All Products
Search
Document Center

Bastionhost:Manage control policies

Last Updated:Jun 20, 2026

You can edit or delete control policies to meet changing business requirements.

Edit a control policy

To edit an existing control policy, follow these steps:

  1. Log on to the Bastionhost system. For more information, see Log on to the system.

  2. In the navigation pane on the left, click Control Policies.

  3. In the control policy list, find the policy to edit and click Actions in the Edit column.

    Alternatively, click the policy name to open the Control Policy Details page.

  4. On the Control Policy Details page, modify the settings on the Control Policy Settings, Command Policy, Command Approval, Protocol Control, Access Control, and Control Policies tabs.

    For more information about modifying the Control Policy Settings, Command Policy, Command Approval, Protocol Control, and Access Control, see Configure a control policy. For more information about associating a Control Policies, see Associate assets or users.

  5. Click Update Control Policy.

Delete a control policy

To delete a control policy, follow these steps:

  1. Log on to the Bastionhost system. For more information, see Log on to the system.

  2. In the navigation pane on the left, click Control Policies.

  3. Find the control policy that you want to delete and click Delete in the Actions column.

    To delete multiple policies at once, select them and then click Delete at the bottom of the list.

  4. In the confirmation dialog box, click Delete.

Associate assets or users

Follow these steps to associate a new control policy with users and assets, or to modify the associations for an existing policy.

  1. Log on to the Bastionhost system. For more information, see Log on to the system.

  2. In the navigation pane on the left, click Control Policies.

  3. Find the control policy you want to modify, and click the number in the Users, User Groups, Hosts, Database, or Asset Group column.

    Alternatively, click the policy name or Edit in the Actions column, and then go to the Control Policies tab.

  4. Configure the enforcement mode for associated assets and users.

    Important

    The selected enforcement mode takes effect immediately. Confirm your desired settings before proceeding.

    Select an enforcement mode based on the following information:

    • Select an enforcement mode for assets

      You can select Takes Effect on All Assets or Takes Effect on Selected All Assets. If you select Takes Effect on All Assets, specify the assets or asset groups to which the policy applies.

      Note

      If multiple control policies with the same priority apply to the same asset, Bastionhost resolves conflicts based on the following order of precedence. For command-related rules, the order is Reject, Allow, and then Approve. For access control rules, a blacklist takes priority over a whitelist.

    • Select an enforcement mode for users

      You can select Apply to All Users or Apply to Selected Users. If you select Apply to All Users, specify the users or user groups to which the policy applies.

    To remove assets or users from the policy, select them and click Remove.