SurePassID Windows Login Manager: Enforce Admin MFA
SurePassID Authentication Server
Enforce Admin MFA
Summary
EnforceAdminMfa is a policy that guarantees
administrative users are always subject to multi-factor
authentication (MFA). When enabled, if the logging-on user is a member
of any configured administrative group, the provider will
never fall back to single-factor (password-only)
authentication, regardless of any other fallback or offline policy.
This policy overrides:
SFAFallbackOption(single-factor fallback options) — forced toSFA_FALLBACK_OPTION_NONEfor admins.AllowOffLineAuth(offline single-factor) — offline1FAfallback is denied for admins.- Per-user
bypass_mfareturned by the server — ignored for admins.
For non-admin users the existing behavior is unchanged.
Configuration values
| Value | Type | Default | Description |
|---|---|---|---|
EnforceAdminMfa |
bool | false |
When true, administrative users must complete MFA and
can never fall back to single-factor. |
AdminMfaGroups |
string (comma-separated group names) | Administrators,Domain Admins |
Groups whose members are treated as administrators for the purpose of this policy. |
AdminMfaGroups is always a comma-separated list of
friendly group names. Administrators never enter SIDs.
If the value is unset or empty, the policy defaults to
Administrators,Domain Admins.
Example:
EnforceAdminMfa = 1
AdminMfaGroups = Administrators, Domain Admins, MyCompany-PrivilegedOps
Design: names in, SIDs internally
Although administrators configure names, all membership matching is performed using SIDs. This gives three benefits:
- Locale-safe —
Administrators/Domain Adminsare localized on non-English Windows. Matching by SID avoids depending on the display name. - Reliable pre-logon — at the credential-provider stage the user's access token does not yet exist, so token string comparisons are fragile. SID comparison against the account's group SIDs is deterministic.
- Well-known groups are aliased to SIDs — the two defaults are not resolved by a localized string lookup; they map to fixed well-known SIDs.
Resolving configured names to SIDs
For each configured group name:
| Configured name (case-insensitive) | Resolution | Well-known SID |
|---|---|---|
Administrators |
CreateWellKnownSid(WinBuiltinAdministratorsSid) |
S-1-5-32-544 |
Domain Admins |
CreateWellKnownSid(WinAccountDomainAdminsSid, <machine domain SID>) |
<domain>-512 |
| anything else | LookupAccountNameW(name) |
resolved SID |
If a custom name cannot be resolved, it is logged and skipped. Because this is an enforcement feature, skipping an unresolvable entry fails safe (it simply does not grant an exemption).
Testing membership
The user's SID and account/domain name are available early during
credential initialization. Group SIDs for the account are enumerated
(NetUserGetGroups for global/domain groups such as
Domain Admins, and NetUserGetLocalGroups with
LG_INCLUDE_INDIRECT for local groups such as
Administrators, including nested membership). Each enumerated
group name is resolved to a SID and compared to the target SID list with
EqualSid. The first match marks the user as an
administrator.
config names --resolve--> target SIDs --+
|
+-- EqualSid --> isAdmin?
|
user account --enumerate groups--> SIDs +
Shared implementation
All of the new logic (resolving configured group names to SIDs,
enumerating a user's groups, and comparing SIDs) lives in the shared
SurePassIdLib library in the AdminGroupPolicy
class, so both consumers use the exact same code:
- Credential provider
(
SurePassIdCredential) — disables all single-factor fallback paths when the user is an enforced admin. - Credential provider filter
(
SurePassIdProviderFilter) — suppresses the password-only credential provider for enforced admins, mirroring the existingUACForceMfabehavior.
Public API
(SurePassIdLib/AdminGroupPolicy.h)
class AdminGroupPolicy {
public:
// Reads EnforceAdminMfa (default false).
static bool IsEnforceAdminMfaEnabled();
// Returns true when the given account is a member of any configured
// administrative group (AdminMfaGroups, default "Administrators,Domain Admins").
static bool IsUserAdmin(PCWSTR pszAccount, PCWSTR pszDomain);
// Convenience: EnforceAdminMfa enabled AND the user is an admin.
static bool ShouldEnforceMfaForUser(PCWSTR pszAccount, PCWSTR pszDomain);
};Enforcement points
| Location | Behavior when enforced admin |
|---|---|
SurePassIdCredential::Initialize (offline,
already-offline branch) |
_fAllowFallback = false even when
AllowOffLineAuth == 1FA. |
SurePassIdCredential::Initialize (FindUser
connection-error branch) |
_fAllowFallback = false even when
AllowOffLineAuth == 1FA. |
SurePassIdCredential::Initialize (online decision) |
_fAllowFallback = false after bypass/fallback-option
checks. |
SurePassIdProviderFilter |
Password-only provider hidden (as with
UACForceMfa). |
Admin not provisioned for MFA
When EnforceAdminMfa is on and the administrator would
normally have been allowed to fall back to single-factor because they
are not provisioned for MFA, MFA can never be
satisfied. Rather than letting the logon proceed and fail later at OTP
validation, the provider fails fast:
An admin is considered not provisioned when any of the
following is true from the FindUser result:
- the user is not found in SurePassID
(
find_user_error_code == 9001), or - the server returned
bypass_mfafor the account, or - the user exists but has no active 2FA devices
(
device_count == 0).
In that case the provider:
- Writes security event
MSG_ADMIN_MFA_NOT_PROVISIONED(ID2011, categorySecurity) to the Windows Application Event Log — subject to the normal event-log enable/disable policy (WriteToEventLog), so it can be turned off. - Displays a distinct message to the user —
ADMIN_MFA_NOT_PROVISIONED("Multi-factor authentication is required for administrators, but your account is not enrolled for MFA. Contact your administrator.") — and returnsERROR_NOT_AUTHENTICATEDwithout waiting for OTP validation.
This applies to both the current-user path and the "Other user" path
in
GetSerialization.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com