Alibaba Cloud IDaaS EIAM (Cloud Identity Service) is available on the DingTalk marketplace as part of the cloud-DingTalk integration. Use this guide to activate, start a free trial of, or purchase IDaaS Enterprise Edition directly from DingTalk.
IDaaS offers a Free Edition and an Enterprise Edition. The Free Edition is available through the Alibaba Cloud IDaaS console. The Enterprise Edition delivers the same product capabilities in both DingTalk and Alibaba Cloud.
Core capabilities
Enterprise identity connector
Many enterprises manage employees, permissions, computers, and networks using systems such as Active Directory (AD) or OpenLDAP — but that data cannot natively sync with the DingTalk address book. As a result, account changes in those upstream systems do not flow through automatically.
IDaaS solves this with free, no-code synchronization. When an employee joins or leaves the company, their account and organization data syncs from AD or OpenLDAP to the DingTalk address book automatically. One change applies everywhere.
Enterprise application pass
Enterprises typically run a mix of Software as a Service (SaaS), open-source, and self-developed applications. Integrating all of them with the DingTalk Workbench for single sign-on (SSO) is often difficult, leaving employees to manage multiple sets of credentials.
IDaaS extends DingTalk's SSO capabilities by integrating hundreds of mainstream applications into the DingTalk Workbench — without any development work. Employees sign in once with a single account and access all authorized applications without a password.
Enterprise security shield
IDaaS consolidates complex application usage and management workflows into four unified nodes. Each node includes built-in security features that provide multi-layered protection: pre-event prevention, in-event blocking, and post-event tracing.
Prerequisites
Before you begin, make sure you have:
A DingTalk administrator account (required for Steps 1 and 2)
The DingTalk PC client installed
An Alibaba Cloud account (required for Steps 3 and 4)
Purchase procedure
The process spans two platforms. Steps 1 and 2 are completed in DingTalk; Steps 3 and 4 are completed in the Alibaba Cloud console.
| Step | Platform | Action |
|---|---|---|
| Step 1 | DingTalk | Activate IDaaS from the DingTalk marketplace |
| Step 2 | DingTalk | Get an activation code |
| Step 3 | Alibaba Cloud | Create an IDaaS instance |
| Step 4 | Alibaba Cloud | Apply the activation code to upgrade the instance |
Step 1: Activate IDaaS in DingTalk
In the DingTalk PC client, go to App Center > System Integration and find Alibaba Cloud IDaaS, or search for it directly. Open the product page and activate the application for free.
Step 2: Get an activation code from DingTalk
The activation code links your DingTalk purchase to your Alibaba Cloud instance. When you open the IDaaS application as a DingTalk administrator, the IDaaS Activation Code Management page appears by default.
Only DingTalk administrators can access the IDaaS Activation Code Management page.
On this page, purchase an activation code or start a free trial. The activation code is a randomly generated number that refreshes every hour — copy it from the right side of the list before proceeding.
Step 3: Create an IDaaS instance
In the Alibaba Cloud IDaaS console, go to Alibaba Cloud IDaaS consoleAlibaba Cloud IDaaS consoleEIAM Cloud Identity Service and create a free instance. After the instance is created, click Access Console to open it.
Step 4: Activate the IDaaS instance
On the Quick Start page of your instance, click Use Activation Code in the lower-right corner. Enter the activation code you copied from DingTalk, then click OK.
Renewal and upgrade
When you open the IDaaS application in DingTalk as an administrator, the IDaaS Activation Code Management page appears by default. If you cannot access this page, ask a DingTalk administrator to grant you the required permissions.
On this page, you can purchase an activation code. What happens next depends on your current activation code status:
If you have an Enterprise Edition activation code with a Normal status: purchasing the same specifications counts as a renewal; purchasing higher specifications counts as an upgrade. Both apply to the existing activation code.
If you do not have an Enterprise Edition activation code with a Normal status: the purchase is treated as a new purchase. Return to the Alibaba Cloud IDaaS console to activate the instance again.
What's next
After activating the Enterprise Edition, follow these guides to configure identity management:
Create an account — sync AD accounts to DingTalk, set up DingTalk QR code sign-in, and enable SSO for Workbench applications