One Server Role. Active Directory Native.
Every MyID MFA component runs on the Authentication Server: the IdP (SAML 2.0, OpenID Connect), RADIUS via Windows NPS and FreeRADIUS, the Web Services API, the Self-Service Portal and the Password Vault. All user records and settings are stored directly in Active Directory, with no schema extensions and no separate database to deploy, back up or replicate. Add a second server for resilience and AD replication handles the data automatically.
| Auth Server | IdP, RADIUS, WSAPI, Self-Service, Web Management Portal |
| User database | Active Directory, no schema changes |
| HA model | Agents Natively Active-Active via AD discovery; load balancer/reverse proxy for web-services HAnts auto-discover via AD |
| Platform | Windows Server 2019 / 2022 / 2025 |
| Runtime | .NET 10 Desktop Runtime |
| WSAPI port | TCP 14443 (TLS), IPv4 and IPv6 |
Authentication Server
Hosts IdP, RADIUS (via Windows NPS and FreeRADIUS), Web Management Portal, Self-Service Portal, Password Vault, Reporting Dashboard and the Web Services API. One install, all roles.
Active Directory Store
All MyID settings and user data stored in AD directly. Replicated automatically across Domain Controllers. No schema extensions required, no separate SQL.
Windows Desktop Agent
Installed on Windows 10/11 and Server 2019–2025. Online and offline logon, passwordless via Password Vault, browser reporting for breached passwords and SIEM integration.
Domain Controller Agent
Installed on every writable Domain Controller. Intercepts AD password changes in real time, validates against NIST SP 800-63B policy, syncs Password Vault, randomises retired account passwords.
Password Vault
Encrypted store for users' AD passwords (AES-256 with RSA 2048-bit asymmetric key). At MFA logon, the Desktop Agent retrieves the password from the vault and delivers to Windows on the user's behalf. Private key may be HSM-protected.
Browser Reporting
Edge and Chrome extensions detect when a user types a breached password into any website, and prompt them to change it on the spot. Admins see the event and the site, never the password: hash checking preserves k-anonymity.
Every authentication method your workforce needs, one platform
From Grid Pattern (no device required) to phishing-resistant FIDO2 passkeys. Mix and match per user, per risk level. Where phishing resistance is mandatory (FIPS 201, NIS2, defence), use PKI certificates or FIDO. Other methods are meaningful step-ups from passwords for general enterprise use.
Grid Pattern
Deviceless or device-bound. User registers a pattern; at login they read values from a randomised grid at their pattern positions. 4x4, 5x5, 6x6, and 8x8 grid sizes; alphanumeric variants and custom grids.
Emoji ID Grid
Simplified Grid Pattern variant using emojis instead of digits- a simpler grid aimed at entry-level users. Lower assurance than full Grid Pattern, not suited to high-assurance environments.
Mobile Push
Approve or deny on your phone with biometric or PIN via the MyID Authenticator app. Denied requests are logged with a reason. Push via RADIUS.
One Time Code (OATH TOTP)
MyID MFA supports standard software OATH time-based one-time passwords (TOTPs) through tokens such as the Microsoft and Google Authenticator apps
Hardware OTP Tokens
One-button hardware authentication with YubiKey and OneSpan Digipass devices. Pair with a PIN or AD password for strong multi-factor logon; Digipass devices also support PIN-protected code generation on the device itself.
FIDO2 / Passkeys
Phishing-resistant cryptographic auth. Device-bound hardware passkeys and synced mobile passkeys in the Desktop Agent. Includes OneSpan Digipass FX1 / FX2 / FX7 and Swissbit iShield Key 2 Pro.
OneSpan Digipass OTP
PIN-protected one-time-code hardware tokens from OneSpan Digipass - a portable, reliable OTP option alongside YubiKey OTP.
One Time Code (SMS / Email)
One-time codes delivered by SMS or email for users without an authenticator app or hardware key.
Self-Service Enrolment
Users enrol and manage their own authenticators - Authenticator app, OATH, YubiKey, OneSpan Digipass and FIDO/passkey - through the Self Service Portal.
Plugs into what you already run, no rip-and-replace
MFA fronts existing identity infrastructure via standard protocols. SAML 2.0 multi-domain Microsoft 365 federation without ADFS, OpenID Connect for modern apps, RADIUS for network estate, plus SIEM-ready audit events out of the box.
SAML 2.0
Enterprise SSO and native multi-domain Microsoft 365 federation. PowerShell scripts provided. No ADFS required. WS-Fed to SAML migration path supported.
OpenID Connect
Modern web and cloud apps. Configurable OIDC claims mapping. Access token settings, access control policies per application.
RADIUS
Built-in RADIUS via Windows NPS and FreeRADIUS. Native integrations: Palo Alto GlobalProtect, Cisco VPN, F5 BIG-IP, Citrix Gateway, Linux servers, any RADIUS-compliant network device.
WS-Fed (legacy)
Legacy Microsoft federation. Configure Exchange, ADFS and MyID MFA to allow Active Directory Federations Services (ADFS) to use MyID MFA to authenticate to Outlook Web Access (OWA) or other applications.
Multi-Tenancy (MSP)
Serve multiple customers from one MyID deployment. Realms keep each customer's users separate, even with duplicate domain or computer names across estates, with per-customer Self-Service Portal domains and Microsoft 365 federation. Dedicated MSP Quick Start Guide included.
SIEM Event Codes
Per-technology event codes in Windows Event Log: Push via RADIUS 1494, Grid deviceless token 1503, OATH 1893, FIDO device-bound 2053, FIDO synced 2052, plus PSM password-change events.
Need the full technical specification?
Download the What's New in MyID MFA datasheet for a full rundown of the latest release.