Connect to an IDaaS identity provider

Updated at:

SASE uses identity to enforce security policies. If your organization already uses an IDaaS identity provider (IdP) to manage its organizational structure, you can connect it to SASE to avoid creating duplicate user identities. After the connection is established, your employees can use their existing corporate accounts to sign in to the SASE client for work. This topic explains how to connect to an IDaaS identity provider.

Limitations

You can enable a maximum of five identity providers simultaneously, only one of which can be a custom identity provider. If you reach the limit, you must disable an existing identity provider before enabling a new one.

Configure an IDaaS identity provider

  1. Log on to the SASE console.

  2. In the left navigation pane, choose Identity Authentication > Identity Access.

  3. On the Identity synchronization tab, click Create IdP.

  4. In the Create IdP panel, select IDaaS, and then click Configure.

  5. The configuration process differs for the new and old versions of IDaaS. Follow the steps in the wizard for your version.

    New IDaaS version

    1. In the Basic Configurations wizard, configure the parameters as described in the following table.

      Parameter

      Description

      IdP Name

      A name for the IDaaS identity provider configuration.

      The name must be 2–100 characters long and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).

      Description

      A description for the configuration.

      This description appears as the logon title in the SASE client so that users can identify the identity provider at sign-in.

      IdP Status

      Configure the status for the identity source. The valid values are:

      • Enabled: The identity source is enabled after it is created.

      • Closed: The identity source is disabled after it is created.

        Important

        If you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.

      IDaaS Version

      Select New Version.

      Regional Instance

      Select the region where your instance is located. You can select Chinese Mainland or Outside Chinese Mainland.

      SAML Metadata File

      Upload the SAML metadata file. IDaaS automatically generates this file when you create an Alibaba Cloud SASE application (on the single sign-on tab of the IDaaS console).

      Grant Read Permissions on Organizational Structure

      Specify whether to authorize SASE to read the organizational structure. Valid values:

      • Yes: Enter the API information of IDaaS to obtain the enterprise directory. You need to configure the following parameters:

        • Instance ID: The ID of the new EIAM instance that you created.

        • Application ID: The ID of the Alibaba Cloud SASE application that you added to the new EIAM instance.

        • client_id: The API authentication ID. IDaaS automatically generates this ID when you create an Alibaba Cloud SASE application (on the General Configurations tab of the IDaaS console).

        • client_secret: The API authentication secret. IDaaS automatically generates this secret when you create an Alibaba Cloud SASE application (on the General Configurations tab of the IDaaS console).

        • Public Key Endpoint: IDaaS automatically generates this URL when you create an Alibaba Cloud SASE application (on the Account Synchronization tab of the IDaaS console).

        • URL for Receiving Synchronization Requests: Copy this URL from the SASE console and paste it into the synchronization reception URL field in the IDaaS console.

        • Encryption/Decryption Key: IDaaS automatically generates this key when you create an Alibaba Cloud SASE application (on the Account Synchronization tab of the IDaaS console).

          Note

          After this is configured, you can apply security policies to users in batches based on the directory. The system does not read your employee information when it applies security policies.

        • Automatic Synchronization: After you turn on the Automatic Synchronization switch, IDaaS automatically synchronizes information based on the synchronization mode.

          If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.

        • Synchronize User Information: After you turn on the Synchronize User Information switch, IDaaS automatically synchronizes employee information based on the Automatic Synchronization Cycle.

          Note

          If the Automatic Synchronization feature is disabled, the Synchronize User Information function does not run.

        • Automatic Synchronization Cycle: Specifies the Automatic Synchronization Cycle. The interval can be set from 1 to 24 hours.

      • No: Does not authorize reading of the organizational structure.

      Logo

      Upload a custom logo.

    2. If you set Grant Read Permissions on Organizational Structure to No, click Ok to complete the configuration.

      If you set Yes to Connectivity Test, you can click Connectivity Test. After the test succeeds, click Next.

    3. In the Synchronization Settings wizard, configure the synchronization scope and field mappings for the organizational structure, and then click Ok.

      Parameter

      Description

      Organizational Structure Synchronization

      Configure the synchronization scope of the organizational structure.

      • Synchronize All: Synchronizes the entire organizational structure from the new version of IDaaS to SASE.

      • Partially Synchronize: Synchronizes only selected parts of the organizational structure.

      Field Synchronization Mapping

      Configure the mappings between IDaaS organizational structure fields and SASE synchronization fields.

