S6E18 - Securing Access to Your Virtual Machines with Azure Bastion
Let's Talk Azure!18 Juli 2025

S6E18 - Securing Access to Your Virtual Machines with Azure Bastion

In this episode, we explore Azure Bastion, Microsoft’s fully managed Platform-as-a-Service (PaaS) solution designed to provide secure Remote Desktop Protocol (RDP) and Secure Shell Protocol (SSH) access to Azure virtual machines (VMs). This Q&A-style episode dives deep into how Azure Bastion strengthens cloud security by eliminating the need for public IP addresses on VMs, reducing exposure to external threats like port scanning or protocol exploits. Alan poses critical questions about Azure Bastion’s functionality, architecture, deployment options, and integration with Azure’s security ecosystem, while our consultant delivers actionable insights tailored for IT administrators, security professionals, and cloud architects.

We cover:

  • Core Functionality: How Azure Bastion enables secure, clientless RDP/SSH access via the Azure portal or native clients, protecting VMs by removing public IP dependencies.
  • Architecture Breakdown: The role of the dedicated AzureBastionSubnet, private IP connectivity, and TLS-based sessions, including support for zonal deployments for high availability.
  • SKU Options: A detailed look at Developer, Basic, Standard, and Premium SKUs, highlighting features like session recording, Private Link integration, and host scaling for different organizational needs.
  • Security Integrations: How Azure Bastion works with Microsoft Defender for Cloud, Microsoft Entra ID (with MFA and conditional access), Azure Private Link, and Azure Monitor to enforce Zero Trust principles and ensure compliance.
  • Real-World Use Cases: Practical scenarios, such as secure admin access for global teams, compliance for regulated industries (e.g., healthcare, finance), and streamlined dev/test environments, with examples like Metinvest’s global VM management.
  • Best Practices: Tips for deployment (e.g., subnet sizing, VNet peering), security (e.g., MFA, NSG configuration), monitoring (e.g., Azure Monitor logs), and cost management (e.g., SKU selection, scaling strategies).
  • Limitations and Considerations: Key factors like SKU constraints, regional availability for zonal deployments, performance considerations, and cost implications, with guidance on mitigating challenges.

What did you think of this episode? Give us some feedback via our contact form, Or leave us a voice message in the bottom right corner of our site.

Read transcript

Avsnitt(156)

S2E3 - Terraform - Deploy your Infrastructure as Code

S2E3 - Terraform - Deploy your Infrastructure as Code

Alan and Sam discuss Terraform, a popular choice in the Infrastructure as Code space. Sam takes the role of 'Expert' and explains his viewpoint of the product and why we should be utilising Terraform ...

22 Juli 202251min

S2E2 - Microsoft Entra - First Look

S2E2 - Microsoft Entra - First Look

Alan and Sam discuss all things Entra, a 'new' product offering by Microsoft. Alan takes the role of the 'Expert' and explains his initial viewpoint of the product and why we should all be excited abo...

15 Juli 202246min

S2E1 - Aaaaaaaand We're Back!

S2E1 - Aaaaaaaand We're Back!

In this episode, Alan and Sam discuss the Podcast, what's happened and what we are planning over the next season. Also with a big a apology that we have been absent for over a year. What did you think...

4 Juli 202220min

S1E9 - Infrastructure as Code – ARM Templates

S1E9 - Infrastructure as Code – ARM Templates

In this episode Alan and Sam deep dive into Infrastructure as Code and specifically ARM Templates inside of Azure. We talk about what infrastructure as code is and how it can improve your infrastructu...

1 Nov 202044min

S1E8 - Microsoft Ignite Recap

S1E8 - Microsoft Ignite Recap

In this episode Alan and Sam talk recap all the latest news from Ignite! Even though Ignite was virtual this year, Microsoft announced a load of new features and products around Azure/Office 365. You ...

30 Sep 202051min

S1E7 - Cloud vs On Premises

S1E7 - Cloud vs On Premises

In this episode Alan and Sam talk around the move from on premises to the cloud. Why are companies doing this? What are the cost advantages? Is the cloud more reliable? When does on premises make more...

16 Sep 202046min

S1E6 - Zero Trust

S1E6 - Zero Trust

This episode we have a deep dive looking at Zero Trust, the principles, components and tools that enable us to be more secure in the modern workplace. Alan lives and breathes security day to day, so h...

26 Aug 202044min

S1E5 - Security Center

S1E5 - Security Center

In this episode we look at Azure Security Center and the features and benefits that it can bring to a range of different teams working with assets in Azure. We highlight some of the vast range of feat...

4 Aug 20201h 1min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
market-makers
skogsforum-podcast
rss-elektrikerpodden
rss-powerboat-sverige-podcast
bilar-med-sladd
rss-veckans-ai
developers-mer-an-bara-kod
rss-uppgang-och-fall
rss-laddstationen-med-elbilen-i-sverige
rss-technokratin
gubbar-som-tjotar-om-bilar
rss-fabriken-2
bli-saker-podden
hej-bruksbil
har-vi-akt-till-mars-an
natets-morka-sida
teknikveckan
rss-snacka-om-ai