SASE enforces identity-driven security policies. If your enterprise uses Lark to manage its organizational structure, you can connect your Lark data source to SASE. This eliminates the need to create separate identity information for your employees. After you connect the Lark data source, your employees can use their existing enterprise accounts to log on to the SASE app and access internal applications. This topic describes how to connect a Lark data source.
Limitations
You can enable a maximum of five data sources at a time. Only one of them can be a custom data source. If you reach this quota, you must disable an existing data source to enable a new one.
Configure Lark data source
-
Log on to the SASE console.
-
In the left-side navigation pane, choose .
-
On the Identity synchronization tab, click Create IdP.
-
In the Create IdP panel, select Lark, click Configure, and then follow the steps in the wizard to complete the configuration.
-
In the Basic Configurations step, configure the following parameters.
Parameter
Description
IdP Name
The name of the Lark data source.
The name must be 2 to 100 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
Description
The description of the configuration.
The description is displayed on the SASE client as the logon title to help users identify the data source at logon.
IdP Status
Configure the status for the identity source. The valid values are:
Enabled: The identity source is enabled after it is created.
Closed: The identity source is disabled after it is created.
ImportantIf you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.
App ID
The ID of the enterprise-built application in the Lark Open Platform.
App Secret
The secret of the enterprise-built application in the Lark Open Platform.
After you configure event subscription, the organizational structure is synchronized to SASE. This ensures that SASE security policies are promptly updated when your organizational structure changes.
-
Encrypt Key
Obtain this value from the Contacts Synchronization page on the Lark Open Platform.
-
Verification Token
Obtain this value from the Contacts Synchronization page of your target application on the Lark Open Platform.
-
Request URL: This value is used to configure a redirect URL on the Lark Open Platform.
Subscribed events: Department Created, Department Deleted, Department Information Changed, Employee Resigned, and Employee Information Changed.
Redirect URL
A fixed value: https://login.aliyuncsas.com/open-dev/feishu.
This value is used to configure the redirect URL in .
Automatic Synchronization
After you enable Automatic Synchronization, the system automatically synchronizes information from Lark based on the synchronization mode.
If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.
Synchronize User Information
After you enable Synchronize User Information, the system automatically synchronizes employee information from Lark at the interval specified by Automatic Synchronization Cycle.
NoteIf Automatic Synchronization is disabled, the Synchronize User Information feature is also disabled.
Automatic Synchronization Cycle
Set the Automatic Synchronization Cycle interval. The value can be from 1 to 24 hours.
Logo
Upload a custom logo.
-
Click Connectivity Test. After the test is successful, click Next.
NoteIf the Connection Failed message appears, verify that the information you entered is correct.
-
In the Synchronization Settings step, configure the synchronization scope for the organizational structure and map the synchronization fields. Then, click Ok.
Parameter
Description
Organizational Structure Synchronization
Configure the synchronization scope for the organizational structure.
-
Synchronize All: Synchronizes the entire organizational structure from Lark to SASE.
-
Partially Synchronize: Synchronizes only the organizational units that you select.
Field Synchronization Mapping
Map the organizational structure fields from Lark to the corresponding fields in SASE.
NoteIf the built-in Local Field After Mapping of the SASE system do not meet your business requirements, you can click View Extended Fields in the upper-right corner of the list. In the View Extended Fields panel, you can add, edit, or delete extended fields.
-
View synchronization records
-
On the Identity synchronization tab, find the IdP that you created and click Synchronize Records in the Actions column.
-
On the Synchronize Records page, view the synchronization history for the IdP.
-
In the Synchronization Task area on the left, click a specific task to view its details in the list on the right.

-
Click Details in the Actions column of a task to view the field information from the Third-party Data Source and the SASE Data Source for that synchronization.
Manual synchronization
If you did not enable Automatic Synchronization when you configured the IdP, or if your IdP's structure has changed, you must synchronize the information manually. Click Create Synchronization Task and then click OK. After the task is complete, you can view the synchronization records.
After a successful synchronization, you can view the updated organizational structure and user information on the tab. For more information, see Employee Center.
Disable automatic synchronization
-
On the Identity synchronization tab, find the IdP and turn off the switch in the Automatic Synchronization column.
-
In the Edit IdP panel, turn off the automatic synchronization switch.
Edit Lark data source
On the Identity synchronization page, find the Lark data source and click Edit in the Actions column.
Disable Lark data source
On the Identity synchronization page, find the Lark data source and turn off the switch in the IdP Status column.
Delete Lark data source
On the Identity synchronization page, find the Lark data source and click Delete in the Actions column.
Related topics
Configure a custom data source
If your enterprise does not use an existing data source, you can use the custom data source provided by SASE to build an organizational structure. For more information, see Connect to a custom data source.
Connect to a third-party data source
If your enterprise already uses LDAP, DingTalk, WeCom, Lark, or IDaaS to manage its organizational structure, you can connect that data source to SASE.
Configure a user group
To create user groups separate from your organizational structure, see User group management.