Skip to content
English
  • There are no suggestions because the search field is empty.

SurePassID MFA for Microsoft Entra External Authentication Methods (EAM)

Enterprise‑Grade Overview and Implementation Guide

What is External MFA (EAM)?

An External Authentication Method (EAM) is a Microsoft Entra ID capability that lets Entra delegate the multi-factor authentication (MFA) challenge to a third-party provider — in this case SurePassID — over standard OpenID Connect. Entra ID remains the primary identity provider for sign-in; SurePassID becomes the trusted MFA authority that satisfies the second factor. EAM is Microsoft's supported successor to the older "custom controls" feature.

Why use SurePassID as an External MFA?

  • Keep Entra ID as your primary IdP while gaining MFA options Entra does not offer natively (hardware OTP tokens, FIDO2/passkeys managed outside Entra, carrier-specific SMS/voice, push, and more).  
  • Reduce Total Cost of Owenrship - Reuse existing SurePassID authenticators (OTP hardware tokens, FIDO2/passkeys, push, SMS/voice) as the Entra second factor without re-issuing credentials or running two MFA systems. 
  • Reuse authenticators you've already issued in SurePassID — no need to re-enroll users or run two disconnected MFA systems.  One token for all of your systems: air-gapped, OT and IT environments.
  • Consolidate MFA across Entra apps and your other SurePassID-protected applications (SAML, OIDC, RADIUS, VPN, Windows login) under one authenticator set and one policy model.
  • Meet assurance/compliance requirements (possession, inherence, or full MFA) with an auditable external provider.  The system enforces Entra Conditional Access policies that requires MFA for the targeted users/apps invokes the external method.

Broad coverage beyond native Entra ID MFA

Unlike native Entra ID MFA, SurePassID can be used across:

  • Cloud applications (via Entra ID, SAML2 and OIDC)
  • On-premise systems (PCs, VPN, RDP, IIS, etc.)
  • Hybrid Windows systems
  • Legacy applications
  • Cloud-gapped systems
  • IT/OT systems (semi air-gapped)

For pure air-gapped systems, SurePassID is the only vendor to offer MFA support for all the supported MFA methods (including FIDO2/WebAuthn) without requiring the cloud.

The result is a single MFA platform for the entire organization with tight controls and policy enforcement.

How does it work (end-user perspective)?

  1. The user signs in to a Microsoft or Entra-protected application with their normal Entra ID credentials (first factor).
  2. An Entra Conditional Access policy determines MFA is required.
  3. Entra redirects the user to SurePassID to complete the second factor.
  4. The user approves the SurePassID challenge (push, OTP, FIDO2/passkey, SMS/voice, etc.).
  5. SurePassID returns a signed result to Entra, which trusts it and completes sign-in — the user lands in the app.

From the user's view it's a single, seamless sign-in flow; they simply complete their familiar SurePassID MFA step.

Key benefits

  • Unified MFA — one authenticator set for Entra and non-Entra apps.
  • Broad authenticator support — OTP hardware tokens, FIDO2/passkeys, push, SMS/voice, and more.
  • Conditional Access integration — MFA is driven by your existing Entra policies; administration stays in Entra.
  • Standards-based — built on OpenID Connect, avoiding proprietary hooks.
  • Auditable & compliant — every authentication is logged; satisfies possession/inherence/MFA (ACR) assurance requirements.
  • No re-enrollment — leverage authenticators users already have.

Proven integration with Microsoft Entra ID

SurePassID integrates through Microsoft's officially supported External Authentication Methods framework — the same standards-based extensibility Microsoft provides for partner MFA providers — rather than a brittle custom hack. Benefits of this proven path:

  • Supported & future-proof — uses Microsoft's documented EAM/OIDC contract, the sanctioned replacement for legacy custom controls.
  • Native admin experience — configured under Entra → Protection → Authentication methods, targeted with standard user/group assignment.
  • Policy-driven — triggered by ordinary Conditional Access policies, so it fits existing governance and reporting.
  • Multi-cloud — works across Azure Commercial, Azure Government, and Azure Government (DoD) endpoints.
  • Low risk — no changes to how users authenticate their first factor to Entra; SurePassID only augments the MFA step.

Supported authenticator methods

SurePassID offers a unified MFA platform supporting:

  • Push notifications
  • TOTP/HOTP
  • FIDO2/WebAuthn
  • SMS/voice OTP
  • Hardware tokens
  • Mobile app approvals
  • Out‑of‑band verification

When integrated with Entra EAM, these methods become selectable inside Entra’s MFA policies.

Category Authenticator
Mobile / soft tokens SurePassID Authenticator Token (include push authentication, Fido2 push authenticatoon)
Mobile / soft tokens Google Authenticator Compliant (such as Authy, Microsoft, etc.)
Desktop / soft tokens SurePassID Desktop Token
Hardware tokens SurePassID FOB Token
Hardware tokens SurePassID OTP Display Card
Hardware tokens Third party  tokens (YubiKey or any OATH compliant device)
FIDO2 Third party  tokens (YubiKey or any Fido2 compliant device)
Out-of-band SMS OTP, SMS PUSH
Out-of-band Voice OTP, VOICE PUSH IVR
Out-of-band Email
Wearables Nymi Band

Note: Available methods can vary by license, tenant policy, and how each user is enrolled. The exact list a given end user sees is governed by SurePassID policy and the authenticators registered to their account.

Note: Available methods can vary by license, tenant policy, and how each user is enrolled. The exact list a given end user sees is governed by SurePassID policy and the authenticators registered to their account.

Note: Available methods can vary by license, tenant policy, and how each user is enrolled. The exact list a given end user sees is governed by SurePassID policy and the authenticators registered to their account.

Note: Available methods can vary by license, tenant policy, and how each user is enrolled. The exact list a given end user sees is governed by SurePassID policy and the authenticators registered to their account.

Prerequisites

Before configuring Entra, ensure:

  • You have administrative access to SurePassID
  • SurePassID Authentication Server Release 2025.4 or later
  • You can create OIDC applications
  • You have Entra Global Admin or Authentication Admin permissions
  • Your Entra tenant supports External Authentication Methods