SlideShare uma empresa Scribd logo
1 de 29
It’s all about Security!
Let’s get you started with Azure Bastion
That’s what we’re Tolkien about
 Common VM administrative access methods
 Dem time
 What is Azure Bastion?
 How to deploy Bastion
 Dem time
 Roadmap
 Key Takeaways
 Q&A(sk the wizard)
Introduction needed?
Common VM administrative
access methods
Easily manage your VMs running in Azure…
Peering
VNet 2 (10.2.0.0/16)
VNet 1 (10.1.0.0/16)
Internet
ATTACK!
ATTACK!
ATTACK!
NAT through Azure Load Balancer
Peering
VNet 2 (10.2.0.0/16)
VNet 1 (10.1.0.0/16)
Internet
ATTACK!
ATTACK!
ATTACK!
…and you need to prevent breaches?
Resource
group
Gateway subnet
NSG NSG
Web subnet
Virtual network
Virtual
network
gateway
Local network gatewayConnection
On-premises network
Client
High security through Azure VPN/ExpressRoute…
Resource
group
Zone 1
Application
Gateway subnet
Zone 2
Zone 3
NSG NSG NSG
Application
Gateway
NSG
Jumpbox
Management
subnet
Web tier
subnet
Data tier
subnet
DDoS
Protection
Public IP
Public IP
Azure load
balancer
Virtual network
 A controlled entry point in your Azure
environment
 Improves security and reduce attack surface
of your VMs
 Setup inside a separated Virtual Network
(VNet) or subnet (Management VNet or
subnet)
 To allow access from the Internet it uses a
PIP
 From that VM you need to jump to your
other VMs
 Deployed as a very small Linux VM
(tunnel an RDP connection through SSH)
 RDS Gateway as a small VM
(tunnel an RDP connection through SSL)
Jump Box
Just-In-Time VM Access (JIT)
 Used to lock down inbound traffic and to limit the time
management ports (RDP/SSH) are open
 Available on the Standard tier of Azure Security Center
 Three states: Configured, Recommended and No
recommendation
 Only supports Azure Resource Manager VMs
 A user needs to request access to a VM
 All requests can be reviewed in the Activity Log
“One does not simply walk into my VNet.”
DEM
What is Azure Bastion?
“Azure Bastion is a PaaS service that you
provision inside your virtual network. It
provides secure and seamless RDP/SSH
connectivity to your virtual machines
directly in the Azure portal over SSL”
Azure Bastion Overview
 A PaaS service (jumpbox as-a-service) provisioned inside your VNet
 Secure RDP/SSH connectivity directly in the Azure Portal (SSL)
 No Public IP address (PIP) is required on your Azure virtual machines (VMs)
 Does not require any additional software for RDP/SSH access – agentless
 Internally it is a VM scale set
 Protection against port scanning, zero-day exploits and malware targeting
How Azure Bastion works
Keep in mind!
for every VNet
Azure Bastion Use Cases
 No VPN/Expressroute available
 no S2S / P2S
 Jumpbox does not meet the requirements
 Port 3389 is not allowed
 More expensive?
 Hard requirement for HTTPS (port 443)
 No management  Must be PAAS
 RDS Gateway & Jumpbox is out of the option
 Must be easy deployable/removable when needed
 Temporary access to VM (and only VM) with JIT
 no additional services (like VPN)
 no access to other resources in the ResourceGroup/Vnet
€ 0.0591 per GB/moNext 100 TB (50 TB – 150 TB)
€ 0.0700 per GB/moNext 40 TB (10 TB – 50 TB)
Pricing
Azure Bastion Scale Unit (Zone 1 - West Europe) € 116.97/month
Outbound Data
Transfer
First 5 GB / month
5 GB – 10 TB
Free
€ 0.0734 per GB/moPrices differ depending on the regions which correspond to Zone 1 and Zone 2
 Zone 1 – West Europe, East US, South Central US, West US
 Zone 2 – Australia East, Japan East
Next 350 TB (150 TB – 500 TB) € 0.0422 per GB/mo
Over 500 TB / month – Contact Azure Sales
How to deploy Bastion
Deployment steps
 Check if Azure Bastion is available in your Azure public region
 Governance: Use a meaningful naming standard (mc2mc-prod-ba), use
resource tags (VNet: mc2mc-prod-vn) and RBAC
 Create a subnet in your VNet: AzureBastionSubnet (/27 or larger)
Network Security Group (NSG) -> foresee all necessary inbound and
outbound security rules
Azure Firewall -> do not associate the RouteTable
 Bastion requires a static PIP (Standard Public IP SKU)
 Create the Azure Bastion host using the Azure Portal, Azure
PowerShell or an ARM Template
AzureBastionSubnet NSG Inbound Rule
 Allow traffic on port 443 from *
 Allow traffic on ports 443 and 4443 from Service tag
GatewayManager
AzureBastionSubnet NSG Outbound Rules
 Allow traffic on ports 3389 and 22 to your VM subnets
 Allow traffic on port 443 for Service tag AzureCloud
Target VM Subnet(s) Outbound Rule
 Allow traffic on ports 3389 and 22 to Azure Bastion
Subnet IP address range
AzureBastionSubnet Network Security Group
What about JIT VM Access?
To access a VM at least the following roles are required
 Reader role on the VM
 Reader role on the NIC with private IP of the VM
 Reader role on het Azure Bastion resource
Required roles to access a VM
 Copy and paste (only text)
 Full screen view
 Currently no file-transfer support
What can you do in a remote session?
DEM
“My precious, Cloud.”
Future roadmap
 VNet Peering support
 Azure AD SSO with MFA
 Native RDP/SSH clients
 RDP full-session recording for auditing
 Azure AD PIM integration
 Private IP for Bastion host (access through
ExpressRoute or S2S VPN)
Azure Bastion Feedback page
Key Takeaways
PaaS service for RDP/SSH to VMs direclty over SSL
No need for a Public IP Address (PIP)
Needed for every VNet
Harden with NSG and JIT
Keep an eye on your Cloud Sp€nd!
Azure Bastion Documentation
https://docs.microsoft.com/en-us/azure/bastion/
Azure Architecture Center
https://docs.microsoft.com/en-us/azure/architecture/
Manage virtual machine access using just-in-time
https://docs.microsoft.com/en-us/azure/security-center/security-center-just-in-time
RDP to Azure Virtual machines using Azure Bastion
https://www.youtube.com/watch?v=eLjuWG-L57Q&feature=youtu.be
References
Q&A(sk the wizard)

