All Products
Search
Document Center

ActionTrail:Audit events in Bastionhost

Last Updated:Aug 20, 2026

Bastionhost is integrated with ActionTrail. You can use ActionTrail to query management events that are generated by user operations in Bastionhost. ActionTrail can also deliver management events to a Logstore in Simple Log Service (SLS) or a bucket in Object Storage Service (OSS) for purposes such as real-time auditing and issue tracing.

Event list

ActionTrail records management events that are generated when users perform operations on cloud resources through OpenAPI or the console. The following table lists the Bastionhost events that are recorded by ActionTrail.

Event name

Event definition

AcceptApproveCommand

Allow a single command.

AcceptOperationTicket

Allow an O&M request.

AddDatabasesToAssetGroup

Batch add databases to a specified asset group.

AddDatabasesToGroup

Batch add database instances to a specified asset group.

AddHostsToAssetGroup

Batch add hosts to a specified resource group.

AddHostsToGroup

Batch add hosts to a specified host group.

AddInstanceMember

Add multiple member accounts to Bastionhost.

AddInstanceRdMember

Add RD member accounts to a Bastionhost instance.

AddNotificationReceiveUsers

Batch add message notification recipients.

AddUsersToGroup

Batch add users to a user group.

AllowCommand

Allow execution of a pending command that requires approval.

AllowCommands

Batch allow execution of pending commands that require approval.

AllowOmTickets

Batch approve O&M approval tickets.

AllowOpsTaskApprovals

Allow pending automatic O&M tasks.

AttachAppAccountsToUser

Batch grant applications and accounts to a specified user.

AttachAppAccountsToUserGroup

Batch grant applications and application accounts to a specified user group.

AttachAppsToAssetGroup

Batch add applications to a specified resource group.

AttachAppsToPolicy

Batch associate applications with control policies.

AttachAssetGroupAccountsToUser

Batch grant asset groups and account names to a specified user.

AttachAssetGroupAccountsToUserGroup

Batch grant asset groups and account names to a specified user group.

AttachAssetGroupsToAsset

Batch associate assets with asset groups.

AttachAssetGroupsToHost

Batch associate hosts with asset groups.

AttachAssetGroupsToPolicy

Batch add asset groups to control policies.

AttachDatabaseAccountsToUser

Batch grant databases and accounts to a specified user.

AttachDatabaseAccountsToUserGroup

Batch grant databases and accounts to a specified user group.

AttachDatabasesToPolicy

Batch associate databases with control policies.

AttachHostAccountsToHostShareKey

Batch associate host accounts with a specified shared key.

AttachHostAccountsToPasswordTask

Batch associate host accounts with a password change task.

AttachHostAccountsToShareKey

Batch associate host accounts with a specified shared key.

AttachHostAccountsToUser

Grant hosts and host accounts to a user.

AttachHostAccountsToUserGroup

Grant hosts and host accounts to a user group.

AttachHostGroupAccountsToUser

Grant host groups and host accounts to a user.

AttachHostGroupAccountsToUserGroup

Grant host groups and host accounts to a user group.

AttachHostGroupsToHost

Batch associate hosts with host groups.

AttachHostGroupsToPolicy

Batch add host groups to control policies.

AttachHostGroupsToUser

Grant host groups to a user.

AttachHostGroupsToUserGroup

Batch grant host groups and account names to a specified user group.

AttachHostsToPolicy

Batch associate hosts with a specified control policy.

AttachHostsToUser

Batch grant hosts to a user.

AttachHostsToUserGroup

Batch grant hosts to a user group.

AttachUserGroupsToPolicy

Batch associate user groups with a specified control policy.

AttachUserGroupsToUser

Batch associate user groups with a specified user.

AttachUsersToPolicy

Batch associate users with a specified control policy.

BanDatabases

Batch disable databases.

BanHosts

Batch disable hosts.

BatchAuthorizeAppAccount

Batch grant applications and accounts to specified users and user groups.

BatchAuthorizeDatabaseAccount

Batch grant databases and accounts to specified users and user groups.

BatchAuthorizeHostAccount

Batch grant hosts and accounts to specified users and user groups.

BindIDaaSInstance

Bind an IDaaS instance to Bastionhost.

CancelAutoOperationTask

Cancel an O&M task.

CancelInstanceMigration

Cancel instance migration.

CancelOperationOmTickets

Cancel O&M approval tickets.

CancelPasswordTasks

Cancel password change tasks.

CancelSessionArchiveTask

Cancel audit session archiving tasks.

CheckOperationAssetPolicy

Check the control policy for O&M assets.

CheckOperationNeedApprove

Check whether O&M requires approval.

CheckUserNamesExistence

Check whether usernames exist.

ClearInstanceADAuthServer

Clear the AD server configuration of Bastionhost.

ClearInstanceLDAPAuthServer

Clear the AD server configuration of Bastionhost.

ConfigInstanceNetwork

Configure instance network settings.

ConfigInstancePort

Configure instance ports.

ConfigInstanceRouterRules

Configure instance routing rules.

ConfigInstanceSecurityGroups

Configure security groups for a specified Bastionhost instance.

ConfigInstanceWhiteList

Configure a public IP address whitelist for a Bastionhost instance.

Create

Purchase on the product sales page.

CreateApp

Create an application.

