The cloud access-control update adds zone-based movement rules, presence-driven roll call and SSO/SCIM support for Microsoft Entra ID and Okta.

Key takeaways

  • BioStar Air v2.13 adds zone-based Anti-Passback with hard and soft enforcement modes.
  • A shared Presence engine supports On Site Now status, zone counts and presence-based Roll Call lists.
  • The update introduces SSO and SCIM integrations for Microsoft Entra ID and Okta; Suprema describes these as an optional paid feature.
  • Installers should validate perimeter-reader coverage, exit-event handling, user-group design and emergency procedures before relying on presence data for muster workflows.

A cloud-access update aimed at more complex movement workflows

Suprema announced BioStar Air version 2.13 on August 26, 2026, expanding its cloud access-control platform with functions intended for facilities that need more than door-by-door authorization. The release centers on controlling movement between areas, estimating who remains on site and connecting physical-access administration more closely to enterprise identity systems.

The changes are relevant to multi-building offices, schools, industrial sites, laboratories and warehouses where a valid credential alone may not provide enough operational context. In these environments, security and facilities teams may also need to track whether a person has followed an expected route, identify the last recorded access point and organize accountability during an emergency.

Zone-based anti-passback adds movement rules

The new Anti-Passback, or APB, capability applies movement logic across configured zones. Suprema says the function can enforce valid entry and exit sequences at a building perimeter or within selected areas, rather than relying solely on individual door permissions.

The platform supports hard and soft APB modes. Under hard enforcement, an access attempt that violates the configured sequence is denied. Soft enforcement permits the event while recording the violation for later review. That distinction gives project teams a choice between immediate control at a high-security boundary and a less disruptive monitoring approach where traffic patterns are still being established.

The practical value of APB depends on the site design. Readers, door direction settings and zone boundaries need to correspond to real travel paths. Teams should also document exception handling for visitors, disabled credentials, deliveries, escorted access and doors used during evacuation.

Presence information is shared across operations and roll call

Version 2.13 introduces On Site Now, a dashboard and detailed view built on a shared Presence engine. Suprema says the engine uses access events and configurable perimeter-zone rules to determine whether an active credential holder is considered on site or off site. Administrators can view a current count, entry information and a person’s last recorded door.

Presence status can be updated from dedicated exit-reader events. Where that arrangement is not available, Suprema says sites can apply an off-site timer. This makes configuration important: a presence display is an operational estimate derived from events and rules, not an independent confirmation of a person’s location.

The same model now feeds BioStar Air Roll Call. Instead of beginning with every active user, an emergency roll-call event can use users considered on site when the event starts. The update also permits user groups and assigned administrators to be linked to particular muster points, helping distribute accountability across larger sites. Suprema Pass mobile credential users may receive muster-point guidance where eligible, according to the manufacturer.

SSO and SCIM connect access administration to IT identity systems

BioStar Air v2.13 adds single sign-on and SCIM provisioning integrations for Microsoft Entra ID and Okta. SSO allows BioStar Air administrators to authenticate through a supported identity provider, while SCIM can synchronize users, groups and administrator roles into the access-control platform.

For integrators, the feature is most useful when the identity source, access groups and physical security roles are designed together. A synchronized identity alone does not determine appropriate door permissions, schedule rules or credential enrollment. Teams should establish ownership for group changes, deprovisioning, failed synchronization and privileged-administrator access before enabling automated provisioning.

Suprema identifies SSO and SCIM as an optional paid BioStar Air feature. Procurement teams should therefore confirm licensing, supported identity-provider configurations, implementation responsibilities and ongoing subscription terms during design review.

What to validate before deployment

The release also adds door-centric access-level management, including multi-door bulk editing, which could reduce configuration steps on larger systems. Suprema separately notes a Stripe-based subscription-billing proof of concept for selected markets; it is not presented as a globally available platform capability.

For a new or upgraded installation, the highest-priority validation work is operational rather than cosmetic. Confirm which readers establish entry and exit, test APB behavior at every transition, define how tailgating and propped doors are handled, and run realistic roll-call exercises with security, facilities and safety personnel. Sites should also test what happens when users leave through unmonitored exits or when access events are delayed.

BioStar Air v2.13 broadens the platform’s role from cloud-managed door access toward occupancy-aware security operations. The new functions may be a fit where movement control, identity lifecycle management and emergency accounting are linked requirements, but their usefulness will rest on sound field configuration and clearly defined procedures.