Skip to content

Your web browser is out of date

Your web browser (the software you use to access the internet) is out of date. You need to update it or use a different web browser to ensure you can complete this form.

Cookies disabled

Cookies are currently not enabled in your web browser. You need to enable cookies to ensure you can complete this form.

WP Entra

Overview

Bespoke WordPress plugin for Microsoft Entra ID (Azure AD) authentication on Avon and Somerset Police sites. Features are toggled via wp-config.php — no admin screens, no per-site plugin settings.

It follows the same packaging style as WP Core: Composer-installed and feature-flagged. The plugin speaks OpenID Connect (OIDC) only — not WS-Federation / SAML.

Typical outcomes:

  • Users sign in with an organisation Entra account
  • WordPress users are created or updated on first login (JIT)
  • An Entra security group can map to a WordPress role (for example administrator)
  • Everyone else receives a low-privilege default role (for example subscriber)

Product-level authorisation stays in the theme. This plugin answers “who are you?” and “may you use wp-admin?”.

Features

Feature Default Description
force_login true Redirects anonymous front-end visitors to Entra sign-in
login_ui true Adds a Microsoft button on wp-login.php and can auto-start Entra
disable_password_login true Blocks password login except for break-glass accounts

Always loaded when the plugin is active:

  • OIDC authorization code flow against a single Entra tenant
  • JIT WordPress user provisioning from ID token claims
  • Entra group object ID → WordPress role mapping
  • /wp-admin/ restricted to mapped roles and break-glass accounts

Public helpers: asp_entra_feature_enabled(), asp_entra_get_user_identity().

Requirements

  • WordPress 6.4+
  • PHP 8.2+
  • Composer (when installed as a dependency)
  • An Entra app registration (OIDC / Web platform)
  • OpenSSL PHP extension (for RS256 ID token validation)

Installation

Via Composer (recommended):

"require": {
  "policedigitalservices/asp-wp-entra": "^1.0"
}

Then:

composer update policedigitalservices/asp-wp-entra

Activate WP Entra, configure ASP_ENTRA / ASP_ENTRA_FEATURES, and flush permalinks once (Settings → Permalinks → Save) so the OIDC callback path resolves.

For local Docker development you can bind-mount the plugin instead of installing via Composer.

Configuration

Connection settings live in ASP_ENTRA (or matching environment constants). Optional behaviours are enabled through ASP_ENTRA_FEATURES.

define('ASP_ENTRA', [
    'tenant_id'     => 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx',
    'client_id'     => 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx',
    'client_secret' => 'your-client-secret',
    'redirect_path' => '/auth/entra/callback',
    'default_role'  => 'subscriber',
    'group_roles'   => [
        // Entra group OBJECT ID => WordPress role
        'aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee' => 'administrator',
    ],
    'break_glass_logins' => [
        'breakglass',
    ],
    'login_button_text' => 'Sign in with Microsoft',
]);

define('ASP_ENTRA_FEATURES', [
    'force_login'            => true,
    'login_ui'               => true,
    'disable_password_login' => true,
]);

Common site patterns:

  • Entra-gated front end — force_login => true, group roles for admins
  • Public front end + Entra for staff/admin — force_login => false, group roles for admins

Break-glass password login (when enabled): https://your-site.example/wp-login.php?asp_entra_password=1

Full Entra app registration steps, token validation notes, and troubleshooting live in the repository README.

Hosting

Runs in consuming WordPress sites.

Tech stack

  • PHP
  • WordPress
  • OpenID Connect (Microsoft Entra ID)

Used by

  • WordPress products that require organisation SSO (for example ERP-style sites)
  • Other ASP WordPress sites that include the package via Composer

Integrations

In house applications

Force IT

Third party

  • Microsoft Entra ID

Contacts

  • Christian King -- Development Team Lead

Repositories

Resources

> TODO: Add backlog, board, or related docs.


Published 21 September 2026
Last updated 21 September 2026