All Products
Search
Document Center

Secure Access Service Edge:SASE client login-free best practices

Last Updated:Jun 21, 2026

This topic describes how to use the identity authentication feature to enable auto-sign-in for the SASE client to improve user experience and access efficiency.

Prerequisites

  • You have activated SASE. If you have not activated SASE, you need to purchase and activate the service. For more information, see Purchase service. You can also apply for a 7-day free trial. For more information, see Apply for a free trial.

  • The SASE client installed on your corporate endpoints is version 4.8.5 or later.

  • If your enterprise uses a corporate identity source to manage its organizational structure, you must first complete identity synchronization and enable the identity source to sync the organizational structure. This allows employees to log on to the SASE client by using their unified corporate identity. You must also enable the custom identity source.

    Note

    After activating SASE, SASE automatically creates a custom identity source for you. In the navigation pane, choose Identity Authentication > Identity Access. On the Identity synchronization tab, you can enable the custom identity source. You can also add users to the custom identity source on the Employee Center tab. For more information, see Employee Center.

Procedure

Step 1: Enable the auto-sign-in policy

After you enable this feature, the client can run without requiring a sign-in. Devices that are not associated with an identity source connect using an anonymous identity, while data protection and endpoint protection policies still apply. To apply internal network access policies, users must sign in manually.

  1. Log on to the SASE console.

  2. In the navigation pane, choose Identity Authentication > Identity Access.

  3. On the Authentication Management tab, click Single Sign-On Policy.

  4. In the Client Auto-Sign-In Policy panel, enable the policy, configure the scope, and view the affected devices.

    Parameter

    Description

    Enable Client Auto-Sign-In

    Enables the client auto-sign-in policy.

    Scope of Automatic Sign-In

    • All Devices: Applies to all devices in the platform's terminal list, including manually imported company devices. After the policy takes effect, these devices will come online with an anonymous identity. Custom identity source authentication must be enabled. You can view enterprise terminal information by choosing Endpoint Management > Terminals in the left-side navigation pane.

    • Authenticated Devices: Applies to all devices for which device authentication is configured in an extension authentication source. After the policy takes effect, these devices sign in as the device owner through auto-sign-in.

    Automatic Sign-In Status

    The devices affected by this policy. You can click the device count to go to the Terminals page and view information about the affected devices.

  5. Click OK.

Step 2: Add an Extended Authentication Source

Auto-sign-in requires information about the sign-in devices and users. If you set the Scope of Automatic Sign-In to All Devices when you configure the policy, SASE automatically creates an Extended Authentication Source. All devices in the Terminals list can then use auto-sign-in without additional operations. If you select Authenticated Devices, you must manually create an Extended Authentication Source and upload a template with device and user information to complete the configuration.

  1. On the Identity Authentication tab, click Extended Authentication Source in the upper-right corner.

  2. On the Extended Authentication Source page, click Add Extended Authentication Source.

  3. In the Add panel, configure the Extended Authentication Source based on the following table, and then click OK.

    Parameter

    Description

    Authentication Source Name

    The name of the Extended Authentication Source.

    The name must be 2 to 100 characters long and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).

    Description

    The description of the configuration.

    This description is displayed as the sign-in title in the SASE client to help you identify the authentication source during sign-in.

    Extended Authentication Source Configuration > Authentication Source Type

    Set Authentication Source Type to Device Authentication.

    1. Click Download Import Template and fill in the device information (MAC address, serial number, and hostname) and user information (name, phone number, and email address) for the devices that will use auto-sign-in.

      In the Associated Identity Source section, select an identity source from the Select identity source drop-down list.

    2. Drag and drop a file or click to browse to upload the template to SASE.

      Note

      If the uploaded file contains duplicate information for a device, auto-sign-in is not enabled for that device.

    Associated IdP

    Select an existing identity source.

    Important

    SASE matches the device and user information that you upload with the information in the associated identity source. If any of the device information matches, a password-free login is enabled for the client. Furthermore, if the user information also matches, the corresponding username is displayed after you log on to the client. If the user information does not match, the username is displayed as anonymous (Company Employee).

Step 3: Sign in to the client

  1. Open the installed SASE client.

  2. Enter your enterprise ID and click Ok to automatically sign in. If the user information does not match, the client displays the username as Employee.