All Products
Search
Document Center

Bastionhost:Feature comparison by Bastionhost edition

Last Updated:Mar 31, 2026

Bastionhost is available in two editions: Basic and Enterprise. Both editions share a common foundation of user management, asset management, O&M controls, auditing, and API access. The Enterprise edition adds a dual-engine architecture and a set of advanced capabilities — multi-account management, database and application O&M, password rotation, network domain proxy, and web-based O&M portal access — that are not available in the Basic edition.

In the following table, 绿色对 indicates that a feature is supported and 红色错 indicates that a feature is not supported.

Which edition is right for you?

If you need...Choose
Core O&M controls, auditing, and SSH/RDP access to Linux and Windows serversBasic
Multi-account management, database O&M, application O&M, or automatic password rotationEnterprise
Cross-network O&M via proxy or web portal access for non-RAM usersEnterprise

Feature comparison

FeatureDescriptionBasicEnterpriseReferences
Infrastructure
ArchitectureDetermines the engine redundancy and availability of the bastion host.Cloud-based single-engine architectureCloud-based dual-engine architectureBenefits
Elastic scalingScale the number of assets, storage capacity, and bandwidth as your environment grows.绿色对绿色对Billing
InternationalizationSwitch the console language between Simplified Chinese, Traditional Chinese, and English. Deploy outside China, with SMS two-factor authentication supported for mobile numbers from multiple telecom carriers outside China.绿色对绿色对Which countries and regions support the SMS-based two-factor authentication feature of Bastionhost?
Multi-account managementManage O&M operations across multiple Alibaba Cloud accounts through Resource Directory from a single bastion host.红色错绿色对Use the multi-account management feature
User management
User rolesAssign administrators, O&M engineers, and auditors with distinct permissions.绿色对绿色对Grant management permissions to a RAM user
User provisioningAdd users individually or import them in bulk from a file.绿色对绿色对Manage users
Directory syncAutomatically sync RAM users, AD-authenticated users, and LDAP-authenticated users.绿色对绿色对Manage users and Configure AD authentication or LDAP authentication
Third-party identity sourcesImport users from Identity as a Service (IDaaS), DingTalk, and Microsoft Entra ID — eliminating the need to manage separate user accounts for each identity source.红色错绿色对Manage users and Manage IDaaS authentication
Account lifecycleChange account states — expired, locked, or inactive — to reflect the current status of a user.绿色对绿色对Configure the parameters on the User Settings tab
Password and lockout policySet account lockout thresholds and password validity periods.绿色对绿色对Configure the parameters on the User Settings tab
Asset management
Server O&MConnect to Windows and Linux servers over SSH and Remote Desktop Protocol (RDP).绿色对绿色对Client-based O&M
Database O&MConnect to ApsaraDB RDS instances (MySQL, SQL Server, PostgreSQL), PolarDB for MySQL, PolarDB for PostgreSQL, PolarDB for PostgreSQL (Compatible with Oracle) clusters, and self-managed MySQL, SQL Server, PostgreSQL, and Oracle databases.红色错绿色对Use the database management feature and Client-based O&M
Application O&MConnect to client applications and web applications over HTTPS and HTTP.红色错绿色对Application management and O&M overview
Asset importAdd assets manually or import Alibaba Cloud and third-party cloud assets in bulk.绿色对绿色对Add hosts and Manage third-party asset sources
Credential managementStore asset passwords and SSH keys in Bastionhost so O&M engineers can access assets without knowing the credentials.绿色对绿色对Manage a host account and Configure account settings for a host
Asset health checksCheck the status of Elastic Compute Service (ECS) instances, ApsaraDB RDS instances, and network connectivity — on a schedule or on demand.绿色对绿色对Manage hosts
Security Center integrationMonitor asset risks — alerts, vulnerabilities, and baseline risks — and navigate directly to Security Center to remediate them.绿色对绿色对Manage hosts
Hybrid asset managementManage assets across third-party clouds, Alibaba Cloud, and on-premises data centers from a single bastion host.绿色对绿色对Best practices of hybrid O&M
Network domain proxyAccess assets in isolated network environments over an internal network using the network domain proxy mode.红色错绿色对Use the network domain feature
Password management
Automatic password changeRotate Linux and Windows server passwords on a schedule or on demand, eliminating stale credentials.红色错绿色对Use the automatic password change feature
KMS secret rotationRotate passwords or keys for ECS instances using Key Management Service (KMS).红色错绿色对Import ECS secrets from KMS
O&M management
Fine-grained authorizationGrant or revoke access at the level of individual users, user groups, asset accounts, and asset group accounts.绿色对绿色对Authorize users or user groups to manage assets and asset accounts and Grant permissions on asset groups
Two-factor authenticationAuthenticate users with SMS, email, Time-Based One-Time Password (TOTP), or DingTalk notifications.绿色对绿色对Enable two-factor authentication
Client tool accessLog on to assets from native client tools: Microsoft Terminal Services Client (MSTSC), Xshell, SecureCRT, and PuTTY.绿色对绿色对Database O&M tools and versions
Secure File Transfer Protocol (SFTP) file transferTransfer files to and from assets using WinSCP, Xftp, SecureFX, and other SFTP clients.绿色对绿色对Perform SFTP-based O&M
Browser-based SSOAccess assets through single sign-on (SSO) directly from a browser.绿色对绿色对SSO-based O&M
O&M portalProvide O&M engineers with an independent portal separate from the admin console.绿色对绿色对
Web portal O&M for non-RAM usersAllow non-RAM users to perform O&M operations directly from the bastion host web portal.红色错绿色对O&M portal-based O&M (non-RAM users)
Real-time session monitoringMonitor active sessions in real time and block any session immediately.绿色对绿色对Search for real-time monitoring sessions and view session details and Block sessions
RDP session controlsControl clipboard usage and disk mapping during RDP sessions.绿色对绿色对Configure a control policy
SSH command controlsConfigure command whitelists and blacklists, and require approval for high-risk commands during SSH sessions.绿色对绿色对Configure a control policy
File operation controlsRestrict file uploads, downloads, deletions, renames, and folder creation or deletion during O&M sessions.绿色对绿色对Configure a control policy
O&M approval workflowRequire O&M engineers to submit an access request that an administrator must approve before they can log on to an asset.绿色对绿色对Review an O&M application
Logon restrictionsRestrict access by user, source IP address, and time window.绿色对绿色对Configure the parameters on the User Settings tab
Session timeoutSet the maximum idle duration and maximum total duration for O&M sessions.绿色对绿色对Configure the parameters on the User Settings tab
O&M audit
Session auditAudit all O&M operations through logs and video recordings, with session playback.绿色对绿色对Search for sessions and view session details
File transfer auditAudit all file transfers performed during O&M sessions.绿色对绿色对
O&M reportsGenerate and export O&M activity reports in PDF, HTML, or Word format.绿色对绿色对View the O&M information on the O&M Reports page and export an O&M report
Log archivingTransfer audit logs to Simple Log Service or download them locally using the log backup feature.绿色对绿色对Archive audit logs in Simple Log Service and Use the log backup feature
API
API operationsCall API operations to manage Bastionhost programmatically.绿色对绿色对List of operations by function