All Products
Search
Document Center

Bastionhost:Release Notes

Last Updated:Mar 31, 2026

This page lists feature and documentation updates for Bastionhost, organized by release version.

2026

Software versionFeatureChange typeDescriptionAffected editionsRelease dateDocumentation
V3.2.50Single sign-on (SSO) O&MNewUpload a private key to access an asset when the host account's key is not managed. >
Note

Not supported for client-based O&M.

Basic, Enterprise Dual-Engine, and SM-compliant editions2026-01-29SSO-based O&M
Web-based O&MEnterprise Dual-Engine and SM-compliant editions
Session recording archiveNewConfigure automatic tasks to archive session recordings.Basic, Enterprise Dual-Engine, and SM-compliant editionsExport session recordings to OSS
O&M portal/consoleNewO&M users can bookmark assets by creating custom favorites. The O&M portal now displays the 10 most recently accessed assets.Basic, Enterprise Dual-Engine, and SM-compliant editionsLog on to the O&M portal
Control policyNewUse a control policy to restrict file uploads and downloads through disk mapping during web-based O&M on Windows servers.Enterprise Dual-Engine and SM-compliant editionsConfigure a control policy
User managementNewConfigure password complexity requirements for users.Basic, Enterprise Dual-Engine, and SM-compliant editionsManage users
ImprovedSynchronize logon name changes for RAM users.
ImprovedEnable detection of high-risk passwords known to be compromised.
Client-based O&MImprovedEnable SSH local and remote port forwarding to use tools like Visual Studio Code (VS Code) for O&M on SSH accounts. >
Important

When using VS Code for O&M, Bastionhost cannot control or audit commands.

Basic, Enterprise Dual-Engine, and SM-compliant editionsConfigure a control policy
SSO O&MImprovedThe SSO client for macOS now supports iTerm2.Basic, Enterprise Dual-Engine, and SM-compliant editionsSSO-based O&M
IDaaS integrationImprovedConfigure a default redirect to the IDaaS logon page when users access the O&M portal. >
Important

Once enabled, local and Active Directory (AD)/LDAP users cannot log on to the O&M portal.

Enterprise Dual-Engine and SM-compliant editionsManage IDaaS authentication
Console pageImprovedThe management and O&M portals in the console are now separate pages.Basic, Enterprise Dual-Engine, and SM-compliant editionsN/A

2025

VersionFeatureChange typeDescriptionAffected editionsRelease dateDocumentation
V3.2.48.1Password change tasksNewChange passwords for privileged Linux accounts.Enterprise Edition, SM Edition2025-10-14Password change tasks
NewChange the password for a single account within a task.Enterprise Edition, SM Edition
ImprovedView failure logs for password change tasks.Enterprise Edition, SM Edition
Host audit data masking policiesNewConfigure data masking policies for host audit logs.Basic Edition, Enterprise Edition, SM EditionData masking policies
Offline playerNewDownload an offline player to play session recording files locally. >
Note

Export session recordings from Bastionhost to OSS first, then download them. See Export session recordings to OSS for details.

