All Products
Search
Document Center

Resource Access Management:Configure SAML on Alibaba Cloud for user SSO

Last Updated:Jun 03, 2026

Configure SAML 2.0 metadata to establish trust between Alibaba Cloud and your identity provider (IdP), enabling RAM users to log on to Alibaba Cloud through user-based SSO.

Background

Setting a default logon suffix, custom logon suffix, or auxiliary domain name simplifies SAML SSO configuration. You can configure logon suffixes in Manage RAM user logon settings or Create and verify a custom logon suffix.

Procedure

  1. Log on to the RAM console as a RAM administrator.

  2. In the left-side navigation pane, choose Integrations > SSO.

  3. Click the User-based SSO tab and configure SSO settings.

    • SSO Status: Select Enabled or Disabled.

      • Disabled (default): RAM users log on with passwords. SSO settings are ignored.

      • Enabled: All RAM users must authenticate through your IdP. Password-based logon is disabled.

      Note

      User-based SSO is a global setting. Once enabled, all RAM users must log on through SSO. This does not affect Alibaba Cloud account logon or AccessKey-based API calls.

    • Metadata File: Click Upload Metadata File to upload your IdP metadata file.

      Note

      Your IdP provides this XML file, which contains the IdP logon service URL and the X.509 public key certificate used to verify SAML assertions.

    • Auxiliary Domain Name (Optional): Specify an auxiliary domain name.

      • An auxiliary domain name can serve as the suffix for the NameID element in the SAML assertion.

      • Without an auxiliary domain name, the NameID element must use the account's default or custom logon suffix.

      Valid NameID values are described in SAML response for user-based SSO.

      Note

      If both a custom logon suffix and an auxiliary domain name are configured, the custom logon suffix takes precedence. The NameID element must use either the custom or default logon suffix.

Next steps

After you configure SAML, create RAM users that match users in your IdP: