Connect Secure Access Service Edge (SASE) to DingTalk so that enterprise users can log on to SASE directly with their DingTalk accounts. You can then manage user access permissions in SASE to secure your company's data.
Scenarios
SASE helps you manage employee access to private networks and the Internet while protecting corporate data. If you already use DingTalk to manage user information, you can connect SASE to DingTalk. This allows enterprise users to log on to the SASE client directly with their DingTalk accounts, eliminating the need to maintain a separate identity management system for SASE.
Workflow
Prerequisites
You have activated Secure Access Service Edge and installed the SASE client.
The descriptions of DingTalk in this topic refer to operations in the new DingTalk console. Information about the DingTalk Open Platform is for reference only. For more information, see the official DingTalk documentation.
Step 1: Create a DingTalk application and add a homepage URL
1.1 Create a DingTalk application
To synchronize DingTalk data to SASE, you must first create a DingTalk application on the DingTalk Open Platform.
The webhook for DingTalk Robot will be commercialized in phases starting from January 1, 2024. It will be fully commercialized on February 1. The free quota is 5,000 calls per calendar month. For more information, see Announcement on the Commercialization of Free Webhooks.
In the DingTalk application marketplace, you can activate the Alibaba Cloud miniapp to receive free alert pushes through DingTalk. Click Activate Now.
Log on to the DingTalk Open Platform with an administrator account. In the top menu bar, click Application Development.
In the navigation pane on the left, choose Internal Enterprise Applications > DingTalk Applications.
On the DingTalk Applications page, click Create Application.
In the Create Internal Enterprise Application dialog box, set the parameters as described in the following table.
Configuration Item
Description
Example
Application Name
The name of the application.
The name can contain only Chinese characters, uppercase letters, lowercase letters, and digits.
Alibaba Cloud SASE
Application Description
A supplementary description of the application.
Alibaba Cloud SASE
Application Icon
The icon for the application.
Upload an image in JPG or PNG format. The image must be larger than 240 × 240 pixels, have an aspect ratio of 1:1, be smaller than 120 KB, and have no border radius.

Click Create.
1.2 Configure the homepage URL
Add a homepage URL for the Alibaba Cloud SASE application that you created.
On the DingTalk Applications page, click the Alibaba Cloud SASE application that you created.
In the navigation pane on the left, choose Application Capabilities > Web Application.
On the Web Application page, set Application Homepage URL to https://login.aliyuncsas.com/ui/dingAuth/ and click Save.
Step 2: Add API permissions and configure security and sharing settings
2.1 Add API permissions
Add API permissions to synchronize the DingTalk organizational structure and configure a homepage URL for secure access to internal applications.
Log on to the DingTalk Open Platform with an administrator account. In the top menu bar, click Application Development.
In the navigation pane on the left, choose Internal Enterprise Applications > DingTalk Applications.
On the DingTalk Applications page, click the Alibaba Cloud SASE application that you created.
In the navigation pane on the left, click Permission Management.
On the Permission Management page, set the permission scope and grant the following permissions.
Set the permission scope to All Employees.
Personal mobile number information
Read permission for personal information in the address book
Enterprise employee mobile number information
Personal information such as email
Read permission for department information in the address book
Read permission for member information
Read permission for department members in the address book
2.2 Security settings
Configure a callback domain name to allow employees to log on to the SASE client with their DingTalk credentials or by scanning a QR code.
In the navigation pane on the left, choose Development Configuration > Security Settings.
On the Security Settings page, in the Server Egress IP field, enter the IP addresses of servers that are allowed to call the DingTalk server-side API.
Set Redirection URL (Callback Domain) to https://login.aliyuncsas.com/open-dev/dingtalk and click Save.
In the navigation pane on the left, choose Development Configuration > Sharing Settings.
On the Sharing Settings page, in the Logon Integration section, add https://login.aliyuncsas.com/open-dev/dingtalk as the callback domain name.
2.3 Sharing settings
Configure sharing settings to allow users to share content after a one-click logon, facilitating internal collaboration.
On the Sharing Settings page, in the Share Integration section, click Edit. Configure the parameters for iOS Sharing and Android Sharing as described in the following table, and then click Save.
Category | Configuration Item | Value |
iOS Sharing | iOS Bundle ID | com.aliyun.security.saseiosApp |
Android Sharing | Android Package Name | com.aliyun.security.sase |
Android Signature | 294e7d6880381b01ea56d91ee6656ff0 |
Step 3: Connect Secure Access Service Edge to DingTalk data
After you configure DingTalk, connect SASE to DingTalk data through the identity source settings.
Log on to the Secure Access Service Edge console.
In the navigation pane on the left, choose .
On the Identity Synchronization tab, click Add Identity Source.
In the Add Identity Source panel, select DingTalk, click Start Configuration, and complete the configuration in the wizard.
In the Basic Configuration wizard, configure the parameters as described in the following table.
Configuration Item
Description
Example
Identity Source Name
DingTalk name.
The name must be 2 to 100 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
test
Description
The description of the configuration.
This description is displayed as the logon title on the SASE client interface to help you identify the identity source when you log on.
