Join our Newsletter — 33% off our NHI Course
Home› FAQ› Architecture & Implementation› How should security teams choose between a bastion-based…
Architecture & Implementation

How should security teams choose between a bastion-based access model and a direct cloud session manager for admin shell access?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 25, 2026 Domain: Architecture & Implementation

Choose the model based on your operational priorities and audit needs. A bastion-based approach gives you a centralized control point, stronger session visibility, and tighter integration with SSH workflows. A direct cloud session manager reduces infrastructure to run, but can create weaker interoperability and less flexible auditing. The right choice depends on whether standardisation or operational simplicity matters more.

How to evaluate bastion access versus a direct session manager

The first question is not which pattern is more modern, but which control point matches the way your admins actually work. A bastion concentrates access through one hardened hop, so it tends to fit teams that value standardised SSH workflows, deep session inspection, and a predictable audit trail. A direct cloud session manager is usually better when you want less infrastructure to own and accept a lighter operational footprint.

The practical difference is where trust and observability sit. With a bastion, the security team owns a clearly defined intermediary that can enforce access policy, record activity, and absorb custom controls. With a session manager, much of that control shifts into the cloud platform, which can simplify operations but may narrow how much you can tailor logging, approval flow, and tool interoperability.

That means the choice should be made on governance fit, not just convenience. If your audit model depends on one place to anchor administration, a bastion is often easier to defend. If your platform already provides consistent remote session controls and your team is optimising for lower maintenance, a direct session manager may be sufficient, provided its native controls meet your evidence and access requirements.

What changes operationally when the access path changes

A bastion-based model usually gives you more freedom to layer controls around the session itself. Teams can add strong shell recording, jump-host hardening, network segmentation, and SSH-specific policy enforcement without waiting for the cloud provider to expose those options. That flexibility matters when you need custom workflows or when administrators still rely on traditional terminal tooling.

A direct cloud session manager reduces the amount of host infrastructure to patch, monitor, and back up. That simplicity can be valuable in small teams or in cloud-native environments where the provider’s session service already integrates with identity, logging, and permission checks. The trade-off is that you are accepting the platform’s opinionated model, so you should verify whether it supports the exact audit detail and command-path visibility you need.

Interoperability is often the hidden deciding factor. If your admins move between clouds, on-premises systems, or mixed SSH tooling, a bastion can act as a stable operational bridge. If your estate is mostly one cloud and one administration model, direct session management may be cleaner and easier to standardise at scale.

What security teams should compare before they decide

The decisive comparison is usually around auditability, blast radius, and administrative friction. Bastions can reduce uncertainty because all admin sessions funnel through a known point, but they also create a higher-value target and an extra system to secure. Direct session managers reduce that standalone exposure, yet they can make it harder to impose consistent controls across every target system if the cloud-native features are not comprehensive enough.

For cloud-session design, the access model should be assessed alongside logging, approval, and privilege scope. The important question is whether the admin can reach only the intended target, whether the session is attributable, and whether the resulting evidence is strong enough for incident review or compliance review. If the answer is yes, the lighter model may be justified; if not, the bastion remains the safer governance anchor.

If the decision is being driven by cloud architecture rather than security requirements, check whether the session manager still preserves the operational signals your responders need, such as who connected, to what, for how long, and under which authorization path. Those details matter more than the label on the access pattern.

Risk and Threat Considerations

Both models create risk if they are treated as a convenience layer rather than a privileged access boundary. A bastion can become a single point of compromise or a blind spot if it is weakly hardened, while a direct session manager can under-deliver on visibility if teams assume the platform’s default logging is enough for forensic or compliance needs.

Failure mechanism: The most common failure is privilege concentration without sufficient session control, where an admin path becomes both broad and hard to reconstruct after the fact. In a bastion model that usually means poor host hardening or weak session capture; in a direct session model it usually means overly coarse permissions or incomplete audit evidence.

Impact: The result is reduced traceability of administrative actions, greater difficulty proving who did what, and a larger blast radius if privileged access is abused or stolen. The risk becomes more serious when the same access path can reach production systems, change infrastructure, or bypass normal application controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, CIS Controls v8 and NIST Zero Trust (SP 800-207) set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegePrivileged admin shell access must be scoped to the minimum target and action set.
AU-2 — Event LoggingThe choice hinges on what session evidence and audit trail the access path can produce.
Recommendation — Enforce least-privilege access paths for administrative shell sessions. Define and retain audit events for privileged shell access sessions.
ISO/IEC 27001:2022A.5.15 — Access controlThe page compares two access models for controlling administrative access to systems.
A.8.15 — LoggingSession visibility and reconstructability are central to the comparison.
Recommendation — Apply access control rules that match the chosen admin access model. Enable logging that preserves admin session accountability.
CIS Controls v8CIS-5 — Account ManagementThe decision affects how privileged administrative access is granted and governed.
Recommendation — Standardise privileged account access paths and review them routinely.
NIST Zero Trust (SP 800-207)Zero Trust ArchitectureThe comparison is about trusted access paths, session boundaries, and control points.
Recommendation — Place privileged shell access behind explicit verification and session control.

Practitioner Guidance

What to verify: Confirm that the chosen model can produce session evidence that is usable after the fact, not just logs that exist in theory. You should be able to show identity, target, time, and session outcome without reconstructing the event from multiple tools.

Decision rule: If your admins need flexible SSH workflows, custom inspection, or one centrally governed access choke point, favour the bastion. If your cloud session manager already gives you strong attribution and enough control for your audit posture, prefer the simpler model and remove unnecessary infrastructure.

Practitioner takeaway: The best choice is the one that preserves privileged-session accountability with the least operational complexity, but only if the resulting evidence is strong enough for incident response and audit review.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 25, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org