CreateAppAccount

Create an application account.

CreateAppServer

Create an application server.

CreateAppTool

Create an application remote client.

CreateAssetGroup

Create an asset group.

CreateAssetSource

Create an asset source.

CreateAsyncEcsRequest

Create a request to synchronize ECS instances.

CreateAsyncJob

Create an asynchronous task.

CreateAsyncRdsRequest

Create a request to synchronize RDS instances.

CreateAuditEventBackupRecord

Create a manual backup.

CreateAutoOperationScript

Create an automatic O&M task script.

CreateAutoOperationTask

Create an automatic O&M task.

CreateDatabase

Create a database.

CreateDatabaseAccount

Create a database account.

CreateDatabaseMaskPolicy

Create a database masking policy.

CreateDatabases

Batch create databases.

CreateDatabasesAccount

Create a database account.

CreateExportConfigJob

Create a configuration backup export task.

CreateHost

Create a host that requires O&M in Bastionhost.

CreateHostAccount

Create a host account for a specified host.

CreateHostGroup

Create a host group.

CreateHosts

Batch create hosts.

CreateHostsAccount

Create a host account.

CreateHostShareKey

Create a host shared key.

CreateInstance

Create an instance.

CreateInstanceADAuthServer

Create an instance AD authentication server.

CreateNetworkDomain

Create a network domain.

CreateNetworkDomainProxy

Create a network domain proxy server.

CreateOldInstanceDataExportTask

Create a session recording export task.

CreateOperationOmTicket

Create an O&M approval ticket.

CreateOperationTicket

Create an O&M request.

CreateOpsAddrNotificationTasks

Create O&M address notification tasks.

CreatePasswordTask

Create a password change task.

CreatePolicy

Create a control policy.

CreatePublicAutoOpsScript

Create a public automatic O&M task script.

CreateRdsHosts

Create RDS-type hosts.

CreateRule

Create an authorization rule.

CreateSessionArchiveTask

Create an audit session archiving task.

CreateShareKey

Create a shared key.

CreateUser

Create a user.

CreateUserGroup

Create a user group.

CreateUserPublicKey

Create a user public key.

CreateUsers

Batch create users.

DeleteAppAccounts

Batch delete application accounts.

DeleteApps

Batch delete applications.

DeleteAppServers

Batch delete application servers.

DeleteAppTools

Batch delete remote clients.

DeleteAssetGroup

Delete an asset group.

DeleteAssetGroups

Batch delete asset groups.

DeleteAssetSource

Delete an asset source.

DeleteAuditSessionVideo

Delete session recordings.

DeleteAutoOperationScripts

Delete automatic O&M task scripts.

DeleteAutoOperationTasks

Batch delete automatic O&M tasks.

DeleteAutoOpsScripts

Administrators batch delete automatic task scripts.

DeleteAutoOpsTasks

Batch delete automatic O&M tasks.

DeleteDatabase

Delete a single database instance.

DeleteDatabaseAccount

Delete a single database account.

DeleteDatabaseAccounts

Delete database accounts.

DeleteDatabaseMaskPolicies

Delete database masking policies.

DeleteDatabases

Batch delete databases.

DeleteDatabasesAccount

Batch delete accounts for multiple databases.

DeleteHost

Delete a single host.

DeleteHostAccount

Delete a single host account.

DeleteHostAccounts

Delete host accounts.

DeleteHostGroup

Delete a single host group.

DeleteHostGroups

Batch delete host groups.

DeleteHosts

Batch delete hosts.

DeleteHostsAccount

Delete host accounts.

DeleteHostShareKey

Delete a host shared key.

DeleteHostShareKeys

Batch delete host shared keys.

DeleteInstanceADAuthServer

Delete an instance AD authentication server.

DeleteManualEventBackupRecord

Delete a manual backup.

DeleteNetworkDomain

Delete a single network domain.

DeleteNetworkDomainProxy

Delete a network domain proxy server.

DeleteOldInstanceDataExportTask

Delete a session recording export task.

DeletePasswordTasks

Delete password change tasks.

DeletePolicies

Batch delete control policies.

DeletePolicy

Delete a single control policy.

DeleteRule

Delete a single authorization rule.

DeleteRules

Batch delete authorization rules.

DeleteShareKeys

Batch delete shared keys.

DeleteUser

Delete a user.

DeleteUserGroup

Delete a user group.

DeleteUserGroups

Batch delete user groups.

DeleteUserPublicKey

Delete a user public key.

DeleteUserPublicKeys

Batch delete user public keys.

DeleteUsers

Batch delete users.

DeleteUserUsbKey

Remove a user USB key.

DenyCommand

Reject execution of a pending command that requires approval.

DenyCommands

Batch reject execution of pending commands that require approval.

DenyOmTickets

Batch reject tickets.

DescribeAppOverview

Retrieve overview data.

DescribeAssetSourceRegions

Retrieve the list of asset source regions.

DescribeAuditHistorySessionOverview

Retrieve historical session overview data.

DescribeAuditLiveSessionOverview

Retrieve real-time session overview data.

DescribeEcsRegion

Retrieve the list of ECS regions.

DescribeGrant

Retrieve authorization information.

DescribeInstance

Query instance information.

DescribeInstanceAttribute

Query all attribute information of an instance.

