To use role-based single sign-on (SSO) with the new MaxCompute console, configure a trust policy on the RAM role that your employees will assume when logging in to Alibaba Cloud. For an overview of role-based SSO, see SAML role-based SSO overview.
In role-based SSO, Alibaba Cloud acts as the service provider (SP) and your company's identity management system acts as the identity provider (IdP). Employees authenticate through the IdP and assume a specified RAM role to access Alibaba Cloud, eliminating the need to synchronize users between the two systems.
Prerequisites
Before you begin, ensure that you have:
A RAM role for your employees to assume. Choose the role type based on who will log in:
RAM user assumes the role: Create a RAM role for a trusted Alibaba Cloud account
IdP account assumes the role: Create a RAM role for a trusted identity provider
Configure the role trust policy
Log on to the Resource Access Management (RAM) console.
In the left navigation pane, choose Identities > Roles.
On the Roles page, click the Role Name of the target role to open its details page.
On the Trust Policy tab, click Edit Trust Policy. On the Edit Trust Policy page, click the JSON tab and update the policy. For details on the JSON fields and values to use, see Modify the trust policy of a RAM role.
Click OK.