=== WPO365 | SEAMLESS WORDPRESS + MICROSOFT INTEGRATION (WPO365 | LOGIN) ===
Contributors: wpo365
Tags: Microsoft, SSO, PowerBI, SharePoint, Email
Requires at least: 5.0
Tested up to: 7.1
Stable tag: 44.0
Requires PHP: 7.4
License: GPLv2 or later
License URI: https://www.gnu.org/licenses/gpl-2.0.html

Seamless Microsoft Entra | Ext. ID | B2C | M365 Integration for WordPress. For SSO, Mail, Roles, Access, Sync, Copilot, SharePoint, PowerBI.

== Description ==

Seamless Microsoft Entra | Ext. ID | B2C | M365 Integration for WordPress. For SSO, Mail, Roles, Access, Sync, Copilot, SharePoint, PowerBI.

= SINGLE SIGN-ON (SSO) =

- Enable Microsoft based Single Sign-on [more](https://www.wpo365.com/feature/single-sign-on/)
- Supported Identity Providers (IdPs): **Azure Active Directory**, **Azure AD B2C**, **Entra External ID (Azure AD for Customers)** [more](https://docs.wpo365.com/article/158-select-identity-provider-idp)
- Supported SSO protocols: **OpenID Connect** and **SAML 2.0** [more](https://docs.wpo365.com/article/159-select-sso-protocol)
- Supported OpenID Connect User Flows: Authorization Code User Flow (recommended) and Hybrid User Flow [more](https://docs.wpo365.com/article/156-why-the-authorization-code-user-flow-is-now-recommended)

= NEW USERS =

- New users that sign in with Microsoft automatically become WordPress users [more](https://www.wpo365.com/feature/single-sign-on/)

= INTRANET =

- Configure the **intranet** authentication mode to restrict access to all front-end posts and pages [more](https://www.wpo365.com/article/building-a-wordpress-based-intranet-restrict-access/)
- Hide the  **WordPress Admin Bar** for specific roles [more](https://docs.wpo365.com/article/150-hide-wp-admin-bar-for-roles)

= MAIL =

- **Send emails using Microsoft Graph** instead of SMTP from your WordPress website [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Choose between delegated (send mail as a user) and application-level (send mail as any user) type permissions.
- Or: Select either a Microsoft 365 account or a personal Microsoft account, like Hotmail.com or Outlook.com, to send WordPress emails.
- Or: Configure [RBAC for Exchange Online](https://learn.microsoft.com/en-us/Exchange/permissions-exo/application-rbac) and authorize as an application but with a limited scope e.g. one specific mailbox.
- Send as **HTML**
- Save to the **Sent Items** folder
- Support for **file attachments**
- Daily refresh of Microsoft Graph access and refresh token
- Auto-flagging and suppression of duplicate emails
- Auto-retry when throttled (HTTP 429)

= SCIM =

- Entra **User Provisioning** (SCIM) [more](https://www.wpo365.com/feature/azure-ad-user-provisioning-scim/)
- **Create** new WP Users

= MICROSOFT TEAMS =

- Support for (seamless) integration of your WordPress website into a **Microsoft Teams** Tabs and Apps [more](https://www.wpo365.com/feature/microsoft-teams/)

= POWER BI =

- Embed Microsoft **Power BI** content (user owns data) [more](https://www.wpo365.com/feature/power-bi-embed/)

= SHAREPOINT =

- Embed a **SharePoint Online** library [more](https://www.wpo365.com/feature/sharepoint-onedrive-library/)
- Embed a **SharePoint Online** list [more](https://www.wpo365.com/feature/sharepoint-list/)
- Embed an **Outlook / Exchange** calendar [more](https://www.wpo365.com/feature/outlook-exchange-calendar/)
- Embed a **SharePoint Online** search [more](https://www.wpo365.com/feature/sharepoint-search/)

= EMPLOYEE DIRECTORY =

- Embed an intuitve Azure AD / Microsoft Graph based **Employee Directory** into a front-end post or page [more](https://www.wpo365.com/feature/employee-directory/)

= WPO365 INSIGHTS =

- **See what matters, when it happens** Track key WPO365 events like logins, sent emails and user creation and updates with WPO365 Insights [more](https://docs.wpo365.com/article/210-wpo365-insights)

= WORDPRESS MULTISITE =

- Support for **WordPress Multisite** [more](https://www.wpo365.com/feature/wordpress-multisite/)

