Search Results :

×

How to Set Up Azure Multitenant SSO / Azure AD Multi-Tenant Login for WordPress?


The miniOrange Azure Multitenant SSO add-on allows users from multiple Azure AD / Microsoft Entra ID tenants to log in to WordPress using a single Azure Multitenant application. It works with the miniOrange SAML SP SSO plugin so that users from your own Office 365 / Azure AD tenants and your clients’ tenants can authenticate with their existing Azure AD credentials without configuring each tenant separately.
By mapping tenant IDs and using a common Azure Multitenant endpoint, you can enable seamless multi-tenant Single Sign-On, tenant-based SSO restriction, and group or role mapping based on tenants.
In this guide, you’ll learn how to set up Azure AD as the Identity Provider (IDP) for multitenant SSO and configure the Azure Multitenant Plugin for WordPress.


Azure AD/B2C/Office 365 Sync Integrations

Azure AD Sync Integrations

Bidirectionally sync user data between Azure AD/B2C/Office 365 and WordPress for seamless Azure Sync and Azure Sync, providing secure authentication through Azure AD SSO.

Azure Integrations   

Azure AD/B2C/Office 365 App Integrations with WordPress

Azure AD App Integrations

Connect WordPress with Azure AD to integrate SharePoint, OneDrive, Power BI, Dynamics 365, Outlook, and more. Simplify user sync, enable Azure multitenancy, and strengthen access management using Azure SSO.

Azure AD/B2C Integrations   

Follow the steps below to configure Azure AD as IdP for WordPress

Configure Azure AD as IdP

  • In the SAML SP SSO plugin for WordPress, navigate to Service Provider Metadata tab. Here, you can find the SP metadata such as SP Entity ID and ACS (AssertionConsumerService) URL which are required to configure Azure AD as the Identity Provider.
Azure Multitenant SSO - Service Provider Metadata

Azure Multitenant SSO - Select Azure Active Directory

  • Select App registrations.
Azure Multitenant SSO - Select App Registrations

  • Click on New registration.
Azure Multitenant SSO - New App Registration

  • Assign a Name and choose the Supported account types as Accounts in any orgnaizational directory (Any Azure AD directory - Multitenant).
  • In the Redirect URL field, provide the ACS URL provided in Service Provider Metadata tab of the plugin and click on Register button.
Azure Multitenant SSO - Application Registration Details

  • Navigate back to the Overview tab of you active directory, copy the Primary Domain and keep it handy.
Azure Multitenant SSO - Copy Primary Domain

  • Now copy the Application ID from the configured app and keep it handy.
Azure Multitenant SSO - Copy Application ID

  • Navigate to Expose an API from left menu panel.
Azure Multitenant SSO - Expose an API

  • Click the Set button and replace the APPLICATION ID URL with https://Primary_Domain/Appication-Id that you have copied previously and click on Save
Azure Multitenant SSO - Replace Application ID URL

  • Go to the Authentication tab in the left panel and select ID Tokens (Used for implicit and Hybrid flows) option also make sure supported account types is Accounts in any orgnaizational directory (Any Azure AD directory - Multitenant) then click on Save.
Azure Multitenant SSO - Select ID Tokens in Authentication

  • Navigate to API Permissions Add Permission and select Microsoft Graph.
Azure Multitenant SSO - Add Microsoft Graph Permission

  • Now click on Application permission, then search for User.Read.All once the option is selected then click on Add permissions button.
Azure Multitenant SSO - Request User.Read.All API Permission

  • To proceed further click on Graant Admin Consent for Demo.
Azure Multitenant SSO - Grant Admin Consent

  • Go back to Azure Active DirectoryApp Registrations window and click on Endpoints.
Azure Multitenant SSO - Click on Endpoints

  • This will navigate up to a window with multiple URLs.
  • Copy the Federation Metadata document URL to get the Endpoints required for configuring your Service Provider.
Azure Multitenant SSO - Copy Federation Metadata Document URL

  • Now paste the Federation Metadata URL in the Service Provider Setup tab of the plugin and click on fetch.
Azure Multitenant SSO - Paste Federation Metadata in Service Provider Setup

  • Naviagate back to your active directory and copy Application ID URI from the Expose an API tab and paste it in the SP Entity ID/ Issuer under Service Provider Endpoints tab.
Azure Multitenant SSO - Copy Application ID URI to SP Entity ID

  • Also replace the SAML Login URl and SAML Logout URl with https://login.microsoft.com/common/saml2 then click on save.
Azure Multitenant SSO - Replace SAML Login and Logout URL
  • First install the Azure Multitenant SSO plugin.
  • In the Azure Multitenant plugin select the Idp from the dropdown and paste the Tenant IDs that you want to configure then click on save.
Azure Multitenant SSO - Add Tenant ID in Plugin

  • To get the Tenant ID for the required office 365 account, navigate back to the Azure AD portal. Click on the Overview tab and copy the tenant ID value as displayed in the below screenshot.
Azure Multitenant SSO - Copy Tenant ID from Azure Overview

  • Now, ask all the tenant administrators to perform the SSO first and grant the required permissions to the application.
Azure Multitenant SSO - Grant Required Permissions Consent

  • Now you can test the SSO in an Incognito window to confirm if the Single Sign-On for multiple tenants is configured correctly.
  • You have successfully configured Azure AD Multitenant SSO for achieving Azure AD SSO login into your WordPress Site.

In this Guide, you have successfully configured Azure Multitenant SSO for WordPress using the miniOrange SAML Single Sign-On (SSO) Login plugin. With Azure AD as the Identity Provider and WordPress as the Service Provider, users from multiple Azure AD tenants can securely access your WordPress site using their existing Azure AD credentials within minutes.


View More FAQs

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

We'll Reach Out to You at the Earliest!


ADFS_sso ×
Hello there!

Need Help? We are right here!

support