Track feature updates, optimizations, and documentation changes for Bastionhost, organized by software version.
2026
Version | Feature | Change type | Description | Affected editions | Documentation |
V3.2.52 (2026-06-29) | Database O&M | Improved |
| Enterprise Dual-Engine and SM-compliant editions | N/A |
Host O&M | Improved | Support SSH protocol O&M for Linux servers with two-factor authentication enabled. Note: Bastionhost Assistant is the only supported authentication method for SFTP access. | Basic, Enterprise Dual-Engine, and SM-compliant editions | N/A | |
Notifications | New | Add AD/LDAP authentication server status alerts to notifications. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
V3.2.51(2026-05-11) | IDaaS authentication integration | Improved |
| Enterprise Dual-Engine and SM-compliant editions | |
Application server | Improved |
| Enterprise Dual-Engine and SM-compliant editions | ||
Application O&M | New | Transfer files during application O&M sessions using web-based remote connections. | Enterprise Dual-Engine and SM-compliant editions | ||
Watermark | New | Enable watermarks for web remote connection windows and session audit playback. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Data archive | New | Set up automatic archiving tasks for operation logs. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Console page | Improved | Optimize the menu hierarchy in the System Settings module. | Basic, Enterprise Dual-Engine, and SM-compliant editions | N/A | |
V3.2.50(2026-01-29) | Single sign-on (SSO) O&M | New | Upload a private key to access an asset when the host account's key is not managed. Not supported for client-based O&M. | Basic, Enterprise Dual-Engine, and SM-compliant editions | |
Web-based O&M | Enterprise Dual-Engine and SM-compliant editions | ||||
Session recording archive | New | Configure automatic tasks to archive session recordings. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
O&M portal/console | New |
| Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Control policy | New | Use a control policy to restrict file uploads and downloads through disk mapping during web-based O&M on Windows servers. | Enterprise Dual-Engine and SM-compliant editions | ||
User management | New | Configure password complexity requirements for users. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Improved | Synchronize logon name changes for Resource Access Management (RAM) users. | ||||
Improved | Enable detection of high-risk passwords known to be compromised. | ||||
Client-based O&M | Improved | Use SSH local and remote port forwarding for O&M on SSH accounts with Visual Studio Code (VS Code). When using VS Code for O&M, Bastionhost cannot control or audit commands. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
SSO O&M | Improved | The SSO client for macOS supports iTerm2. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
IDaaS integration | Improved | Configure a default redirect to the IDaaS logon page when users access the O&M portal. Once enabled, local and Active Directory (AD)/LDAP users cannot log on to the O&M portal. | Enterprise Dual-Engine and SM-compliant editions | ||
Console page | Improved | Separate the management and O&M portals in the console. | Basic, Enterprise Dual-Engine, and SM-compliant editions | N/A |
2025
Version | Feature | Change type | Description | Affected editions | Documentation |
V3.2.48.1(2025-10-14) | Password change tasks | New | Change passwords for privileged Linux accounts. | Enterprise Dual-Engine and SM-compliant editions | |
New | Change the password for a single account within a task. | ||||
Improved | View failure logs for password change tasks. | ||||
Host audit data masking policies | New | Configure data masking policies for host audit logs. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Offline player | New | Play session recording files locally with an offline player. Export session recordings from Bastionhost to OSS first, then download them. See Export session recordings to OSS for details. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Bastionhost Assistant | New | Use macOS Terminal. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Improved | Install silently. | ||||
User management | New | Display and filter RAM users marked as "User source deleted". | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
New | View and export user public keys from the console. | ||||
System stability | New | Configure an IP locking policy that automatically adds an IP to the denylist when failed logon attempts from that IP reach the threshold. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
API | New | Add a Resource Directory member account to a Bastionhost instance. | Enterprise Dual-Engine and SM-compliant editions | ||
Query the list of Resource Directory member accounts in a Bastionhost instance. | |||||
Remove a Resource Directory member account from a Bastionhost instance. | |||||
