Azure Bastion and Secure Access

Watch the video to deepen your understanding.
SubscribeComplete the full lesson to earn 25 points — 50 with Pro
Work through each section, then tap “Mark as Complete” on the last one.
✦ Skip the page breaks, the wait, and see fewer ads — read each lesson on a single page with Pro
Lesson: Azure Bastion and Secure Access
Introduction: The Challenge of Remote Management
In traditional cloud network architectures, administrators often open RDP (Remote Desktop Protocol, port 3389) or SSH (Secure Shell, port 22) ports to the public internet to manage virtual machines. This is a critical security vulnerability. Exposing these management ports makes your infrastructure a target for brute-force attacks, port scanning, and credential harvesting.
Azure Bastion is a Platform-as-a-Service (PaaS) offering that provides secure, seamless RDP and SSH connectivity to your virtual machines directly in the Azure portal over SSL. With Azure Bastion, your virtual machines do not require a public IP address, and you no longer need to manage Network Security Group (NSG) rules for remote access.
How Azure Bastion Works
Azure Bastion is deployed within your Virtual Network (VNet) in a specific subnet named AzureBastionSubnet. When an administrator initiates a connection through the Azure Portal, the Bastion service acts as a gateway. It establishes a secure tunnel, proxying the RDP/SSH traffic from the portal directly to the private IP of the target virtual machine.
Key Benefits
- No Public IPs Required: VMs stay isolated from the public internet.
- Integrated Authentication: Uses your existing Azure AD/RBAC permissions.
- Zero-Footprint Client: No need to install agents or software on the target VM or the local machine.
- Integrated Security: Works seamlessly with NSGs and Azure Firewall.
Practical Example: Deploying Azure Bastion
1. Prerequisites
- A Virtual Network (VNet).
- A dedicated subnet named
AzureBastionSubnet(minimum size /26).
2. Deployment via Azure CLI
You can deploy Bastion using the Azure CLI. This is often faster and more repeatable than using the portal.
# Create the dedicated subnet
az network vnet subnet create \
--resource-group MyResourceGroup \
--vnet-name MyVNet \
--name AzureBastionSubnet \
--address-prefixes 10.0.1.0/26
# Create a Public IP for the Bastion service
az network public-ip create \
--resource-group MyResourceGroup \
--name MyBastionIP \
--sku Standard
# Deploy the Bastion resource
az network bastion create \
--name MyBastionHost \
--resource-group MyResourceGroup \
--vnet-name MyVNet \
--public-ip-address MyBastionIP \
--location eastus
3. Connecting to a VM
Once deployed, navigate to your Virtual Machine in the Azure Portal:
- Select Connect > Bastion.
- Enter your credentials (username/password or SSH private key).
- The session will open in a new tab within your browser.
Note: The connection is encrypted via TLS, ensuring that your management traffic is secure from end-to-end.
Best Practices for Secure Access
1. Use the "Standard" SKU
Always prefer the Standard SKU for Bastion in production environments. It includes features like:
- IP-based connection: Connect to VMs via private IP.
- File Transfer: Move files between your local machine and the target VM.
- Shareable Links: Allow users to connect without needing Azure Portal access.
2. Network Security Group (NSG) Configuration
To ensure Bastion functions correctly, your NSG rules must allow specific traffic.
- Inbound: Allow
GatewayManagerandAzureLoadBalancertags to communicate with theAzureBastionSubneton port 443. - Outbound: Allow the
AzureBastionSubnetto communicate with the target VM subnet on ports 3389 (RDP) and 22 (SSH).
3. Least Privilege Access
Use Azure RBAC to control who can access the Bastion service. Assign the Reader role to the VM and the Virtual Machine Administrator Login or Virtual Machine User Login roles to those who need management access.
Common Pitfalls
- Subnet Sizing: The
AzureBastionSubnetmust be named exactly that. If you misspell it or use a different name, the deployment will fail. - Forgetting to remove Public IPs: A common mistake is leaving public IPs on VMs after setting up Bastion. Once Bastion is configured, audit your VMs and remove all public IP addresses to maximize your security posture.
- Ignoring Costs: Azure Bastion is a premium service that incurs an hourly cost. For small dev/test environments, consider shutting down the Bastion resource when not in use, though this is not recommended for production.
- NSG Blocking: If the connection fails, 90% of the time it is due to an overly restrictive NSG rule on the target VM's subnet blocking the internal traffic from the
AzureBastionSubnet.
⚠️ Security Warning
Even with Bastion, ensure your target VMs are hardened. Bastion secures the path to the VM, but it does not protect the VM from internal threats or malware if the VM is improperly configured. Always follow the principle of "Defense in Depth."
Key Takeaways
- Eliminate Public Exposure: Azure Bastion is the gold standard for removing public-facing RDP/SSH ports from your cloud infrastructure.
- Infrastructure as Code: Always automate your Bastion deployment using Terraform, Bicep, or CLI to ensure consistent networking configurations across environments.
- Governance: Use Azure Policy to restrict the creation of Public IPs on VMs, forcing developers to use Bastion for access.
- Operational Efficiency: Bastion removes the need for complex VPN configurations for simple administrative tasks, allowing teams to connect instantly from any secure browser.
- Monitoring: Enable Azure Bastion diagnostic logs to track who is accessing which VMs and when, providing a robust audit trail for compliance.
Reach the last section to complete this lesson and earn points — you're on section 1 of 4.
