Is Bastion Service needed if I have vpn connection to Azure?

Komoroske, Gina 371 Reputation points
2020-08-07T15:52:21.983+00:00

Hi,
Sorry if this is such a basic question, but I can't seem to find the answer anywhere.

If I have a vpn connection to the vnets in my hub & spoke subscriptions, do I need this Azure Bastion service?

I have recently deployed Azure AD DS, and it would not allow me to create a Windows VM in there until I had this Bastion Service added. Once I added it, I could create the Windows VM, but I can RDP to that Windows VM w/out the Bastion Service due to my vpn connection.

I'd rather not have to pay for this Bastion service if I don't have to. Can I safely delete this?

Thanks in advance for any input. This is in a production environment, we don't have a similar test environment, so it's not something I want to do and find out the hard way that was a bad idea.

Gina

Azure Bastion
Azure Bastion
An Azure service that provides private and fully managed Remote Desktop Protocol (RDP) and Secure Shell (SSH) access to virtual machines.
245 questions
0 comments No comments
{count} votes

Accepted answer
  1. SaiKishor-MSFT 17,216 Reputation points
    2020-08-07T23:09:02.22+00:00

    @Komoroske, Gina
    Thank you for your patience while we were looking into your issue. I understand that you want to know if Bastion service is required or not if you have a VPN connection to Azure VNET.

    Ideally you would not require the Bastion service if you have a VPN since VPN is going to get you connected to your private resources on the VNET securely and privately which is similar to what Bastion also does. However, there are going to be some differences.

    • Using Bastion you can connect to your resources from anywhere i.e., any source machine whereas with a VPN, you can only connect to your resources from the networks specified for the VPN connection.
    • With Azure Bastion you get some added features such as Monitoring/logging of connections.
    • Azure Bastion also includes Azure Active Directory integration

    If you are looking for any of the above features, you would still need to use Bastion, if not, VPN should suffice to be able to connect to the VNET resources securely and privately. I hope this answers your question. If you have any further questions, please let us know and we will be glad to assist anytime. Have a good day!

    2 people found this answer helpful.
    0 comments No comments

1 additional answer

Sort by: Most helpful
  1. Moamen Hany 1,091 Reputation points MVP
    2020-08-08T13:28:27.303+00:00

    This might helps
    https://learn.microsoft.com/answers/answers/62375/view.html

    Please do not forget to "Accept the answer" and Upvote on the post that helps you, this can be beneficial to other community members.
    http://www.moamenhany.com

    3 people found this answer helpful.
    0 comments No comments