How to Replace Public RDP With Azure Bastion and Just-in-Time Access
Retrospective: this article looks back at events from May 2019, written in 2026 with the benefit of hindsight.
Exposed RDP and SSH ports are among the most attacked entry points in the cloud. Azure Bastion and just-in-time (JIT) VM access let administrators reach virtual machines without leaving management ports open to the internet.
Option 1: Azure Bastion
Azure Bastion provides browser-based or native-client RDP and SSH to VMs over TLS, without public IP addresses on the VMs.
- Create an
AzureBastionSubnetin the virtual network (or a peered hub network). - Deploy Azure Bastion (Basic or Standard SKU; Standard adds native client support and more features).
- Remove public IPs from VMs and remove inbound RDP/SSH rules from internet-facing NSGs.
- Grant users the minimum roles needed to connect (Reader on the VM, Bastion and NIC).
- Require Entra ID sign-in with MFA through Conditional Access for Azure management.
Option 2: Just-in-time VM access
JIT, part of Microsoft Defender for Cloud (Defender for Servers Plan 2), keeps management ports closed by default and opens them only for an approved user, source IP and time window.
- Enable Defender for Servers on the subscription.
- In Defender for Cloud, enable JIT on target VMs and define allowed ports and maximum request time.
- Users request access through the portal or API; NSG rules are created temporarily and removed afterwards.
Which to use
Bastion removes public exposure entirely; JIT limits exposure in time. Many organizations use Bastion as the default and JIT for exceptions.
Verify
Run an Azure Resource Graph query or check Defender for Cloud recommendations for "Management ports should be closed on your virtual machines." The target is zero.
Don't forget AWS
The equivalent pattern in AWS is Systems Manager Session Manager with no inbound ports open.