Title: IvoryGate
Author: sebaklim93411
Published: <strong>September 27, 2026</strong>
Last modified: September 27, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/ivorygate.svg)

# IvoryGate

 By [sebaklim93411](https://profiles.wordpress.org/sebaklim93411/)

[Download](https://downloads.wordpress.org/plugin/ivorygate.0.1.2.zip)

 * [Details](https://wordpress.org/plugins/ivorygate/#description)
 * [Reviews](https://wordpress.org/plugins/ivorygate/#reviews)
 *  [Installation](https://wordpress.org/plugins/ivorygate/#installation)
 * [Development](https://wordpress.org/plugins/ivorygate/#developers)

 [Support](https://wordpress.org/support/plugin/ivorygate/)

## Description

IvoryGate signs users in to existing WordPress accounts using an identity authenticated
by Microsoft IIS Windows Authentication.

The plugin is designed for controlled Windows and IIS environments such as intranets.
It does not implement Kerberos or NTLM itself and never receives or stores a Windows
password. IIS performs Windows Authentication and provides the trusted server identity.

Key properties:

 * Exact, case-sensitive mapping from a Windows identity to an existing WordPress
   user ID.
 * No automatic user creation, role changes, or password changes.
 * HTTPS is required for automatic SSO.
 * Secure WordPress authentication cookies are created with the official WordPress
   API.
 * When SSO is enabled, WordPress password login and application passwords are disabled.
 * Unknown, missing, duplicated, or invalid mappings fail closed.
 * Optional logging contains fixed event codes only and does not include identities,
   cookies, passwords, or request data.
 * Existing WordPress sessions are not switched to another account.

#### Important requirements

IvoryGate requires:

 * Microsoft IIS with Windows Authentication using Negotiate, NTLM, or Kerberos.
 * A server configuration in which IIS securely sets REMOTE_USER, AUTH_USER, and
   AUTH_TYPE.
 * HTTPS for the request, WordPress Address, and Site Address.
 * Existing WordPress user accounts to map to.
 * A single-site WordPress installation. WordPress Multisite is not supported.

IIS may reject a request with HTTP 401 before WordPress or IvoryGate runs. In that
case, the browser may show its own Windows credentials dialog. A WordPress plugin
cannot replace that dialog or reliably detect private or incognito browsing mode.

IvoryGate does not trust identity values from HTTP_REMOTE_USER, X-Forwarded-User,
Authorization, cookies, or other client-controlled headers.

#### Lockout protection

Before enabling SSO, retain administrative access to the server files.

To restore native WordPress login during recovery, add the following before WordPress
loads:

define( ‘IVORYGATE_DISABLE_SSO’, true );

You can also disable the plugin by renaming its directory from the server file system.
The plugin intentionally retains its settings when deactivated or uninstalled.

### Privacy

IvoryGate does not transmit data to external services. Configuration is stored in
the local WordPress options table. It contains explicit Windows identity strings
and WordPress user IDs entered by an administrator.

Optional diagnostic logging writes only fixed event codes to the operating system
log through PHP syslog. It does not log identities, passwords, cookies, tokens, 
exception messages, or request data.

## Installation

 1.  Configure HTTPS and IIS Windows Authentication.
 2.  Install and activate IvoryGate.
 3.  Open Settings > IvoryGate while signed in as an administrator.
 4.  Verify the displayed IIS identity and authentication type.
 5.  Add an exact mapping from the current Windows identity to an existing WordPress
     user.
 6.  Confirm that IIS is the trusted source of the server identity.
 7.  Keep server file access available, then enable Windows SSO.
 8.  Test with a separate browser profile and verify the selected WordPress user.
 9.  Verify that an unknown identity is denied access.

Do not enable SSO until the diagnostics, HTTPS status, and mapping are correct.

## FAQ

### Does IvoryGate store Windows passwords?

No. IIS performs Windows Authentication. IvoryGate never receives or stores the 
Windows password, PIN, Microsoft token, or incoming WordPress authentication cookie.

### Does it create WordPress users?

No. Every Windows identity must be explicitly mapped to one existing WordPress user
ID.

### Why does the browser show a system credentials dialog?

IIS sends an authentication challenge before PHP and WordPress run. Browser policy,
intranet-zone configuration, the Windows session, domain configuration, and Kerberos
or NTLM availability determine whether authentication is automatic or a credentials
dialog appears.

### Can IvoryGate detect incognito or private browsing?

No. Browsers do not provide a reliable server-side signal for private browsing. 
Browser or organization policy must control private browsing when that is required.

### What happens to the normal WordPress login form?

When SSO is enabled, IvoryGate returns HTTP 403 instead of displaying password-based
WordPress login to an unauthenticated user. It also blocks password authentication
and application passwords. The emergency constant restores native login for recovery.

### What happens when SSO is disabled?

WordPress authentication behaves normally. IvoryGate does not issue an SSO cookie
or block password login.

### Does IvoryGate support Multisite?

No. SSO is blocked on WordPress Multisite.

### Does IvoryGate send data to external services?

No. The plugin makes no external network requests and has no telemetry.

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“IvoryGate” is open source software. The following people have contributed to this
plugin.

Contributors

 *   [ sebaklim93411 ](https://profiles.wordpress.org/sebaklim93411/)

[Translate “IvoryGate” into your language.](https://translate.wordpress.org/projects/wp-plugins/ivorygate)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/ivorygate/), check 
out the [SVN repository](https://plugins.svn.wordpress.org/ivorygate/), or subscribe
to the [development log](https://plugins.trac.wordpress.org/log/ivorygate/) by [RSS](https://plugins.trac.wordpress.org/log/ivorygate/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 0.1.2

 * Added the verified WordPress.org owner to Contributors.
 * Sanitized nonce, settings, query, and server request values before use.

#### 0.1.1

 * Added SSO-only mode when Windows SSO is enabled.
 * Blocked the WordPress password form, password authentication, and application
   passwords while SSO is enabled.
 * Added a clear HTTP 403 message when IIS admits a request but IvoryGate cannot
   complete SSO.
 * Retained the emergency constant that restores native WordPress login.
 * Added WordPress.org metadata and documentation.
 * Corrected request-value sanitization and displayed version metadata.

#### 0.1.0

 * Initial stable release.
 * Added exact IIS Windows identity mapping to existing WordPress accounts.
 * Added HTTPS-only automatic SSO and secure WordPress session creation.
 * Added administrator diagnostics and fixed-code system logging.

## Meta

 *  Version **0.1.2**
 *  Last updated **2 days ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 6.0 or higher **
 *  Tested up to **7.1.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [iis](https://wordpress.org/plugins/tags/iis/)[intranet](https://wordpress.org/plugins/tags/intranet/)
   [security](https://wordpress.org/plugins/tags/security/)[sso](https://wordpress.org/plugins/tags/sso/)
 *  [Advanced View](https://wordpress.org/plugins/ivorygate/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/ivorygate/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/ivorygate/reviews/)

## Contributors

 *   [ sebaklim93411 ](https://profiles.wordpress.org/sebaklim93411/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/ivorygate/)