Mais conteúdo relacionado

Mais procurados

07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
carlitocabana
 
Microsoft Azure Active Directory
Microsoft Azure Active DirectoryMicrosoft Azure Active Directory
Microsoft Azure Active Directory
David J Rosenthal
 
Azure Blueprints - 企業で期待される背景と特徴、活用方法
Azure Blueprints - 企業で期待される背景と特徴、活用方法Azure Blueprints - 企業で期待される背景と特徴、活用方法
Azure Blueprints - 企業で期待される背景と特徴、活用方法
Toru Makabe
 

Mais procurados (20)

OpenStack Framework Introduction
OpenStack Framework IntroductionOpenStack Framework Introduction
OpenStack Framework Introduction
 
Microsoft Azure Security Overview
Microsoft Azure Security OverviewMicrosoft Azure Security Overview
Microsoft Azure Security Overview
 
VMware NSX 101: What, Why & How
VMware NSX 101: What, Why & HowVMware NSX 101: What, Why & How
VMware NSX 101: What, Why & How
 
Microsoft SQL Server Database Administration.pptx
Microsoft SQL Server Database Administration.pptxMicrosoft SQL Server Database Administration.pptx
Microsoft SQL Server Database Administration.pptx
 
An Intrudction to OpenStack 2017
An Intrudction to OpenStack 2017An Intrudction to OpenStack 2017
An Intrudction to OpenStack 2017
 
Introduction To OpenStack
Introduction To OpenStackIntroduction To OpenStack
Introduction To OpenStack
 
マイクロサービスのセキュリティ概説
マイクロサービスのセキュリティ概説マイクロサービスのセキュリティ概説
マイクロサービスのセキュリティ概説
 
NSX-T Architecture and Components.pptx
NSX-T Architecture and Components.pptxNSX-T Architecture and Components.pptx
NSX-T Architecture and Components.pptx
 
Fleet and elastic agent
Fleet and elastic agentFleet and elastic agent
Fleet and elastic agent
 
