Download the PHP package dmlab/module-admin-sso-azure without Composer

On this page you can find all versions of the php package dmlab/module-admin-sso-azure. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package module-admin-sso-azure

DmLab_AdminSsoAzure

Microsoft Entra ID (Azure AD) login for the Magento 2 admin panel.

License Magento PHP Version

A thin Microsoft Entra ID provider plugin for the provider-agnostic admin-sso capability. It supplies the Entra OIDC preset — discovery from your tenant, scopes, groups claim, login-button branding — while all OIDC protocol lives in sso-core and all admin logic in admin-sso. Installing it pulls admin-sso and sso-core automatically.

Installation

Register the Entra app

In the Azure portal → Microsoft Entra ID → App registrations → New registration:

  1. Supported account types — Accounts in this organizational directory only (single tenant). Multi-tenant admin login is not supported (see Tenant below).
  2. Redirect URI — platform Web, value = the admin-sso callback: https://<admin-host>/<admin-path>/adminsso/sso/callback (<admin-path> is the backend frontName, default admin). It must match the admin URL used at runtime exactly.
  3. Register, then copy the Application (client) ID and the Directory (tenant) ID.
  4. Certificates & secrets → New client secret — copy the secret value.
  5. Groups claim — for IdP-group → ACL-role mapping, Token configuration → Add groups claim, and emit it on the ID token. Without this Entra sends no groups and role mapping falls back to the default role.

Configuration

Admin → Stores → Configuration → DMLab → Admin SSO.

General (dmlab_admin_sso/general/*):

Field Value
Enable Admin SSO Yes
Identity Provider Microsoft Entra ID
Client ID Application (client) ID from the Entra app
Client Secret client secret value from the Entra app

Microsoft Entra ID (dmlab_admin_sso/azure/*, shown when Entra is selected):

Field Value
Tenant Directory (tenant) GUID or a verified domain of your directory (single-tenant only)

The discovery URL is derived from the tenant: https://login.microsoftonline.com/<tenant>/v2.0/.well-known/openid-configuration. Admin SSO is single-tenant only — the multi-tenant meta values common/organizations advertise a templated {tenantid} issuer that never matches a real token, so they are rejected.

Group → role mapping and enforce-SSO/break-glass are configured in admin-sso; see that module's README.

Group overage limitation

Entra omits the groups claim when a user belongs to more than ~200 groups, sending a _claim_names/_claim_sources overage reference to Microsoft Graph instead. v1 reads the groups claim directly, so such users get no group-based roles and fall back to the default role. A Graph fallback is a future task. Keep affected admins under the overage limit, or scope the groups claim (Token configuration) to the groups assigned to the application.

Requirements

Part of the DMLab identity suite

Repo Role
sso-core Shared OIDC engine (installed automatically)
admin-sso · admin-sso-<idp> Admin-panel SSO login
customer-sso · customer-sso-<idp> Storefront SSO login
admin-scim · admin-scim-<idp> Admin-user provisioning (SCIM 2.0)

License

https://dmlab.work.


All versions of module-admin-sso-azure with dependencies

PHP Build Version
Package Version
Requires php Version ~8.3.0||~8.4.0||~8.5.0
magento/framework Version >=103.0
dmlab/module-admin-sso Version *
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package dmlab/module-admin-sso-azure contains the following files

Loading the files please wait ...