Adding Group Policy Support to an Existing SurePassID Installation

SurePassID Authentication Server

Adding Group Policy (GPO) Support to an Existing SurePassID Installation

Audience: Windows / Active Directory administrators Applies to: SurePassID Windows Login Manager 2026.2 and later

This guide explains how to take an existing SurePassID Windows Login Manager installation — where settings are configured locally on each machine — and move to centrally managed Group Policy, so one change applies everywhere.


How it works (read this first)

The Windows Login Manager reads its settings from two registry locations:

Location Registry key Who writes it
Local (fallback) HKLM\SOFTWARE\SurePassId\CredProv The SurePassID configuration app / installer
Policy (authoritative) HKLM\SOFTWARE\Policies\SurePassId\CredProv Group Policy (GPO)

Rules the product enforces automatically:

  • If a policy value exists, it always wins — whether or not a local value is present.
  • If no policy value exists, the local value is used — so offline and non-domain machines keep working.
  • If a local value disagrees with a policy value, the local value is ignored and a security violation is written to the Windows Event Log (source SurePassID WLM, category Security).

So "adding GPO support" simply means publishing your settings into the policy location. Nothing about the installed product needs to change.


What you'll do (overview)

  1. Install the administrative template (ADMX/ADML) so the settings appear in the Group Policy editor.
  2. Configure the settings on one "staging" machine using the SurePassID configuration app (as you do today).
  3. Publish those settings to a GPO — either with the Publish to GPO button in the app, or by running the provided PowerShell script.
  4. Link the GPO to the target computers and refresh policy.
  5. Verify the settings applied.

Prerequisites

Requirement Needed for
A domain-joined "staging" machine with SurePassID configured Steps 2–3
RSAT: Group Policy Management Tools installed on the machine doing the publish Domain GPO creation
Delegated GPO rights in AD (Domain Admin, or delegated Create/Edit GPOs) Creating/editing the GPO
Local Administrator (elevation / UAC) Writing the machine registry
Access to the domain Central Store (optional but recommended) Step 1

Standalone / offline machines: you can still use policy locally without a domain — see Appendix B.


Step 1 — Install the administrative template (ADMX/ADML)

The template teaches the Group Policy editor how to display SurePassID settings.

Files (from the product's GroupPolicy folder):

  • SurePassID.admx
  • en-US\SurePassID.adml

Copy the files to your domain's Central Store so every admin workstation sees them:

# Run on a Domain Controller or admin workstation with access to SYSVOL
$dom = $env:USERDNSDOMAIN
Copy-Item .\SurePassID.admx        "\\$dom\SYSVOL\$dom\Policies\PolicyDefinitions\"
Copy-Item .\en-US\SurePassID.adml  "\\$dom\SYSVOL\$dom\Policies\PolicyDefinitions\en-US\"

If the PolicyDefinitions folder does not exist, create it first — this is the standard ADMX Central Store location.

Option B — Single admin workstation (local)

Copy-Item .\SurePassID.admx        C:\Windows\PolicyDefinitions\
Copy-Item .\en-US\SurePassID.adml  C:\Windows\PolicyDefinitions\en-US\

Verify: Open Group Policy Management ? edit any GPO ? navigate to Computer Configuration ? Policies ? Administrative Templates ? SurePassID Windows Login Manager. You should see the setting categories (Server, Authentication Methods, Protection, Proxy, Logging).


Step 2 — Configure the settings on a staging machine

Use the SurePassID configuration app exactly as you do today on a single representative machine:

  1. Launch the SurePassID configuration app (elevated).
  2. Set the server URL, token/key, authentication methods, protection options, logging, proxy, etc.
  3. Save. This writes the values to HKLM\SOFTWARE\SurePassId\CredProv.

This machine is now your source of truth for the policy you're about to publish.

Tip: Configure and test everything locally on this machine first. What you publish is an exact copy of what's on it.


Step 3 — Publish the settings to the GPO

You have two equivalent ways to publish. Both read the local key and write it to HKLM\SOFTWARE\Policies\SurePassId\CredProv (creating/updating the GPO).

Option A — The "Publish to GPO" button (easiest)

  1. In the SurePassID configuration app, click Publish to GPO.
  2. Approve the UAC / elevation prompt.
  3. The app detects your environment and either:
    • Domain + RSAT present: updates the domain GPO "SurePassID WLM", or
    • Standalone / no RSAT: writes local machine policy only.
  4. Confirm the success message.

