This document describes how to implement single sign-on (SSO) to IDaaS applications in WeCom Workbench, including creating applications in IDaaS, creating applications and configuring the homepage address in WeCom, and verifying SSO.
Prerequisites
Before starting the configuration, ensure that you have completed the following preparations:
You have activated Alibaba Cloud IDaaS EIAM Service.
You have a WeCom account with administrator permissions.
The target application supports integration with SAML 2.0 protocol or OAuth 2.0 protocol.
Procedure
Step 1: Create an application in IDaaS
This topic uses Alibaba Cloud SASE as an example.
Log on to the IDaaS console, select the corresponding IDaaS instance, and click Manage in the Operation column.
Select , search for Alibaba Cloud SASE application and click Add Application.
Obtain the ID from the General tab. This ID will be used to construct the homepage URL for WeCom single sign-on.
Click the tab.
SSO: Ensure that single sign-on is in the Enabled status.
Select site: China site.
User: Prioritize application account, then IDaaS username.
Authorize: Select accessible to all members.
Application Settings: Download the IdP metadata and upload it as the SASE "SAML Metadata Configuration File" to complete the SSO configuration.
After completing the configuration, click the Save button. For more information, see Alibaba Cloud SASE SSO.
Step 2: Create an application in WeCom admin console
Log on to the WeCom admin console, and create a self-built enterprise application in .
Fill in the application information.
Application Logo: Upload an application logo. We recommend using a 750×750 jpg or png image under 1MB.
Application Name: Enter the name to be displayed for the application on the platform.
Application Description: Briefly describe the function and purpose of the application.
Visibility: Select the departments or members who can use this application. After completing the form, click the Create Application button to submit.
Set the application homepage address on the application details page.
Click Settings to navigate to the Set Workbench Application Homepage page.
Select the Web option, and click Configure Mobile And Desktop Separately.
Enter the mobile and desktop URLs. Both need to be constructed with the application address in the following format:
https://{IDaaS User Portal Address}/login/go/{IDaaS Application ID} # Example: https://of5*****.aliyunidaas.com/login/go/app_nbryes3eewn***************For information about how to obtain the IDaaS user portal address, see IDaaS Portal Access Methods.
For information about how to obtain the IDaaS application ID, see Step 1: Obtain the Application ID.
Select the option to always enter the homepage in the WeChat plugin. When selected, members will always enter the enterprise-configured homepage when clicking the application in WeChat. After completing the configuration, click OK.
Step 3: Verify SSO
Click the created application in the WeCom Workbench.
If the login is successful, you will directly enter the target application interface without needing to enter your username and password again.