How to use Azure Bastion to connect securely to your Azure VMs | Azure Friday

Поделиться
HTML-код
  • Опубликовано: 10 сен 2024
  • Using a bastion host can help limit threats such as port scanning and other types of malware targeting your VMs. Ashish Jain joins Scott Hanselman to show how Azure Bastion gives you secure and seamless RDP and SSH access to your virtual machines. Now you can securely access your VMs over SSL from the Azure portal and without exposing public IP addresses.
    Azure Bastion overview
    aka.ms/azfr/58...
    Azure Bastion docs
    aka.ms/azfr/58...
    Deploy Azure Bastion in an Azure Virtual Network (sample ARM template)
    aka.ms/azfr/58...
    Create a free account (Azure)
    aka.ms/azfr/58...
    #microsoft #microsoftazure

Комментарии • 59

  • @davidlockley9251
    @davidlockley9251 2 года назад +5

    Great explanation guys. Very easy to follow, even 2.5 yrs later :)

  • @ondrapaulicek
    @ondrapaulicek 4 года назад +9

    I really like Azure Fridays, keep up the great work guys!

  • @whereisthehook
    @whereisthehook Год назад

    Does Bastion only support RDP/SSH, or can I also connect to a HTTPS webpage through it?

  • @fnd237
    @fnd237 Год назад

    Can you run this in dual monitor mode? If not, the users won't accept it.

  • @miluskalucich2901
    @miluskalucich2901 4 года назад

    if i pay for the azure bastion service i need to pay for a SSL Certificate for my RDWeb/RDGW Server? or it is enought with the azure bastion?

  • @AsheeshKum
    @AsheeshKum 3 года назад

    Any way we can access from my desktop thru internet to private subnet linux machine VNC server GUI via bastion windows machine... ANY HELP is APPRECIATED.

  • @vishnuks2917
    @vishnuks2917 4 года назад +1

    Good Explanation. Really helpful..

  • @amjadafana
    @amjadafana 3 года назад +1

    When will AAD authentication be supported? Right now only local VM credentials only are supported which does not satisfy most if not all organizations and requirements to use domain trusted connections.

    • @MicrosoftAzure
      @MicrosoftAzure  3 года назад

      Hey there! AAD support is something the team is working towards as part of the roadmap, but we don't have any specific time frame that we can share on its release at this time.

  • @TechLeadEngineer
    @TechLeadEngineer 4 года назад +2

    The main security risk is on the Bastion having to allow SSH and RDP access on its public IP. Is there a way to restrict the Bastion to only be accessible using a private IP? Or perhaps does Azure Private Link an option to access the Bastion resource?

  • @RobertLenior
    @RobertLenior 3 года назад

    Absolutely stunning ! Thanks

  • @nigamonwheels145
    @nigamonwheels145 3 года назад

    Really good and informative

  • @saravansince86
    @saravansince86 4 года назад +1

    We are getting only the CLI interface.What about GUI interface of the server access.

    • @jainashish
      @jainashish 4 года назад

      part of our roadmap.

  • @jpedfonseca
    @jpedfonseca 4 года назад

    Hello can you tell me if Windows VMs from Azure supports hyper-v? If not, there is any change to connect more than one VM in network? Thanks.

    • @MicrosoftAzure
      @MicrosoftAzure  4 года назад +1

      Hey there João! This certainly seems possible. Have a look at the documentation we have available here for more details. msft.it/6058TW1Gg

  • @user-lc8dw6qu7r
    @user-lc8dw6qu7r 2 года назад

    Thanks a lot. It was useful and clear.

  • @manishgoyal5424
    @manishgoyal5424 3 года назад

    Sir pls. Tell me , for ex. In a company 50 employees are how will they work in azure.

  • @sysadmin_dc3398
    @sysadmin_dc3398 2 года назад

    It sounds interesting, might try it sometime.

  • @kamilble2441
    @kamilble2441 2 года назад

    Can you copy paste files as in normal RDP?

  • @darshank
    @darshank 4 года назад +4

    The configuration part is missing.

  • @morzei3005
    @morzei3005 3 года назад

    Indeed you assign static IP to bastion and then if that IP has been compromised, all VMs would be accessible?!

  • @roopeshk.r3219
    @roopeshk.r3219 3 года назад

    Hi, Microsoft ..i'm a Student and i'm using the windows to connect LinuxVm and followed up until last step ...
    Where he types ls ..then how is the VM starts ?

    • @MicrosoftAzure
      @MicrosoftAzure  3 года назад +1

      Hello. To clarify, the Virtual Machine had already been started prior to the demonstration for using Azure Bastion to login. If you need assistance with connecting the VM, please take a look at this guide. msft.it/6054VRWHO

    • @roopeshk.r3219
      @roopeshk.r3219 3 года назад

      @@MicrosoftAzure thank you Ms Azure i have tried that and followed but still facing same issue and i have raised the question..awaiting Azure Bastion expert suggesions on Azure Q/A.