Basic Edition, Enterprise Edition, SM EditionExport session recordings to OSS
Bastionhost AssistantNewSupports macOS Terminal.Basic Edition, Enterprise Edition, SM EditionSSO-based O&M
ImprovedSupports silent installation.
User managementNewDisplay and filter RAM users with the "User source deleted" status.Basic Edition, Enterprise Edition, SM EditionManage users
NewView and export user public keys from the console.Basic Edition, Enterprise Edition, SM Edition
System stabilityNewConfigure an IP locking policy. When the number of failed logon attempts from the same source IP address reaches the threshold, the system automatically adds the IP to the denylist.Basic Edition, Enterprise Edition, SM EditionUser settings
APINewAdd a Resource Directory member account to a Bastionhost instance.Enterprise Edition, SM EditionAdd a Resource Directory member account to a Bastionhost instance (Available only in V3.2.48 and later)
NewQuery the list of Resource Directory member accounts in a Bastionhost instance.Enterprise Edition, SM EditionQuery the list of Resource Directory member accounts imported into a specified Bastionhost instance (Available only in V3.2.48 and later)
NewRemove a Resource Directory member account from a Bastionhost instance.Enterprise Edition, SM EditionRemove a Resource Directory member account from a Bastionhost instance (Available only in V3.2.48 and later)
V3.2.46Database command controlNewConfigure allowlist and denylist policies for commands run during database O&M.Enterprise Edition, SM Edition2025-03-28Configure a control policy
Password change tasksNewSupports SSH key rotation.Enterprise Edition, SM EditionPassword change tasks
Third-party asset sourceNewIntegrate third-party asset sources with Google Cloud.Basic Edition, Enterprise Edition, SM EditionManage third-party asset sources
Logon remarksNewWhen enabled, O&M users must enter remarks for web-based O&M, SSO-based O&M, and O&M token requests.Basic Edition, Enterprise Edition, SM EditionConfigure a control policy
Web-based RDP O&MNewTransfer files during web-based O&M sessions on Windows servers.Enterprise Edition, SM EditionWeb-based O&M
Database auditImprovedThe database audit page now displays the execution duration of SQL statements and supports sorting by duration.Enterprise Edition, SM EditionN/A
V3.2.45Network domain HTTPS proxyNewConfigure an HTTPS proxy for a network domain proxy server.Enterprise Edition, SM Edition2025-01-15Network domain
Custom asset remarksNewO&M users can add custom remarks to assets in the O&M portal.Basic Edition, Enterprise Edition, SM EditionLog on to the O&M portal
RDP client-based O&MImprovedThe RDP client interface now has an optimized font size and supports resolution configuration. Supports the Windows 11 24H2 operating system. >
Note

Enable bitmap caching in system settings. See Configure O&M settings.

Basic Edition, Enterprise Edition, SM EditionRDP O&M issues
LDAP authenticationImprovedThe connection test for the LDAP authentication server now displays failure logs.Basic Edition, Enterprise Edition, SM EditionN/A

2024

VersionFeatureChange typeDescriptionAffected editionsRelease dateDocumentation
V3.2.44Web-based database O&MNewPerform O&M on databases through the web interface.Enterprise Dual-Engine Edition, SM Edition2024-11-19Web-based O&M
APINewAdded APIs for: creating O&M requests, creating SSO O&M links, exporting configuration backups, and querying storage usage.Basic Edition, Enterprise Dual-Engine Edition, SM EditionAPI catalog
User status settingsImprovedCustomize the check interval for automatically locking users after a specified period of inactivity.Basic Edition, Enterprise Dual-Engine Edition, SM EditionN/A
O&M requestsImprovedOperators can now provide a reason when submitting O&M requests.Basic Edition, Enterprise Dual-Engine Edition, SM EditionN/A
V3.2.43Application O&MNewManage and perform O&M on client application and web application assets.Enterprise Dual-Engine Edition, SM Edition2024-09-23Application Management and Web-based O&M
Single sign-on (SSO)NewUse the SSO client to launch local clients to access assets.Basic Edition, Enterprise Dual-Engine Edition, SM EditionSSO-based O&M
Password change taskNewAutomatic password change tasks can now manage Windows system account passwords.Enterprise Dual-Engine Edition, SM EditionPassword change tasks
IDaaS authenticationImprovedConfigure the user synchronization scope and SSO initiator.Enterprise Dual-Engine Edition, SM EditionManage IDaaS authentication
Operation logImprovedRefined details in audit log entries.Basic Edition, Enterprise Dual-Engine Edition, SM EditionArchive logs to Log Service
Network domainImprovedAdded key-based authentication for SSH proxy servers in network domains.Enterprise Dual-Engine Edition, SM EditionNetwork domain
Web-based O&MImprovedSave theme settings for web-based O&M sessions.Enterprise Dual-Engine Edition, SM EditionWeb-based O&M
User managementImprovedExported user tables now include the expiration date, status, and last logon time.Basic Edition, Enterprise Dual-Engine Edition, SM EditionExport users
Host O&MImprovedAdministrators can add comments when reviewing O&M requests. Improved the user experience of the O&M pop-up window.Basic Edition, Enterprise Dual-Engine Edition, SM EditionReview an O&M request
Portal O&MBasic Edition, Enterprise Dual-Engine Edition, SM EditionO&M overview
Overview pageImprovedView the resource connection pool usage. Overload protection triggers when connections consume too many resources.Basic Edition, Enterprise Dual-Engine Edition, SM EditionLog in to the system
V3.2.42User settingsNewRequire multiple users to reset their passwords on their next logon in bulk.Basic Edition, Enterprise Dual-Engine Edition2024-06-26Manage users
V3.2.41Automated O&MNewCreate O&M tasks to run scripts in batches across multiple host accounts.Enterprise Dual-Engine Edition2024-06-05Automated O&M
Centralized multi-account O&MNewConnect to Resource Directory to automatically import ECS and RDS assets from multiple accounts.Enterprise Dual-Engine EditionMulti-account management
Private network O&MNewAccess the O&M portal and perform web-based O&M over a private network.Enterprise Dual-Engine EditionEnable the private O&M portal
KMS credential integrationNewImport ECS credentials from Key Management Service (KMS) in the same account to use as host accounts.Enterprise Dual-Engine EditionImport KMS credentials
Active Directory (AD) authenticationImprovedConfigure multiple AD authentication servers. Synchronize organizational units (OUs) from an AD server as bastion host user groups.Basic Edition, Enterprise Dual-Engine EditionConfigure AD or LDAP authentication
Authorization dashboardNewView assets authorized for a user, including those inherited from user groups and authorization rules.Basic Edition, Enterprise Dual-Engine EditionN/A
V3.2.40User logon restrictionsNewRestrict user logons to a bastion host based on time periods and source IP addresses.Basic Edition, Enterprise Dual-Engine Edition2024-03-27User settings
APINewAdded APIs for network domains, control policies, authorization rules, and database management. Configure the language parameter for user management notifications.Basic Edition, Enterprise Dual-Engine EditionN/A
Password change taskImprovedPassword complexity rules for password change tasks now support custom character counts.Enterprise Dual-Engine EditionPassword change tasks
NotificationsImprovedCustomize the language for notifications.Basic Edition, Enterprise Dual-Engine EditionNotifications
V3.2.39IDaaS authenticationNewUsers authenticated through IDaaS can now log on to the O&M portal. >
Note

