SASE uses an identity-driven approach to apply security policies. If your organization already uses WUYING Workspace to manage its organizational structure, you can connect the WUYING Workspace identity provider to SASE. This eliminates the need to recreate identity information for your employees. After connecting the identity provider, employees can sign in to the SASE App by using their existing corporate accounts. This topic describes how to connect to a WUYING Workspace identity provider.
Limitations
You can enable a maximum of five identity providers at a time. Only one of them can be a custom identity provider. If you reach this limit, you must disable an existing identity provider before you can enable a new one.
Configure WUYING Workspace identity provider
-
Log in to the SASE console.
-
In the left-side navigation pane, choose .
-
On the Identity synchronization tab, click Create IdP.
-
In the Create IdP panel, select EDS, and then click Configure. Follow the wizard to complete the configuration.
-
In the Basic Configurations wizard, configure the following parameters and click Ok.
Parameter
Description
IdP Name
Enter a name for the identity provider.
IdP Status
Configure the status for the identity source. The valid values are:
Enabled: The identity source is enabled after it is created.
Closed: The identity source is disabled after it is created.
ImportantIf you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.
EDS Workspace Account Configuration
Configure the Alibaba Cloud UID for WUYING Workspace. Click Add More to add a maximum of five UIDs.
Automatic Synchronization
If you enable Automatic Synchronization, the system automatically synchronizes information from WUYING Workspace based on the synchronization mode.
If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.
Automatic Synchronization Cycle
Set the Automatic Synchronization Cycle. The interval can be set from 1 to 24 hours.
View synchronization records
-
On the Identity synchronization tab, find the identity source that you added and click Synchronize Records in the Actions column.
-
On the Synchronize Records page, view the information synchronization records for the identity source.
-
In the Synchronization Task section on the left, click a specific task to view its synchronization details in the list on the right.

-
In the Actions column for a task, click Details to view the field information for the Third-party Data Source and SASE Data Source.
Manual synchronization
If you did not enable Automatic Synchronization when you configured the identity source, or if your directory structure has changed, you must synchronize the information manually. Click Create Synchronization Task and then click OK. After the synchronization task is complete, you can view the synchronization records.
After the synchronization is successful, you can view the synchronized organizational structure and user information on the tab. For more information, see Employee Center.
Disable automatic synchronization
-
On the Identity synchronization tab, find the identity source that you added and turn off the switch in the Automatic Synchronization column.
-
In the Edit IdP panel, turn off the automatic synchronization switch.
Edit WUYING Workspace identity provider
On the Identity synchronization page, find the relevant WUYING Workspace identity provider and click Edit in the Actions column to update its settings.
Disable WUYING Workspace identity provider
On the Identity synchronization page, find the relevant WUYING Workspace identity provider and turn off the switch in the IdP Status column.
Delete WUYING Workspace identity provider
On the Identity synchronization page, find the relevant WUYING Workspace identity provider and click Delete in the Actions column.
Related documents
Best practices
Configure user-defined identity provider
If your organization does not use any identity provider, you can use the custom identity provider offered by SASE to build your organizational structure. For more information, see Connect to a custom identity provider.
Connect to a third-party identity provider
If your organization already uses an identity provider such as LDAP, DingTalk, WeCom, Lark, or IDaaS to manage the organizational structure, you can connect the identity provider to SASE.
Configure user groups
If you need to create user groups outside your organizational structure, see User group management.