Opening RDP (Remote Desktop Protocol, port 3389) or SSH (Secure Shell, port 22) to the internet exposes virtual machines (VMs) to constant scanning and password-guessing attacks. Azure Bastion is a managed service that lets you connect to your VMs over RDP and SSH without giving them public IP addresses. You connect to Bastion over TLS (Transport Layer Security) on port 443, from the Azure portal or a native client, and Bastion opens the RDP or SSH session to the VM's private IP inside the virtual network (VNet). The VMs need no public IP and no agent, which shrinks the attack surface dramatically.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.