Not supported in Alibaba Finance Cloud and Alibaba Gov Cloud.

Enterprise Dual-Engine Edition2024-02-26Manage IDaaS authentication
Third-party asset sourcesNewAdd Azure as an asset source.Basic Edition, Enterprise Dual-Engine EditionN/A
Control policyNewAdded a keyboard audit setting. When enabled, audit keyboard input during RDP O&M sessions on the Text tab.Basic Edition, Enterprise Dual-Engine EditionSearch for and view sessions
APINewAdded an O&M token API.Basic Edition, Enterprise Dual-Engine EditionN/A
User password securityImprovedConfigure a password history policy to prevent users from reusing previous passwords.Basic Edition, Enterprise Dual-Engine EditionUser settings
User managementImprovedSynchronize mobile numbers and email addresses of RAM users. Modify user expiration dates in bulk. Configure an import policy to resolve conflicts with duplicate usernames when importing from a file.Basic Edition, Enterprise Dual-Engine EditionN/A
Asset managementImprovedManually check the status of ECS and RDS assets.Basic Edition, Enterprise Dual-Engine EditionManage hosts
V3.2.38.3Control policyNewAssociate control policies at the asset account level for more granular control.Basic Edition, Enterprise Dual-Engine Edition2024-01-25Configure a control policy
User managementNewAutomatically lock users who have been inactive for a specified period.Basic Edition, Enterprise Dual-Engine EditionManage users and User settings
Asset managementNewExport and import passwords and keys for asset accounts.Basic Edition, Enterprise Dual-Engine EditionExport the host list and Database management
Client-based O&MImprovedImproved the search function in the SSH O&M client. Filter search results and sort them by different parameters.Basic Edition, Enterprise Dual-Engine EditionN/A
AD/LDAP user managementImprovedChoose whether to synchronize mobile numbers for AD/LDAP users.Basic Edition, Enterprise Dual-Engine EditionConfigure AD or LDAP authentication
AuthorizationImprovedWhen granting permissions for asset group accounts, the system now displays a list of existing accounts for selection.Basic Edition, Enterprise Dual-Engine EditionAuthorize users for asset groups and asset group accounts
Session auditImprovedSession audit searches now support fuzzy matching.Basic Edition, Enterprise Dual-Engine EditionN/A

