Connect to an IDaaS identity provider
SASE uses identity to enforce security policies. If your organization already uses an IDaaS identity provider (IdP) to manage its organizational structure, you can connect it to SASE to avoid creating duplicate user identities. After the connection is established, your employees can use their existing corporate accounts to sign in to the SASE client for work. This topic explains how to connect to an IDaaS identity provider.
Limitations
You can enable a maximum of five identity providers simultaneously, only one of which can be a custom identity provider. If you reach the limit, you must disable an existing identity provider before enabling a new one.
Configure an IDaaS identity provider
-
Log on to the SASE console.
-
In the left navigation pane, choose .
-
On the Identity synchronization tab, click Create IdP.
-
In the Create IdP panel, select IDaaS, and then click Configure.
-
The configuration process differs for the new and old versions of IDaaS. Follow the steps in the wizard for your version.
New IDaaS version
-
In the Basic Configurations wizard, configure the parameters as described in the following table.
Parameter
Description
IdP Name
A name for the IDaaS identity provider configuration.
The name must be 2–100 characters long and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
Description
A description for the configuration.
This description appears as the logon title in the SASE client so that users can identify the identity provider at sign-in.
IdP Status
Configure the status for the identity source. The valid values are:
Enabled: The identity source is enabled after it is created.
Closed: The identity source is disabled after it is created.
ImportantIf you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.
IDaaS Version
Select New Version.
Regional Instance
Select the region where your instance is located. You can select Chinese Mainland or Outside Chinese Mainland.
SAML Metadata File
Upload the SAML metadata file. IDaaS automatically generates this file when you create an Alibaba Cloud SASE application (on the single sign-on tab of the IDaaS console).
Grant Read Permissions on Organizational Structure
Specify whether to authorize SASE to read the organizational structure. Valid values:
-
Yes: Enter the API information of IDaaS to obtain the enterprise directory. You need to configure the following parameters:
-
Instance ID: The ID of the new EIAM instance that you created.
-
Application ID: The ID of the Alibaba Cloud SASE application that you added to the new EIAM instance.
-
client_id: The API authentication ID. IDaaS automatically generates this ID when you create an Alibaba Cloud SASE application (on the General Configurations tab of the IDaaS console).
-
client_secret: The API authentication secret. IDaaS automatically generates this secret when you create an Alibaba Cloud SASE application (on the General Configurations tab of the IDaaS console).
-
Public Key Endpoint: IDaaS automatically generates this URL when you create an Alibaba Cloud SASE application (on the Account Synchronization tab of the IDaaS console).
-
URL for Receiving Synchronization Requests: Copy this URL from the SASE console and paste it into the synchronization reception URL field in the IDaaS console.
-
Encryption/Decryption Key: IDaaS automatically generates this key when you create an Alibaba Cloud SASE application (on the Account Synchronization tab of the IDaaS console).
NoteAfter this is configured, you can apply security policies to users in batches based on the directory. The system does not read your employee information when it applies security policies.
-
Automatic Synchronization: After you turn on the Automatic Synchronization switch, IDaaS automatically synchronizes information based on the synchronization mode.
If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.
-
Synchronize User Information: After you turn on the Synchronize User Information switch, IDaaS automatically synchronizes employee information based on the Automatic Synchronization Cycle.
NoteIf the Automatic Synchronization feature is disabled, the Synchronize User Information function does not run.
-
Automatic Synchronization Cycle: Specifies the Automatic Synchronization Cycle. The interval can be set from 1 to 24 hours.
-
-
No: Does not authorize reading of the organizational structure.
Logo
Upload a custom logo.
-
If you set Grant Read Permissions on Organizational Structure to No, click Ok to complete the configuration.
If you set Yes to Connectivity Test, you can click Connectivity Test. After the test succeeds, click Next.
-
In the Synchronization Settings wizard, configure the synchronization scope and field mappings for the organizational structure, and then click Ok.
Parameter
Description
Organizational Structure Synchronization
Configure the synchronization scope of the organizational structure.
-
Synchronize All: Synchronizes the entire organizational structure from the new version of IDaaS to SASE.
-
Partially Synchronize: Synchronizes only selected parts of the organizational structure.
Field Synchronization Mapping
Configure the mappings between IDaaS organizational structure fields and SASE synchronization fields.
