SurePassID Windows Login Manager AutoLogon Setup Guide
SurePassID Authentication Server
SurePassID Windows Logon Manager - AutoLogon Setup Guide
This guide explains how to configure Windows AutoAdminLogon so that it continues to work when the SurePassID Windows Login Manager is enforcing MFA.
For the design and rationale, see
docs/AUTOLOGON_MFA_DESIGN.md.
Overview
When SurePassID enforces MFA it disables the built-in Windows password credential provider, which normally stops native autologon from working. With this capability enabled, the SurePassID provider performs the autologon itself for the single configured autologon account, bypassing MFA for that account.
Key points:
- Applies to one account per machine (the native Windows autologon account).
- Persistent — it runs on every reboot, not just once.
- Disabled by default. You must explicitly enable
AllowAutoLogon. - The autologon account bypasses MFA. Treat it as a single-factor account and scope it to kiosk / service / lab machines.
Prerequisites
- SurePassID Windows Login Manager installed and enforcing MFA.
- Local administrator rights on the machine (or GPO management rights for domain deployment).
- The account you want to auto-log-on already exists and can sign in normally.
Step 1 — Configure the Windows autologon account
You can set the native autologon values with Sysinternals Autologon (recommended, stores the password as an encrypted LSA secret) or manually.
Option A: Sysinternals Autologon (recommended)
- Download
Autologonfrom Sysinternals. - Run it as administrator.
- Enter the Username, Domain, and Password.
- Click Enable.
This stores DefaultUserName,
DefaultDomainName, sets AutoAdminLogon = 1,
and saves the password as the LSA private secret
DefaultPassword (encrypted).
Option B: Manual registry
Under
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon:
| Value | Type | Example |
|---|---|---|
AutoAdminLogon |
REG_SZ | 1 |
DefaultUserName |
REG_SZ | kioskuser |
DefaultDomainName |
REG_SZ | CONTOSO |
DefaultPassword |
REG_SZ | (plaintext — discouraged) |
Storing
DefaultPasswordin the registry keeps the password in plaintext. Prefer Option A so it is stored as an encrypted LSA secret. The provider reads the LSA secret first and only falls back to the plaintext value.
Step 2 — Enable
AllowAutoLogon for SurePassID
Enable the SurePassID policy value so the provider is allowed to perform autologon.
Local machine (registry)
Under HKLM\SOFTWARE\SurePassId\CredProv:
| Value | Type | Value |
|---|---|---|
AllowAutoLogon |
REG_SZ | 1 |
Or import a .reg file:
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\SurePassId\CredProv]
"AllowAutoLogon"="1"
Domain (Group Policy) — recommended
Set AllowAutoLogon to Enabled in
the SurePassID GPO. This writes the value under
HKLM\SOFTWARE\Policies\SurePassId\CredProv, which is
authoritative and audited. See docs/GPO_SETUP_GUIDE.md.
Step 3 — Verify
- Reboot the machine.
- The configured account should sign in automatically without an MFA prompt.
- Confirm the audit event was written (see below).
Verification and troubleshooting
Enable tracing (TraceOn = 1) and review the SurePassID
log / Windows Event Log.
| Symptom | Likely cause | Fix |
|---|---|---|
| Machine stops at the logon screen | AllowAutoLogon not set to 1 |
Enable it (Step 2). |
| Autologon ignored, MFA prompt appears | AutoAdminLogon not 1, or username/password
missing |
Re-check Step 1. |
| Wrong account or domain | DefaultUserName / DefaultDomainName
incorrect |
Correct the Winlogon values. |
| Works then stops after a password change | Stored password is stale | Re-run Sysinternals Autologon / update the LSA secret. |
| Local value ignored | A GPO policy value overrides it | Set the value via GPO, or remove the GPO policy. |
The provider writes a security audit event each time
autologon is used, recording the account and whether the
AllowAutoLogon value came from GPO or the local
registry.
Disabling autologon
Set AllowAutoLogon = 0 (or Disabled in
GPO), and disable the native autologon
(AutoAdminLogon = 0, or click Disable in
Sysinternals Autologon). After the next reboot, all users (including the
former autologon account) must complete MFA.
Security notes
- The autologon account is a single-factor bypass by design. Restrict it to kiosk / lab / service machines and use a least-privileged account.
- Prefer managing
AllowAutoLogonvia GPO for central control and auditability. - Prefer the LSA secret over a plaintext
DefaultPassword.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com