SurePassID Windows Login Manager Group Policy Setup Guide
SurePassID Authentication Server
Group Policy (GPO) Setup Guide
Audience: Windows / Active Directory administrators Applies to: SurePassID Windows Login Manager 2026.2 and later
This guide explains how to install and use the SurePassID Group Policy administrative template (ADMX/ADML) to centrally manage the Windows Login Manager settings, including the new AllowAutoLogon policy.
For migrating existing local settings into a GPO, see
GroupPolicy/UserGuide-Add-GPO-Support.md. For the design of
the policy precedence model, see
GroupPolicy/README-GroupPolicy-Design.md.
How it works
The Windows Login Manager reads settings from two registry locations:
| Location | Registry key | Who writes it |
|---|---|---|
| Local (fallback) | HKLM\SOFTWARE\SurePassId\CredProv |
Configuration app / installer |
| Policy (authoritative) | HKLM\SOFTWARE\Policies\SurePassId\CredProv |
Group Policy (GPO) |
Rules enforced automatically:
- If a policy value exists, it always wins.
- If no policy value exists, the local value is used (offline / non-domain machines keep working).
- If a local value disagrees with a policy value, the local value is ignored and a security violation is written to the Windows Event Log.
Prerequisites
| Requirement | Needed for |
|---|---|
| RSAT: Group Policy Management Tools | Editing GPOs |
| Delegated GPO rights (Domain Admin or Create/Edit GPOs) | Creating/editing the GPO |
| Access to the domain Central Store (optional) | Domain-wide template deployment |
Step 1 — Install the administrative template
Copy the template files:
| File | Destination (single machine) | Destination (domain Central Store) |
|---|---|---|
GroupPolicy\SurePassID.admx |
C:\Windows\PolicyDefinitions\ |
\\<domain>\SYSVOL\<domain>\Policies\PolicyDefinitions\ |
GroupPolicy\en-US\SurePassID.adml |
C:\Windows\PolicyDefinitions\en-US\ |
\\<domain>\SYSVOL\<domain>\Policies\PolicyDefinitions\en-US\ |
Using the Central Store is recommended so every administrator sees the same template.
Step 2 — Open the policy settings
- Open Group Policy Management
(
gpmc.msc). - Create or edit a GPO linked to the target computers' OU.
- Navigate to: Computer Configuration ? Policies ? Administrative Templates ? SurePassID ? Windows Login Manager.
Settings are grouped into the following categories:
- Server — authentication server URL, token, key, connectivity.
- Authentication Methods — OTP, SMS, email, push, FIDO2, offline.
- Protection — secure login, PIV, admin MFA, AllowAutoLogon.
- Web Proxy — proxy configuration.
- Logging — tracing and event log settings.
All values are written to
HKLM\SOFTWARE\Policies\SurePassId\CredProv.
Step 3 — Configure AllowAutoLogon
Under the Protection category:
- Open AllowAutoLogon.
- Set it to Enabled to allow the SurePassID provider to perform Windows AutoAdminLogon (the autologon account bypasses MFA), or Disabled / Not Configured to keep MFA enforced for all users.
- Click OK.
Enabling AllowAutoLogon does not by itself configure autologon. You must also configure the native Windows autologon account (username, domain, password). See
docs/AUTOLOGON_SETUP_GUIDE.md.
Boolean policies (like AllowAutoLogon,
AllowPIV, EnforceAdminMfa) write:
| Policy state | Registry value written |
|---|---|
| Enabled | AllowAutoLogon = "1" |
| Disabled | AllowAutoLogon = "0" |
| Not Configured | (no value; local/fallback value applies) |
Step 4 — Link and apply the GPO
- Link the GPO to the OU containing the target computers.
- On a target machine, run
gpupdate /force. - Reboot if you changed logon-related settings such as
AllowAutoLogon.
Step 5 — Verify
- Run
gpresult /h report.htmland confirm the SurePassID settings applied. - Check
HKLM\SOFTWARE\Policies\SurePassId\CredProvfor the expected values. - Review the Windows Event Log (source SurePassID WLM, category Security) for any policy-override violations, which indicate a local value was ignored in favor of the policy value.
Troubleshooting
| Symptom | Likely cause | Fix |
|---|---|---|
| Settings don't appear in the editor | ADMX/ADML not installed or wrong locale folder | Re-copy files; ensure .adml is under the matching
language folder (e.g. en-US). |
| Policy not applying | GPO not linked / not refreshed | Link the GPO; run gpupdate /force. |
| Local change has no effect | A policy value overrides it | Change the value in the GPO, or set the policy to Not Configured. |
| AllowAutoLogon enabled but autologon doesn't happen | Native autologon not configured | Configure Winlogon values (see
docs/AUTOLOGON_SETUP_GUIDE.md). |
| Security violations in the Event Log | Local value differs from policy value | Expected when both are set; the policy value is authoritative. Remove the local value if undesired. |
Related documents
docs/AUTOLOGON_SETUP_GUIDE.md— configuring the autologon account.docs/AUTOLOGON_MFA_DESIGN.md— design and rationale.GroupPolicy/UserGuide-Add-GPO-Support.md— migrating local settings to GPO.GroupPolicy/README-GroupPolicy-Design.md— policy precedence design.
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com