How to Configure SAML Authentication for Alibaba Cloud (User-Based SSO)

Item

Details

Prerequisites

  • This page provides instructions for using User-Based SSO.
    For instructions on Role-Based SSO, please see this page.

  • Prior configuration on Alibaba Cloud is required.
  • You must create a user in Alibaba Cloud with the same email address used in TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by Alibaba Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see this page

SP-Side Configuration

To be configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible via TrustLogin)

SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Devices

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Add App" button in the upper right of the screen.
    01.png

  2. On the "Add Enterprise App" screen, search for and select "Alibaba Cloud (User-Based SSO) (SAML)".
    02.png

  3. Download the metadata under "Identity Provider Information" in advance.
    03.png

Now switch to configuring Alibaba Cloud.
In a separate window, log in to the Alibaba Cloud RAM console with an administrator account.

Alibaba Cloud Configuration

  1. Open "SSO > User-based SSO Login Method" and click "Edit".
    04.png

  2. Enable "SSO Status" and upload the metadata downloaded from TrustLogin via "Upload" under Metadata File.
    Change the "Auxiliary Domain Name" to match your operational requirements.
    Click "OK" to save the settings.
    05.png

  3. Copy the URL under "SAML Service Provider Metadata URL" and open it in a separate window.
    06.png

  4. Extract and note down the Entity ID value enclosed in entityID="" near the beginning of the file.
    07.png

Return to the TrustLogin configuration again.

TrustLogin Admin Page Configuration (Continued)

  1. Enter the Entity ID extracted from the Alibaba Cloud metadata into the "Entity ID" field under "Service Provider Settings".

    08.png

  2. Click "Register" to save.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. In "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select "Alibaba Cloud (User-Based SSO) (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Alibaba Cloud (User-Based SSO) (SAML)" app.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Alibaba Cloud (User-Based SSO)

Item

Details

Prerequisites

  • This page provides instructions for using User-Based SSO.
    For instructions on Role-Based SSO, please see this page.

  • Prior configuration on Alibaba Cloud is required.
  • You must create a user in Alibaba Cloud with the same email address used in TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by Alibaba Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see this page

SP-Side Configuration

To be configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible via TrustLogin)

SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Devices

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Add App" button in the upper right of the screen.
    01.png

  2. On the "Add Enterprise App" screen, search for and select "Alibaba Cloud (User-Based SSO) (SAML)".
    02.png

  3. Download the metadata under "Identity Provider Information" in advance.
    03.png

Now switch to configuring Alibaba Cloud.
In a separate window, log in to the Alibaba Cloud RAM console with an administrator account.

Alibaba Cloud Configuration

  1. Open "SSO > User-based SSO Login Method" and click "Edit".
    04.png

  2. Enable "SSO Status" and upload the metadata downloaded from TrustLogin via "Upload" under Metadata File.
    Change the "Auxiliary Domain Name" to match your operational requirements.
    Click "OK" to save the settings.
    05.png

  3. Copy the URL under "SAML Service Provider Metadata URL" and open it in a separate window.
    06.png

  4. Extract and note down the Entity ID value enclosed in entityID="" near the beginning of the file.
    07.png

Return to the TrustLogin configuration again.

TrustLogin Admin Page Configuration (Continued)

  1. Enter the Entity ID extracted from the Alibaba Cloud metadata into the "Entity ID" field under "Service Provider Settings".

    08.png

  2. Click "Register" to save.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. In "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select "Alibaba Cloud (User-Based SSO) (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Alibaba Cloud (User-Based SSO) (SAML)" app.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.