Bind or unbind a DingTalk account for a RAM user
Binding a RAM user to a DingTalk account enables you to log on to the Alibaba Cloud console by scanning a QR code with DingTalk, improving both convenience and security. This topic describes how to bind and unbind a DingTalk account for a RAM user, and how to use a DingTalk account to log on to the Alibaba Cloud console.
Prerequisites
A RAM administrator must first allow RAM users to manage their own DingTalk accounts. For a root account, this permission is enabled by default. For instructions on how to modify this setting, see Manage the security settings of a RAM user.
Limitations
-
RAM users can only bind their own DingTalk accounts. A root account cannot bind a DingTalk account for its RAM users.
-
A RAM user can be bound to only one DingTalk account.
-
Within the same root account, a DingTalk account can be bound to only one RAM user.
-
A single DingTalk account can be bound to a maximum of five different RAM users across different root accounts.
Bind a DingTalk account
Only RAM users can bind their own DingTalk accounts. A RAM administrator cannot do this for other RAM users.
From the logon page
Before you log on, you can bind your DingTalk account from the RAM user logon page.
From security settings
After you log on as a RAM user, you can bind a DingTalk account from the security settings page.
-
Log on to the RAM user logon page.
-
Hover over the avatar in the upper-right corner and click Security Settings.
-
In the left-side navigation pane, choose Security Information. In the Logon Information section, click Bind next to DingTalk Binding Status.
-
On the Bind RAM user with DingTalk page, a QR code is displayed.
-
Open the DingTalk app on your mobile device and scan the QR code displayed on the tab.
-
On the Bind RAM user with DingTalk page, verify that the DingTalk account name is correct and then click Bind.
-
In the Binding Succeeded dialog box, click OK. The system automatically redirects you to the User information page in the RAM console.
-
Verify that the DingTalk Binding Status is now Bound.
From other services
For other cloud services that support DingTalk integration, you can also bind a DingTalk account to a RAM user from the consoles of these services or within the DingTalk app. For example, to initiate the binding from Alibaba Cloud DevOps, see Bind a RAM user to a DingTalk account.
This method may require your DingTalk account to belong to a specific DingTalk organization, or it may ask you to specify one. The exact requirements depend on the cloud service. For details, see the documentation for that service.
Log on with a DingTalk account
A RAM user can log on with a username and a password, a passkey, or a DingTalk account. For more information, see Log on to the Alibaba Cloud console as a RAM user.
Scan QR code in browser
-
On the RAM user logon page, click the Logon with DingTalk tab.
-
Open the DingTalk app on your mobile device and scan the QR code displayed on the tab.
-
In the DingTalk app, tap Logon to Alibaba Cloud RAM.
-
On the Logon with DingTalk page, review the RAM user information associated with the DingTalk account and then click Log On.
NoteIf the DingTalk account is bound to multiple RAM users, you must select the target RAM user from the list before you can log on.
One-click logon in app
When opening an Alibaba Cloud link in the DingTalk app (such as from a chat), if the page requires you to log on, tap One-click logon with DingTalk account. This logs you on as the RAM user bound to your DingTalk account without requiring you to enter a username and password. If your DingTalk account is bound to multiple RAM users, you need to select the desired user from the list.
Unbind a DingTalk account
After unbinding a DingTalk account, you can no longer use it to log on by scanning a QR code or by using the one-click logon feature in the DingTalk app. Unbinding may also affect the RAM user's access to other Alibaba Cloud services that rely on DingTalk integration. For example, to understand the impact of unbinding on Alibaba Cloud DevOps, see FAQ.
From the RAM console
A RAM administrator can unbind DingTalk accounts for any RAM user in the RAM console.
-
Log on to the RAM console as a root account or a RAM user that has RAM administrator permissions (
AliyunRAMFullAccess). -
In the left-side navigation pane, choose .
-
In the user list, click the name of the target RAM user.
-
On the Authentication tab, in the Login Profile section, click Unbind next to DingTalk Binding Status.
-
In the Unbind DingTalk account dialog box, review the consequences of unbinding and then click Unbind.
-
After unbinding, the DingTalk Binding Status displays Unbound.
From security settings
A RAM user can unbind their own DingTalk account from the security settings page.
-
Log on to the RAM user logon page.
-
Hover over the avatar in the upper-right corner and click Security Settings.
-
In the left-side navigation pane, choose Security Information. In the Logon Information section, click Unbind next to DingTalk Binding Status.
-
In the Unbind DingTalk account dialog box, review the consequences of unbinding and then click Unbind.
-
After unbinding, the DingTalk Binding Status displays Unbound.