V3.2.46(2025-03-28) | Database command control | New | Configure allowlist and denylist policies for commands during database O&M. | Enterprise Dual-Engine and SM-compliant editions | |
Password change tasks | New | Supports SSH key rotation. | Enterprise Dual-Engine and SM-compliant editions | ||
Third-party asset source | New | Integrate third-party asset sources with Google Cloud. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Logon remarks | New | Require O&M users to enter remarks for web-based O&M, SSO-based O&M, and O&M token requests. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Web-based RDP O&M | New | Transfer files during web-based O&M on Windows servers. | Enterprise Dual-Engine and SM-compliant editions | ||
Database audit | Improved | View and sort SQL statement execution durations on the database audit page. | Enterprise Dual-Engine and SM-compliant editions | N/A | |
V3.2.45(2025-01-15) | Network domain HTTPS proxy | New | Configure an HTTPS proxy for network domain proxy servers. | Enterprise Dual-Engine and SM-compliant editions | |
Custom asset remarks | New | O&M users can add custom remarks to assets in the O&M portal. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
RDP client-based O&M | Improved |
| Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
LDAP authentication | Improved | View failure logs during LDAP authentication server connection tests. | Basic, Enterprise Dual-Engine, and SM-compliant editions | N/A |
2024
Version | Feature | Change type | Description | Affected editions | Documentation |
V3.2.44(2024-11-19) | Web-based database O&M | New | Perform O&M on databases through the web interface. | Enterprise Dual-Engine and SM-compliant editions | |
API | New |
| Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
User status settings | Improved | Customize the check interval for automatically locking users after a specified period of inactivity. | Basic, Enterprise Dual-Engine, and SM-compliant editions | N/A | |
O&M requests | Improved | Provide a reason when submitting O&M requests. | Basic, Enterprise Dual-Engine, and SM-compliant editions | N/A | |
V3.2.43(2024-09-23) | Application O&M | New | Manage and access client application and web application assets. | Enterprise Dual-Engine and SM-compliant editions | |
Single sign-on (SSO) | New | Launch local clients from the SSO client to access assets. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Password change task | New | Manage Windows system account passwords with automatic password change tasks. | Enterprise Dual-Engine and SM-compliant editions | ||
IDaaS authentication | Improved | Configure the user synchronization scope and SSO initiator. | Enterprise Dual-Engine and SM-compliant editions | ||
Operation log | Improved | Refined details in audit log entries. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Network domain | Improved | Use key-based authentication for SSH proxy servers in network domains. | Enterprise Dual-Engine and SM-compliant editions | ||
Web-based O&M | Improved | Save theme settings for web-based O&M sessions. | Enterprise Dual-Engine and SM-compliant editions | ||
User management | Improved | Exported user tables include the expiration date, status, and last logon time. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Host O&M | Improved |
| Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
Portal O&M | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||||
Overview page | Improved | Monitor resource connection pool usage. Overload protection activates when resource consumption is too high. | Basic, Enterprise Dual-Engine, and SM-compliant editions | ||
V3.2.42(2024-06-26) | User settings | New | Require multiple users to reset their passwords on their next logon in bulk. | Basic and Enterprise Dual-Engine editions | |
V3.2.41(2024-06-05) | Automated O&M | New | Create O&M tasks to run scripts in batches across multiple host accounts. | Enterprise Dual-Engine edition | |
Centralized multi-account O&M | New | Connect to Resource Directory to automatically import Elastic Compute Service (ECS) and ApsaraDB RDS (RDS) assets from multiple accounts. | Enterprise Dual-Engine edition | ||
Private network O&M | New |
| Enterprise Dual-Engine edition | ||
KMS credential integration | New | Import ECS credentials from Key Management Service (KMS) in the same account to use as host accounts. | Enterprise Dual-Engine edition | ||
Active Directory (AD) authentication | Improved |
| Basic and Enterprise Dual-Engine editions | ||
Authorization dashboard | New | View assets authorized for a user, including those inherited from user groups and authorization rules. | Basic and Enterprise Dual-Engine editions | N/A | |
V3.2.40(2024-03-27) | User logon restrictions | New | Restrict user logons to a bastion host based on time periods and source IP addresses. | Basic and Enterprise Dual-Engine editions | |
API | New |
| Basic and Enterprise Dual-Engine editions | N/A | |
