Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallSome links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Azure Bastion lets administrators reach Azure virtual machines over RDP or SSH without exposing the VMs’ management ports or assigning them public IP addresses. Use Developer for limited testing, Basic for straightforward dedicated access, Standard for native RDP/SSH clients and added flexibility, and Premium when private-only deployment or session recording is required. Bastion reduces Internet exposure; it does not replace strong identity controls, network rules, or guest-OS security.
What Azure Bastion protects—and what it does not
Windows administration commonly uses RDP on TCP 3389; Linux administration commonly uses SSH on TCP 22. Exposing either port to the Internet invites scanning and attempts to exploit weak credentials, reused passwords, or software vulnerabilities. A self-managed jump box can provide an intermediate route, but it is another server to patch, harden, monitor, and protect.
Azure Bastion is a Microsoft-managed service deployed into an Azure virtual network. An administrator connects to Bastion through the Azure portal over TLS, then Bastion reaches the target VM over its private network address. The VM does not need a public IP or a Bastion-specific agent. Browser-based RDP and SSH are supported; Standard and Premium also support connections through local RDP and SSH clients. Microsoft’s Bastion overview describes the service and connection models.
Administrator
|
Azure portal or Azure CLI
|
TLS / HTTPS
|
Azure Bastion
|
Private VNet path
|
Windows VM (RDP) or Linux VM (SSH)
Bastion removes the need to expose a target VM’s management port publicly. It does not remove RDP or SSH from the guest, patch the operating system, make weak guest credentials safe, or automatically override NSGs, firewalls, routes, and other network controls. A compromised Azure identity that can use Bastion may still be able to reach administrative targets. Treat Bastion as one part of a defense-in-depth design.
#1 Best Overall
Choose a Bastion SKU for the access you need
| SKU | Best suited to | Key capabilities and limits |
|---|---|---|
| Developer | Development and testing | Free shared infrastructure; one VM connection at a time; selected regions only; no VNet peering. Not intended for production. |
| Basic | Simple dedicated access | Paid, dedicated deployment with fixed two-instance capacity and browser-based RDP/SSH. Supports VNet peering, but not native clients, scaling, private-only deployment, or session recording. |
| Standard | Production teams needing flexibility | Paid; native RDP/SSH clients; host scaling from 2 to 50 instances; shareable links, IP-based connections, custom ports, and file upload/download. |
| Premium | Documented isolation or recording requirements | Includes Standard capabilities, plus session recording and private-only deployment without a public IP on the Bastion resource. |
Feature availability and limits can change; consult the current SKU comparison before selecting a design. Native-client connections require Standard or Premium. Session recording is a Premium feature for supported graphical sessions through the Bastion host; it is not available for native-client sessions. A recording-enabled host records all sessions passing through it, so plan storage access and retention accordingly. See Microsoft’s guidance on session recording.
SKU upgrades are supported, but downgrades are not. A move from Developer to a dedicated SKU requires dedicated infrastructure; depending on the path, you may need to delete and recreate the resource. Check the upgrade guidance before making a change.
Prerequisites and subnet sizing
- An Azure subscription, a virtual network, and a target VM with RDP or SSH enabled internally.
- For a dedicated Basic, Standard, or Premium deployment, a subnet named exactly
AzureBastionSubnet. New dedicated deployments require a subnet of/26or larger. Older deployments created before November 2, 2021 may still operate with/27, but do not use that legacy size for a new deployment. - A Standard static public IP for a public dedicated Bastion deployment. Premium also supports private-only deployment without a public IP on the Bastion resource, but that requires a suitable private access path.
- Network rules, routing, and guest firewall settings that allow the required internal RDP or SSH traffic.
- Azure permissions to view the VM and its network interface and use the Bastion resource, plus valid guest credentials or a supported configured sign-in method.
Developer has separate availability and deployment constraints. For deployment requirements and the current minimum subnet size, refer to the Bastion FAQ and quickstart.
Deploy Bastion in the Azure portal
The portal layout and labels may change; the following is the general deployment path, verified in the research current on August 18, 2026:
- Open the Azure portal and create or select the virtual network that contains the VM.
- For a dedicated deployment, add a subnet named
AzureBastionSubnetwith a prefix of/26or larger. Reserve this subnet for Bastion. - For a public dedicated deployment, create or select a Standard static public IP. Premium private-only deployment is the exception.
- Create an Azure Bastion resource in the same region as the virtual network, choose the SKU, and associate the VNet, subnet, and—where required—public IP.
- Enable only the optional features you need, such as native-client support, file copy, shareable links, IP-based connections, or Premium session recording.
- Wait for deployment to complete and verify that the Bastion resource is healthy.
- Open the VM and select Connect > Bastion. Choose RDP for Windows or SSH for Linux, then authenticate to the guest.
- After confirming the new access path works, remove the VM’s public IP if no other workload or service depends on it. Review any inbound rules that previously allowed Internet RDP or SSH.
The current quickstart notes that the VM must allow the relevant protocol internally—typically TCP 3389 for RDP or TCP 22 for SSH—and that the connection workflow needs reader access to the VM and network interface. See the deployment quickstart for current portal details.
Connect with a native RDP or SSH client
Standard and Premium can broker a connection from a local RDP or SSH client through Bastion. This can fit an operator’s existing workflow, but it changes the audit profile: current session recording does not capture native-client sessions. Enable native-client support on the Bastion resource, install and sign in to a current Azure CLI, and select the intended subscription:
Rank #3
az login
az account list
az account set --subscription "<subscription-id>"
Retrieve the VM resource ID, then start an RDP session:
az vm show
--name "<vm-name>"
--resource-group "<vm-resource-group>"
--show-details
--query id
--output tsv
az network bastion rdp
--name "<bastion-name>"
--resource-group "<bastion-resource-group>"
--target-resource-id "<vm-resource-id>"
For SSH, use the corresponding command and authentication options supported by your installed CLI. Check its current help rather than assuming flags remain unchanged:
az network bastion ssh --help
Microsoft documents the current workflow and requirements in the native-client guide and the Azure CLI reference.
