{"id":374481,"date":"2026-09-27T06:17:51","date_gmt":"2026-09-27T06:17:51","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/ivorygate\/"},"modified":"2026-09-27T06:17:21","modified_gmt":"2026-09-27T06:17:21","slug":"ivorygate","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/ivorygate\/","author":23572728,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"0.1.2","stable_tag":"0.1.2","tested":"7.1.2","requires":"6.0","requires_php":"7.4","requires_plugins":null,"header_name":"IvoryGate","header_author":"IVORYcore","header_description":"IIS Windows SSO with explicit identity mapping and password login lockdown.","assets_banners_color":"","last_updated":"2026-09-27 06:17:21","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":44,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"0.1.2":{"tag":"0.1.2","author":"sebaklim93411","date":"2026-09-27 06:17:21","revision":3715046}},"upgrade_notice":[],"ratings":[],"assets_icons":[],"assets_banners":[],"assets_blueprints":{},"all_blocks":[],"tagged_versions":["0.1.2"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[3885,6307,600,2469,282894],"plugin_category":[54],"plugin_contributors":[282895],"plugin_business_model":[],"class_list":["post-374481","plugin","type-plugin","status-publish","hentry","plugin_tags-iis","plugin_tags-intranet","plugin_tags-security","plugin_tags-sso","plugin_tags-windows-authentication","plugin_category-security-and-spam-protection","plugin_contributors-sebaklim93411","plugin_committers-sebaklim93411"],"banners":[],"icons":{"svg":false,"icon":"https:\/\/s.w.org\/plugins\/geopattern-icon\/ivorygate.svg","icon_2x":false,"generated":true},"screenshots":[],"raw_content":"<!--section=description-->\n<p>IvoryGate signs users in to existing WordPress accounts using an identity authenticated by Microsoft IIS Windows Authentication.<\/p>\n\n<p>The plugin is designed for controlled Windows and IIS environments such as intranets. It does not implement Kerberos or NTLM itself and never receives or stores a Windows password. IIS performs Windows Authentication and provides the trusted server identity.<\/p>\n\n<p>Key properties:<\/p>\n\n<ul>\n<li>Exact, case-sensitive mapping from a Windows identity to an existing WordPress user ID.<\/li>\n<li>No automatic user creation, role changes, or password changes.<\/li>\n<li>HTTPS is required for automatic SSO.<\/li>\n<li>Secure WordPress authentication cookies are created with the official WordPress API.<\/li>\n<li>When SSO is enabled, WordPress password login and application passwords are disabled.<\/li>\n<li>Unknown, missing, duplicated, or invalid mappings fail closed.<\/li>\n<li>Optional logging contains fixed event codes only and does not include identities, cookies, passwords, or request data.<\/li>\n<li>Existing WordPress sessions are not switched to another account.<\/li>\n<\/ul>\n\n<h4>Important requirements<\/h4>\n\n<p>IvoryGate requires:<\/p>\n\n<ul>\n<li>Microsoft IIS with Windows Authentication using Negotiate, NTLM, or Kerberos.<\/li>\n<li>A server configuration in which IIS securely sets REMOTE_USER, AUTH_USER, and AUTH_TYPE.<\/li>\n<li>HTTPS for the request, WordPress Address, and Site Address.<\/li>\n<li>Existing WordPress user accounts to map to.<\/li>\n<li>A single-site WordPress installation. WordPress Multisite is not supported.<\/li>\n<\/ul>\n\n<p>IIS may reject a request with HTTP 401 before WordPress or IvoryGate runs. In that case, the browser may show its own Windows credentials dialog. A WordPress plugin cannot replace that dialog or reliably detect private or incognito browsing mode.<\/p>\n\n<p>IvoryGate does not trust identity values from HTTP_REMOTE_USER, X-Forwarded-User, Authorization, cookies, or other client-controlled headers.<\/p>\n\n<h4>Lockout protection<\/h4>\n\n<p>Before enabling SSO, retain administrative access to the server files.<\/p>\n\n<p>To restore native WordPress login during recovery, add the following before WordPress loads:<\/p>\n\n<p>define( 'IVORYGATE_DISABLE_SSO', true );<\/p>\n\n<p>You can also disable the plugin by renaming its directory from the server file system. The plugin intentionally retains its settings when deactivated or uninstalled.<\/p>\n\n<h3>Privacy<\/h3>\n\n<p>IvoryGate does not transmit data to external services. Configuration is stored in the local WordPress options table. It contains explicit Windows identity strings and WordPress user IDs entered by an administrator.<\/p>\n\n<p>Optional diagnostic logging writes only fixed event codes to the operating system log through PHP syslog. It does not log identities, passwords, cookies, tokens, exception messages, or request data.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Configure HTTPS and IIS Windows Authentication.<\/li>\n<li>Install and activate IvoryGate.