Concept and mechanism
Administering a VM without directly publishing SSH or RDP reduces an exposure surface. Azure Bastion supports VM access through its private IP but does not remove authentication, permissions, or network requirements. Features such as session recording depend on the chosen tier. JIT manages temporary port access subject to supported controls and existing rules. When the window ends, restoring rules does not guarantee termination of established connections. If operational policy requires no sessions after a given time, the runbook must include session management and verification in addition to controlling new connections.
Guided application
In private AKS, the API server is accessed through an internal network; the deployment agent needs resolution and a path to that control plane. More application replicas or a cluster-admin role do not repair a network timeout. Disk protection addresses another requirement. Disk Storage SSE alone does not cover caches and temporary disks in the same way as encryption at host. For new VMs, assess support and coverage for that mechanism. Current documentation announces ADE retirement on September15,2028, so design should account for migration and copies depending on that technology. Do not assume private or encrypted covers every service layer.
JIT ends at21:00, but the maintenance session continues. Verify and apply authorized closure if required, preserving intervention evidence.
Common pitfalls
Bastion treated as no authentication; private API treated as isolation of every pod; SSE treated as cache coverage.
Related topics: Identity and temporary privilege · Network boundaries and private access · Data protection and use
Define the required effect at each layer and validate it with the correct consumer.
Reference: Defender for Servers JIT access and expiry · AZ-500 objectives2026-01-22; retired2026-08-31