Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Drupal 10.6.17 Update released for Drupal core (10.6.17)! Release: Drupal 11.3.17 Update released for Drupal core (11.3.17)! Release: Drupal 11.4.7 Update released for Drupal core (11.4.7)! Release: Radix 6.0.9 Minor update available for theme radix (6.0.9). Release: Configuration Inspector 2.1.12 Minor update available for module config_inspector (2.1.12). Release: AI (Artificial Intelligence) 1.5.0-rc4 New release candidate for module ai (1.5.0-rc4). Release: Native Observability 2.0.0 Major update available for module native_observability (2.0.0). Release: Seeds Widgets 2.5.4 Minor update available for module seeds_widgets (2.5.4). Usage Milestone: Schemata Module schemata crossed 1,000 active installs. Module Revived: Commerce Variation Add-on 3.0.3 Module commerce_vado updated after 18 months of inactivity (3.0.3).

This module allows users to log into your Drupal site using Microsoft Azure Active Directory credentials. It can optionally enrich user profiles with data from the Graph API, map Azure AD groups to Drupal roles, and provide single sign-out functionality.

OpenID Connect client / plugin for Microsoft Azure Active Directory authentication

This module is a Microsoft Azure Active Directory client for OpenID Connect.

Microsoft Azure AD connection can be achieved by using the Generic client in OpenID Connect. The OpenID Connect Microsoft Azure AD client basically does the same thing, but adds some powerful Azure AD specific settings, which can be found below.

Graph API to enrich the user data

An option is added to the settings page that enables the use of the Graph API instead of the Open ID Connect userinfo endpoint. It brings more fields of the user profile. There is also an option to use another property for email address (when using Graph). Finally, it is optional to to update existing user's email address in case another email address property is used.

Map user's AD groups to Drupal roles

Enable this to configure Drupal user role assignment based on AD group membership.

Single sign out

Checking this option will enable Single Sign Out to occur so long as the logout url has been set to (http(s)://yoursite.com/openid-connect/windows_aad/signout) in your Azure AD registered app settings. If a user logs out of the Drupal app then they will be logged out of their SSO session elsewhere as well. Conversely if a user signs out of their SSO account elsewhere, such as Office 365, they will also be logged out of this app.

Missing email address not blocking

This module will check if an email address is part of the UserInfo data. In case no email is there, it will still create the user, but use the username instead, providing a notice to prompt the user to change it in his/her user settings. This message to the user is optional.

Integration with Key module

Integration with the Key module, so safe storage of sensitive data, in our case the client secret, is provided.

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

1 tracked project depends on this one

Activity

Tracked releases
3
Tracked since
Nov 2024
Latest release
6 months ago
Releases (12 mo)
1 ▼ from 2
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
2.0.0-beta10 Pre-release 9–11 Mar 11, 2026
2.0.0-beta9 Pre-release 9–11 Feb 28, 2025
2.0.0-beta8 Pre-release 9–10 Nov 11, 2024