Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Yandex Identity Hub
    • All guides
    • Subscribing a user to notifications
      • Overview
      • Configuring an identity federation
      • Configuring a federated user group mapping
      • Renewing a Yandex Cloud SAML certificate
      • Setting up a domain in an identity federation
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  • Release notes

In this article:

  • Associating a domain
  • Getting a list of domains
  • Viewing information about a domain
  • Deleting a domain
  1. Step-by-step guides
  2. Managing identity federations
  3. Setting up a domain in an identity federation

Setting up a domain in an identity federation

Written by
Yandex Cloud
Updated at October 29, 2025
  • Associating a domain
  • Getting a list of domains
  • Viewing information about a domain
  • Deleting a domain

Note

This feature is at the Preview stage.

A domain allows you to authenticate through Login Discovery. When authenticating, a user with your domain will be redirected to your identity federation.

Associating a domainAssociating a domain

CLI

If you do not have the Yandex Cloud CLI installed yet, install and initialize it.

By default, the CLI uses the folder specified when creating the profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also set a different folder for any specific command using the --folder-name or --folder-id parameter.

  1. See the description of the CLI command to associate a domain with a federation:

    yc organization-manager federation saml add-domain --help
    
  2. Run this command:

    yc organization-manager federation saml add-domain <federation_name_or_ID> \
      --domain <domain>
    

    Where --domain is your domain.

    Result:

    done (1s)
    domain: example. com
    status: NEED_TO_VALIDATE
    status_code: organization/domain-diagnostics#need-to-validate
    created_at: "2025-10-09T06:40:18.704791371Z"
    validated_at: "1970-01-01T00:00:00Z"
    challenges:
    - created_at: "2025-10-09T06:40:18.704791371Z"
    updated_at: "2025-10-09T06:40:18.704791371Z"
    type: DNS_TXT
    status: PENDING
    dns_challenge:
    name: _yandexcloud-challenge. example. com
    type: TXT
    value: TlHc5HKJDeQIgPqaoiiSXxgy3CWFD+MLMJJP********
    

    Save the value as you will need it to validate the domain.

Getting a list of domainsGetting a list of domains

CLI

If you do not have the Yandex Cloud CLI installed yet, install and initialize it.

By default, the CLI uses the folder specified when creating the profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also set a different folder for any specific command using the --folder-name or --folder-id parameter.

  1. See the description of the CLI command for getting a list of domains in a federation:

    yc organization-manager federation saml list-domains --help
    
  2. Run this command:

    yc organization-manager federation saml list-domains <federation_name_or_ID>
    

Viewing information about a domainViewing information about a domain

CLI

If you do not have the Yandex Cloud CLI installed yet, install and initialize it.

By default, the CLI uses the folder specified when creating the profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also set a different folder for any specific command using the --folder-name or --folder-id parameter.

  1. See the description of the CLI command for viewing information about a domain in a federation:

    yc organization-manager federation saml get-domain --help
    
  2. Run this command:

    yc organization-manager federation saml get-domain <federation_name_or_ID> \
      --domain <domain>
    

    Where --domain is your domain.

Deleting a domainDeleting a domain

You cannot delete the default domain or a domain with associated users.

CLI

If you do not have the Yandex Cloud CLI installed yet, install and initialize it.

By default, the CLI uses the folder specified when creating the profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also set a different folder for any specific command using the --folder-name or --folder-id parameter.

  1. See the description of the CLI command for deleting a domain from a federation:

    yc organization-manager federation saml delete-domain --help
    
  2. Run this command:

    yc organization-manager federation saml delete-domain <federation_name_or_ID> \
      --domain <domain>
    

    Where --domain is your domain.

    For example, delete my-domain.ru from my-federation:

    yc organization-manager federation saml delete-domain my-federation \
      --domain my-domain.ru
    

Was the article helpful?

Previous
Renewing a Yandex Cloud SAML certificate
Next
Creating a user pool
© 2025 Direct Cursus Technology L.L.C.