S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S6E12 - Microsoft updates April - new products and features released

S6E12 - Microsoft updates April - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

2 Touko 202553min

S6E11 - Insights into Microsoft Secure 2025

S6E11 - Insights into Microsoft Secure 2025

This week, Alan and Sam talk about new features and services that have been announced at Microsoft Secure 2025 Some of the Microsoft product features and update we covered: Security Copilot Agents Da...

25 Huhti 202554min

S6E10 - Microsoft updates March - new products and features released

S6E10 - Microsoft updates March - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

11 Huhti 202541min

S6E9 - Monitor your OAuth Apps using Defender for Cloud Apps

S6E9 - Monitor your OAuth Apps using Defender for Cloud Apps

This episode Alan and Sam dive into the issues around OAuth apps and understanding how they are being used. Alan discusses the issues organisations are facing when any user could consent to applicatio...

28 Maalis 202538min

S6E8 - Mapping the Threatscape: Security Explorer & Attack Paths in Microsoft Defender for Cloud

S6E8 - Mapping the Threatscape: Security Explorer & Attack Paths in Microsoft Defender for Cloud

In this episode, we dive into two great features of Microsoft Defender for Cloud: Security Explorer and Attack Paths. Join us as we unpack how these tools leverage the Cloud Security Graph to help you...

21 Maalis 202547min

S6E7 - Microsoft updates February - new products and features released

S6E7 - Microsoft updates February - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

14 Maalis 202547min

S6E6 - Protect your servers with Defender for Server

S6E6 - Protect your servers with Defender for Server

Alan and Sam dive into Defender for Cloud's Protective workload for server. Alan goes through the different plans available and the features that are available. Here are a few things we covered: What...

21 Helmi 202549min

S6E5 - Securing Your Data: Exploring Defender for Databases in Microsoft Defender for Cloud

S6E5 - Securing Your Data: Exploring Defender for Databases in Microsoft Defender for Cloud

In this episode, we dive into the world of database security with Microsoft's Defender for Databases. Join us as we explore how this tool within Microsoft Defender for Cloud can transform your approac...

14 Helmi 202551min