Bastionhost is available in two editions: Basic and Enterprise. Both editions include user management, asset management, O&M controls, auditing, and API access. The Enterprise edition adds a dual-engine architecture and advanced capabilities such as multi-account management, database and application O&M, password rotation, network domain proxy, and a web-based O&M portal.
In the following tables, a checkmark (✅) indicates that a feature is supported and a cross (❌) indicates that a feature is not supported.
Which edition is right for you?
The following table helps you choose the right edition based on your requirements.
If you need... | Choose |
Core O&M controls, auditing, and SSH/RDP access to Linux and Windows servers | Basic |
Multi-account management, database O&M, application O&M, or automatic password rotation | Enterprise |
Cross-network O&M via proxy or web portal access for non-RAM users | Enterprise |
For a full feature comparison, see Functions and features.
Infrastructure
The following table compares infrastructure features between editions.
Feature | Description | Basic | Enterprise | References |
Architecture | Determines the engine redundancy and availability of the bastion host. | Cloud-based single-engine | Cloud-based dual-engine | |
Elastic scaling | Scale the number of assets, storage capacity, and bandwidth as your environment grows. | ✅ | ✅ | |
Internationalization | Switch the console language between Simplified Chinese, Traditional Chinese, and English. Deploy outside China, with SMS two-factor authentication supported for mobile numbers from multiple telecom carriers outside China. | ✅ | ✅ | |
Multi-account management | Manage O&M operations across multiple Alibaba Cloud accounts through Resource Directory from a single bastion host. | ❌ | ✅ |
User management
The following table compares user management features between editions.
Feature | Description | Basic | Enterprise | References |
User roles | Assign administrators, O&M engineers, and auditors with distinct permissions. | ✅ | ✅ | |
User provisioning | Add users individually or import them in bulk from a file. | ✅ | ✅ | |
Directory sync | Automatically sync RAM users, AD-authenticated users, and LDAP-authenticated users. | ✅ | ✅ | |
Third-party identity sources | Import users from IDaaS, DingTalk, and Microsoft Entra ID. | ✅ | ✅ | |
Account lifecycle | Change account states—expired, locked, or inactive—to reflect the current status of a user. | ✅ | ✅ | |
Password and lockout policy | Set account lockout thresholds and password validity periods. | ✅ | ✅ |
Asset management
The following table compares asset management features between editions.
Feature | Description | Basic | Enterprise | References |
Server O&M | Connect to Windows and Linux servers over SSH and RDP. | ✅ | ✅ | |
Database O&M | Connect to ApsaraDB RDS (MySQL, SQL Server, PostgreSQL), PolarDB clusters, and self-managed databases. | ❌ | ✅ | |
Application O&M | Connect to client applications and web applications over HTTPS and HTTP. | ❌ | ✅ | |
Asset import | Add assets manually or import Alibaba Cloud and third-party cloud assets in bulk. | ✅ | ✅ | |
Credential management | Store asset passwords and SSH keys in Bastionhost for passwordless access. | ✅ | ✅ | |
Asset health checks | Check the status of ECS instances, ApsaraDB RDS instances, and network connectivity. | ✅ | ✅ | |
Security Center integration | Monitor asset risks—alerts, vulnerabilities, and baseline risks. | ✅ | ✅ | |
Hybrid asset management | Manage assets across third-party clouds, Alibaba Cloud, and on-premises data centers. | ✅ | ✅ | |
Network domain proxy | Access assets in isolated network environments over an internal network. | ❌ | ✅ |
Password management
The following table compares password management features between editions.
Feature | Description | Basic | Enterprise | References |
Automatic password change | Rotate Linux and Windows server passwords on a schedule or on demand. | ❌ | ✅ | |
KMS secret rotation | Rotate passwords or keys for ECS instances using KMS. | ❌ | ✅ |
O&M management
The following table compares O&M management features between editions.
Feature | Description | Basic | Enterprise | References |
Fine-grained authorization | Grant or revoke access at the level of individual users, user groups, asset accounts, and asset group accounts. | ✅ | ✅ | |
Two-factor authentication | Authenticate users with SMS, email, TOTP, or DingTalk notifications. | ✅ | ✅ | |
Client tool access | Log on to assets from native client tools: MSTSC, Xshell, SecureCRT, and PuTTY. | ✅ | ✅ | |
SFTP file transfer | Transfer files to and from assets using WinSCP, Xftp, SecureFX, and other SFTP clients. | ✅ | ✅ | |
Browser-based SSO | Access assets through single sign-on (SSO) directly from a browser. | ✅ | ✅ | |
O&M portal | Provide O&M engineers with an independent portal separate from the admin console. | ✅ | ✅ | — |
Web portal O&M for non-RAM users | Allow non-RAM users to perform O&M operations directly from the bastion host web portal. | ❌ | ✅ | |
Real-time session monitoring | Monitor active sessions in real time and block any session immediately. | ✅ | ✅ | |
RDP session controls | Control clipboard usage and disk mapping during RDP sessions. | ✅ | ✅ | |
SSH command controls | Configure command whitelists and blacklists, and require approval for high-risk commands. | ✅ | ✅ | |
File operation controls | Restrict file uploads, downloads, deletions, renames, and folder creation or deletion. | ✅ | ✅ | |
O&M approval workflow | Require O&M engineers to submit an access request that an administrator must approve. | ✅ | ✅ | |
Logon restrictions | Restrict access by user, source IP address, and time window. | ✅ | ✅ | |
Session timeout | Set the maximum idle duration and maximum total duration for O&M sessions. | ✅ | ✅ | |
Automated O&M | Create O&M tasks to distribute scripts to multiple hosts in batches, improving O&M efficiency. | ✅ | ✅ | — |
Intelligent O&M | Provides smarter task triggering, orchestration, and result analysis capabilities beyond Automated O&M. | ❌ | ✅ |
O&M audit
The following table compares O&M audit features between editions.
Feature | Description | Basic | Enterprise | References |
Session audit | Audit all O&M operations through logs and video recordings, with session playback. | ✅ | ✅ | |
File transfer audit | Audit all file transfers performed during O&M sessions. | ✅ | ✅ | — |
O&M reports | Generate and export O&M activity reports in PDF, HTML, or Word format. | ✅ | ✅ | |
Log archiving | Transfer audit logs to Simple Log Service or download them locally using the log backup feature. | ✅ | ✅ |
API
The following table compares API features between editions.
Feature | Description | Basic | Enterprise | References |
API operations | Call API operations to manage Bastionhost programmatically. | ✅ | ✅ |