SurePassID Identity Provider
Release 2026.4
Overview
This release introduces significant security enhancements, policy evaluation improvements, and expanded protocol support across all three federation surfaces of the SurePassID Identity Provider: SAML 2.0, OpenID Connect (OIDC), and the Microsoft Entra ID External Authentication Method (EAM). Key improvements include centralized policy evaluation, enhanced security validation, comprehensive Single Logout (SLO) support for both SAML and OIDC, a full OIDC authorization server implementation, EAM support for Entra ID multifactor authentication, and improved audit logging.
All tenant, client, and protocol configuration is performed in the SurePassID Admin Portal.
✨ New Features
1. Centralized Federation Policy Evaluation
Key Benefits:
- ✅ Consistent policy evaluation across all SSO applications
- ✅ Centralized policy logic in shared library
- ✅ Enhanced audit logging with JSON-serialized results
- ✅ Support for IP whitelist and time-based access controls
- ✅ Multiple enforcement modes (Ignore, Log, Enforce)
2. Enhanced SSO Security Validation Audit Logging
2.1 Replay Attack
- Audit Code:
AuditResultCode.SSOReplayAttackDetected
2.2 SP Issuer Validation
2.3 AuthnRequest Signature Validation
- Audit Codes:
AuditResultCode.SSOAuthnRequestSignatureInvalidAuditResultCode.SSOAuthnRequestSignatureRequired- Include telemetric data for further automated analysis
3. Comprehensive Single Logout (SLO) Support
3.1 SP-Initiated Logout
- Support: Full support for Service Provider initiated logout requests
- Features:
- Validates logout request signatures (if configured)
- Checks for replay attacks on logout requests
- Validates destination URL matches IdP SLO endpoint
- Sends signed logout responses (configurable)
- Removes SAML sessions from cache
3.2 IdP-Initiated Logout
- Support: Full Identity Provider initiated logout with response handling
- Features:
- Processes logout responses from Service Providers
- Logs success/failure status codes
- Handles status messages and error conditions
3.3 Logout Request Security Validations
Replay Attack Prevention:
- Audit Code:
AuditResultCode.SSOReplayAttackDetected
Destination Validation:
- Audit Code:
AuditResultCode.SSOLogoutDestinationMismatch
Signature Validation:
- Audit Codes:
AuditResultCode.SSOLogoutSignatureRequiredAuditResultCode.SSOLogoutSignatureInvalid
- Protection: Validates request authenticity and integrity
4. SAML Session Management
Location: SamlRequestIdCache
(referenced in SLO service)
Features:
- Session tracking with
SessionIndexsupport - Session cache for logout request validation
- Automatic session removal on logout
- Session information includes:
- User ID
- Partner ID
- SP Entity ID
- Creation timestamp
5. Enhanced Audit Trail
Improvements:
- Detailed audit logging for all SSO/SLO operations
- JSON-serialized policy evaluation results
- Security event tracking with severity levels
- Request/response correlation via unique IDs
New Audit Result Codes: | Code | Description |
|------|-------------| | SSOReplayAttackDetected |
Duplicate request ID detected | |
SSOAuthnRequestSignatureInvalid | AuthnRequest signature
failed verification | | SSOAuthnRequestSignatureRequired |
Signature required but not present | |
SSOLogoutDestinationMismatch | Logout destination doesn't
match expected URL | | SSOLogoutSignatureRequired | Logout
signature required but not present | |
SSOLogoutSignatureInvalid | Logout signature failed
verification | | SSOAcsUrlMismatch | ACS URL doesn't match
registered URL |
6. OpenID Connect (OIDC) Provider
The Identity Provider now exposes a full OpenID Connect authorization server alongside SAML 2.0. Each tenant has its own issuer, signing keys, and discovery document.
