All Products
Search
Document Center

Bastionhost:RDP O&M

Last Updated:Jun 20, 2026

To manage Windows servers from macOS, you can use a remote connection client to connect to Bastionhost. Then, from the Bastionhost interface, select the asset you want to manage. This topic uses Microsoft Remote Desktop as an example to describe the O&M process over RDP.

Prerequisites

  • You have imported assets and users to the Bastionhost instance and granted the users permissions on the assets. For more information, see Create a host, Manage users, and Authorize users to manage specified assets and asset accounts.

    Note
    • To enable passwordless logon to a host, you must grant the user permissions on the asset account. For more information, see Authorize assets and asset accounts for a user.

    • If you do not manage a specific account, you can enable the Empty account in Special Asset Accounts. When a user logs on using the Empty account, they must manually enter the asset account password. For more information, see O&M configuration.

  • You have obtained the O&M address of the bastion host instance. You can find the O&M address in the Bastion Host Information section on the Overview page. For more information, see Overview of the Bastionhost console.概览

    Note

    Bastionhost provides a fixed O&M address as a domain name and uses dynamic IP addresses to prevent attacks. The IP address that is resolved from the O&M address may change. To prevent O&M failures caused by IP address changes, you must use the domain name provided by Bastionhost for O&M.

  • You have installed an RDP client, such as Microsoft Remote Desktop.

Password authentication

  1. Open the Microsoft Remote Desktop tool.

  2. Enter the Bastionhost O&M address and click Add.

    The Bastionhost O&M address must be in the format <Bastionhost O&M address>:63389. For example, kagp******-public.bastionhost.aliyuncs.com:63389.

    The default RDP port is 63389. If you need to change the Bastionhost O&M port, see Configure Bastionhost.

  3. Enter the username and password for your Bastionhost account, and then click Continue.

  4. If two-factor authentication is enabled for your Bastionhost account, enter the verification code.

    For information about how to configure two-factor authentication, see Enable two-factor authentication.

  5. On the asset management page, double-click the host that you want to manage to log in and start an O&M session.

    The page displays a list of hosts with connection information in columns such as Hostname, IP, Username, and Port. You can use the search box at the top to find the target host.

Token authentication

  1. Open the Microsoft Remote Desktop tool.

  2. Enter the Bastionhost O&M address and click Add.

    The Bastionhost O&M address must be in the format <Bastionhost O&M address>:63389. For example, kagp******-public.bastionhost.aliyuncs.com:63389.

    The default RDP port is 63389. If you need to change the Bastionhost O&M port, see Configure Bastionhost.

  3. Enter your Bastionhost username and O&M token, and then click Continue.

    To learn how to obtain an O&M token, see Manage O&M tokens.

  4. On the asset management page, double-click the host that you want to manage to log in and start an O&M session.

Related documents

For a list of compatible remote connection clients and their versions, see Client remote connection tools and versions.