Connect to a WUYING Workspace identity provider

Updated at:

SASE uses an identity-driven approach to apply security policies. If your organization already uses WUYING Workspace to manage its organizational structure, you can connect the WUYING Workspace identity provider to SASE without recreating identity information for your employees. After connecting the identity provider, employees can sign in to the SASE App by using their existing corporate accounts.

Limitations

You can enable a maximum of five identity providers at a time. Only one of them can be a custom identity provider. If you reach this limit, you must disable an existing identity provider before you can enable a new one.

Configure WUYING Workspace identity provider

  1. Log in to the SASE console.

  2. In the left-side navigation pane, choose Identity Authentication > Identity Access.

  3. On the Identity synchronization tab, click Create IdP.

  4. In the Create IdP panel, select EDS, and then click Configure. Follow the wizard to complete the configuration.

  5. In the Basic Configurations wizard, configure the following parameters and click Ok.

    Parameter

    Description

    IdP Name

    Enter a name for the identity provider.

    IdP Status

    Configure the status for the identity source. The valid values are:

    • Enabled: The identity source is enabled after it is created.

    • Closed: The identity source is disabled after it is created.

      Important

      If you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.

    EDS Workspace Account Configuration

    Configure the Alibaba Cloud UID for WUYING Workspace. Click Add More to add a maximum of five UIDs.

    Automatic Synchronization

    If you enable Automatic Synchronization, the system automatically synchronizes information from WUYING Workspace based on the synchronization mode.

    If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.

    Automatic Synchronization Cycle

    Set the Automatic Synchronization Cycle. Valid values: 1 to 24 hours.

View synchronization records

  1. On the Identity synchronization tab, locate the identity provider and click Synchronize Records in the Actions column.

  2. On the Synchronize Records page, view the synchronization records for the identity provider.

  3. In the Synchronization Task area on the left, click a specific task to view its synchronization details in the list on the right.

    The synchronization task card on the left displays the Task ID, Synchronization Method (manual or automatic), Synchronization Status, Creation Time, End Time, Department Synchronization Count, and User Synchronization Count. The synchronization records table on the right includes columns for Synchronization Time, Action, Task Status, Type, Name, and Actions. You can filter records by type, action, and status, or search by name.

  4. Click Details in the Actions column for a specific record to view its field information from both the Third-party Data Source and the SASE Data Source.

Manual synchronization

If you did not enable Automatic Synchronization during configuration, or if your directory structure has changed, you need to synchronize the information manually. Click Create Synchronization Task and then click OK. After the task is complete, you can view the new synchronization records.

Note

After a successful synchronization, you can view the synchronized organizational structure and user information on the Identity Authentication > Identity Access > Employee Center tab. For more information, see Employee Center.

Disable automatic synchronization

  • On the Identity synchronization page, locate the identity provider and turn off the switch in the Automatic Synchronization column.

  • In the Edit IdP panel, turn off the automatic synchronization switch.

Edit WUYING Workspace identity provider

On the Identity synchronization page, find the relevant WUYING Workspace identity provider and click Edit in the Actions column to update its settings.

Disable WUYING Workspace identity provider

On the Identity synchronization page, find the relevant WUYING Workspace identity provider and turn off the switch in the IdP Status column.

Delete WUYING Workspace identity provider

On the Identity synchronization page, find the relevant WUYING Workspace identity provider and click Delete in the Actions column.

Related documents

Best practices

Configure user-defined identity provider

If your organization does not use any identity provider, you can use the custom identity provider offered by SASE to build your organizational structure. For more information, see Connect to a custom identity provider.

Connect to a third-party identity provider

If your organization already uses an identity provider such as LDAP, DingTalk, WeCom, Lark, or IDaaS to manage the organizational structure, you can connect the identity provider to SASE.

Configure user groups

If you need to create user groups outside your organizational structure, see User group management.