Azure Bastion

E937582

Azure Bastion is a managed PaaS service from Microsoft that provides secure, seamless RDP and SSH connectivity to virtual machines directly through the Azure portal without exposing them to the public internet.

All labels observed (1)

Label Occurrences
Azure Bastion canonical 2

How this entity was disambiguated

Statements (49)

Predicate Object
instanceOf Platform as a Service ⓘ
managed service ⓘ
network security service ⓘ
accessMethod Azure portal ⓘ
accessScope virtual machines in peered virtual networks ⓘ
virtual machines in the same virtual network ⓘ
avoids public IP exposure on virtual machines ⓘ
billingModel data transfer charges ⓘ
per-hour usage ⓘ
deploymentModel per virtual network ⓘ
designedFor secure remote access to Azure virtual machines ⓘ
developer Microsoft ⓘ
hasFeature IP-based connection to targets ⓘ
Kerberos authentication for Windows VMs ⓘ
file copy over RDP and SSH ⓘ
native client support via Bastion tunnel ⓘ
shareable links for sessions ⓘ
hasTier Basic ⓘ
Standard ⓘ
integratesWith Azure Firewall ⓘ
Azure Network Security Groups ⓘ
Azure Private Link ⓘ
Azure Virtual Network ⓘ
management fully managed by Microsoft ⓘ
networkPlacement virtual network ⓘ
partOf Microsoft Azure ⓘ
linked to: Azure
provides RDP connectivity to virtual machines ⓘ
SSH connectivity to virtual machines ⓘ
regionAvailability multiple Azure regions worldwide ⓘ
requires public IP address for Bastion host ⓘ
subnet named AzureBastionSubnet ⓘ
securityBenefit eliminates need to open RDP ports to internet ⓘ
eliminates need to open SSH ports to internet ⓘ
reduces attack surface of virtual machines ⓘ
securityFeature browser-based session over SSL ⓘ
integration with Azure role-based access control ⓘ
no inbound public connectivity to virtual machines ⓘ
support for Azure AD-based access control via portal ⓘ
supports Azure Virtual Desktop session hosts ⓘ
Azure Virtual Machine Scale Sets ⓘ
Azure Virtual Machines ⓘ
Linux virtual machines ⓘ
Windows virtual machines ⓘ
supportsProtocol RDP ⓘ
SSH ⓘ
TLS ⓘ
useCase jump host replacement ⓘ
secure administration of production workloads ⓘ
uses HTML5-based web client ⓘ

How these facts were elicited

Referenced by (2)

Full triples — surface form annotated when it differs from this entity's canonical label.

Azure portal → supportsService → Azure Bastion ⓘ
Azure Virtual Network → relatedTo → Azure Bastion ⓘ