= REST API ENDPOINT PROTECTION =

- Protect your **WordPress REST API** endpoints with a combination of a WordPress cookie and a nonce for delegated access [more](https://docs.wpo365.com/article/151-wordpress-cookies-based-protection-for-the-wordpress-rest-api)

= DEVELOPERS =

- Developers can now connect to a RESTful API for Microsoft Graph in their favorite programming language and without the hassle of authentication and authorization [more](https://docs.wpo365.com/article/129-a-restful-proxy-to-microsoft-graph-inside-wordpress)
- *PHP hooks* for developers to build custom Microsoft Graph / Office 365 integrations [more](https://docs.wpo365.com/article/82-developer-hooks)

https://youtu.be/S9tiASl1nH0

**ADD FUNCTIONALITY WITH PREMIUM EXTENSIONS**

Features below can be unlocked with [premium WPO365 plugins](https://www.wpo365.com/pricing/).

= SINGLE SIGN-ON (SSO) =

- **Hide the WordPress login page** "/wp-login.php" and replace with a fully customizable login / logged-out page. [more](https://www.wpo365.com/feature/configure-a-custom-login-page-and-hide-wp-login-php/)

= SYNC =

- Full **User Sync** using MS Graph from Entra to WordPress [more](https://www.wpo365.com/feature/user-synchronization/)
- **Create** new WP Users
- **Update** existing WP Users
- (Soft) **Delete** existing WP Users
- Lookup / Add a user in Entra ID (Azure Active Directory) on WordPress's built-in **Add New User page**. [more](https://docs.wpo365.com/article/228-add-new-wordpress-user-from-entra-aad)

*WP User Roles, Profiles and Avatars will be updated and other rules e.g. LearnDash Enrollments will be applied*

= SCIM =

- Integrate with Entra **User Provisioning** (SCIM) [more](https://www.wpo365.com/feature/azure-ad-user-provisioning-scim/)
- **Create** new WP Users
- **Update** existing WP Users
- (Soft) **Delete** existing WP Users
- **Map User Attributes** beyond name and email and store as WordPress user meta

*WP User Roles, Profiles and Avatars will be updated and other rules e.g. LearnDash Enrollments will be applied*

= INTRANET =

- Block Direct Access to the Media Library [more](https://docs.wpo365.com/article/229-require-login-for-the-wordpress-media-folder)

= ROLES + ACCESS =

- Assign WordPress roles by Entra Groups, Entra User Attributes, Domains and / or App Roles [more](https://www.wpo365.com/feature/roles-access/)
- Restrict access to site / pages by Entra Groups, Domains and / or WPO365 Audiences [more](https://www.wpo365.com/feature/roles-access/)
- Redirect after login by Entra Groups and / or Domains [more](https://www.wpo365.com/feature/roles-access/)

= COPILOT =

- Copilot Rewrite will help authors to generate improved versions of their content without leaving WordPress [more](https://www.wpo365.com/feature/copilot-rewrite-for-wordpress/)
- Use Copilot Chat for WordPress and embed directly in your WordPress intranet or extranet [more](https://www.wpo365.com/feature/copilot-chat-for-wordpress/)

= LEARNDASH =

- Auto-Enroll WP Users in LearnDash Courses and Groups by Entra Groups, Domains and / or Defaults [more](https://www.wpo365.com/feature/learndash/)

= CUSTOM USER FIELDS =
- Enhance WordPress / BuddyPress User Profiles with **Entra User Attributes** [more](https://www.wpo365.com/feature/custom-user-fields/)

= MAIL =

- Auto-retry to deliver emails that failed to send [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Send attachments larger than 3MB  [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Send as / On behalf [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Send from a Shared Mailbox [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Send from alias addresses [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Enable Staging Mode [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Mail Throttle [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Send as BCC [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)
- Default Reply-To [more](https://www.wpo365.com/feature/send-mail-using-ms-graph/)

= MICROSOFT 365 APPS =

- Power BI [more](https://www.wpo365.com/feature/power-bi-embed/)
- SharePoint Library [more](https://www.wpo365.com/feature/sharepoint-onedrive-library/)
- SharePoint List [more](https://www.wpo365.com/feature/sharepoint-list/)
- SharePoint Search [more](https://www.wpo365.com/feature/sharepoint-search/)
- Exchange Calendar [more](https://www.wpo365.com/feature/outlook-exchange-calendar/)
- Viva Engage [more](https://www.wpo365.com/feature/yammer-for-wordpress/)
- Employee Directory [more](https://www.wpo365.com/feature/employee-directory/)