DescribeInstanceBastionhost

Retrieve the bastion host of an instance.

DescribeInstanceConsoleVersion

Query the system version of an instance.

DescribeInstanceLoginTicket

Retrieve the login ticket of an instance.

DescribeInstanceOperationTicket

Retrieve the operation ticket of an instance.

DescribeInstances

Query the list of instances.

DescribeOpenService

Retrieve the service activation status.

DescribeOperateName

Retrieve the list of operation behaviors.

DescribeRegions

Query the Alibaba Cloud regions supported by Bastionhost instances.

DescribeSyncInfo

Retrieve synchronization information.

DetachAppAccountsFromUser

Batch revoke application and account authorizations from a specified user.

DetachAppAccountsFromUserGroup

Batch revoke application and account authorizations from a specified user group.

DetachAppsFromAssetGroup

Batch detach applications from asset groups.

DetachAppsFromPolicy

Batch detach applications from a specified control policy.

DetachAssetGroupAccountsFromUser

Batch revoke asset group and account authorizations from a specified user.

DetachAssetGroupAccountsFromUserGroup

Batch revoke asset group and account authorizations from a specified user group.

DetachAssetGroupsFromAsset

Remove a specified asset from asset groups.

DetachAssetGroupsFromHost

Batch remove asset groups from a specified host.

DetachAssetGroupsFromPolicy

Batch remove asset groups from a specified control policy.

DetachDatabaseAccountsFromUser

Revoke database and database account authorizations granted to a user.

DetachDatabaseAccountsFromUserGroup

Revoke database and database account authorizations granted to a user group.

DetachDatabasesFromPolicy

Batch remove database associations from control policies.

DetachHostAccountsFromHostShareKey

Remove the association between host accounts and a shared key.

DetachHostAccountsFromPasswordTask

Batch detach host accounts from a specified password change task.

DetachHostAccountsFromShareKey

Batch detach host accounts from a specified host shared key.

DetachHostAccountsFromUser

Revoke host and host account authorizations granted to a user.

DetachHostAccountsFromUserGroup

Revoke host and host account authorizations granted to a user group.

DetachHostGroupAccountsFromUser

Revoke authorized host groups and host accounts from a user.

DetachHostGroupAccountsFromUserGroup

Revoke authorized host groups and host accounts from a user group.

DetachHostGroupsFromHost

Batch detach host groups from a specified host.

DetachHostGroupsFromPolicy

Batch detach host groups from a specified control policy.

DetachHostGroupsFromUser

Batch revoke host group authorizations from a specified user.

DetachHostGroupsFromUserGroup

Batch revoke host group authorizations from a specified user group.

DetachHostsFromPolicy

Batch detach hosts from a specified control policy.

DetachHostsFromUser

Batch revoke host authorizations from a specified user.

DetachHostsFromUserGroup

Batch revoke host authorizations from a specified user group.

DetachUserGroupsFromPolicy

Batch detach user groups from a specified control policy.

DetachUserGroupsFromUser

Batch detach user groups from a specified user.

DetachUsersFromPolicy

Batch detach users from a specified control policy.

DisableInstancePublicAccess

Turn off public network access for an instance.

DisableRule

Disable an authorization rule.

DownloadAuditEventBackupRecord

Retrieve the download URL of an event backup record.

EnableInstancePublicAccess

Turn on public network access for a specified Bastionhost instance.

EnablePasswordTasks

Batch enable password change tasks.

EnableRDService

Enable the RD trusted service.

EnableRule

Enable an authorization rule.

ExecutePasswordTasks

Batch execute password change tasks.

ExecutePasswordTaskWithHostAccounts

Batch execute host accounts for a specified password change task.

ExportAuditReport

Export an O&M audit report.

ExportAuthenticationRules

Export authorization rules.

ExportDatabases

Export databases.

ExportHostAccountsPasswordHistory

Export the password change history of a password change task.

ExportHosts

Export hosts.

ExportPasswordTaskHistoryByTurnID

Export the history of a password change task.

GenerateAssetOperationToken

Request an O&M token.

GetADAuthServer

Retrieve the AD authentication server configuration of an instance.

GetApp

Retrieve application details.

GetAppServer

Retrieve application server details.

GetAppServerDeploymentScript

Retrieve the deployment script of an application server.

GetArchiveConfig

Retrieve audit archiving configurations.

GetAssetGroup

Retrieve an asset group.

GetAssetOperationToken

Retrieve the details of an asset O&M token.

GetAssetPolicy

Retrieve the asset policy information of an instance.

GetAsyncEcsRequestResult

Retrieve the result of an ECS synchronization request.

GetAsyncJob

Retrieve an asynchronous task.

GetAsyncRdsRequestResult

Retrieve the result of an RDS synchronization request.

GetAuditAutoOperationDetail

Retrieve the details of automatic O&M results.

GetAuditAutoOperationOutput

Retrieve the execution results of an automatic O&M task.

GetAuditCountReport

Retrieve the number of O&M operations from a report.

GetAuditDatabaseEvent

Retrieve database O&M events.

GetAuditDownloadUrlForAutoOpsTask

Retrieve the download URL for O&M task output.

GetAuditDurationReport

Retrieve the O&M duration data from a report.

GetAuditFileSizeReport

Retrieve the O&M size data from a report.

