Security Center uses service-linked roles (SLRs) to access other Alibaba Cloud services in specific scenarios. Learn about each SLR, its use cases, and how to create, view, or delete it.
A service-linked role (SLR) is a RAM role whose trusted entity is an Alibaba Cloud service. Security Center uses SLRs to access other cloud services and resources.
SLRs are usually created automatically when you perform a related operation. If automatic creation fails, or if Security Center does not support automatic creation for an SLR, you must create the SLR manually.
RAM assigns an immutable system policy to each SLR. View policy details from theSystem policy reference.
Scenarios
Security Center provides the following SLRs.
|
Service-linked role |
Service identifier |
Scenarios |
|
AliyunServiceRoleForSas |
sas.aliyuncs.com |
|
|
AliyunServiceRoleForSasCloudSiem |
cloudsiem.sas.aliyuncs.com |
Accesses VPC and Cloud Firewall resources for threat analysis and response to collect and deliver logs, handle events, and analyze threats. This provides capabilities such as centralized alert management and threat source analysis. |
|
AliyunServiceRoleForSasCspm |
cspm.sas.aliyuncs.com |
Accesses ActionTrail resources for Cloud Security Posture Management (CSPM) configuration checks. |
|
AliyunServiceRoleForSasRd |
rd.sas.aliyuncs.com |
In multi-account scenarios, allows a delegated administrator account to access member account consoles in a resource directory. Enables centralized security configuration and real-time risk monitoring across member accounts. |
|
AliyunServiceRoleForSasSecurityLake |
security-lake.sas.aliyuncs.com |
Accesses OSS and Data Lake Formation (DLF) resources for the threat analysis cold data feature to manage log data and run interactive queries. |
Create a service-linked role
AliyunServiceRoleForSas
The system automatically creates this SLR when you first use one of the following features and grant permissions.
|
Module |
Features |
|
Risk governance |
|
|
Container security |
|
|
Host security |
|
|
Other configurations |
|
AliyunServiceRoleForSasCloudSiem
Created automatically when you first use threat analysis and response and grant permissions.Grant the threat analysis and response feature the permissions to access Alibaba Cloud resources.
AliyunServiceRoleForSasCspm
Created automatically when you first use Cloud Security Posture Management and grant permissions.
Since November 21, 2022 (UTC+8), the CSPM access policy migrated from AliyunServiceRoleForSas to AliyunServiceRoleForSasCspm. To migrate, go to the Cloud Security Posture Management page. In the Role Policy Migration Reminder dialog box, click OK, then click Authorize Now to authorize.
AliyunServiceRoleForSasRd
Created automatically under a member account when a management or delegated administrator account uses multi-account security management to add the member to the monitored list.
AliyunServiceRoleForSasSecurityLake
Created automatically when you first use the threat analysis cold data feature and grant permissions.
View a service-linked role
After creating an SLR, view its details on the Roles page of the RAM console:
-
Basic information
The Basic Information section shows the role name, creation time, ARN, and description.
-
Access policy
On the Permissions tab, click the policy name to view the policy document.
NoteSLR access policies are only visible from the role details page, not from the Policies page.
-
Trust policy
The Trust Policy tab shows which Alibaba Cloud service can assume the role. Check the
Servicefield.
Delete a service-linked role
Deleting an SLR disables all features that depend on it.
If you no longer use Security Center for an extended period or before you log off from your Alibaba Cloud account, you may need to manually delete the SLR. To delete an SLR, go to the RAM console. Delete a RAM role.