All Products
Search
Document Center

Bastionhost:Authorize a user to manage asset groups and the accounts of assets in the asset groups

Last Updated:May 27, 2024

After you add a user to your bastion host, you can authorize the user to manage asset groups. This way, the user can log on to the bastion host to perform O&M operations on the assets in the asset groups. This topic describes how to authorize a user to manage asset groups.

Prerequisites

Authorize a user to manage asset groups

  1. Log on to the Bastionhost console. In the top navigation bar, select the region in which your bastion host resides.

  2. In the bastion host list, find the bastion host that you want to manage and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user whom you want to authorize to manage asset groups and click Authorize User to Manage Asset Groups in the Actions column.

  5. On the Managed Asset Groups tab, click Authorize User to Manage Asset Groups.

  6. In the Authorize User to Manage Asset Groups panel, select the asset groups on which you want to authorize the user to perform O&M operations and click OK.

Authorize a user to manage the accounts of assets in one or more asset groups

Authorize a user to manage the accounts of assets in a single asset group

To authorize a user to manage the accounts used to log on to the assets in a single asset group, perform the following steps:

  1. Log on to the Bastionhost console. In the top navigation bar, select the region in which your bastion host resides.

  2. In the bastion host list, find the bastion host that you want to manage and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user whom you want to authorize to manage asset groups and click Authorize User to Manage Asset Groups in the Actions column.

  5. On the Managed Asset Groups tab, click No accounts found. Click here to authorize the user to manage the accounts of the asset group.

  6. In the Select Account panel, select the accounts that you want to authorize the user to manage and click OK.

Authorize a user to manage an account of assets in multiple asset groups at a time

To authorize a user to manage an account of the assets in multiple asset groups at a time, perform the following steps:

  1. Log on to the Bastionhost console. In the top navigation bar, select the region in which your bastion host resides.

  2. In the bastion host list, find the bastion host that you want to manage and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user whom you want to authorize to manage the account and click Authorize User to Manage Asset Groups in the Actions column.

  5. Select the asset groups whose account you want to authorize the user to manage and choose Batch > Bind Accounts to Multiple Asset Groups below the list.

  6. In the Accounts section, enter the name of the account and click Update.

Remove asset groups from the list of asset groups that a user is authorized to manage

If a user no longer needs to perform O&M operations on some asset groups, you can follow the principle of least privilege to remove these asset groups from the list of asset groups that the user is authorized to manage.

  1. Log on to the Bastionhost console. In the top navigation bar, select the region in which your bastion host resides.

  2. In the bastion host list, find the bastion host that you want to manage and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user that you want to manage and click Authorize User to Manage Asset Groups in the Actions column.

  5. On the Managed Asset Groups tab, select the asset groups that you want to remove and click Remove below the list.

  6. In the dialog box that appears, click Remove.

Remove an account of the assets in multiple asset groups that a user is authorized to manage

To remove an account of the assets in multiple asset groups that a user is authorized to manage at a time, perform the following steps:

  1. Log on to the Bastionhost console. In the top navigation bar, select the region in which your bastion host resides.

  2. In the bastion host list, find the bastion host that you want to manage and click Manage.

  3. In the left-side navigation pane, choose Users > Users.

  4. On the Users page, find the user that you want to manage and click Authorize User to Manage Asset Groups in the Actions column.

  5. On the Managed Asset Groups tab, select the asset groups whose account you want to remove and choose Batch > Remove Accounts of Multiple Asset Groups below the list.

  6. In the Accounts section, specify the account to remove and click Update.