Rank #4
Harden the full access path
Restrict network reachability
Bastion does not bypass network controls. Permit the required connection from the Bastion subnet or another explicitly approved management source; deny Internet-sourced RDP and SSH. Adapt rules to the actual topology instead of copying a generic NSG rule without checking its source and scope. Check:
- NSGs on both relevant subnets and the VM network interface.
- Azure Firewall or network virtual appliance policy.
- User-defined routes and peering routes, including whether traffic is sent to a reachable next hop.
- The VM’s private IP, listening service, and guest OS firewall.
- DNS resolution if the chosen connection method uses a host name.
Control who can connect
Keep Azure authorization separate from guest operating-system authorization. Azure RBAC determines who can view resources, use or modify Bastion, initiate connections, create shareable links, or access recordings. The VM still requires valid Windows or Linux credentials, unless a supported Entra-based sign-in configuration is in place; Azure permission alone does not make someone a guest OS administrator.
Use least-privilege roles, Microsoft Entra MFA, and time-limited elevation or Privileged Identity Management where available. Review privileged access regularly and monitor relevant Azure activity and sign-in records. MFA on the Azure identity path does not replace secure guest credentials.
Best Value
Protect the operating system and audit data
Patch and harden the VM, monitor it, and review its local accounts and administrative groups. If using Premium session recording, configure the required Azure Storage account and protect its permissions. Recordings may contain sensitive administrative activity: set retention, access, encryption, legal-hold, and deletion policies deliberately. A recording-enabled host records all sessions through it, while native-client sessions are not currently recorded.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Hub-and-spoke and private-only designs
A Bastion host in a hub VNet can serve VMs in peered spoke VNets, which may avoid deploying a separate paid host for each workload VNet. Confirm peering, routing, NSGs, firewall rules, and any forwarded-traffic or gateway-transit requirements for the design. Shared reachability should not grant administrators broader access than intended. Separate hosts may be appropriate for regional isolation, regulatory boundaries, or distinct administrative groups. Sharing depends on the network topology and controls; it is not automatic.
In a public Bastion deployment, the Bastion resource has a public IP while target VMs can remain private. Premium’s private-only option removes the public IP from Bastion itself and is intended for organizations with an appropriate private access path, such as VPN or ExpressRoute. It is not the default architecture for every deployment. See the service overview for deployment models.
Recommended Free Tools
Costs and lifecycle
Developer is free, but it is limited to testing and development. Paid Bastion charges begin when the service is deployed, not only when an administrator is connected; outbound data transfer may also be charged. Standard or Premium scaling can affect the deployed instance count and cost. Exact rates depend on region, SKU, instance count, and data transfer, so check the current pricing page or Azure pricing calculator for the planned deployment.
For a lab or temporary environment, include deletion in the cleanup checklist. Also review whether one appropriately secured hub deployment can serve peered spokes, and whether the chosen SKU’s advanced features are genuinely needed. Microsoft provides further Bastion cost-optimization guidance.
Troubleshooting common failures
- Deployment fails or subnet is rejected: Confirm the subnet is named exactly
AzureBastionSubnet, reserved for Bastion, and at least/26for a new dedicated deployment. - The VM is missing from the connection pane: Check same-VNet or correctly peered-VNet placement, the user’s read permissions on the VM and NIC, Bastion health, and whether the SKU supports the requested connection method.
- Connection times out: Check subnet and NIC NSGs, firewalls, routes, peering, guest firewall, RDP/SSH service status, private address, and listening port.
- Native RDP or SSH fails: Verify Standard or Premium, enabled native-client support, current Azure CLI, correct Bastion resource group and VM resource ID, and local endpoint security rules. Confirm the VM permits traffic from Bastion.
- A recording is missing: Verify Premium, recording configuration, supported browser-based graphical connection, storage configuration and permissions, and the operator’s access to the storage data. Native-client sessions are not recorded.
- The bill is higher than expected: Look for a paid host left deployed after testing, an unnecessarily advanced SKU, increased Standard/Premium instance count, data transfer, or redundant regional and spoke deployments.
When another access method makes more sense
| Option | Better fit | Trade-off |
|---|---|---|
| VPN Gateway | Administrators need network-level access to multiple private services, not just selected VMs. | Requires gateway, routing, client, and identity or certificate configuration; it can expose broader network reachability. See Microsoft’s admin access design guidance. |
| Self-managed jump box | Custom tools, domain workflows, or deep network integration are required. | Your team owns patching, hardening, backup, monitoring, scaling, and protection of the host. |
| Azure Virtual Desktop | Users need managed desktops or published applications. | It is an end-user desktop service, not a generic replacement for administering arbitrary VMs. See Azure Virtual Desktop. |
| Azure Serial Console | Emergency recovery or certain boot and networking problems. | It is a recovery path, not a general interactive RDP/SSH substitute. |
| PAM gateway | Approval workflows, credential brokering, command controls, or cross-cloud access are required. | Typically adds licensing, integration, and operational complexity. |
Bastion is a strong fit when the requirement is controlled RDP/SSH administration of Azure VMs without public VM management ports. A VPN is more appropriate for broad private-network access; AVD for user desktops; and a jump box or PAM platform for custom workflows or controls beyond Bastion’s model. For a foundational access design, Bastion should be paired with carefully scoped network rules, strong identity, guest OS security, monitoring, and deliberate cost cleanup.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

