All Products
Search
Document Center

Bastionhost:Authorize a user to manage asset groups and the accounts of assets in the asset groups

Last Updated:Mar 31, 2026

When your organization has multiple teams with different access requirements — for example, developers who need access to staging servers but not production, or operations engineers who manage a specific set of databases — you can grant users access to specific asset groups in Bastionhost. Access is controlled in two layers:

  1. Asset group access — grants the user permission to manage a given asset group.

  2. Account authorization — specifies which accounts the user can use to log on to assets in that group.

Both layers must be configured before a user can connect to an asset.

Prerequisites

Before you begin, ensure that you have:

Authorize a user to manage asset groups

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your bastion host resides.

  2. In the bastion host list, find your bastion host and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user and click Authorize User to Manage Asset Groups in the Actions column.

  5. On the Managed Asset Groups tab, click Authorize User to Manage Asset Groups.

  6. In the Authorize User to Manage Asset Groups panel, select the asset groups to authorize and click OK.

Authorize a user to manage accounts in asset groups

After authorizing a user to manage asset groups, grant access to specific accounts within those groups. Choose the approach based on how many asset groups you need to update.

Authorize accounts in a single asset group

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your bastion host resides.

  2. In the bastion host list, find your bastion host and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user and click Authorize User to Manage Asset Groups in the Actions column.

  5. On the Managed Asset Groups tab, click No accounts found. Click here to authorize the user to manage the accounts of the asset group.

  6. In the Select Account panel, select the accounts to authorize and click OK.

Bind accounts to multiple asset groups at once

Use this approach to assign the same account to assets across multiple asset groups simultaneously.

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your bastion host resides.

  2. In the bastion host list, find your bastion host and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user and click Authorize User to Manage Asset Groups in the Actions column.

  5. Select the asset groups to update, then choose Batch > Bind Accounts to Multiple Asset Groups below the list.

  6. In the Accounts section, enter the account name and click Update.

Remove asset groups from a user's authorized list

To follow the principle of least privilege, remove asset groups when a user no longer needs O&M access to them.

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your bastion host resides.

  2. In the bastion host list, find your bastion host and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user and click Authorize User to Manage Asset Groups in the Actions column.

  5. On the Managed Asset Groups tab, select the asset groups to remove and click Remove below the list.

  6. In the dialog box that appears, click Remove.

Remove accounts from multiple asset groups at once

To remove an account from assets across multiple asset groups simultaneously:

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your bastion host resides.

  2. In the bastion host list, find your bastion host and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user and click Authorize User to Manage Asset Groups in the Actions column.

  5. On the Managed Asset Groups tab, select the asset groups whose account you want to remove, then choose Batch > Remove Accounts of Multiple Asset Groups below the list.

  6. In the Accounts section, specify the account to remove and click Update.