All Products
Search
Document Center

Data Management:Log on to DMS with domain accounts

Last Updated:Aug 27, 2026

You can use your enterprise's identity system to log on to the Alibaba Cloud Management Console by configuring user-based single sign-on (SSO) or role-based SSO. SSO is also known as identity federation.

Background

Alibaba Cloud supports SAML 2.0-based single sign-on (SSO), also known as identity federation. This section introduces basic concepts of Security Assertion Markup Language (SAML) and single sign-on (SSO).

Concept

Description

Identity provider (IdP)

A RAM entity that contains metadata about an external identity provider. An IdP can provide identity management services.

  • Enterprise on-premises IdP: Microsoft Active Directory Federation Service (AD FS), Shibboleth, and others.

  • Cloud IdP: IDaaS, Microsoft Entra ID, Google Workspace, Okta, OneLogin, and others.

Service provider (SP)

An application that uses the identity management capabilities of an IdP to provide services to users. The SP uses the user information provided by the IdP. Some non-SAML protocol-based identity systems, such as OpenID Connect, also refer to the service provider as a relying party of the IdP.

Security Assertion Markup Language (SAML 2.0)

A standard protocol for enterprise-level user authentication. SAML 2.0 is one of the technical implementations for communication between SPs and IdPs. SAML 2.0 has become a de facto standard for enterprise-level SSO.

SAML assertion

The core elements used to describe authentication requests and responses in the SAML protocol. For example, specific user attributes are included in the assertion of an authentication response.

Trust

A mutual trust mechanism established between an SP and an IdP, typically implemented using public and private keys. The SP obtains the SAML metadata of the IdP through a trusted method. The metadata contains the public key used by the IdP to sign SAML assertions. The SP uses this public key to verify the integrity of the assertions.

OIDC

OpenID Connect (OIDC) is built on top of OAuth 2.0. OAuth is an authorization protocol, and OIDC adds an identity layer on top of OAuth. In addition to the authorization capabilities provided by OAuth, OIDC also allows clients to authenticate end users and retrieve basic user information through OIDC protocol APIs (HTTP RESTful).

OIDC token

OIDC can issue identity tokens on behalf of logged-in users, known as OIDC tokens. OIDC tokens are used to retrieve basic information about logged-in users.

Client ID

When your application is registered with an external IdP, a client ID is generated. You must use this client ID when requesting an OIDC token from the external IdP. The issued OIDC token also carries this client ID in the aud field. Configure this client ID when creating the OIDC identity provider. When using an OIDC token to exchange for an STS token, Alibaba Cloud verifies whether the client ID in the aud field of the OIDC token matches the client ID configured in the OIDC identity provider. Only a match allows the role assumption.

Verification fingerprint

To prevent the issuer URL from being maliciously hijacked or tampered with, you need to configure a verification fingerprint generated from the HTTPS CA certificate of the external IdP. Alibaba Cloud helps you automatically calculate this fingerprint, but we recommend that you calculate it locally (for example, Obtain an OIDC IdP thumbprint with OpenSSL). Compare it with the fingerprint calculated by Alibaba Cloud. If they do not match, the issuer URL may have been compromised. Confirm and enter the correct fingerprint.

Issuer URL

The issuer URL is provided by the external IdP and corresponds to the iss field value in the OIDC token. The issuer URL must start with https and conform to the standard URL format. Query parameters (identified by ?), fragments (identified by #), and login information (identified by @) are not allowed.

Temporary identity credential

Security Token Service (STS) is a temporary access credential management service provided by Alibaba Cloud. Through STS, you can obtain temporary identity credentials (STS tokens) with customizable validity periods and access permissions.

SSO methods

You can use a SAML 2.0-compliant enterprise identity provider (IdP), such as AD FS, to implement single sign-on (SSO) with Alibaba Cloud. Alibaba Cloud offers two SSO methods that are based on the SAML 2.0 protocol:

  • User-based SSO: Alibaba Cloud uses the SAML assertion from the identity provider (IdP) to map an enterprise user to a RAM user. After logging on, the enterprise user accesses Alibaba Cloud as that RAM user.

  • Role-based SSO: Alibaba Cloud uses the SAML assertion from the identity provider (IdP) to determine which RAM role an enterprise user can assume. After logging on, the enterprise user accesses Alibaba Cloud by assuming the RAM role that is specified in the SAML assertion.

For a detailed comparison of user-based SSO and role-based SSO, see Use cases for SSO methods.

Procedure

Synchronize RAM users

After configuring single sign-on (SSO), an administrator must navigate to the O&M > Users page in the Data Management Service (DMS) console and click Synchronize RAM User to add RAM users to DMS in batches. For more information, see Add a user.

Note

DMS automatically assigns the DMS administrator role to any RAM user with the AdministratorAccess permission. All other RAM users are assigned the regular user role. For more information about DMS system roles, see System roles.

Example

This example shows the result of configuring single sign-on (SSO) from Microsoft AD to Alibaba Cloud.

  1. Go to the Alibaba Cloud logon page and click Sign in as RAM User at the bottom.

  2. Enter your Alibaba Cloud username and click Next.

  3. Follow the prompts to complete the logon process.

  4. In the list of products, click Data Management Service (DMS).

    On the Alibaba Cloud Management Console home page, navigate to the Products & Services tab. In the My Shortcuts section, click Data Management Service (DMS) in the Recently Visited list.