Configure user-based single sign-on (SSO) between Google Workspace (as the enterprise IdP) and Alibaba Cloud. This example covers the end-to-end setup.
Step 1: Get SAML provider metadata from Alibaba Cloud
-
Log on to the RAM console as a RAM administrator.
-
In the left-side navigation pane, choose .
-
Click the User-based SSO tab. In the SAML Service Provider Metadata URL section, copy the metadata URL for your Alibaba Cloud account.
-
Open the copied link in a new browser window and save the metadata XML file locally.
NoteThe metadata XML contains Alibaba Cloud SAML service provider information. Record the value of the
entityIDattribute from theEntityDescriptorelement and the value of theLocationattribute from theAssertionConsumerServiceelement. You need these values to configure Google Workspace.
Step 2: Create a SAML SSO app in Google Workspace
-
Log on to the Google Admin console as a super administrator.
-
In the left-side navigation pane, choose .
-
Click Add app, and then click Add custom SAML app.
-
On the Add custom SAML app page, create an application that supports SAML SSO.
-
On the App details page, enter an app name, for example, AlibabaCloudUserSSO, and then click CONTINUE.
-
On the Google Identity Provider details page, click DOWNLOAD METADATA to download the metadata, and then click CONTINUE.
-
On the Service provider details page, enter the ACS URL and Entity ID, and then click CONTINUE.
-
ACS URL: The
Locationvalue that you recorded in Step 1: Get SAML service provider metadata from Alibaba Cloud. -
Entity ID: The
entityIDvalue that you recorded in Step 1: Get SAML service provider metadata from Alibaba Cloud. -
Start URL: The Alibaba Cloud page users are redirected to after successful SSO.
NoteOnly URLs from Alibaba-owned domains are allowed for Default RelayState (*.aliyun.com, *.hichina.com, *.yunos.com, *.taobao.com, *.tmall.com, *.alibabacloud.com, and *.alipay.com). Invalid URLs are ignored. If empty, you are redirected to the Alibaba Cloud console homepage.
-
-
On the Attribute mapping page, click FINISH.
-
-
On the details page of the created app, click User access.
-
Optional: In the Organizational Units section, select the organizational unit for which you want to enable SSO. By default, the app applies to the entire organization.
-
In the Service status section, select ON for everyone.
NoteIf you specified an organizational unit in step 6, select ON.
-
Click SAVE.
Step 3: Enable user-based SSO in Alibaba Cloud
-
In the left-side navigation pane of the RAM console, choose .
-
Click the User-based SSO tab. In the SSO Status section, click Enabled.
NoteUser-based SSO is a global feature. Once enabled, all RAM users must use SSO to log on. If you are logged on as a RAM user, keep SSO disabled until you create the required RAM users to avoid lockout from configuration errors. Alternatively, log on with your Alibaba Cloud account to perform the configuration.
-
In the Metadata File section, click Upload Metadata File and upload the IdP metadata that you downloaded from Google Workspace in Step 2: Create a SAML SSO app in Google Workspace.
-
In the Auxiliary Domain Name section, click Edit. Then, enable the auxiliary domain name and set it to the email suffix of the Google Workspace usernames.
NoteIf your Google Workspace organization has users with multiple email suffixes, only users whose email addresses end with the specified suffix can log on to Alibaba Cloud.
Step 4: Create a user in Google Workspace
-
In the left-side navigation pane, choose .
-
Click Add new user.
-
On the User Information page, enter the First name, Last name, and Primary email (for example, u2@example.com). Select an Organizational unit, and then click ADD NEW USER.
NoteIf you specified an organizational unit for the app in Step 2: Create a SAML SSO app in Google Workspace, select the same Organizational unit.
Step 5: Create a RAM user in Alibaba Cloud
-
In the left-side navigation pane of the RAM console, choose .
-
On the Users page, click Create User.
-
On the Create User page, enter the Logon Name and Display Name.
NoteMake sure the prefix of the RAM user's logon name matches the username prefix in Google Workspace. In this example, the prefix is
u2. -
In the Access Mode section, select Console Access and configure other parameters, such as the logon password.
-
Click OK.
Verify the result
After configuration, you can initiate SSO from either Alibaba Cloud or Google Workspace.
Log on from Alibaba Cloud (SP-initiated)
-
In the RAM console, on the Overview page, copy the logon URL for RAM users.
-
Hover over your profile picture in the upper-right corner and click log out, or open the copied RAM user logon URL in a new browser window.
-
On the RAM user login page, click Log in with an enterprise account. You are redirected to the Google Workspace login page.
-
On the Google Workspace logon page, enter your username (u2@example.com) and password, and then click Next.
The system logs you in via SSO and redirects you to the specified Start URL page. If no valid Start URL is specified, you are redirected to the Alibaba Cloud console homepage. If this page is displayed, the configuration is successful.
After logging on, click your profile picture in the upper-right corner. In the drop-down list, confirm that the current identity is u2 (labeled RAM user) and the enterprise alias is example. This confirms that the SSO configuration is successful.
Log on from Google Workspace (IdP-initiated)
Log on to Google Workspace and click the app you created in Step 2: Create a SAML SSO app in Google Workspace.
The system logs you in via SSO and redirects you to the specified Start URL page. If no valid Start URL is specified, you are redirected to the Alibaba Cloud console homepage, which indicates that the configuration is successful.