If you no longer use Cloud Config, delete the AliyunServiceRoleForConfig service-linked role to remove permissions that are no longer needed. The steps vary by account type.
Cloud Config supports the following account types:
Ordinary account: An independent Alibaba Cloud account that is not part of a resource directory.
Management account: An Alibaba Cloud account that enables a resource directory and manages all member accounts within it.
Delegated administrator account: For more information, see Manage a delegated administrator account.
Member account: An Alibaba Cloud account that belongs to a resource directory.
Ordinary accounts
-
Deactivate Cloud Config.
For more information, see Deactivate Cloud Config.
-
Delete the AliyunServiceRoleForConfig service-linked role.
For more information, see Delete a RAM role.
Management accounts or delegated administrator accounts
-
Deactivate Cloud Config.
For more information, see Deactivate Cloud Config.
NoteBefore deactivating Cloud Config, make sure no account group has been created under the management account or delegated administrator account. For more information, see
.
-
Use a management account or delegated administrator account to delete the AliyunServiceRoleForConfig service-linked role.
For more information, see Delete a RAM role.
Member accounts
-
Deactivate Cloud Config.
For more information, see Deactivate Cloud Config.
NoteBefore deactivating Cloud Config, make sure the member account has not been added to any account group. For more information, see
.
-
Delete the AliyunServiceRoleForConfig service-linked role.
For more information, see Delete a RAM role.