{"id":407,"date":"2023-04-16T14:25:50","date_gmt":"2023-04-16T14:25:50","guid":{"rendered":"https:\/\/cyberlorenzo.tech\/?p=407"},"modified":"2023-04-16T14:40:22","modified_gmt":"2023-04-16T14:40:22","slug":"creating-a-azure-bastion-host-using-azure-portal","status":"publish","type":"post","link":"https:\/\/cyberlorenzo.tech\/?p=407","title":{"rendered":"Creating a Azure Bastion Host using Azure Portal"},"content":{"rendered":"\n<p>With Azure Bastion, users can securely access their VMs using a web-based console over SSL-encrypted HTTPS connections, without the need for a public IP address, VPN, or remote desktop client. This simplifies remote access and eliminates the need for a jumpbox or other intermediate hosts, reducing the attack surface and improving security. Azure Bastion integrates with Azure Active Directory (Azure AD) for user authentication and role-based access control (RBAC) for fine-grained access management.<\/p>\n\n\n\n<p>In this short demonstration I will be showing you how this can be set up on my Azure tenant.<\/p>\n\n\n\n<p><strong>All credit goes out to<a href=\"https:\/\/cloudacademy.com\/\" title=\" Cloud Academy\"> Cloud Academy<\/a> for providing this interactive lab<\/strong><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>First let&#8217;s navigate to the Bastions service. Select Bastions<\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-edited.png\" alt=\"\" class=\"wp-image-409\" width=\"453\" height=\"-182\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-edited.png 207w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-edited-150x150.png 150w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-edited-50x50.png 50w\" sizes=\"(max-width: 207px) 100vw, 207px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Once on the Bastions host main page, select create Bastion<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"540\" height=\"165\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-1.png\" alt=\"\" class=\"wp-image-410\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-1.png 540w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-1-300x92.png 300w\" sizes=\"auto, (max-width: 540px) 100vw, 540px\" \/><\/figure>\n\n\n\n<p>On this page, you&#8221;ll need to select the proper subscription, resource group, virtual network that the VMs are hosted on and lastly the tier of Bastion you are using. Be sure to select the proper tier or the Bastion host will not provision. <\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"826\" height=\"953\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-2.png\" alt=\"\" class=\"wp-image-411\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-2.png 826w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-2-260x300.png 260w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-2-768x886.png 768w\" sizes=\"auto, (max-width: 826px) 100vw, 826px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Your final results should look something like this below.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"779\" height=\"959\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-3.png\" alt=\"\" class=\"wp-image-412\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-3.png 779w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-3-244x300.png 244w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-3-768x945.png 768w\" sizes=\"auto, (max-width: 779px) 100vw, 779px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-4-edited.png\" alt=\"\" class=\"wp-image-424\" width=\"683\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-4-edited.png 795w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-4-edited-300x225.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-4-edited-768x576.png 768w\" sizes=\"(max-width: 795px) 100vw, 795px\" \/><\/figure>\n\n\n\n<p><strong>Wait for deployment to finish initializing <\/strong>this could take up to five minutes. <\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"333\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-5-1024x333.png\" alt=\"\" class=\"wp-image-414\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-5-1024x333.png 1024w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-5-300x98.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-5-768x250.png 768w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-5.png 1171w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>After initializing is finished, click connect <\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"447\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-6-1024x447.png\" alt=\"\" class=\"wp-image-415\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-6-1024x447.png 1024w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-6-300x131.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-6-768x335.png 768w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-6-1536x670.png 1536w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-6.png 1668w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><strong>Select Bastion<\/strong>, since this is the method we will be using to connect to the VM. <\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"486\" height=\"189\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-7.png\" alt=\"\" class=\"wp-image-416\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-7.png 486w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-7-300x117.png 300w\" sizes=\"auto, (max-width: 486px) 100vw, 486px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>Enter the credentials <\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"454\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-8-1024x454.png\" alt=\"\" class=\"wp-image-417\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-8-1024x454.png 1024w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-8-300x133.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-8-768x340.png 768w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-8.png 1151w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<p>You are now connected to Bastion over SSL to the virtual machines. <\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"558\" src=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-9-1024x558.png\" alt=\"\" class=\"wp-image-418\" srcset=\"https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-9-1024x558.png 1024w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-9-300x164.png 300w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-9-768x419.png 768w, https:\/\/cyberlorenzo.tech\/wp-content\/uploads\/2023\/04\/image-9.png 1161w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With Azure Bastion, users can securely access their VMs using a web-based console over SSL-encrypted HTTPS connections, without the need for a public IP address, VPN, or remote desktop client. This simplifies remote access and eliminates the need for a jumpbox or other intermediate hosts, reducing the attack surface and improving security. Azure Bastion integrates [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":426,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"saved_in_kubio":false,"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[20],"tags":[21],"class_list":["post-407","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-projects","tag-azure"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/posts\/407","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=407"}],"version-history":[{"count":5,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/posts\/407\/revisions"}],"predecessor-version":[{"id":429,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/posts\/407\/revisions\/429"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=\/wp\/v2\/media\/426"}],"wp:attachment":[{"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=407"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=407"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberlorenzo.tech\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=407"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}