This topic describes how to use the identity authentication feature to enable auto-sign-in for the SASE client to improve user experience and access efficiency.
Prerequisites
-
You have activated SASE. If you have not activated SASE, you need to purchase and activate the service. For more information, see Purchase service. You can also apply for a 7-day free trial. For more information, see Apply for a free trial.
-
The SASE client installed on your corporate endpoints is version 4.8.5 or later.
-
If your enterprise uses a corporate identity source to manage its organizational structure, you must first complete identity synchronization and enable the identity source to sync the organizational structure. This allows employees to log on to the SASE client by using their unified corporate identity. You must also enable the custom identity source.
NoteAfter activating SASE, SASE automatically creates a custom identity source for you. In the navigation pane, choose . On the Identity synchronization tab, you can enable the custom identity source. You can also add users to the custom identity source on the Employee Center tab. For more information, see Employee Center.
Procedure
Step 1: Enable the auto-sign-in policy
After you enable this feature, the client can run without requiring a sign-in. Devices that are not associated with an identity source connect using an anonymous identity, while data protection and endpoint protection policies still apply. To apply internal network access policies, users must sign in manually.
-
Log on to the SASE console.
-
In the navigation pane, choose .
-
On the Authentication Management tab, click Single Sign-On Policy.
-
In the Client Auto-Sign-In Policy panel, enable the policy, configure the scope, and view the affected devices.
Parameter
Description
Enable Client Auto-Sign-In
Enables the client auto-sign-in policy.
Scope of Automatic Sign-In
-
All Devices: Applies to all devices in the platform's terminal list, including manually imported company devices. After the policy takes effect, these devices will come online with an anonymous identity. Custom identity source authentication must be enabled. You can view enterprise terminal information by choosing in the left-side navigation pane.
-
Authenticated Devices: Applies to all devices for which device authentication is configured in an extension authentication source. After the policy takes effect, these devices sign in as the device owner through auto-sign-in.
Automatic Sign-In Status
The devices affected by this policy. You can click the device count to go to the Terminals page and view information about the affected devices.
-
-
Click OK.
Step 2: Add an Extended Authentication Source
Auto-sign-in requires information about the sign-in devices and users. If you set the Scope of Automatic Sign-In to All Devices when you configure the policy, SASE automatically creates an Extended Authentication Source. All devices in the Terminals list can then use auto-sign-in without additional operations. If you select Authenticated Devices, you must manually create an Extended Authentication Source and upload a template with device and user information to complete the configuration.
-
On the Identity Authentication tab, click Extended Authentication Source in the upper-right corner.
-
On the Extended Authentication Source page, click Add Extended Authentication Source.
-
In the Add panel, configure the Extended Authentication Source based on the following table, and then click OK.
Parameter
Description
Authentication Source Name
The name of the Extended Authentication Source.
The name must be 2 to 100 characters long and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
Description
The description of the configuration.
This description is displayed as the sign-in title in the SASE client to help you identify the authentication source during sign-in.
Set Authentication Source Type to Device Authentication.
-
Click Download Import Template and fill in the device information (MAC address, serial number, and hostname) and user information (name, phone number, and email address) for the devices that will use auto-sign-in.
In the Associated Identity Source section, select an identity source from the Select identity source drop-down list.
-
Drag and drop a file or click to browse to upload the template to SASE.
NoteIf the uploaded file contains duplicate information for a device, auto-sign-in is not enabled for that device.
Associated IdP
Select an existing identity source.
ImportantSASE matches the device and user information that you upload with the information in the associated identity source. If any of the device information matches, a password-free login is enabled for the client. Furthermore, if the user information also matches, the corresponding username is displayed after you log on to the client. If the user information does not match, the username is displayed as
anonymous(Company Employee). -
Step 3: Sign in to the client
-
Open the installed SASE client.
-
Enter your enterprise ID and click Ok to automatically sign in. If the user information does not match, the client displays the username as Employee.