S

Sanch MultiDomain LDAP Auth for Active Directory

0/5 (0 ratings) — active installs Updated Aug 31, 2026

Sanch MultiDomain LDAP Auth for Active Directory provides enterprise-grade Single Sign-On (SSO) and access control for corporate WordPress intranets. Built for multi-forest environments, it allows users to authenticate seamlessly against multiple Domain Controllers while strictly enforcing path-based access policies and dynamic role propagation.

Key Features

  • Multi-Domain & Multi-DC Authentication: Connect and authenticate against multiple LDAP/LDAPS servers across different Active Directory domains/UPN suffixes.
  • Mandatory Intranet Login: The site is strictly private. All guests are automatically redirected to the login screen.
  • Blacklist Path-Based ACL: Once logged in, content is accessible to all staff by default. Easily restrict specific intranet sections, categories, and custom routes based on AD Group Membership (CN) or mapped WP Roles.
  • Strict Cascade Filtering: Restricting a category URL automatically hides all posts belonging to that category, even if the post’s permalink does not match the restricted URL path.
  • JIT Provisioning & Single Source of Truth: Automatic user creation on first successful AD bind, with strict role sync on every login.
  • LDAP Clone Protection: Detects and prevents authentication if multiple accounts match the same SAMAccountName across refined Base DNs.