S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S6E4 - Microsoft updates January - new products and features released

S6E4 - Microsoft updates January - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

7 Helmi 202548min

S6E3 - How can CSPM help fortify your defences

S6E3 - How can CSPM help fortify your defences

Alan and Sam discuss why it is important to have Cloud Security Posture Management (CSPM) solutions in place. Alan goes through the general benefits of CSPM, enhancements since its release and dives ...

31 Tammi 202549min

S6E2 - Securing the API Gateway: A Deep Dive into Microsoft Defender for APIs

S6E2 - Securing the API Gateway: A Deep Dive into Microsoft Defender for APIs

In this episode, we explore the critical world of API security through the lens of Microsoft Defender for APIs. Join us as we discuss how this tool can safeguard your APIs in increasingly cloud-centri...

24 Tammi 20251h 5min

S6E1 - Microsoft updates December - new products and features released

S6E1 - Microsoft updates December - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

17 Tammi 202538min

S5E42 - Season 5 Finale!

S5E42 - Season 5 Finale!

In this episode, we wrap up the season, where we explore our favourite episode of the season. We also talk about the what happened in 2024, and how the podcast has grown in terms of listenership and e...

13 Joulu 20241h

S5E41 - Manage your patching processes using Azure Update Manager and Hotpatch

S5E41 - Manage your patching processes using Azure Update Manager and Hotpatch

Alan and Sam discuss the process organisations go through to manage patches. Alan dives into some of the tooling and covers: Why is patch management important and what are some of the issues you can ...

6 Joulu 202436min

S5E40 - Microsoft updates November - New features and updates from Ignite 2024

S5E40 - Microsoft updates November - New features and updates from Ignite 2024

This week, Alan and Sam talk about the Microsoft Ignite event and the announcements that came out of it. Alan dives into the in-person experience in Chicago. They dive into a couple of the announcemen...

29 Marras 202457min

S5E39 - Navigating DevOps Security Challenges with Microsoft Defender for Cloud

S5E39 - Navigating DevOps Security Challenges with Microsoft Defender for Cloud

In this episode, we tackle the critical challenges of securing DevOps environments in today’s fast-paced, cloud-centric landscape. With cyber threats evolving at an unprecedented rate, safeguarding yo...

15 Marras 202441min