All Products
Search
Document Center

Bastionhost:Feature comparison by Bastionhost edition

Last Updated:Apr 02, 2026

Bastionhost is available in two editions: Basic and Enterprise. Both editions share a common foundation of user management, asset management, O&M controls, auditing, and API access. The Enterprise edition adds a dual-engine architecture and a set of advanced capabilities — multi-account management, database and application O&M, password rotation, network domain proxy, and web-based O&M portal access — that are not available in the Basic edition.

In the following table, 绿色对 indicates that a feature is supported and 红色错 indicates that a feature is not supported.

Which edition is right for you?

If you need... Choose
Core O&M controls, auditing, and SSH/RDP access to Linux and Windows servers Basic
Multi-account management, database O&M, application O&M, or automatic password rotation Enterprise
Cross-network O&M via proxy or web portal access for non-RAM users Enterprise

Feature comparison

Feature Description Basic Enterprise References
Infrastructure
Architecture Determines the engine redundancy and availability of the bastion host. Cloud-based single-engine architecture Cloud-based dual-engine architecture Benefits
Elastic scaling Scale the number of assets, storage capacity, and bandwidth as your environment grows. 绿色对 绿色对 Billing
Internationalization Switch the console language between Simplified Chinese, Traditional Chinese, and English. Deploy outside China, with SMS two-factor authentication supported for mobile numbers from multiple telecom carriers outside China. 绿色对 绿色对 Which countries and regions support the SMS-based two-factor authentication feature of Bastionhost?
Multi-account management Manage O&M operations across multiple Alibaba Cloud accounts through Resource Directory from a single bastion host. 红色错 绿色对 Use the multi-account management feature
User management
User roles Assign administrators, O&M engineers, and auditors with distinct permissions. 绿色对 绿色对 Grant management permissions to a RAM user
User provisioning Add users individually or import them in bulk from a file. 绿色对 绿色对 Manage users
Directory sync Automatically sync RAM users, AD-authenticated users, and LDAP-authenticated users. 绿色对 绿色对 Manage users and Configure AD authentication or LDAP authentication
Third-party identity sources Import users from Identity as a Service (IDaaS), DingTalk, and Microsoft Entra ID — eliminating the need to manage separate user accounts for each identity source. 红色错 绿色对 Manage users and Manage IDaaS authentication
Account lifecycle Change account states — expired, locked, or inactive — to reflect the current status of a user. 绿色对 绿色对 Configure the parameters on the User Settings tab
Password and lockout policy Set account lockout thresholds and password validity periods. 绿色对 绿色对 Configure the parameters on the User Settings tab
Asset management
Server O&M Connect to Windows and Linux servers over SSH and Remote Desktop Protocol (RDP). 绿色对 绿色对 Client-based O&M
Database O&M Connect to ApsaraDB RDS instances (MySQL, SQL Server, PostgreSQL), PolarDB for MySQL, PolarDB for PostgreSQL, PolarDB for PostgreSQL (Compatible with Oracle) clusters, and self-managed MySQL, SQL Server, PostgreSQL, and Oracle databases. 红色错 绿色对 Use the database management feature and Client-based O&M
Application O&M Connect to client applications and web applications over HTTPS and HTTP. 红色错 绿色对 Application management and O&M overview
Asset import Add assets manually or import Alibaba Cloud and third-party cloud assets in bulk. 绿色对 绿色对 Add hosts and Manage third-party asset sources
Credential management Store asset passwords and SSH keys in Bastionhost so O&M engineers can access assets without knowing the credentials. 绿色对 绿色对 Manage a host account and Configure account settings for a host
Asset health checks Check the status of Elastic Compute Service (ECS) instances, ApsaraDB RDS instances, and network connectivity — on a schedule or on demand. 绿色对 绿色对 Manage hosts
Security Center integration Monitor asset risks — alerts, vulnerabilities, and baseline risks — and navigate directly to Security Center to remediate them. 绿色对 绿色对 Manage hosts
Hybrid asset management Manage assets across third-party clouds, Alibaba Cloud, and on-premises data centers from a single bastion host. 绿色对 绿色对 Best practices of hybrid O&M
Network domain proxy Access assets in isolated network environments over an internal network using the network domain proxy mode. 红色错 绿色对 Use the network domain feature
Password management
Automatic password change Rotate Linux and Windows server passwords on a schedule or on demand, eliminating stale credentials. 红色错 绿色对 Use the automatic password change feature
KMS secret rotation Rotate passwords or keys for ECS instances using Key Management Service (KMS). 红色错 绿色对 Import ECS secrets from KMS
O&M management
Fine-grained authorization Grant or revoke access at the level of individual users, user groups, asset accounts, and asset group accounts. 绿色对 绿色对 Authorize users or user groups to manage assets and asset accounts and Grant permissions on asset groups
Two-factor authentication Authenticate users with SMS, email, Time-Based One-Time Password (TOTP), or DingTalk notifications. 绿色对 绿色对 Enable two-factor authentication
Client tool access Log on to assets from native client tools: Microsoft Terminal Services Client (MSTSC), Xshell, SecureCRT, and PuTTY. 绿色对 绿色对 Database O&M tools and versions
Secure File Transfer Protocol (SFTP) file transfer Transfer files to and from assets using WinSCP, Xftp, SecureFX, and other SFTP clients. 绿色对 绿色对 Perform SFTP-based O&M
Browser-based SSO Access assets through single sign-on (SSO) directly from a browser. 绿色对 绿色对 SSO-based O&M
O&M portal Provide O&M engineers with an independent portal separate from the admin console. 绿色对 绿色对
Web portal O&M for non-RAM users Allow non-RAM users to perform O&M operations directly from the bastion host web portal. 红色错 绿色对 O&M portal-based O&M (non-RAM users)
Real-time session monitoring Monitor active sessions in real time and block any session immediately. 绿色对 绿色对 Search for real-time monitoring sessions and view session details and Block sessions
RDP session controls Control clipboard usage and disk mapping during RDP sessions. 绿色对 绿色对 Configure a control policy
SSH command controls Configure command whitelists and blacklists, and require approval for high-risk commands during SSH sessions. 绿色对 绿色对 Configure a control policy
File operation controls Restrict file uploads, downloads, deletions, renames, and folder creation or deletion during O&M sessions. 绿色对 绿色对 Configure a control policy
O&M approval workflow Require O&M engineers to submit an access request that an administrator must approve before they can log on to an asset. 绿色对 绿色对 Review an O&M application
Logon restrictions Restrict access by user, source IP address, and time window. 绿色对 绿色对 Configure the parameters on the User Settings tab
Session timeout Set the maximum idle duration and maximum total duration for O&M sessions. 绿色对 绿色对 Configure the parameters on the User Settings tab
O&M audit
Session audit Audit all O&M operations through logs and video recordings, with session playback. 绿色对 绿色对 Search for sessions and view session details
File transfer audit Audit all file transfers performed during O&M sessions. 绿色对 绿色对
O&M reports Generate and export O&M activity reports in PDF, HTML, or Word format. 绿色对 绿色对 View the O&M information on the O&M Reports page and export an O&M report
Log archiving Transfer audit logs to Simple Log Service or download them locally using the log backup feature. 绿色对 绿色对 Archive audit logs in Simple Log Service and Use the log backup feature
API
API operations Call API operations to manage Bastionhost programmatically. 绿色对 绿色对 List of operations by function