Search Results :

×

When thousands of employees access a Joomla portal through a corporate Identity Provider, their profile information, name, email, phone number, and department needs to be accurate from the very first login. Asking employees to manually fill in their own profile details is unreliable at any scale, and keeping that data updated over time is simply not practical.

The miniOrange SAML SSO plugin for Joomla solves this through Automated Account Creation and Attribute Mapping. The first time an employee logs in via SSO, the plugin automatically creates their Joomla account and populates their profile using the data sent directly by the Identity Provider. Every subsequent login refreshes that data, so the Joomla portal always reflects whatever is currently on record in the corporate directory: no manual entry, no outdated profiles, no administrative overhead.

This use case has been seamlessly implemented using the plugin listed below. To achieve this, you will need to install the following plugin on your Joomla instance:

usecase card logo

miniOrange SAML Single Sign-On (SP) Plugin

Download Extension

A multinational corporation with thousands of employees worldwide used a Joomla-based internal hub as a central collaboration space. Employee identities were already managed inside a corporate Identity Provider, Azure AD, Okta, or Google Workspace, where HR teams maintained up-to-date records for every staff member.

The problem was that none of this existing data carried over to Joomla automatically. Every new employee had to either manually fill in their Joomla profile or wait for an IT administrator to create and populate their account by hand. Across a global workforce, this meant IT teams were spending significant time on repetitive account creation tasks that added no real value.

The situation became harder to manage over time. Employees changed their contact details, moved between departments, or took on new job titles, and none of these updates made their way into Joomla unless someone remembered to update them manually. The result was a Joomla user database full of stale, incomplete, or inconsistent profile data that teams simply could not rely on. For a platform meant to support collaboration and internal communication, inaccurate user information quietly undermined its usefulness every single day.

The miniOrange SAML SSO plugin was configured to connect Joomla directly to the organization's Identity Provider and automatically handle both account creation and profile data population at the point of login, requiring no manual steps from either the employee or the IT team.


Step 1: Install and activate the miniOrange SAML Single Sign-On plugin on the Joomla instance.


Step 2: In the plugin's admin panel, go to the Service Provider Setup section and download the Joomla SP metadata. Upload this metadata into your Identity Provider (Azure AD, Okta, or Google Workspace) to register Joomla as a trusted SAML application.


Step 3: Enter the Identity Provider's SAML Metadata URL or manually input the Entity ID, SSO Login URL, and X.509 Certificate into the plugin to establish the trusted connection between the IdP and Joomla.


Step 4: Navigate to the Attribute Mapping section of the plugin. Here, map the SAML attributes sent by the Identity Provider to the corresponding Joomla user profile fields. For example, map the IdP attribute first_name to Joomla's First Name field, last_name to Last Name, email to Email Address, and phone to Phone Number.


Step 5: Enable Auto-Create User on First Login so that when an employee logs in for the very first time, the plugin automatically creates their Joomla account using the profile data received from the Identity Provider, with no pre-provisioning required.


Step 6: Enable Sync User Attributes on Every Login so that each subsequent login triggers a fresh pull of the user's profile attributes from the IdP. This ensures that any changes made in the central corporate directory, such as a name change, updated email address, or new phone number, are automatically reflected in Joomla the next time the employee logs in.


Step 7: Optionally, configure Role Mapping to automatically assign the appropriate Joomla user role based on attributes sent by the IdP, such as department, job title, or group membership, so that new accounts are created with the correct permissions from the start.


Step 8: Test the full flow by logging in with a test IdP account and verifying that the Joomla account is created correctly, all mapped profile fields are populated accurately, and a subsequent login with updated IdP attributes correctly refreshes the Joomla profile.


For educational platforms and institutions of any size, managing content access does not have to mean choosing between openness and security. With the miniOrange Joomla SAML SSO plugin and Page Restriction plugin working in combination, Joomla-based educational websites can enforce precise, reliable access control exactly where it is needed on the pages that matter without interfering with the public experience that drives discovery and engagement.

Students, members, and subscribers gain a seamless single sign-on experience tied directly to their institution's Identity Provider. Administrators eliminate the burden of managing disconnected credentials and manually maintaining access lists. And premium educational content, whether ePaper editions, course materials, research archives, or members-only resources, is consistently protected and accessible only to those who are entitled to it.

Whether you are running a university portal, an academic publishing platform, an online learning site, or a professional membership organization on Joomla, this combination of SAML-based authentication and granular page restriction delivers a scalable, standards-compliant content access strategy with no custom development required.

  1. SAML Single Sign-On for Joomla
  2. SAML vs OAuth in Joomla: Which should you choose?
  3. Check out our documentation

We'll Reach Out to You at the Earliest

mo-form

 Thank you for your response. We will get back to you soon.

Something went wrong. Please submit your query again

Table of Contents

Hello there!

Need Help? We are right here!

support