2023

VersionFeatureChange typeDescriptionAffected editionsRelease dateDocumentation
Basic EditionSwitch to a different zoneNewSwitch your bastion host to a different zone to prevent service interruptions if the current zone becomes unavailable.Basic Edition2023-09-18Configure a bastion host
V3.2.37.1O&M for PolarDB databasesNewO&M support for PolarDB databases.Enterprise Edition2023-08-30Supported assets and Use the database management feature
User list exportNewExport the user list, including fields such as username, email address, mobile number, user group, and creation time.Basic Edition and Enterprise EditionManage users
O&M tokenEnhancedFlexibly configure the validity period and usage limits for O&M tokens. O&M users can renew tokens independently.Basic Edition and Enterprise EditionConfigure O&M settings and Manage an O&M token
API updateEnhancedAdded APIs for O&M review and command review.Basic Edition and Enterprise EditionNone
Asset network connectivity checkEnhancedEnable or disable the asset network check feature. Configure the check interval for asset connectivity.Basic Edition and Enterprise EditionDiagnose network issues
O&M session duration limitEnhancedConfigure the maximum O&M session duration. The maximum duration for a single session is seven days.Basic Edition and Enterprise EditionConfigure O&M settings
Real-time database O&M connectionsEnhancedOptimized real-time connection and concurrency calculation for database access using O&M tokens to improve audit accuracy.Enterprise EditionNone
V3.2.36Stability enhancementsEnhancedOptimized the overload protection process to improve the stability of product components.Basic Edition and Enterprise Edition2023-07-18None
V3.2.35Multi-zone configurationNewConfigure zones for vSwitches.Enterprise Edition2023-05-30Configure network settings for bastion host instances
NotificationsNewAdded user-related notifications: password expiration reminders and user account expiration reminders.Basic Edition and Enterprise EditionUse the notification feature
Two-factor authenticationNewMobile-based two-factor authentication for users in Thailand (+66), Vietnam (+84), and Cambodia (+855).Basic Edition and Enterprise EditionEnable two-factor authentication
Asset authorization workflowEnhancedAuthorizing an asset now automatically redirects to the asset account authorization page.Basic Edition and Enterprise EditionNone
AD/LDAP user snapshot synchronizationEnhancedThe system now periodically caches users from AD and LDAP servers.Basic Edition and Enterprise EditionConfigure AD authentication or LDAP authentication
V3.2.33Connectivity check toolNewUse a self-service tool to troubleshoot O&M connection issues between a client and a bastion host and between a bastion host and an asset.Basic Edition and Enterprise Edition2023-02-21None
Asset risk monitoringNewIntegration with Security Center for asset risk monitoring. Synchronize and view risk statuses, including the number of alerts, vulnerabilities, and baseline risks. Navigate directly to Security Center to resolve issues.Basic Edition and Enterprise EditionNone

