Comparison route

Single service comparison

Back to main page

Privileged Access Security

Azure Bastion

Azure Bastion is a fully managed PaaS bastion deployed in its own subnet that brokers secure RDP and SSH sessions directly from the Azure portal to private virtual machines, without exposing public IPs or requiring client-side VPNs. It integrates with Azure Entra ID authentication, JIT access, and NSG controls, metered per deployed hour plus outbound data transfer.

Azure logo

Azure

Service information

Azure Bastion iconAzure Bastion

Shortname: Bastion

Huawei equivalent shortnames: CBH

Keywords: privileged access, bastion, security, audit

Differences vs Huawei

Azure Bastion is a thin session brokering appliance scoped to virtual network connectivity, terminating only RDP/SSH over TLS from the browser; Huawei Cloud Bastion Host (CBH) is a broader privileged access management platform that centralizes host account lifecycle, authorization policies, multi-factor auth, automated operations, and full session recording/playback for hosts and databases. CBH also manages credentials and assets, whereas Bastion provides none of that governance layer.

Connectivity and identity integration diverge sharply. Bastion binds to a VNet/subnet, uses Entra ID for the portal user, and forwards to private IPs without re-authenticating the target account; CBH acts as an explicit jump server that re-authenticates each managed credential, federates to IAM or LDAP, and enforces command-level authorization and session approval workflows. Protocols also differ: CBH additionally covers Telnet, MySQL, and other DB/web ops, not only RDP/SSH.

Scaling, HA, and operational responsibility differ. Bastion is stateless per region and scaled by Microsoft with built-in SLA, billed by instance-hour; CBH is purchased as a sized instance tied to managed-asset tiers (10 to 10,000 assets) and concurrent-session caps, with standard and professional editions requiring you to pick capacity and handle disk/audit retention. Verify regional availability and edition/asset coverage per target region before treating CBH as a drop-in replacement.

Migration to Huawei

Assess access scope first: enumerate Azure Bastion-dependent VMs, the Entra ID groups and JIT policies granting access, and the protocols in use (RDP/SSH only, or you also need DB/web ops). Map these to CBH assets, system users, and authorization policies; use the professional edition only if database audit or automated operations are in scope. Confirm the target region offers CBH and choose an asset-concurrency tier sized to peak concurrent admins plus headroom for managed hosts and cloud/off-cloud servers.

For configuration and credential migration, import target hosts from IAM/VPC, onboard host credentials into CBH as managed accounts, and rebuild authorization groups and command-control policies to mirror Entra ID JIT behavior. Replace browser-brokered Bastion sessions with web-based or client-based CBH sessions; recreate MFA by wiring CBH to Huawei IAM or a remote auth source, and set session recording and retention to meet your compliance window (disk size scales with recording volume).

Validate before cutover: pilot with non-production hosts, confirm RDP/OSH file transfer, clipboard, and DB/web operations behave per policy, and replay recorded sessions to verify audit completeness. Run Bastion and CBH in parallel, then cut over by removing public-IP exceptions and disabling Bastion provisioning once all admin paths route through CBH; decommission the Bastion subnet only after sign-off. No automated Bastion-to-CBH migration tool exists, so policy and asset onboarding are manual.

Mind the cost and operational gaps. Azure bills Bastion by deployed hour plus outbound egress with implicit scaling; CBH is a fixed monthly instance fee tied to asset tier and edition, with separate disk and audit-retention cost, so recompute TCO at peak concurrent sessions and retention rather than raw session hours. CBH also does not natively provide Bastion's Entra ID or NSG-per-subnet semantics, so combine CBH with IAM, CCM, and VPC/NSG design to recover identity, certificate, and network-isolation controls.

Huawei Cloud logo

Huawei Cloud

Huawei equivalent service

Cloud Bastion Host iconCloud Bastion Host

Shortname: CBH

General function: Privileged Access Security

Privileged access and operation audit bastion service.

Keywords: bastion, privileged access, audit