All Products
Search
Document Center

Data Security Center:Data authorization

Last Updated:Apr 18, 2026

This topic answers frequently asked questions about data asset authorization and provides solutions.

Reasons for authorization failure

When you authorize Data Security Center (DSC) to access data in MaxCompute, ApsaraDB RDS, and Object Storage Service (OSS), the authorization may fail. You can troubleshoot the issue based on the following common causes.

ApsaraDB RDS authorization failure

  • The username or password for accessing the ApsaraDB RDS database is invalid.

  • The service IP addresses of DSC are deleted from the whitelist of the ApsaraDB RDS database.

  • The ApsaraDB RDS database resides on the classic network, but the public endpoint of the ApsaraDB RDS database is inaccessible due to access control.

MaxCompute authorization failure

  • The name of the MaxCompute project is invalid.

  • The DSC account fails to be added to the MaxCompute project.

Assets in data domains

No. These are assets in your account that you have authorized for Data Security Center (DSC). For more information, see Manage assets by data domain.

Authorize self-managed databases

  • Only self-managed databases on Elastic Compute Service (ECS) instances in a Virtual Private Cloud (VPC) are supported.

  • Only MySQL, SQL Server, and Oracle self-managed databases on ECS instances are supported.

For more information, see Authorize DSC to access a self-managed database on an ECS instance.

DSCSupport for the China (Shenzhen) Finance region

No. For more information about the regions that DSC supports, see Supported regions.

Support for regions outside the Chinese mainland

Yes. DSC is available in the Singapore, Malaysia (Kuala Lumpur), and Indonesia (Jakarta) regions.

For an ApsaraDB for OceanBase tenant in Oracle mode, when you connect its database toDSC, how do you define an instance?

An ApsaraDB for OceanBase cluster is considered a single instance.

Assets protected by storage protection capacity

The storage protection capacity is the total capacity of data that DSC is authorized to protect in Object Storage Service (OSS) and Log Service (SLS).

Prerequisites for asset authorization

  1. You have activated the Free Edition of Data Security Center or purchased a paid edition of Data Security Center.For more information, see Free Edition of Data Security Center or Purchase Data Security Center.

  2. You have authorized Data Security Center to access cloud services. For more information, see Authorize DSC to access cloud resources.

  3. You have confirmed that your database type is supported by DSC.

    • For more information about supported database types, see Supported data asset types. Examples include ApsaraDB RDS, PolarDB, PolarDB-X, Tair, ApsaraDB for MongoDB, ApsaraDB for OceanBase, Tablestore, AnalyticDB, and AnalyticDB.

    • For self-managed databases on ECS instances, only those in a Virtual Private Cloud (VPC) that run MySQL, SQL Server, or Oracle are supported. Before authorization, you must configure the correct CIDR block based on the database's region and grant DSC permission to access the database with a specified database user. For more information, see Authorize DSC to access a self-managed database on an ECS instance.

  4. Asset synchronization is complete.

    • After you purchase a DSC instance, DSC immediately performs an asset synchronization task the first time you log on to the console. DSC automatically syncs new data assets to the unauthorized asset lists at midnight every day. If you need to authorize an asset created on the current day, you must perform a manual synchronization.

Cannot find a database instance during authorization

Troubleshooting item

Description

Solution

Database type

Verify that your database type is supported by DSC.

For more information, see Supported data asset types.

Instance status

Ensure that your database instance is running and visible in the DSC console.

  • If the instance is not running, start it in the console of the database instance.

  • If the instance is not visible, manually synchronize your assets. For more information, see Asset synchronization steps.

Region configuration

Verify that the selected region matches the actual region of your database instance. The CIDR block authorization for DSC is region-specific. Ensure that the database instance and the authorized CIDR block are in the same region.

In the upper-left corner of the DSC console, select Chinese Mainland or Outside Chinese Mainland based on the region of your database instance.

For more information about which regions are included in Chinese Mainland and Outside Chinese Mainland, see Supported regions.

Asset synchronization

If your database instance was recently created, you may need to manually synchronize it in the DSC console.

For more information, see Asset synchronization steps.

Permission configuration

Check whether the permission policy includes the necessary permissions for the database instance. Ensure that your RAM user or RAM role has permissions to access and manage the database instance.

Modify the permission policy for the RAM user or RAM role. For more information, see Policies.

Network configuration

Verify that the network configuration of your database instance allows access from the DSC CIDR block. For databases in a VPC, ensure that the security group rules allow the DSC CIDR block to access the database instance.

Modify the network configuration of the corresponding database instance. For information about how to configure an ApsaraDB RDS for MySQL instance, see Connect to an ApsaraDB RDS for MySQL instance.

RDS instance shows no database after sync

A newly created database takes time to synchronize.

Insufficient quota in free edition

No.

The free edition does not support upgrades or renewals. If the free edition does not meet your business requirements, purchase Data Security Center to ensure continuous data security governance. For more information, see Purchase Data Security Center.

References

Grant access to data assets