All Products
Search
Document Center

Bastionhost:Feature comparison by Bastionhost edition

Last Updated:Aug 28, 2026

Bastionhost is available in two editions: Basic and Enterprise. Both editions include user management, asset management, O&M controls, auditing, and API access. The Enterprise edition adds a dual-engine architecture and advanced capabilities such as multi-account management, database and application O&M, password rotation, network domain proxy, and a web-based O&M portal.

In the following tables, a checkmark (✅) indicates that a feature is supported and a cross (❌) indicates that a feature is not supported.

Which edition is right for you?

The following table helps you choose the right edition based on your requirements.

If you need...

Choose

Core O&M controls, auditing, and SSH/RDP access to Linux and Windows servers

Basic

Multi-account management, database O&M, application O&M, or automatic password rotation

Enterprise

Cross-network O&M via proxy or web portal access for non-RAM users

Enterprise

For a full feature comparison, see Functions and features.

Infrastructure

The following table compares infrastructure features between editions.

Feature

Description

Basic

Enterprise

References

Architecture

Determines the engine redundancy and availability of the bastion host.

Cloud-based single-engine

Cloud-based dual-engine

Benefits

Elastic scaling

Scale the number of assets, storage capacity, and bandwidth as your environment grows.

Billing

Internationalization

Switch the console language between Simplified Chinese, Traditional Chinese, and English. Deploy outside China, with SMS two-factor authentication supported for mobile numbers from multiple telecom carriers outside China.

SMS 2FA countries

Multi-account management

Manage O&M operations across multiple Alibaba Cloud accounts through Resource Directory from a single bastion host.

Multi-account management

User management

The following table compares user management features between editions.

Feature

Description

Basic

Enterprise

References

User roles

Assign administrators, O&M engineers, and auditors with distinct permissions.

Grant management permissions

User provisioning

Add users individually or import them in bulk from a file.

Manage users

Directory sync

Automatically sync RAM users, AD-authenticated users, and LDAP-authenticated users.

Manage users, AD/LDAP

Third-party identity sources

Import users from IDaaS, DingTalk, and Microsoft Entra ID.

Manage users, IDaaS

Account lifecycle

Change account states—expired, locked, or inactive—to reflect the current status of a user.

User Settings

Password and lockout policy

Set account lockout thresholds and password validity periods.

User Settings

Asset management

The following table compares asset management features between editions.

Feature

Description

Basic

Enterprise

References

Server O&M

Connect to Windows and Linux servers over SSH and RDP.

Client-based O&M

Database O&M

Connect to ApsaraDB RDS (MySQL, SQL Server, PostgreSQL), PolarDB clusters, and self-managed databases.

Database management, Client-based O&M

Application O&M

Connect to client applications and web applications over HTTPS and HTTP.

Application management, O&M overview

Asset import

Add assets manually or import Alibaba Cloud and third-party cloud assets in bulk.

Add hosts, Third-party assets

Credential management

Store asset passwords and SSH keys in Bastionhost for passwordless access.

Manage host account, Account settings

Asset health checks

Check the status of ECS instances, ApsaraDB RDS instances, and network connectivity.

Manage hosts

Security Center integration

Monitor asset risks—alerts, vulnerabilities, and baseline risks.

Manage hosts

Hybrid asset management

Manage assets across third-party clouds, Alibaba Cloud, and on-premises data centers.

Hybrid O&M

Network domain proxy

Access assets in isolated network environments over an internal network.

Network domain

Password management

The following table compares password management features between editions.

Feature

Description

Basic

Enterprise

References

Automatic password change

Rotate Linux and Windows server passwords on a schedule or on demand.

Automatic password change

KMS secret rotation

Rotate passwords or keys for ECS instances using KMS.

Import ECS secrets from KMS

O&M management

The following table compares O&M management features between editions.

Feature

Description

Basic

Enterprise

References

Fine-grained authorization

Grant or revoke access at the level of individual users, user groups, asset accounts, and asset group accounts.

Authorize users, Asset groups

Two-factor authentication

Authenticate users with SMS, email, TOTP, or DingTalk notifications.

Enable 2FA

Client tool access

Log on to assets from native client tools: MSTSC, Xshell, SecureCRT, and PuTTY.

Database O&M tools

SFTP file transfer

Transfer files to and from assets using WinSCP, Xftp, SecureFX, and other SFTP clients.

SFTP-based O&M

Browser-based SSO

Access assets through single sign-on (SSO) directly from a browser.

SSO-based O&M

O&M portal

Provide O&M engineers with an independent portal separate from the admin console.

Web portal O&M for non-RAM users

Allow non-RAM users to perform O&M operations directly from the bastion host web portal.

Non-RAM O&M

Real-time session monitoring

Monitor active sessions in real time and block any session immediately.

Real-time monitoring, Block sessions

RDP session controls

Control clipboard usage and disk mapping during RDP sessions.

Control policy

SSH command controls

Configure command whitelists and blacklists, and require approval for high-risk commands.

Control policy

File operation controls

Restrict file uploads, downloads, deletions, renames, and folder creation or deletion.

Control policy

O&M approval workflow

Require O&M engineers to submit an access request that an administrator must approve.

Review O&M application

Logon restrictions

Restrict access by user, source IP address, and time window.

User Settings

Session timeout

Set the maximum idle duration and maximum total duration for O&M sessions.

User Settings

Automated O&M

Create O&M tasks to distribute scripts to multiple hosts in batches, improving O&M efficiency.

Intelligent O&M

Provides smarter task triggering, orchestration, and result analysis capabilities beyond Automated O&M.

Intelligent O&M

O&M audit

The following table compares O&M audit features between editions.

Feature

Description

Basic

Enterprise

References

Session audit

Audit all O&M operations through logs and video recordings, with session playback.

Search for sessions

File transfer audit

Audit all file transfers performed during O&M sessions.

O&M reports

Generate and export O&M activity reports in PDF, HTML, or Word format.

O&M Reports

Log archiving

Transfer audit logs to Simple Log Service or download them locally using the log backup feature.

Archive audit logs, Log backup

API

The following table compares API features between editions.

Feature

Description

Basic

Enterprise

References

API operations

Call API operations to manage Bastionhost programmatically.

List of operations