azure-bastion-jit
Installation
SKILL.md
Azure Bastion + Just-In-Time VM Access
The combination of Azure Bastion (managed, browser/native-client jump service) and Defender for Cloud just-in-time (JIT) VM access (time-limited NSG allow-rules for management ports) eliminates the two most common Azure VM compromise paths: internet-exposed RDP/SSH and standing-open management ports.
When to use
Designing or hardening administrative access to Azure IaaS VMs and VMSS. Use this skill for SKU selection, JIT policy, public-IP elimination, and the operational workflow.
Do not use this skill for hybrid VPN/SD-WAN design, ZTNA replacement of VPN
(entra-global-secure-access), or AKS-only access.