Skip to content

Repository files navigation

SSO for Microsoft Entra

Lint & Test WordPress Plugin WordPress Plugin Downloads PHP 8.0+ WordPress 6.0+ License: GPL v2

Single Sign-On authentication for WordPress using Microsoft Entra ID (Azure AD) via OpenID Connect with PKCE.

Features

  • OpenID Connect (OIDC) with PKCE — the most secure OAuth 2.0 flow
  • Automatic user provisioning on first SSO login
  • Encrypted client-secret storage
  • Configurable rate limiting on login attempts
  • Contextual Help tabs built into the settings page
  • Vietnamese translation included, community translations via translate.wordpress.org

Quick Start

  1. Install and activate the plugin.
  2. In Azure Portal: App registrations > + New registration.
  3. Set Redirect URI (Web) to https://yoursite.com/sso/callback.
  4. Copy the Application (client) ID and Directory (tenant) ID.
  5. Go to Certificates & secrets > + New client secret > copy the Value.
  6. In WordPress: Settings > Entra SSO > enter Tenant ID, Client ID, Client Secret > Save Changes.
  7. Add API permissions: Microsoft Graph > Delegated: openid, profile, email.
  8. Test in an incognito window.

Requirements

  • PHP 8.0 or higher
  • WordPress 6.0 or higher
  • A Microsoft Entra ID (Azure AD) tenant

Installation

From WordPress Admin (Recommended)

  1. In your WordPress admin, go to Plugins > Add New.
  2. Search for SSO for Microsoft Entra.
  3. Click Install Now and then Activate.

From WordPress.org

Download the latest stable version directly from the WordPress Plugin Directory.

From GitHub Releases

  1. Download the latest release zip from Releases.
  2. Go to Plugins > Add New > Upload Plugin.
  3. Upload the zip file and activate.

Manual

cd wp-content/plugins/
git clone https://github.com/codetot-web/sso-for-microsoft-entra.git

Activate the plugin from the WordPress admin.

Configuration

Click the Help button (top-right) on the settings page for step-by-step guides:

  • Quick Start — OIDC setup walkthrough
  • Azure Setup — Full app registration walkthrough
  • Troubleshooting — Common errors and fixes

Security

  • PKCE (Proof Key for Code Exchange) prevents authorization code interception
  • OAuth state parameter prevents CSRF attacks
  • ID token nonce prevents token replay
  • administrator role is blocked as the SSO default role
  • Default role for new SSO users is subscriber
  • Client secret encrypted at rest using libsodium or AES-256-GCM

Development

# Install dependencies (including dev)
composer install

# Run linter
vendor/bin/phpcs --standard=phpcs.xml.dist

# Run tests
vendor/bin/phpunit

Contributing

Contributions are welcome. Please open an issue first to discuss what you would like to change.

Support

License

GPL-2.0-or-later

About

SSO for Microsoft Entra — Single Sign-On for WordPress using SAML 2.0 and OpenID Connect with PKCE

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages