Search Results :

×

Secure ExpressionEngine
SAML SSO

The most flexible open-source CMS now has the most secure Single Sign On (SSO). Our ExpressionEngine SAML SSO plugin lets users log in to multiple EE websites or subsites using a single set of credentials (username and password) across any Identity Provider (Azure AD/Entra ID, Okta, ADFS, Google Workspace, Office 365, and 25+ more).
Expression Engine SAML SSO - Banner Image

Enterprise SSO. Built for ExpressionEngine.


30+

Identity Providers Supported

SAML 2.0

Compliant

Industry-Standard Security

Why Traditional ExpressionEngine Logins Hold You Back

Manual authentication scales poorly. As your audience grows, login friction, support tickets, and security gaps multiply.

Login Fatigue

Users juggle multiple credentials, lose productivity, and abandon sessions when login feels heavy.

Password Reset Overhead

Help desks are drowning in password tickets that drain the budget and slow your teams down.

Security Vulnerabilities

Weak passwords, reused credentials, and phishing attempts expose ExpressionEngine to real risk.

Fragmented Identity Systems

Disconnected tools force admins to manage users in silos with no central visibility.

Advanced Features of ExpressionEngine SAML SSO

ExpressionEngine SSO gives your IT team control over who gets in, what they see, and when access ends.

Single Sign-On

Single Sign-On (SSO)

Enable ExpressionEngine SAML SSO to give users one set of login credentials, such as a username and password, to access your ExpressionEngine site and every other connected application.

Complete Site Protection

Complete Site Protection

Lock every page of your ExpressionEngine site behind SSO. Any unauthenticated visitor is redirected to your IDP automatically. Nothing on your site stays accessible without a valid, active login session.

Attribute Mapping

Attribute Mapping

Map name, email, department, and custom attributes from your Identity Provider directly into ExpressionEngine user profiles at login. Profiles stay accurate and current without any manual data entry from your team.


Role and Group Mapping

Role and Group Mapping

Assign ExpressionEngine roles and group memberships based on your Identity Provider's data. Every user lands in the right access tier the moment they log in, with no admin intervention required after the initial setup.

Single Logout

Single Logout (SLO)

Logging out of ExpressionEngine ends the session at your Identity Provider, too. No session lingers in the background. Users sign out completely from both sides with one action, which matters most in shared environments.

Custom SP Certificate

Custom SP Certificate

Sign every SAML login and logout request with your own certificate. Organizations that require end-to-end request signing get complete control over how the ExpressionEngine SAML SSO exchange is secured and validated.

Start Securing Your ExpressionEngine Site Today

How ExpressionEngine SAML SSO Works

SSO for ExpressionEngine follows four clear steps. The whole process takes a few seconds for your users.

Step 1

User Clicks Login

The visitor lands on your ExpressionEngine site and selects Sign in with SSO.

Step 2

Redirect to Identity Provider

miniOrange forwards the request to your configured IDP using the SAML protocol.

Step 3

Authentication Completed

The IDP verifies credentials and returns a signed, validated assertion.

Step 4

Logged into ExpressionEngine

User lands inside ExpressionEngine with the right role, mapped attributes, and a secure session.

Supported Identity Providers for ExpressionEngine SSO

Integrate ExpressionEngine Single Sign-On with the IDP your enterprise already uses, or contact us to connect it securely to any custom SAML provider.

ExpressionEngine SSO integrations - azure
ExpressionEngine SSO integrations - okta
ExpressionEngine SSO integrations - adfs
ExpressionEngine SSO integrations - onelogin
ExpressionEngine SSO integrations - salesforce
ExpressionEngine SSO integrations - google workspace
ExpressionEngine SSO integrations - ping

Choose the Right ExpressionEngine SSO Pricing Plan

Compare plans side-by-side and pick what fits your scale. Upgrade or switch anytime.

FREE

$0

Free Download

Download Now
  • Unlimited Authentication
  • Role Mapping
  • Different SAML Request Binding Types
  • Change SP base URL & SP Entity ID
  • Custom SP Certificate
  • Attribute Mapping
  • Single Logout
  • Group Mapping
  • Redirect After SSO
PREMIUM
Most Popular

$999/Per Year


Buy Now
  • Unlimited Authentication
  • Role Mapping
  • Different SAML Request Binding Types
  • Change SP base URL & SP Entity ID
  • Custom SP Certificate
  • Attribute Mapping
  • Single Logout
  • Group Mapping
  • Redirect After SSO

Real World Use Cases
Supported by Our ExpressionEngine SAML SSO Plugin

The ExpressionEngine SAML SSO plugin empowers teams that manage users, roles, and access policies on an EE site.

