Dataphin requires login authentication before use. You can integrate your enterprise’s existing authentication system with Dataphin through a supported protocol, allowing users to log in with their enterprise credentials.
Background information
After deployment, Dataphin provides one default login method:
-
Dataphin built-in accounts: Log in using a username and password provided by Dataphin.
-
Alibaba Cloud RAM: Log in using an Alibaba Cloud RAM user account.
Dataphin supports visual SSO configuration and multi-account system login, which simplify manual setup, reduce communication and setup costs, and allow multiple account systems to work simultaneously. For details, see Login Settings.
Scenarios
-
Reduce user management costs: Integrate your enterprise’s authentication system with Dataphin to manage access permissions centrally. Users do not need separate Dataphin accounts, which unifies identity management and reduces overhead.
-
Improve user experience: Users log in to Dataphin with their existing enterprise credentials, without creating separate usernames or passwords.
Function Overview
-
Protocol configuration: Dataphin supports these standard login protocols: CAS, OAuth 2.0, SAML, Alibaba Cloud RAM, and Lark. If your enterprise uses a nonstandard or custom-built internal protocol, Dataphin also supports integration via third-party SSO.
-
Account mapping (for administrators): Some users may already be using Dataphin before you integrate an enterprise login system. To preserve their identities, the administrator must map existing Dataphin users to users in your enterprise login system.
For example, User 1 and User 2 previously logged in with Dataphin’s default method. When you integrate SSO, you must provide their unique IDs in the SSO system to bind their SSO UIDs to their Dataphin UIDs. After SSO login, these users retain their existing Dataphin data.
-
Account binding (for users): When a user logs in to Dataphin and the source UID has not been recorded, the user must choose an identity option on the next login.
-
Select Run as new identity to create a new user in Dataphin. This action cannot be undone. Choose carefully.
-
Select Associate with existing account to link your current account with an existing account from another login method. You must log in again to complete the association.
-