azure-bastion-jit

Installation
SKILL.md

Azure Bastion + Just-In-Time VM Access

The combination of Azure Bastion (managed, browser/native-client jump service) and Defender for Cloud just-in-time (JIT) VM access (time-limited NSG allow-rules for management ports) eliminates the two most common Azure VM compromise paths: internet-exposed RDP/SSH and standing-open management ports.

When to use

Designing or hardening administrative access to Azure IaaS VMs and VMSS. Use this skill for SKU selection, JIT policy, public-IP elimination, and the operational workflow.

Do not use this skill for hybrid VPN/SD-WAN design, ZTNA replacement of VPN (entra-global-secure-access), or AKS-only access.

Bastion SKUs — pick by feature need

Installs
34
GitHub Stars
173
First Seen
Jun 20, 2026
azure-bastion-jit — vinayaklatthe/microsoft-security-skills