Password change task | Improved | Configure custom character counts in password complexity rules for password change tasks. | Enterprise Dual-Engine edition | ||
Notifications | Improved | Customize the language for notifications. | Basic and Enterprise Dual-Engine editions | ||
V3.2.39(2024-02-26) | IDaaS authentication | New | Log on to the O&M portal with IDaaS authentication. Not supported in Alibaba Finance Cloud and Alibaba Gov Cloud. | Enterprise Dual-Engine edition | |
Third-party asset sources | New | Add Azure as an asset source. | Basic and Enterprise Dual-Engine editions | N/A | |
Control policy | New | Audit keyboard input during RDP O&M sessions on the Text tab. | Basic and Enterprise Dual-Engine editions | ||
API | New | Added an O&M token API. | Basic and Enterprise Dual-Engine editions | N/A | |
User password security | Improved | Configure a password history policy to prevent users from reusing previous passwords. | Basic and Enterprise Dual-Engine editions | ||
User management | Improved |
| Basic and Enterprise Dual-Engine editions | N/A | |
Asset management | Improved | Manually check the status of ECS and RDS assets. | Basic and Enterprise Dual-Engine editions | ||
V3.2.38.3(2024-01-25) | Control policy | New | Associate control policies at the asset account level for granular access control. | Basic and Enterprise Dual-Engine editions | |
User management | New | Automatically lock users who have been inactive for a specified period. | |||
Asset management | New | Export and import passwords and keys for asset accounts. | |||
Client-based O&M | Improved | Filter and sort search results by different parameters in the SSH O&M client. | N/A | ||
AD/LDAP user management | Improved | Choose whether to synchronize mobile numbers for AD/LDAP users. | |||
Authorization | Improved | Select from existing accounts when granting permissions for asset group accounts. | |||
Session audit | Improved | Use fuzzy matching in session audit searches. | N/A |
2023
Version | Feature | Change type | Description | Affected editions | Documentation |
Basic Edition(2023-09-18) | Switch to a different zone | New | Switch your bastion host to a different zone to prevent service interruptions if the current zone becomes unavailable. | Basic edition | |
V3.2.37.1(2023-08-30) | O&M for PolarDB databases | New | O&M support for PolarDB databases. | Enterprise Dual-Engine edition | |
User list export | New | Export the user list, including fields such as username, email address, mobile number, user group, and creation time. | Basic and Enterprise Dual-Engine editions | ||
O&M token | Enhanced | Flexibly configure the validity period and usage limits for O&M tokens. O&M users can renew tokens independently. | Basic and Enterprise Dual-Engine editions | ||
API update | Enhanced | Added APIs for O&M review and command review. | Basic and Enterprise Dual-Engine editions | N/A | |
Asset network connectivity check | Enhanced |
| Basic and Enterprise Dual-Engine editions | ||
O&M session duration limit | Enhanced | Configure the maximum O&M session duration. The maximum duration for a single session is seven days. | Basic and Enterprise Dual-Engine editions | ||
Real-time database O&M connections | Enhanced | Optimized real-time connection and concurrency calculation for database access using O&M tokens to improve audit accuracy. | Enterprise Dual-Engine edition | N/A | |
V3.2.36(2023-07-18) | Stability enhancements | Enhanced | Optimize the overload protection process to improve component stability. | Basic and Enterprise Dual-Engine editions | N/A |
V3.2.35(2023-05-30) | Multi-zone configuration | New | Configure zones for vSwitches. | Enterprise Dual-Engine edition | |
Notifications | New | Added user-related notifications: password expiration reminders and user account expiration reminders. | Basic and Enterprise Dual-Engine editions | ||
Two-factor authentication | New | Mobile-based two-factor authentication for users in Thailand (+66), Vietnam (+84), and Cambodia (+855). | Basic and Enterprise Dual-Engine editions | ||
Asset authorization workflow | Enhanced | Automatically redirect to the asset account authorization page when authorizing an asset. | Basic and Enterprise Dual-Engine editions | N/A | |
AD/LDAP user snapshot synchronization | Enhanced | Periodically cache users from AD and LDAP servers. | Basic and Enterprise Dual-Engine editions | ||
V3.2.33(2023-02-21) | Connectivity check tool | New | Troubleshoot O&M connection issues between a client and a bastion host, and between a bastion host and an asset. | Basic and Enterprise Dual-Engine editions | N/A |
Asset risk monitoring | New | Synchronize and view asset risk statuses from Security Center, including alerts, vulnerabilities, and baseline risks. Navigate to Security Center to resolve issues. | Basic and Enterprise Dual-Engine editions | N/A |
2022
Version | Feature | Change type | Description | Affected editions | Documentation |
V3.2.31(2022-12-22) | Oracle database O&M | New | Perform O&M on Oracle databases. | Enterprise Dual-Engine edition | |
