Search Results :

×

Most organizations think of Joomla purely as a website platform. But with the right plugin, it can become something far more powerful: a central Identity Provider that controls authentication across every platform in your ecosystem.

The miniOrange SAML IDP plugin for Joomla makes this possible. It transforms your Joomla site into the single source of truth for user identity, allowing external platforms like a Learning Management System or a community forum to trust Joomla as their authentication authority. Users log into Joomla once and gain access to every connected platform automatically: no separate accounts, no repeated logins, no friction.

This use case has been seamlessly implemented using the plugin listed below. To achieve this, you will need to install the following plugin on your Joomla instance:

usecase card logo

miniOrange SAML Single Sign-On (IDP) Plugin

Download Extension

An online training institution ran its entire membership and user management through Joomla. Users purchased memberships, maintained their profiles, and engaged with the brand primarily through the main Joomla website. Alongside this, the institution operated a Moodle-based Learning Management System for course delivery and a separate platform for its community forums.

Each platform had its own login system. A user who bought a membership on Joomla still had to create a separate account on Moodle to access their courses, and yet another account on the forum to participate in community discussions. For an institution whose entire value proposition was a connected learning experience, this fragmented account structure created exactly the wrong first impression. New members frequently dropped off during the onboarding process, confused by why a platform they had just paid to join required them to register again elsewhere.

Support tickets about login issues across the three platforms were a constant drain on the team. Worse, when a membership expired or an account was suspended on Joomla, those users often retained full access to Moodle and the forum indefinitely because there was no link between the systems and no way to enforce a centralized access policy across all three from a single point of control.

The miniOrange SAML IDP plugin was installed on the main Joomla site, designating it as the central Identity Provider for the entire ecosystem. Moodle and the community forum were then configured as SAML Service Providers, establishing a trusted SSO connection between Joomla and each external platform.


Step 1: Install and activate the miniOrange SAML Identity Provider plugin on the main Joomla website.


Step 2: In the plugin's admin panel, navigate to the Service Provider Configuration section and add Moodle as the first connected SP. Enter Moodle's SP Entity ID and ACS (Assertion Consumer Service) URL, which can be retrieved from Moodle's SAML authentication settings.


Step 3: Repeat the same process to register the community forum as a second Service Provider, entering its corresponding SP Entity ID and ACS URL.


Step 4: Download or copy the Joomla IDP Metadata generated by the plugin, including the Entity ID, SSO Login URL, and X.509 Certificate, and upload this into the SAML configuration of both Moodle and the forum platform so that they recognize and trust Joomla as their Identity Provider.


Step 5: In the plugin's Attribute Configuration section, define which Joomla user profile fields should be included in the SAML assertion sent to each Service Provider, such as the user's name and email address. If your Joomla site uses a membership extension (such as Membership Pro or EasySocial), additional attributes like membership status or membership tier can also be mapped and passed to the connected platforms, provided the membership extension exposes these fields in the Joomla user profile.


Step 6: Enable Auto-Create User on SP Side within each Service Provider's SAML configuration, so that the first time a Joomla user accesses Moodle or the forum via SSO, an account is automatically created for them on that platform using the attributes passed from Joomla with no separate registration required.


Step 7: Test the full SSO flow end-to-end: log into Joomla and confirm that accessing Moodle and the forum requires no additional login, and verify that user attributes are correctly passed through and displayed on each connected platform.


Once the SAML IDP configuration was live, the institution's three platforms began functioning as a single, connected ecosystem. A user who logged into Joomla could move directly into their Moodle courses and the community forum without encountering another login screen. New members no longer needed to register separately on each platform; their Joomla account was all they needed. The support team saw an immediate drop in login-related tickets as the confusion of managing multiple accounts was removed entirely. Critically, access control became centralized for the first time; suspending or deactivating an account on Joomla now effectively cut off access to all connected platforms, giving the institution full confidence that membership boundaries were being enforced consistently across the entire ecosystem.

  1. SAML Single Sign-On for Joomla
  2. SAML vs OAuth in Joomla: Which should you choose?
  3. Check out our documentation

We'll Reach Out to You at the Earliest

mo-form

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

Table of Contents

Hello there!

Need Help? We are right here!

support