This topic describes how to configure Alibaba Cloud role SSO in IDaaS. Role SSO eliminates the need to create a RAM user for each member.
Step 1: Create an application in IDaaS
Log on to the IDaaS console.
Select an IDaaS instance and click Console in the Actions column.
Navigate to , search for the Alibaba Cloud role SSO application template, and click Add Application.
Confirm the application name and click Add.
The Application Name is
Alibaba Cloud role SSO.
Step 2: Configure application SSO in IDaaS
After adding the application, you are automatically redirected to the application's SSO configuration page.
On the Sign-In > SSO tab, turn on the SSO Configuration switch. Enter the Alibaba Cloud Account ID (the ID of the target Alibaba Cloud account) and the IdP Name (the name for the identity provider that you will create in RAM). Configure the Application Account (which corresponds to a RAM role name) and the authorization scope. By default, the scope is set to Manual Authorization, which requires you to assign permissions on the Application Authorization tab.
Configure the SSO settings.
Alibaba Cloud Account ID: Find this on the console home page by clicking your profile picture or navigating to Account Center.

IdP Name: The name can only contain letters, numbers, and the characters .-_. The name cannot start or end with a special character.
Application Account: This is the primary key used to match the RAM role during single sign-on.
Authorize: For testing purposes, we recommend that you select All Users and skip the permission assignment step.
In the Application Configuration section, download the IdP metadata and save it to your computer. This file establishes a trust relationship between Alibaba Cloud and IDaaS.
Go to Single Sign-On> Application Accounts, and click Add Application Account.
Select the accounts that will use Alibaba Cloud role SSO and add application accounts for them. The application account name must exactly match the Alibaba Cloud role name. If one IDaaS account maps to multiple Alibaba Cloud roles, you can create multiple application accounts.
Step 3: Configure role SSO in RAM
Log on to the RAM console.
In the left navigation pane, choose .
On the Role-based SSO tab, go to the SAML tab and click Create IdP.
Enter an identity provider name. This name must match the IdP Name that you configured in Step 2. Upload the IdP metadata that you downloaded from IDaaS in Step 2. Click Create IdP.
Step 4: Create a role for the identity provider
Log on to the RAM console.
In the left navigation pane, choose .
On the Role page, click Create Role.
In the upper-right corner of the Create Role page, click Switch To Policy Editor.
Select Identity Provider and click Edit. For IdP Type, select the identity provider that you created in Step 3, and then click OK.
In the Create Role dialog box, enter a Role Name and click OK. The Role Name must be identical to the application account name that you configured in Step 2.
You can assign permissions to the RAM role. Any IDaaS account that uses single sign-on with this role will have the same permissions.
On the RAM role's details page, select the Permissions tab, and click Add Permissions to assign the required permission policies to the role. After you grant the permissions, you can view the attached policies in the permission policy list. To remove a policy, click Revoke Permission.
Step 5: Verify SSO
Log on to the IDaaS application portal with an IDaaS account that has permissions for the Alibaba Cloud role SSO application. Click the Alibaba Cloud Role-Based SSO icon to initiate single sign-on.
If an IDaaS account has two or more application accounts (Alibaba Cloud roles), you must select an application account to use for single sign-on.
Select the appropriate application account and click OK to sign on to Alibaba Cloud as the selected role.