Overview
CloudSSO supports single sign-on (SSO) based on Security Assertion Markup Language (SAML) 2.0. Alibaba Cloud acts as the service provider (SP), and your enterprise identity management system acts as the identity provider (IdP). With SSO configured, employees log on to CloudSSO using their existing IdP credentials — no additional accounts required.
Procedure
-
Get the SP metadata from CloudSSO.
Download and view the SP metadata in the CloudSSO console. For more information, see the Obtain SP metadata section of the "Configure SSO" topic.
-
Add Alibaba Cloud as a trusted SAML SP in your IdP and configure SAML assertions.
After adding Alibaba Cloud as a trusted SAML SP, associate your users with the application. Configuration steps vary by IdP — see your IdP documentation for details.
-
Get the IdP SAML metadata from your IdP.
Download the SAML metadata file from your IdP. The method varies by IdP — see your IdP documentation for details.
-
Add the IdP as a trusted SAML IdP in the CloudSSO console.
You can either upload the IdP's SAML metadata file directly, or configure the SAML information manually. Manual configuration requires only three parameters: Entity ID, Logon URL, and Certificate. If you need to configure additional parameters, generate the IdP metadata file using your IdP client and upload it instead.
-
Enable SSO in the CloudSSO console.
For more information, see the Enable single sign-on section of the "Configure SSO" topic.
-
Add users to CloudSSO.
If your IdP supports System for Cross-domain Identity Management (SCIM) and has a large number of users, synchronize users automatically from the IdP to CloudSSO. For more information, see Synchronize users or groups in Microsoft Entra ID by using SCIM and Synchronize users or groups in Okta by using SCIM.
If your IdP has a small number of users, create them manually in the CloudSSO console. Set the
NameIDattribute to match the username in your SAML assertions. For more information, see the Create a user section of the "Perform basic operations" topic.
Log on to CloudSSO as an IdP user using SSO.
References
FAQ
For more information, see FAQ about SSO