Staff Portal SSO
Member and Community Sites
Cross-Application SSO
Partner and Contractor Access
Multi-Site and Regional SSO
Agency and Client Portals

Staff Portal SSO


Connect your internal ExpressionEngine portal to your corporate IDP (Azure AD, Okta, or ADFS) and let employees log in once to access HR resources, announcements, and internal tools. No separate passwords. No duplicate accounts. Every user stays in sync with your corporate directory from day one.

Member and Community Sites


Managing roles, permissions, and registrations on a membership site gets much easier when users log in with credentials they already have (a work account or a social identity like Google). Admins control access directly from the IDP. No manual updates inside ExpressionEngine every time something changes.

Cross-Application SSO


ExpressionEngine rarely runs alone. When it sits alongside dashboards, internal apps, and content sites, connecting all of them to one IDP means users log in once and move between every application without re-entering credentials. One login. Every tool. No interruptions.

Partner and Contractor Access


Give partners, vendors, and contractors access to your ExpressionEngine portals through their own Identity Provider (Azure AD B2C, Okta, or Google Workspace). They get in fast. You stay in control. Sensitive areas stay locked down without creating a separate account for every external user.

Multi-Site and Regional SSO


Large teams running ExpressionEngine across multiple sites or regions (each serving a different audience) need one consistent login everywhere. Connecting every installation to the same Identity Provider keeps access control synchronized. The right people reach the right site every time.

Agency and Client Portals


Managing multiple ExpressionEngine sites across different clients (each with their own Identity Provider and access requirements) takes time without the right setup. The multi-site and multiple IDP support in the ExpressionEngine SSO plugin lets you configure authentication once per client and replicate it across every installation. Less setup time. More client sites covered.

Why Choose miniOrange for ExpressionEngine SSO

Four reasons teams trust the ExpressionEngine SAML SSO plugin over every other option.

Enterprise-Grade Security and Privacy

Every SAML request is signed and encrypted. Authentication data never gets stored outside the exchange.

Start at No Cost

The core plugin is free to download from the EE Marketplace. Upgrade to the Premium plan when your team needs role mapping, SLO, or multi-site support.

Custom Configurations

Non-standard IDP setups get direct engineering attention. Your environment, your rules, built to spec.

24/7 Technical Support

Premium customers reach the same team that built the plugin, with direct technical answers around the clock.

Frequently Asked Questions

Answers to Common Queries About ExpressionEngine SAML SSO

General FAQsGeneral

What Is ExpressionEngine SSO?

ExpressionEngine SSO lets your users log in once using a single username and password and access your ExpressionEngine site without logging in again. It removes the need to remember multiple passwords and makes the login experience much easier for users.

How Does ExpressionEngine SAML Login Work?

When a user clicks the login button, they are taken to a trusted login system called an identity provider. Once they have entered their details there, they are automatically logged into ExpressionEngine without needing to enter their credentials again. This process is secure and happens in the background using SAML.

Which Identity Providers Are Supported?

ExpressionEngine Single Sign-On works with popular identity providers like Azure AD/Entra ID, Okta, and Google Workspace. It also supports any provider that follows standard login methods like SAML, so you can use the system you already have.

Can I Enable Single Logout (SLO) With ExpressionEngine SSO?

Yes, you can enable Single Logout (SLO). This means when a user logs out of ExpressionEngine, their session is properly closed, helping keep accounts secure and preventing unauthorized access.

Licensing & Support FAQsLicensing & Support

What does the license cover?

When you buy a license, it covers one instance (a single active installation of the plugin on one site) of the ExpressionEngine SAML SSO plugin. Your license stays active for as long as your plan runs, whether that is one year or more.

Can I add unlimited users, or do I need a separate license for each site?

You can add unlimited users on a single site without any restrictions on the number of logins. The one thing to keep in mind is that each license of the ExpressionEngine SAML SSO plugin covers one site. If you want to use the plugin on another site, you will need a separate license for it.

Does the license include updates?

Yes, it does. As long as your license is active, you get every update we release at no extra cost. This means you always have the latest version of the ExpressionEngine SAML SSO plugin without having to pay anything more.

Is support included in the license, or does it cost extra?

Support is included. Our team provides 24/7 assistance for any technical issues you face while using the plugin, including direct help from our developers. The level of priority you receive depends on the support plan you choose. Please have a look at the available plans to find the one that works best for you.

Evaluate ExpressionEngine SSO With Your Actual Environment in Mind

Our team walks you through the complete setup live, from Identity Provider connection to role assignment, so your IT and security teams leave with a clear answer before any purchase decision.

Want to Schedule a Demo?

mo-form

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

Hello there!

Need Help? We are right here!

support