Configure a logon method
CloudSSO supports two mutually exclusive logon methods: username-password logon and single sign-on (SSO) through an external identity provider (IdP). This topic describes how to switch between the two methods.
Logon methods
CloudSSO supports two mutually exclusive logon methods. Only one can be active at a time — enabling one automatically disables the other.
-
Username-password logon
Users enter their CloudSSO username and password to access Alibaba Cloud. This method is enabled by default.
-
SSO
Users authenticate through an external IdP. To use this method, you must first configure an IdP and upload its metadata file.
Enable or disable username-password logon
Username-password logon is enabled by default. Disabling it automatically enables SSO. Before switching to SSO, upload the IdP metadata file — SSO cannot be enabled without it.
Log on to the CloudSSO console.
In the left-side navigation pane, click Settings.
-
On the User Login Methods tab, in the Username-password Logon section, turn the switch on or off.
To enable username-password logon, turn on the switch.
-
To disable username-password logon, turn off the switch. SSO is automatically enabled.
NoteUpload the IdP metadata file before disabling username-password logon. Without the metadata file, SSO cannot be activated.
Enable or disable SSO
SSO is disabled by default. Enabling it automatically disables username-password logon. For more information, see Manage single sign-on.