Sanch MultiDomain LDAP Auth for Active Directory
·
Enterprise Active Directory integration featuring multi-domain authentication, Zero-Trust ACL URL routing, and dynamic role mapping.
Sanch MultiDomain LDAP Auth for Active Directory provides enterprise-grade Single Sign-On (SSO) and access control for corporate WordPress intranets. Built for multi-forest environments, it allows users to authenticate seamlessly against multiple Domain Controllers while strictly enforcing path-based access policies and dynamic role propagation.
Key Features
- Multi-Domain & Multi-DC Authentication: Connect and authenticate against multiple LDAP/LDAPS servers across different Active Directory domains/UPN suffixes.
- Zero-Trust Path-Based ACL: Restrict intranet sections, categories, and custom routes based on AD Group Membership (CN) or mapped WP Roles.
- JIT Provisioning & Single Source of Truth: Automatic user creation on first successful AD bind, with optional strict role sync on every login.
- LDAP Clone Protection: Detects and prevents authentication if multiple accounts match the same SAMAccountName across refined Base DNs to block privilege escalation.
- REST API & Write ACL Protection: Enforces URL routing policies over REST API endpoints and post/page editing privileges (
map_meta_cap). - Secure Connections: Supports LDAP (Plaintext), LDAP + StartTLS, and LDAPS (SSL/TLS Encrypted).