S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Episoder(156)

S3E6 - Microsoft Defender for Office - Protecting users from phishing attacks and more

S3E6 - Microsoft Defender for Office - Protecting users from phishing attacks and more

Alan and Sam discuss how Microsoft Defender for Office (MDO) can be used to protect users from phishing attacks. Alan will go through all the security benefits, as well some of the education training ...

10 Feb 202344min

S3E5 - Confidential Computing in Azure - Apply Zero Trust Principles to your IaaS and PaaS Workloads

S3E5 - Confidential Computing in Azure - Apply Zero Trust Principles to your IaaS and PaaS Workloads

Alan and Sam discuss how Confidential Computing can be used to add additional zero trust principle layers to workloads running in Azure. Confidential Computing gives administrators multiple levels to ...

3 Feb 202349min

S3E4 - Privileged Identity Management - Secure Azure and Azure AD

S3E4 - Privileged Identity Management - Secure Azure and Azure AD

Alan and Sam discuss how Microsoft’s Privileged Identity Management (PIM) can be used to improve your identity Security. PIM gives the ability to provide just-in-time access to management roles in Azu...

27 Jan 202344min

S3E3 - Do the same for less - 15 ways to reduce your costs in Azure

S3E3 - Do the same for less - 15 ways to reduce your costs in Azure

Alan and Sam explain 15 ways that you can save costs in Azure…. ssh…. don’t tell Microsoft! If you have workloads in Azure, we hope that you will find some ideas that will enable you to save some mone...

20 Jan 202348min

S3E2 - Azure Virtual Desktop - Providing access to applications and desktops anywhere.

S3E2 - Azure Virtual Desktop - Providing access to applications and desktops anywhere.

Alan and Sam discuss how Azure Virtual Desktop (AVD) can be used provide application and virtual desktops from anywhere. Alan discusses how AVD works, the benefits to organisations, management and the...

13 Jan 202355min

S3E1 - Azure MFA - Securing access to your corporate environment

S3E1 - Azure MFA - Securing access to your corporate environment

Alan and Sam discuss how Azure MFA can be used to improve you security posture. MFA is ubiquitous in 2023, however utilizing MFA in a secure and user first experience can be challenging. In this episo...

6 Jan 202359min

S2E21 - Season Finale! - End of Season Recap

S2E21 - Season Finale! - End of Season Recap

Alan and Sam discuss how Season 2 has gone. They discuss their best episodes, the podcast stats and what the plans are for Season 3 in the new year. We would like to say thank all their listeners of t...

25 Nov 202244min

S2E20 - Microsoft XDR – Create a Holistic View of Your Environment

S2E20 - Microsoft XDR – Create a Holistic View of Your Environment

Alan and Sam discuss Microsoft XDR and why it is now becoming a requirement in organisations. They both take the role of the 'Expert' and explains what XDR is, how it helps reduce security risk. What ...

18 Nov 20221h 10min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
tomprat-med-gunnar-tjomlid
energi-og-klima
nasjonal-sikkerhetsmyndighet-nsm
teknisk-sett
elektropodden
fornybaren
shifter
rss-impressions-2
smart-forklart
teknologi-og-mennesker
rss-ai-forklart
rss-polypod
rss-alt-vi-kan
rss-ki-praten
rss-heis
pedagogisk-intelligens
rss-forenklingspodden
rss-alt-som-gar-pa-strom