All Products
Search
Document Center

Secure Access Service Edge:Secure DingTalk user access with Secure Access Service Edge

Last Updated:Sep 20, 2026

Connect Secure Access Service Edge (SASE) to DingTalk so that enterprise users can log on to SASE directly with their DingTalk accounts. You can then manage user access permissions in SASE to secure your company's data.

Scenarios

SASE helps you manage employee access to private networks and the Internet while protecting corporate data. If you already use DingTalk to manage user information, you can connect SASE to DingTalk. This allows enterprise users to log on to the SASE client directly with their DingTalk accounts, eliminating the need to maintain a separate identity management system for SASE.

Workflow

image

Prerequisites

You have activated Secure Access Service Edge and installed the SASE client.

Important

The descriptions of DingTalk in this topic refer to operations in the new DingTalk console. Information about the DingTalk Open Platform is for reference only. For more information, see the official DingTalk documentation.

Step 1: Create a DingTalk application and add a homepage URL

1.1 Create a DingTalk application

To synchronize DingTalk data to SASE, you must first create a DingTalk application on the DingTalk Open Platform.

Note
  • The webhook for DingTalk Robot will be commercialized in phases starting from January 1, 2024. It will be fully commercialized on February 1. The free quota is 5,000 calls per calendar month. For more information, see Announcement on the Commercialization of Free Webhooks.

  • In the DingTalk application marketplace, you can activate the Alibaba Cloud miniapp to receive free alert pushes through DingTalk. Click Activate Now.

  1. Log on to the DingTalk Open Platform with an administrator account. In the top menu bar, click Application Development.

  2. In the navigation pane on the left, choose Internal Enterprise Applications > DingTalk Applications.

  3. On the DingTalk Applications page, click Create Application.

  4. In the Create Internal Enterprise Application dialog box, set the parameters as described in the following table.

    Configuration Item

    Description

    Example

    Application Name

    The name of the application.

    The name can contain only Chinese characters, uppercase letters, lowercase letters, and digits.

    Alibaba Cloud SASE

    Application Description

    A supplementary description of the application.

    Alibaba Cloud SASE

    Application Icon

    The icon for the application.

    Upload an image in JPG or PNG format. The image must be larger than 240 × 240 pixels, have an aspect ratio of 1:1, be smaller than 120 KB, and have no border radius.

    图标

  5. Click Create.

1.2 Configure the homepage URL

Add a homepage URL for the Alibaba Cloud SASE application that you created.

  1. On the DingTalk Applications page, click the Alibaba Cloud SASE application that you created.

  2. In the navigation pane on the left, choose Application Capabilities > Web Application.

  3. On the Web Application page, set Application Homepage URL to https://login.aliyuncsas.com/ui/dingAuth/ and click Save.

Step 2: Add API permissions and configure security and sharing settings

2.1 Add API permissions

Add API permissions to synchronize the DingTalk organizational structure and configure a homepage URL for secure access to internal applications.

  1. Log on to the DingTalk Open Platform with an administrator account. In the top menu bar, click Application Development.

  2. In the navigation pane on the left, choose Internal Enterprise Applications > DingTalk Applications.

  3. On the DingTalk Applications page, click the Alibaba Cloud SASE application that you created.

  4. In the navigation pane on the left, click Permission Management.

  5. On the Permission Management page, set the permission scope and grant the following permissions.

    Set the permission scope to All Employees.

    • Personal mobile number information

    • Read permission for personal information in the address book

    • Enterprise employee mobile number information

    • Personal information such as email

    • Read permission for department information in the address book

    • Read permission for member information

    • Read permission for department members in the address book

2.2 Security settings

Configure a callback domain name to allow employees to log on to the SASE client with their DingTalk credentials or by scanning a QR code.

  1. In the navigation pane on the left, choose Development Configuration > Security Settings.

  2. On the Security Settings page, in the Server Egress IP field, enter the IP addresses of servers that are allowed to call the DingTalk server-side API.

  3. Set Redirection URL (Callback Domain) to https://login.aliyuncsas.com/open-dev/dingtalk and click Save.

  4. In the navigation pane on the left, choose Development Configuration > Sharing Settings.

  5. On the Sharing Settings page, in the Logon Integration section, add https://login.aliyuncsas.com/open-dev/dingtalk as the callback domain name.

2.3 Sharing settings

Configure sharing settings to allow users to share content after a one-click logon, facilitating internal collaboration.

On the Sharing Settings page, in the Share Integration section, click Edit. Configure the parameters for iOS Sharing and Android Sharing as described in the following table, and then click Save.

Category

Configuration Item

Value

iOS Sharing

iOS Bundle ID

com.aliyun.security.saseiosApp

Android Sharing

Android Package Name

com.aliyun.security.sase

Android Signature

294e7d6880381b01ea56d91ee6656ff0

Step 3: Connect Secure Access Service Edge to DingTalk data

After you configure DingTalk, connect SASE to DingTalk data through the identity source settings.

  1. Log on to the Secure Access Service Edge console.

  2. In the navigation pane on the left, choose Identity Authentication > Identity Access.

  3. On the Identity Synchronization tab, click Add Identity Source.

  4. In the Add Identity Source panel, select DingTalk, click Start Configuration, and complete the configuration in the wizard.

  5. In the Basic Configuration wizard, configure the parameters as described in the following table.

    Configuration Item

    Description

    Example

    Identity Source Name

    DingTalk name.

