Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For most Azure administrators, Azure Bastion is the managed jump-box option for RDP: it brokers a connection to a VM over its private address, so the target VM does not need a public IP. Use a Point-to-Site (P2S) VPN instead when administrators need broader access to private Azure resources, and use Just-in-Time (JIT) access only when a VM must retain a public IP. Avoid exposing RDP directly to the internet.

What a jump box does in Azure

A jump box is an intermediary used to reach systems on a private network. Rather than opening RDP on every workload VM, an administrator connects through a controlled access point, which then reaches the target over the private network.

Azure Bastion is Microsoft’s managed version of this pattern. It brokers RDP or SSH to VMs in its virtual network and, when networking is configured appropriately, to VMs in peered VNets. The target VM does not need a public IP. Microsoft describes internet-exposed management ports as an unnecessary threat surface: Azure Bastion architecture.

A self-managed jump-box VM is still an option for legacy workflows or specialized tooling that cannot use Bastion. In that design, the jump box—not each target—should be the only internet-facing management endpoint, and it must be hardened and maintained as a critical security boundary.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Choose the access method that matches the job

Option Best fit Exposure and access scope Main trade-off
Azure Bastion Basic or Standard Browser-based RDP, or native-client RDP when supported and enabled Target VM can remain private; access is brokered to selected VMs Managed service with SKU-dependent features and cost
Azure Bastion Premium, private-only deployment Environments that require Bastion itself to have no public IP Private connectivity, typically through VPN or ExpressRoute for clients outside Azure Requires Premium and must be selected at deployment; a regular Bastion deployment cannot be converted in place
Point-to-Site VPN Administrators who need private access to RDP plus databases, storage, or internal apps Client joins the VNet over a VPN, giving broader network reach than an individual brokered session Requires client, gateway, and identity configuration
Just-in-Time VM access A VM that must keep a public IP and needs occasional, approved RDP access Temporarily permits the requested access; new connections are blocked after the window closes It does not terminate connections already established when the window expires
Self-managed jump-box VM Legacy or specialized tools that cannot use Bastion Public access should terminate only on the hardened jump box; it reaches targets privately You own patching, hardening, monitoring, scaling, and credential controls

For JIT, Azure creates temporary allow rules in an NSG or Azure Firewall for the approved access window. Microsoft advises against inbound RDP (TCP 3389) or SSH (TCP 22) rules from 0.0.0.0/0, meaning any internet source. See Microsoft’s JIT access guidance and Bastion guidance.

Deploy Bastion as a private-VM access path

  1. Plan the network. Place Bastion in a dedicated subnet named AzureBastionSubnet in the hub VNet. Use VNet peering when it should reach spoke VMs. Required subnet prefixes and NSG rules depend on the architecture and SKU; follow the applicable Bastion networking requirements.
  2. Keep target VMs private where practical. Remove public IPs from the target VMs when feasible. Bastion is designed to reach them without one.
  3. Select the SKU for the required connection method and controls. Basic supports browser-based RDP. Standard adds capabilities including native-client connections, file transfer, shareable links, IP-based connections, custom inbound ports, and additional host instances. Premium supports private-only deployment and session recording. Confirm current availability and requirements in Microsoft’s SKU and deployment documentation.
  4. Configure identity and permissions. Grant least-privilege Azure RBAC access to the Bastion resource and the target VM, NIC, and VNet as required by the chosen connection flow. Microsoft Entra authentication can evaluate MFA and Conditional Access; some flows require role assignments and VM extensions. Consider time-bound administrative privileges through Privileged Identity Management. See Bastion authentication guidance.
  5. Check NSGs and routing. Confirm required traffic to and from AzureBastionSubnet is not blocked. Microsoft specifically notes that traffic including port 443 from virtual-network sources must be allowed for applicable architectures. Validate the exact rules against the current network requirements.
  6. Connect using the supported client. In the Azure portal, open the VM and select Connect, then choose Bastion and authenticate. Supported configurations also allow native operating-system clients; those options depend on the SKU and configuration. See Microsoft’s RDP connection instructions.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Understand Bastion capacity and private-only constraints

Microsoft’s service table states that Basic has two dedicated host instances and supports 40 concurrent RDP or 80 concurrent SSH sessions; Standard supports 2–50 host instances. These are service capacity figures, not a guarantee of performance for a particular network or workload. Validate the current limits and plan for expected concurrent administrators in Microsoft’s admin-access guidance.

A private-only Premium Bastion deployment is a distinct deployment choice: it must be selected when deploying and cannot be converted in place from a regular Bastion deployment. A client outside Azure needs private connectivity, such as ExpressRoute or VPN, to reach a private-only Bastion. See the Bastion architecture documentation.

There is no universal price, latency, or throughput figure that applies to every deployment. Cost and practical capacity vary with SKU, region, host-instance count, concurrent sessions, VPN gateway choices, and network topology; check the current regional pricing and limits for the architecture you plan to run.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Quick Recap

Secure the whole administrator path

  • Prefer Bastion or P2S VPN over direct public RDP, and remove public IPs from target VMs when feasible.
  • Require MFA for VPN and Entra sign-in, and apply Conditional Access where appropriate.
  • Grant only the Azure roles needed for the session and resource, using time-bound elevation for privileged administration when appropriate.
  • Keep JIT access windows as short as practical and restrict the permitted source IP.
  • For a self-managed jump box, limit who can reach it, tightly control its credentials, allow it to reach only necessary targets, and keep patching, monitoring, and recovery procedures current.
  • Never allow inbound TCP 3389 or TCP 22 from 0.0.0.0/0. Microsoft’s explicit warning is in its developer and administrator access guidance.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.