Introduction to Hyper-V
Introduction to Hyper-VIntroduction to Hyper-V
Introduction to Hyper-V
 
Alphorm.com Formation Microsoft Azure (AZ-104) : Administration
Alphorm.com Formation Microsoft Azure (AZ-104) : AdministrationAlphorm.com Formation Microsoft Azure (AZ-104) : Administration
Alphorm.com Formation Microsoft Azure (AZ-104) : Administration
 
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
 
Microsoft Azure Active Directory
Microsoft Azure Active DirectoryMicrosoft Azure Active Directory
Microsoft Azure Active Directory
 
Linux Training For Beginners | Linux Administration Tutorial | Introduction T...
Linux Training For Beginners | Linux Administration Tutorial | Introduction T...Linux Training For Beginners | Linux Administration Tutorial | Introduction T...
Linux Training For Beginners | Linux Administration Tutorial | Introduction T...
 
Microsoft Intune
Microsoft IntuneMicrosoft Intune
Microsoft Intune
 
今さら聞けない!Active Directoryドメインサービス入門
今さら聞けない!Active Directoryドメインサービス入門今さら聞けない!Active Directoryドメインサービス入門
今さら聞けない!Active Directoryドメインサービス入門
 
IoT & Azure (EventHub)
IoT & Azure (EventHub)IoT & Azure (EventHub)
IoT & Azure (EventHub)
 
Alphorm.com : Formation Active directory 2008 R2 (70-640)
Alphorm.com : Formation Active directory 2008 R2 (70-640)Alphorm.com : Formation Active directory 2008 R2 (70-640)
Alphorm.com : Formation Active directory 2008 R2 (70-640)
 
Virtualization with KVM (Kernel-based Virtual Machine)
Virtualization with KVM (Kernel-based Virtual Machine)Virtualization with KVM (Kernel-based Virtual Machine)
Virtualization with KVM (Kernel-based Virtual Machine)
 
Azure Blueprints - 企業で期待される背景と特徴、活用方法
Azure Blueprints - 企業で期待される背景と特徴、活用方法Azure Blueprints - 企業で期待される背景と特徴、活用方法
Azure Blueprints - 企業で期待される背景と特徴、活用方法
 

Semelhante a It's all about Security! Let’s get you started with Azure Bastion

Cisco Router As A Vpn Server
Cisco Router As A Vpn ServerCisco Router As A Vpn Server
Cisco Router As A Vpn Server
mmoizuddin
 

Semelhante a It's all about Security! Let’s get you started with Azure Bastion (20)

Design a Secure Azure IaaS - Lesson Learnt from Government Cloud
Design a Secure Azure IaaS - Lesson Learnt from Government Cloud Design a Secure Azure IaaS - Lesson Learnt from Government Cloud
Design a Secure Azure IaaS - Lesson Learnt from Government Cloud
 
Azure bastion- Remote desktop RDP/SSH in Azure using Bastion Service as (PaaS)
Azure bastion- Remote desktop RDP/SSH in Azure using Bastion Service as (PaaS)Azure bastion- Remote desktop RDP/SSH in Azure using Bastion Service as (PaaS)
Azure bastion- Remote desktop RDP/SSH in Azure using Bastion Service as (PaaS)
 
CCI2018 - Azure Network - Security Best Practices
CCI2018 - Azure Network - Security Best PracticesCCI2018 - Azure Network - Security Best Practices
CCI2018 - Azure Network - Security Best Practices
 
Azure Hub spoke v1.0
Azure Hub spoke v1.0Azure Hub spoke v1.0
Azure Hub spoke v1.0
 
Hub_Spoke_v1.0.pptx
Hub_Spoke_v1.0.pptxHub_Spoke_v1.0.pptx
Hub_Spoke_v1.0.pptx
 
Azure Networking: Innovative Features and Multi-VNet Topologies
Azure Networking: Innovative Features and Multi-VNet TopologiesAzure Networking: Innovative Features and Multi-VNet Topologies
Azure Networking: Innovative Features and Multi-VNet Topologies
 
Architecting Secure Web Systems
Architecting Secure Web SystemsArchitecting Secure Web Systems
Architecting Secure Web Systems
 
Part 03: Azure Virtual Networks – Understanding and Creating Point-to-Site VP...
Part 03: Azure Virtual Networks – Understanding and Creating Point-to-Site VP...Part 03: Azure Virtual Networks – Understanding and Creating Point-to-Site VP...
Part 03: Azure Virtual Networks – Understanding and Creating Point-to-Site VP...
 