    The name must be 2 to 100 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).

    test

    Description

    The description of the configuration.

    This description is displayed as the logon title on the SASE client interface to help you identify the identity source when you log on.

    DingTalk logon

    Identity Source Status

    Configure the status for the identity source. The valid values are:

    • Enabled: The identity source is enabled after it is created.

    • Closed: The identity source is disabled after it is created.

      Important

      If you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.

    Enabled

    CorpId

    The unique identifier of an enterprise in DingTalk. You can obtain the CorpId from the homepage of the DingTalk Open Platform.

    ding3608be7c4e5266ce4ac5d6980864****

    AppKey

    The AppKey of the application created in the DingTalk Open Platform. You can obtain the AppKey from the Credentials and Basic Information page of the target application in the DingTalk Open Platform.

    dingwjlht8b93ara****

    AppSecret

    The AppSecret of the application created in the DingTalk Open Platform. You can obtain the AppSecret from the Credentials and Basic Information page of the target application in the DingTalk Open Platform.

    1Uji1mEjhmWq_SmE0KNScspYk0bBgDrlZ95vUTR-bn4FbfeVQQKNr1_1giWA****

    Advanced Configuration

    DingTalk Type: Select Standard DingTalk or Exclusive DingTalk.

    Event Subscription: After you configure event subscriptions, the organizational structure of your enterprise employees is synchronized to SASE. This ensures that SASE security policies are updated in a timely manner when the organizational structure is adjusted or employees leave the company.

    • Encryption aes_key

      Obtain the encryption aes_key from the Event Subscription page of the target application in the DingTalk Open Platform.

    • Encryption token

      Obtain the encryption token from the Event Subscription page of the target application in the DingTalk Open Platform.

    • Encryption aes_key: SRIcwnup1JHFJ4O2SzLS1RtQGJzC3RG2c33AM******

    • Encryption token: YYwR3A3rV6mrvpC******

    Automatic Synchronization

    If you enable Automatic Synchronization, the system automatically synchronizes information from DingTalk based on the synchronization mode.

    If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.

    Enabled

    Synchronize Employee Information

    If you enable Synchronize Employee Information, the system automatically synchronizes employee information from DingTalk based on the Automatic Synchronization Epoch.

    Note

    If Automatic Synchronization is disabled, the Synchronize Employee Information feature is not executed.

    Enabled

    Automatic Synchronization Period

    Set the Automatic Synchronization Epoch. You can set the interval from 1 hour to 24 hours.

    24 hours

    The panel also provides the links required for configuration. You can click the links to copy them.

  6. Click Test Connectivity. After the test is successful, click Next.

    Note

    If the connection fails, verify that the server address, server port, and other information are correct.

  7. In the Synchronization Configuration wizard, configure the synchronization scope and field mapping for the organizational structure, and then click Confirm.

    Configuration Item

    Description

    Organizational Structure Synchronization

    Configure the scope for synchronizing the organizational structure.

    • Full Synchronization: Synchronizes the entire DingTalk organizational structure to the SASE system.

    • Partial Synchronization: Select the organizational structures to synchronize.

    Field Synchronization Mapping

    Configure the mapping between DingTalk organizational structure fields and SASE synchronization fields.

    Note

    If the built-in Mapped Local Fields in the SASE system do not meet your business requirements, you can click View Extended Fields in the upper-right corner of the list. In the View Extended Fields panel, you can add, edit, or delete extended fields.

Step 4: Configure DingTalk event subscriptions

Configure DingTalk event subscriptions so that the application can receive event notifications in real time.

  1. Log on to the DingTalk Open Platform with an administrator account. In the top menu bar, click Application Development.

  2. In the navigation pane on the left, choose Internal Enterprise Applications > DingTalk Applications.

  3. On the DingTalk Applications page, click the Alibaba Cloud SASE application that you created.

  4. Configure event subscriptions.

    1. In the navigation pane on the left, click Event Subscription. Set Push Method to HTTP Push. Enter the Encryption aes_key, Signature token, and Request URL. Follow these steps to configure the parameters.

      1. In the Secure Access Service Edge console, find the identity source instance that you created in Step 3. In the Edit Identity Source panel, copy the Request URL and paste it into the Request URL field of the Event Subscription configuration for the application on the DingTalk Open Platform.

      2. Copy the AES encryption key and Signature token that are generated in the Event Subscription section of your application on the DingTalk Open Platform, and paste them into the corresponding AES encryption key and Encryption token fields in the Edit Identity Source panel on the Secure Access Service Edge console. For more information, see the following screenshot of the configuration items.

      3. After the configuration is complete, save the settings for both the identity source and the event subscription.

    2. On the Event Subscription page, select the address book events to enable.

      These include User added to address book, User updated in address book, User removed from address book, Department created in address book, Department updated in address book, and Department deleted from address book. For more information about how to configure DingTalk event subscriptions, see Event Subscription.

Step 5: Verify the connection

  1. Open the SASE client that you installed.

  2. Enter the enterprise verification ID and click OK.

    You can log on to the Secure Access Service Edge console. In the navigation pane on the left, on the Settings page, obtain the Enterprise Authentication Identifier.

  3. Enter your DingTalk username and password and click Log On, or scan the QR code to log on.

    A successful logon indicates that the connection is established.