S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Juli 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Avsnitt(155)

S7E6 - ITDR - A must in all organisations

S7E6 - ITDR - A must in all organisations

Alan and Sam discuss the importance of monitoring identities across all systems. Alan goes through wat ITDR is, why it is important and the benefit. Here are a few areas we covered:Why is it important...

20 Mars 40min

S7E5 - February News

S7E5 - February News

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

13 Mars 47min

S7E4 - Unified Tenant Configuration Management APIs

S7E4 - Unified Tenant Configuration Management APIs

Alan and Sam dive into configuration drift with M365 and assessment against security baselines. Here are a few things we covered:What is configuration drift, and why a security baseline is important.M...

27 Feb 56min

S7E03 - January News

S7E03 - January News

This week, Alan and Sam talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these updates that peaked our in...

13 Feb 56min

S7E02 - Entra Account Recovery - Next Level Self Service

S7E02 - Entra Account Recovery - Next Level Self Service

Alan and Sam dive into the next level of self-service for Entra accounts. Alan takes us through what Entra Account Recovery is and how it is different to Self-Service Password Reset. Here are a few th...

30 Jan 49min

S7E01 - December News

S7E01 - December News

This week, Alan and Sam Introduce season 7 and talk about new features and services that have gone into Public Preview or General Available status in the last month. We dive into a couple of these upd...

16 Jan 54min

S6E30 - Season 6 Finale!

S6E30 - Season 6 Finale!

In this episode, we wrap up the season, where we explore our favorite episodes of the season. We also talk about the what happened in 2025, and how the podcast has grown in terms of listenership and e...

12 Dec 20251h 4min

S6E29 - Ignite 2025 Recap - San Fran and what's hot off the press

S6E29 - Ignite 2025 Recap - San Fran and what's hot off the press

This week, Alan and Sam talk about last weeks Microsoft Ignite event and the announcements that came out of it. Alan dives into the in-person experience in San Francisco. They dive into a couple of th...

28 Nov 20251h 3min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
bilar-med-sladd
market-makers
rss-elektrikerpodden
rss-technokratin
skogsforum-podcast
har-vi-akt-till-mars-an
rss-veckans-ai
rss-laddstationen-med-elbilen-i-sverige
developers-mer-an-bara-kod
gubbar-som-tjotar-om-bilar
bli-saker-podden
rss-powerboat-sverige-podcast
hej-bruksbil
rss-milpodden
natets-morka-sida
rss-en-ai-till-kaffet
rss-snacka-om-ai
rss-rapporterat