= ADVANCED LOGIN OPTIONS =

- Support for Multitenancy [more](https://www.wpo365.com/feature/advanced-login-options/)
- Support for multiple IdPs [more](https://www.wpo365.com/feature/multiple-identity-providers/)
- Force SSO [more](https://www.wpo365.com/feature/advanced-login-options/)
- Dual Login [more](https://www.wpo365.com/feature/advanced-login-options/)
- Intercept manual login [more](https://www.wpo365.com/feature/advanced-login-options/)
- Prevent pwd. / email change [more](https://www.wpo365.com/feature/advanced-login-options/)
- Single Sign-out [more](https://www.wpo365.com/feature/advanced-login-options/)
- Sign out of M365 [more](https://www.wpo365.com/feature/advanced-login-options/)
- Custom login URL [more](https://www.wpo365.com/feature/advanced-login-options/)
- Custom loading template [more](https://www.wpo365.com/feature/advanced-login-options/)
- B2C custom domain [more](https://www.wpo365.com/feature/advanced-login-options/)
- Embedded B2C login [more](https://www.wpo365.com/feature/advanced-login-options/)
- Custom new User email [more](https://www.wpo365.com/feature/advanced-login-options/)

= WPO365 INSIGHTS =

- Get **WPO365 Alerts** in your inbox when a critical WPO365 event occurs [more](https://docs.wpo365.com/article/210-wpo365-insights)

= AVATAR =

- M365 Profile Picture as WordPress / BuddyPress Avatar [more](https://www.wpo365.com/feature/avatar/)

= REST API ENDPOINT PROTECTION =

- Enable **Azure AD** based protection for your **WordPress REST API** endpoints [more](https://docs.wpo365.com/article/147-azure-ad-based-protection-for-the-wordpress-rest-api)

= CONFIGURATION =

- Save multiple configurations
- Directly edit (the JSON representation of) a configuration

== Prerequisites ==

- Make sure that you have disabled caching for your Website, especially when you configure a WordPress based intranet and access to WP Admin and all pubished pages and posts requires authentication. With caching enabled, the plugin may not work as expected
- We have tested our plugin with Wordpress >= 5 and PHP >= 7.4
- You need to Entra ID Tenant Administrator to configure both Azure Active Directory and the plugin
- When configuring a WordPress based intranet, you should consider restricting access to the otherwise publicly available wp-content directory [more](https://docs.wpo365.com/article/36-authentication-scenario)

== Support ==

We will go to great length trying to support you if the plugin doesn't work as expected. Go to our [Support Page](https://www.wpo365.com/how-to-get-support/) to get in touch with us. We haven't been able to test our plugin in all endless possible Wordpress configurations and versions so we are keen to hear from you and happy to learn!

== Feedback ==

We are keen to hear from you so share your feedback with us and contact us using the [contact form](https://www.wpo365.com/contact/) on our website!

== Open Source ==

When you’re a developer and interested in the code you should have a look at our repo over at [WordPress](http://plugins.svn.wordpress.org/wpo365-login/).

== Installation ==

Please check out [our Getting Started page](https://docs.wpo365.com/category/21-getting-started) for detailed installation and configuration instructions.

== Frequently Asked Questions ==

Please check out [our online FAQs](https://docs.wpo365.com/category/26-support) for answers to commonly asked questions.

== Screenshots ==
1. Microsoft Entra ID based Single Sign-on (SSO).
2. Hide WordPress Login and custom login route / page.
3. Support for Azure AD B2C / Entra External ID.
4. Send WordPress emails using Microsoft Graph.
5. Co-pilot Rewrite for WordPress (block editor).
6. Synchronize users from Entra ID to WordPress.
7. WP role assignment and access rules for Entra ID groups.
8. Apps to embed Microsoft 365 services in WordPress.
9. Embed Power BI for WordPress (configuration).
10. Embed Power BI content in WordPress.
11. Embed SharePoint Library in WordPress.
12. Embed Outlook / Exchange calendar in WordPress (date picker).
13. Embed Outlook / Exchange calendar in WordPress (list view).


== Upgrade Notice ==

Please check the [online change log](https://www.wpo365.com/change-log/) for upgrade notices.

== Changelog ==

Also available [online](https://www.wpo365.com/change-log/).

