SurePassID Windows Login Manager Configuration Reference
SurePassID Authentication Server
SurePassID Windows Login Manager - Configuration Reference
WindowsLoginManager reads all of its policy from the
Windows registry. Value names are surfaced by
ConfigurationManager. This document describes each
recognized value.
Value names below are the exact registry value names read by the provider. Consult your deployment/installer for the hive and key path used in your environment. Boolean-style values are commonly stored as strings; the provider treats values beginning with
1,T, ortas true.
SurePassID Authenticator Server
| Value | Description |
|---|---|
AuthServerURL |
Base URL / endpoint of the SurePassID authenticator (MFA) server. |
AuthServerToken |
Server API token used to authenticate requests. |
AuthServerKey |
Server API key/secret paired with the token. |
ConnectionAllowHttp |
Allow HTTP (non-TLS) connections to the server. Testing/development only. |
ConnectionTimeoutSeconds |
HTTP connection timeout (seconds) for server calls. See
SPRegistry::GetConnectionTimeOut. |
DisableMfaServerConnectivity |
Disables the MFA server connectivity check. |
SessionSeconds |
Lifetime of an authenticated session. |
Web proxy
| Value | Description |
|---|---|
ProxySetting |
Proxy mode: 0 = none (PROXY_SETTING_NONE),
1 = manual (PROXY_SETTING_MANUAL),
2 = auto (PROXY_SETTING_AUTO). |
ProxyDomain |
Proxy host/domain. |
ProxyPort |
Proxy port. |
OATH / OTP authentication methods
| Value | Description |
|---|---|
AllowOtp |
Allow one-time passcode (OTP) entry. |
AllowSMS |
Allow OTP delivery via SMS. |
AllowEmail |
Allow OTP delivery via email. |
AllowCall |
Allow OTP delivery via voice call. |
Push authentication methods
| Value | Description |
|---|---|
AutoAuthMethod |
The default/auto-selected authentication method. |
AllowPushApp |
Allow push approval via the mobile app. |
AllowPushSMS |
Allow push delivery via SMS. |
AllowPushVoice |
Allow push delivery via voice. |
AllowPushAppSMS |
Deprecated. |
PushPromptUser |
Deprecated. |
PushAppName |
App name shown in the push prompt (max length
MAX_PUSH_NAME_LENGTH = 20). |
PushReason |
Reason text shown in the push prompt (max length
MAX_PUSH_REASON_LENGTH = 20). |
PushRelyingPartyUrl |
Relying-party URL used for push authentication. |
FIDO2 / security key
| Value | Description |
|---|---|
AllowFido2SecurityKey |
Allow FIDO2 security-key (second-factor) authentication. |
AllowFido2Passwordless |
Allow FIDO2 passwordless authentication. |
AllowOfflineFido2 |
Enable FIDO2 offline authentication. Setting to 0
invalidates any cached FIDO2 credentials. |
FIDO2Origin |
The FIDO2 origin value used for assertions. |
NfcSharedAccess |
Use PC/SC shared access mode for NFC readers. See
SPRegistry::ReadRegistryPcscSharedMode. |
NfcAllowedReaders |
Restrict NFC to a specific set of allowed readers. See
SPRegistry::ReadRegistryNfcAllowedReaders. |
PIV (smart card)
| Value | Description |
|---|---|
AllowPIV |
Allow PIV / smart-card authentication. |
UAC
| Value | Description |
|---|---|
UACForceMfa |
Force MFA during UAC (elevation / CredUI) prompts. |
Single-factor (SFA) behavior & fallback
| Value | Description |
|---|---|
AllowSingleFactorTestMode |
Enables single-factor test mode. Testing only — not for production. |
SFAFallbackOption |
Controls when a single-factor logon is allowed as a fallback. Read
by SPRegistry::ReadGetRegistrySingleFactorFallbackOption
and consumed by AuthenticationDecisionEngine. See
below. |
SFADomainWhiteList |
Comma-separated whitelist of domains permitted to use SFA. Read by
SPRegistry::ReadRegistrySFADomainWhitelist and checked by
ConfigurationManager::CheckSFADomainWhiteList. |
