azure-bastion

Provide secure browser-based remote access to Azure resources without public IP exposure.

Updated Mar 18, 2026
One-click install
npx skills add https://github.com/mfcollins3/standup --skill azure-bastion-mfcollins3
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: azure-bastion
Source: https://github.com/mfcollins3/standup/tree/main/.github/skills/azure-bastion
Command: npx skills add https://github.com/mfcollins3/standup --skill azure-bastion-mfcollins3

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Azure Bastion provides secure, browser-based remote access to Azure virtual machines and private resources without exposing them to the public internet, reducing attack surface and simplifying access control.

Core Features & Use Cases

  • Secure remote access to VMs, AKS clusters, and private networks without exposing public IPs
  • Architecture guidance for hub/spoke and VNet designs, private-only deployments, and scalable access patterns
  • Security hardening and identity integration (Entra ID, Kerberos where applicable), audit trails, and session monitoring for compliance

Quick Start

Use Azure Bastion to securely access your VMs and private resources through the browser without exposing public IPs.

Frequently Asked Questions about azure-bastion

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I securely access Azure virtual machines without exposing public IPs?

Azure Bastion provides secure browser-based remote access to Azure virtual machines and private resources directly over TLS, eliminating the need to expose public IPs and reducing the overall attack surface.

What is the best way to design hub and spoke network architectures for remote access?

Architecture guidance for hub/spoke and VNet designs with Azure Bastion ensures scalable access patterns and controlled connectivity for private networks. This approach centralizes secure remote login and session management across spoke environments.

Can I integrate Entra ID and Kerberos authentication with Azure Bastion?

Azure Bastion supports identity integration with Entra ID and Kerberos where applicable, enabling security hardening and controlled access. This integration provides audit trails and session monitoring for compliance in private network deployments.

Does Azure Bastion work with AKS clusters and private network deployments?

Azure Bastion enables controlled access to AKS clusters and private network deployments without exposing public IPs. It supports private-only deployments and scalable access patterns for secure remote login and session management.

How do I monitor remote access sessions and maintain audit trails for compliance?

Session monitoring and audit trails for compliance are supported through Azure Bastion's security hardening features. These capabilities track remote login activity and integrate with identity providers to maintain controlled access visibility.