S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S3E21 - Season 3 Finale - including a Microsoft Build 2023 recap!

S3E21 - Season 3 Finale - including a Microsoft Build 2023 recap!

It's the Season 3 Finale! Where has the time gone! Alan and Sam discuss the season, what their favorite episode were. They discuss some of the announcements at Microsoft Build 2023 that peaked their i...

26 Touko 202339min

S3E20 - Windows 365 vs Azure Virtual Desktop, how do you decide?

S3E20 - Windows 365 vs Azure Virtual Desktop, how do you decide?

Alan and Sam discuss the difference between Windows 365 and Azure Virtual Desktop (AVD). Alan goes through what to consider when choosing which technology to use for different scenarios. What did you ...

19 Touko 202351min

S3E19 - Azure DevOps Services - plan, manage and deploy software more effectively

S3E19 - Azure DevOps Services - plan, manage and deploy software more effectively

Alan and Sam discuss Azure DevOps services and its features. Sam gives us a tour of the features and benefits of Azure DevOps and how it can be integrated into your development process. What did you t...

12 Touko 20231h 5min

S3E18 - Windows 365 - the ultimate managed Cloud PC for all

S3E18 - Windows 365 - the ultimate managed Cloud PC for all

Alan and Sam discuss all of the features of Windows 365. Alan goes through the pricing, benefits and how organisations can use this to provide secure access to their environments. Windows 365 Cloud PC...

5 Touko 202351min

S3E17 - Azure Load Testing - Load test your APIs and Web Applications with ease

S3E17 - Azure Load Testing - Load test your APIs and Web Applications with ease

Alan and Sam discuss how Azure Load Testing can streamlined you load testing QA process. Bring your JMeter scripts, configure the service and let Azure and Microsoft take care of the rest. Sam runs us...

28 Huhti 202350min

S3E16 - Azure Firewall - Securing your Azure Network

S3E16 - Azure Firewall - Securing your Azure Network

Alan and Sam discuss how Azure Firewall can help secure your network environment. Alan discusses how to set it up, and when you should decide to use it over Network Virtual Appliances (NVA). They also...

21 Huhti 202352min

S3E15 - Azure API Management - Manage and Secure your APIs at scale

S3E15 - Azure API Management - Manage and Secure your APIs at scale

Alan and Sam discuss Azure API Management. Sam explains the key features and benefits of using API management to manage your APIs at scale. What did you think of this episode? Give us some feedback v...

14 Huhti 20231h

S3E14 - Azure Private Link (plus some important news!!!) - Secure access to your Azure resources

S3E14 - Azure Private Link (plus some important news!!!) - Secure access to your Azure resources

Alan and Sam discuss the Azure Private Link and how it can secure your services. Alan goes through the functionality available and the benefits of using Azure Private Endpoints to access PaaS. Alan al...

7 Huhti 202357min