All Products
Search
Document Center

Secure Access Service Edge:Securing WeCom user access with SASE

Last Updated:Sep 14, 2026

By connecting SASE (Secure Access Service Edge) to WeCom, your enterprise users can log in to SASE by using their WeCom accounts. This allows you to manage access permissions for WeCom users in SASE and secure your corporate data. This topic describes how to connect SASE to WeCom.

Use cases

SASE helps you manage employee access to internal networks and the internet, and protect corporate data to meet the daily security needs of your enterprise. If you already use WeCom to manage your company's user information, you can connect SASE with WeCom. This allows users to log in to the SASE client directly with their WeCom accounts, eliminating the need to maintain a separate identity management system for SASE and reducing your user information maintenance costs.

Prerequisites

You have enabled SASE and installed the SASE client. For more information, see Apply for a free trial and Setup.

Note

The WeCom platform information in this topic is for reference only. For the most accurate information, refer to the official WeCom documentation.

Step 1: Connect SASE and WeCom

You need to establish a connection with WeCom data in the identity source management feature of SASE.

  1. Log on to the SASE console.

  2. In the left-side navigation pane, choose Identity Authentication > Identity Access.

  3. On the Identity synchronization tab, click Create IdP.

  4. In the Create IdP panel, select WeCom, click Configure, and configure the following parameters.

    Parameter

    Description

    Example

    IdP Name

    A name for the WeCom IdP.

    The name must be 2 to 100 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).

    test_123

    Description

    A description for the configuration.

    This description is displayed as the logon title on the SASE client to help users identify the IdP.

    WeCom data source

    IdP Status

    Configure the status for the identity source. The valid values are:

    • Enabled: The identity source is enabled after it is created.

    • Closed: The identity source is disabled after it is created.

      Important

      If you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.

    Enabled

    Automatic Synchronization

    After you enable the Automatic Synchronization switch, the system will automatically synchronize relevant information from WeCom based on the synchronization mode.

    If you have not enabled Automatic Synchronization, you need to manually synchronize the organizational structure. For more information, see View Synchronization Records.

    Enabled

    Synchronize User Information

    After you turn on the Synchronize User Information switch, the system will automatically synchronize employee information from WeCom based on the Automatic Synchronization Cycle.

    Note

    If the Automatic Synchronization feature is not enabled, the Synchronize User Information function is not performed.

    Enabled

    Automatic Synchronization Cycle

    Set the Automatic Synchronization Cycle. You can set an automatic synchronization to run once every 1 to 24 hours.

    24 hours

  5. Click Obtain Authorization QR Code and use a WeCom administrator account to scan the resulting QR code to grant authorization.

  6. After successful authorization, view the new WeCom IdP on the Identity synchronization tab.

  7. In the Actions column, click Edit. In the Edit IdP panel, enter the Schema value, and then click Next.

    Important

    You can obtain the Schema value by submitting a ticket to contact an SASE engineer. Example value: wwauth4151efa784c9324d00****.

  8. In the Synchronization Settings wizard, configure the synchronization scope and field mappings, and then click OK.

    Parameter

    Description

    Organizational Structure Synchronization

    The scope for organizational structure synchronization.

    • Synchronize All: Synchronizes the entire WeCom organizational structure to the SASE system.

    • Partially Synchronize: Synchronizes selected parts of the organizational structure.

    Field Synchronization Mapping

    Configure the mapping between WeCom organizational structure fields and SASE synchronization fields.

    Note

    If the built-in Local Field After Mapping in the SASE system do not meet your business requirements, you can click View Extended Fields in the upper-right corner of the list. In the View Extended Fields panel, you can add, edit, or delete extended fields.

Adding a WeCom IdP automatically creates a self-built SASE application in WeCom. You need to set the visibility scope of the SASE application in WeCom to ensure that the WeCom organizational structure is synchronized to the created SASE application. For more information, see How to set the visibility scope of a third-party application.

Step 2: Verify the integration

Once the connection is set up, your users can log on to the SASE client by using their WeCom accounts.

  1. Open the installed SASE app.

  2. Enter the enterprise verification ID and click OK.

    You can log on to the Secure Access Service Edge console. In the navigation pane on the left, on the Settings page, obtain the Enterprise Authentication Identifier.

  3. Enter your WeCom account credentials and click Log On.

    A successful logon indicates that the integration is working.