Endpoints: | Purpose | URL Pattern |
|---------|-------------| | Discovery |
/oidc/{domain}/.well-known/openid-configuration | | JWKS |
/oidc/{domain}/jwks | | Authorization |
/oidc/{domain}/authorize | | Token |
/oidc/{domain}/token | | UserInfo |
/oidc/{domain}/userinfo | | Logout |
/oidc/{domain}/logout |
Supported Capabilities:
- ✅ Authorization Code flow (
response_type=code) - ✅ Refresh token grant with rotation and reuse detection
- ✅ PKCE (
S256), enforceable per client - ✅ Client authentication via
client_secret_basic,client_secret_post, andnone(public clients) - ✅ Signed request objects (JAR, RFC 9101) using
RS256 - ✅ Claims parameter support (OIDC Core section 5.5)
- ✅ UserInfo endpoint with scope-based claim release
- ✅ Consent screen with durable per-client consent grants
- ✅ RP-initiated logout with front-channel and back-channel Single Logout
- ✅ JWKS publication with two-key overlap for zero-downtime key rotation
- ✅ Per-tenant and per-IP rate limiting on OIDC endpoints
Refresh Token Security: Refresh tokens are rotated on every use. Presenting a previously rotated token is treated as replay and revokes the entire token chain. An absolute session lifetime is enforced independently of rotation.
Not supported in this release:
client_credentials grant, private_key_jwt
client authentication, implicit and hybrid flows, Pushed Authorization
Requests (PAR), DPoP, and JARM.
7. Microsoft Entra ID External Authentication Method (EAM)
The Identity Provider can now act as an external authentication method for Microsoft Entra ID, allowing SurePassID MFA to satisfy an Entra ID multifactor authentication requirement.
Endpoints: | Purpose | URL Pattern |
|---------|-------------| | Discovery |
/eam/{domain}/.well-known/openid-configuration | | JWKS |
/eam/{domain}/jwks | | Authorization |
/eam/{domain}/authorize |
Supported Capabilities:
- ✅ Signed request object (JAR) validation against the Entra ID JWKS
- ✅ Parameter mode using
id_token_hintfor deployments that do not send a request object - ✅
acrandamrclaims reporting the authentication methods actually used - ✅
RS256-signedid_tokenreturned byform_postafter successful MFA - ✅ Replay protection rejecting a reused request object
jti - ✅ Per-tenant EAM configuration including client ID, redirect URIs, and ACR override
- ✅ Full audit coverage of discovery, authorization, and callback paths
Note: EAM replay protection shares the SAML request
ID cache, so SamlCache.RequestIdExpirationMinutes also
governs the EAM replay window.
New Audit Result Codes (OIDC and EAM): | Code |
Description | |------|-------------| |
SSOReplayAttackDetected | Reused EAM request object
jti detected | | ApiAccessViolation | EAM or
OIDC request failed parameter validation |
🔄
6. OIDC Client Configuration
Each OIDC relying party is registered per tenant with the following settings:
| Setting | Description |
|---|---|
| Client ID | Public identifier for the relying party |
| Client Secret | Stored as a hash; omit for public clients |
| Redirect URIs | Exact-match list of permitted redirect targets |
| Scopes | Scopes the client is permitted to request |
| Grant Types | authorization_code and optionally
refresh_token |
| Require PKCE | Enforces S256 code challenge for this client |
| Require Consent | Forces the consent screen even for previously granted scopes |
| Request Object JWKS URI | Key source for validating signed request objects (JAR) |
| ACR Override | Overrides the advertised authentication context value |
7. EAM Tenant Configuration
| Setting | Description |
|---|---|
| Client ID | Entra ID application client identifier |
| Entra OpenID Config URL | Discovery document used to retrieve the Entra ID signing keys |
| Redirect URIs | Permitted form_post return targets |
| ACR Override | Overrides the acr value asserted after successful
MFA |
| Client Secret | Optional additional defense-in-depth check |
Tenants may also be configured through Eam.{domain}.*
keys in web.config, which remain supported for existing
deployments.
