Skip to main content

Azure Bastion

A fully managed PaaS service that provides secure RDP and SSH connectivity to VMs directly through the Azure Portal over TLS, without exposing the VM's public IP or opening inbound ports to the internet.

Azure Bastion

Bastion sits inside your VNet and proxies RDP/SSH sessions through the browser, so target VMs never need a public IP or an open management port.

Why It Matters in Production

Razorpay removed all public IPs from its production VMs and routes every admin session through Azure Bastion, eliminating an entire class of "exposed RDP" attack that regularly shows up in cloud security scans.

Bash
az network bastion create --name razorpay-prod-bastion \
--public-ip-address bastion-pip --resource-group razorpay-prod-rg \
--vnet-name razorpay-prod-vnet --location centralindia
Tip

Bastion requires its own dedicated subnet named exactly AzureBastionSubnet with a minimum /26 address range.

Frequently Asked Questions

How does Azure Bastion avoid the security risk of a traditional jump box?

A traditional jump box needs its own public IP with SSH/RDP ports open to the internet, making it a constant target for brute-force and scanning attacks. Azure Bastion is provisioned inside your VNet and accessed entirely through the Azure Portal over TLS on port 443 — target VMs never need a public IP or an open inbound port at all, since Bastion handles the connection over Azure's private backbone.

What's a common mistake when adopting Azure Bastion?

Deploying it but leaving NSG rules that still allow direct SSH/RDP from the internet to VMs, defeating the purpose — Bastion only helps if it's the sole path in. Also, Bastion is billed per-hour regardless of usage plus data processed, so leaving it provisioned in a rarely-used dev subscription can be a quiet ongoing cost that teams forget to check against actual usage.