𝐏𝐮𝐛𝐥𝐢𝐜 𝐏𝐫𝐞𝐯𝐢𝐞𝐰: 𝐄𝐧𝐭𝐫𝐚 𝐈𝐃 𝐬𝐮𝐩𝐩𝐨𝐫𝐭 𝐟𝐨𝐫 𝐑𝐃𝐏 𝐜𝐨𝐧𝐧𝐞𝐜𝐭𝐢𝐨𝐧𝐬 𝐢𝐧 𝐩𝐨𝐫𝐭𝐚𝐥 Azure Bastion provides secure RDP and SSH access to Azure virtual machines directly via the Azure portal or via the native SSH/RDP client already installed on your local computer. Previously, Bastion supported Entra ID authentication (formerly AAD) for RDP and SSH connections via native client and for SSH connections via the portal. Today, we are introducing public preview for Entra ID support for RDP connections in the portal, delivering a more seamless and secure experience for users. Azure Blog : https://lnkd.in/d3EXBXE7
Mohammed Ali’s Post
More Relevant Posts
-
🔒 Azure Bastion: Simplifying the Login Experience The Public Preview for native Entra ID login in Azure Bastion is available! You can now connect to your VMs via RDP directly through the Azure Portal using Bastion — authenticated via Entra ID identities. 🔧 What you need to get started: - The VM must have the AADLoginForWindows extension enabled (either during deployment or added later) - The user or group requires the Virtual Machine Administrator Login or Virtual Machine User Login RBAC role - An existing Azure Bastion deployment in the (or peered) VNet What I especially like is the way it works with RBAC inheritance — assign access at the subscription or resource group level and it automatically applies to all VMs. For admins like me, this makes it much easier to provide quick administrator access to all scoped VMs. Clean and straightforward. On my blog, I compared the previous authentication methods with this new capability. Feel free to check it out: https://lnkd.in/eK7Fms3Z #Azure #EntraID #AzureBastion #CloudSecurity #Microsoft #PublicPreview
To view or add a comment, sign in
-
Azure Bastion Bastion provides secure and seamless RDP and SSH connectivity to your virtual machines directly from the Azure portal using Transport Layer Security (TLS). Key benefits of Azure Bastion:- RDP and SSH directly in Azure portal -Remote session over TLS and firewall traversal for RDP/SSH -No Public IP required on the Azure VM -No hassle managing NSGs -Protection against port scanning Azure Bastion offers four SKU(Stock-Keeping Unit) Plans tiers— "Developer, Basic, Standard, and Premium" *Developer (Free):-Offers basic private RDP/SSH access,No scaling, limited features like no peered network access. *Basic: Cost-effective,same-VNet connections, concurrent sessions, basic features Limited to 2 instances *Standard :- most use cases, offering flexibility and scaling,VNet peering,File Transfer/Copy-Paste,Supports multiple instances (host scaling) for more connections. *Premium: For enterprise needs, highest capability.Standard features plus session recording, high concurrency File Transfer/Copy-Paste #SC-900 #Microsoft Microsoft Learn
To view or add a comment, sign in
-
-
Enforce access policies for teams while maintaining permissions to on-prem apps without code changes. Start managing groups and users in the cloud with Microsoft Entra ID. https://lnkd.in/g7nW-Ksn Strengthen your security posture by moving groups and users from Active Directory to Microsoft Entra. This gives you seamless access for your teams, stronger authentication with MFA and passwordless options, and centralized visibility into risks across your environment. Simplify hybrid identity management by reducing dual overhead, prioritizing key groups, migrating users without disruption, and automating policies with Graph or PowerShell. #IDGovernance #microsoftsecurity #azureactivedirectory #microsoftentraid #entra #microsoft
To view or add a comment, sign in
-
Enforce access policies for teams while maintaining permissions to on-prem apps without code changes. Start managing groups and users in the cloud with Microsoft Entra ID. https://lnkd.in/g7nW-Ksn Strengthen your security posture by moving groups and users from Active Directory to Microsoft Entra. This gives you seamless access for your teams, stronger authentication with MFA and passwordless options, and centralized visibility into risks across your environment. Simplify hybrid identity management by reducing dual overhead, prioritizing key groups, migrating users without disruption, and automating policies with Graph or PowerShell. #IDGovernance #microsoftsecurity #azureactivedirectory #microsoftentraid #entra #microsoft
To view or add a comment, sign in
-
WOW, Microsoft has announced Entra ID support for RDP connections in the Azure portal! 🎉 This new capability simplifies secure remote access by integrating Azure Virtual Machines with Microsoft Entra ID authentication, reducing reliance on local accounts and improving compliance. What do you think about this feature? Will it change how you manage RDP access?