2022

Software versionFeatureChange typeDescriptionAffected editionsRelease dateDocumentation
V3.2.31Oracle database O&MNewO&M support for Oracle databases.Enterprise Edition2022-12-22O&M overview
Third-party asset source managementEnhancedImport and manage assets from third-party cloud sources, including Amazon Web Services and Tencent Cloud.Basic Edition and Enterprise EditionManage third-party asset sources
O&M portalEnhancedLocal, AD, and LDAP users can modify their keys and personal information through the O&M portal.Basic Edition and Enterprise EditionO&M engineer security policies
Asset connectivity checkNewAutomatic asset connectivity checks. The connectivity status is updated every 4 hours.Basic Edition and Enterprise EditionManage hosts
AD and LDAP configurationEnhancedClear AD and LDAP authentication configurations.Basic Edition and Enterprise EditionConfigure AD and LDAP authentication
APIEnhancedAdded API operations to manage user public keys. When creating or editing a user, configure their validity period, two-factor authentication, and require a password change on their next logon.Basic Edition and Enterprise EditionNone
Host keyNewHost keys now support the ed25519 format.Basic Edition and Enterprise EditionNone
V3.2.30O&M approvalNewSecondary O&M approval. When an O&M user logs on to an asset, an administrator must provide a second approval.Basic Edition and Enterprise Edition2022-11-21Configure control policies
Host O&M tokenNewFor client-based O&M, request an O&M token from the host's O&M interface to perform tasks.Basic Edition and Enterprise EditionNone
Message notificationsNewReceive notifications — including command alerts, storage alerts, and O&M address changes — by text message and email, in addition to internal messages.Basic Edition and Enterprise EditionMessage notifications
Asset monitoringNewActivity monitoring for O&M assets. Filter assets that have not been accessed for O&M in the last 7 or 30 days.Basic Edition and Enterprise EditionNone
User logon configurationNewRequire key-based authentication for all logons to Bastionhost.Basic Edition and Enterprise EditionUser configuration
Two-factor authenticationNewTwo-factor authentication using text messages for Saudi Arabia (+966).Basic Edition and Enterprise EditionEnable two-factor authentication
Two-factor authentication configurationEnhancedModify two-factor authentication settings for multiple users in bulk from the User List page.Basic Edition and Enterprise EditionEnable two-factor authentication
Control policyEnhancedImproved the logic for creating a control policy.Basic Edition and Enterprise EditionConfigure control policies
User status monitoringEnhancedAdded a flag for deleted RAM users.Basic Edition and Enterprise EditionManage users
Stability enhancementsEnhancedAdded an overload protection mechanism to improve the stability of O&M sessions.Basic Edition and Enterprise EditionNone
V3.2.28Database O&M auditNewDatabase O&M auditing. Control and audit O&M on RDS instances running MySQL, SQL Server, or PostgreSQL, and on self-managed databases.Enterprise Edition2022-07-27Database management
O&M portalNewWeb-based O&M portal. O&M users can perform O&M on authorized assets, and local users can log on using OTP token authentication.Basic Edition and Enterprise EditionO&M overview
Two-factor authentication for OTP tokensNewLocal users can scan a QR code in the O&M portal to authenticate with an OTP token.Basic Edition and Enterprise EditionEnable two-factor authentication
Custom host portNewSpecify custom ports when importing hosts in bulk from an Excel file.Basic Edition and Enterprise EditionModify the service port of a host
V3.2.26Third-party asset source managementNewImport assets from third-party asset sources.Basic Edition and Enterprise Edition2022-04-06Create a host
Two-factor verification codeNewSend two-factor verification codes through DingTalk work notifications. Select Chinese or English as the language for the verification code.Basic Edition and Enterprise EditionEnable two-factor authentication
User configuration for two-factor authenticationNewConfigure two-factor authentication for individual users.Basic Edition and Enterprise EditionManage users
API operationsNewAdded API operations for AD authentication, two-factor authentication, and shared key configuration.Basic Edition and Enterprise EditionAsset management (for V3.2.X only) and System settings (for V3.2.X only)
Search criteria for password change tasksEnhancedSearch for password change tasks by host IP address and hostname.Enterprise EditionNone
Text message authenticationNewText message authentication for users in Poland (+48) and Spain (+34).Basic Edition and Enterprise EditionWhich countries and regions are supported for Bastionhost two-factor authentication by text message?
AD and LDAP user synchronizationEnhancedPeriodically synchronize the configuration and status of AD and LDAP users.Basic Edition and Enterprise EditionUser configuration