Third-party asset source management | Enhanced | Import and manage assets from Amazon Web Services and Tencent Cloud. | Basic and Enterprise Dual-Engine editions | ||
O&M portal | Enhanced | Modify keys and personal information through the O&M portal for local, AD, and LDAP users. | Basic and Enterprise Dual-Engine editions | ||
Asset connectivity check | New | Run automatic asset connectivity checks. Connectivity status updates every 4 hours. | Basic and Enterprise Dual-Engine editions | ||
AD and LDAP configuration | Enhanced | Clear AD and LDAP authentication settings. | Basic and Enterprise Dual-Engine editions | ||
API | Enhanced |
| Basic and Enterprise Dual-Engine editions | N/A | |
Host key | New | Host keys support the ed25519 format. | Basic and Enterprise Dual-Engine editions | N/A | |
V3.2.30(2022-11-21) | O&M approval | New | Require a second administrator approval when an O&M user logs on to an asset. | Basic and Enterprise Dual-Engine editions | |
Host O&M token | New | Request an O&M token from the host O&M interface for client-based O&M tasks. | Basic and Enterprise Dual-Engine editions | N/A | |
Message notifications | New | Receive command alerts, storage alerts, and O&M address change notifications by text message and email, in addition to internal messages. | Basic and Enterprise Dual-Engine editions | ||
Asset monitoring | New | Monitor O&M asset activity. Filter assets not accessed in the last 7 or 30 days. | Basic and Enterprise Dual-Engine editions | N/A | |
User logon configuration | New | Require key-based authentication for all Bastionhost logons. | Basic and Enterprise Dual-Engine editions | ||
Two-factor authentication | New | Two-factor authentication using text messages for Saudi Arabia (+966). | Basic and Enterprise Dual-Engine editions | ||
Two-factor authentication configuration | Enhanced | Modify two-factor authentication settings for multiple users in bulk from the user list. | Basic and Enterprise Dual-Engine editions | ||
Control policy | Enhanced | Improve the control policy creation logic. | Basic and Enterprise Dual-Engine editions | ||
User status monitoring | Enhanced | Flag deleted RAM users. | Basic and Enterprise Dual-Engine editions | ||
Stability enhancements | Enhanced | Add an overload protection mechanism to improve O&M session stability. | Basic and Enterprise Dual-Engine editions | N/A | |
V3.2.28(2022-07-27) | Database O&M audit | New | Control and audit O&M on RDS instances running MySQL, SQL Server, or PostgreSQL, and on self-managed databases. | Enterprise Dual-Engine edition | |
O&M portal | New | Perform O&M on authorized assets through the web-based O&M portal. Local users can log on with OTP token authentication. | Basic and Enterprise Dual-Engine editions | ||
Two-factor authentication for OTP tokens | New | Local users can scan a QR code in the O&M portal to authenticate with an OTP token. | Basic and Enterprise Dual-Engine editions | ||
Custom host port | New | Specify custom ports when importing hosts in bulk from an Excel file. | Basic and Enterprise Dual-Engine editions | ||
V3.2.26(2022-04-06) | Third-party asset source management | New | Import assets from third-party sources. | Basic and Enterprise Dual-Engine editions | |
Two-factor verification code | New | Send two-factor verification codes through DingTalk work notifications in Chinese or English. | Basic and Enterprise Dual-Engine editions | ||
User configuration for two-factor authentication | New | Configure two-factor authentication for individual users. | Basic and Enterprise Dual-Engine editions | ||
API operations | New |
| Basic and Enterprise Dual-Engine editions | ||
Search criteria for password change tasks | Enhanced | Search password change tasks by host IP address and hostname. | Enterprise Dual-Engine edition | N/A | |
Text message authentication | New | Text message authentication for users in Poland (+48) and Spain (+34). | Basic and Enterprise Dual-Engine editions | Which countries and regions are supported for Bastionhost two-factor authentication by text message? | |
AD and LDAP user synchronization | Enhanced | Synchronize AD and LDAP user configuration and status on a schedule. | Basic and Enterprise Dual-Engine editions |
2021
Version | Feature | Change type | Description | Affected editions | Documentation |
V3.2.22(2021-11-22) | Authorization rule | New | Authorize multiple users to manage assets in bulk with configurable validity periods. | Basic and Enterprise Dual-Engine editions | |
Configuration export and import | New | Export configurations from one Bastionhost instance and import them to others. | Basic and Enterprise Dual-Engine editions | ||
Network domain HA mode | New | Configure a standby proxy server for a network domain. The system automatically fails over to the standby if the primary server fails. | Enterprise Dual-Engine edition | ||