GetAuditManagementLog

Retrieve operation logs.

GetAuditOMConfig

Retrieve O&M configurations.

GetAuditOssDownloadUrl

Retrieve the OSS download URL for Bastionhost-related tools.

GetAuditPlaySessionInfo

Retrieve session details.

GetAuditPlayUrl

Retrieve the session playback URL.

GetAuditReportOverview

Retrieve O&M report overview data.

GetAuditSession

Retrieve session details.

GetAuditSessionPolicy

Retrieve audit session policies.

GetAutoOperationScript

Retrieve the details of an automatic O&M task script.

GetAutoOperationSubTaskOutput

Retrieve the execution result of a single account in an automatic O&M task.

GetAutoOperationTask

Retrieve the details of an automatic O&M task.

GetAutoOperationTaskCapacity

Retrieve the allowed capacity of an O&M task.

GetAutoOpsScript

Administrators retrieve O&M script details.

GetAutoOpsTask

Administrators retrieve O&M tasks.

GetDatabase

Retrieve database details.

GetDatabaseAccount

Retrieve database account details.

GetDatabaseMaskPolicy

Retrieve database masking policies.

GetDataEncryptionConfig

Retrieve data encryption methods.

GetDownloadUrlForAutoOperationTask

O&M personnel retrieve the download URL for automatic O&M resources.

GetExportConfigJob

Retrieve the details of a configuration backup export task.

GetGenerateAssetOperationToken

Generate an asset O&M token.

GetHost

Retrieve the details of a specified host.

GetHostAccount

Retrieve the details of a specified host account.

GetHostAccountPasswordTaskOutput

Retrieve the execution output of a host account in a password change task.

GetHostGroup

Retrieve the details of a specified host group.

GetHostShareKey

Retrieve the details of a host shared key.

GetIDaaSInstanceConfig

Retrieve the information of a bound IDaaS instance.

GetIDaaSServer

Retrieve the IDaaS authentication server configuration.

GetInstanceADAuthServer

Retrieve the AD authentication server configuration of an instance.

GetInstanceLDAPAuthServer

Retrieve the LDAP authentication server configuration of an instance.

GetInstanceMigration

Retrieve instance migration information.

GetInstanceStoreInfo

Query the storage status information of an instance.

GetInstanceTLSConfig

Retrieve the TLS configuration of an instance O&M port.

GetInstanceTwoFactor

Retrieve the two-factor authentication configuration of an instance.

GetInstanceUpgradeInfo

Retrieve instance upgrade information.

GetLDAPAuthServer

Retrieve the LDAP authentication server configuration of an instance.

GetLoginPolicy

Retrieve the login policy of an instance.

GetNetworkDomain

Retrieve network domain details.

GetNotificationConfig

Retrieve message notification policies.

GetOMConfig

Retrieve O&M configurations.

GetOpenMemberStatus

Retrieve the membership activation status of a user.

GetOperationAssetNetworkDiagnosticInfo

Retrieve asset network diagnostic information.

GetOperationDatabaseToken

Retrieve a database O&M token.

GetOperationOssDownloadUrl

Retrieve the OSS download URL for Bastionhost-related tools.

GetOperationSSOConfig

Retrieve the Bastionhost Assistant O&M configuration.

GetOperationToken

Retrieve a host O&M token.

GetOssDownloadUrl

Retrieve the OSS download URL for resources.

GetOssPolicyToken

Retrieve an OSS signed direct upload token.

GetPasswordTask

Retrieve the details of a password change task.

GetPolicy

Retrieve the details of a control policy.

GetPolicyAssetScope

Retrieve the effective asset scope of a specified control policy.

GetPolicyUserScope

Retrieve the effective user scope of a specified control policy.

GetRule

Retrieve an authorization rule.

GetSessionPolicy

Retrieve session cleanup policies.

GetShareKey

Retrieve a shared key.

GetSpecialAccountInfo

Retrieve the O&M special account configuration.

GetStoreInfo

Retrieve storage usage information.

GetStorePolicy

Retrieve storage policy configurations.

GetTwoFactor

Retrieve two-factor authentication configurations.

GetUnattachUserList

Retrieve the list of users who can bind USB keys.

GetUser

Retrieve user information.

GetUserGroup

Retrieve the details of a specified Bastionhost user group.

GetUserLoginPolicy

Retrieve user login control policies.

GetUserPasswordConfig

Retrieve user password configuration information.

GetUserPasswordExpire

Retrieve user password expiration configuration.

GetUserPolicy

Retrieve user policy configurations.

GetUserPublicKey

Retrieve user public key details.

GrantServiceRole

Grant a service role.

ImportDatabases

Import files to databases and accounts.

ImportHosts

Import files and accounts to hosts.

ImportKMSSecretsForHosts

Import KMS credentials for specified ECS hosts.

InterruptAuditSession

Terminate a single session.

InterruptAuditSessions

Batch terminate sessions.

ListADAuthServers

Retrieve AD authentication servers of an instance.

ListAllHostAccountsForAutoOperationTask

Retrieve all accounts that can be associated with a specified O&M task.

ListAppAccounts

Retrieve the list of application accounts.

ListAppAccountsForPolicy

Retrieve the list of accounts that can be associated with a specified application.

ListAppAccountsForRule

Retrieve the list of application accounts under a specified O&M rule.