2021

Software versionFeatureChange typeDescriptionAffected editionsRelease dateDocumentation
V3.2.22Authorization ruleNewAuthorize multiple users to manage assets in bulk and set a validity period for each rule.Basic Edition and Enterprise Edition2021-11-22Create an authorization rule and Manage authorization rules
Configuration export and importNewExport configurations from one Bastionhost instance and apply them to others.Basic Edition and Enterprise EditionConfiguration backup
Network domain HA modeNewConfigure a standby proxy server for a network domain. If the primary proxy server fails, the system automatically switches to the standby.Enterprise EditionNetwork domain
Network domain proxyNewInternal message notifications for network domain proxy exceptions.Enterprise EditionMessage notification
Personalized desktopNewWhen enabled, users can access their existing Windows personalized desktops during O&M sessions.Basic Edition and Enterprise EditionO&M configuration
Force password reset on next logonNewWhen creating a local user, require them to reset their password on their next logon.Basic Edition and Enterprise EditionManage users
V3.2.20Access assets through a proxyNewAccess assets through SSH, SOCKS5, and HTTP proxies.Enterprise Edition2021-07-22Network domain
Global configuration for host fingerprintsNewGlobal setting to control whether to verify host fingerprints.Basic Edition and Enterprise EditionO&M configuration
Account logon permission controlEnhancedAdded a switch for empty account permissions.Basic Edition and Enterprise EditionO&M configuration
O&M log backup and exportNewBack up and export O&M logs.Basic Edition and Enterprise EditionLog backup
Internal message notificationsNewAdded internal message notifications for: command approvals and rejections, password change tasks, storage alerts, weekly O&M reports, and shared key expiration.Basic Edition and Enterprise EditionMessage notification
Text message authenticationNewText message authentication for users in France (+33), Israel (+972), and Italy (+39).Basic Edition and Enterprise EditionWhich countries and regions support two-factor authentication by text message for Bastionhost?
V3.2.18Export host listsNewExport host lists.Basic Edition and Enterprise Edition2021-04-21Export the host list
Key managementNewBind keys to host accounts in bulk.Basic Edition and Enterprise EditionShared key
User taggingEnhancedTag users who have not logged in for a custom period.Basic Edition and Enterprise EditionNone
AD/LDAP user importEnhancedFilter AD or LDAP users by username when importing.Basic Edition and Enterprise EditionManage users
Control policyNewUse a control policy to restrict user logon times.Basic Edition and Enterprise EditionConfigure a control policy
Two-factor authenticationNewEmail-based two-factor authentication. Customize the number of days to skip re-verification after a successful authentication.Basic Edition and Enterprise EditionEnable two-factor authentication
Password validity periodNewConfigure the password validity period for local users.Basic Edition and Enterprise EditionUser configuration
V3.2.17Password change taskNewChange passwords for Linux host accounts in bulk.Enterprise Edition2021-03-15Password change tasks
Batch-clear host fingerprintsNewClear host fingerprints in bulk.Basic Edition and Enterprise EditionClear host fingerprints
Search for hosts, host groups, users, and user groupsEnhancedSearch for hosts and host groups by name. Search for users and user groups by name.Basic Edition and Enterprise EditionNone
Text message authenticationNewText message authentication for users in South Korea (+82), the Philippines (+63), Taiwan, China (+886), Switzerland (+41), and Sweden (+46).Basic Edition and Enterprise EditionWhich countries and regions support two-factor authentication by text message for Bastionhost?
Restrict user logonEnhancedRestrict users from logging on after their real-time sessions are blocked.Basic Edition and Enterprise EditionBlock sessions
Add users with validity periodNewSet a validity period when adding a local, AD, or LDAP user.Basic Edition and Enterprise EditionManage users
O&M reportsNewO&M reports exportable in Word, PDF, and HTML formats.Basic Edition and Enterprise EditionView and export O&M reports
Extended storage for audit recordingsEnhancedPurchase extended storage packages for audit recordings.Basic Edition and Enterprise EditionPurchase an instance
Host O&M via web terminalNewPerform O&M on hosts directly from the Bastionhost console using the web terminal.Enterprise EditionHost O&M
O&M session duration limitsEnhancedLimit the idle and total duration of an O&M session.Basic Edition and Enterprise EditionO&M configuration
APINewAdded APIs for managing users, user groups, hosts, host groups, host accounts, and host authorizations.Basic Edition and Enterprise EditionHosts (for V3.2.17 and later)

2020

VersionFeatureChange typeDescriptionAffected editionsRelease dateDocumentation
V3.2.13Enterprise EditionNewBastionhost Enterprise Edition is now available.Basic Edition and Enterprise Edition2020-11-16Billing methods
WizardNewA setup wizard guides first-time users through Bastionhost. Find it in the upper-right corner of the console.Basic Edition and Enterprise EditionNone
Tagging for released ECS instancesEnhancedTag released ECS instances.Basic Edition and Enterprise EditionNone
User settingsNewAssign a user to a user group during user creation.Basic Edition and Enterprise EditionManage users
SMS authenticationNewSMS authentication for users in Germany (+49), Australia (+61), the United States (+1), Dubai (+971), Japan (+81), the United Kingdom (+44), India (+91), and Macao, China (+853).Basic Edition and Enterprise EditionWhich countries and regions are supported for SMS two-factor authentication?
Network diagnosticsNewNetwork diagnostics feature.Basic Edition and Enterprise EditionNetwork diagnostics