All Products
Search
Document Center

Cloud Config:How do I delete the AliyunServiceRoleForConfig service-linked role?

Last Updated:Jun 03, 2026

If you no longer use Cloud Config, delete the AliyunServiceRoleForConfig service-linked role to remove permissions that are no longer needed. The steps vary by account type.

Cloud Config supports the following account types:

  • Ordinary account: An independent Alibaba Cloud account that is not part of a resource directory.

  • Management account: An Alibaba Cloud account that enables a resource directory and manages all member accounts within it.

  • Delegated administrator account: For more information, see Manage a delegated administrator account.

  • Member account: An Alibaba Cloud account that belongs to a resource directory.

Ordinary accounts

  1. Deactivate Cloud Config.

    For more information, see Deactivate Cloud Config.

  2. Delete the AliyunServiceRoleForConfig service-linked role.

    For more information, see Delete a RAM role.

Management accounts or delegated administrator accounts

  1. Deactivate Cloud Config.

    For more information, see Deactivate Cloud Config.

    Note

    Before deactivating Cloud Config, make sure no account group has been created under the management account or delegated administrator account. For more information, see

    Delete an account group

    .

  2. Use a management account or delegated administrator account to delete the AliyunServiceRoleForConfig service-linked role.

    For more information, see Delete a RAM role.

Member accounts

  1. Deactivate Cloud Config.

    For more information, see Deactivate Cloud Config.

    Note

    Before deactivating Cloud Config, make sure the member account has not been added to any account group. For more information, see

    Modify an account group

    .

  2. Delete the AliyunServiceRoleForConfig service-linked role.

    For more information, see Delete a RAM role.