Managed Security Service (MSS) uses service-linked roles (SLRs) to access your resources in other cloud services, such as Elastic Compute Service (ECS) and ApsaraDB RDS. An SLR is a RAM role that only a trusted Alibaba Cloud service can assume, allowing MSS to perform security assessments and security hardening on your behalf.
Roles and permissions
MSS creates different service-linked roles based on the features you use.
AliyunServiceRoleForMssp
This role is required to use the basic features of MSS. It grants MSS access to your core cloud resources for security assessments and security hardening.
-
Role name:
AliyunServiceRoleForMssp. -
Access policy:
AliyunServiceRolePolicyForMssp. -
Policy document: For more information, see AliyunServiceRolePolicyForMssp.
AliyunServiceRoleForESAMssp
This role is required to use MSS for security operations on Edge Security Acceleration (ESA). It grants MSS access to your ESA and Simple Log Service (SLS) resources.
-
Role name:
AliyunServiceRoleForESAMssp. -
Access policy:
AliyunServiceRolePolicyForESAMssp. -
Policy document: For more information, see AliyunServiceRolePolicyForESAMssp.
The AliyunServiceRolePolicyForMssp and AliyunServiceRolePolicyForESAMssp access policies are system-generated. You cannot modify these policies.
Delete a service-linked role
Service-linked roles are required for MSS to perform security operations on your resources. You cannot delete these roles while your MSS subscription is active. After your subscription expires, delete the roles by following these steps:
-
Go to the Roles page.
-
Search for
AliyunServiceRoleForMssporAliyunServiceRoleForESAMssp. In the Actions column, click Delete Role.
References
-
For instructions on authorizing MSS to access cloud resources, see Grant Managed Security Service access to cloud resources.
-
To learn more about service-linked roles, see Service-linked roles.