Microsoft MVP Windows Server | Azure Hybrid & Migration, RCDA Trainer, CGI Luminary, Director Consulting Expert
☁️ Azure Bastion + Entra ID: less passwords, more identity 🙂 Azure Bastion just closed an annoying gap: You can now sign in to a Windows VM over Bastion using Microsoft Entra ID (preview) – directly from the Azure portal, no local password needed. 🤯 This is one more step away from jump hosts, shared admin passwords and “whoever owns the RDP file wins”. 🔥 What changed? When you connect via Bastion (RDP), you can choose "Authentication type: Microsoft Entra ID (Preview)" Bastion then uses your Entra identity to sign in to the VM. No local admin account, no saved RDP creds. ⚠️ Keep in mind 1️⃣ A lot of tooling still expects classic RDP credentials 2️⃣ Many environments are hybrid – not every VM is Entra-ready 3️⃣ The feature is preview, so design with that in mind Find all the details here: https://lnkd.in/d3W-JNND If you already tested this at scale: I’m curious what worked well (and what broke) in your environment. 🙂 #AzureBastion #Azure #EntraID
To view or add a comment, sign in
-
-
Migrate your critical AD groups to the cloud to secure access to important apps. See how to make Microsoft Entra the source of authority. https://lnkd.in/g7nW-Ksn Strengthen your security posture by moving groups and users from Active Directory to Microsoft Entra. This gives you seamless access for your teams, stronger authentication with MFA and passwordless options, and centralized visibility into risks across your environment. Simplify hybrid identity management by reducing dual overhead, prioritizing key groups, migrating users without disruption, and automating policies with Graph or PowerShell. #IDGovernance #microsoftsecurity #azureactivedirectory #microsoftentraid #entra #microsoft
To view or add a comment, sign in
-
This is an excellent capability. RDP is an exposure everywhere, and any time it can be controlled via strong identity and MFA, jump on that. This will make cloud server management more secure, we need something similar for on premise
Microsoft MVP 🏆| MCT🔥| Nerdio NVP | Microsoft Azure Certified Solutions Architect Expert | Principal Cloud Architect 👨💼 | Helping you to understand the Microsoft Cloud! | Deepen your knowledge - Follow me! 😁
🚀 New Preview Feature: Entra ID–Based RDP Login to Azure VMs (via Bastion!) Microsoft just introduced a major upgrade to remote administration in Azure — and it’s now available in public preview: You can now authenticate to Windows VMs over RDP using Microsoft Entra ID… directly through Azure Bastion. No local accounts. No passwords. No public IPs. No open port 3389. Just identity-based, Zero Trust–aligned access in the browser. This is a big shift in how secure VM access is done in Azure. --- 🆕 What’s new in this preview? Azure Bastion now supports Microsoft Entra ID authentication for RDP sessions. When the required roles and the AADLoginForWindows extension are in place: Virtual Machine Administrator Login Virtual Machine User Login …Entra ID becomes the default authentication method in Bastion. This unlocks: ✔️ True identity-based RDP access ✔️ Enforcement of Conditional Access policies ✔️ Consistent sign-in experience across Azure resources ✔️ Strong alignment with Zero Trust principles --- 🔐 Why this matters Traditional RDP relies on local accounts or domain credentials and typically requires exposed ports or jump hosts. With this preview: RDP runs over port 443 through Bastion VMs stay fully isolated from the internet No client tools or agents are required Access is managed entirely through Entra ID This is the direction secure cloud management is headed. --- 🛠 What you need to enable it To use the new Entra ID RDP login: A Bastion host deployed in the VM’s VNet (Standard SKU or higher for custom ports) A Windows VM in that VNet The AADLoginForWindows extension enabled One of the required Entra roles assigned Reader permissions on VM, NIC, VNet, and Bastion --- ▶️ How to connect 1. Open your VM in the Azure Portal 2. Select Connect → Bastion 3. Choose RDP + Microsoft Entra ID (Preview) 4. Click Connect — your session launches instantly in the browser No open RDP port. No jump box. No password prompts. Just clean, secure, identity-driven access. --- If you haven’t tested this preview yet, it’s absolutely worth trying. This feature pushes Azure VM administration even further toward a passwordless, Zero Trust, identity-first model — and that’s a win for every cloud environment. #MicrosoftEntra #AzureBastion #AzureSecurity #RDP #ZeroTrust #CloudAdministration #Azure #AVD