Azure Network Security Groups (NSG)
Azure Network Security Groups (NSG)Azure Network Security Groups (NSG)
Azure Network Security Groups (NSG)
 
Azure Service Endpoints vs. Private Links
Azure Service Endpoints vs. Private LinksAzure Service Endpoints vs. Private Links
Azure Service Endpoints vs. Private Links
 
Introducing Azure Bastion
Introducing Azure BastionIntroducing Azure Bastion
Introducing Azure Bastion
 
Azure Network and Infrastructure
Azure Network and InfrastructureAzure Network and Infrastructure
Azure Network and Infrastructure
 
Architecting Advanced Network Security Across VPCs with AWS Transit Gateway
Architecting Advanced Network Security Across VPCs with AWS Transit GatewayArchitecting Advanced Network Security Across VPCs with AWS Transit Gateway
Architecting Advanced Network Security Across VPCs with AWS Transit Gateway
 
Io t security and azure sphere
Io t security and azure sphereIo t security and azure sphere
Io t security and azure sphere
 
Server-side Intelligent Switching using Windows Azure
Server-side Intelligent Switching using Windows AzureServer-side Intelligent Switching using Windows Azure
Server-side Intelligent Switching using Windows Azure
 
Configuring asa site to-site vp ns
Configuring asa site to-site vp nsConfiguring asa site to-site vp ns
Configuring asa site to-site vp ns
 
Cld006 azure v_net___express_route_最新情報
Cld006 azure v_net___express_route_最新情報Cld006 azure v_net___express_route_最新情報
Cld006 azure v_net___express_route_最新情報
 
Packet Capture on AWS
Packet Capture on AWSPacket Capture on AWS
Packet Capture on AWS
 
Cozystack: Free PaaS platform and framework for building clouds
Cozystack: Free PaaS platform and framework for building cloudsCozystack: Free PaaS platform and framework for building clouds
Cozystack: Free PaaS platform and framework for building clouds
 
Cisco Router As A Vpn Server
Cisco Router As A Vpn ServerCisco Router As A Vpn Server
Cisco Router As A Vpn Server
 

Último

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 

Último (20)

DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 

It's all about Security! Let’s get you started with Azure Bastion

  • 1. It’s all about Security! Let’s get you started with Azure Bastion
  • 2. That’s what we’re Tolkien about  Common VM administrative access methods  Dem time  What is Azure Bastion?  How to deploy Bastion  Dem time  Roadmap  Key Takeaways  Q&A(sk the wizard)
  • 5. Easily manage your VMs running in Azure… Peering VNet 2 (10.2.0.0/16) VNet 1 (10.1.0.0/16) Internet ATTACK! ATTACK! ATTACK!
  • 6. NAT through Azure Load Balancer Peering VNet 2 (10.2.0.0/16) VNet 1 (10.1.0.0/16) Internet ATTACK! ATTACK! ATTACK!
  • 7. …and you need to prevent breaches?
  • 8. Resource group Gateway subnet NSG NSG Web subnet Virtual network Virtual network gateway Local network gatewayConnection On-premises network Client High security through Azure VPN/ExpressRoute…
  • 9. Resource group Zone 1 Application Gateway subnet Zone 2 Zone 3 NSG NSG NSG Application Gateway NSG Jumpbox Management subnet Web tier subnet Data tier subnet DDoS Protection Public IP Public IP Azure load balancer Virtual network  A controlled entry point in your Azure environment  Improves security and reduce attack surface of your VMs  Setup inside a separated Virtual Network (VNet) or subnet (Management VNet or subnet)  To allow access from the Internet it uses a PIP  From that VM you need to jump to your other VMs  Deployed as a very small Linux VM (tunnel an RDP connection through SSH)  RDS Gateway as a small VM (tunnel an RDP connection through SSL) Jump Box
  • 10. Just-In-Time VM Access (JIT)  Used to lock down inbound traffic and to limit the time management ports (RDP/SSH) are open  Available on the Standard tier of Azure Security Center  Three states: Configured, Recommended and No recommendation  Only supports Azure Resource Manager VMs  A user needs to request access to a VM  All requests can be reviewed in the Activity Log
  • 11. “One does not simply walk into my VNet.” DEM
  • 12. What is Azure Bastion?
  • 13. “Azure Bastion is a PaaS service that you provision inside your virtual network. It provides secure and seamless RDP/SSH connectivity to your virtual machines directly in the Azure portal over SSL”
  • 14. Azure Bastion Overview  A PaaS service (jumpbox as-a-service) provisioned inside your VNet  Secure RDP/SSH connectivity directly in the Azure Portal (SSL)  No Public IP address (PIP) is required on your Azure virtual machines (VMs)  Does not require any additional software for RDP/SSH access – agentless  Internally it is a VM scale set  Protection against port scanning, zero-day exploits and malware targeting
  • 16. Keep in mind! for every VNet
  • 17. Azure Bastion Use Cases  No VPN/Expressroute available  no S2S / P2S  Jumpbox does not meet the requirements  Port 3389 is not allowed  More expensive?  Hard requirement for HTTPS (port 443)  No management  Must be PAAS  RDS Gateway & Jumpbox is out of the option  Must be easy deployable/removable when needed  Temporary access to VM (and only VM) with JIT  no additional services (like VPN)  no access to other resources in the ResourceGroup/Vnet
  • 18. € 0.0591 per GB/moNext 100 TB (50 TB – 150 TB) € 0.0700 per GB/moNext 40 TB (10 TB – 50 TB) Pricing Azure Bastion Scale Unit (Zone 1 - West Europe) € 116.97/month Outbound Data Transfer First 5 GB / month 5 GB – 10 TB Free € 0.0734 per GB/moPrices differ depending on the regions which correspond to Zone 1 and Zone 2  Zone 1 – West Europe, East US, South Central US, West US  Zone 2 – Australia East, Japan East Next 350 TB (150 TB – 500 TB) € 0.0422 per GB/mo Over 500 TB / month – Contact Azure Sales
  • 19. How to deploy Bastion
  • 20. Deployment steps  Check if Azure Bastion is available in your Azure public region  Governance: Use a meaningful naming standard (mc2mc-prod-ba), use resource tags (VNet: mc2mc-prod-vn) and RBAC  Create a subnet in your VNet: AzureBastionSubnet (/27 or larger) Network Security Group (NSG) -> foresee all necessary inbound and outbound security rules Azure Firewall -> do not associate the RouteTable  Bastion requires a static PIP (Standard Public IP SKU)  Create the Azure Bastion host using the Azure Portal, Azure PowerShell or an ARM Template
  • 21. AzureBastionSubnet NSG Inbound Rule  Allow traffic on port 443 from *  Allow traffic on ports 443 and 4443 from Service tag GatewayManager AzureBastionSubnet NSG Outbound Rules  Allow traffic on ports 3389 and 22 to your VM subnets  Allow traffic on port 443 for Service tag AzureCloud Target VM Subnet(s) Outbound Rule  Allow traffic on ports 3389 and 22 to Azure Bastion Subnet IP address range AzureBastionSubnet Network Security Group
  • 22. What about JIT VM Access?
  • 23. To access a VM at least the following roles are required  Reader role on the VM  Reader role on the NIC with private IP of the VM  Reader role on het Azure Bastion resource Required roles to access a VM
  • 24.  Copy and paste (only text)  Full screen view  Currently no file-transfer support What can you do in a remote session?
  • 26. Future roadmap  VNet Peering support  Azure AD SSO with MFA  Native RDP/SSH clients  RDP full-session recording for auditing  Azure AD PIM integration  Private IP for Bastion host (access through ExpressRoute or S2S VPN) Azure Bastion Feedback page
  • 27. Key Takeaways PaaS service for RDP/SSH to VMs direclty over SSL No need for a Public IP Address (PIP) Needed for every VNet Harden with NSG and JIT Keep an eye on your Cloud Sp€nd!
  • 28. Azure Bastion Documentation https://docs.microsoft.com/en-us/azure/bastion/ Azure Architecture Center https://docs.microsoft.com/en-us/azure/architecture/ Manage virtual machine access using just-in-time https://docs.microsoft.com/en-us/azure/security-center/security-center-just-in-time RDP to Azure Virtual machines using Azure Bastion https://www.youtube.com/watch?v=eLjuWG-L57Q&feature=youtu.be References