      Note

      If the built-in Local Field After Mapping in SASE does not meet your business requirements, you can click View Extended Fields in the upper-right corner of the list. In the View Extended Fields panel, you can create, edit, or delete extended fields.

    Old IDaaS version

    1. In the Basic Configurations wizard, configure the parameters as described in the following table.

      Parameter

      Description

      IdP Name

      A name for the IDaaS identity provider configuration.

      The name must be 2–100 characters long and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).

      Description

      A description for the configuration.

      This description appears as the logon title in the SASE client so that users can identify the identity provider at sign-in.

      IdP Status

      Configure the status for the identity source. The valid values are:

      • Enabled: The identity source is enabled after it is created.

      • Closed: The identity source is disabled after it is created.

        Important

        If you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.

      IDaaS Version

      Select Old Version.

      SAML Metadata File

      Upload the SAML metadata file. IDaaS automatically generates this file when you create the application details (SAML).

      Grant Read Permissions on Organizational Structure

      Specify whether to authorize SASE to read the organizational structure. Valid values:

      • Yes: Enter the API information of IDaaS to obtain the enterprise directory. You must configure the API key and API secret, and configure the automatic synchronization features.

        Note

        After this is configured, you can apply security policies to users in batches based on the directory. The system does not read your employee information when it applies security policies.

        • Automatic Synchronization: After you turn on the Automatic Synchronization switch, IDaaS automatically synchronizes information based on the synchronization mode.

          If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.

        • Synchronize User Information: After you turn on the Synchronize User Information switch, IDaaS automatically synchronizes employee information based on the Automatic Synchronization Cycle.

          Note

          If the Automatic Synchronization feature is not enabled, the Synchronize User Information function is not executed.

        • Automatic Synchronization Cycle: Set the Automatic Synchronization Cycle. You can select an interval from 1 to 24 hours.

      • No: Does not authorize reading of the organizational structure.

      SP entity ID

      This value is fixed: https://saml-csas.aliyuncs.com/saml/metadata.

      SP ACS URL

      This value is fixed: https://saml-csas.aliyuncs.com/saml/acs.

      Logo

      Upload a custom logo.

    2. If you set Grant Read Permissions on Organizational Structure to No, click Ok to complete the configuration.

      If you set it to Yes, you can click Connectivity Test. After the test succeeds, click Ok to complete the configuration.

View synchronization records

If you set Grant Read Permissions on Organizational Structure to Yes and enabled automatic synchronization when you configured the identity provider, you can view the synchronization records after the automatic synchronization is complete.

  1. On the Identity synchronization tab, find the IdP that you created and click Synchronize Records in the Actions column.

  2. On the Synchronize Records page, view the synchronization history for the IdP.

  3. In the Synchronization Task area on the left, click a specific task to view its details in the list on the right.

    image

  4. Click Details in the Actions column of a task to view the field information from the Third-party Data Source and the SASE Data Source for that synchronization.

Manual synchronization

If you did not enable Automatic Synchronization when you configured the IdP, or if your IdP's structure has changed, you must synchronize the information manually. Click Create Synchronization Task and then click OK. After the task is complete, you can view the synchronization records.

Note

After a successful synchronization, you can view the updated organizational structure and user information on the Identity Authentication > Identity Access > Employee Center tab. For more information, see Employee Center.

Disable automatic synchronization

  • On the Identity synchronization tab, find the IdP and turn off the switch in the Automatic Synchronization column.

  • In the Edit IdP panel, turn off the automatic synchronization switch.

Edit an IDaaS identity provider

To edit an IDaaS identity provider, find it on the Identity synchronization page and click Edit in the Actions column.

Disable an IDaaS identity provider

To disable an IDaaS identity provider, find it on the Identity synchronization page and turn off the switch in the IdP Status column.

Delete an IDaaS identity provider

To delete an IDaaS identity provider, find it on the Identity synchronization page and click Delete in the Actions column.

Related topics

Best practices

Configure a SASE identity provider

If your organization does not use an identity provider, you can use the custom identity provider in SASE to create your organizational structure. For more information, see Configure a custom identity provider.

Connect to a third-party identity provider

If your organization already uses an identity provider such as LDAP, DingTalk, WeCom, Lark, or IDaaS to manage its organizational structure, you can connect it to SASE.

Configure user groups

To create user groups outside your organization's organizational structure, see User group management.