When your business spans both Alibaba Cloud and Amazon Web Services (AWS), managing security assets across these platforms becomes fragmented, making it difficult to maintain a unified security view and slowing down risk detection and response. By connecting your AWS account to Security Center, you can centrally manage security for core AWS services such as EC2, RDS, and S3. This enables unified monitoring of your multi-cloud security posture, configuration risk detection, security event tracking, and consistent cross-cloud security policies.
Choose an onboarding method
Choose the appropriate onboarding method based on your security requirements, supported features, and environment type. Two options are available: quick configuration and manual configuration.
Comparison Item | Quick Configuration | Manual Configuration |
Authorized Account Type | The root account access key is used only for initial authorization. | Create an IAM user with minimum required permissions. |
Supported Features | Supports only Host . |
|
Configuration Complexity | Simple | Medium |
Method 1: Quick configuration (host only)
Step 1: Create root account credentials in AWS
The root account access key is used only for initial authorization, allowing Security Center to automatically create a dedicated IAM sub-user with restricted permissions (prefixed with AlibabaSasSubAccount_) in your AWS account. After successful authorization, you should immediately delete this root account access key.
Sign in to the AWS Management Console
Sign in to the AWS IAM console. On the dashboard, click My security credentials.
ImportantOnly the root account can configure security credentials.
Create an access key
On the My security credentials page, complete the configuration as described below, and then click Create access key.
Use case: Select a use case based on your business scenario. If none are suitable, select Other.
Set description tag (optional): Up to 256 characters. Allowed characters include letters, digits, UTF-8 spaces, and the following special characters: _ . : / = + - @.
Save the access key
After creation, go to the Retrieve access keys page to view and save the Access key ID and Secret access key.
NoteYou can click Download .csv file to save the access key to your local device.
Step 2: Complete onboarding in Security Center
Go to the authorization page:
You can start the AWS asset onboarding process through any of the following paths:
Recommended path:
Log on to Security Center console.
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
On the tab, click Grant Permission, and then select AWS.
Other entry points:
On the following pages, in the Multi-cloud Service Access or Add Multi-cloud Asset section, find and click the Onboard or Authorize button below the
icon:
Configure access credentials:
In the Add Assets Outside Cloud panel, select Quick Configuration, select the features you want to onboard, and then click Next.
On the Submit AccessKey Pair page, accurately enter the credential information you created in AWS.
Enter Master Account Secret ID and SecretKey: Enter the root account access key credentials (Access key ID and Secret access key) created in Step 1: Create root account credentials in AWS.
Region to Obtain Cloud Service Information: Select the available AWS region. The system will verify asset accessibility in the selected region.
Domain: Configure based on the selected onboarding region. For AWS China, select "China Edition"; for all others, select "International Edition".
After filling in the information, click Next. The system will automatically verify the credentials and permissions.
Configure synchronization policy:
Select region: Select the AWS region where the assets you want to onboard are located.
NoteThe synchronized asset data will be attributed to the data center corresponding to the region selected in the upper-left corner of the Security Center console.
Chinese Mainland: Chinese mainland data center.
Outside Chinese Mainland: Singapore data center.
Region Management: Recommended. After selected, assets in new regions under this AWS account will be automatically synchronized without manual configuration.
Host Asset Synchronization Frequency: Set the synchronization interval for AWS host (EC2) assets. If you do not need synchronization, set it to "Off".
AK Service Status Check: Set the interval for Security Center to automatically check the validity of the AWS account API key. You can select "Off" to disable detection.
After completing the configuration, click Synchronize Assets. The system will automatically synchronize host assets from the AWS account to Security Center.
ImportantAfter completing the above operations, Security Center will automatically create a sub-user in AWS with the prefix
AlibabaSasSubAccount_to authorize the connection. Do not delete or disable the automatically created sub-user account or its API key; otherwise, asset onboarding and security monitoring will be interrupted.
Step 3: Delete the AWS root account access key
After successfully onboarding your assets, immediately delete the root account access key used for initial authorization to reduce security risks.
Sign in to the AWS IAM console as the root account, and on the dashboard, click My security credentials.
In the AccessKey Pair section, locate the access key used for this authorization, and click Delete under Actions to confirm the deletion.
Method 2: Manual configuration
This method uses a restricted-permission IAM sub-user created in AWS for onboarding, providing both high security and full feature support.
Step 1: Create sub-account authorization credentials in AWS
Create an IAM sub-user with minimum required permissions for Security Center integration, and obtain its access key.
For more information, see the official AWS documentation: Creating IAM users , Adding permissions .
Sign in to the AWS Management Console
Sign in to the AWS IAM console. In the left-side navigation pane, click Users. On the Users page, click Create user.