ListAppAccountsForUser

Retrieve applications and accounts authorized to a specified user.

ListAppAccountsForUserGroup

Retrieve applications and accounts authorized to a specified user group.

ListApproveCommands

Retrieve the list of commands that require approval.

ListApps

Retrieve the list of applications.

ListAppServerAccounts

Retrieve the list of accounts for a specified application server.

ListAppServers

Retrieve the list of application servers.

ListAppsForPolicy

Retrieve applications associated with a specified policy.

ListAppsForUser

Retrieve the list of applications authorized or not authorized to a specified user.

ListAppsForUserGroup

Retrieve the list of applications authorized or not authorized to a specified user group.

ListAppsInAssetGroup

Retrieve the list of applications in an asset group.

ListAppsNotForPolicy

Retrieve databases not associated with a specified policy.

ListAppsNotForRule

Retrieve applications not associated with a specified authorization rule.

ListAppsNotInAssetGroup

Retrieve the list of applications not in an asset group.

ListAppTools

Retrieve the list of application clients.

ListAssetConnectStatus

Query the connection status of assets.

ListAssetGroupAccountNames

Retrieve all account names under a specified asset group.

ListAssetGroupAccountNamesForUser

Query asset groups and account names authorized to a specified user.

ListAssetGroupAccountNamesForUserGroup

Query asset groups and account names authorized to a specified user group.

ListAssetGroups

Query the list of asset groups.

ListAssetGroupsForHost

Query the list of asset groups that a specified host has joined.

ListAssetGroupsForPolicy

Query asset groups associated with a specified control policy.

ListAssetGroupsForUser

Query asset groups authorized to a specified user.

ListAssetGroupsForUserGroup

Query asset groups authorized to a specified user group.

ListAssetGroupsNotForHost

Query asset groups that a specified host has not joined.

ListAssetGroupsNotForPolicy

Query asset groups not associated with a specified control policy.

ListAssetGroupsNotForRule

Query asset groups not associated with a specified authorization rule.

ListAssetSourceInstances

Query instances under a specified asset source.

ListAssetSources

Query the list of asset sources.

ListAuditAutoOperationEvents

Retrieve the O&M task audit list.

ListAuditCommandEvents

Query O&M command events.

ListAuditDatabaseEvents

Query O&M database events.

ListAuditEventBackupRecords

Query event backup records.

ListAuditEventTypes

Query O&M event types.

ListAuditFileEvents

Query O&M file events.

ListAuditGraphEvents

Query O&M graphical events.

ListAuditHistorySessions

Query historical O&M sessions.

ListAuditHostAccountsForAutoOperation

Retrieve the list of accounts related to automatic O&M task results.

ListAuditLiveSessions

Query real-time O&M sessions.

ListAuditManagementLogs

Query operation logs.

ListAuditPlayFiles

Query session files.

ListAuditPlayInstructions

Query session events.

ListAutoOperationHistory

Retrieve the historical details of a specified O&M task.

ListAutoOperationScript

Retrieve the list of automatic O&M scripts for O&M personnel.

ListAutoOperationSubTasksForHistory

Retrieve account execution records for a specified execution task history.

ListAutoOperationTasks

O&M personnel retrieve the list of O&M tasks.

ListAutoOpsTasks

Administrators and O&M personnel retrieve the list of O&M tasks.

ListBannedIps

Retrieve the list of banned IP addresses.

ListDatabaseAccounts

Retrieve the list of database accounts.

ListDatabaseAccountsForPolicy

Retrieve the list of database accounts associated with a specified control policy.

ListDatabaseAccountsForRule

Query database accounts associated with a specified authorization rule.

ListDatabaseAccountsForUser

Query database accounts authorized to a specified user.

ListDatabaseAccountsForUserGroup

Query database accounts authorized to a specified user group.

ListDatabaseMaskPolicies

Query database masking policies.

ListDatabases

Query the list of databases.

ListDatabasesForPolicy

Query the list of databases associated with a control policy.

ListDatabasesForUser

Query the list of databases authorized to a user.

ListDatabasesForUserGroup

Query the list of databases authorized to a user group.

ListDatabasesInAssetGroup

Query databases under a specified asset group.

ListDatabasesNotForPolicy

Query the list of databases not associated with a control policy.

ListDatabasesNotForRule

Query databases not associated with a specified authorization rule.

ListDatabasesNotInAssetGroup

Query databases not associated with a specified asset group.

ListDoneOmTickets

Query the list of processed O&M approval tickets.

ListDoneOpsTaskApprovals

Administrators retrieve the list of approved O&M tasks.

ListHostAccounts

Retrieve the list of host accounts.

ListHostAccountsForAutoOperationTask

Retrieve the list of accounts associated with a specified O&M task.

ListHostAccountsForAutoOpsTask

Administrators retrieve the list of all accounts associated with a task.

ListHostAccountsForHostShareKey

Retrieve host accounts associated with a host shared key.

ListHostAccountsForPasswordTask

Query host accounts associated with a specified password change task.

ListHostAccountsForPolicy

Retrieve the list of host accounts associated with a specified control policy.

ListHostAccountsForRule

Query host accounts associated with a specified authorization rule.

ListHostAccountsForShareKey

Query host accounts associated with a specified shared key.

ListHostAccountsForUser

Query the list of authorized host accounts.

