Latest press releases from Suprema
BioStar Air v2.13: Know, Control and Respond Across Complex Sites
August 26, 2026


Cloud access control should become easier to manage as organizations grow, not harder. 

BioStar Air was designed around that principle, combining centralized cloud management with Suprema’s native biometric capabilities and hybrid edge architecture. With version 2.13, the platform expands that foundation to address more operationally complex environments, where managing doors is only one part of the challenge. 

Organizations increasingly need to understand who is on site, control how people move between secured areas, keep identities synchronized with IT systems, and respond with better information during an emergency. 

BioStar Air v2.13 brings these workflows closer together through new Anti-Passback and zone capabilities, SSO and SCIM integration, a shared Presence engine, and a significantly enhanced Roll Call experience. 

 

ith BioStar Air v2.13, we're adding zones, presence monitoring, anti-passback, compatibility with Okta and Entra, and enhanced roll call capabilities.

 

"We’ve heard from many potential customers who love BioStar Air’s cloud-native architecture, intuitive interface, and native compatibility with Suprema’s biometric access control readers, but needed additional capabilities for more complex environments. With BioStar Air v2.13, we’re adding zones, presence monitoring, anti-passback, compatibility with Okta and Entra, and enhanced roll call capabilities. These additions remove some of the biggest barriers for larger organizations and make BioStar Air a compelling choice for customers with more demanding access control requirements." - Erik Cornelius, Product Manager, BioStar Air, Suprema

 


TL;DR: What changes with BioStar Air v2.13? 

BioStar Air v2.13 extends cloud access control into environments with more complex identity, movement, presence, and safety requirements. 
 

  • Know: See who is on site, view people counts by zone, and understand where people last used their credentials. 
     
  • Control: Enforce desired paths through a site and prevent credential sharing with zone-based Anti-Passback. Connect BioStar Air with Microsoft Entra ID or Okta for centralized identity management.
     
  • Respond: Keep people safe by creating accurate Roll Call lists with a unified Presence Engine and coordinating responses across assigned muster points.  
        

Together, these capabilities make BioStar Air a stronger fit for growing offices, campuses, schools, laboratories, manufacturing plants, warehouses, multi-tenant buildings, gyms, and multi-building sites.  
 

 

How does BioStar Air v2.13 control movement across more complex sites? 

As access control environments grow, the question is no longer simply whether a person is authorized to open a particular door. Organizations may also need to control how that person moves through the site.


Anti-Passback adds zone-based movement enforcement 


BioStar Air v2.13 introduces Anti-Passback, or APB, to enforce valid entry and exit sequences across configured zones.

 

BioStar Air v2.13 Ⅰ New Anti-pass back feature

 

This prevents credential sharing and unauthorized re-entry while improving the reliability of presence records. Administrators can apply movement rules to a building perimeter or to specific areas within a site, giving them more control than individual door permissions alone. 

For example, a laboratory may require employees to enter a controlled area through a designated entrance and leave through a designated exit. A gym can use APB to reduce credential sharing between members. On a campus, the same principle can be applied across buildings or restricted internal areas. 

The detailed implementation also supports hard and soft enforcement modes. Hard APB rejects invalid access attempts, while soft APB allows the event but flags and records the violation for review.

 

Zones give you granular control of spaces within your site 

Zones provide administrators with a more structured view of the site. 

Instead of treating every reader and door as an isolated element, administrators can organize access around areas and see how many people are currently considered inside each configured zone. 

This becomes particularly useful in environments such as campuses, warehouses, laboratories, or multi-building offices, where understanding occupancy by area can be as important as monitoring individual access events. 

The result is a clearer model of people, movement, and space, rather than a long sequence of disconnected door events.

 

How does BioStar Air know who is currently on site?

Finding out who may still be inside a facility has traditionally required administrators to interpret access logs or rely on separate operational processes. 

BioStar Air v2.13 introduces On Site Now, built on a shared Presence engine. 

 

BioStar Air v2.13 Ⅰ On Site Now,  know who is currently on site

 

On Site Now turns access events into real-time presence information


The Presence engine uses access events and configurable Perimeter Zone rules to determine whether an active credential user is currently considered on site or off site. 

Administrators can see an On Site count directly from the dashboard and open a dedicated Presence view for more detail, including entry information and the last door recorded for each person. Sites with dedicated exit readers can use those events to update presence, while other configurations can use an off-site timer when appropriate.  

This provides a clear view of your operations without requiring administrators to reconstruct movement manually from event logs. 

 

Why does this matter for schools, campuses and distributed facilities?


Consider a school or university campus with students, faculty, contractors, visitors, and administrative staff moving through different buildings throughout the day. 

Security or facility teams may need to know how many people are currently considered on site, which areas are occupied, or where a specific user's last access event occurred. 

The same requirement exists in warehouses, manufacturing sites and large corporate facilities. On Site Now gives administrators that operational context from the same access control platform already managing users, credentials and doors. 

 

How does v2.13 improve emergency Roll Call?

Presence becomes especially valuable when normal operations are interrupted. 

BioStar Air already supported Roll Call, but v2.13 connects the workflow directly to the same Presence model used by On Site Now. 

 

BioStar Air v2.13 Ⅰ On site presence to Roll Call

 

Enhanced Roll Call starts with a more relevant emergency list


Previous Roll Call behavior could treat all active users as potentially present. With v2.13, the system can instead use current Presence status to build a list around active users considered on site when the event begins.  

This gives safety personnel a more useful starting point when determining who may still need to be accounted for. 

Because Roll Call and On Site Now share the same Presence engine, their accuracy depends on the same site configuration and access-event information.

 

Muster points distribute responsibility across complex sites


For larger environments, emergency response is rarely handled by one administrator standing at one assembly point. 