= v44.0 =

* Support for WordPress 7.1. [ALL]
* Feature: Use **Copilot Rewrite** - a block-editor sidebar tool - to rewrite selected content blocks (paragraphs, headings, lists, quotes, code, and more) with AI assistance, including support for personal and organization-wide rewrite instructions. [ESSENTIALS, PROFESSIONAL, INTEGRATE (LOGIN+, SYNC, INTRANET)] [Read more](https://www.wpo365.com/feature/copilot-rewrite-for-wordpress/)
* Feature: **Copilot Chat** is a new app that lets visitors have an AI-powered conversation grounded in your organization's Microsoft 365 / SharePoint content, embeddable anywhere on your WordPress site - with conversation export, retry-on-failure, source attributions, and custom styling support. [APPS, INTEGRATE (INTRANET)] [Read more](https://www.wpo365.com/feature/copilot-chat-for-wordpress/)
* Feature: Enable a fully customizable **WordPress Login Page** at https://{your website}/wpo/Login and optionally hide the classic WordPress page "/wp-login.php", with an option to hide the username / password form, custom branding, layout (single or split-column), colors, logo, custom title / description text, and translatable labels. [ESSENTIALS, PROFESSIONAL, INTEGRATE (LOGIN+, SYNC, INTRANET)] [Read more](https://www.wpo365.com/feature/configure-a-custom-login-page-and-hide-wp-login-php/)
* Feature: Added a matching custom **"Logged Out" page** ('/wpo/loggedout') that can be used as the default landing page after sign-out or an SSO sign-in error, without needing a separately configured error page. [ESSENTIALS, PROFESSIONAL, INTEGRATE (LOGIN+, SYNC, INTRANET)]
* Improvement: A fully redesigned, more compact calendar list layout with a day-badge, and a combined start/end time column. Events that span multiple days or last all day are now displayed more clearly, showing correct start / end dates and an "All day event" label instead of confusing time ranges. [LOGIN, APPS, INTEGRATE (INTRANET)] [Updated screenshots](https://www.wpo365.com/feature/add-outlook-or-exchange-calendars-to-wordpress/)
* Improvement: The plugin will now - on a daily base - automatically refresh the Microsoft Graph mail connection's access and refresh token, so outgoing mail no longer risks failing due to a long-expired token after periods of low activity. [LOGIN, MAILER] Consult the update [tutorial](https://tutorials.wpo365.com/courses/email-configure-microsoft-graph-mailer/lessons/update-wpo365-authorize-connect-to-microsoft-graph/)
* Improvement: Added automatic detection and suppression of duplicate outgoing emails sent within a short time window. [LOGIN, MAILER] [Read more](https://tutorials.wpo365.com/courses/email-configure-microsoft-graph-mailer/lessons/improve-the-reliability-of-sending-wordpress-emails/)
* Improvement: The existing "obfuscate Entra ID options" switch - that will delete sensitive Entra ID settings from the database once they're defined in 'wp-config.php' when toggled on - is now capable of automatically restoring those settings if switched off again. [ANY PREMIUM] [Read more](https://tutorials.wpo365.com/courses/wp-config-php-single-identity-provider-idp/lessons/delete-sensitive-entra-id-options-from-the-database/)
* Improvement: Added an optimized mobile layout option (portrait or landscape) for embedded Power BI reports on narrow screens. [APPS, INTEGRATE (INTRANET)]
* Improvement: The "Sign in with Microsoft" button - when multiple identity providers are configured - now highlights the identity-provider dropdown in red if you try to sign in without picking one, instead of just leaving the button disabled with no explanation. [LOGIN]
* Improvement: The "block direct Media Folder access" feature now (again) support a "Secure Download Mode" for Litespeed servers (requires additional server-configuration - consult online documentation). [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMER (LOGIN+, SYNC, INTRANET)]
* Improvement: Added "Default LD assignment scope" as an additional option to configure default LearnDash course and group assignments, so you can control whether those assignments should be applied to new users only, instead of always being applied to all users. [ROLES + ACCESS, PROFESSIONAL, INTEGRATE, CUSTOMERS (SYNC, INTRANET)] [Read more](https://docs.wpo365.com/article/184-learndash-integration)
* Improvement: The plugin's built-in "Send WordPress emails using Microsoft Graph" feature nows honor a "Retry-After" header - when Microsoft Graph throttles a request - with a short automatic retry, instead of failing immediately. [LOGIN, MAILER]
* Improvement: If you have configured multiple Identity Providers, you can now configure the "Allow users from other tenants" setting individually for each identity provider in wp-config.php. [LOGIN]
* Fix: Tested for compatibility with multilingual plugins that add language-specific URL paths, such as "/en" and "/nl". [LOGIN]
* Fix: The start / end date and time of Calendar app events are now correctly translated to the user's timezone. [LOGIN, APPS, INTEGRATE (INTRANET)]
* Fix: The "Access Denied" message shown to users blocked for not belonging to a required group has been corrected to a more accurate, specific message. [ROLES + ACCESS, PROFESSIONAL, INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
* Fix: The wizard no longer shows a misleading "invalid secret" warning for a masked secret field when Entra ID options have been obfuscated. [ANY PREMIUM]
* Fix: Identified a bug where selecting a specific identity provider from a multi-tenant sign-in dropdown when "Use client-side redirect" has been selected, would drop the selected Identity Provider, incorrectly falling back to the default identity provider. [LOGIN]
* Fix: On a WordPress Multisite installation, the "block direct Media Folder access" feature would generate a download-authorization cookie for one network site and replay it when connected to another network site. Now the service includes a host check, when validating the cookie. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMER (LOGIN+, SYNC, INTRANET)]
* Fix: A new installation of the WPO365 | LOGIN plugin will no longer produce an initial "List of pages freed from authentication" with absolute URLs but with site relative paths instead - to prevent a WPO365 Health Message from showing up. [LOGIN]
* Fix: The SSO bypass cookie (set by the plugin when SSO for the login page is enabled and the correct secret has been added to the login page URL) was being cleared immediately after being set under certain circumstances, preventing the bypass from working beyond the first page load. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
* Fix: If you have configured multiple Identity Providers, the plugin can now refresh access tokens for users who signed in using a non-default Identity Provider. [LOGIN]
* This release updates the version numbers of all premium plugins to 44.0 to align with the core plugin WPO365 | LOGIN.

