S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S4E16 - Intune - Modern Management for Windows

S4E16 - Intune - Modern Management for Windows

Alan and Sam discuss how Microsoft Intune can help manage your Windows 10/11 estate from anywhere that has an internet connection. Alan goes through the capabilities and how it can help organisations....

29 Syys 202342min

S4E15 - Purview Insider Risk Management - Minimise internal risks to data security

S4E15 - Purview Insider Risk Management - Minimise internal risks to data security

This week we discussed Purview Insider Risk Management. Insider Risk Management is a compliance solution that enables organisations to discover, track and manage insider risk. Insider risks can be int...

22 Syys 202343min

S4E14 - Monitor Active Directory with Microsoft Defender for Identity

S4E14 - Monitor Active Directory with Microsoft Defender for Identity

Alan and Sam discuss how Microsoft Defender for Identity monitors and detects unusual behavior's and attacks on Active Directory: Here are a few things we covered: What is Active Directory Why do we ...

15 Syys 202345min

S4E13 - Azure Lighthouse - Large scale multi-tenant management within Azure

S4E13 - Azure Lighthouse - Large scale multi-tenant management within Azure

This week we discussed Azure Lighthouse. Lighthouse allow organisations and partners access and manage resources and services in multiple tenants at scale. Lighthouse allows management of access, prov...

8 Syys 202351min

S4E12 - Microsoft Defender for Cloud Apps - Your SSPM and CASB solution

S4E12 - Microsoft Defender for Cloud Apps - Your SSPM and CASB solution

Alan and Sam discuss how Microsoft Defender for Cloud Apps can help monitor and secure access to your SaaS applications. Here are a few things we covered: What is Microsoft Defender for Cloud Apps Ho...

1 Syys 202348min

S4E11 - Azure Chaos Studio - Use chaos to improve your infrastructure resilience in Azure

S4E11 - Azure Chaos Studio - Use chaos to improve your infrastructure resilience in Azure

This week we discussed Azure Chaos Studio. Chaos Studio allows organisations to run test plans to introduce chaos. Learn how your applications and infrastructure are effected by infrastructure disrupt...

25 Elo 202344min

S4E10 - Microsoft Entra - Global Secure Access First Look

S4E10 - Microsoft Entra - Global Secure Access First Look

Alan and Sam discuss Microsoft Entra ID Global Secure Access. A feature that was announced with the rebrand of Azure AD to Microsoft Entra ID. Here are a few things we covered: What is Microsoft Entr...

18 Elo 202345min

S4E9 - Microsoft Dev Box - Azure hosted development environments

S4E9 - Microsoft Dev Box - Azure hosted development environments

This week we discussed Microsoft Dev Box. Dev Box allows development teams to create development environments for their projects in the cloud. This enables development teams to utilise infrastructure ...

11 Elo 202343min