Skip to main content
Home > MyID Product Family > MyID MFA > MyID MFA Technical Features

MyID MFA
Technical Features

Active Directory native authentication. One server role hosting IdP, RADIUS, Password Vault and the Web Services API. There is no separate database to manage and no schema to extend. Agents (Desktop, Domain Controller, RADIUS) are natively Active-Active with no load balancer. For multi-server high availability of the web services (IdP, Self-Service, Admin Portal and the Web Services API), place a load balancer or reverse proxy in front.

Architecture

One Server Role. Active Directory Native.

Every MyID MFA component runs on the Authentication Server: the IdP (SAML 2.0, OpenID Connect), RADIUS via Windows NPS and FreeRADIUS, the Web Services API, the Self-Service Portal and the Password Vault. All user records and settings are stored directly in Active Directory, with no schema extensions and no separate database to deploy, back up or replicate. Add a second server for resilience and AD replication handles the data automatically.

Auth Server IdP, RADIUS, WSAPI, Self-Service, Web Management Portal
User database Active Directory, no schema changes
HA model Agents Natively Active-Active via AD discovery; load balancer/reverse proxy for web-services HAnts auto-discover via AD
Platform Windows Server 2019 / 2022 / 2025
Runtime .NET 10 Desktop Runtime
WSAPI port TCP 14443 (TLS), IPv4 and IPv6

Authentication Server

Hosts IdP, RADIUS (via Windows NPS and FreeRADIUS), Web Management Portal, Self-Service Portal, Password Vault, Reporting Dashboard and the Web Services API. One install, all roles.

Active Directory Store

All MyID settings and user data stored in AD directly. Replicated automatically across Domain Controllers. No schema extensions required, no separate SQL.

Windows Desktop Agent

Installed on Windows 10/11 and Server 2019–2025. Online and offline logon, passwordless via Password Vault, browser reporting for breached passwords and SIEM integration.

Domain Controller Agent

Installed on every writable Domain Controller. Intercepts AD password changes in real time, validates against NIST SP 800-63B policy, syncs Password Vault, randomises retired account passwords.

Password Vault

Encrypted store for users' AD passwords (AES-256 with RSA 2048-bit asymmetric key). At MFA logon, the Desktop Agent retrieves the password from the vault and delivers to Windows on the user's behalf. Private key may be HSM-protected.

Browser Reporting

Edge and Chrome extensions detect when a user types a breached password into any website, and prompt them to change it on the spot. Admins see the event and the site, never the password: hash checking preserves k-anonymity.

Authentication methods

Every authentication method your workforce needs, one platform

From Grid Pattern (no device required) to phishing-resistant FIDO2 passkeys. Mix and match per user, per risk level. Where phishing resistance is mandatory (FIPS 201, NIS2, defence), use PKI certificates or FIDO. Other methods are meaningful step-ups from passwords for general enterprise use.

Grid Pattern

Deviceless or device-bound. User registers a pattern; at login they read values from a randomised grid at their pattern positions. 4x4, 5x5, 6x6, and 8x8 grid sizes; alphanumeric variants and custom grids.

Emoji ID Grid

Simplified Grid Pattern variant using emojis instead of digits- a simpler grid aimed at entry-level users. Lower assurance than full Grid Pattern, not suited to high-assurance environments.

Mobile Push

Approve or deny on your phone with biometric or PIN via the MyID Authenticator app. Denied requests are logged with a reason. Push via RADIUS.

One Time Code (OATH TOTP)

MyID MFA supports standard software OATH time-based one-time passwords (TOTPs) through tokens such as the Microsoft and Google Authenticator apps

Hardware OTP Tokens

One-button hardware authentication with YubiKey and OneSpan Digipass devices. Pair with a PIN or AD password for strong multi-factor logon; Digipass devices also support PIN-protected code generation on the device itself.

FIDO2 / Passkeys

Phishing-resistant cryptographic auth. Device-bound hardware passkeys and synced mobile passkeys in the Desktop Agent. Includes OneSpan Digipass FX1 / FX2 / FX7 and Swissbit iShield Key 2 Pro.

OneSpan Digipass OTP

PIN-protected one-time-code hardware tokens from OneSpan Digipass - a portable, reliable OTP option alongside YubiKey OTP.

One Time Code (SMS / Email)

One-time codes delivered by SMS or email for users without an authenticator app or hardware key.

Self-Service Enrolment

Users enrol and manage their own authenticators - Authenticator app, OATH, YubiKey, OneSpan Digipass and FIDO/passkey - through the Self Service Portal.

Application integration

Plugs into what you already run, no rip-and-replace

MFA fronts existing identity infrastructure via standard protocols. SAML 2.0 multi-domain Microsoft 365 federation without ADFS, OpenID Connect for modern apps, RADIUS for network estate, plus SIEM-ready audit events out of the box.

SAML 2.0

Enterprise SSO and native multi-domain Microsoft 365 federation. PowerShell scripts provided. No ADFS required. WS-Fed to SAML migration path supported.

OpenID Connect

Modern web and cloud apps. Configurable OIDC claims mapping. Access token settings, access control policies per application.

RADIUS

Built-in RADIUS via Windows NPS and FreeRADIUS. Native integrations: Palo Alto GlobalProtect, Cisco VPN, F5 BIG-IP, Citrix Gateway, Linux servers, any RADIUS-compliant network device.

WS-Fed (legacy)

Legacy Microsoft federation. Configure Exchange, ADFS and MyID MFA to allow Active Directory Federations Services (ADFS) to use MyID MFA to authenticate to Outlook Web Access (OWA) or other applications.

Multi-Tenancy (MSP)

Serve multiple customers from one MyID deployment. Realms keep each customer's users separate, even with duplicate domain or computer names across estates, with per-customer Self-Service Portal domains and Microsoft 365 federation. Dedicated MSP Quick Start Guide included.

SIEM Event Codes

Per-technology event codes in Windows Event Log: Push via RADIUS 1494, Grid deviceless token 1503, OATH 1893, FIDO device-bound 2053, FIDO synced 2052, plus PSM password-change events.

MyID MFA

Need the full technical specification?

Download the What's New in MyID MFA datasheet for a full rundown of the latest release.