- Introduction to Azure Monitor
- Azure Monitor Architecture and Data Sources
- Configuring Log Analytics Workspaces
- Designing Log Routing Solutions
- Configuring Diagnostic Settings
- Application Insights for Solution Architects
- Network Watcher and Network Monitoring
- Azure Monitor Alerts and Action Groups
- Workbooks and Custom Dashboards
- Designing a Comprehensive Monitoring Strategy
- Logging and Monitoring Quiz5q
- Microsoft Entra ID for Solution Architects
- Designing Identity Solutions: B2B Collaboration
- Designing Identity Solutions: B2C Scenarios
- Conditional Access Policy Design
- Designing for Multi-Factor Authentication
- Managed Identities for Azure Resources
- Service Principals and App Registrations
- Role-Based Access Control Design
- Privileged Identity Management
- Microsoft Entra ID Protection
- Zero Trust Architecture with Microsoft Entra
- Authentication and Authorization Quiz5q
- Introduction to Azure Governance
- Designing Management Group Hierarchies
- Subscription Strategy Design
- Resource Group Organization Patterns
- Azure Policy Design and Assignment
- Custom Policy Definitions and Initiatives
- Resource Locks and Tagging Strategies
- Azure Blueprints and Landing Zones
- Cost Management and Budget Design
- Cloud Adoption Framework for Governance
- Governance Solutions Quiz5q
- Introduction to Azure Storage
- Storage Account Types and Replication
- Blob Storage Tiers and Lifecycle Management
- Azure Files and Azure NetApp Files
- Azure Managed Disks Design
- Azure Data Lake Storage Gen2
- Cosmos DB Consistency Models
- Cosmos DB Partitioning and Throughput Design
- Cosmos DB API Selection Guide
- Table Storage and Queue Storage Design
- Storage Security and Encryption
- Non-Relational Storage Quiz5q
- Azure SQL Database Service Tiers
- Azure SQL Managed Instance Design
- Azure Database for MySQL and PostgreSQL
- Database Scaling: Vertical and Horizontal
- Read Replicas and Geo-Replication
- Database Security and Auditing Design
- Transparent Data Encryption and Always Encrypted
- Caching with Azure Cache for Redis
- Azure SQL Elastic Pools Design
- Relational Storage Quiz5q
- Azure Data Factory Design Patterns
- Data Integration Pipeline Architecture
- Azure Synapse Analytics Design
- Azure Databricks Integration Patterns
- Azure Stream Analytics for Real-Time Data
- Azure Event Hubs for Data Ingestion
- Data Migration Strategies and Tools
- Azure Purview for Data Governance
- Data Integration Quiz5q
- Introduction to High Availability in Azure
- Availability Zones and Availability Sets
- Azure Load Balancer Design
- Application Gateway and WAF Design
- Azure Front Door and Global Load Balancing
- Azure Traffic Manager Routing Methods
- Multi-Region Architecture Design
- SLA Design and Composite SLAs
- Health Probes and Failover Configuration
- Azure Service Fabric for Stateful HA
- High Availability Quiz5q
- Azure Backup Architecture and Vaults
- Backup Policies for VMs and Databases
- Azure Site Recovery Design
- RTO and RPO Planning Strategies
- Geo-Redundant and Cross-Region Recovery
- Hybrid and On-Premises Backup Solutions
- Resiliency Patterns and Chaos Engineering
- Disaster Recovery Testing and Drills
- Azure Immutable Backup and Soft Delete
- Backup and Disaster Recovery Quiz5q
- Introduction to Azure Compute Options
- Virtual Machine Design and Sizing
- VM Scale Sets and Autoscaling Strategies
- Azure Batch for Large-Scale Workloads
- Azure App Service Plans and Design
- App Service Environments and Isolation
- Azure Container Instances
- Azure Kubernetes Service Architecture
- AKS Networking and Storage Design
- Azure Functions and Serverless Design
- Durable Functions and Orchestration
- Compute Decision Framework
- Azure Virtual Desktop Design
- Compute Solutions Quiz5q
- Microservices Architecture Patterns
- Azure API Management Design
- Azure Service Bus Messaging Design
- Azure Event Grid and Event-Driven Architecture
- Azure Event Hubs for Streaming
- Azure Logic Apps and Integration Workflows
- Azure SignalR and Web PubSub
- Caching Strategies and Azure CDN
- App Configuration and Feature Flags
- Designing for Scalability and Performance
- Azure Container Apps Design
- Application Architecture Quiz5q
- Virtual Network Design and Address Planning
- Subnet Design and Network Segmentation
- Hub-Spoke Network Topology
- Azure Virtual WAN Design
- VPN Gateway Design and Configuration
- ExpressRoute Circuit Design
- Network Security Groups Design
- Azure Firewall and Firewall Manager
- Azure DDoS Protection Design
- Private Endpoints and Private Link
- Azure DNS and DNS Architecture
- Network Performance and Traffic Routing
- Azure Bastion and Secure Access
- Network Solutions Quiz5q
- Azure Migrate Overview and Assessment
- Migration Assessment and Discovery
- Azure Cloud Adoption Framework for Migration
- VM Migration with Azure Migrate
- Database Migration with Azure DMS
- Application Migration to App Service
- Containerizing Applications for Migration
- Migration Cost Planning and Optimization
- Data Box and Offline Migration Methods
- Migrations Quiz5q
Enjoying the courses?
Everything stays free. Pro shows fewer ads, doubles the points you earn on every lesson and quiz so you progress twice as fast, unlocks half of every practice exam — plus full case studies — with the Learn & Exam study modes, and lets you read each lesson on one page.
- ✓ Fewer advertisements
- ✓ 2× points per lesson & quiz
- ✓ 50% of every exam unlocked
- ✓ Learn & Exam modes
- ✓ Distraction-free lessons