SurePassID Windows Login Manager: Enforce Admin MFA

SurePassID Authentication Server

Enforce Admin MFA

Summary

EnforceAdminMfa is a policy that guarantees administrative users are always subject to multi-factor authentication (MFA). When enabled, if the logging-on user is a member of any configured administrative group, the provider will never fall back to single-factor (password-only) authentication, regardless of any other fallback or offline policy.

This policy overrides:

  • SFAFallbackOption (single-factor fallback options) — forced to SFA_FALLBACK_OPTION_NONE for admins.
  • AllowOffLineAuth (offline single-factor) — offline 1FA fallback is denied for admins.
  • Per-user bypass_mfa returned by the server — ignored for admins.

For non-admin users the existing behavior is unchanged.

Configuration values

Value Type Default Description
EnforceAdminMfa bool false When true, administrative users must complete MFA and can never fall back to single-factor.
AdminMfaGroups string (comma-separated group names) Administrators,Domain Admins Groups whose members are treated as administrators for the purpose of this policy.

AdminMfaGroups is always a comma-separated list of friendly group names. Administrators never enter SIDs. If the value is unset or empty, the policy defaults to Administrators,Domain Admins.

Example:

EnforceAdminMfa = 1
AdminMfaGroups  = Administrators, Domain Admins, MyCompany-PrivilegedOps

Design: names in, SIDs internally

Although administrators configure names, all membership matching is performed using SIDs. This gives three benefits:

  1. Locale-safe — Administrators / Domain Admins are localized on non-English Windows. Matching by SID avoids depending on the display name.
  2. Reliable pre-logon — at the credential-provider stage the user's access token does not yet exist, so token string comparisons are fragile. SID comparison against the account's group SIDs is deterministic.
  3. Well-known groups are aliased to SIDs — the two defaults are not resolved by a localized string lookup; they map to fixed well-known SIDs.

Resolving configured names to SIDs

For each configured group name:

Configured name (case-insensitive) Resolution Well-known SID
Administrators CreateWellKnownSid(WinBuiltinAdministratorsSid) S-1-5-32-544
Domain Admins CreateWellKnownSid(WinAccountDomainAdminsSid, <machine domain SID>) <domain>-512
anything else LookupAccountNameW(name) resolved SID

If a custom name cannot be resolved, it is logged and skipped. Because this is an enforcement feature, skipping an unresolvable entry fails safe (it simply does not grant an exemption).

Testing membership

The user's SID and account/domain name are available early during credential initialization. Group SIDs for the account are enumerated (NetUserGetGroups for global/domain groups such as Domain Admins, and NetUserGetLocalGroups with LG_INCLUDE_INDIRECT for local groups such as Administrators, including nested membership). Each enumerated group name is resolved to a SID and compared to the target SID list with EqualSid. The first match marks the user as an administrator.

config names --resolve--> target SIDs --+
                                        |
                                        +-- EqualSid --> isAdmin?
                                        |
user account --enumerate groups--> SIDs +

Shared implementation

All of the new logic (resolving configured group names to SIDs, enumerating a user's groups, and comparing SIDs) lives in the shared SurePassIdLib library in the AdminGroupPolicy class, so both consumers use the exact same code:

  • Credential provider (SurePassIdCredential) — disables all single-factor fallback paths when the user is an enforced admin.
  • Credential provider filter (SurePassIdProviderFilter) — suppresses the password-only credential provider for enforced admins, mirroring the existing UACForceMfa behavior.

Public API (SurePassIdLib/AdminGroupPolicy.h)

class AdminGroupPolicy {
public:
    // Reads EnforceAdminMfa (default false).
    static bool IsEnforceAdminMfaEnabled();

    // Returns true when the given account is a member of any configured
    // administrative group (AdminMfaGroups, default "Administrators,Domain Admins").
    static bool IsUserAdmin(PCWSTR pszAccount, PCWSTR pszDomain);

    // Convenience: EnforceAdminMfa enabled AND the user is an admin.
    static bool ShouldEnforceMfaForUser(PCWSTR pszAccount, PCWSTR pszDomain);
};

Enforcement points

Location Behavior when enforced admin
SurePassIdCredential::Initialize (offline, already-offline branch) _fAllowFallback = false even when AllowOffLineAuth == 1FA.
SurePassIdCredential::Initialize (FindUser connection-error branch) _fAllowFallback = false even when AllowOffLineAuth == 1FA.
SurePassIdCredential::Initialize (online decision) _fAllowFallback = false after bypass/fallback-option checks.
SurePassIdProviderFilter Password-only provider hidden (as with UACForceMfa).

Admin not provisioned for MFA

When EnforceAdminMfa is on and the administrator would normally have been allowed to fall back to single-factor because they are not provisioned for MFA, MFA can never be satisfied. Rather than letting the logon proceed and fail later at OTP validation, the provider fails fast:

An admin is considered not provisioned when any of the following is true from the FindUser result:

  • the user is not found in SurePassID (find_user_error_code == 9001), or
  • the server returned bypass_mfa for the account, or
  • the user exists but has no active 2FA devices (device_count == 0).

In that case the provider:

  1. Writes security event MSG_ADMIN_MFA_NOT_PROVISIONED (ID 2011, category Security) to the Windows Application Event Log — subject to the normal event-log enable/disable policy (WriteToEventLog), so it can be turned off.
  2. Displays a distinct message to the user — ADMIN_MFA_NOT_PROVISIONED ("Multi-factor authentication is required for administrators, but your account is not enrolled for MFA. Contact your administrator.") — and returns ERROR_NOT_AUTHENTICATED without waiting for OTP validation.

This applies to both the current-user path and the "Other user" path in GetSerialization.

SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com