Bastionhost allows you to authorize a user to manage hosts. After you add a user, you can authorize the user to manage hosts. After the user is authorized to manage the hosts, the user can log on to a bastion host to perform O&M operations on the hosts. This topic describes how to authorize a user to manage hosts.

Authorize a user to manage hosts

To authorize a user to manage hosts, perform the following steps:

  1. Log on to your bastion host. For more information, see Log on to a bastion host.
  2. In the left-side navigation pane, choose Users > Users.
  3. Find the user whom you want to authorize to manage hosts and click Authorize Hosts in the Actions column.
    Authorize a user to manage hosts
  4. On the Authorized Hosts tab, click Authorize Hosts.
  5. In the Authorize Hosts panel, select one or more hosts you want to authorize the user to manage and click OK.

Remove the hosts that a user is authorized to manage

If a user is no longer required to manage specific hosts, perform the following steps to remove the hosts that the user is authorized to manage to achieve the principle of least privilege:

  1. Log on to your bastion host. For more information, see Log on to a bastion host.
  2. In the left-side navigation pane, choose Users > Users.
  3. Find the user and click Authorize Hosts in the Actions column.
    Authorize a user to manage hosts
  4. Select the hosts that you want to remove and click Remove.
    Remove the hosts that a user is authorized to manage
  5. In the message that appears, click Remove.

Authorize the accounts of a single host for a user

To authorize the accounts of a single host for a user, perform the following steps:

  1. Log on to your bastion host. For more information, see Log on to a bastion host.
  2. In the left-side navigation pane, choose Users > Users.
  3. Find the user whom you want to authorize to manage hosts and click Authorize Hosts in the Actions column.
    Authorize a user to manage hosts
  4. On the Authorized Hosts tab, click the account name or None. Authorize accounts in the Authorized Accounts column.
    Authorize the accounts of a single host
  5. In the Select Accounts panel, select one or more accounts and click Update.
    Note If no account is created on the host, you can click Create Host Account in the Select Accounts panel to create an account.

Authorize the accounts of multiple hosts for a user

To authorize the accounts of multiple hosts for a user at a time, perform the following steps:

  1. Log on to your bastion host. For more information, see Log on to a bastion host.
  2. In the left-side navigation pane, choose Users > Users.
  3. Find the user whom you want to authorize to manage hosts and click Authorize Hosts in the Actions column.
    Authorize a user to manage hosts
  4. On the Authorized Hosts tab, select the hosts whose accounts you want to authorize for the user and choose Batch > Batch Authorize Accounts. Authorize the accounts of multiple hosts for a user
  5. In the Batch Authorize Accounts panel, specify Accounts.
    Batch Authorize Accounts
    Note When you want to authorize the accounts of multiple hosts for a user at a time, you can select only one host account at a time.
  6. Click Update.

Remove the accounts of multiple hosts that are authorized for a user

To remove the accounts of multiple hosts that are authorized for a user at a time, perform the following steps:

  1. Log on to your bastion host. For more information, see Log on to a bastion host.
  2. In the left-side navigation pane, choose Users > Users.
  3. Find the user from whom you want to remove the accounts of multiple hosts and click Authorize Hosts in the Actions column.
    Authorize a user to manage hosts
  4. On the Authorized Hosts tab, select the hosts.
  5. Choose Batch > Batch Remove Authorized Accounts. Authorized Hosts tab
  6. In the Batch Remove Authorized Accounts panel, specify Accounts.
    Batch Remove Authorized Accounts pane
    Note When you remove the accounts of multiple hosts that are authorized for a user at a time, you can select only one host account at a time.
  7. Click Update.