ListHostAccountsForUserGroup

Query the list of authorized host accounts.

ListHostAccountsNotForAnyPasswordTask

Query host accounts not associated with any password change task.

ListHostAccountsOfHost

Query host accounts under a specified host.

ListHostGroupAccountNamesForUser

Query authorized host account names in a host group.

ListHostGroupAccountNamesForUserGroup

Query authorized host account names.

ListHostGroups

Retrieve the list of host groups under a specified Bastionhost.

ListHostGroupsForHost

Query host groups that a specified host has joined.

ListHostGroupsForPolicy

Query host groups associated with a specified control policy.

ListHostGroupsForUser

Query the list of authorized or unauthorized host groups.

ListHostGroupsForUserGroup

Query the list of authorized or unauthorized host groups.

ListHostGroupsNotForHost

Query host groups not associated with a specified host.

ListHostGroupsNotForPolicy

Query host groups not associated with a specified control policy.

ListHostGroupsNotForRule

Query host groups not associated with a specified authorization rule.

ListHosts

Query the list of hosts under a specified Bastionhost instance.

ListHostsForAppServer

Retrieve the list of available hosts for an application server.

ListHostsForPolicy

Query hosts associated with a control policy.

ListHostsForUser

Query the list of authorized or unauthorized hosts.

ListHostsForUserGroup

Query the list of authorized or unauthorized hosts.

ListHostShareKeys

Retrieve the list of host shared keys.

ListHostsInAssetGroup

Query hosts under a specified asset group.

ListHostsInGroup

Query hosts under a specified host group.

ListHostsNotForPolicy

Query hosts not associated with a specified control policy.

ListHostsNotForRule

Query hosts not associated with a specified authorization rule.

ListHostsNotInAssetGroup

Query hosts not associated with a specified asset group.

ListHostsNotInGroup

Query hosts not associated with a specified host group.

ListInstanceDistributions

Retrieve the instance distribution list.

ListInstanceMembers

Retrieve the list of Bastionhost RD member accounts.

ListInstanceRdMembers

Query the list of imported RD member accounts in a specified Bastionhost instance.

ListKMSSecretsForHosts

Batch retrieve the list of KMS credentials bound to specified ECS hosts.

ListNetworkDomains

Query the list of network domains.

ListNewDNsForUser

Retrieve new DNs for AD/LDAP users.

ListNotificationReceiveUsers

Query the list of message notification recipients.

ListOldInstanceDataExportTask

Retrieve the list of data export tasks.

ListOperationApps

Retrieve operable applications.

ListOperationAppServers

O&M personnel retrieve the list of application servers.

ListOperationAppTools

O&M personnel retrieve remote clients.

ListOperationAssetConnectStatus

Retrieve asset connection status.

ListOperationAssetSources

O&M personnel retrieve asset sources.

ListOperationDatabaseAccounts

Query accounts authorized for a specified database.

ListOperationDatabases

Retrieve the list of authorized databases.

ListOperationHostAccounts

Retrieve the list of authorized host accounts.

ListOperationHostAccountsOfHosts

Query accounts authorized for a specified host.

ListOperationHosts

Retrieve the list of authorized hosts.

ListOperationOmTickets

Retrieve the list of message notification recipients.

ListOperationTickets

Retrieve the list of O&M requests that require approval.

ListOperationUserAssetGroups

O&M personnel retrieve the list of asset groups.

ListPasswordTaskExecuteHistory

Query the execution history of password change tasks.

ListPasswordTasks

Query the list of password change tasks.

ListPolicies

Query the list of control policies.

ListPublicAutoOpsScript

Administrators retrieve public scripts.

ListRuleAppsForUser

Retrieve applications authorized or not authorized to a specified user under the authorization rule dimension.

ListRuleAssetGroupsForUser

Retrieve asset groups authorized or not authorized to a specified user under the authorization rule dimension.

ListRuleDatabasesForUser

Retrieve databases authorized or not authorized to a user under the authorization rule dimension.

ListRuleHostsForUser

Retrieve hosts authorized or not authorized to a user under the authorization rule dimension.

ListRules

Query the list of authorization rules.

ListSessionArchiveTasks

Retrieve the list of audit session archiving tasks.

ListShareKeys

Query the list of shared keys.

ListTagKeys

Query the list of tags bound to a resource.

ListTagResources

Query the list of tags bound to Bastionhost instances.

ListTasksForAutoOperationScript

Retrieve the list of O&M tasks associated with a specified script.

ListTasksForAutoOpsScript

Administrators retrieve the list of O&M tasks associated with a specified script.

ListTodoOmTickets

Query unprocessed O&M approval tickets.

ListTodoOpsTaskApprovals

Administrators retrieve the list of unapproved O&M tasks.

ListUserAttachToUsbKeys

Retrieve the list of user USB keys.

ListUserGroupAppsForUser

Retrieve applications authorized or not authorized to a user under the user group dimension.

ListUserGroupAssetGroupsForUser

Retrieve asset groups authorized or not authorized to a user under the user group dimension.

ListUserGroupDatabasesForUser

Retrieve databases authorized or not authorized to a user under the user group dimension.

ListUserGroupHostsForUser

Retrieve hosts authorized or not authorized to a user under the user group dimension.