Configure user details
User name: Enter a custom name that is easy to identify (for example,
aliyun-security-center-user).Provide user access to the AWS Management Console: Do not select. This user is for API access only.
Set user permissions
Select Attach policies directly.
Based on the features you plan to use in Security Center, select the corresponding permission policies.
Feature
AWS Policy
Notes
Host
AmazonEC2ReadOnlyAccessIAMReadOnlyAccessNone
CSPM (CSPM)
ReadOnlyAccessIAMReadOnlyAccessIf you need comprehensive risk detection based on log auditing, see Configure AWS service audit logs for CSPM to configure audit logs for relevant services in AWS.
Agentless Detection
You need to manually create a custom policy.
You need to establish a log delivery pipeline in AWS consisting of CloudTrail, S3, and SQS. For specific steps, see Create a custom policy for Agentless Detection.
In Permission options, select Attach policies directly, enter the policy name in the search box to filter, select the target policy, and then click Next.
Review and create
After confirming that the user information and permission policies are correct, click Create user.
Create and save API keys
After the user is created successfully, return to the Users list, and click the name of the newly created user to go to its details page.
In the Summary section, click Create access key, and complete the key configuration as described below.
Use case: Select a use case based on your business scenario. If none are suitable, select Others.
Description tag: Leave it blank or customize a tag (for example,
for-aliyun-sasc).
Click Create access key to go to the Retrieve access keys page, then view and save the Access key ID and Secret access key.
The secret access key is displayed only once at creation time and cannot be recovered if lost. Click Download .csv file to save the key information, and then click Done.
Step 2: Complete onboarding configuration in Security Center
After successfully creating the sub-user API key for authorization in AWS, return to the Security Center console to complete the onboarding configuration.
Go to the authorization page
NoteFor more entry points, see other entry points.
Log on to Security Center console.
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
On the tab, click Grant Permission, and then select AWS.
Configure access credentials
In the Add Assets Outside Cloud panel, select Manual Configuration, select the features you want to onboard, and then click Next.
Host: Allows Security Center to automatically discover and synchronize your AWS EC2 host assets.
CSPM: Use Cloud Security Posture Management to scan AWS cloud product configurations for configuration risk management.
Agentless Detection: Use agentless detection to scan AWS assets for vulnerabilities and risks.
On the Submit AccessKey Pair page, accurately enter the credential information you created in AWS.
Sub-account SecretID and Sub-account SecretKey: Enter the credentials from Step 1: Create sub-account authorization credentials in AWS.
Region to Obtain Cloud Service Information: Select the available AWS region. The system will verify asset accessibility in the selected region.
Domain: Configure based on the selected onboarding region. For AWS China, select "China Edition"; for all others, select "International Edition".
After filling in the information, click Next. The system will automatically verify the credentials and permissions.
Configure audit logs (optional)
If you need to use the log auditing feature of Cloud Platform Configuration Check (CSPM), configure it here. Otherwise, click Skip.
ImportantFirst complete all configurations in the AWS console as described in What should I do if the automatic credential and permission verification fails after filling in the access key?.
AWS Region: Enter the region ID where the AWS queue is located. For region ID reference, see AWS Region IDs .
SQS Queue Name: Enter the name of the SQS queue you created.
Configure synchronization policy
On the Policy Configuration page, configure the settings as needed:
Select region: Select the AWS region where the assets you want to onboard are located.
NoteAsset data is automatically attributed to the data center corresponding to the region selected in the upper-left corner of the Security Center console.
Chinese Mainland: Chinese mainland data center.
Outside Chinese Mainland: Singapore data center.
Region Management: Recommended. After selected, assets in new regions under this AWS account will be automatically synchronized without manual configuration.
Host Asset Synchronization Frequency: Set the synchronization interval for AWS host (EC2) assets. If you do not need synchronization, set it to "Off".
NoteThis parameter needs to be configured only when the onboarded feature includes Host.
Cloud Service Synchronization Frequency: Set the synchronization interval for AWS cloud product configurations. If you do not need synchronization, set it to "Off".
NoteThis parameter needs to be configured only when the onboarded feature includes Cloud Platform Configuration Check.
AK Service Status Check: Set the interval for Security Center to automatically check the validity of the AWS account API key. You can select "Off" to disable detection.
After completing the configuration, click Synchronize Assets. The system will automatically synchronize data from the AWS account to Security Center.
Manage onboarded assets
Host
Go to the page. In the Add Multi-cloud Asset section, click the
icon to view the onboarded AWS hosts. You can follow the steps below for in-depth protection and management of onboarded AWS EC2 hosts.
For more information, see Server assets
Install the client: Install the Security Center client on your AWS hosts. When running the installation command, select AWS for Service Provider. For details, see Install the agent.
