S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S2E10 - Microsoft Entra – Azure AD – Identity Governance

S2E10 - Microsoft Entra – Azure AD – Identity Governance

Alan and Sam discuss how Identity Governance within Azure AD, part of Microsoft's Entra family of identity products can help with your user lifecycle. Alan takes the role of the 'Expert' and explains ...

9 Syys 202238min

S2E9 - Microsoft Entra Permission Management - First Look

S2E9 - Microsoft Entra Permission Management - First Look

Alan and Sam take a first look at Microsoft Entra permissions management. Sam takes the role of the 'Expert' and explains how the product allows you to discover and remediate permissions creep in your...

2 Syys 202244min

S2E8 - Securing Multi-Cloud environments with Microsoft Defender for Cloud

S2E8 - Securing Multi-Cloud environments with Microsoft Defender for Cloud

Alan and Sam discuss how Microsoft Defender for Cloud can help Secure your multi-cloud environments. Alan takes the role of the 'Expert' and explains how you can easily gain visibility of your multi-c...

26 Elo 202251min

S2E7 - Cloud Adoption Framework for Azure

S2E7 - Cloud Adoption Framework for Azure

Alan and Sam take a look at The Cloud Adoption Framework for Azure. Sam takes the role of the 'Expert' and explains his experience with the Cloud Adoption framework and highlights the reasoning about ...

19 Elo 202257min

S2E6 - Microsoft Entra – Securing and Managing Cloud Identities

S2E6 - Microsoft Entra – Securing and Managing Cloud Identities

Alan and Sam discuss how Azure AD, part of the Microsoft Entra family can secure your identity in the cloud. Alan takes the role of the 'Expert' and explains his viewpoint of the product and why we sh...

12 Elo 20221h 5min

S2E5 - Managing Compliance with Azure Policy

S2E5 - Managing Compliance with Azure Policy

Alan and Sam discuss all things Azure Policy, a way to manage Azure compliance at scale. Sam takes the role of the 'Expert' and explains his viewpoint of the product/tooling and why it can help organi...

5 Elo 202257min

S2E4 - Modern Device Management with Microsoft Endpoint Manager

S2E4 - Modern Device Management with Microsoft Endpoint Manager

Alan and Sam discuss how Microsoft Endpoint Manager (MEM) can simplify device management whilst making it easy to secure them. Alan takes the role of the 'Expert' and explains his viewpoint of the pro...

29 Heinä 202252min

S2E3 - Terraform - Deploy your Infrastructure as Code

S2E3 - Terraform - Deploy your Infrastructure as Code

Alan and Sam discuss Terraform, a popular choice in the Infrastructure as Code space. Sam takes the role of 'Expert' and explains his viewpoint of the product and why we should be utilising Terraform ...

22 Heinä 202251min