All Products
Search
Document Center

Bastionhost:RDP O&M

Last Updated:Jun 20, 2026

To manage a Windows server from a local Windows system, connect to Bastionhost by using a remote client. After connecting, select the host you want to manage from the Bastionhost interface. This topic uses the native Windows Remote Desktop Connection (Mstsc) client as an example to describe the RDP-based O&M procedure.

Prerequisites

  • You have imported assets and users to the Bastionhost instance and granted the users permissions on the assets. For more information, see Create a host, Manage users, and Authorize users to manage specified assets and asset accounts.

    Note
    • To enable passwordless logon to a host, you must grant the user permissions on the asset account. For more information, see Authorize assets and asset accounts for a user.

    • If you do not manage a specific account, you can enable the Empty account in Special Asset Accounts. When a user logs on using the Empty account, they must manually enter the asset account password. For more information, see O&M configuration.

  • You have obtained the O&M address of the Bastionhost instance. You can find the O&M address in the Bastion Host Information section on the Overview page. For more information, see Overview of the Bastionhost console.概览

    Note

    Bastionhost provides a fixed O&M address as a domain name and uses dynamic IP addresses to prevent attacks. The IP address that is resolved from the O&M address may change. To prevent O&M failures caused by IP address changes, you must use the domain name provided by Bastionhost for O&M.

Password authentication

  1. On your local Windows host, open Remote Desktop Connection (Mstsc).

  2. Enter the Bastionhost O&M address and click Connect.

    The O&M address is in the following format: <O&M address>:63389. For example, kagp******-public.bastionhost.aliyuncs.com:63389.

    The default RDP port is 63389. To change the O&M port of the Bastionhost instance, see Configure a bastion host.

  3. In the Remote Desktop Connection dialog box, click Yes.

  4. In the login dialog box, enter your Bastionhost username and password, and then click Login.

  5. If two-factor authentication is enabled for the Bastionhost user, enter the verification code.

    For more information about how to configure two-factor authentication for a Bastionhost user, see Enable two-factor authentication.

  6. On the asset management page, double-click the host you want to manage to log on to the target host.

    This page lists the connection information for the hosts that you can manage, such as Hostname, IP, Username, and Port.

Token authentication

  1. On your local Windows host, open Remote Desktop Connection (Mstsc).

    Click Show Options in the lower-left corner to display additional connection settings.

  2. On the General tab, enter the Bastionhost O&M address and your username, select the Allow me to save credentials checkbox, and then click Connect.

    The O&M address is in the following format: <O&M address>:63389. For example, kagp******-public.bastionhost.aliyuncs.com:63389.

    The default RDP port is 63389. To change the O&M port of the Bastionhost instance, see Configure a bastion host.

  3. In the dialog box that appears, enter the O&M token and click OK.

    To learn how to obtain an O&M token, see Manage O&M tokens.

  4. In the Remote Desktop Connection dialog box, click Yes to log on to the target host.

Related articles

For a list of compatible remote connection clients and their versions, see Supported remote connection clients and versions.