Upgrade your edition for protection: The default free edition provides only basic security detection. For comprehensive security capabilities (such as anti-virus, vulnerability remediation, and intrusion prevention), bind a paid edition (Anti-virus edition or higher) to your AWS hosts. For details, see Manage host and container security quotas.
Cloud Security Posture Management (CSPM)
In the Security Center console, go to the page. In the left-side All Alibaba Cloud Services navigation pane, click AWS to view your onboarded AWS assets. The following CSPM features are available for onboarded AWS assets:
For more information, see View cloud service information.
Run configuration risk checks: Check for configuration risks in your AWS products. For details, see Set up and run cloud platform configuration risk check policies.
Handle risk items: Based on the check results, view and remediate failed risk check items to improve the compliance and security of your cloud assets. For details, see View and handle failed cloud platform configuration risk check items.
Agentless detection
In the Security Center console, go to the page. In the Add Multi-cloud Asset section, click the
icon to view the number of onboarded AWS assets. After onboarding, you can use agentless detection to scan AWS hosts for vulnerabilities, baselines, and more.
AWS advanced configuration (Agentless Detection and CSPM)
Create a custom policy for Agentless Detection
For more information, see the official AWS documentation: Creating IAM users , Adding permissions .
Sign in to the AWS IAM console, go to the Policies page, and click Create policy.
In the Policy editor section, select JSON and paste the following JSON into the editor.
{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Action": [ "ec2:DeleteSubnet", "ec2:DeleteVpcEndpoints", "ec2:DeleteInternetGateway", "ec2:TerminateInstances", "ec2:StopInstances", "ec2:DeleteSecurityGroup", "ec2:DeleteVpc" ], "Resource": "*", "Condition": { "StringLike": { "ec2:ResourceTag/Name": "alibaba-cloud-security-scan*" } } }, { "Effect": "Allow", "Action": [ "ec2:DeleteSnapshot" ], "Resource": "*", "Condition": { "StringLike": { "ec2:ResourceTag/Name": "SAS_Agentless*" } } }, { "Effect": "Allow", "Action": [ "ec2:CopySnapshot", "ec2:AuthorizeSecurityGroupIngress", "ec2:DescribeInstances", "ec2:CreateImage", "ec2:CreateVpc", "ec2:AttachInternetGateway", "ec2:CopyImage", "ec2:ModifyImageAttribute", "ec2:DescribeSnapshots", "ec2:ModifySubnetAttribute", "ec2:DescribeInternetGateways", "ec2:ModifySnapshotAttribute", "ec2:DescribeInstanceTypeOfferings", "ec2:DescribeAvailabilityZones", "ec2:CreateInternetGateway", "ec2:CreateSecurityGroup", "ec2:DescribeVolumes", "ec2:CreateSnapshot", "ec2:AuthorizeSecurityGroupEgress", "ec2:RunInstances", "ec2:DetachInternetGateway", "ec2:DescribeSecurityGroups", "ec2:DescribeImages", "ec2:CreateVpcEndpoint", "ec2:CreateSnapshots", "ec2:DescribeVpcs", "ec2:DescribeImageAttribute", "ec2:DescribeVpcEndpoints", "ec2:CreateSubnet", "ec2:DescribeSubnets", "ec2:ModifyVpcEndpoint", "ec2:CreateTags", "ec2:DescribeRouteTables", "ec2:CreateRoute", "ec2:DescribeRegions", "kms:Decrypt", "kms:DescribeKey", "kms:CreateGrant", "kms:ListGrants", "kms:RevokeGrant", "kms:GenerateDataKey", "kms:ReEncrypt*", "iam:GetUser" ], "Resource": "*" } ] }Click Next, name the policy (for example,
AliyunSASC-AgentlessScan-Policy), and then click Create policy.Refer to Set user permissions to attach this policy to the AWS sub-account.
Configure AWS service audit logs for CSPM
Step 1: Create a CloudTrail Trail
This step creates a log trail in AWS CloudTrail to continuously record and store cloud resource management operations within the specified region, providing foundational log support for CSPM data collection. For more information, see the official AWS documentation: Create a trail .
Sign in to the AWS CloudTrail console
Sign in to the AWS CloudTrail console. In the region selector at the upper-right corner of the console, select the AWS region you want to monitor.
On the dashboard or in the left-side navigation pane, select Trails, and then click Create trail.
Configure trail attributes
On the Choose trail attributes page, configure as described below, and then click Next.
Trail name: Enter a clear, identifiable name (for example,
aliyun-sasc-audit-trail).Storage location:
ImportantRecord the bucket name for use in subsequent configurations.
Create new S3 bucket: Enter a globally unique, all-lowercase, English-only bucket name.
Use existing S3 bucket: In the Trail log bucket name section, click Browse, and select the target bucket from the dialog.
Log file SSE-KMS encryption: Clear the check box. Use the default SSE-S3 encryption method for log files.