BioStar Air v2.13 allows user groups and responsible administrators to be associated with specific muster points. Assigned administrators can focus on the users within their responsibility rather than working through an entire site-wide list. 

This is particularly relevant for schools, campuses, industrial facilities and multi-building environments where evacuation flows may be distributed across several locations. 

Eligible Suprema Pass mobile credential users can also receive guidance directing them toward the appropriate muster point, while off-site users can be warned not to approach the facility during an active event.  

 

How does BioStar Air connect physical access with enterprise identity management? 


More complex organizations often already manage employee identities through centralized IT systems. Creating and maintaining those identities separately inside an access control platform adds unnecessary administrative work and creates another lifecycle to manage. 

BioStar Air v2.13 addresses this through SSO and SCIM integration with Microsoft Entra ID and Okta.

 

SSO brings administrator access under existing identity policies


Single Sign-On allows BioStar Air administrators to authenticate through a supported identity provider. 

For IT-governed organizations, this means administrator access can be brought closer to the authentication policies already used for other enterprise applications rather than relying entirely on separately maintained credentials. 

 

SCIM reduces manual identity lifecycle management


SCIM provisioning extends the integration to users, user groups and administrators. 

Organizations can synchronize identities from their existing identity provider and map groups to BioStar Air user groups or administrator roles. This reduces the need to manually recreate, update and deactivate every identity in the access control system. 

For a university, for example, an existing identity structure for faculty, staff or other groups can become part of the physical access workflow. In a corporate environment, the same approach helps connect workforce identity management with site access. 
 

SSO and SCIM integration is an optional paid BioStar Air feature.  


 

How does v2.13 keep larger systems easier to manage?


Adding more advanced control should not mean adding unnecessary administrative complexity. 


Door-centric access level management reduces configuration steps


With v2.13, administrators can assign or remove access levels directly from door workflows rather than managing every door-to-access-level relationship from the Access Level page. 

The capability is also available through multi-door bulk editing, reducing navigation overhead for sites with larger numbers of doors and access levels.  

For administrators and installers, this means configuration can follow the object they are already working with: the door.

 

A billing PoC begins testing new partner workflows 


Version 2.13 also introduces a Stripe-based subscription Billing proof of concept for selected markets. 

The PoC is intended to validate new subscription billing workflows and reduce some of the manual administration associated with partner billing. It remains a limited rollout rather than a globally available BioStar Air capability.  

 

What does BioStar Air v2.13 change in practice? 

BioStar Air v2.13 broadens the type of access control challenge the platform can address. 

Administrators can now connect enterprise identities more closely with physical access, enforce how users move through controlled areas, understand who is considered on site, and use that same information to support emergency response. 

For environments such as campuses, laboratories, warehouses, corporate facilities and multi-building sites, those capabilities add an important layer of operational control without moving away from the centralized, cloud-based experience that defines BioStar Air. 

Know who is there. Control how access works. Respond with better information. 

With v2.13, BioStar Air takes another step toward making more complex sites easier to see, manage, and protect.  

 




Frequently Asked questions about BioStar Air


What is BioStar Air?


BioStar Air is Suprema’s cloud-native access control platform, built to reduce local infrastructure, simplify operations, and deliver biometric, mobile, and RFID access across multiple sites. It supports both direct-to-cloud deployment and hybrid edge architecture, allowing organizations to start with simple one-cable installations or extend to controller-based systems for retrofits and more complex environments.


How is BioStar Air different from traditional cloud-based access control (ACaaS)?


Most ACaaS solutions still depend heavily on local controllers and site-by-site hardware architecture. BioStar Air is cloud-native and edge-driven, with direct-to-cloud deployment for simple one-cable installations, while now also supporting hybrid edge architecture for retrofits and more complex environments through controller-based configurations. This gives you faster deployment, real-time sync across sites, and more flexibility to scale from standalone doors to large, distributed systems.


Does BioStar Air support cloud-based biometric authentication?


Yes. BioStar Air offers cloud-native facial authentication, with remote DIY selfie enrollment, instant on-site face enrollment directly at the reader, and bulk enrollment via CSV file. No third-party devices or middleware are required, and templates sync instantly across all authorized readers.


Can I use BioStar Air for multiple buildings or locations?


Absolutely. BioStar Air is built for distributed, multi-site environments, from separate buildings to sprawling campuses and global operations. You can manage everything from a single cloud dashboard, and with its hybrid edge architecture, it also supports environments where continuous cabling is difficult by combining direct-to-cloud deployment with controller-based configurations where needed.


Does BioStar Air require a server or controller onsite?


No on-site server is required. BioStar Air can run with smart readers connected directly to the cloud for simple deployments, while also supporting local controllers in hybrid edge configurations for retrofits and more complex environments. This gives you the flexibility to stay infrastructure-light where possible, or add controller-based architecture where the site requires it.


What credentials are supported by BioStar Air?


BioStar Air supports a wide range of credentials:
 

  • Facial authentication
     
  • Mobile credentials on Android and iOS
     
  • App-less dynamic QR codes
     
  • App-less Link Pass for web-based door access
     
  • RFID cards, including MIFARE Classic, FeliCa, iCLASS, and Seos
     
  • PIN codes
     

You can also combine multiple credentials for the same user depending on the access scenario. Credential availability depends on the compatible reader in use.


Is BioStar Air secure and privacy-compliant?


Yes. BioStar Air uses end-to-end encryption, ISO 27001-aligned infrastructure, and does not store raw biometric images. Biometric templates are stored securely in the cloud and on the device, while matching happens locally on the reader. BioStar Air also supports privacy-focused external support (new Technician access feature) by allowing limited, controlled access for technicians without exposing sensitive user data.