ListUserGroups

Retrieve the list of user groups.

ListUserGroupsForPolicy

Query user groups associated with a specified control policy.

ListUserGroupsForUser

Query user groups that a specified user has joined.

ListUserGroupsNotForPolicy

Query user groups not associated with a specified control policy.

ListUserGroupsNotForRule

Query user groups not associated with a specified authorization rule.

ListUserGroupsNotForUser

Query user groups that a specified user has not joined.

ListUserPublicKeys

Query the list of user public keys.

ListUsers

Retrieve the list of user details.

ListUsersForAD

Query the list of users under an AD authentication server.

ListUsersForIDaaS

Query the list of users under an IDaaS authentication server.

ListUsersForIDaaSEIAM

Retrieve the list of users not imported from an IDaaSEIAM server.

ListUsersForLDAP

Query the list of users under an LDAP authentication server.

ListUsersForPolicy

Query users associated with a specified control policy.

ListUsersInGroup

Query users in a specified user group.

ListUsersNotForPolicy

Query the list of users not associated with a specified control policy.

ListUsersNotForRule

Query users not associated with a specified authorization rule.

ListUsersNotInGroup

Query users not associated with a specified user group.

ListUserSourceEventLogs

Retrieve the list of user source synchronization events.

LockUsers

Batch lock Bastionhost users.

ManualSyncInstances

Manually synchronize asset source instances.

Modify

Change configurations on the product sales page.

ModifyADAuthServer

Modify the AD authentication server configuration of Bastionhost.

ModifyApp

Modify application details.

ModifyAppAccount

Modify an application account.

ModifyAppServer

Modify an application server.

ModifyAppTool

Modify an application client.

ModifyArchiveConfig

Modify audit archiving configurations.

ModifyAssetGroup

Modify asset group information.

ModifyAssetPolicy

Modify asset policies.

ModifyAssetSource

Modify asset source information.

ModifyAutoOperationScript

O&M personnel modify automatic O&M scripts.

ModifyAutoOperationTask

O&M personnel modify O&M task details.

ModifyAutoOperationTasks

O&M personnel batch modify O&M task details.

ModifyCustomName

Modify a custom name.

ModifyDatabase

Modify database information.

ModifyDatabaseAccount

Modify database account information.

ModifyDatabaseMaskPoliciesState

Batch modify the status of database masking policies.

ModifyDatabaseMaskPolicy

Modify database masking policy information.

ModifyDatabasesActiveAddressType

Modify the database endpoint type.

ModifyDataEncryptionConfig

Modify data encryption methods.

ModifyHost

Modify basic host information.

ModifyHostAccount

Modify host account information.

ModifyHostAccountNamesForUser

Modify host and account names authorized to a specified user.

ModifyHostAccountNamesForUserGroup

Modify host and account names authorized to a specified user group.

ModifyHostAccountsForUser

Modify hosts and accounts authorized to a specified user.

ModifyHostAccountsForUserGroup

Modify hosts and accounts authorized to a specified user group.

ModifyHostActiveIp

Modify the host IP type.

ModifyHostGroup

Modify the name or description of a host group.

ModifyHostsActiveAddressType

Modify the endpoint type used for O&M on hosts.

ModifyHostShareKey

Modify a host shared key.

ModifyHostsPort

Batch modify the port of a specified protocol for hosts.

ModifyIDaaSServer

Modify the IDaaS authentication server configuration.

ModifyInstanceADAuthServer

Modify the AD authentication server configuration of an instance.

ModifyInstanceAttribute

Modify the information of a specified Bastionhost instance.

ModifyInstanceIDaaSConfig

Modify the configuration of a bound IDaaS instance.

ModifyInstanceLDAPAuthServer

Modify the LDAP authentication server configuration of an instance.

ModifyInstanceNetworkConfig

Modify the network configuration of Bastionhost.

ModifyInstanceTLSConfig

Update the TLS security configuration of an instance.

ModifyInstanceTwoFactor

Modify the two-factor authentication configuration of an instance.

ModifyInstanceUpgradePeriod

Modify the instance upgrade period.

ModifyLDAPAuthServer

Modify the LDAP authentication server information of an instance.

ModifyLocalUserForceResetPassword

Batch modify the configuration that requires local users to reset their passwords at next logon.

ModifyLoginPolicy

Modify login policies.

ModifyNetworkDomain

Modify network domain information.

ModifyNetworkDomainProxy

Modify network domain proxy server information.

ModifyNotificationConfig

Modify the message notification configuration of an instance.

ModifyOMConfig

Modify the O&M configuration of an instance.

ModifyOperationUserAssetInfo

Modify the custom information of assets for O&M personnel.

ModifyPasswordTask

Modify password change task information.

ModifyPlan

Modify a plan.

ModifyPolicy

Modify control policy information.

ModifyPortsForHost

Modify the O&M connection port of a specified host.

ModifyPublicAutoOpsScript

Administrators modify public scripts.

ModifyRule

Modify authorization rule information.

ModifyRulesState

Batch modify the status of authorization rules.

ModifySessionPolicy

Update session cleanup policies.

ModifyShareKey

Modify host shared key information.

ModifySpecialAccountInfo

Modify the O&M special account configuration of an instance.

ModifyStorePolicy

Modify the storage policy configuration of an instance.

