Microsoft Entra ID SSO Login
This module lets people log into a website using their Microsoft account.
A visitor without an account could take over any user account on the website. They could log in as a site administrator without needing a password or access to an email address. This would let them see private information and change anything on the site.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youAny site using this module.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this critical. Cyber Essentials expects a fix within 14 days. Do it this week.
Tell your developerUpdate Microsoft Entra ID SSO Login to 1.0.4.
For developers: what the fix changed
The fix is intended to validate API responses from Microsoft (specifically using ID token claims instead of unverified Graph API profile emails) to prevent account takeover, but the actual code changes for this validation (likely in SocialAuthEntraIdController.php) are missing from the provided diff.
The fix is not clearly separable from the other changes in this release, so treat the summary above as a pointer rather than a finding.
Also in this release The release added account type support, updated the settings form with security options to block user 1 and admin roles, added a license to the font-awesome library, and updated documentation.
.cspell.json+33 −0README.md+270 −1config/install/social_auth_entra_id.settings.yml+3 −0config/schema/social_auth_entra_id.schema.yml+19 −0social_auth_entra_id.info.yml+1 −1social_auth_entra_id.libraries.yml+4 −0social_auth_entra_id.routing.yml+6 −0src/Controller/SocialAuthEntraIdController.php+0 −0src/Form/SocialAuthEntraIdSettingsForm.php+164 −23src/Plugin/Block/EntraIdLoginBlockBlock.php+84 −9