You can use your enterprise's identity system to log on to the Alibaba Cloud Management Console by configuring user-based single sign-on (SSO) or role-based SSO. SSO is also known as identity federation.
Background
Alibaba Cloud supports SAML 2.0-based single sign-on (SSO), also known as identity federation. This section introduces basic concepts of Security Assertion Markup Language (SAML) and single sign-on (SSO).
Concept | Description |
Identity provider (IdP) | A RAM entity that contains metadata about an external identity provider. An IdP can provide identity management services.
|
Service provider (SP) | An application that uses the identity management capabilities of an IdP to provide services to users. The SP uses the user information provided by the IdP. Some non-SAML protocol-based identity systems, such as OpenID Connect, also refer to the service provider as a relying party of the IdP. |
Security Assertion Markup Language (SAML 2.0) | A standard protocol for enterprise-level user authentication. SAML 2.0 is one of the technical implementations for communication between SPs and IdPs. SAML 2.0 has become a de facto standard for enterprise-level SSO. |
SAML assertion | The core elements used to describe authentication requests and responses in the SAML protocol. For example, specific user attributes are included in the assertion of an authentication response. |
Trust | A mutual trust mechanism established between an SP and an IdP, typically implemented using public and private keys. The SP obtains the SAML metadata of the IdP through a trusted method. The metadata contains the public key used by the IdP to sign SAML assertions. The SP uses this public key to verify the integrity of the assertions. |
OIDC | OpenID Connect (OIDC) is built on top of OAuth 2.0. OAuth is an authorization protocol, and OIDC adds an identity layer on top of OAuth. In addition to the authorization capabilities provided by OAuth, OIDC also allows clients to authenticate end users and retrieve basic user information through OIDC protocol APIs (HTTP RESTful). |
OIDC token | OIDC can issue identity tokens on behalf of logged-in users, known as OIDC tokens. OIDC tokens are used to retrieve basic information about logged-in users. |
Client ID | When your application is registered with an external IdP, a client ID is generated. You must use this client ID when requesting an OIDC token from the external IdP. The issued OIDC token also carries this client ID in the |
Verification fingerprint | To prevent the issuer URL from being maliciously hijacked or tampered with, you need to configure a verification fingerprint generated from the HTTPS CA certificate of the external IdP. Alibaba Cloud helps you automatically calculate this fingerprint, but we recommend that you calculate it locally (for example, Obtain an OIDC IdP thumbprint with OpenSSL). Compare it with the fingerprint calculated by Alibaba Cloud. If they do not match, the issuer URL may have been compromised. Confirm and enter the correct fingerprint. |
Issuer URL | The issuer URL is provided by the external IdP and corresponds to the |
Temporary identity credential | Security Token Service (STS) is a temporary access credential management service provided by Alibaba Cloud. Through STS, you can obtain temporary identity credentials (STS tokens) with customizable validity periods and access permissions. |
SSO methods
You can use a SAML 2.0-compliant enterprise identity provider (IdP), such as AD FS, to implement single sign-on (SSO) with Alibaba Cloud. Alibaba Cloud offers two SSO methods that are based on the SAML 2.0 protocol:
-
User-based SSO: Alibaba Cloud uses the SAML assertion from the identity provider (IdP) to map an enterprise user to a RAM user. After logging on, the enterprise user accesses Alibaba Cloud as that RAM user.
-
Role-based SSO: Alibaba Cloud uses the SAML assertion from the identity provider (IdP) to determine which RAM role an enterprise user can assume. After logging on, the enterprise user accesses Alibaba Cloud by assuming the RAM role that is specified in the SAML assertion.
For a detailed comparison of user-based SSO and role-based SSO, see Use cases for SSO methods.
Procedure
-
User-based SSO: For more information, see Overview of user-based SSO.
The following topics provide configuration examples for implementing user-based SSO with common enterprise IdPs, such as AD FS, Okta, and Microsoft Entra ID:
-
Role-based SSO: For more information, see Overview of SAML role-based SSO.
The following topics provide configuration examples for implementing role-based SSO with common enterprise IdPs, such as AD FS, Okta, and Microsoft Entra ID:
Synchronize RAM users
After configuring single sign-on (SSO), an administrator must navigate to the page in the Data Management Service (DMS) console and click Synchronize RAM User to add RAM users to DMS in batches. For more information, see Add a user.
DMS automatically assigns the DMS administrator role to any RAM user with the AdministratorAccess permission. All other RAM users are assigned the regular user role. For more information about DMS system roles, see System roles.
Example
This example shows the result of configuring single sign-on (SSO) from Microsoft AD to Alibaba Cloud.
-
Go to the Alibaba Cloud logon page and click Sign in as RAM User at the bottom.
-
Enter your Alibaba Cloud username and click Next.
-
Follow the prompts to complete the logon process.
-
In the list of products, click Data Management Service (DMS).
On the Alibaba Cloud Management Console home page, navigate to the Products & Services tab. In the My Shortcuts section, click Data Management Service (DMS) in the Recently Visited list.