Title: Sanch MultiDomain LDAP Auth for Active Directory
Author: sanchshevchuk
Published: <strong>August 1, 2026</strong>
Last modified: August 1, 2026

---

Search plugins

![](https://s.w.org/plugins/geopattern-icon/sanch-multidomain-ldap-auth.svg)

# Sanch MultiDomain LDAP Auth for Active Directory

 By [sanchshevchuk](https://profiles.wordpress.org/sanchshevchuk/)

[Download](https://downloads.wordpress.org/plugin/sanch-multidomain-ldap-auth.1.0.0.zip)

 * [Details](https://wordpress.org/plugins/sanch-multidomain-ldap-auth/#description)
 * [Reviews](https://wordpress.org/plugins/sanch-multidomain-ldap-auth/#reviews)
 *  [Installation](https://wordpress.org/plugins/sanch-multidomain-ldap-auth/#installation)
 * [Development](https://wordpress.org/plugins/sanch-multidomain-ldap-auth/#developers)

 [Support](https://wordpress.org/support/plugin/sanch-multidomain-ldap-auth/)

## Description

Sanch MultiDomain LDAP Auth for Active Directory provides enterprise-grade Single
Sign-On (SSO) and access control for corporate WordPress intranets. Built for multi-
forest environments, it allows users to authenticate seamlessly against multiple
Domain Controllers while strictly enforcing path-based access policies and dynamic
role propagation.

#### Key Features

 * **Multi-Domain & Multi-DC Authentication:** Connect and authenticate against 
   multiple LDAP/LDAPS servers across different Active Directory domains/UPN suffixes.
 * **Zero-Trust Path-Based ACL:** Restrict intranet sections, categories, and custom
   routes based on AD Group Membership (CN) or mapped WP Roles.
 * **JIT Provisioning & Single Source of Truth:** Automatic user creation on first
   successful AD bind, with optional strict role sync on every login.
 * **LDAP Clone Protection:** Detects and prevents authentication if multiple accounts
   match the same SAMAccountName across refined Base DNs to block privilege escalation.
 * **REST API & Write ACL Protection:** Enforces URL routing policies over REST 
   API endpoints and post/page editing privileges (`map_meta_cap`).
 * **Secure Connections:** Supports LDAP (Plaintext), LDAP + StartTLS, and LDAPS(
   SSL/TLS Encrypted).

## Installation

 1. Upload the `sanch-multidomain-ldap-auth` directory to the `/wp-content/plugins/`
    directory.
 2. Activate the plugin through the ‘Plugins’ menu in WordPress.
 3. Ensure the PHP LDAP extension (`php-ldap`) is installed and enabled on your web
    server.
 4. Navigate to **Settings -> AD Auth Settings** in your WordPress admin dashboard.
 5. Configure your Domain Controllers (IP, Port, Domain, Base DN) and define your AD
    Group to WP Role mapping rules.

## FAQ

### Does this plugin require the PHP LDAP extension?

Yes, your web server must have the `php-ldap` PHP module enabled to initiate connections
with your Active Directory Domain Controllers.

### What happens if an AD user does not belong to any mapped group?

By default under Zero-Trust policy, authentication will fail with an “Access Denied”
message if the user does not belong to at least one mapped AD Group.

### How are custom WP roles handled?

You can select existing WordPress roles or create custom role slugs directly from
the settings page, assigning base capability sets (`subscriber`, `editor`, `author`,`
administrator`).

## Reviews

There are no reviews for this plugin.

## Contributors & Developers

“Sanch MultiDomain LDAP Auth for Active Directory” is open source software. The 
following people have contributed to this plugin.

Contributors

 *   [ sanchshevchuk ](https://profiles.wordpress.org/sanchshevchuk/)

[Translate “Sanch MultiDomain LDAP Auth for Active Directory” into your language.](https://translate.wordpress.org/projects/wp-plugins/sanch-multidomain-ldap-auth)

### Interested in development?

[Browse the code](https://plugins.trac.wordpress.org/browser/sanch-multidomain-ldap-auth/),
check out the [SVN repository](https://plugins.svn.wordpress.org/sanch-multidomain-ldap-auth/),
or subscribe to the [development log](https://plugins.trac.wordpress.org/log/sanch-multidomain-ldap-auth/)
by [RSS](https://plugins.trac.wordpress.org/log/sanch-multidomain-ldap-auth/?limit=100&mode=stop_on_copy&format=rss).

## Changelog

#### 1.0.0

 * Initial release. Features Multi-Domain authentication, LDAP Clone Guard, StartTLS/
   LDAPS support, and Zero-Trust path-based ACL routing.

## Meta

 *  Version **1.0.0**
 *  Last updated **6 hours ago**
 *  Active installations **Fewer than 10**
 *  WordPress version ** 5.8 or higher **
 *  Tested up to **7.0.2**
 *  PHP version ** 7.4 or higher **
 * Tags
 * [acl](https://wordpress.org/plugins/tags/acl/)[active directory](https://wordpress.org/plugins/tags/active-directory/)
   [authentication](https://wordpress.org/plugins/tags/authentication/)[ldap](https://wordpress.org/plugins/tags/ldap/)
   [multi domain](https://wordpress.org/plugins/tags/multi-domain/)
 *  [Advanced View](https://wordpress.org/plugins/sanch-multidomain-ldap-auth/advanced/)

## Ratings

No reviews have been submitted yet.

[Your review](https://wordpress.org/support/plugin/sanch-multidomain-ldap-auth/reviews/#new-post)

[See all reviews](https://wordpress.org/support/plugin/sanch-multidomain-ldap-auth/reviews/)

## Contributors

 *   [ sanchshevchuk ](https://profiles.wordpress.org/sanchshevchuk/)

## Support

Got something to say? Need help?

 [View support forum](https://wordpress.org/support/plugin/sanch-multidomain-ldap-auth/)