SASE uses identity-driven security policies. If your organization uses a WeCom identity source to manage its organizational structure, you can connect that identity source to SASE. This eliminates the need to create separate identity information for your employees. After you connect the WeCom identity source, employees can use their existing corporate accounts to log in to the SASE App. This topic describes how to connect a WeCom identity source.
Limitations
You can enable a maximum of five identity sources at the same time, and only one of them can be a custom identity source. If you reach this limit, you must disable an existing identity source before you can enable a new one.
Configure a WeCom identity source
-
Log in to the SASE console.
-
In the left-side navigation pane, choose .
-
On the Identity synchronization tab, click Create IdP.
-
In the Create IdP panel, select WeCom, and then click Configure and configure the parameters.
Parameter
Description
IdP Name
The name of the WeCom identity source.
The name must be 2 to 100 characters in length and can contain Chinese characters, letters, digits, hyphens (-), and underscores (_).
Description
A description of the configuration.
This description appears as the login title in the SASE client to identify the identity source during login.
IdP Status
Configure the status for the identity source. The valid values are:
Enabled: The identity source is enabled after it is created.
Closed: The identity source is disabled after it is created.
ImportantIf you disable an identity source, end users cannot use the SASE app to access internal applications. Proceed with caution.
Automatic Synchronization
After you enable Automatic Synchronization, the system automatically synchronizes information from WeCom.
If you do not enable Automatic Synchronization, you must manually synchronize the organizational structure. For more information, see Synchronization records.
Synchronize User Information
After you enable Synchronize User Information, the system automatically synchronizes employee information from WeCom at the interval set for the Automatic Synchronization Cycle.
NoteIf Automatic Synchronization is disabled, the Synchronize User Information feature does not take effect.
Automatic Synchronization Cycle
Set the Automatic Synchronization Cycle. You can set the interval to a value from 1 hour to 24 hours.
-
Click Obtain Authorization QR Code and scan the QR code with a WeCom administrator account to grant permissions.
-
After successful authorization, the new WeCom identity source appears on the Identity synchronization tab.
-
Click Edit in the Actions column. In the Edit IdP panel, configure the Schema value and, as needed, configure Automatic Synchronization, Synchronize User Information, and LOGO. Then click Next.
ImportantTo obtain the Schema value, submit a ticket to contact SASE engineers.
-
In the Synchronization Settings wizard, configure the synchronization scope and field mappings. Then, click Ok.
Parameter
Description
Organizational Structure Synchronization
Configure the synchronization scope for the organizational structure.
-
Synchronize All: Synchronizes the entire organizational structure from WeCom to SASE.
-
Partially Synchronize: Select the specific organizational units that you want to synchronize.
Field Synchronization Mapping
Configure the mappings between fields of the WeCom organizational structure and the SASE synchronization fields.
NoteIf the built-in Local Field After Mapping options in SASE do not meet your needs, you can click View Extended Fields in the upper-right corner of the list. In the View Extended Fields panel, you can add, edit, or delete extension fields.
-
After you add the WeCom identity source, an SASE application is automatically created in WeCom. You must set the Visibility Scope for the SASE application in WeCom to ensure that the organizational structure synchronizes to the SASE application. For more information, see How to set the visibility scope for third-party applications.
View synchronization records
-
On the Identity synchronization tab, locate the identity provider and click Synchronize Records in the Actions column.
-
On the Synchronize Records page, view the synchronization records for the identity provider.
-
In the Synchronization Task area on the left, click a specific task to view its synchronization details in the list on the right.
The synchronization task card on the left displays the Task ID, Synchronization Method (manual or automatic), Synchronization Status, Creation Time, End Time, Department Synchronization Count, and User Synchronization Count. The synchronization records table on the right includes columns for Synchronization Time, Action, Task Status, Type, Name, and Actions. You can filter records by type, action, and status, or search by name.
-
Click Details in the Actions column for a specific record to view its field information from both the Third-party Data Source and the SASE Data Source.
Manual synchronization
If you did not enable Automatic Synchronization during configuration, or if your directory structure has changed, you need to synchronize the information manually. Click Create Synchronization Task and then click OK. After the task is complete, you can view the new synchronization records.
After a successful synchronization, you can view the synchronized organizational structure and user information on the tab. For more information, see Employee Center.
Disable automatic synchronization
-
On the Identity synchronization page, locate the identity provider and turn off the switch in the Automatic Synchronization column.
-
In the Edit IdP panel, turn off the automatic synchronization switch.
Edit WeCom identity source
On the Identity synchronization page, find the WeCom identity source and click Edit in the Actions column to modify its information.
Disable WeCom identity source
On the Identity synchronization page, find the WeCom identity source and turn off the switch in the IdP Status column.
Delete WeCom identity source
On the Identity synchronization page, find the WeCom identity source and click Delete in the Actions column to delete it.
Related documents
Configure a custom identity source
If your organization does not use an identity source, you can use the custom identity source provided by SASE to establish an organizational structure. For more information, see Connect a custom identity source.
Connect a third-party identity source
If your organization uses an identity source such as LDAP, DingTalk, WeCom, Lark, or IDaaS to manage its organizational structure, you can connect that identity source to SASE.
Configure a user group
If you need to create user groups outside of your main organizational structure, see User group management.