🔒 Security Enhancements
1. Extended Logging
2. Certificate Management
Enhanced certificate retrieval with support for multiple key management providers:
- None (plaintext)
- SurePassLocal (local encryption)
- SurePass (remote KMS)
- SafeNet, FutureEx, nCipher, Townsend, Kms (HSM providers)
3. OIDC Token Security (new)
- Refresh token rotation: A refresh token is invalidated as soon as it is exchanged, and a new one is issued
- Reuse detection: Presenting an already-rotated refresh token revokes the entire descendant token chain
- Absolute session lifetime: Enforced independently of rotation, capping how long a session can be extended
- Single-use authorization codes: Codes are bound to the issuing client and PKCE challenge, and cannot be redeemed twice
- Access token revocation: Revoked access tokens are tracked in a deny-list and rejected at the UserInfo endpoint
- Exact-match redirect URI validation: Redirect targets must match a registered URI exactly
4 OIDC Endpoint Rate Limiting (new)
OIDC endpoints are rate limited per tenant and per calling IP address to reduce the impact of credential stuffing and enumeration attempts.
8. EAM Request Validation (new)
- Request objects are validated against the Entra ID JWKS before any authentication is performed
- Replay protection rejects a reused request object
jti - Parameter mode validates the supplied
id_token_hintwas issued by Entra ID - The asserted subject must match the expected
login_hintorsub, and the request is rejected if neither is present
9. Signing Key Rotation (new)
Both OIDC and EAM publish JWKS documents that support a two-key overlap window, allowing signing keys to be rotated without invalidating tokens that are still in flight.
🧭 Deployment Sizing and Compatibility
Recommended Cache Settings by Deployment Size
| Deployment | Cache Provider | Session Expiration | Cleanup Frequency |
|---|---|---|---|
| Small (< 100 users) | InMemory | 8 hours | Automatic |
| Medium (100-1000 users) | SqlServer | 8 hours | Every 5 minutes |
| Large (> 1000 users) | SqlServer | 4 hours | Every 2 minutes |
In-memory cache: Sub-millisecond lookups, automatic cleanup every 60 seconds, memory grows with active sessions, and state is lost on application restart.
SQL Server cache: Typical lookup of 2-5 ms, persists across restarts, configurable batch cleanup, and suitable for thousands of concurrent sessions.
Note: These settings apply to the SAML request ID and session caches. The OIDC session cache is in-memory only and is not affected by the cache provider selection.
Tested Service Providers
Salesforce, Microsoft 365 / Entra ID, Google Workspace, AWS IAM Identity Center, ServiceNow, Okta (as SP), and custom SAML 2.0 Service Providers.
Browser Support
Chrome, Firefox, Safari, and Microsoft Edge (current versions). Internet Explorer 11 has limited Single Logout support.
