S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S5E22 - Data API builder - Rapidly build CRUD APIs

S5E22 - Data API builder - Rapidly build CRUD APIs

This week Alan and Sam discuss Data API builder. It is a powerful tool designed to streamline the process of creating and deploying APIs for data-driven applications. It facilitates the rapid developm...

14 Kesä 202443min

S5E21 - Microsoft updates May - new products and features released

S5E21 - Microsoft updates May - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

7 Kesä 202446min

S5E20 - MDE Device Discovery - Find those unknown devices

S5E20 - MDE Device Discovery - Find those unknown devices

Alan and Sam talk about why it is important to monitor your network for connected devices. Alan runs us through the benefits of doing it with Microsoft Defender for Endpoint. Here are a few areas we c...

31 Touko 202444min

S5E19 - Azure AI Search - Cloud-based, AI-enhanced search for applications.

S5E19 - Azure AI Search - Cloud-based, AI-enhanced search for applications.

This week Alan and Sam discuss Azure AI Search. It is a robust, cloud-based search service provided by Microsoft that leverages artificial intelligence to enhance search functionalities within applica...

24 Touko 202449min

S5E18 - Managing macOS with Microsoft

S5E18 - Managing macOS with Microsoft

Alan and Sam discuss the management of macOS and how it is a little different to other operating systems. Alan guides through what can be configured and the reasons why. Here are a few things we cover...

17 Touko 202446min

S5E17 - Azure Data Box - move big data to Azure efficiently

S5E17 - Azure Data Box - move big data to Azure efficiently

This week Alan and Sam discuss Azure Data Box. It is a ruggedised appliance designed to simplify the process of transferring large volumes of data to Azure cloud storage, offering high-speed data tran...

10 Touko 202439min

S5E16 - Microsoft updates April - new products and features released

S5E16 - Microsoft updates April - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

3 Touko 202430min

S5E15 - Entra Global Secure Access - An Identity-Centric Security Service Edge

S5E15 - Entra Global Secure Access - An Identity-Centric Security Service Edge

Alan and Sam discuss Microsoft Entra Global Secure Access. A identity-centric Security Service Edge (SSE) solution that helps secure user's internet and on-premises access. Here are a few things we co...

26 Huhti 202452min