Sharraxaad
Sanch MultiDomain LDAP Auth for Active Directory provides enterprise-grade Single Sign-On (SSO) and access control for corporate WordPress intranets. Built for multi-forest environments, it allows users to authenticate seamlessly against multiple Domain Controllers while strictly enforcing path-based access policies and dynamic role propagation.
Key Features
- Multi-Domain & Multi-DC Authentication: Connect and authenticate against multiple LDAP/LDAPS servers across different Active Directory domains/UPN suffixes.
- Zero-Trust Path-Based ACL: Restrict intranet sections, categories, and custom routes based on AD Group Membership (CN) or mapped WP Roles.
- JIT Provisioning & Single Source of Truth: Automatic user creation on first successful AD bind, with optional strict role sync on every login.
- LDAP Clone Protection: Detects and prevents authentication if multiple accounts match the same SAMAccountName across refined Base DNs to block privilege escalation.
- REST API & Write ACL Protection: Enforces URL routing policies over REST API endpoints and post/page editing privileges (
map_meta_cap). - Secure Connections: Supports LDAP (Plaintext), LDAP + StartTLS, and LDAPS (SSL/TLS Encrypted).
Rakibaad
- Upload the
sanch-multidomain-ldap-authdirectory to the/wp-content/plugins/directory. - Activate the plugin through the ‘Plugins’ menu in WordPress.
- Ensure the PHP LDAP extension (
php-ldap) is installed and enabled on your web server. - Navigate to Settings -> AD Auth Settings in your WordPress admin dashboard.
- Configure your Domain Controllers (IP, Port, Domain, Base DN) and define your AD Group to WP Role mapping rules.
SBI
-
Does this plugin require the PHP LDAP extension?
-
Yes, your web server must have the
php-ldapPHP module enabled to initiate connections with your Active Directory Domain Controllers. -
What happens if an AD user does not belong to any mapped group?
-
By default under Zero-Trust policy, authentication will fail with an “Access Denied” message if the user does not belong to at least one mapped AD Group.
-
How are custom WP roles handled?
-
You can select existing WordPress roles or create custom role slugs directly from the settings page, assigning base capability sets (
subscriber,editor,author,administrator).
Dibu-eegisyo
Ma jiraan wax dibu-eegis ah oo ku saabsan kaabahan.
Ka-qaybgalayaasha & Horumariyayaasha
“Sanch MultiDomain LDAP Auth for Active Directory” waa softiweer il furan. Dadka soo socda ayaa wax ku biiriyay kaabahan.
Ka-qaybgalayaashaKu tarjun “Sanch MultiDomain LDAP Auth for Active Directory” luqaddaada.
Ma xiisaynaysaa horumarinta?
Baadh koodka, fiiri bakhaarka SVN, ama iska qor diiwaanka horumarinta adigoo adeegsanaya RSS.
Isbeddellada
1.0.0
- Initial release. Features Multi-Domain authentication, LDAP Clone Guard, StartTLS/LDAPS support, and Zero-Trust path-based ACL routing.