Skip to main content
drupalreleases
Release: Cms 2.2.3 — Update released for Drupal core (2.2.3)! Release: Libraries API 4.2.1 — Minor update available for module libraries (4.2.1). Release: Menu Link Attributes 8.x-1.10 — Minor update available for module menu_link_attributes (8.x-1.10). Release: Menu Link Attributes 8.x-1.9 — Minor update available for module menu_link_attributes (8.x-1.9). Release: Taxonomy Menu 8.x-3.9 — Minor update available for module taxonomy_menu (8.x-3.9). Release: Menu Item Extras 3.2.0 — Minor update available for module menu_item_extras (3.2.0). Release: Layout Paragraphs 2.1.4 — Minor update available for module layout_paragraphs (2.1.4). Release: PhotoSwipe - Responsive JavaScript Modal Image Gallery 5.0.11 — Minor update available for module photoswipe (5.0.11). Module Revived: Libraries API 4.2.0 — Module libraries updated after 11 months of inactivity (4.2.0). Security Coverage: Component Library — Module component_library now has official Drupal security advisory coverage.

SAML Authentication Restrict to OU

217 sites No security coverage Drupal 10–11

Part of the Samlauth ecosystem · 4 projects

View on drupal.org

This module enhances SAML Authentication by restricting site access based on Organizational Unit (OU) attributes provided by your Identity Provider. It's ideal for large organizations, allowing administrators to control access based on Active Directory groups without managing individual Drupal roles. The module supports parsing complex Distinguished Names, offers strict (AND) or flexible (OR) OU matching, and allows customization of the access denied message.

SAML Authentication Restrict to OU provides a security layer for the SAML Authentication module by restricting site access based on Organizational Unit (OU) attributes sent by the Identity Provider (IdP).

This module is specifically designed for Enterprise environments using Active Directory, allowing administrators to limit site access to specific departments or groups within a large organization without the overhead of managing individual Drupal roles for every user.

Features

  • Restrict Login Toggle: A master switch that allows you to enable or disable the restriction logic globally without losing your settings.
  • Distinguished Name (DN) Parsing: Automatically extracts multiple OU values from complex DN strings commonly sent by Active Directory (e.g., CN=user,OU=Marketing,OU=Users...).
  • Strict Mode: Optionally require that a user belongs to all listed OUs rather than just one (AND vs OR logic).
  • Customizable Access Denied Message: Control the exact message shown to rejected users, with support for basic HTML markup to ensure visibility.

Requirements

This module requires the SAML Authentication module.

Installation

Install as you would normally install a contributed Drupal module. For further information, see Installing Drupal Modules.

Configuration

The configuration form is located at:

/admin/config/people/saml-restrict

From the configuration form you can:

  • Restrict Login to OUs: Enable the master toggle to begin enforcing restrictions.
  • SAML Attribute Name: Set this to the attribute containing your OU data. In most AD setups, this is dn.
  • Allowed OUs: Enter the names of authorized OUs, one per line (e.g., Staff, Faculty, Marketing). This check is case-insensitive to ensure reliable matching across directory updates. Do not include "ou=" prefixes.
  • Strict Mode: Check this if a user must be a member of every OU listed to gain access.
  • Access Denied Message: Customize the message displayed to users who are rejected. Basic HTML is supported.

Depends on

Dependencies of the latest stable release

Required by

Tracked projects that depend on this one

No tracked projects depend on this one yet.

Activity

Tracked releases
7
Tracked since
Apr 2026
Latest release
5 months ago
Releases (12 mo)
7 ▲ from 0
Maintenance
Slowing

Release Timeline

Releases

Version Type Core Release date
1.0.5 Stable 10–11 Apr 10, 2026
1.0.4 Stable 10–11 Apr 10, 2026
1.0.3 Stable 10–11 Apr 10, 2026
1.0.2 Stable 10–11 Apr 10, 2026
1.x-dev Dev 10–11 Apr 10, 2026
1.0.1 Stable 10–11 Apr 10, 2026
1.0.0 Stable 10–11 Apr 10, 2026