DingTalk logon
Identity Source Status
Configure the status for the identity source. The valid values are:
Enabled: The identity source is enabled after it is created.
Closed: The identity source is disabled after it is created.
ImportantIf you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.
Enabled
CorpId
The unique identifier of an enterprise in DingTalk. You can obtain the CorpId from the homepage of the DingTalk Open Platform.
ding3608be7c4e5266ce4ac5d6980864****
AppKey
The AppKey of the application created in the DingTalk Open Platform. You can obtain the AppKey from the Credentials and Basic Information page of the target application in the DingTalk Open Platform.
dingwjlht8b93ara****
AppSecret
The AppSecret of the application created in the DingTalk Open Platform. You can obtain the AppSecret from the Credentials and Basic Information page of the target application in the DingTalk Open Platform.
1Uji1mEjhmWq_SmE0KNScspYk0bBgDrlZ95vUTR-bn4FbfeVQQKNr1_1giWA****
Advanced Configuration
DingTalk Type: Select Standard DingTalk or Exclusive DingTalk.
Event Subscription: After you configure event subscriptions, the organizational structure of your enterprise employees is synchronized to SASE. This ensures that SASE security policies are updated in a timely manner when the organizational structure is adjusted or employees leave the company.
Encryption aes_key
Obtain the encryption aes_key from the Event Subscription page of the target application in the DingTalk Open Platform.
Encryption token
Obtain the encryption token from the Event Subscription page of the target application in the DingTalk Open Platform.
Encryption aes_key: SRIcwnup1JHFJ4O2SzLS1RtQGJzC3RG2c33AM******
Encryption token: YYwR3A3rV6mrvpC******
Automatic Synchronization
If you enable Automatic Synchronization, the system automatically synchronizes information from DingTalk based on the synchronization mode.
If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see View synchronization records.
Enabled
Synchronize Employee Information
If you enable Synchronize Employee Information, the system automatically synchronizes employee information from DingTalk based on the Automatic Synchronization Epoch.
NoteIf Automatic Synchronization is disabled, the Synchronize Employee Information feature is not executed.
Enabled
Automatic Synchronization Period
Set the Automatic Synchronization Epoch. You can set the interval from 1 hour to 24 hours.
24 hours
The panel also provides the links required for configuration. You can click the links to copy them.
Copy Request URL: This value is used to configure subscription management on the DingTalk Open Platform.
Copy Application Homepage URL: This value is used to view the application details on the DingTalk Open Platform.
Copy Callback Domain Name: This value is used to set the callback domain name on the DingTalk Open Platform.
Click Test Connectivity. After the test is successful, click Next.
NoteIf the connection fails, verify that the server address, server port, and other information are correct.
In the Synchronization Configuration wizard, configure the synchronization scope and field mapping for the organizational structure, and then click Confirm.
Configuration Item
Description
Organizational Structure Synchronization
Configure the scope for synchronizing the organizational structure.
Full Synchronization: Synchronizes the entire DingTalk organizational structure to the SASE system.
Partial Synchronization: Select the organizational structures to synchronize.
Field Synchronization Mapping
Configure the mapping between DingTalk organizational structure fields and SASE synchronization fields.
NoteIf the built-in Mapped Local Fields in the SASE system do not meet your business requirements, you can click View Extended Fields in the upper-right corner of the list. In the View Extended Fields panel, you can add, edit, or delete extended fields.
Step 4: Configure DingTalk event subscriptions
Configure DingTalk event subscriptions so that the application can receive event notifications in real time.
Log on to the DingTalk Open Platform with an administrator account. In the top menu bar, click .
In the navigation pane on the left, choose Internal Enterprise Applications > DingTalk Applications.
On the DingTalk Applications page, click the Alibaba Cloud SASE application that you created.
Configure event subscriptions.
In the navigation pane on the left, click Event Subscription. Set Push Method to HTTP Push. Enter the Encryption aes_key, Signature token, and Request URL. Follow these steps to configure the parameters.
In the Secure Access Service Edge console, find the identity source instance that you created in Step 3. In the Edit Identity Source panel, copy the Request URL and paste it into the Request URL field of the Event Subscription configuration for the application on the DingTalk Open Platform.
Copy the AES encryption key and Signature token that are generated in the Event Subscription section of your application on the DingTalk Open Platform, and paste them into the corresponding AES encryption key and Encryption token fields in the Edit Identity Source panel on the Secure Access Service Edge console. For more information, see the following screenshot of the configuration items.
After the configuration is complete, save the settings for both the identity source and the event subscription.
On the Event Subscription page, select the address book events to enable.
These include User added to address book, User updated in address book, User removed from address book, Department created in address book, Department updated in address book, and Department deleted from address book. For more information about how to configure DingTalk event subscriptions, see Event Subscription.
Step 5: Verify the connection
Open the SASE client that you installed.
Enter the enterprise verification ID and click OK.
You can log on to the Secure Access Service Edge console. In the navigation pane on the left, on the Settings page, obtain the Enterprise Authentication Identifier.
Enter your DingTalk username and password and click Log On, or scan the QR code to log on.
A successful logon indicates that the connection is established.