To view or add a comment, sign in
-
-
Windows Authentication for Cloud-Native Identities: Modernizing Azure SQL Managed Instance (Preview). Organizations moving to the cloud often face a critical challenge: maintaining seamless authentication for legacy applications without compromising security or user experience. Today, we’re excited to announce support for Windows Authentication for Microsoft Entra principals on Azure SQL Managed Instance, enabling cloud-native identities to authenticate using familiar Windows credentials. Why This Matters Traditionally, Windows Authentication relied on on-premises Active Directory, making it difficult for businesses adopting a cloud-only strategy to preserve existing authentication models. With this new capability: Hybrid Identity Support: Users synchronized between on-premises AD DS and Microsoft Entra ID can continue using a single set of credentials for both environments. Cloud-Only Identity (Preview): Identities that... #techcommunity #azure #microsoft https://lnkd.in/g42wKnFe
To view or add a comment, sign in
-
🚨 Most Common Azure VM Issue Every Azure Administrator Faces 🚨 ❌ Unable to connect to Azure Virtual Machine (RDP / SSH issue) This is one of the top recurring problems in day-to-day Azure administration. 🔍 What usually goes wrong? • Network Security Group (NSG) rules missing or misconfigured • Required ports not opened ° RDP – Port 3389 ° SSH – Port 22 • Public IP not assigned or changed • VM is stopped / deallocated • OS-level firewall blocking access 💼 Real-Time Scenario: A production VM goes live, but the application team reports: “We can’t access the server.” After checking: • VM is running • But NSG doesn’t allow inbound RDP • Once port 3389 is allowed → Access restored ✅ 🛠 How Azure Admins fix it: ✔ Verify VM power state ✔ Check NSG inbound rules ✔ Confirm Public IP association ✔ Use Azure Serial Console / Run Command if locked out ✔ Reset NIC or redeploy VM if required 🎯 Key Learning: 90% of Azure VM access issues are network-related, not VM-related. Understanding NSG + Networking basics is critical for every Azure Administrator. 💡 This issue alone is frequently asked in Azure Administrator interviews. #Azure #AzureVM #AzureAdministrator #CloudComputing #AzureNetworking #LearningAzure #AzureSupport #DevOpsJourney
To view or add a comment, sign in
-
Today's lesson: Why my Azure App Gateway subnet refused to save 😅 I was working on hardening our Azure infrastructure today and ran into a bit of a wall. I tried to apply a strict Network Security Group (NSG) to an Application Gateway v2 subnet, and Azure immediately threw this error: ❌ "Network security group blocks incoming internet traffic on ports 65200 - 65535... This is not permitted." (See the red box in the image below) I initially thought, "Why does it need these high ports open?" What I learned: Unlike the older V1 SKUs, the V2 Gateway requires a constant connection to the Azure Control Plane for health checks and auto-scaling. If you block this "heartbeat," the resource fails or won't provision. The Fix: You don't need to leave it wide open. The secure solution is using the GatewayManager Service Tag. As soon as I added this inbound rule, the subnet saved, and the gateway went healthy. A small configuration detail, but critical to know! #Azure #CloudSecurity #DevOps #LearningEveryday #AzureTips
To view or add a comment, sign in
-