SurePassID Windows Login Manager AutoLogon Setup Guide

SurePassID Authentication Server

SurePassID Windows Logon Manager - AutoLogon Setup Guide

This guide explains how to configure Windows AutoAdminLogon so that it continues to work when the SurePassID Windows Login Manager is enforcing MFA.

For the design and rationale, see docs/AUTOLOGON_MFA_DESIGN.md.

Overview

When SurePassID enforces MFA it disables the built-in Windows password credential provider, which normally stops native autologon from working. With this capability enabled, the SurePassID provider performs the autologon itself for the single configured autologon account, bypassing MFA for that account.

Key points:

  • Applies to one account per machine (the native Windows autologon account).
  • Persistent — it runs on every reboot, not just once.
  • Disabled by default. You must explicitly enable AllowAutoLogon.
  • The autologon account bypasses MFA. Treat it as a single-factor account and scope it to kiosk / service / lab machines.

Prerequisites

  • SurePassID Windows Login Manager installed and enforcing MFA.
  • Local administrator rights on the machine (or GPO management rights for domain deployment).
  • The account you want to auto-log-on already exists and can sign in normally.

Step 1 — Configure the Windows autologon account

You can set the native autologon values with Sysinternals Autologon (recommended, stores the password as an encrypted LSA secret) or manually.

  1. Download Autologon from Sysinternals.
  2. Run it as administrator.
  3. Enter the Username, Domain, and Password.
  4. Click Enable.

This stores DefaultUserName, DefaultDomainName, sets AutoAdminLogon = 1, and saves the password as the LSA private secret DefaultPassword (encrypted).

Option B: Manual registry

Under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:

Value Type Example
AutoAdminLogon REG_SZ 1
DefaultUserName REG_SZ kioskuser
DefaultDomainName REG_SZ CONTOSO
DefaultPassword REG_SZ (plaintext — discouraged)

Storing DefaultPassword in the registry keeps the password in plaintext. Prefer Option A so it is stored as an encrypted LSA secret. The provider reads the LSA secret first and only falls back to the plaintext value.

Step 2 — Enable AllowAutoLogon for SurePassID

Enable the SurePassID policy value so the provider is allowed to perform autologon.

Local machine (registry)

Under HKLM\SOFTWARE\SurePassId\CredProv:

Value Type Value
AllowAutoLogon REG_SZ 1

Or import a .reg file:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\SurePassId\CredProv]
"AllowAutoLogon"="1"

Set AllowAutoLogon to Enabled in the SurePassID GPO. This writes the value under HKLM\SOFTWARE\Policies\SurePassId\CredProv, which is authoritative and audited. See docs/GPO_SETUP_GUIDE.md.

Step 3 — Verify

  1. Reboot the machine.
  2. The configured account should sign in automatically without an MFA prompt.
  3. Confirm the audit event was written (see below).

Verification and troubleshooting

Enable tracing (TraceOn = 1) and review the SurePassID log / Windows Event Log.

Symptom Likely cause Fix
Machine stops at the logon screen AllowAutoLogon not set to 1 Enable it (Step 2).
Autologon ignored, MFA prompt appears AutoAdminLogon not 1, or username/password missing Re-check Step 1.
Wrong account or domain DefaultUserName / DefaultDomainName incorrect Correct the Winlogon values.
Works then stops after a password change Stored password is stale Re-run Sysinternals Autologon / update the LSA secret.
Local value ignored A GPO policy value overrides it Set the value via GPO, or remove the GPO policy.

The provider writes a security audit event each time autologon is used, recording the account and whether the AllowAutoLogon value came from GPO or the local registry.

Disabling autologon

Set AllowAutoLogon = 0 (or Disabled in GPO), and disable the native autologon (AutoAdminLogon = 0, or click Disable in Sysinternals Autologon). After the next reboot, all users (including the former autologon account) must complete MFA.

Security notes

  • The autologon account is a single-factor bypass by design. Restrict it to kiosk / lab / service machines and use a least-privileged account.
  • Prefer managing AllowAutoLogon via GPO for central control and auditability.
  • Prefer the LSA secret over a plaintext DefaultPassword.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com