What is Azure Bastion?
Azure Bastion is a fully managed PaaS service that provides secure RDP and SSH connectivity to virtual machines over TLS, either through the Azure portal in the browser or via the native SSH/RDP client already installed on your local computer. VMs need no public IP address, agent, or special client software.
The service is deployed directly in your virtual network and protects VMs from port scanning and brute-force attacks from the internet.
Core Features
- Four SKU tiers: Developer, Basic, Standard, and Premium with different feature sets
- Browser-based RDP and SSH access without client installation (all SKUs)
- Native client support for local RDP/SSH clients including Microsoft Entra ID authentication (Standard and Premium)
- TLS-encrypted connections over port 443
- Shareable links for time-limited access without Azure portal sign-in (Standard and Premium)
- Session recording for compliance requirements and private-only deployment without a public IP (Premium)
Typical Use Cases
Zero Trust network: Eliminating public IP addresses on VMs. Administrators access resources exclusively through the Azure portal or native clients, without VPN or jump hosts.
Compliance requirements: Access can be authenticated via Microsoft Entra ID and logged; with the Premium SKU, sessions can additionally be recorded.
Temporary access: With shareable links (Standard/Premium), external service providers can get time-limited access to specific VMs without needing their own Azure permissions.
Development and test environments: The free Developer SKU uses shared infrastructure for single VM connections and is well suited for dev/test scenarios.
Benefits
- No management of jump hosts or VPN infrastructure
- Reduced attack surface by eliminating public IPs
- Centralized logging of all access
- Works over standard HTTPS without firewall adjustments
- Scales from free dev/test usage up to Premium requirements with session recording
Frequently Asked Questions
What does Azure Bastion cost?
Azure Bastion is billed hourly depending on the selected SKU (Basic, Standard, Premium), plus outbound data transfer charges; billing starts once Bastion is deployed, regardless of actual usage. The Developer SKU is free but supports only one VM connection at a time and is available only in select regions.
What is the difference between the SKUs?
Basic provides the dedicated core functionality for production environments. Standard adds scaling, native client support, shareable links, IP-based connections, custom ports, and file transfer. Premium adds session recording and private-only deployment without a public IP. Developer is a free tier on shared infrastructure for dev/test.
Can I use existing RDP/SSH clients?
Yes, with the Standard or Premium SKU you can use local RDP and SSH clients, including authentication via Microsoft Entra ID. The connection is routed through the Bastion tunnel.
Does Azure Bastion work with peered VNets?
Yes, using virtual network peering a single Bastion deployment can serve multiple virtual networks, so you don’t need a separate Bastion instance in every VNet.
Integration with innFactory
As a Microsoft Solutions Partner, innFactory supports you with Azure Bastion: network architecture, Zero Trust implementation, and access control.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Azure (official documentation). This page does not represent an offer by Azure.
