Search Results :

×

In any organization where employees work across different departments with different levels of data access, keeping permissions accurate is just as important as keeping them secure. When roles change frequently, and user counts run into the hundreds or thousands, manually managing who can see what inside Joomla is neither practical nor safe.

The miniOrange SAML SSO plugin for Joomla handles this automatically through its Group Mapping feature. When an employee logs in, the plugin reads their group membership directly from the SAML assertion sent by the Identity Provider and assigns them to the correct Joomla User Group on the spot. If their role changes in the IdP, their Joomla permissions update on their next login: no manual reassignment, no administrative backlog, and no risk of someone retaining access they should no longer have.

This use case has been seamlessly implemented using the plugin listed below. To achieve this, you will need to install the following plugin on your Joomla instance:

usecase card logo

miniOrange SAML Single Sign-On (SP) Plugin

Download Extension

An enterprise organization maintained a Joomla resource site containing confidential departmental content, internal HR policies, IT system documentation, marketing assets, and other materials that were only meant for the relevant teams. Employee groups such as HR_Team, IT_Admins, and Marketing_Staff were already defined and actively managed inside the central Identity Provider, where the IT team handled all role assignments.

The problem was that none of this group information carried over to Joomla automatically. Every time a new employee joined, a Joomla administrator had to manually assign them to the correct User Group. Every time someone changed departments or took on a new role, the same administrator had to track that change down and update Joomla separately. With a workforce that moved frequently between teams and departments, these updates were easy to miss and slow to action.

The consequences of falling behind were serious. Employees who had moved on from a department often retained access to that department's confidential content simply because no one had updated their Joomla group in time. New joiners sometimes spent days without access to the resources they actually needed. There was no reliable way to guarantee that what the IdP said about a user's role was accurately reflected in what Joomla allowed them to see, and in an organization handling sensitive internal data, that gap represented a real and ongoing security risk.

The miniOrange SAML SSO plugin was configured to read each employee's group membership from the SAML assertion at login and automatically assign the corresponding Joomla User Group, ensuring that access rights in Joomla are always driven by the authoritative record held in the Identity Provider.


Step 1: Install and activate the miniOrange SAML Single Sign-On plugin on the Joomla instance and complete the base SAML configuration by registering Joomla as a Service Provider within the corporate Identity Provider.


Step 2: In your Identity Provider, confirm that departmental group memberships such as HR_Team, IT_Admins, and Marketing_Staff are configured to be included as attributes within the SAML assertion sent to Joomla on each login.


Step 3: In the plugin's admin panel, navigate to the Group/Role Mapping section and create mapping rules that link each IdP group to the appropriate Joomla User Group. For example, map HR_Team to the Joomla Editor group, IT_Admins to Super Users, and Marketing_Staff to Author.


Step 4: Enable Auto-Assign User Group on Login so that every time an employee authenticates, the plugin reads their current group from the SAML assertion and places them into the correct Joomla User Group automatically, including on their very first login.


Step 5: Enable Sync Group Membership on Every Login to ensure that any changes made to a user's group in the Identity Provider are carried through to Joomla permissions on their next login, without requiring any manual update inside Joomla.


Step 6: Configure Default Group Assignment for users whose SAML assertion does not include a recognized group attribute, assigning them to a restricted access group by default to prevent unintended access to protected content.


Step 7: Set up Joomla Content Access Rules for each User Group using Joomla's native access control system, ensuring that each group can only view and interact with the content relevant to their department.


Step 8: Test the configuration by logging in with accounts from each IdP group and confirming that the correct Joomla User Group is assigned and that access is restricted to only the appropriate content for each role.


With SAML Group Mapping in place, the organization's Joomla permissions became a direct and automatic reflection of its Identity Provider, the single source of truth already used to manage every employee's role and clearance level. New employees were assigned the correct access on their very first login without any manual intervention. When someone moved departments or changed roles, their Joomla permissions updated on their next login to match the new group assignment in the IdP. Nobody retained access beyond their current role, and nobody was left waiting for an administrator to manually catch up with a change that had already happened at the directory level. The security team gained confidence that what employees could access in Joomla was always accurate, current, and governed by the same policies that controlled access everywhere else in the organization.

  1. SAML Single Sign-On for Joomla
  2. SAML vs OAuth in Joomla: Which should you choose?
  3. Check out our documentation

We'll Reach Out to You at the Earliest

mo-form

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

Table of Contents

Hello there!

Need Help? We are right here!

support