NoteIf the built-in Local Field After Mapping in SASE does not meet your business requirements, you can click View Extended Fields in the upper-right corner of the list. In the View Extended Fields panel, you can create, edit, or delete extended fields.
-
Old IDaaS version
-
In the Basic Configurations wizard, configure the parameters as described in the following table.
Parameter
Description
IdP Name
A name for the IDaaS identity provider configuration.
The name must be 2–100 characters long and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
Description
A description for the configuration.
This description appears as the logon title in the SASE client so that users can identify the identity provider at sign-in.
IdP Status
Configure the status for the identity source. The valid values are:
Enabled: The identity source is enabled after it is created.
Closed: The identity source is disabled after it is created.
ImportantIf you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.
IDaaS Version
Select Old Version.
SAML Metadata File
Upload the SAML metadata file. IDaaS automatically generates this file when you create the application details (SAML).
Grant Read Permissions on Organizational Structure
Specify whether to authorize SASE to read the organizational structure. Valid values:
-
Yes: Enter the API information of IDaaS to obtain the enterprise directory. You must configure the API key and API secret, and configure the automatic synchronization features.
NoteAfter this is configured, you can apply security policies to users in batches based on the directory. The system does not read your employee information when it applies security policies.
-
Automatic Synchronization: After you turn on the Automatic Synchronization switch, IDaaS automatically synchronizes information based on the synchronization mode.
If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.
-
Synchronize User Information: After you turn on the Synchronize User Information switch, IDaaS automatically synchronizes employee information based on the Automatic Synchronization Cycle.
NoteIf the Automatic Synchronization feature is not enabled, the Synchronize User Information function is not executed.
-
Automatic Synchronization Cycle: Set the Automatic Synchronization Cycle. You can select an interval from 1 to 24 hours.
-
-
No: Does not authorize reading of the organizational structure.
SP entity ID
This value is fixed: https://saml-csas.aliyuncs.com/saml/metadata.
SP ACS URL
This value is fixed: https://saml-csas.aliyuncs.com/saml/acs.
Logo
Upload a custom logo.
-
If you set Grant Read Permissions on Organizational Structure to No, click Ok to complete the configuration.
If you set it to Yes, you can click Connectivity Test. After the test succeeds, click Ok to complete the configuration.
-
View synchronization records
If you set Grant Read Permissions on Organizational Structure to Yes and enabled automatic synchronization when you configured the identity provider, you can view the synchronization records after the automatic synchronization is complete.
-
On the Identity synchronization tab, find the IdP that you created and click Synchronize Records in the Actions column.
-
On the Synchronize Records page, view the synchronization history for the IdP.
-
In the Synchronization Task area on the left, click a specific task to view its details in the list on the right.

-
Click Details in the Actions column of a task to view the field information from the Third-party Data Source and the SASE Data Source for that synchronization.
Manual synchronization
If you did not enable Automatic Synchronization when you configured the IdP, or if your IdP's structure has changed, you must synchronize the information manually. Click Create Synchronization Task and then click OK. After the task is complete, you can view the synchronization records.
After a successful synchronization, you can view the updated organizational structure and user information on the tab. For more information, see Employee Center.
Disable automatic synchronization
-
On the Identity synchronization tab, find the IdP and turn off the switch in the Automatic Synchronization column.
-
In the Edit IdP panel, turn off the automatic synchronization switch.
Edit an IDaaS identity provider
To edit an IDaaS identity provider, find it on the Identity synchronization page and click Edit in the Actions column.
Disable an IDaaS identity provider
To disable an IDaaS identity provider, find it on the Identity synchronization page and turn off the switch in the IdP Status column.
Delete an IDaaS identity provider
To delete an IDaaS identity provider, find it on the Identity synchronization page and click Delete in the Actions column.
Related topics
Best practices
Configure a SASE identity provider
If your organization does not use an identity provider, you can use the custom identity provider in SASE to create your organizational structure. For more information, see Configure a custom identity provider.
Connect to a third-party identity provider
If your organization already uses an identity provider such as LDAP, DingTalk, WeCom, Lark, or IDaaS to manage its organizational structure, you can connect it to SASE.
Configure user groups
To create user groups outside your organization's organizational structure, see User group management.