= v43.4 =
* Fix: Fixed an issue on WordPress Multisite installations where content embedded from another site could fail to render when WPO365 Audiences was enabled. [ROLES + ACCESS, PROFESSIONAL, CUSTOMERS, INTEGRATE (SYNC, INTRANET)]
* Fix: Fixed an issue where a double forward slash inside a query string value (e.g. "https://" within a redirect_to parameter) could be incorrectly collapsed to a single slash while the plugin sanitized the current request URL, which could prevent users from signing in successfully. [LOGIN, MAILER]

= v43.3 =
* Security Fix: Strengthened verification of certain AJAX requests to help prevent unauthorized changes to plugin settings. [ALL]

= v43.2 =
* Fix: Fixed an issue that prevented externally triggered WPO365 User Synchronization jobs from starting via the public "?wpo365_sync_run" endpoint. [INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
* Fix: Removed support for the LiteSpeed-specific "Secure Download Mode" that relied on the X-LiteSpeed-Location header due to technical issues. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
* Fix: Added no-cache headers to responses generated by the custom endpoint that initiates single sign-on, helping prevent client-side caching issues that could result in "nonce not found" exceptions. [LOGIN]

= v43.1 =
* Fix: Fixed an issue that could prevent anonymous AJAX requests (admin-ajax.php) from working correctly on WordPress sites that configured WPO365 Intranet Mode. [LOGIN]
* Fix: Administrators are now allowed to exclude site-relative paths that start with "/wp-admin". [LOGIN]

= v43.0 =
* BREAKING CHANGE: To address multiple vulnerabilities that could allow attackers to bypass WPO365 Intranet Mode, entries in the "Pages freed from authentication" list are now interpreted as server-relative paths. All entries must start with a forward slash (/) and are matched against the beginning of the requested URI path. Consult [this article](https://www.wpo365.com/article/strengthening-intranet-mode-security-important-changes-to-url-matching/) for details. [LOGIN, MAILER]
* This release updates the version numbers of all premium plugins to 43.0 to align with the core plugin WPO365 | LOGIN. No functional changes were made to the premium plugins.