The button publishes in mirror mode — the GPO becomes an exact copy of the local settings, including removing any values you deleted locally.

Option B — The PowerShell script

Run from the machine you configured in Step 2, from an elevated PowerShell prompt:

# Domain GPO, exact mirror of the local settings:
.\New-SurePassIDGpo.ps1 -GpoName "SurePassID WLM" -Mirror

What it does:

  • Reads every value under HKLM\SOFTWARE\SurePassId\CredProv.
  • Creates the GPO "SurePassID WLM" if it doesn't exist, otherwise updates it.
  • Writes the values into HKLM\SOFTWARE\Policies\SurePassId\CredProv inside the GPO.

About -Mirror: with -Mirror, values removed locally are also removed from the GPO (exact sync). Without it, the script only adds/overwrites and never deletes — which can cause the GPO to drift from your local settings. Use -Mirror when the configuration app is your single source of truth.


A new GPO does nothing until it is linked to an Organizational Unit (OU) containing the target computers.

Using Group Policy Management (GUI):

  1. Open Group Policy Management.
  2. Right-click the target OU (e.g., Workstations) ? Link an Existing GPO…
  3. Select SurePassID WLM ? OK.

Or PowerShell:

New-GPLink -Name "SurePassID WLM" -Target "OU=Workstations,DC=contoso,DC=com"

Then refresh policy on the endpoints (or wait for the normal ~90-minute cycle):

gpupdate /force

Step 5 — Verify

On a target machine after policy has applied:

  1. Check the policy key exists:

    Get-ItemProperty "HKLM:\SOFTWARE\Policies\SurePassId\CredProv"

    You should see your published values.

  2. Confirm precedence: the Windows Login Manager now uses the policy values. If a machine still has different local values under HKLM\SOFTWARE\SurePassId\CredProv, they are ignored.

  3. Check for security violations: open Event Viewer ? Windows Logs ? Application, filter by source SurePassID WLM. A Security category event indicates a local value conflicted with policy and was overridden — useful for spotting tampering or stale local configuration.


Making changes later (ongoing management)

When settings need to change:

  1. Update the settings on your staging machine with the configuration app.
  2. Click Publish to GPO (or re-run New-SurePassIDGpo.ps1 -GpoName "SurePassID WLM" -Mirror).
  3. Endpoints pick up the change on the next policy refresh.

Because publish runs in mirror mode, the GPO always matches your staging machine exactly — additions, edits, and deletions all propagate.


Appendix A — Privileges quick reference

Action Required rights
Read local settings Standard user
Write local settings (HKLM\SOFTWARE\SurePassId\...) Local Administrator (elevated)
Publish local policy (-LocalOnly) Local Administrator (elevated)
Create/edit the domain GPO Domain Admin or delegated Create/Edit GPOs + RSAT
Link the GPO to an OU Delegated Link GPOs on the OU (usually Domain Admin)

Important: Local Administrator is not enough to edit a domain GPO. That requires directory-level delegation in Active Directory.


Appendix B — Standalone / offline machines

For machines that are not domain-joined (or where RSAT isn't available), you can still enforce settings via local machine policy:

Button: the Publish to GPO button automatically falls back to local policy on non-domain machines.

Script:

# Writes HKLM\SOFTWARE\Policies\SurePassId\CredProv on this machine only:
.\New-SurePassIDGpo.ps1 -LocalOnly -Mirror

This does not create a domain GPO; it sets the authoritative policy key on that single machine. The same precedence rules apply — the policy values override the local values on that machine.


Troubleshooting

Symptom Cause / Fix
SurePassID node missing in the GP editor ADMX/ADML not installed, or not in the Central Store. Repeat Step 1; ensure the .adml is in the en-US subfolder.
"The GroupPolicy module is required" RSAT: Group Policy Management Tools not installed. Install RSAT, or use -LocalOnly for a single machine.
Access denied editing the GPO You have local admin but not AD GPO-edit delegation. Publish from an account/workstation with delegated Edit settings on the GPO.
Settings don't change on endpoints GPO not linked to the right OU, or policy not refreshed. Link the GPO (Step 4) and run gpupdate /force.
Old value still applied after a local delete You published without -Mirror. Re-run with -Mirror to remove stale values.
Security-category events in the Application log A local value conflicts with policy and was overridden. Clean up or remove the local value if unexpected.
UAC prompt cancelled Publish was aborted. Re-run and approve the elevation prompt.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com