Help Center/ Cloud Bastion Host/ User Guide/ Policy/ ACL Rules/ Setting Two-person Authorization
Updated on 2026-07-30 GMT+08:00

Setting Two-person Authorization

Scenarios

Two-person authorization, also known as two-person approval, adds an additional layer of resource security during operation. After two-person authorization is configured, operators can access core resources only after being authorized and authenticated by the administrator onsite. Even if the operation personnel account is lost, the information of business-critical resources will not be disclosed, reducing operation risks and ensuring the security of critical assets.

Notes and Constraints

Only department administrators of the current and superior departments, including the system administrator admin, can be selected as the approvers for two-person authorization.

Prerequisites

  • Your role has the management permission for the ACL Rules module. For details about how to check the permissions of each role, see Role.
  • You have created an ACL rule and associated it with system users and managed resource accounts. For details, see Creating an ACL Rule.

Configuring Two-person Authorization

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  3. Locate the target ACL rule and choose More > Approver in the Operation column. The Edit Approvers dialog box is displayed.
  4. Select one or more department administrators and set them as approvers of two-person authorization.
  5. Click OK.

Verifying the Result

After two-person authorization is successfully configured, double authorization is required whenever a user associated with the configured rule attempts to access resources covered by that rule.

The user needs to select an approver and enter the account password of the approver. The user then can access the resource only after the verification is successful.