New "User sync" tab that imports Microsoft 365 / Entra ID users as
WordPress accounts and keeps them up to date:
- Scope: whole tenant or the (nested) members of selected groups,
guests optional, e-mail domain allow-list respected. Existing accounts
are linked by e-mail address.
- Roles: selectable default role plus a group -> role mapping (in
addition to or instead of the default role, first match wins).
Roles of pre-existing accounts are only managed on request.
- Profile: selectable Graph attributes (names, job title, department,
phones, address, language, ...) and the profile photo as avatar.
- Deprovisioning: accounts disabled or deleted in Microsoft 365 (or
removed from the sync groups) are deactivated or deleted; accounts
deactivated by the sync are reactivated automatically. Deactivated
accounts lose every sign-in path and all sessions.
- Safeguards: dry run, safety stop above 20 % (min. 5) deprovisioning,
abort on any Graph error, "deleted" only on a 404 for the object ID,
protected pre-existing administrators and own account, content
reassignment required for deletion, run lock.
- Runs manually, via WP-Cron or `wp m365-login sync [--dry-run]`.
- Users screen column with deactivate/reactivate row actions and a
read-only Microsoft 365 section on the profile screen.
The Graph client gains paging, retry on throttling and user, group
member and photo endpoints. The group picker is now reusable.
Version 1.1.0, German translations (du/Sie), docs and audit addendum.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
rsync is not available everywhere; tar honours the same .distignore
patterns and ships with every CI runner.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JJxAHYdMfKPoN4koRc4Ci2
Adds a WordPress plugin that places a customisable "Sign in with
Microsoft" button on wp-login.php and signs existing users in via the
OpenID Connect authorization code flow with PKCE. Users are matched by
e-mail address only; no accounts are created.
Security: single-use state/nonce bound to an HttpOnly cookie, ID token
signature verification against Microsoft's JWKS (RS256 only) with
issuer/audience/tenant/expiry/nonce checks, optional tenant pinning,
account binding to the Microsoft object ID, e-mail domain allow-list,
client secret encrypted at rest (AES-256-GCM).
Admin: settings screen with connection, button and security tabs, live
button preview, colour presets, media-library icon picker, redirect URI
copy button and tenant connectivity test.
Packaging for WordPress.org: readme.txt with External services section,
GPL-2.0 license, uninstall.php, POT + German translations, .distignore,
build script, PHPCS config and CI running Plugin Check.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JJxAHYdMfKPoN4koRc4Ci2