ModifyTwoFactor

Modify the two-factor configuration of an instance.

ModifyUser

Modify a user.

ModifyUserGroup

Modify user group information.

ModifyUserPasswordConfig

Edit local user password-related configurations.

ModifyUserPasswordExpire

Modify the user password expiration configuration of an instance.

ModifyUserPolicy

Modify instance user configuration information.

ModifyUserPublicKey

Modify a user public key.

ModifyUsersEffectiveTime

Batch set user validity periods.

ModifyUsersLoginPolicy

Set user login control policies.

ModifyUsersNotificationLanguage

Batch modify the message notification language for users.

ModifyUsersTwoFactor

Batch modify user two-factor authentication methods.

MoveDatabasesToNetworkDomain

Batch move databases into a specified network domain.

MoveHostsToNetworkDomain

Batch move hosts into a specified network domain.

MoveResourceGroup

Move a Bastionhost instance to a specified resource group.

NetworkDomainConnectCheck

Check the connection status of a network domain proxy server.

RefreshEcsRequest

Refresh the ECS synchronization status.

RefundInstance

You can release an instance.

RejectApproveCommand

Reject a single command.

RejectOperationTicket

Reject an O&M request.

RejectOpsTaskApprovals

Reject automatic O&M task approvals.

Release

Release instances and other resources.

ReleaseInstance

Release an instance.

RemoveDatabasesFromAssetGroup

Batch remove databases from a specified asset group.

RemoveDatabasesFromGroup

Batch remove databases from a specified asset group.

RemoveHostsFromAssetGroup

Batch remove hosts from a specified asset group.

RemoveHostsFromGroup

Batch remove hosts from a specified host group.

RemoveInstanceMember

Remove Bastionhost RD member accounts.

RemoveInstanceRdMember

Remove RD member accounts from a Bastionhost instance.

RemoveNotificationReceiveUsers

Remove message notification recipients.

RemoveUsersFromGroup

Batch remove users from a user group.

Renew

Renew instances or resource plans.

RenewAssetOperationToken

Renew an asset O&M token.

RenewInstance

Renew an instance.

ResetHostAccountCredential

Clear the logon credentials of a specified host account.

ResetHostAccountPassword

Reset the password of a host account.

ResetHostAccountPrivateKey

Reset the private key of a host account.

ResetHostsFingerPrint

Reset host fingerprints.

SaveUserMobile

Save a user mobile number.

SetAppAccountToPolicy

Associate database accounts with a control policy.

SetAssetGroupAccountNamesToPolicy

Set account names for asset groups associated with a control policy.

SetDatabaseAccountToPolicy

Associate database accounts with a control policy.

SetDefaultAdAuthServer

Set the default AD source.

SetHostAccountToPolicy

Associate host accounts with a control policy.

SetInstancePrivatePortal

Configure a private network portal for an instance.

SetOperationSSOConfig

O&M personnel set O&M configurations.

SetPolicyAccessTimeRangeConfig

Set the logon time range restriction for a specified control policy.

SetPolicyApprovalConfig

Set the O&M approval configuration for a specified control policy.

SetPolicyAssetScope

Set the effective asset scope for a specified control policy.

SetPolicyCommandConfig

Set the command control configuration for a specified control policy.

SetPolicyIPAclConfig

Set the access control configuration for a specified control policy.

SetPolicyProtocolConfig

Set the protocol control configuration for a specified control policy.

SetPolicyUserScope

Set the effective user scope for a specified control policy.

SetUserUsbKey

Bind a certificate to a specified user.

StartAutoOperationTasks

Batch start tasks.

StartInstance

Start a specified Bastionhost instance.

StartInstanceMigration

Start instance migration.

StopAutoOperationTasks

Batch stop tasks.

StopAutoOpsTasks

Administrators batch stop tasks.

SyncUserDN

Synchronize user DNs to the latest version.

TagResources

Create and bind tags to specified Bastionhost instances.

TcpConnectCheck

Check TCP connection status.

UnbanDatabases

Batch unban databases.

UnbanHosts

Batch unban hosts.

UnbindIDaaSInstance

Unbind an IDaaSEIAM instance.

UnblockBannedIp

Unblock banned IP addresses.

UnlockUsers

Batch unlock Bastionhost users.

UntagResources

Batch unbind and delete tags from specified Bastionhost instances.

UpgradeInstanceImageVersion

Upgrade the image version of an instance.

UpgradeInstanceVersion

Upgrade the instance version.

ValidateDatabaseAccountPassword

Validate a database account password.

ValidateHostAccountPassword

Validate a host account password.

ValidateOperationDatabaseAccountPassword

Validate the password of an authorized database account.

ValidateOperationHostAccountPassword

Validate the password of an authorized host account.

VerifyADAuthServer

Verify the AD authentication server configuration of an instance.

VerifyIDaaSServer

Verify the IDaaS authentication server configuration.

VerifyInstanceADAuthServer

Verify the AD authentication server configuration of an instance.

VerifyInstanceDingTalkTwoFactorConfig

Verify the DingTalk authentication configuration of an instance.

VerifyInstanceLDAPAuthServer

Verify the LDAP authentication server configuration of an instance.

VerifyLDAPAuthServer

Verify the LDAP authentication server configuration of an instance.

VerifyUserInfoSignature

Verify user information signatures.