    • @MicrosoftAzure
      @MicrosoftAzure  3 года назад

      Thanks for letting us know. To clarify, are you saying that you have an open support ticket, or have asked this question on a forum?

    • @roopeshk.r3219
      @roopeshk.r3219 3 года назад

      @@MicrosoftAzure Actually i went over to Twitter Azure and they advised me to go with Q/A in forum..but can you tell me how i shd raise support ticket.

    • @MicrosoftAzure
      @MicrosoftAzure  3 года назад

      Thanks for clarifying. Our @AzureSupport team on Twitter is able to route in the same direction. The Q&A forum is another place to find support, if you don't have a support plan. Here's how to file a support ticket, if you have an active plan. msft.it/6058VRtvi

  • @pigrebanto
    @pigrebanto 2 года назад

    does it allow to access to all VMs in the VNET?

    • @MicrosoftAzure
      @MicrosoftAzure  2 года назад +1

      Hi there, Antonio! Azure Bastion manages connectivity to all VMs deployed in the local and peered VNET(s). More info: msft.it/6058Z7Rjk

  • @welltecnologia
    @welltecnologia 2 года назад

    Realy very very good! But, version for connect directly from desktop?

  • @LelandVelasco
    @LelandVelasco 4 года назад +1

    Nice

  • @mehdi5738
    @mehdi5738 2 года назад

    Thanks Folks

  • @rajivgupta9400
    @rajivgupta9400 4 года назад

    can we access Bastion through Azure Ad users

    • @MicrosoftAzure
      @MicrosoftAzure  4 года назад

      Hey there Rajiv! Right now this is not a supported feature, however this is something that is currently on the roadmap! Keep an eye out on the Azure updates page for the latest updates: msft.it/6058TsGHY

  • @bhaskars8209
    @bhaskars8209 3 года назад

    i have a azure ad but forgot the password

  • @bhavana2131983
    @bhavana2131983 4 года назад

    Did not show the How to part

  • @StarsManny
    @StarsManny 2 года назад

    Why is it so quiet?

  • @nigamonwheels145
    @nigamonwheels145 3 года назад

    Wow

  • @ulrichnyamsi6975
    @ulrichnyamsi6975 4 года назад +1

    Need to update this video. As it is, not useful at all.

  • @Adrien_broner
    @Adrien_broner 3 года назад

    Is it free?

  • @Southpaw07
    @Southpaw07 3 года назад +1

    I assume MS going to dump Bastion entirely :). there is no integration with AAD and MFA so not a solution and stone age technology

  • @kishoreahmed
    @kishoreahmed 3 года назад

    It is very costly service and there should be pause option for this service when not in use.

  • @tejbeepat1477
    @tejbeepat1477 4 года назад

    is this feature free?

  • @thearchibaldtuttle
    @thearchibaldtuttle 3 года назад

    Always understood "Bastian", which is a douchebag name IMHO. However, Bastion sounds like a great solution!

  • @LuisBlancoAustin
    @LuisBlancoAustin 4 года назад +1

    They don't even show you how to configure the darn thing.

    • @user-bj4nu4yw5i
      @user-bj4nu4yw5i 4 года назад +1

      Azure documentation website is a goldmine, use it. docs.microsoft.com/en-us/azure/bastion/

  • @ALionLifeOfLiving
    @ALionLifeOfLiving 4 года назад

    no how to

  • @mobracska
    @mobracska 4 года назад

    GRRRRRRRRRRRRR Unable to use keyboard shortcuts ....

  • @lordbagira3626
    @lordbagira3626 4 года назад +1

    jump boxes and public IPs haven't been a thing for a long time in cloud. i thought this was an old video until I saw the date. use a vpn. this video is not a best practice. hell, an authenticated socks proxy is more flexible than this. forcing ops teams to use a web browser for an ssh session? get real.

  • @ahmetgure1506
    @ahmetgure1506 3 года назад +2

    All these are fake solutions. Make a real tool, like Vmware Remote Console!..

  • @James-sc1lz
    @James-sc1lz 3 года назад

    No that impressed. All I need to do is look at AWS and they will have the same thing but from many moons ago. Talk about catch up MS.

  • @jho186
    @jho186 6 месяцев назад

    Can we use Azure bastion to ssh Routers and switches?

    • @MicrosoftAzure
      @MicrosoftAzure  6 месяцев назад

      Hi there! Are your SSH routers and switches reachable from your virtual network at this time?

    • @jho186
      @jho186 6 месяцев назад

      @@MicrosoftAzure yes all in same supernet

    • @MicrosoftAzure
      @MicrosoftAzure  6 месяцев назад

      Thank you so much. Yes, this is supported. To proceed, you'll need an IP based connection to be turned on. Here is some information that may be useful: msft.it/6052c33wY