All Products
Search
Document Center

Secure Access Service Edge:Administrator guide for initial private access setup

Last Updated:Jul 17, 2026

Learn how the private access feature works and how to quickly set it up after you enable SASE (Secure Access Service Edge).

Private access security

Private access is a SaaS-based zero-trust network access feature built on software-defined perimeter (SDP) technology. With the SASE private access solution, employees can securely reach cloud-based business resources over a private network while you manage their access permissions — without exposing public IP addresses or modifying the existing network architecture.

image

Procedure

Step 1: Configure an identity provider (IdP)

An identity provider (IdP) handles identity authentication for enterprise employees. SASE supports third-party and self-built authentication systems, including LDAP, DingTalk, WeChat Work, Feishu, IDaaS, and custom identity providers. If your business uses multiple IdPs, you can configure each one and enable its authentication status to use the SASE service with different IdPs.

To quickly test the feature, this topic uses a custom IdP as an example.

  1. Log on to the SASE console.

  2. In the left-side navigation pane, choose Identity Authentication > Identity Access.

  3. On the Identity synchronization tab, find the Custom IdP, click Actions in the Edit column, and follow the on-screen instructions to configure the custom IdP. For more information, see Connect to a custom identity provider.

  4. On the User Group Management tab, click Create User Group.

  5. In the Create User Group panel, configure information for the user group, such as Organizational Structure, Account Name, Email Address, and Mobile Phone Number. Then, click OK. For more information, see User group management.

Step 2: Configure a user group

When you configure a policy, you must specify the user group to which the policy applies.

  1. In the navigation pane on the left, choose Identity Authentication > Identity Access.

  2. On the User Group Management tab, click Create User Group.

  3. In the Create User Group pane, configure the Organizational Structure, Account Name, Email Address, and Mobile Phone Number for the user group. Then, click OK. For more information, see User Group Management.

Step 2: Configure a private application

In SASE, a private application represents an internal IT resource, such as an application, server, or database, that does not require a public IP address. To access a private application, employees must use a device with the SASE client installed and pass identity and security policy checks.

  1. In the navigation pane on the left, choose Private Access > Application Management.

  2. On the Office Application page, in the Custom Tags section, click Add, set a tag name, and then click OK.

    You can add up to 100 custom tags.

  3. Click Add Application and configure the application by following these steps.

    If you have a DNS server for resolving your enterprise's internal CIDR blocks, you can click Internal DNS Configuration. In the DNS Address dialog box, manually enter the Default DNS Service and Other DNS Services. The default DNS group (each DNS group can contain up to two DNS server IP addresses) is pushed to the SASE client as the primary enterprise DNS. Employees can switch DNS groups on the client to meet specific access requirements.

    If you do not configure a DNS service, SASE automatically configures an Alibaba Cloud DNS server to resolve your enterprise's internal CIDR blocks. If Alibaba Cloud DNS PrivateZone is configured, it is prioritized for IP or domain name resolution.

    1. On the Manual Configuration tab, configure the following parameters.

      Parameter

      Description

      Example

      Application Name

      The name of the private application.

      The name must be 1 to 128 characters in length and can contain Chinese characters, letters, digits, hyphens (-), underscores (_), and periods (.).

      Attendance Management Application

      Description

      The description of the private application.

      Attendance management address for employees

      Tag

      A custom tag for the application, which helps you classify, search for, and manage applications.

      OA System

      Status

      The access status of the application. Valid values:

      • Enable: The application is available.

      • Disable: The application is unavailable.

      Enable

    2. Click Next and configure the following address and port information.

      Parameter

      Description

      Example

      Application Address

      The private access address of the application. You can define applications or resources by using IP addresses, CIDR blocks, domain names, and wildcard domain names. Multiple private access addresses can be set for a single application.

      10.10.1.100

      Port

      The port number or port range used by the application.

      80-200

      Protocol

      The protocol of the application. Valid values: All Protocols, TCP, and UDP.

      All Protocols

Step 3: Establish a network connection

Before you establish a network connection, confirm your current service deployment and select the appropriate connection solution.

Service deployment environment

Solution

Environment requirements

Enterprise services and resources are deployed on Alibaba Cloud

Use the network configuration feature to establish network connections between specified Alibaba Cloud VPC resources and SASE end users.

On the Network Configuration > Alibaba Cloud Services page, enable the network connection for the VPC where the target service server is located.

Requirements for office computers:

  • Windows (64-bit, 32-bit, .msi 64-bit, .msi 32-bit): Windows 7 or later

  • macOS: macOS 10.10 or later

  • Linux: Ubuntu 18.04 or later, UOS

Enterprise services and resources are deployed in a non-Alibaba Cloud environment, such as AWS or Tencent Cloud, and an Alibaba Cloud Virtual Border Router (VBR), Cloud Connect Network (CCN), or VPN Gateway is already used for network connectivity.

Use Alibaba Cloud network channels, such as Leased Lines, SAG, or IPsec-VPN, to allow SASE clients to access service resources in non-Alibaba Cloud environments.

On the Network Configuration > Non-Alibaba Cloud Services > Cloud Network Instance tab, configure the origin fetch VPC and enable the network connection.