Network domain proxy | New | Internal message notifications for network domain proxy exceptions. | Enterprise Dual-Engine edition | ||
Personalized desktop | New | Access existing Windows personalized desktops during O&M sessions. | Basic and Enterprise Dual-Engine editions | ||
Force password reset on next logon | New | Require local users to reset their password on next logon. | Basic and Enterprise Dual-Engine editions | ||
V3.2.20(2021-07-22) | Access assets through a proxy | New | Access assets through SSH, SOCKS5, or HTTP proxies. | Enterprise Dual-Engine edition | |
Global configuration for host fingerprints | New | Configure whether to verify host fingerprints globally. | Basic and Enterprise Dual-Engine editions | ||
Account logon permission control | Enhanced | Toggle empty account permissions. | Basic and Enterprise Dual-Engine editions | ||
O&M log backup and export | New | Back up and export O&M session logs. | Basic and Enterprise Dual-Engine editions | ||
Internal message notifications | New |
| Basic and Enterprise Dual-Engine editions | ||
Text message authentication | New | Text message authentication for users in France (+33), Israel (+972), and Italy (+39). | Basic and Enterprise Dual-Engine editions | Which countries and regions support two-factor authentication by text message for Bastionhost? | |
V3.2.18(2021-04-21) | Export host lists | New | Export lists of managed hosts. | Basic and Enterprise Dual-Engine editions | |
Key management | New | Bind keys to multiple host accounts at once. | Basic and Enterprise Dual-Engine editions | ||
User tagging | Enhanced | Tag users inactive for a configurable period. | Basic and Enterprise Dual-Engine editions | N/A | |
AD/LDAP user import | Enhanced | Filter AD or LDAP users by username during import. | Basic and Enterprise Dual-Engine editions | ||
Control policy | New | Restrict user logon times with control policies. | Basic and Enterprise Dual-Engine editions | ||
Two-factor authentication | New | Use email-based two-factor authentication. Configure the number of days to skip re-verification after a successful login. | Basic and Enterprise Dual-Engine editions | ||
Password validity period | New | Configure the password validity period for local users. | Basic and Enterprise Dual-Engine editions | ||
V3.2.17(2021-03-15) | Password change task | New | Change passwords for multiple Linux host accounts at once. | Enterprise Dual-Engine edition | |
Batch-clear host fingerprints | New | Clear multiple host fingerprints at once. | Basic and Enterprise Dual-Engine editions | ||
Search for hosts, host groups, users, and user groups | Enhanced |
| Basic and Enterprise Dual-Engine editions | N/A | |
Text message authentication | New | Text message authentication for users in South Korea (+82), the Philippines (+63), Taiwan, China (+886), Switzerland (+41), and Sweden (+46). | Basic and Enterprise Dual-Engine editions | Which countries and regions support two-factor authentication by text message for Bastionhost? | |
Restrict user logon | Enhanced | Prevent users from logging on after their active sessions are blocked. | Basic and Enterprise Dual-Engine editions | ||
Add users with validity period | New | Set validity periods for local, AD, or LDAP users during creation. | Basic and Enterprise Dual-Engine editions | ||
O&M reports | New | Export O&M reports in Word, PDF, or HTML format. | Basic and Enterprise Dual-Engine editions | ||
Extended storage for audit recordings | Enhanced | Purchase additional storage packages for audit recordings. | Basic and Enterprise Dual-Engine editions | ||
Host O&M via web terminal | New | Perform O&M on hosts from the Bastionhost console using the web terminal. | Enterprise Dual-Engine edition | ||
O&M session duration limits | Enhanced | Set idle and total duration limits for O&M sessions. | Basic and Enterprise Dual-Engine editions | ||
API | New |
| Basic and Enterprise Dual-Engine editions |
2020
Version | Feature | Change type | Description | Affected editions | Documentation |
V3.2.13(2020-11-16) | Enterprise Edition | New | Bastionhost Enterprise Edition is available. | Basic and Enterprise Dual-Engine editions | |
Wizard | New | A setup wizard guides first-time users through Bastionhost setup. Access it from the upper-right corner of the console. | Basic and Enterprise Dual-Engine editions | N/A | |
Tagging for released ECS instances | Enhanced | Add tags to released ECS instances. | Basic and Enterprise Dual-Engine editions | N/A | |
User settings | New | Assign users to user groups during creation. | Basic and Enterprise Dual-Engine editions | ||
SMS authentication | New | SMS authentication for users in Germany (+49), Australia (+61), the United States (+1), Dubai (+971), Japan (+81), the United Kingdom (+44), India (+91), and Macao, China (+853). | Basic and Enterprise Dual-Engine editions | Which countries and regions are supported for SMS two-factor authentication? | |
Network diagnostics | New | Diagnose network connectivity issues. | Basic and Enterprise Dual-Engine editions |