Updated on 2026-07-30 GMT+08:00

Managing ACL Policies

Scenarios

You can modify, enable, disable, or delete an ACL rule you configure, or associate an ACL rule with a user, user group, resource account, or account group.

Prerequisites

Your role has the management permission for the ACL Rules module. For details about how to check the permissions of each role, see Role.

Viewing and Editing an ACL Rule

You can edit rules to meet your changed operation needs. For example, if your operation personnel or resource permissions are changed, you can check involved rules and edit their settings, including basic permissions, related users, user groups, accounts, and account groups, and approvers of two-person authorization.

  • A modified rule takes effect the instant its status changes to Enabled.
  • If associated users have logged in to resources before the modification, those users need to log out and log in again for the modified rule to take effect.
  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  3. View the rule list.

    Table 1 Parameters in the ACL rule list

    Parameter

    Description

    Rule Name

    Name of an ACL rule.

    Status

    Status of an ACL rule.

    User

    Users or user groups associated with the ACL rule.

    Account

    Resource account or account group associated with the ACL rule.

    Operation

    Operations you can perform for an ACL rule.

  4. Locate the row that contains the target rule, and click the rule name or Manage in the Operation column to go to the details page.
  5. View and edit basic rule information.

    • In the Basic Info area, view basic rule information, such as the department and status.
    • In the Basic Info area, click Edit on the right. In the displayed dialog box, modify the period of validity, department, and other information of the rule. For details about the parameters, see Table 1.

  6. View and edit users or user groups associated with the rule.

    • In the User and UserGroup areas, view the users or user groups associated with the rule.
    • In the User or User Group area, click Edit on the right. In the displayed dialog box, associate users or user groups with the rule.
    • In the list, locate the row that contains the target user or user group, and click Remove to delete the associated user or user group and cancel the authorization.

  7. View and edit resource accounts and account groups associated with the rule.

    • In the Account and AccountGroup areas, view the resource accounts or account groups associated with the rule.
    • In the Account or Account Group area, click Edit on the right. In the displayed configuration window, add a resource account or account group to be associated.
    • To remove a resource account or account group, click Remove in the row of the resource account or account group.

  8. View and edit two-person authorization.

    • In the Approver area, view the two-person authorization candidates associated with the rule.
    • In the Approver area, click Edit on the right. In the displayed dialog box, add associated approvers.
    • To remove an approver, click Remove in the row of the approver.

Associating an ACL Rule with a User or User Group

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  3. In the row containing the target rule, click Relate in the Operation column and select User or UserGroup.
  4. In the displayed dialog box, associate the rule with a user or user group.

    Make sure the associated users or users in the associated user groups have the permissions for the Host Operations or App Operations module. Otherwise, after they log in to the system, the Operation module will be unavailable to them. This means they cannot log in to any managed resources for operation. For details about the permissions of each role, see Role.
    • You can associate a rule with multiple users or user groups at once.
      • Select users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selectable users or Selectable user groups box, and click to move them to the Selected users or Selected user groups box.
      • Remove users or user groups: On the Relate User or Relate User Group tab, select users or user groups in the Selected users or Selected user groups box, and click to move them back to the Selectable users or Selectable user groups box.
    • After a user group is associated with a rule, users automatically obtain the permissions of the rule the instant they are added to the user group.

  5. Click OK.

Associating an ACL Rule with a Resource Account or Account Group

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  3. In the Operation column of the target rule, click Relate and select Account or AccountGroup.
  4. In the displayed dialog box, associate the rule with a resource account or account group.

    • You can associate a rule with multiple managed resource accounts or account groups at once.
      • Select a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selectable accounts or Selectable account groups box, and click to move it to the Selected accounts or Selected account groups box.
      • Remove a resource account or account group: On the Relate Account or Relate Account Group tab, select the target resource account or account group in the Selected accounts or Selected account groups box, and click to remove it back to the Selectable accounts or Selectable account groups box.
    • After an account group is associated with a rule, accounts automatically obtain the permissions of the rule the instant they are added to the account group.

  5. Click OK.

Enabling or Disabling an ACL Rule

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  1. Enable or disable an ACL rule.

    • Enabling a rule
      1. In the rule list, select all the target rules and click Enable in the lower left corner.
      2. In the displayed dialog box, click OK.
    • Disabling a rule
      1. In the rule list, select all the target rules and click Disable in the lower left corner.
      2. In the displayed dialog box, click OK.

Exporting ACL Rules

You can export all ACL rules in a few clicks.

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  1. (Optional) Select all the target rules. If no rules are selected, all rules are exported by default.
  2. Click in the upper right corner and create an export task.
  3. Click Go to Download Center to go to the download task list.
  4. When the packing progress of the download task reaches 100%, click Download in the Operation column to download the file to a local PC. Once the file is downloaded, open it locally to check the exported ACL rules.

Deleting an ACL Rule

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose Policy > ACL Rules to enter the ACL rule list page.
  1. Delete ACL rules.

    • Deleting a single rule
      1. In the row containing the target rule, click Delete in the Operation column.
      2. In the displayed dialog box, click OK.
    • Batch deleting rules
      1. On the ACL rule list page, select all the target rules.
      2. Click Delete in the lower left corner.
      3. In the displayed dialog box, click OK.