Integrate Role-based Alibaba Cloud

Role-based Alibaba Cloud allows an enterprise to manage users in IDaaS without the need to synchronize users from IDaaS to Alibaba and allows users of the enterprise to access Alibaba Cloud using a specific RAM role. See https://www.alibabacloud.com/help/en/ram/user-guide/role-based-sso-by-using-saml/ for more information.

Note: This guide was tested using Identity as a Service 5.36 and Alibaba Cloud. Other versions of Alibaba Cloud may require integration and configuration steps that differ from those documented in this procedure. For newer versions of Alibaba Cloud, this integration guide may be used as an initial approach for integrating Alibaba Cloud. In the event of other issues, contact support@entrust.com for assistance.

To integrate role-based Alibaba Cloud with Identity as a Service you must do the following:

Before you begin, open two browser windows: one for Alibaba Cloud and one for IDaaS.

Step 1: Download the metadata file from Alibaba Cloud and create a role and Trusted Entity as an Identity Provider

Step 2: Add role-based Alibaba Cloud to Identity as a Service

Step 3: Download the metadata from Identity as a Service

Step 4: Configure role-based Alibaba Cloud with IDaaS

Step 5: Add the ARN values to IDaaS

Step 6: Create a resource rule to protect access to Atlassian

Step 7: Test the integration