🔒 Azure Bastion: Simplifying the Login Experience The Public Preview for native Entra ID login in Azure Bastion is available! You can now connect to your VMs via RDP directly through the Azure Portal using Bastion — authenticated via Entra ID identities. 🔧 What you need to get started: - The VM must have the AADLoginForWindows extension enabled (either during deployment or added later) - The user or group requires the Virtual Machine Administrator Login or Virtual Machine User Login RBAC role - An existing Azure Bastion deployment in the (or peered) VNet What I especially like is the way it works with RBAC inheritance — assign access at the subscription or resource group level and it automatically applies to all VMs. For admins like me, this makes it much easier to provide quick administrator access to all scoped VMs. Clean and straightforward. On my blog, I compared the previous authentication methods with this new capability. Feel free to check it out: https://lnkd.in/eK7Fms3Z #Azure #EntraID #AzureBastion #CloudSecurity #Microsoft #PublicPreview
Native Entra ID login in Azure Bastion Public Preview
More Relevant Posts
-
Migrate your critical AD groups to the cloud to secure access to important apps. See how to make Microsoft Entra the source of authority. https://lnkd.in/g7nW-Ksn Strengthen your security posture by moving groups and users from Active Directory to Microsoft Entra. This gives you seamless access for your teams, stronger authentication with MFA and passwordless options, and centralized visibility into risks across your environment. Simplify hybrid identity management by reducing dual overhead, prioritizing key groups, migrating users without disruption, and automating policies with Graph or PowerShell. #IDGovernance #microsoftsecurity #azureactivedirectory #microsoftentraid #entra #microsoft
To view or add a comment, sign in
-
Migrate your critical AD groups to the cloud to secure access to important apps. See how to make Microsoft Entra the source of authority. https://lnkd.in/g7nW-Ksn Strengthen your security posture by moving groups and users from Active Directory to Microsoft Entra. This gives you seamless access for your teams, stronger authentication with MFA and passwordless options, and centralized visibility into risks across your environment. Simplify hybrid identity management by reducing dual overhead, prioritizing key groups, migrating users without disruption, and automating policies with Graph or PowerShell. #IDGovernance #microsoftsecurity #azureactivedirectory #microsoftentraid #entra #microsoft
To view or add a comment, sign in
-
Enforce access policies for teams while maintaining permissions to on-prem apps without code changes. Start managing groups and users in the cloud with Microsoft Entra ID. https://lnkd.in/g7nW-Ksn Strengthen your security posture by moving groups and users from Active Directory to Microsoft Entra. This gives you seamless access for your teams, stronger authentication with MFA and passwordless options, and centralized visibility into risks across your environment. Simplify hybrid identity management by reducing dual overhead, prioritizing key groups, migrating users without disruption, and automating policies with Graph or PowerShell. #IDGovernance #microsoftsecurity #azureactivedirectory #microsoftentraid #entra #microsoft
To view or add a comment, sign in
-
Enforce access policies for teams while maintaining permissions to on-prem apps without code changes. Start managing groups and users in the cloud with Microsoft Entra ID. https://lnkd.in/g7nW-Ksn Strengthen your security posture by moving groups and users from Active Directory to Microsoft Entra. This gives you seamless access for your teams, stronger authentication with MFA and passwordless options, and centralized visibility into risks across your environment. Simplify hybrid identity management by reducing dual overhead, prioritizing key groups, migrating users without disruption, and automating policies with Graph or PowerShell. #IDGovernance #microsoftsecurity #azureactivedirectory #microsoftentraid #entra #microsoft
To view or add a comment, sign in
-
Azure Bastion Bastion provides secure and seamless RDP and SSH connectivity to your virtual machines directly from the Azure portal using Transport Layer Security (TLS). Key benefits of Azure Bastion:- RDP and SSH directly in Azure portal -Remote session over TLS and firewall traversal for RDP/SSH -No Public IP required on the Azure VM -No hassle managing NSGs -Protection against port scanning Azure Bastion offers four SKU(Stock-Keeping Unit) Plans tiers— "Developer, Basic, Standard, and Premium" *Developer (Free):-Offers basic private RDP/SSH access,No scaling, limited features like no peered network access. *Basic: Cost-effective,same-VNet connections, concurrent sessions, basic features Limited to 2 instances *Standard :- most use cases, offering flexibility and scaling,VNet peering,File Transfer/Copy-Paste,Supports multiple instances (host scaling) for more connections. *Premium: For enterprise needs, highest capability.Standard features plus session recording, high concurrency File Transfer/Copy-Paste #SC-900 #Microsoft Microsoft Learn
To view or add a comment, sign in
-
-
