About Azure Bastion
Azure Bastion is Microsoft Azure's fully managed service for secure RDP and SSH access to virtual machines through Azure without exposing the virtual machines' RDP or SSH ports directly to the public internet. It supports browser-based access through the Azure portal and, on higher tiers, native client connections and additional administration features. Azure Bastion is best suited to organizations that want a centrally managed administrative access path for Azure virtual machines while reducing reliance on public IP addresses and traditional jump servers. Buyers should compare the Developer, Basic, Standard, and Premium SKUs because deployment model, capacity, networking, client access, recording, and pricing differ substantially.
What is included
Access
| Protocols | Secure RDP and SSH access to Azure virtual machines through Bastion without requiring public RDP or SSH endpoints on the target VMs. |
|---|
SKUs
| Developer, Basic, Standard, Premium | Developer uses shared infrastructure; Basic provides dedicated browser access; Standard adds scaling and advanced connection features; Premium adds recording and private-only deployment. |
|---|
Networking
| Dedicated subnet | Basic, Standard, and Premium dedicated deployments require an AzureBastionSubnet with a /26 or larger prefix. |
|---|
Clients
| Browser and native access | Browser-based RDP and SSH are supported on dedicated tiers, while Standard and Premium add selected native client and file transfer scenarios. |
|---|
Scaling
| Scale units | Basic uses two fixed instances; Standard and Premium can scale from two through 50 instances. |
|---|
Security
| Premium controls | Premium adds session recording and private-only Bastion deployment for stronger privileged-access and network exposure requirements. |
|---|
Pricing
| Hourly dedicated billing | Developer is free; Basic, Standard, and Premium are billed hourly while deployed, with additional scale and outbound data transfer charges where applicable. |
|---|
What is Azure Bastion used for?
Azure Bastion is used to administer Azure virtual machines over RDP or SSH while keeping the target virtual machines on private IP addresses. A user can open a Bastion connection from the Azure portal and work with a Windows or Linux virtual machine without exposing TCP port 3389 or 22 directly to the internet. Microsoft also supports selected native-client connection methods on higher SKUs.
This reduces one common attack surface, but Bastion does not replace identity, endpoint security, operating system hardening, patching, network segmentation, or privileged-access governance. The service provides a managed connection path to the virtual machine. The organization still decides who can connect, which credentials or identities are allowed, what the administrator can do after login, and how activity is monitored.
How do Developer, Basic, Standard, and Premium differ?
Microsoft currently offers four Azure Bastion SKUs. Developer is a free, shared-infrastructure option intended for development and testing. It has limited regional availability and allows one virtual machine connection at a time. Basic uses a dedicated Bastion deployment and provides browser-based RDP and SSH for production scenarios with fixed capacity.
Standard adds features for larger or more advanced administration, including configurable scaling, native client connections, IP-based connections, custom ports, shareable links, and supported file transfer scenarios. Premium includes Standard capabilities and adds session recording plus private-only deployment. Teams should choose from the administrative and security requirements rather than treating Premium only as a capacity upgrade.
How does a dedicated Bastion deployment connect to virtual machines?
For Basic and higher dedicated deployments, Microsoft requires an AzureBastionSubnet with a prefix of /26 or larger. The Bastion resource is deployed into the virtual network and reaches target virtual machines through their private addresses. A public IP is used by normal dedicated Bastion deployments, while Premium supports a private-only deployment option for organizations that do not want a public Bastion endpoint.
Virtual machines do not need their own public IP addresses for Bastion access. This can simplify the network exposure model because administrators no longer need to publish RDP or SSH directly on every server. Bastion can also connect to supported virtual machines in peered virtual networks, which can allow a central administration design instead of deploying a separate access host for every workload network.
When do browser access and native clients make sense?
Browser-based RDP and SSH are available through the Azure portal with Basic and higher dedicated SKUs and are useful when administrators want access without installing or configuring a separate local client. The connection is presented through the browser while Bastion handles the path to the target virtual machine.
