S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S3E13 - Azure Static Web Apps - Rapidly deploy globally hosted static & serverless web applications

S3E13 - Azure Static Web Apps - Rapidly deploy globally hosted static & serverless web applications

Alan and Sam discuss Azure static Web applications. Part of Azure App Service, static web apps allows developers to deploy static web applications in conjunction with serverless function applications ...

31 Maalis 202346min

S3E12 - Microsoft Intune Suite - New SKUs are in town!

S3E12 - Microsoft Intune Suite - New SKUs are in town!

Alan and Sam discuss the new Intune licences that have recently been released. Alan goes through the new functionality that is coming to Intune and why they help manage and support your endpoints. MS ...

24 Maalis 202350min

S3E11 - Azure Cognitive Services - Efficiently add cognitive functionality into your apps/services

S3E11 - Azure Cognitive Services - Efficiently add cognitive functionality into your apps/services

Alan and Sam discuss the functionality provided by Azure Cognitive Services, a group of AI powered cognitive solutions that can rapidly add advanced cognitive functionality to your applications and se...

17 Maalis 202356min

S3E10 - Power Platform - Managing your application lifecycle with Solutions

S3E10 - Power Platform - Managing your application lifecycle with Solutions

Alan and Sam discuss how Power Platform solutions can help manage your lo-code/no-code application lifecycle. Alan runs through what a solution can be used for and what can be managed in Power Platfor...

10 Maalis 202341min

S3E9 - Azure Developer CLI - Helping Developers to Deploy and manage their Applications on Azure

S3E9 - Azure Developer CLI - Helping Developers to Deploy and manage their Applications on Azure

Alan and Sam discuss how The Azure Developer CLI can be used to help automate and manage key points in the application development lifecycle. Sam discusses what the Azure Developer CLI (azd) is, the f...

3 Maalis 202356min

S3E8 - Azure Key Vault - Securing your Certificates and Secrets

S3E8 - Azure Key Vault - Securing your Certificates and Secrets

Alan and Sam discuss how Azure Key vault can help secure your certificates, keys, and secrets. Alan goes though the types of vaults you can use and how you can secure the access to the secrets. They a...

24 Helmi 202353min

S3E7 - Azure Stack - Take Azure with you to the Edge

S3E7 - Azure Stack - Take Azure with you to the Edge

Alan and Sam discuss how Azure Stack solutions can help bring the capabilities of Azure management plane to your on-premises and edge environments. Sam goes through the three solutions, what their cap...

17 Helmi 20231h

S3E6 - Microsoft Defender for Office - Protecting users from phishing attacks and more

S3E6 - Microsoft Defender for Office - Protecting users from phishing attacks and more

Alan and Sam discuss how Microsoft Defender for Office (MDO) can be used to protect users from phishing attacks. Alan will go through all the security benefits, as well some of the education training ...

10 Helmi 202344min