Secure your VM access with
Azure Bastion
The VM Administrative
Access Problem Space
You need to manage your VMs running in Azure…
…and you need to prevent breaches
Common VM
administrative access
methods
Hybrid cloud
VMs with public IP addresses (PIPs)
NAT through Azure Load Balancer
Jump box
Azure Bastion
Azure Bastion – Managed jump box
Azure Portal
Remote Protocol
(RDP, SSH)
TLS
Internet
Port 443
AzureBastionSubnet
TLS
Virtual Network
Azure VM
Azure VM
Azure VM
Target VM Subnet(s)
Azure Bastion
Private IP
Port: 3389, 22
“Gateway Manager”
Bastion controller
JIT VM Access
JIT VM Access
Bastion Support for VNet Peering(Preview)
Azure Bastion roadmap
currently in preview
Azure bastion

Azure bastion