If you want employees to sign in to an Agent application with their IDaaS identities, configure the IDaaS application identity service as the SSO identity source for a user pool. You can also synchronize IDaaS accounts to the Agent Identity user pool for centralized management. Follow these steps to configure the integration, SSO sign-in, user synchronization, and configuration verification.
Capabilities
The Application Identity Service IDaaS identity source supports the following capabilities. Enable them independently as needed:
SSO Sign-in: Set IDaaS as the SSO identity source for a user pool to centrally manage the sign-in entry point for Agent applications.
User Sync: Set the synchronization scope by account, group, or organization to synchronize IDaaS users to the user pool for centralized management.
SSO sign-in and user synchronization can use different identity sources. A user pool can have only one SSO identity source enabled at a time. User synchronization can coexist with other synchronization sources.
Prerequisites
Before you begin, complete the following prerequisites:
A user pool has been created.
The
AliyunAgentIdentityFullAccesssystem policy has been granted to the RAM user or role used by the operator.An account with IDaaS administrative permissions is available.
Connect IDaaS
The first connection creates a dedicated IDaaS instance, an inbound application for the current user pool, and the related configuration. Before you connect, make sure that the account has IDaaS administrative permissions.
Sign in to the Agent Identity console.
In the left navigation pane, select Inbound > User Pool.
Open the target user pool and select Identity Providers.
On the IDaaS card, click Configure.
If the page shows Not Configured, click Connect IDaaS.
-
After the page shows that the connection is configured, reopen the configuration page to view the following information:
Instance ID: The IDaaS instance connected to the current user pool.
Inbound Application ID: The inbound application in IDaaS that corresponds to the current user pool.
Multiple user pools can reuse the same IDaaS instance, but each user pool has a separate inbound application. The connection workflow creates these applications. Don't modify or delete them manually in the IDaaS console.
Configure SSO sign-in
After you enable SSO sign-in, IDaaS becomes the SSO identity source for the user pool. Before you enable it, make sure that switching identity sources won't affect existing sign-in entry points.
On the user pool's Identity Providers page, find IDaaS.
Turn on SSO Sign-in.
If another SSO identity source is already enabled, confirm the switch as prompted.
Click Configure and verify that the instance ID and inbound application ID are correct. Return to the identity source page and verify that the SSO Sign-in switch is on.
Configure user synchronization
After you enable user synchronization, set the synchronization scope by account, group, or organization. User synchronization can coexist with other synchronization sources.
On the IDaaS card, turn on User Sync.
Click Configure. In the User Synchronization Configuration area, click Set Sync Principals.
Click Add User to go to the IDaaS account management page, where you can create accounts and organizations.
Return to the Configure Synchronization Scope page and click the refresh icon button on the right. After the information refreshes, select the organizations or groups to synchronize.
Verify the selected organizational information and click Run IDaaS Sync Job.
Select View IDaaS Sync Logs to open the synchronization logs in the IDaaS console. The logs show information about the synchronization task, such as the start time, end time, trigger method, and result description.
To view task details on the IDaaS side, click View IDaaS Sync Logs.
Select Users to view the target user's UserType and status. The UserType value is Sync from IDaaS, and the status is Enabled.
Verify the configuration
After you finish the configuration, check the following items:
Identity source status: The IDaaS card displays the current configuration.
SSO Sign-in: If SSO sign-in is enabled, the switch on the identity source card is on.
User Sync: If user synchronization is enabled, the switch on the identity source card is on.
Object relationship: The configuration details show the correct IDaaS instance and the inbound application that corresponds to the current user pool.
Synchronization scope: The accounts, groups, or organizations in the list match the configured scope.
Synchronized users: After synchronization, the user list shows the target users, their user synchronization types, and their statuses.