🔐 User Identity vs System Identity (Azure) 👤 𝗨𝘀𝗲𝗿 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆 Used by humans Login with password + MFA Best for portal access & approvals 🤖 𝗦𝘆𝘀𝘁𝗲𝗺 (𝗠𝗮𝗻𝗮𝗴𝗲𝗱) 𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆 Used by Azure resources No password ❌ Best for CI/CD & automation 📌 𝗗𝗲𝘃𝗢𝗽𝘀 𝗥𝘂𝗹𝗲 Humans → User Identity Pipelines & Resources → Managed Identity Less passwords = More security 🔐 #𝗔𝘇𝘂𝗿𝗲#𝗗𝗲𝘃𝗢𝗽𝘀#𝗠𝗮𝗻𝗮𝗴𝗲𝗱𝗜𝗱𝗲𝗻𝘁𝗶𝘁𝘆#𝗔𝘇𝘂𝗿𝗲𝗔𝗗#𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁𝗘𝗻𝘁𝗿𝗮#𝗖𝗹𝗼𝘂𝗱𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆#𝗧𝗲𝗿𝗿𝗮𝗳𝗼𝗿𝗺#𝗖𝗹𝗼𝘂𝗱𝗖𝗼𝗺𝗽𝘂𝘁𝗶𝗻𝗴#𝗟𝗲𝗮𝗿𝗻𝗶𝗻𝗴𝗜𝗻𝗣𝘂𝗯𝗹𝗶𝗰#𝗧𝗲𝗰𝗵𝗦𝗶𝗺𝗽𝗹𝗶𝗳𝗶𝗲𝗱
To view or add a comment, sign in
-
-
This is an excellent capability. RDP is an exposure everywhere, and any time it can be controlled via strong identity and MFA, jump on that. This will make cloud server management more secure, we need something similar for on premise
Microsoft MVP 🏆| MCT🔥| Nerdio NVP | Microsoft Azure Certified Solutions Architect Expert | Principal Cloud Architect 👨💼 | Helping you to understand the Microsoft Cloud! | Deepen your knowledge - Follow me! 😁
🚀 New Preview Feature: Entra ID–Based RDP Login to Azure VMs (via Bastion!) Microsoft just introduced a major upgrade to remote administration in Azure — and it’s now available in public preview: You can now authenticate to Windows VMs over RDP using Microsoft Entra ID… directly through Azure Bastion. No local accounts. No passwords. No public IPs. No open port 3389. Just identity-based, Zero Trust–aligned access in the browser. This is a big shift in how secure VM access is done in Azure. --- 🆕 What’s new in this preview? Azure Bastion now supports Microsoft Entra ID authentication for RDP sessions. When the required roles and the AADLoginForWindows extension are in place: Virtual Machine Administrator Login Virtual Machine User Login …Entra ID becomes the default authentication method in Bastion. This unlocks: ✔️ True identity-based RDP access ✔️ Enforcement of Conditional Access policies ✔️ Consistent sign-in experience across Azure resources ✔️ Strong alignment with Zero Trust principles --- 🔐 Why this matters Traditional RDP relies on local accounts or domain credentials and typically requires exposed ports or jump hosts. With this preview: RDP runs over port 443 through Bastion VMs stay fully isolated from the internet No client tools or agents are required Access is managed entirely through Entra ID This is the direction secure cloud management is headed. --- 🛠 What you need to enable it To use the new Entra ID RDP login: A Bastion host deployed in the VM’s VNet (Standard SKU or higher for custom ports) A Windows VM in that VNet The AADLoginForWindows extension enabled One of the required Entra roles assigned Reader permissions on VM, NIC, VNet, and Bastion --- ▶️ How to connect 1. Open your VM in the Azure Portal 2. Select Connect → Bastion 3. Choose RDP + Microsoft Entra ID (Preview) 4. Click Connect — your session launches instantly in the browser No open RDP port. No jump box. No password prompts. Just clean, secure, identity-driven access. --- If you haven’t tested this preview yet, it’s absolutely worth trying. This feature pushes Azure VM administration even further toward a passwordless, Zero Trust, identity-first model — and that’s a win for every cloud environment. #MicrosoftEntra #AzureBastion #AzureSecurity #RDP #ZeroTrust #CloudAdministration #Azure #AVD
To view or add a comment, sign in
-
-
When the cookie expires but the attack path doesn’t… Andrew Gomez walks through how Azure Seamless SSO provides a legitimate authentication flow to pivot into Entra ID and complete the escalation chain to Global Administrator. Read the full write-up and see how identity attack paths unfold in hybrid environments. https://ghst.ly/44XzgYf
To view or add a comment, sign in
-
AWS quietly dropped "aws login" this before re:Invent and it's a bigger deal than the limited fanfare suggests. Who needs this: Anyone still using IAM Users for CLI/SDK access (yes, you should still migrate to Identity Center, but this helps until you do). What it does: Exchanges your AWS Console session for short-term CLI credentials - no more storing access keys on your machine! Why it matters: Deleting long-term credentials sitting on developer machines reduces credential leak risk, and even helps you bridge to Identity Center migration by updating developer workflows. If you're already using IAM Identity Center for human access (which you should be), then don't worry about this feature. Think of it as harm reduction for IAM Users - not the end goal, but a meaningful security improvement for teams not ready to fully migrate yet. Have you tested it yet? Any gotchas I should cover in a follow-up? #AWSSecurity #CloudSecurity #DevSecOps #IAM
To view or add a comment, sign in
-
Azure Tenant vs Subscription vs Landing Zone (Plain English) These three Azure terms are often used interchangeably — but they mean very different things. Tenant 👉 Your organization’s identity boundary Users, groups, authentication, trust live here. Subscription 👉 Where resources run and costs are tracked Used to separate environments, teams, and billing. Landing Zone 👉 A pre-configured subscription Security, identity, networking, logging, and governance are already in place so teams can deploy safely. Think of it this way: a) Tenant = the company b) Subscription = departments or cost centers c) Landing Zone = a ready-to-use, secured environment If you’ve standardized identity, RBAC, policies, and networking, you already have a landing zone — even if you don’t call it that. #Azure #CloudEngineering #PlatformEngineering #DevSecOps #AzureLandingZone
To view or add a comment, sign in