Choose log events
On the Choose log events page , configure as described below, and then click Next.
Event type: Management events.
API activity: Read, Write.
Review and create
On the Review and create page , review all configuration items . After confirming everything is correct, click Create trail.
Step 2: Create an SQS Message Queue
This queue is used to receive log file event notifications from the S3 bucket and serves as the target message channel for log delivery. For more information, see the official AWS documentation: Create a message queue .
Sign in to the AWS SQS console.
Sign in to the AWS SQS console , select a region, and then click Create queue.
WarningMake sure the selected region is the same as the one where you created the CloudTrail trail.
Configure queue details
Type : Standard .
Name: Enter an easily identifiable queue name (for example,
aliyun-sasc-log-queue).ImportantThis queue name will be used to generate its unique ARN for subsequent access policy configuration. Make sure it is entered correctly.
Configure the access policy
This is the most critical step. This policy defines who can send messages to this queue and who can read messages from it.
In the Access policy panel, select Advanced.
ImportantRecord the Account ID and queue ARN from the default policy for subsequent access policy configuration.
In the JSON policy, the Account ID is located in the
Statement.Principal.AWSfield, and the queue ARN is located in theStatement.Resourcefield.Copy the entire JSON template below and paste it into the policy editor, replacing all existing content.
{ "Version": "2012-10-17", "Id": "__default_policy_ID", "Statement": [ { "Sid": "__owner_statement", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::${Account ID}:root" }, "Action": "SQS:*", "Resource": "${SQS ARN}" }, { "Sid": "example-statement-ID", "Effect": "Allow", "Principal": { "Service": "s3.amazonaws.com" }, "Action": [ "SQS:SendMessage" ], "Resource": "${SQS ARN}", "Condition": { "ArnLike": { "aws:SourceArn": "arn:aws:s3:*:*:${S3 bucket name}" } } } ] }[Important] Replace the placeholders in the template according to the following table:
Placeholder
How to Obtain the Value
Example
${Account ID}The Account ID saved in the previous step.
99********1${SQS ARN}The SQS ARN saved in the previous step.
arn:aws:sqs:ap-northeast-1:123******012:aliyun-sasc-log-queue${S3 bucket name}The name of the S3 bucket set when you created the CloudTrail trail.
NoteYou can sign in to the AWS S3 console, find the bucket in the corresponding region, and view its information on the details page.
aws-cloudtrail-logs-123******12-abcdefAfter replacing the placeholders, scroll to the bottom of the page and click Create queue.
Step 3: Create an S3 Event Notification
This step configures an event notification rule for the S3 bucket to automatically send notifications to the specified SQS queue when new log files are generated. For more information, see the official AWS documentation: Amazon S3 event notifications .
Sign in to the AWS S3 console
Sign in to the AWS S3 console, and in the region selector, click General purpose buckets.
WarningMake sure the selected region is the same as the one where you created the CloudTrail trail.
On the General purpose buckets tab, locate the S3 bucket name set when creating the CloudTrail trail, and go to its details page.
Configure the event notification
On the Properties tab, in the Event notifications section, click Create event notification. Complete the configuration as described below.
Event types: Select Put.
Destination: Select SQS queue, and specify the SQS queue created in Step 2: Create an SQS Message Queue.
After completing the configuration, click Save changes.
Step 4: Configure Queue Read and Write Permissions
This step grants the dedicated IAM user created by Security Center permission to read notification messages from the SQS queue.
Create an SQS policy:
Sign in to the AWS IAM console. On the Policies page, click Create Policy.
Complete the configuration as described below.
Selected service: SQS.
Effect: Allow.
Read : Select GetQueueUrl and ReceiveMessage.
Write : Select ReceiveMessage.
Resources: Click Add ARN, and enter the queue ARN in the Resource ARN field.
NoteYou can sign in to the AWS SQS console , find the queue in the corresponding region, and view its ARN on the details page.
Attach the policy to the IAM user:
Refer to Set user permissions to attach the SQS policy created in the previous step to the target IAM user.
FAQ
Why can't I see some onboarded AWS resources in Security Center?
Region not selected: In the onboarding configuration in Security Center, verify that the AWS region where the resource is located has been selected.
Synchronization delay: After initial onboarding or configuration changes, there may be a delay in asset synchronization. Please wait for the synchronization to complete.
What should I do if the automatic credential and permission verification fails after filling in the access key?
Permission issue: The sub-account has insufficient permissions. Refer to Set user permissions, go to the AWS console to modify or supplement the relevant user permission policy.
Account issue: For the quick configuration method, the access key must be generated by the root account. Refer to Step 1: Create root account credentials in AWS, sign in to the AWS console as the root account and create an API access key.
Region issue: The currently selected region is unavailable. Try switching to another available region or the corresponding domain, and then resubmit.