Standard and Premium add native client support for selected RDP and SSH scenarios. Native clients can be preferable when an administrator needs familiar desktop client behavior, tunneling, or supported file-transfer workflows. Microsoft documents feature and authentication differences between browser and native connections, so teams should verify their required authentication method, operating system, port, and transfer workflow before choosing a SKU.
How do scaling and concurrent connections work?
Bastion capacity varies by SKU. Basic uses two fixed instances. Standard and Premium allow scale units to be configured from two through 50 instances. Microsoft's current SKU comparison lists approximate maximum concurrent capacity of about 40 RDP or 80 SSH sessions for Basic across its two instances, while a fully scaled Standard or Premium deployment can reach approximately 1,000 RDP or 2,000 SSH sessions under the documented guidance.
These figures are planning guidance rather than a guarantee for every workload. Session behavior, protocol, VM responsiveness, network conditions, file transfer, and other factors can affect real capacity. Organizations with many administrators or automation-heavy access patterns should monitor Bastion utilization and scale deliberately rather than waiting for users to encounter connection pressure.
How does Azure Bastion pricing work?
Azure Bastion pricing depends on the SKU and deployment model rather than one universal monthly price. Microsoft currently lists Bastion Developer as free. Basic, Standard, and Premium dedicated deployments are billed hourly from the time the Bastion resource is deployed until it is deleted, even when no administrator is actively connected. Standard and Premium base pricing includes two instances, with additional configured instances billed separately.
Outbound data transfer can also add cost. Microsoft's current pricing page includes the first 5 GB of outbound data per month at no charge and then applies data-transfer meters beyond that amount. Pricing was checked on August 26, 2026. Buyers should estimate how many Bastion instances need to remain deployed, expected administrative traffic, and whether the environment is temporary or always on rather than comparing only connection count.
What security features are available in Azure Bastion Premium?
Premium is the security-focused Bastion tier for organizations that need more control over privileged sessions. Microsoft documents session recording for Premium. Recordings are stored in a customer-designated Azure Blob Storage container and can provide an additional audit trail for administrative activity. Premium also supports private-only Bastion deployment, which removes the normal public IP requirement for the Bastion host itself.
Session recording should be integrated with an organization's broader privileged-access policy, retention rules, access controls, and incident process. A recording is sensitive administrative data and should not be treated as an ordinary media file. Private-only deployment can reduce public exposure, but teams still need working private connectivity for administrators to reach the Bastion resource.
What are the main limitations and operational tradeoffs?
Dedicated Azure Bastion is an always-provisioned service, so Basic, Standard, and Premium can generate hourly cost even when administrators rarely connect. The dedicated deployment also consumes an AzureBastionSubnet and requires network planning. Developer avoids dedicated infrastructure cost but is limited to supported regions, shared infrastructure, and one connection at a time, which makes it unsuitable for many production environments.
SKU changes also require planning. Microsoft supports upgrading to higher Bastion SKUs but does not support downgrading an existing deployment. Moving backward requires deleting and recreating the Bastion resource. Native-client capabilities, file transfer, authentication methods, private-only deployment, and session recording also depend on the selected SKU and connection method, so requirements should be confirmed before production deployment.
Who should choose something else?
Teams that already have secure private administrative connectivity through a tightly managed VPN, private access platform, or other privileged access system may not need Bastion for every network. Organizations that need access to large fleets outside Azure through one vendor-neutral privileged-access platform may also prefer a broader PAM or remote-access product. Azure Bastion is focused on administrative connectivity to supported Azure virtual machines rather than being a general employee remote desktop platform.
Azure Bastion is strongest when Azure virtual machines need RDP or SSH administration and the organization wants to remove direct public management ports, avoid operating its own jump servers, and keep the access path integrated with Azure networking and governance. Buyers should choose it when that reduction in access infrastructure and public exposure justifies the ongoing service cost and SKU-specific constraints.
Reviews
No reviews yet
Nobody has reviewed Azure Bastion here yet.