EnforceAdminMfa |
When true, administrative users must complete MFA and
can never fall back to single-factor. Overrides
SFAFallbackOption, AllowOffLineAuth, and
per-user bypass_mfa. See
ENFORCE_ADMIN_MFA.md. |
AdminMfaGroups |
Comma-separated list of group names whose members
are treated as administrators for EnforceAdminMfa. Defaults
to Administrators,Domain Admins. |
ForceLocalAuth |
Force local (Windows) authentication. See
SPRegistry::ReadRegistryForceLocalAuthentication. |
SFAFallbackOption
values
AuthenticationDecisionEngine::CheckForFallbackFromFallbackOption
interprets this value together with the FindUser result and
the user's device count:
| Option | Behavior |
|---|---|
SFA_FALLBACK_OPTION_NONE |
Never fall back to single-factor. |
SFA_FALLBACK_OPTION_NO_SP_USER |
Allow SFA when the user is not found in SurePassID
(FindUser returns not found, error
9001). |
SFA_FALLBACK_OPTION_SP_USER_NO_2FA_DEVICES |
Allow SFA when the user exists but has no registered 2FA devices. |
Optional protection
| Value | Description |
|---|---|
OnlySecureWindowsLogin |
Restrict authentication to secure Windows logon scenarios. |
AllowUserToChangePassword |
Permit the user to change their Windows password from the tile. |
Offline authentication
| Value | Description |
|---|---|
AllowOffLineAuth |
Controls offline OTP behavior.
ConfigurationManager::GetOfflineOtpOption maps:
0 ? offline-2FA, 2 ? offline-1FA, otherwise ?
2FA (OFFLINE_OPTION_2FA). Setting to 0
invalidates any cached OTP credentials. |
AllowOfflineFido2 |
(See FIDO2 section.) Enables offline FIDO2 authentication. |
Credential provider filter / tile whitelisting
| Value | Description |
|---|---|
CredentialProviderWhiteList |
GUID-based whitelist of credential-provider tiles allowed by the
provider filter. Read via
SPRegistry::ReadRegistryCredProvWhiteList /
ReadCredProvWhiteListAsGuids. |
Bypass & domain
| Value | Description |
|---|---|
BypassCode |
Configured MFA bypass code. Supports the {pt} (plain
text), {sha256} (hashed), and {notallowed}
forms handled by CSurePassClientLib::Check2FABypassCode.
Use of a bypass code raises the MSG_MFA_BYPASS_CODE_USED
Windows security event. |
DefaultDomain |
Default Windows domain applied to the entered username. See
SPRegistry::ReadRegistryDefaultDomain. |
UsernameCache |
When enabled (1/T/t), caches
the last username. See
ConfigurationManager::IsUsernameCacheOn. |
Logging / diagnostics
| Value | Description |
|---|---|
LogLevel |
Trace verbosity for SPLog: Error,
Warning, Info, Trace. |
TraceFilePath |
Destination path for trace output. |
LogFilenameBase |
Base name for log files. |
LogFilenameExtension |
Extension for log files. |
TraceOfflineCache |
Enable extra tracing of the offline cache. See
SPRegistry::ReadRegistryTraceOffLineCache. |
WriteToEventLog |
Forward Error/Warning (and Info) messages to the Windows Application Event Log. Enabled by default. |
WriteTraceToEventLog |
When enabled (and LogLevel is Trace), also forward
Trace entries to the Windows Event Log. |
TraceOn |
Deprecated — superseded by
LogLevel. |
Configuration source control
| Value | Description |
|---|---|
UsePropertyFile |
Read configuration from a property file instead of (or in addition to) the registry. |
PropertyFilePath |
Path to the property file when UsePropertyFile is
enabled. |
Notes
- Changing these values takes effect on the next logon, since the provider reads configuration when it constructs a credential.
- Some values (e.g.
AuthServerToken,AuthServerKey) are also accessed as wide strings (REG_AUTH_SERVER_TOKEN_WCS,REG_AUTH_SERVER_KEY_WCS) internally.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com