S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S3E5 - Confidential Computing in Azure - Apply Zero Trust Principles to your IaaS and PaaS Workloads

S3E5 - Confidential Computing in Azure - Apply Zero Trust Principles to your IaaS and PaaS Workloads

Alan and Sam discuss how Confidential Computing can be used to add additional zero trust principle layers to workloads running in Azure. Confidential Computing gives administrators multiple levels to ...

3 Helmi 202349min

S3E4 - Privileged Identity Management - Secure Azure and Azure AD

S3E4 - Privileged Identity Management - Secure Azure and Azure AD

Alan and Sam discuss how Microsoft’s Privileged Identity Management (PIM) can be used to improve your identity Security. PIM gives the ability to provide just-in-time access to management roles in Azu...

27 Tammi 202344min

S3E3 - Do the same for less - 15 ways to reduce your costs in Azure

S3E3 - Do the same for less - 15 ways to reduce your costs in Azure

Alan and Sam explain 15 ways that you can save costs in Azure…. ssh…. don’t tell Microsoft! If you have workloads in Azure, we hope that you will find some ideas that will enable you to save some mone...

20 Tammi 202348min

S3E2 - Azure Virtual Desktop - Providing access to applications and desktops anywhere.

S3E2 - Azure Virtual Desktop - Providing access to applications and desktops anywhere.

Alan and Sam discuss how Azure Virtual Desktop (AVD) can be used provide application and virtual desktops from anywhere. Alan discusses how AVD works, the benefits to organisations, management and the...

13 Tammi 202355min

S3E1 - Azure MFA - Securing access to your corporate environment

S3E1 - Azure MFA - Securing access to your corporate environment

Alan and Sam discuss how Azure MFA can be used to improve you security posture. MFA is ubiquitous in 2023, however utilizing MFA in a secure and user first experience can be challenging. In this episo...

6 Tammi 202359min

S2E21 - Season Finale! - End of Season Recap

S2E21 - Season Finale! - End of Season Recap

Alan and Sam discuss how Season 2 has gone. They discuss their best episodes, the podcast stats and what the plans are for Season 3 in the new year. We would like to say thank all their listeners of t...

25 Marras 202244min

S2E20 - Microsoft XDR – Create a Holistic View of Your Environment

S2E20 - Microsoft XDR – Create a Holistic View of Your Environment

Alan and Sam discuss Microsoft XDR and why it is now becoming a requirement in organisations. They both take the role of the 'Expert' and explains what XDR is, how it helps reduce security risk. What ...

18 Marras 20221h 10min

S2E19 - Microsoft Power Platform – Power to the Users

S2E19 - Microsoft Power Platform – Power to the Users

Alan and Sam discuss Microsoft Power Platform and why it is a useful tool have in an organisation. Alan takes the role of the 'Expert' and explains how you can easily build internal apps, automate pro...

11 Marras 20221h 11min