SurePassID Windows Login Manager Configuration Reference

SurePassID Authentication Server

SurePassID Windows Login Manager - Configuration Reference

WindowsLoginManager reads all of its policy from the Windows registry. Value names are surfaced by ConfigurationManager. This document describes each recognized value.

Value names below are the exact registry value names read by the provider. Consult your deployment/installer for the hive and key path used in your environment. Boolean-style values are commonly stored as strings; the provider treats values beginning with 1, T, or t as true.

SurePassID Authenticator Server

Value Description
AuthServerURL Base URL / endpoint of the SurePassID authenticator (MFA) server.
AuthServerToken Server API token used to authenticate requests.
AuthServerKey Server API key/secret paired with the token.
ConnectionAllowHttp Allow HTTP (non-TLS) connections to the server. Testing/development only.
ConnectionTimeoutSeconds HTTP connection timeout (seconds) for server calls. See SPRegistry::GetConnectionTimeOut.
DisableMfaServerConnectivity Disables the MFA server connectivity check.
SessionSeconds Lifetime of an authenticated session.

Web proxy

Value Description
ProxySetting Proxy mode: 0 = none (PROXY_SETTING_NONE), 1 = manual (PROXY_SETTING_MANUAL), 2 = auto (PROXY_SETTING_AUTO).
ProxyDomain Proxy host/domain.
ProxyPort Proxy port.

OATH / OTP authentication methods

Value Description
AllowOtp Allow one-time passcode (OTP) entry.
AllowSMS Allow OTP delivery via SMS.
AllowEmail Allow OTP delivery via email.
AllowCall Allow OTP delivery via voice call.

Push authentication methods

Value Description
AutoAuthMethod The default/auto-selected authentication method.
AllowPushApp Allow push approval via the mobile app.
AllowPushSMS Allow push delivery via SMS.
AllowPushVoice Allow push delivery via voice.
AllowPushAppSMS Deprecated.
PushPromptUser Deprecated.
PushAppName App name shown in the push prompt (max length MAX_PUSH_NAME_LENGTH = 20).
PushReason Reason text shown in the push prompt (max length MAX_PUSH_REASON_LENGTH = 20).
PushRelyingPartyUrl Relying-party URL used for push authentication.

FIDO2 / security key

Value Description
AllowFido2SecurityKey Allow FIDO2 security-key (second-factor) authentication.
AllowFido2Passwordless Allow FIDO2 passwordless authentication.
AllowOfflineFido2 Enable FIDO2 offline authentication. Setting to 0 invalidates any cached FIDO2 credentials.
FIDO2Origin The FIDO2 origin value used for assertions.
NfcSharedAccess Use PC/SC shared access mode for NFC readers. See SPRegistry::ReadRegistryPcscSharedMode.
NfcAllowedReaders Restrict NFC to a specific set of allowed readers. See SPRegistry::ReadRegistryNfcAllowedReaders.

PIV (smart card)

Value Description
AllowPIV Allow PIV / smart-card authentication.

UAC

Value Description
UACForceMfa Force MFA during UAC (elevation / CredUI) prompts.

Single-factor (SFA) behavior & fallback

Value Description
AllowSingleFactorTestMode Enables single-factor test mode. Testing only — not for production.
SFAFallbackOption Controls when a single-factor logon is allowed as a fallback. Read by SPRegistry::ReadGetRegistrySingleFactorFallbackOption and consumed by AuthenticationDecisionEngine. See below.
SFADomainWhiteList Comma-separated whitelist of domains permitted to use SFA. Read by SPRegistry::ReadRegistrySFADomainWhitelist and checked by ConfigurationManager::CheckSFADomainWhiteList.
EnforceAdminMfa When true, administrative users must complete MFA and can never fall back to single-factor. Overrides SFAFallbackOption, AllowOffLineAuth, and per-user bypass_mfa. See ENFORCE_ADMIN_MFA.md.
AdminMfaGroups Comma-separated list of group names whose members are treated as administrators for EnforceAdminMfa. Defaults to Administrators,Domain Admins.
ForceLocalAuth Force local (Windows) authentication. See SPRegistry::ReadRegistryForceLocalAuthentication.

SFAFallbackOption values

AuthenticationDecisionEngine::CheckForFallbackFromFallbackOption interprets this value together with the FindUser result and the user's device count:

Option Behavior
SFA_FALLBACK_OPTION_NONE Never fall back to single-factor.
SFA_FALLBACK_OPTION_NO_SP_USER Allow SFA when the user is not found in SurePassID (FindUser returns not found, error 9001).
SFA_FALLBACK_OPTION_SP_USER_NO_2FA_DEVICES Allow SFA when the user exists but has no registered 2FA devices.

Optional protection

Value Description
OnlySecureWindowsLogin Restrict authentication to secure Windows logon scenarios.
AllowUserToChangePassword Permit the user to change their Windows password from the tile.

Offline authentication

Value Description
AllowOffLineAuth Controls offline OTP behavior. ConfigurationManager::GetOfflineOtpOption maps: 0 ? offline-2FA, 2 ? offline-1FA, otherwise ? 2FA (OFFLINE_OPTION_2FA). Setting to 0 invalidates any cached OTP credentials.
AllowOfflineFido2 (See FIDO2 section.) Enables offline FIDO2 authentication.

Credential provider filter / tile whitelisting

Value Description
CredentialProviderWhiteList GUID-based whitelist of credential-provider tiles allowed by the provider filter. Read via SPRegistry::ReadRegistryCredProvWhiteList / ReadCredProvWhiteListAsGuids.

Bypass & domain

Value Description
BypassCode Configured MFA bypass code. Supports the {pt} (plain text), {sha256} (hashed), and {notallowed} forms handled by CSurePassClientLib::Check2FABypassCode. Use of a bypass code raises the MSG_MFA_BYPASS_CODE_USED Windows security event.
DefaultDomain Default Windows domain applied to the entered username. See SPRegistry::ReadRegistryDefaultDomain.
UsernameCache When enabled (1/T/t), caches the last username. See ConfigurationManager::IsUsernameCacheOn.

Logging / diagnostics

Value Description
LogLevel Trace verbosity for SPLog: Error, Warning, Info, Trace.
TraceFilePath Destination path for trace output.
LogFilenameBase Base name for log files.
LogFilenameExtension Extension for log files.
TraceOfflineCache Enable extra tracing of the offline cache. See SPRegistry::ReadRegistryTraceOffLineCache.
WriteToEventLog Forward Error/Warning (and Info) messages to the Windows Application Event Log. Enabled by default.
WriteTraceToEventLog When enabled (and LogLevel is Trace), also forward Trace entries to the Windows Event Log.
TraceOn Deprecated — superseded by LogLevel.

Configuration source control

Value Description
UsePropertyFile Read configuration from a property file instead of (or in addition to) the registry.
PropertyFilePath Path to the property file when UsePropertyFile is enabled.

Notes

  • Changing these values takes effect on the next logon, since the provider reads configuration when it constructs a credential.
  • Some values (e.g. AuthServerToken, AuthServerKey) are also accessed as wide strings (REG_AUTH_SERVER_TOKEN_WCS, REG_AUTH_SERVER_KEY_WCS) internally.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com