= v42.11 =
* Change: The plugin will no longer redirect AJAX and REST request to Microsoft but instead return a 401 Unauthorized message and terminate the connection. [LOGIN]
* Improvement: A new hand-off mode can now be configured for protected Media Library downloads, helping improve performance and the delivery of large files. See [updated documentation](https://docs.wpo365.com/article/229-require-login-for-the-wordpress-media-folder) for details. [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTRANET)]
* Fix: Fixed Teams silent authentication, which could fail when an internal redirect to the custom SSO endpoint interrupted the authentication response. [LOGIN]
* Fix: The SCIM manager attribute is now returned as a complex object, in line with Entra ID expectations, to prevent provisioning errors. [SCIM, INTEGRATE, (INTRANET)]
* Fix: Manager IDs received from Entra ID are now stored as user meta (with key "wpo365_manager_id"). When enabled, the user profile displays a link to view the corresponding WordPress manager. [SCIM, INTEGRATE (SYCN, INTRANET)]
* Fix: the SCIM userName property's value is now sourced from Entra ID’s userPrincipalName (by default always stored as user meta with key "userPrincipalName"), replacing the WordPress username - used previously - to prevent mismatches and provisioning errors. [SCIM, INTEGRATE (INTRANET)]
* Fix: Users deactivated in Entra ID and synchronized as inactive in WordPress are now correctly reactivated in WordPress when re-enabled in Entra ID. [SCIM, INTEGRATE (INTRANET)]
* Fix: WPO365 Insights will now correctly log all updated user attributes when more than one is patched by the integration with Microsoft Entra ID's Application Provisioning Service. [SCIM, INTEGRATE (INTRANET)]
* Fix: A reactivation button is now correctly displayed on the WordPress "Users" page when a user is deactivated and Entra ID Application Provisioning integration is enabled. [SCIM, INTEGRATE (INTRANET)]
* Fix: The identity provider dropdown on the login page now consistently displays the default placeholder text when multiple providers are configured. [LOGIN]
* Fix: Fixed broken and outdated links in the plugin wizard. [LOGIN, MAILER]

= v42.10 =
* Fix: Updated phpseclib to version 3.0.52 (was 3.0.43), which patches [CVE-2026-44167](https://app.opencve.io/cve/CVE-2026-44167). [LOGIN, MAILER]
* Fix: Resolved an issue where WordPress 7 styles forced showing an unwanted border on the Toast element (for displaying embed-app errors) [LOGIN, APPS, INTEGRATE (INTRANET)]

= v42.9 =
* Fix: Fixed an issue where incorrect URL encoding caused query string parameters to be lost when redirecting users to their originally requested page. [LOGIN]
* Fix: The plugin will now load modern JavaScript modules correctly on a subdomain-based WordPress Multisite installation, to avoid CORS related issues. [LOGIN]

= v42.8 =
* Fix: Improved the interim-login experience when a WordPress session expires. The plugin now detects this scenario earlier and ensures the “Session expired” prompt is shown. [LOGIN]

= v42.7 =
* Fix: Resolved an issue that prevented the plugin from forcing Single Sign-on for the login page when a custom authentication scenario WPO_AUTH_SCENARIO has been defined (in wp-config.php). [LOGIN]

= v42.6 =
* Fix: Resolved an issue that prevented the plugin for redirecting the user back to the URL they intended to navigate to, before WPO365 initialized SSO and sent the user to Microsoft to authenticate. [LOGIN]

= v42.5 =
* Fix: Resolved an issue that prevented Single Sign-On from starting when a custom authentication scenario WPO_AUTH_SCENARIO was defined (in wp-config.php) in combination with using client-side redirection to Microsoft (see option "Use client-side redirect on the plugin's "Login / logout" configuration page). [LOGIN]

= v42.4 =
* Fix: Resolved an issue that could prevent Single Sign-On from starting when the request URL was altered by plugins, reverse proxies, or subdirectory setups. [LOGIN]

= v42.3 =
* Fix: Resolved an issue that prevented Single Sign-On from starting when a custom authentication scenario WPO_AUTH_SCENARIO was defined (in wp-config.php). [LOGIN]

= v42.2 =
* Fix: To maintain compatibility with legacy premium Power BI embed-app configurations, the plugin now automatically converts specific string values into arrays when processing manually edited Token Request JSON. [LOGIN]
* Fix: The body of the email sent when an (OpenID Connect) Application (Client) Secret is about to expire now includes the blog's name. [LOGIN]

= v42.1 =
* Improvement: Redirection to Microsoft for SSO now consistently routes through the plugin’s custom endpoint **/wpo/sso/start**. This allows administrators to **exclude a single endpoint from caching**, ensuring reliable nonce verification and preventing cache-related errors such as “Your login has been tampered with”. Read this [article](https://www.wpo365.com/news/improved-reliability-and-security-for-single-sign-on-sso/) to get a better understanding. [LOGIN, MAILER, ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTRANET)]
* Fix: Dynamic tokens such as "wp_user_email" in a custom Power BI token request JSON are once again properly resolved to their corresponding values. [APPS, INTEGRATE (INTRANET)]
* Fix: Translation for the “Your login has been tampered with” error is now correctly resolved. [LOGIN, MAILER]

