassID events for other users but not this one Check SurePassID policy configuration for this user/machine
User not in SurePassID Debug log shows FindUser: user not found in SurePassID Create the user in SurePassID and provision an MFA token
IP mismatch (NAT/VPN) Debug log shows IP mismatch: Windows=192.168.x.x vs MFA=70.x.x.x Expected with NAT. Set RequireIpMatch=false or verify both IPs belong to the same session
Time window too narrow Debug log shows candidate MFA events just outside the window Increase TimeWindowMinutes
Service/batch logon (not interactive) Logon type is 3 (Network) or 5 (Service) Filter these out with LogonTypes: [2, 10] to focus on interactive/RDP logons

Debug Logging

Run with --verbose or set "Logging": { "LogLevel": { "Default": "Debug" } } to see detailed correlation decisions:

[MFA-GAP]  Event winlog-DC01-59344656 by 'DOMAIN\admin' NO MFA COVERAGE
            Windows:   UTC=2026-05-13 03:54:46 Local=2026-05-12 20:54:46 IP=192.168.50.154
            Searched:  names=[DOMAIN\admin, admin], window=±5min, requireIp=True
            Reason:    MFA event SP-118AB7B5 matched by username+time (delta=00:00:10) but IP mismatch: Windows=192.168.50.154 vs MFA=70.125.9.165 (RequireIpMatch=True)
            FindUser:  user resolved (LoginName=admin, Email=admin@company.com)

The Reason line tells you exactly why the match failed.


6. SFA-Only IP Address Analysis

Question: Which machines/IPs are allowing privileged users to log in without MFA?

The Privileged Authentication Report contains the data to answer this. Look at events where:

  • AuthFactors = Sfa or MfaCoverage = NoMfaCoverage
  • The IpAddress field identifies the machine

How to Extract SFA-Only IPs from the Report

From the JSON report output, filter for gap events:

# Parse the JSON report and find IPs with MFA coverage gaps
$report = Get-Content "Output\PrivilegedAuthReport.json" | ConvertFrom-Json
$sfaIps = $report.Events |
    Where-Object { $_.MfaCoverage -eq "NoMfaCoverage" } |
    Group-Object IpAddress |
    Sort-Object Count -Descending |
    Select-Object @{N="IP";E={$_.Name}}, Count,
        @{N="Users";E={ ($_.Group | Select-Object -ExpandProperty Username -Unique) -join ", " }}

$sfaIps | Format-Table -AutoSize

Example output:

IP              Count Users
--              ----- -----
192.168.50.154      12 DOMAIN\admin, DOMAIN\svcadmin
192.168.50.201       5 DOMAIN\admin
10.0.1.50            3 DOMAIN\dbadmin

These are the machines where SurePassID MFA is not installed or not enforcing. They are your highest-priority remediation targets.

All SFA Events by IP (Including SurePassID SFA)

$report = Get-Content "Output\PrivilegedAuthReport.json" | ConvertFrom-Json
$report.Events |
    Where-Object { $_.AuthFactors -eq "Sfa" } |
    Group-Object IpAddress |
    Sort-Object Count -Descending |
    Select-Object @{N="IP";E={$_.Name}}, Count,
        @{N="Users";E={ ($_.Group | Select-Object -ExpandProperty Username -Unique) -join ", " }},
        @{N="Sources";E={ ($_.Group | Select-Object -ExpandProperty SourceSystem -Unique) -join ", " }} |
    Format-Table -AutoSize

Note: A future version may include a dedicated SFA IP Summary section directly in the report. For now, the data is available in the event-level detail and can be extracted as shown above.


7. Remediation Playbook

Priority 1: CRITICAL (Address Immediately)

Finding Action
Privileged user not in SurePassID 1. Create user in SurePassID admin console
2. Provision MFA token (Push or FIDO2 recommended)
3. Verify user can authenticate with MFA
Privileged user has no MFA tokens 1. Provision token in SurePassID
2. Send enrollment instructions to user
3. Verify activation
Machine/IP with MFA gaps 1. Identify the machine from its IP address
2. Install SurePassID credential provider or network agent
3. Test MFA enforcement
4. Re-run compliance check to verify

Priority 2: HIGH (Address Within 48 Hours)

Finding Action
MFA bypass enabled 1. Review if bypass was intentional (documented exception?)
2. If not, disable bypass in SurePassID admin console
3. Verify user can still authenticate
Unexpected SFA usage 1. Verify SurePassID agent is installed on the machine
2. Check SurePassID policy — is MFA enforced for this user?
3. Check for agent errors in SurePassID server logs
All tokens disabled 1. Investigate why tokens were disabled
2. Re-enable or provision new tokens

Priority 3: MEDIUM (Address Within 1 Week)

Finding Action
IP mismatch causing false gaps 1. If NAT/VPN, set RequireIpMatch=false
2. If legitimate concern, investigate network path
Low MFA adoption rate (non-privileged) 1. Plan MFA rollout for remaining users
2. Enable SurePassID enrollment self-service

Ongoing

Activity Frequency
Run compliance check Daily (via Windows Service) or before each audit
Review MFA coverage gaps Weekly
Review privilege drift report Weekly
Full remediation audit Monthly or per compliance cycle

8. Compliance Framework Mapping

HIPAA (45 CFR § 164.312)

Requirement Report Section What to Check
Access Control (a)(1) Privileged Auth Report All privileged access events are logged
Unique User ID (a)(2)(i) Privileged Auth Report Each event has a unique username
Automatic Logoff (a)(2)(iii) Not directly covered Use Windows GPO settings
Authentication (d) SFA/MFA Summary, Coverage MFA adoption rate = 100%, no SFA gaps
Audit Controls (b) All reports Complete audit trail of privileged access

CMMC 2.0 (NIST SP 800-171)

Practice Report Section What to Check
IA.L2-3.5.3 (MFA for privileged) MFA Coverage Analysis MfaCoverageRate = 100%, MfaCoverageGaps = 0
IA.L2-3.5.1 (Identify users) Privilege Drift Report No UsersNotInSurePassId
AC.L2-3.1.1 (Limit access) Privileged Auth Report Review who has privileged access
AU.L2-3.3.1 (Audit events) All reports Events from all DCs are collected

Key Audit Evidence

When presenting to auditors:

  1. Privileged Auth Report — proves every privileged logon is logged and tracked
  2. MFA Coverage Analysis — proves MFA is enforced on every machine (gaps = machines without MFA)
  3. Privilege Drift Report — proves proactive monitoring of MFA posture
  4. SFA/MFA Summary — proves MFA adoption rate with trend data
  5. SFA-Only IP list — identifies exactly which machines need MFA remediation

Appendix: Report File Locations

Reports are written to the output directory (default: ./Output):

File Report
PrivilegedAuthReport.json Privileged Authentication Report
SfaMfaSummary.json SFA vs MFA Summary
PrivilegeDriftReport.json Privilege Drift Report
EvidencePack_*.zip All reports bundled with metadata (use --evidence-pack)
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com