<\/li>\n<li>Open Settings &gt; IvoryGate while signed in as an administrator.<\/li>\n<li>Verify the displayed IIS identity and authentication type.<\/li>\n<li>Add an exact mapping from the current Windows identity to an existing WordPress user.<\/li>\n<li>Confirm that IIS is the trusted source of the server identity.<\/li>\n<li>Keep server file access available, then enable Windows SSO.<\/li>\n<li>Test with a separate browser profile and verify the selected WordPress user.<\/li>\n<li>Verify that an unknown identity is denied access.<\/li>\n<\/ol>\n\n<p>Do not enable SSO until the diagnostics, HTTPS status, and mapping are correct.<\/p>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20ivorygate%20store%20windows%20passwords%3F\"><h3>Does IvoryGate store Windows passwords?<\/h3><\/dt>\n<dd><p>No. IIS performs Windows Authentication. IvoryGate never receives or stores the Windows password, PIN, Microsoft token, or incoming WordPress authentication cookie.<\/p><\/dd>\n<dt id=\"does%20it%20create%20wordpress%20users%3F\"><h3>Does it create WordPress users?<\/h3><\/dt>\n<dd><p>No. Every Windows identity must be explicitly mapped to one existing WordPress user ID.<\/p><\/dd>\n<dt id=\"why%20does%20the%20browser%20show%20a%20system%20credentials%20dialog%3F\"><h3>Why does the browser show a system credentials dialog?<\/h3><\/dt>\n<dd><p>IIS sends an authentication challenge before PHP and WordPress run. Browser policy, intranet-zone configuration, the Windows session, domain configuration, and Kerberos or NTLM availability determine whether authentication is automatic or a credentials dialog appears.<\/p><\/dd>\n<dt id=\"can%20ivorygate%20detect%20incognito%20or%20private%20browsing%3F\"><h3>Can IvoryGate detect incognito or private browsing?<\/h3><\/dt>\n<dd><p>No. Browsers do not provide a reliable server-side signal for private browsing. Browser or organization policy must control private browsing when that is required.<\/p><\/dd>\n<dt id=\"what%20happens%20to%20the%20normal%20wordpress%20login%20form%3F\"><h3>What happens to the normal WordPress login form?<\/h3><\/dt>\n<dd><p>When SSO is enabled, IvoryGate returns HTTP 403 instead of displaying password-based WordPress login to an unauthenticated user. It also blocks password authentication and application passwords. The emergency constant restores native login for recovery.<\/p><\/dd>\n<dt id=\"what%20happens%20when%20sso%20is%20disabled%3F\"><h3>What happens when SSO is disabled?<\/h3><\/dt>\n<dd><p>WordPress authentication behaves normally. IvoryGate does not issue an SSO cookie or block password login.<\/p><\/dd>\n<dt id=\"does%20ivorygate%20support%20multisite%3F\"><h3>Does IvoryGate support Multisite?<\/h3><\/dt>\n<dd><p>No. SSO is blocked on WordPress Multisite.<\/p><\/dd>\n<dt id=\"does%20ivorygate%20send%20data%20to%20external%20services%3F\"><h3>Does IvoryGate send data to external services?<\/h3><\/dt>\n<dd><p>No. The plugin makes no external network requests and has no telemetry.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>0.1.2<\/h4>\n\n<ul>\n<li>Added the verified WordPress.org owner to Contributors.<\/li>\n<li>Sanitized nonce, settings, query, and server request values before use.<\/li>\n<\/ul>\n\n<h4>0.1.1<\/h4>\n\n<ul>\n<li>Added SSO-only mode when Windows SSO is enabled.<\/li>\n<li>Blocked the WordPress password form, password authentication, and application passwords while SSO is enabled.<\/li>\n<li>Added a clear HTTP 403 message when IIS admits a request but IvoryGate cannot complete SSO.<\/li>\n<li>Retained the emergency constant that restores native WordPress login.<\/li>\n<li>Added WordPress.org metadata and documentation.<\/li>\n<li>Corrected request-value sanitization and displayed version metadata.<\/li>\n<\/ul>\n\n<h4>0.1.0<\/h4>\n\n<ul>\n<li>Initial stable release.<\/li>\n<li>Added exact IIS Windows identity mapping to existing WordPress accounts.<\/li>\n<li>Added HTTPS-only automatic SSO and secure WordPress session creation.<\/li>\n<li>Added administrator diagnostics and fixed-code system logging.<\/li>\n<\/ul>","raw_excerpt":"Passwordless WordPress sign-in using trusted IIS Windows Authentication and explicit identity-to-user mappings.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/374481","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=374481"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/sebaklim93411"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=374481"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=374481"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=374481"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=374481"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=374481"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=374481"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}