= v42.0 =
* Change: To improve and streamline the Microsoft Single Sign-On flow, authentication is now consistently initiated via the **/wpo/sso/start** endpoint (or **?wpo_sso_start=1** without permalinks), and all login buttons have been updated accordingly. See the [updated online documentation](https://www.wpo365.com/news/simplified-microsoft-single-sign-on/) for details. [LOGIN, MS GRAPH MAILER]
* Improvement: You can now send emails from **alias addresses** when using Microsoft Graph, enabling more tailored and professional communication. Consult the [online documentation](https://docs.wpo365.com/article/231-send-from-an-alias-email-address) for details. [MAIL, PROFESSIONAL, INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
* Improvement: New you can configure the **SharePoint Library (premium) embed-app** to hide folders and enforce file downloads (instead of opening files in Microsoft 365). [APPS, INTEGRATE (INTRANET)]
* Improvement: Completely refactored the **WPO365 User Synchronization** feature for improved reliability e.g. to eliminate caching issues with expired next-links and enhance logging for better diagnostics. [INTEGRATE (SYNC, INTRANET)]
* Improvement: Users of the new automated embed-app configurator can now duplicate apps - allowing them to effectively create an embed-app template. [LOGIN, APPS, INTEGRATE (INTRANET)]
* Fix: **Nonce** handling has been enhanced to prevent caching issues and ensure more secure authentication requests. [LOGIN, MS GRAPH MAILER]
* Fix: Enhanced **Microsoft Teams** experience by updating to the latest Microsoft Teams JavaScript SDK. Also refactored existing support for embedded WordPress running in an iframe. [LOGIN]
* Fix: **Media Folder protection** now supports query string variables for greater flexibility. Administrators using Apache should reinitialize the feature to apply the required .htaccess updates. [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (SYNC, INTRANET)]
* Fix: Resolved a race condition in the automated embed-app configurator that could overwrite existing configuration and lead to permission-related issues. [LOGIN, APPS, INTEGRATE (INTRANET)]
* Fix: Users of the new automated embed-app configurator are now asked to choose between embedding for their organization or for customers to ensure the correct permissions are applied - when applicable. [APPS, INTEGRATE (INTRANET)]
* Fix: Users of the new automated embed-app configurator for Power BI are now able to configure XmlaPermissions (for Paginated Reports). [APPS, INTEGRATE (INTRANET)]
* Fix: Resolved several issues affecting configurations with multiple Identity Providers. [ESSENTIALS, PROFESSIONAL, CUSTOMERS, INTEGRATE (LOGIN+, SYNC, INTRANET)]
* Support for WordPress 7.0.

= v41.3 =
* Fix: The Mail Log Viewer now reliably displays attachment names without crashing. [LOGIN, MAILER]
* Fix: Corrected an issue that could cause a crash while generating client secret expiration warning emails. [LOGIN, MAILER]
* Fix: Resolved a "Failed to execute 'querySelector' on 'Document'" error in the wizard app triggered by invalid auto-generated element IDs. [LOGIN, MAILER]

= v41.2 =
* Fix: Prevented duplicate or incorrect type attributes on script tags, which could cause "Cannot use import statement outside a module" errors. [LOGIN]
* Fix: Resolved a critical error that could occur when obtaining an access token for an embed-app due to an undefined method call. [LOGIN]
* Fix: Automatically disables SSO when the mail function is invoked in the context of the WPO365 | MICROSOFT GRAPH MAILER plugin (preventing the plugin from logging unconfigured-warnings). [MAILER].

= v41.1 =
* Fix: Prevented duplicate or incorrect type attributes on script tags, which could cause "Cannot use import statement outside a module" errors. [LOGIN]

= v41.0 =
* Change: Added a brand‑new M*365 Apps Framework for embedding content from SharePoint Online, Microsoft Entra ID, Exchange Online, and Power BI, with persistent app configuration stored in the database, a preview option, and a guided configuration wizard. [LOGIN, APPS, INTEGRATE (INTRANET)]
* Change: Redesigned the menu of the plugin's Configuration Pages - new with a new vertical navigation, Redesigned the plugin menu with a new vertical navigation, improving clarity and access to features. [ALL]
* Improvement: To align with Microsoft’s current branding, Azure AD has been renamed to Microsoft Entra ID throughout the plugin, and all portal links now open in entra.microsoft.com. [ALL]
* Improvement: Added major enhancements to the Premium SharePoint Library embed: users can now search the library, upload files, and choose from new card templates or a more customizable HTML table view. [APPS, INTEGRATE (INTRANET)]
* Improvement: Enhanced the Exchange Online Calendar embed-app, including a date picker with event cards, and support for displaying events across a rolling one‑year period. [APPS, INTEGRATE (INTRANET)]
* Improvement: Refactored the plugin's "User Registration" configuration and move "Roles + Access" to its own configuration page for better clarity and maintainability. [LOGIN]
* Fix: Fixed an issue in the stand‑alone WPO365 | MICROSOFT GRAPH MAILER plugin and tested and confirmed compatibility with GCC High tenants. [MAILER]
* Fix: The WPO365 | PROFESSIONAL now ships with the required integration source code for itthinx Groups. [PROFESSIONAL]
* Fix: Updated the Exchange Online Calendar embed-app so links in event descriptions now open in a new tab. [LOGIN, APPS, INTEGRATE (INTRANET)]
* Fix: Dropped the core‑js polyfill dependency as it is no longer required by the plugin. [LOGIN]