Requirements for office computers:

  • Windows (64-bit, 32-bit, .msi 64-bit, .msi 32-bit): Windows 7 or later

  • macOS: macOS 10.10 or later

  • Linux: Ubuntu 18.04 or later, UOS

Enterprise services and resources are deployed in a non-Alibaba Cloud environment

SASE provides a connector feature that you can use to connect to your non-Alibaba Cloud network. This lets you use the SASE app to access services in the non-Alibaba Cloud environment.

This method does not depend on other network products for network access.

On the Network Configuration > Non-Alibaba Cloud Services > Connector List tab, manually add an SASE connector. Then, run commands to deploy the connector and ensure that the connector instance is enabled.

Requirements for office computers:

  • Windows (64-bit, 32-bit, .msi 64-bit, .msi 32-bit): Windows 7 or later

  • macOS: macOS 10.10 or later

  • Linux: Ubuntu 18.04 or later, UOS

Server requirements for deploying the connector:

  • Virtual machine or server configuration:

    • CPU: 4 cores

    • Memory: 8 GB

    • Disk: 40 GB

    • Operating system: CentOS 7 or later

  • Network configuration: The server must be able to access the Internet. If a firewall is configured, you must allow outbound traffic on ports 443 and 8000 for the server or virtual machine on which the connector is deployed.

  • Specification limit: 200 MB of traffic forwarding.

  • Port requirements: Ensure that ports 9000 to 9010 are not occupied.

This topic uses business resources deployed in a non-Alibaba Cloud environment as an example.

  1. In the left-side navigation pane, choose Private Access > Network Settings.

  2. On the Network Settings page, click Services Outside Alibaba Cloud.

  3. Add and deploy a connector.

    1. On the Connectors tab, click Add Connector.

      You can add up to five connectors.

    2. In the Add Connector panel, configure the parameters based on your business requirements. Then, click OK.

      Parameter

      Description

      Example

      Region

      The region of the connector. For optimal access quality, select the region closest to your server.

      China (Beijing)

      Instance Name

      The name of the connector.

      private-access-connector-for-company-A

      Instance Switch

      SASE end users can access applications associated with the connector only when the instance is Enable.

      Important

      If you disable the Instance Switch, end users cannot access private applications by using the SASE client. Proceed with caution.

      Enabled

      In the left-side navigation pane, choose Private Access > Network Configuration, and click the Non-Alibaba Cloud Services tab. In the Connector List section, you can view the added connector instances and their status, and add new connectors by clicking Add Connector.

  4. Install and deploy the connector.

    1. In the Actions column, click Deploy. In the Deploy panel, copy the deployment command for the connector.

      curl -sSL https://sase-app.oss-cn-hangzhou.aliyuncs.com/connector.default.sh | ALIUID=1637xxxx0585 CODE=AE854025xxxxDB714E2C INSTANCE_ID=connector-09fcxxxxd8ba bash
    2. Log on to the server or virtual machine on which you want to deploy the connector as the root user and run the command.

Step 4: Create a zero trust policy

A zero trust policy controls access by mapping user groups to specific applications. By default, all access is denied. You must create Allow policies to grant users access to applications.

  1. In the left-side navigation pane, choose Private Access > Access Control.

  2. On the Zero Trust Policies tab, click Create Policy.

  3. In the Create Policy panel, configure the following parameters, and then click OK.

    You can create an unlimited number of zero trust policies based on your business requirements.

    Parameter

    Description

    Example

    Policy Name

    The name of the zero trust policy.

    The name must be 2 to 100 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).

    Allow policy for attendance app

    Description

    The description of the zero trust policy.

    All users can access the attendance management application.

    Priority

    A number that determines the evaluation order. A lower number indicates a higher priority (1 is the highest). Policies are evaluated from highest to lowest priority.

    If policies conflict, the policy with the higher priority takes effect.

    1

    Action

    The action of the policy. Valid values:

    • Allow Access: The policy allows users or devices to access the specified application.

    • Access Denied: The policy denies users or devices from accessing the specified application.

    Allow

    Applicable User

    The policy is applied to the endpoint devices of users in the specified user groups. SASE then allows or blocks matching access behaviors accordingly.

    Click Add. On the User Group tab, select the user group to which the policy applies. If the current user groups do not meet your needs, you can configure a new one on the Custom User Group tab. For more information about how to configure user groups, see User group management.

    All employees of the company

    Selected Applications

    The applications that are allowed or denied based on the Action setting.

    Click Add. On the Tag tab, select the specified applications based on the configured tags. You can also select applications directly on the Application tab.

    Attendance Management Application

    Security Baselines

    Select a security baseline template that meets your enterprise's requirements.

    -

    Policy Status

    Set the status of the policy.

    Enabled

Step 5: Verify the configuration

  1. Open the SASE client that you have installed.

  2. Enter the enterprise verification ID and click OK.

    You can log on to the Secure Access Service Edge console. In the navigation pane on the left, on the Settings page, obtain the Enterprise Authentication Identifier.

  3. Log on by using the initial username and password that you received by email or phone.

  4. Click Connect to Private Network.

  5. Access the enterprise attendance management application.

    If you can access the application, the configuration is successful.