Connect Alibaba Cloud IDaaS to DingTalk to synchronize your organizational structure and users from DingTalk. This integration enhances the efficiency and security of your enterprise identity management.
Use cases
Alibaba Cloud IDaaS uses identity providers (IdPs) to manage connections to your existing identity systems. As an Alibaba Cloud product, DingTalk offers a seamless, native integration with IDaaS. The connection process is straightforward, taking about two minutes to complete by scanning a QR code and granting authorization. This simple configuration provides the following capabilities:
|
Category |
Capabilities |
|
Accounts |
|
|
Sign-in |
|
|
Applications |
|
Two methods for connecting to DingTalk
From the Identity Providers menu, add DingTalk as an identity provider and enable its features during the setup process.
Alibaba Cloud IDaaS supports two methods for importing data from DingTalk:
|
Method |
Description |
|
Third-party application method (quick connect) |
Uses the DingTalk third-party application solution. You can complete the configuration by scanning a QR code to grant authorization. Pros: Simple and fast configuration. Note
No information entry is required. Scan the QR code and grant authorization to complete the setup. Cons: Cannot retrieve user mobile numbers and email addresses in bulk. This information must be entered by an administrator or authorized by users during sign-in. |
|
First-party application method (advanced configuration) |
Builds on the third-party application method. This requires a DingTalk administrator to create a first-party application, grant the corresponding permissions, and configure the application information in Alibaba Cloud IDaaS. Pros: Flexible permissions and access to complete user information. Cons: Longer configuration process. |
Quick connection to DingTalk
In the Quick Start or IdPs menu, click Bind DingTalk to begin the quick connection process for inbound provisioning.
Step 1: Select features
In the first step, select the features you want to enable for the DingTalk integration. If you have no preference, proceed to the next step.
Feature descriptions
-
Sync Target: Specifies the destination node in Alibaba Cloud IDaaS where DingTalk address book data is imported.
-
Incremental Sync: When enabled, Alibaba Cloud IDaaS calls the DingTalk API to listen for address book events. Any changes in the DingTalk address book are synchronized to Alibaba Cloud IDaaS in real time.
-
You can define a mapping identifier in the field mapping settings. Use a field from the Alibaba Cloud IDaaS account (for example, a mobile number) to match a corresponding field from the DingTalk user (such as a mobile number). If a match is found, the existing IDaaS account is updated. Otherwise, a new account is created.
-
We recommend that you perform a full synchronization before enabling incremental synchronization. Otherwise, some data may fail to synchronize.
-
If a single account fails to import, the import of other accounts is not affected.
-
You can view failure information by clicking Details.
-
-
DingTalk QR code logon: If selected, a DingTalk QR code logon method is created and enabled in the Login menu. This allows users to immediately log on by scanning a QR code.
-
Trigger a full sync: If selected, all data within the authorized scope of the DingTalk address book is imported after the connection is complete.
Step 2: Scan to activate
In this step, a DingTalk administrator must scan the QR code to activate the free third-party application for the DingTalk enterprise.
The page displays a QR code and instructions. If the application is already activated, you can directly click Confirm application activated, Next to proceed to the binding step.
After scanning the QR code, the administrator is redirected to the application activation page in DingTalk. Follow the on-screen instructions to activate the application. The process involves clicking Activate for Free, selecting the scope of use, clicking Activate Now, and then clicking Open Application to complete the binding.
After the connection is complete, if you need to adjust the scope of the DingTalk address book that is synchronized to Alibaba Cloud IDaaS, modify the settings for the Alibaba Cloud IDaaS application on the DingTalk Admin Console - Application Management. Alibaba Cloud IDaaS uses the authorization scope of this application during synchronization.
Step 3: Scan to connect
In the final step, the DingTalk administrator must click the DingTalk Admin Scan to Bind button within the application, then scan the QR code from this step and confirm. This completes the connection. Alibaba Cloud IDaaS then performs a full or incremental synchronization based on your configuration, and users can log on to IDaaS by using the DingTalk QR code logon.
Manage DingTalk identity provider
After connecting DingTalk, you are automatically redirected to the IdPs menu. Here, you can manage the features of the identity provider. The management panel is organized into three functional areas: QR Scan Sign-In, Sync to IDaaS, and Advanced Configuration. Each area can be enabled or disabled independently and provides links for actions such as View Logs, Trigger Sync, and Modify.
-
Check import status
-
Import notification: If you selected Push/Pull Now during the connection process, the status Importing... is displayed on the page. Click Logs to go to the Synchronization Tasks page and monitor the progress.
