Bespoke WordPress plugin for Microsoft Entra ID (Azure AD) authentication on Avon and Somerset Police sites. Features are toggled via wp-config.php — no admin screens, no per-site plugin settings.
It follows the same packaging style as WP Core: Composer-installed and feature-flagged. The plugin speaks OpenID Connect (OIDC) only — not WS-Federation / SAML.
Typical outcomes:
Product-level authorisation stays in the theme. This plugin answers “who are you?” and “may you use wp-admin?”.
| Feature | Default | Description |
|---|---|---|
| force_login | true | Redirects anonymous front-end visitors to Entra sign-in |
| login_ui | true |
Adds a Microsoft button on wp-login.php and can auto-start Entra
|
| disable_password_login | true | Blocks password login except for break-glass accounts |
Always loaded when the plugin is active:
/wp-admin/ restricted to mapped roles and break-glass accountsPublic helpers: asp_entra_feature_enabled(), asp_entra_get_user_identity().
Via Composer (recommended):
"require": {
"policedigitalservices/asp-wp-entra": "^1.0"
}
Then:
composer update policedigitalservices/asp-wp-entra
Activate WP Entra, configure ASP_ENTRA / ASP_ENTRA_FEATURES, and flush permalinks once (Settings → Permalinks → Save) so the OIDC callback path resolves.
For local Docker development you can bind-mount the plugin instead of installing via Composer.
Connection settings live in ASP_ENTRA (or matching environment constants). Optional behaviours are enabled through ASP_ENTRA_FEATURES.
define('ASP_ENTRA', [
'tenant_id' => 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx',
'client_id' => 'xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx',
'client_secret' => 'your-client-secret',
'redirect_path' => '/auth/entra/callback',
'default_role' => 'subscriber',
'group_roles' => [
// Entra group OBJECT ID => WordPress role
'aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee' => 'administrator',
],
'break_glass_logins' => [
'breakglass',
],
'login_button_text' => 'Sign in with Microsoft',
]);
define('ASP_ENTRA_FEATURES', [
'force_login' => true,
'login_ui' => true,
'disable_password_login' => true,
]);
Common site patterns:
force_login => true, group roles for adminsforce_login => false, group roles for adminsBreak-glass password login (when enabled): https://your-site.example/wp-login.php?asp_entra_password=1
Full Entra app registration steps, token validation notes, and troubleshooting live in the repository README.
Runs in consuming WordPress sites.
> TODO: Add backlog, board, or related docs.