All Products
Search
Document Center

Bastionhost:Host O&M

Last Updated:Mar 31, 2026

Use single sign-on (SSO) to launch a local client and connect to a remote host directly from the Bastionhost console or the O&M portal.

Prerequisites

Before you begin, make sure you have:

Two logon modes are available:
Password-free logon: The administrator grants O&M permissions on the asset directly to the engineer. See Authorize users or user groups to manage assets and asset accounts.
Password logon: The administrator selects Unauthorized Asset Accounts Are Allowed in the Special Asset Accounts section. In this mode, host accounts are not hosted on the bastion host. See Configure O&M settings.

Step 1/2: Configure an O&M device

Set up the local client parameters that Bastionhost Assistant uses when launching a session.

  1. Log on to the Bastionhost console and select the target region in the top navigation bar.

  2. In the bastion host list, find the target instance and click Manage.

  3. In the navigation pane, choose Asset O&M > Host O&M.

  4. On the Host O&M page, click Device Settings.

  5. In the Device Settings panel, configure the settings for each protocol you use.

RDP

SettingDescription
ResolutionSize of the remote desktop window. Configurable width and height. Default: 800 × 600.
Connection ModeSelect Connect to Management Sessions to skip permission verification for ApsaraDB RDS during Remote Desktop Protocol (RDP)-based O&M.
Local Devices and ResourcesLocal devices mapped to the remote server, including printers and clipboards.
Session TitleTitle shown at the top of the remote desktop window. Configurable with: asset IP address, asset port, asset name, asset logon name, and protocol. Displayed only on Windows.
Note

Not shown in full-screen mode by default. Spaces in the asset name appear as underscores (\_) in the title.

Local DriversLocal drives mapped to the remote server. Displayed only on Windows.
Client PathFull installation path of the local client. Displayed only on macOS.

SSH

SettingDescription
Local ClientDefault local client to launch. Supported: Xshell, PuTTY, SecureCRT, MobaXterm.
Device TypeTerminal emulation type. Supported: VT100, xterm, Linux.
Encoding MethodCharacter encoding for the client. Default: UTF-8.
Session TitleTitle shown in the client. Configurable with: asset IP address, asset port, asset name, asset logon name, and protocol. Displayed only on Windows.
Note

Session titles cannot be modified in MobaXterm. Spaces in the asset name appear as underscores (\_) in the title.

Client PathFull installation path of the local client. Displayed only on macOS.

SFTP

SettingDescription
Local ClientDefault local client to launch. Supported: Xftp, WinSCP, FileZilla, FlashFXP, SecureFX, MobaXterm.
Session TitleTitle shown in the client. Configurable with: asset IP address, asset port, asset name, asset logon name, and protocol. Displayed only on Windows.
Client PathFull installation path of the local client. Displayed only on macOS.

Step 2/2: Perform host O&M

Choose the access path that matches your account type, then connect to the target host.

Bastionhost console (for RAM users)

  1. Log on to the Bastionhost console and select the target region in the top navigation bar.

  2. In the bastion host list, find the target instance and click Manage.

  3. In the navigation pane, choose Asset O&M > Host O&M.

  4. Find the host you want to connect to.

  5. In the Remote Connection column, click the drop-down arrow. In the dialog box, select a host account, set Logon Method to Local Client Logon, and then click Log On.

O&M portal (for non-RAM users)

  1. Log on to the O&M portal. For instructions, see Log on to the O&M portal.

  2. In the left navigation bar, click Host.

  3. In the Remote Connection column, click the drop-down arrow. In the dialog box, select a host account, set Logon Method to Local Client Logon, and then click Log On.