-
Handle missing mobile numbers/email addresses: After synchronization is complete, a notification appears on the IdPs page. Imported accounts can immediately use DingTalk QR code logon for Alibaba Cloud IDaaS or its applications. However, newly imported accounts are missing mobile numbers or email addresses. We recommend that users add this information to enable features such as two-factor authentication and password recovery. For more information, see DingTalk QR code logon.
-
-
Modify the sync target: If you change the sync target, you must manually trigger a full synchronization and verify that the organizational structure is updated as expected.
-
DingTalk QR code logon: If you enabled the DingTalk Scan to Log On Version method during connection, Alibaba Cloud IDaaS creates a corresponding logon method in the Login menu. You can manage this feature from either the Identity Providers or the Login menu. Users can then go to the logon page to sign in by scanning the QR code. For more information, see DingTalk QR code logon.
-
Connect multiple DingTalk organizations: Alibaba Cloud IDaaS supports connecting to multiple DingTalk address books. To do this, an administrator from each DingTalk enterprise must complete the activation and connection process. When managing multiple enterprises, you may want to synchronize their accounts to different target nodes to keep them separate. For example, to import address books from Enterprise A and Enterprise B into Alibaba Cloud IDaaS, we recommend that you first create Organization A and Organization B under the root node of your IDaaS organizational structure. Then, during the connection process, specify that Enterprise A syncs to Organization A, and Enterprise B syncs to Organization B. Note that a single DingTalk enterprise can only be connected to one Alibaba Cloud IDaaS instance. Support for connecting one DingTalk enterprise to multiple IDaaS instances may be added in a future release.
Enable DingTalk advanced configuration
After connecting DingTalk, you can enable advanced configuration on the identity provider page to retrieve complete user information from DingTalk.
If you use DingTalk Enterprise and have the exclusive account feature enabled, Alibaba Cloud IDaaS cannot retrieve mobile numbers from these accounts due to the security design of DingTalk Enterprise. To use mobile numbers, an administrator must add them on the console, or employees must add them manually in the application portal.
In the Advanced Configuration section of the identity provider management panel, click the Disabled toggle to enable advanced configuration.
Step 1: Select features
Currently, no configuration options are available in this step. You can proceed to the next step.
Step 2: Create application
In this step, you need to configure the application details from DingTalk in Alibaba Cloud IDaaS. The page displays three configuration fields: CorpId (pre-filled), AppKey, and AppSecret.
Log on to the DingTalk Open Platform - In-house Enterprise Development and click Add Application to enter the basic information for your internal application.
In the Create an in-house enterprise application dialog box, set Application Type to H5 microapp, enter an Application Name and Application Description, select Enterprise Self-development for Development Mode, and then click Create.
After the application is created, you are automatically redirected to its details page in DingTalk. Copy the AppKey and AppSecret and paste them into the corresponding fields in Alibaba Cloud IDaaS.
These credentials can be found in the Application Credentials section of the application details page.
After entering the information, click Complete Authorization. Alibaba Cloud IDaaS tests the connection to DingTalk. If the information is correct, you can proceed to the Next step.
Step 3: Assign permissions
In this step, you need to assign permissions within the DingTalk application. Click Permission Management, select all permissions under both User Base Management and Application Management, and then click Batch Request.
For the permission scope, select All Employees. If you need to adjust the scope of the DingTalk address book that is synchronized to Alibaba Cloud IDaaS, modify the settings for the Alibaba Cloud IDaaS application on the DingTalk Admin Console - Application Management. Alibaba Cloud IDaaS uses the authorization scope of this application during synchronization.
After granting the authorization, click the Confirm Authorization button in Alibaba Cloud IDaaS. IDaaS verifies that the application has the required DingTalk address book management permissions. If the check passes, the configuration is complete, and Alibaba Cloud IDaaS can then retrieve information such as employee mobile numbers and email addresses.
If you want to restrict access so that only Alibaba Cloud IDaaS can make requests to this DingTalk application, you can specify the egress IP address in the Security Setting of the application page in DingTalk. You can enter multiple IP addresses separated by commas, in IPv4, wildcard IPv4, IPv6, or IPv6 CIDR format. Because this application is for data synchronization, not daily employee use, enter any valid URL for the Application Homepage URL.
Step 4: Adjust field mapping (optional)
Use Field Mapping to configure rules for using DingTalk data (like mobile numbers and email addresses) as fields in an Alibaba Cloud IDaaS account, or to bind a DingTalk user to an IDaaS account with a matching mobile number.