All Products
Search
Document Center

Bastionhost:Authorize assets and asset accounts for a user

Last Updated:Aug 06, 2026

After you create a user, you must authorize assets for that user. This allows the user to use Bastionhost to perform O&M on those assets. This topic describes how to authorize assets and asset accounts for a user.

Prerequisites

Authorize assets for a user

Authorize hosts

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Users > Users.

  4. On the Users page, find the user and click Permission on Host in the Actions column.

  5. On the Managed Hosts tab, click Permission on Host.

  6. In the Permission on Host panel, select one or more hosts and click OK.

Authorize databases

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Users > Users.

  4. On the Users page, find the user and click Permission on Database in the Actions column.

  5. On the Managed Databases tab, click Permission on Database.

  6. In the Permission on Database panel, select one or more databases and click OK.

Authorize applications

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Users > Users.

  4. On the Users page, find the user and click Authorize Application in the Actions column.

  5. On the Authorized Applications tab, click Authorize Application. In the panel that appears, select one or more applications and click OK.

Authorize asset accounts for a user

Authorize a single asset account

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Users > Users.

  4. In the user list, click the name of the target user.

  5. On the tab for the target asset, click No accounts found. Click here to authorize the user to manage the accounts of the asset group..

  6. In the panel that appears, select the asset account and click Update.

    Note

    If no accounts are available, click Create Host Account to create an asset account.

Batch authorize asset accounts

To authorize multiple asset accounts for a user in a batch, perform the following steps:

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Users > Users.

  4. In the user list, click the name of the target user.

  5. On the tab for the target asset, select the assets. At the bottom of the list, choose .

  6. Enter the account name and click Update.

    Note

    You can specify only one account name per batch operation.

Remove authorized assets from a user

To follow the principle of least privilege, remove assets from a user's authorized list if they no longer need O&M access to those assets.

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Users > Users.

  4. In the user list, click the name of the target user.

  5. On the tab for the target asset, select the assets to remove and click Remove at the bottom of the list.

  6. In the confirmation dialog box that appears, click Remove.

Batch remove authorized asset accounts

To remove authorized asset accounts from a user in a batch, perform the following steps:

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Users > Users.

  4. In the user list, find the target user and click the username to go to the details page.

  5. On the Managed Hosts, Managed Databases, or Authorized Applications tab, select the assets. At the bottom of the list, choose .

  6. Enter the account name and click Update.

    Note

    You can remove only one account name per batch operation.