All Products
Search
Document Center

CloudSSO:Service-linked role for CloudSSO

Last Updated:Jun 03, 2026

Create, view, and delete the AliyunServiceRoleForCloudSSO service-linked role for centralized permission management in your resource directory.

Use cases

AliyunServiceRoleForCloudSSO grants CloudSSO permissions to manage RAM roles, RAM users, permission policies, and service providers for centralized permission management for your resource directory.

AliyunServiceRoleForCloudSSO is one of the Service-linked roles in Alibaba Cloud.

Create a service-linked role

AliyunServiceRoleForCloudSSO is automatically created in the following scenarios:

  • When you create a CloudSSO directory, the role is created in the management account of your resource directory.

  • When you first provision an access configuration for a member account in CloudSSO, the role is created in that member account.

  • When you first configure RAM user provisioning for a member account in CloudSSO, the role is created in that member account.

View a service-linked role

After AliyunServiceRoleForCloudSSO is created, you can view its basic information, trust policy, and permission policy (AliyunServiceRolePolicyForCloudSSO) in the RAM console.

  1. Log on to the RAM console.

  2. In the left-side navigation pane, choose Identity > Roles.

  3. On the Roles page, click AliyunServiceRoleForCloudSSO.

  4. View the basic information of the role.

    In the Basic Information section, view the RAM role name, creation time, and ARN.

  5. View the trust policy of the role.

    Click the Trust Policy tab. The Service field specifies which cloud service can assume this role, such as "Service": ["cloudsso.aliyuncs.com"].

  6. View the permission policy of the role, AliyunServiceRolePolicyForCloudSSO.

    1. Click the Permissions tab.

    2. Click the permission policy name AliyunServiceRolePolicyForCloudSSO.

    3. On the Policy Document tab, view the content of the permission policy.

    Note

    Service-linked role permission policies do not appear in the RAM console permission policy list.

Delete a service-linked role

You can delete AliyunServiceRoleForCloudSSO in the following scenarios:

  • Delete the service-linked role from a management account

    After you delete the CloudSSO directory, manually delete AliyunServiceRoleForCloudSSO in the RAM console. Delete a RAM role.

  • Delete the service-linked role from a member account

    When you remove a member account from your resource directory, AliyunServiceRoleForCloudSSO in that account is automatically deleted.