AliyunServiceRolePolicyForCloudSSO 是專用于服務關聯角色的授權策略,會在創建服務關聯角色 AliyunServiceRoleForCloudSSO 時自動授權,以允許服務關聯角色代您訪問其他云服務。本策略由對應的阿里云服務按需更新,請勿將本策略授權給服務關聯角色之外的 RAM 身份使用。
策略詳情
類型:系統策略
創建時間:2021-06-08 02:27:56
更新時間:2022-09-16 07:24:29
當前版本:v5
策略內容
{
"Version": "1",
"Statement": [
{
"Action": [
"ram:CreateSAMLProvider",
"ram:CreatePolicy",
"ram:ListRoles",
"ram:ListPolicies"
],
"Resource": "*",
"Effect": "Allow"
},
{
"Action": [
"ram:ListPolicyVersions",
"ram:DeletePolicyVersion",
"ram:CreatePolicyVersion",
"ram:DeletePolicy"
],
"Resource": "acs:ram:*:*:policy/AliyunReservedSSO*",
"Effect": "Allow"
},
{
"Action": [
"ram:GetSAMLProvider",
"ram:DeleteSAMLProvider",
"ram:GetRole",
"ram:CreateRole",
"ram:DeleteRole",
"ram:GetPolicy",
"ram:AttachPolicyToRole",
"ram:DetachPolicyFromRole",
"ram:ListPoliciesForRole"
],
"Resource": [
"acs:ram:*:*:saml-provider/AliyunReservedSSO*",
"acs:ram:*:*:role/aliyunreservedsso*",
"acs:ram:*:*:policy/*"
],
"Effect": "Allow"
},
{
"Action": [
"ram:CreateUser",
"ram:DeleteUser",
"ram:GetUser",
"ram:UpdateUserProvisionType",
"ram:UnBindMFADevice",
"ram:DeleteLoginProfile",
"ram:UnbindUserPersonalDingTalk",
"ram:ListAccessKeys",
"ram:DeleteAccessKey",
"ram:ListGroupsForUser",
"ram:RemoveUserFromGroup",
"ram:ListPublicKeys",
"ram:DeletePublicKey"
],
"Resource": [
"acs:ram:*:*:user/*",
"acs:ram:*:*:group/*"
],
"Effect": "Allow"
},
{
"Action": [
"ram:DeleteServiceLinkedRole",
"ram:GetServiceLinkedRoleDeletionStatus"
],
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "cloudsso.aliyuncs.com"
}
}
},
{
"Action": "ram:DeleteServiceLinkedRole",
"Resource": "*",
"Effect": "Allow",
"Condition": {
"StringEquals": {
"ram:ServiceName": "cloudsso.aliyuncs.com"
}
}
}
]
}
相關文檔
文檔內容是否對您有幫助?