All Products
Search
Document Center

Managed Security Service:Service-linked role

Last Updated:Jun 16, 2026

Managed Security Service (MSS) uses service-linked roles (SLRs) to access your resources in other cloud services, such as Elastic Compute Service (ECS) and ApsaraDB RDS. An SLR is a RAM role that only a trusted Alibaba Cloud service can assume, allowing MSS to perform security assessments and security hardening on your behalf.

Roles and permissions

MSS creates different service-linked roles based on the features you use.

AliyunServiceRoleForMssp

This role is required to use the basic features of MSS. It grants MSS access to your core cloud resources for security assessments and security hardening.

  • Role name: AliyunServiceRoleForMssp.

  • Access policy: AliyunServiceRolePolicyForMssp.

  • Policy document: For more information, see AliyunServiceRolePolicyForMssp.

AliyunServiceRoleForESAMssp

This role is required to use MSS for security operations on Edge Security Acceleration (ESA). It grants MSS access to your ESA and Simple Log Service (SLS) resources.

  • Role name: AliyunServiceRoleForESAMssp.

  • Access policy: AliyunServiceRolePolicyForESAMssp.

  • Policy document: For more information, see AliyunServiceRolePolicyForESAMssp.

Note

The AliyunServiceRolePolicyForMssp and AliyunServiceRolePolicyForESAMssp access policies are system-generated. You cannot modify these policies.

Delete a service-linked role

Service-linked roles are required for MSS to perform security operations on your resources. You cannot delete these roles while your MSS subscription is active. After your subscription expires, delete the roles by following these steps:

  1. Go to the Roles page.

  2. Search for AliyunServiceRoleForMssp or AliyunServiceRoleForESAMssp. In the Actions column, click Delete Role.

References