S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Episoder(155)

S6E28 - Automate Your Security Baseline with Microsoft’s Open-Source Assessment Tool

S6E28 - Automate Your Security Baseline with Microsoft’s Open-Source Assessment Tool

In this episode, we dive into Microsoft’s Zero Trust Assessment - an open-source, automated tool that scans hundreds of Entra ID and Intune settings against NIST, CISA, CIS, and Microsoft’s own intern...

14 Nov 202531min

S6E27 - Microsoft updates October- new products and features released

S6E27 - Microsoft updates October- new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

7 Nov 202546min

S6E26 - Classify and protect your data using Purview sensitivity labels

S6E26 - Classify and protect your data using Purview sensitivity labels

In this episode, Alan and Sam drive into the importance of classifying data in an organisation. Alan goes through the capability in Purview to tag files and encrypt them. Here are a few things we cove...

31 Okt 202540min

S6E25 - Securing Azure's Core: Microsoft Defender for Resource Manager, Key Vault, and APIs

S6E25 - Securing Azure's Core: Microsoft Defender for Resource Manager, Key Vault, and APIs

In this episode, we dive into three key Cloud Workload Protection Platform (CWPP) offerings within Microsoft Defender for Cloud: Defender for Resource Manager, Defender for Key Vault, and Defender for...

24 Okt 202557min

S6E24 - Microsoft updates September - new products and features released

S6E24 - Microsoft updates September - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

3 Okt 202537min

S6E23 - Unified DLP Platform - Monitor, alert and protect data using Purview DLP

S6E23 - Unified DLP Platform - Monitor, alert and protect data using Purview DLP

Alan and Sam discuss the topic of DLP and how Purview can help audit policy matches and provide preventions. Aland goes though the range of capability and data sources that can be integrated with Purv...

19 Sep 202548min

S6E22 - Microsoft updates August - new products and features released

S6E22 - Microsoft updates August - new products and features released

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

12 Sep 202544min

S6E21 - Protecting Data within Storage Accounts with Microsoft Defender for Storage

S6E21 - Protecting Data within Storage Accounts with Microsoft Defender for Storage

In this episode, we dive into Microsoft Defender for Storage, a key component of Microsoft Defender for Cloud. We break down its features for threat detection and malware scanning, discuss real-world ...

29 Aug 202544min

Populært innen Teknologi

lydartikler-fra-aftenposten
romkapsel
teknisk-sett
energi-og-klima
nasjonal-sikkerhetsmyndighet-nsm
tomprat-med-gunnar-tjomlid
shifter
smart-forklart
rss-ki-praten
rss-impressions-2
elektropodden
hans-petter-og-co
pedagogisk-intelligens
rss-ai-forklart
fornybaren
rss-polypod
rss-alt-som-gar-pa-strom
rss-for-alarmen-gar
rss-bits-and-bytes-for-advokater
rss-startup