S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Heinä 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Jaksot(155)

S5E14 - Azure Backup - utilise Azure to manage and store your backups

S5E14 - Azure Backup - utilise Azure to manage and store your backups

This week Alan and Sam discuss Azure Backup. It is a comprehensive solution offered by Microsoft Azure for safeguarding data across cloud and on-premises environments, providing seamless backup and re...

19 Huhti 202454min

S5E13 - Microsoft Cloud PKI - deploy your user and device certificates from the cloud

S5E13 - Microsoft Cloud PKI - deploy your user and device certificates from the cloud

Alan and Sam discuss Microsoft's new Cloud PKI service, which enables the management and deployment of device and user certificates through Intune. Below are some key points we addressed: What are us...

12 Huhti 202435min

S5E12 -  Microsoft updates April - new products and features released

S5E12 - Microsoft updates April - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

5 Huhti 202434min

S5E11 - Azure Keyvault - A managed key, certificate and secret storage solution

S5E11 - Azure Keyvault - A managed key, certificate and secret storage solution

Alan and Sam discuss Azure Key Vault, it is a centralized cloud service designed for securely storing and managing cryptographic keys, certificates, and secrets used by cloud applications and services...

29 Maalis 202448min

S5E10 - Microsoft Customer Connection Programs (CCP)

S5E10 - Microsoft Customer Connection Programs (CCP)

Alan and Sam talk about the Microsoft Connection Program (CCP). A Community of Technical professional from Customers, to Partners and MVPs that interacts with Microsoft Product groups around new feat...

22 Maalis 202432min

S5E9 - Microsoft updates March - new products and features released

S5E9 - Microsoft updates March - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

8 Maalis 202429min

S5E8 - Azure Event Grid - Managed event routing service for event-driven architectures.

S5E8 - Azure Event Grid - Managed event routing service for event-driven architectures.

Alan and Sam discuss Azure Event Grid. It simplifies event-driven architectures by providing a fully managed service for routing events from various sources to multiple destinations in near real-time,...

1 Maalis 202440min

S5E7 - Vulnerability Management - Reducing risk of compromise in your organisation

S5E7 - Vulnerability Management - Reducing risk of compromise in your organisation

Alan and Sam discuss what vulnerability management is, and why it is important to an organisation. Alan dives into how Microsoft security solutions help identify weaknesses and monitor their remediati...

23 Helmi 202448min