All Products
Search
Document Center

Data Security Center:Authorize DSC to access cloud resources

Last Updated:Jun 21, 2026

Before you use Data Security Center (DSC) to detect sensitive data in your cloud assets or analyze security risks, you must authorize DSC to access your cloud resources, such as Object Storage Service (OSS), ApsaraDB RDS, MaxCompute, and Security Center. This topic describes how to complete the necessary RAM authorization, including the initial authorization and the specific authorization required to enable data audit for MaxCompute.

Initial authorization

Note

Before you begin, make sure you have activated Data Security Center (either the free or paid edition). For more information, see Activate Data Security Center.

When you first log on to the console after activating DSC, you are prompted to complete the initial cloud resource authorization. This authorization allows DSC to access your cloud services, such as OSS, ApsaraDB RDS, MaxCompute, and Security Center, to perform operations such as sensitive data scanning, data leakage risk monitoring, and analysis.

  1. Log on to the DSC console.

  2. In the RAM-based Authorization dialog box, click Authorize. On the RAM Authorization page, review the details of the service-linked role that will be created. The role is named AliyunServiceRoleForSDDP and uses the AliyunServiceRolePolicyForSDDP permission policy, which allows DSC to access cloud resources in OSS, ApsaraDB RDS, MaxCompute, and Security Center. Click Authorize to confirm.

After you click Authorize, the system creates the AliyunServiceRoleForSDDP service-linked role, which uses the AliyunServiceRolePolicyForSDDP permission policy. For details about the policy, see AliyunServiceRolePolicyForSDDP.

You can view the service-linked role on the RAM console - Roles page. For more information, see Service-linked roles.

Authorization for MaxCompute data audit

When you enable the data audit feature for MaxCompute, you are prompted to complete a cloud resource authorization. This authorization allows DSC to access ActionTrail real-time logs for real-time audit analysis and risk identification.

  1. Log on to the Data Security Center console.

  2. Enable the data audit feature.

    • From Asset Center: In the left-side navigation pane, choose Asset Center. Under the Big Data section, choose MaxCompute. In the Data Auditing column, click the image icon to enable the feature.

    • From the Native Data Auditing console: In the left-side navigation pane, choose Data Audit > Native Data Auditing. On the Overview tab, find the target MaxCompute asset and click Enable Now in the Actions column.

  3. In the RAM-based Authorization dialog box, click Authorize.

After you click Authorize, the system creates the AliyunServiceRoleForSDDPAsset service-linked role, which uses the AliyunServiceRolePolicyForSDDPAsset permission policy. For details about the policy, see AliyunServiceRolePolicyForSDDPAsset.

You can view the service-linked role on the RAM console - Roles page. For more information, see Service-linked role.

Delete service-linked roles

If you no longer need to use DSC, you can log on to the RAM console to delete the AliyunServiceRoleForSDDP and AliyunServiceRoleForSDDPAsset service-linked roles. For detailed instructions, see Service-linked roles.