= v40.3 =
* Improvement: Protecting the Media Library by restricting access to logged-in users is now also supported for Auth.-Only authentication scenarios. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC INTRANET)] 
* Improvement: When protection of the Media Library is enabled, WPO365 will award a cookie when a user signs in with SSO, further optimizing the performance. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC INTRANET)]
* Fix: When a cookie granting access to the Media Library is not found, WordPress will now loaded in an isolated function to prevent conflicts with other variables. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC INTRANET)]
* Fix: The exported SAML 2.0 service provider XML configuration file is now "well-formed". [LOGIN]
* Fix: The ROLES + ACCESS (premium) plugin now includes the mapping tool for itthinx Groups. [ROLES + ACCESS]
* Fix: The SCIM (premium) plugin now unlocks the "custom field mapping tool" on the plugin's "User Sync" configuration page. [SCIM]

= v40.2 =
* Security Fix: An XSS vulnerability has been patched. [ALL]

= v40.1 =
* Fix: Two free / basic apps for embedding Microsoft 365 services — SharePoint Online Search and Employee Directory — failed to perform their search functionality. [LOGIN]

= v40.0 =
* Security Fix: A Server Side Request Forgery (SSRF) vulnerability has been patched. [ALL]
* (Breaking) Change: The long-term deprecated version of WPO365 User Synchronization has now been removed. [INTEGRATE (SYNC, INTRANET)]
* Improvement: When an administrator enables WPO365's "shared" WPMU-mode, WPO365 can now be configured to update the user’s WordPress role(s) based on your Entra group-to-WP-role mappings not only for the current site, but also for all subsites where the user is a member. See the [online documentation](https://docs.wpo365.com/article/230-synchronize-wp-roles-across-all-sub-sites) for details. [ROLES + ACCESS, PROFESSIONAL, INTEGRATE, CUSTOMERS (SYNC, INTRANET)]
* Improvement: This version introduces a number of enhancements when embedding an Outlook / Exchange Online calendar in WordPress:
  * The free version now supports clickable items to pop up a dialog with the event's details.
  * Premium versions can now also use a Shared Calendar as their source.
  * The event's HTML content will now be rendered in an iframe.
  * Event details will now list the event start and end date, location and a clickable link in case of an online meeting.
  * By default will (new) calendars show an extra column for the event's end date.
  * Multi-day events are now easily identifiable by a dedicated icon.
  * See the updated [feature documentation](https://www.wpo365.com/feature/add-outlook-or-exchange-calendars-to-wordpress/).
* Improvement: Confirms support for WordPress 6.9. [ALL]
* Improvement: When embedding Power BI content in WordPress for customers, WPO365 will now also update dynamic tokens found in an Effective Identity's customData property. The [online documentation](https://tutorials.wpo365.com/courses/embed-power-bi-content-in-wordpress/lessons/advanced-row-level-security-rls/) has been updated to reflect this. [APPS, INTEGRATE (INTRANET)]
* Improvement: Direct Access to the Media Library now uses a cookie, to prevent 429 Too Many Requests errors and to reduce the server load. The [online documentation](https://docs.wpo365.com/article/229-require-login-for-the-wordpress-media-folder) has been updated accordingly. [ESSENTIALS, PROFESSIONAL, INTEGRATE, CUSTOMERS (LOGIN+, SYNC, INTRANET)]
* Fix: When WPO365 User Synchronization is triggered via an external link, WPO365 now waits for WordPress to fully initialize, ensuring that all hooks (filters and actions) are properly attached. [INTEGRATE (SYNC, INTRANET)]

= Older versions =

Please check the [online change log](https://www.wpo365.com/change-log/) for previous changelogs.
