Azure Bastion
E937582
Azure Bastion is a managed PaaS service from Microsoft that provides secure, seamless RDP and SSH connectivity to virtual machines directly through the Azure portal without exposing them to the public internet.
Statements (49)
| Predicate | Object |
|---|---|
| instanceOf |
Platform as a Service
ⓘ
managed service ⓘ network security service ⓘ |
| accessMethod | Azure portal NERFINISHED ⓘ |
| accessScope |
virtual machines in peered virtual networks
ⓘ
virtual machines in the same virtual network ⓘ |
| avoids | public IP exposure on virtual machines ⓘ |
| billingModel |
data transfer charges
ⓘ
per-hour usage ⓘ |
| deploymentModel | per virtual network ⓘ |
| designedFor | secure remote access to Azure virtual machines ⓘ |
| developer | Microsoft ⓘ |
| hasFeature |
IP-based connection to targets
ⓘ
Kerberos authentication for Windows VMs ⓘ file copy over RDP and SSH ⓘ native client support via Bastion tunnel ⓘ shareable links for sessions ⓘ |
| hasTier |
Basic
ⓘ
Standard ⓘ |
| integratesWith |
Azure Firewall
NERFINISHED
ⓘ
Azure Network Security Groups NERFINISHED ⓘ Azure Private Link NERFINISHED ⓘ Azure Virtual Network NERFINISHED ⓘ |
| management | fully managed by Microsoft ⓘ |
| networkPlacement | virtual network ⓘ |
| partOf | Microsoft Azure NERFINISHED ⓘ |
| provides |
RDP connectivity to virtual machines
ⓘ
SSH connectivity to virtual machines ⓘ |
| regionAvailability | multiple Azure regions worldwide ⓘ |
| requires |
public IP address for Bastion host
ⓘ
subnet named AzureBastionSubnet ⓘ |
| securityBenefit |
eliminates need to open RDP ports to internet
ⓘ
eliminates need to open SSH ports to internet ⓘ reduces attack surface of virtual machines ⓘ |
| securityFeature |
browser-based session over SSL
ⓘ
integration with Azure role-based access control ⓘ no inbound public connectivity to virtual machines ⓘ support for Azure AD-based access control via portal ⓘ |
| supports |
Azure Virtual Desktop session hosts
ⓘ
Azure Virtual Machine Scale Sets NERFINISHED ⓘ Azure Virtual Machines NERFINISHED ⓘ Linux virtual machines ⓘ Windows virtual machines ⓘ |
| supportsProtocol |
RDP
ⓘ
SSH ⓘ TLS NERFINISHED ⓘ |
| useCase |
jump host replacement
ⓘ
secure administration of production workloads ⓘ |
| uses | HTML5-based web client ⓘ |
Referenced by (1)
Full triples — surface form annotated when it differs from this entity's canonical label.