SurePassID Windows Login Manager Group Policy Setup Guide

SurePassID Authentication Server

Group Policy (GPO) Setup Guide

Audience: Windows / Active Directory administrators Applies to: SurePassID Windows Login Manager 2026.2 and later

This guide explains how to install and use the SurePassID Group Policy administrative template (ADMX/ADML) to centrally manage the Windows Login Manager settings, including the new AllowAutoLogon policy.

For migrating existing local settings into a GPO, see GroupPolicy/UserGuide-Add-GPO-Support.md. For the design of the policy precedence model, see GroupPolicy/README-GroupPolicy-Design.md.


How it works

The Windows Login Manager reads settings from two registry locations:

Location Registry key Who writes it
Local (fallback) HKLM\SOFTWARE\SurePassId\CredProv Configuration app / installer
Policy (authoritative) HKLM\SOFTWARE\Policies\SurePassId\CredProv Group Policy (GPO)

Rules enforced automatically:

  • If a policy value exists, it always wins.
  • If no policy value exists, the local value is used (offline / non-domain machines keep working).
  • If a local value disagrees with a policy value, the local value is ignored and a security violation is written to the Windows Event Log.

Prerequisites

Requirement Needed for
RSAT: Group Policy Management Tools Editing GPOs
Delegated GPO rights (Domain Admin or Create/Edit GPOs) Creating/editing the GPO
Access to the domain Central Store (optional) Domain-wide template deployment

Step 1 — Install the administrative template

Copy the template files:

File Destination (single machine) Destination (domain Central Store)
GroupPolicy\SurePassID.admx C:\Windows\PolicyDefinitions\ \\<domain>\SYSVOL\<domain>\Policies\PolicyDefinitions\
GroupPolicy\en-US\SurePassID.adml C:\Windows\PolicyDefinitions\en-US\ \\<domain>\SYSVOL\<domain>\Policies\PolicyDefinitions\en-US\

Using the Central Store is recommended so every administrator sees the same template.


Step 2 — Open the policy settings

  1. Open Group Policy Management (gpmc.msc).
  2. Create or edit a GPO linked to the target computers' OU.
  3. Navigate to: Computer Configuration ? Policies ? Administrative Templates ? SurePassID ? Windows Login Manager.

Settings are grouped into the following categories:

  • Server — authentication server URL, token, key, connectivity.
  • Authentication Methods — OTP, SMS, email, push, FIDO2, offline.
  • Protection — secure login, PIV, admin MFA, AllowAutoLogon.
  • Web Proxy — proxy configuration.
  • Logging — tracing and event log settings.

All values are written to HKLM\SOFTWARE\Policies\SurePassId\CredProv.


Step 3 — Configure AllowAutoLogon

Under the Protection category:

  1. Open AllowAutoLogon.
  2. Set it to Enabled to allow the SurePassID provider to perform Windows AutoAdminLogon (the autologon account bypasses MFA), or Disabled / Not Configured to keep MFA enforced for all users.
  3. Click OK.

Enabling AllowAutoLogon does not by itself configure autologon. You must also configure the native Windows autologon account (username, domain, password). See docs/AUTOLOGON_SETUP_GUIDE.md.

Boolean policies (like AllowAutoLogon, AllowPIV, EnforceAdminMfa) write:

Policy state Registry value written
Enabled AllowAutoLogon = "1"
Disabled AllowAutoLogon = "0"
Not Configured (no value; local/fallback value applies)

  1. Link the GPO to the OU containing the target computers.
  2. On a target machine, run gpupdate /force.
  3. Reboot if you changed logon-related settings such as AllowAutoLogon.

Step 5 — Verify

  • Run gpresult /h report.html and confirm the SurePassID settings applied.
  • Check HKLM\SOFTWARE\Policies\SurePassId\CredProv for the expected values.
  • Review the Windows Event Log (source SurePassID WLM, category Security) for any policy-override violations, which indicate a local value was ignored in favor of the policy value.

Troubleshooting

Symptom Likely cause Fix
Settings don't appear in the editor ADMX/ADML not installed or wrong locale folder Re-copy files; ensure .adml is under the matching language folder (e.g. en-US).
Policy not applying GPO not linked / not refreshed Link the GPO; run gpupdate /force.
Local change has no effect A policy value overrides it Change the value in the GPO, or set the policy to Not Configured.
AllowAutoLogon enabled but autologon doesn't happen Native autologon not configured Configure Winlogon values (see docs/AUTOLOGON_SETUP_GUIDE.md).
Security violations in the Event Log Local value differs from policy value Expected when both are set; the policy value is authoritative. Remove the local value if undesired.

  • docs/AUTOLOGON_SETUP_GUIDE.md — configuring the autologon account.
  • docs/AUTOLOGON_MFA_DESIGN.md — design and rationale.
  • GroupPolicy/UserGuide-Add-GPO-Support.md — migrating local settings to GPO.
  • GroupPolicy/README-GroupPolicy-Design.md — policy precedence design.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com