Framework Requirements
- .NET Framework 4.8
- SQL Server 2016 or later (required for the SqlServer cache provider)
- IIS 10 or later recommended
⚠️ Known Issues
1. HTTP-Redirect Binding for Logout Responses
Issue: Logout responses default to HTTP-POST even
when HTTP-Redirect is configured
Reason: HTTP-Redirect requires query string signature
which is more complex
Workaround: Use HTTP-POST binding for logout
(recommended)
Status: Under consideration for future release
2. Session Index Cleanup
Issue: In-memory session cache may grow if SPs don't
send logout requests
Impact: Minimal - sessions auto-expire based on
timestamp
Workaround: Sessions automatically expire, or restart
service to clear
Status: Monitoring for future optimization
3. OIDC Session Cache Is Not Shared Across Nodes
Issue: The OIDC session cache is in-memory only and
is not affected by the SamlCache.Provider setting
Impact: In a load-balanced deployment without sticky
sessions, an OIDC logout handled by a different node than the one that
registered the relying party may not notify every participant
Workaround: Enable sticky sessions for OIDC logout
traffic
Status: A shared OIDC session store is under
consideration for a future release
4. OIDC Protocol Features Not Yet Implemented
Issue: The following OpenID Connect features are not
supported in this release: client_credentials grant,
private_key_jwt client authentication, implicit and hybrid
flows, Pushed Authorization Requests (PAR), DPoP, and JARM
Impact: Relying parties requiring these features cannot
be onboarded
Workaround: Use the Authorization Code flow with PKCE,
which is the recommended pattern for both confidential and public
clients
Status: PAR, DPoP, and JARM have design documents and
are candidates for a future release
5. EAM Replay Window Is Shared With SAML
Issue: EAM request object jti replay
protection uses the SAML request ID cache, so
SamlCache.RequestIdExpirationMinutes (default 5) also sets
the EAM replay window
Impact: If an Entra ID request object remains valid
longer than the configured window, its cache entry can expire before the
request object does
Workaround: Ensure the configured expiration is at
least as long as the Entra ID request object lifetime
Status: A dedicated EAM replay window is under
consideration
🚨 Deprecation Notices
None in This Release
All existing APIs remain supported. No deprecation warnings.
⬆️ Upgrade Notes
Prerequisites
- .NET Framework: 4.8 or higher
- Database: SQL Server 2016 or higher
- ComponentSpace SAML: 2.0 or higher
Deployment Steps
- Backup: Create full backup of database and application
- Update Binaries: Deploy new
SurePassIdpassemblies - Update Shared Library: Deploy updated
SurePassClassLib.dll - Test SSO: Verify existing SSO integrations still work
- Configure SLO: Enable Single Logout for SP applications
- Test SLO: Verify logout operations work correctly
- Review Logs: Check diagnostic traces and audit logs
Rollback Plan
If issues occur:
- Restore previous application binaries
- No database rollback needed (schema unchanged)
- Clear application cache
- Restart application pool
🛠 Support and Troubleshooting
Diagnostic Tracing
Enable detailed diagnostic tracing to troubleshoot issues:
<appSettings>
<add key="Server.TracePath" value="C:\Logs\SurePassIdp\" />
<add key="Trace.Enabled" value="true" />
</appSettings>Trace files are created daily with naming:
SurePassIdp<YYYYMMDD>.log
Common Issues
Issue: Replay Attack Detected
Symptom: SSOReplayAttackDetected audit
event
Cause: SP is reusing request IDs or user is refreshing
page
Solution: Configure SP to generate unique request IDs;
educate users not to refresh during auth
Issue: Signature Verification Failed
Symptom:
SSOAuthnRequestSignatureInvalid audit event
Cause: Certificate mismatch, clock skew, or tampered
request
Solution: Verify SP certificate matches, check system
clocks, review network security
Issue: Logout Destination Mismatch
Symptom: SSOLogoutDestinationMismatch
audit event
Cause: SP sending logout request to wrong URL
Solution: Configure SP with correct IdP SLO endpoint
URL
Audit Log Queries
Find recent security events:
SELECT TOP 100 *
FROM PartnerUserAudit
WHERE ResultCode IN (9139, 9140, 9141, 9142, 9143, 9144, 9145)
ORDER BY AuditDate DESCFind policy violations:
SELECT TOP 100 *
FROM PartnerUserAudit
WHERE ResultCode IN (9069, 9070, 9061, 9065)
ORDER BY AuditDate DESC📧 Contact
For questions, issues, or feature requests:
- Support: Contact SurePassID Support
© 2013–2026 SurePassID. All rights reserved. Protected by patents pending. SurePassID, the SurePassID logo and design, and Secure SSO are registered trademarks or trademarks of SurePassID, Corp. in the United States and/or other jurisdictions. All other marks and names mentioned herein may be trademarks of their respective companies.
SurePassID 360 Central Avenue #800 St. Petersburg, FL 33701 USA +1 (888) 200-8144 surepassid.com