All Products
Search
Document Center

Cloud Config:Enable SSO for RAM users

Last Updated:Jun 23, 2026

This rule evaluates RAM users as compliant if SSO is enabled.

Use cases

User SSO applies to the following scenarios:

  • Require Service Provider (SP)-initiated SSO, where users start the logon process from the Alibaba Cloud console logon page rather than from your IdP portal.

  • Access Alibaba Cloud services that do not support RAM roles (that is, access through Security Token Service (STS)). For the list of services that support RAM role access, see Services that work with STS.

  • Work with an IdP that does not support complex attribute configuration.

  • Keep your IdP configuration simple — user-based SSO requires less setup than role-based SSO and covers most standard access scenarios.

Risk level

Default risk level: Medium.

You can change the risk level based on your business requirements.

Detection logic

  • A RAM user is compliant if SSO is enabled.

  • A RAM user is non-compliant if SSO is not enabled. To remediate this issue, see Remediation.

Rule details

Parameter

Description

Rule name

SSO enabled for RAM users

Rule identifier

ram-user-sso-enabled

Tag

SSO, RAM, User

Automatic remediation

Not supported

Trigger type

Periodic execution

Evaluation frequency

24 hours

Supported resource type

All resource types

Input parameter

None

Remediation

Enable SSO for the RAM user. For detailed instructions, see User SSO overview.