Connect Secure Access Service Edge (SASE) to WeCom so your enterprise users can log on to SASE directly with their WeCom accounts—no separate identity system to maintain.
What this integration supports
SSO via WeCom: Users log on to the SASE client with their existing WeCom credentials.
Automatic org sync: SASE periodically pulls the organizational structure and employee information from WeCom based on a configurable sync cycle (1–24 hours).
Selective sync: Choose to sync your entire WeCom org or a specific subset.
Field mapping: Map WeCom org fields to SASE fields, with support for custom extension fields.
Getting the Schema value (required for sync) requires submitting a ticket to an SASE engineer. Plan for this before starting the configuration.
WeCom platform information in this topic is for reference only. For authoritative details, see the official WeCom documentation.
Prerequisites
Before you begin, make sure you have:
An activated SASE subscription. See Apply for a free trial.
The SASE client installed. See Use the settings feature.
Connect SASE to WeCom
Step 1: Configure SASE in the console
Log on to the SASE console.
In the left navigation pane, choose Identity Authentication > Identity Access.
On the Identity synchronization tab, click Create IdP.
In the Create IdP panel, select WeCom, click Configure, and set the following parameters.
ImportantDisabling IdP Status prevents end users from using the SASE App to access internal applications. Proceed with caution.
Parameter Description Example IdP Name Name for this identity source. 2–100 characters. Allowed: Chinese characters, letters, digits, hyphens (-), and underscores (_). test_123Description Displayed as the logon title on the SASE client. Helps users identify the identity source at sign-in. WeCom data sourceIdP Status Whether the identity source is active after creation. Enabled: active. Closed: disabled. Enabled Automatic Synchronization When enabled, SASE syncs org data from WeCom automatically. When disabled, you must trigger syncs manually. See Connect an LDAP IdP to SASE for manual sync instructions. Enabled Synchronize User Information When enabled, SASE syncs employee information from WeCom on each Automatic Synchronization Cycle. Has no effect if Automatic Synchronization is disabled. Enabled Automatic Synchronization Cycle How often SASE pulls data from WeCom. Valid range: 1–24 hours. 24 hours Click Obtain Authorization QR Code. Use a WeCom administrator account to scan the QR code and grant permissions.
After authorization succeeds, the new WeCom identity source appears on the Identity synchronization tab.
In the Actions column, click Edit. In the Edit IdP panel, set the Schema value, then click Next.
ImportantGet the Schema value from an SASE engineer by submitting a ticket. The value follows the format
wwauth4151efa784c9324d00****.In the Synchronization Settings wizard, configure the sync scope and field mappings, then click OK.
Parameter Description Organizational Structure Synchronization Synchronize All: syncs the entire WeCom org to SASE. Partially Synchronize: select which parts of the org to sync. Field Synchronization Mapping Maps WeCom org fields to SASE fields. To add, edit, or delete custom fields, click View Extended Fields in the upper-right corner.
Step 2: Set the visibility range in WeCom
After you save the configuration, SASE automatically creates a self-managed application in WeCom. For the WeCom org structure to sync correctly, set the Visibility Range for this application in WeCom.
See How to set the visibility range of a third-party application in the WeCom documentation.
Verify the connection
After completing the setup, test the integration by logging on to SASE with a WeCom account.
Open the SASE App.
Enter your enterprise ID and click Confirm. To find your enterprise ID, log on to the SASE console and go to Settings. Obtain the Enterprise Authentication Identifier value.
Enter your WeCom account and password, then click Log On.
A successful logon confirms the integration is working.