Skip to main content
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudsoe.bastion-f04db31b-7ce1-4a33-a69d-29cf78722618/image2_cloudsoeazuremarketplace.png

Bastion Host (Jump Box) on Azure

by Cloud SOE

Securely provide contractors, employees and partners access to your cloud resources using a Bastion Host.

Deploy a hardened bastion host, also known as a jump box or jump host, as the single audited entry point into your Azure virtual network (VNet). Built for platform teams, managed service providers and security-conscious administrators who need controlled SSH access to private virtual machines for staff, third-party contractors and automation tooling, with every session logged and every account managed through a defined lifecycle. This image ships with a CIS-aligned Linux operating system, an opinionated OpenSSH configuration, optional TOTP multi-factor authentication and session auditing enabled from first boot.

Bastion or Jump Box: Same Job, Done Properly

Whatever your team calls it, the requirements are the same: one hardened host that sits at the network edge so nothing else has to, strong authentication, complete session records and straightforward onboarding and offboarding for everyone who requires access. Most organisations build this manually from a standard virtual machine image and configuration drift begins immediately. This image starts from a secure, production-ready baseline and is designed to remain easy to maintain.

  • Provide secure access for third-party contractors and vendors without granting Azure identities or direct access to production systems.
  • Meet compliance requirements by providing a designated jump host with session records stored in infrastructure you control.
  • Access Azure Database services, on-premises servers connected through VPN or ExpressRoute, Kubernetes clusters and other private network resources through secure SSH tunnelling.
  • Perform secure SFTP and SCP file transfers through a controlled and audited access point.
  • Standardise administrator access across Azure, AWS and other cloud environments using the same hardened operational model.

What You Get Out of the Box

  • CIS-aligned operating system hardening with an opinionated OpenSSH configuration including key-only authentication, disabled root login, modern ciphers and MACs, and strict forwarding controls.
  • Fail2ban configured for SSH protection with sensible ban policies.
  • UFW firewall allowing SSH access only.
  • Optional TOTP multi-factor authentication for SSH logins.
  • Configurable legal login banners for organisational compliance requirements.
  • No listening services except SSH, minimising the attack surface by design.

Common Use Cases

  • Single Audited Entry Point – Administrators securely access private Azure virtual machines, databases and infrastructure through one controlled and logged gateway.
  • Contractor Access – Create time-limited user accounts with optional MFA and complete session auditing.
  • Compliance and Audit Evidence – Store session logs and access records in Azure Storage for regulatory and security auditing.
  • Database Tunnelling – Securely forward connections to Azure Database for PostgreSQL, MySQL, SQL Managed Instance and other private services without exposing public endpoints.
  • MSP Operations – Deploy one identical bastion host per customer environment using a repeatable, hardened image.

Sizing Guidance

Bastion hosts have modest resource requirements because they primarily handle SSH sessions rather than application workloads. Resource usage increases when session recording, auditing and multiple concurrent users are enabled.

  • Small teams and typical administrative access: Standard_B1ms (1 vCPU, 2 GB RAM)
  • Session recording or multiple concurrent administrators: Standard_B2s (2 vCPU, 4 GB RAM)
  • Larger environments or MSP deployments with high concurrent usage: Standard_D2s_v5 (2 vCPU, 8 GB RAM)
English (United States)
Your Privacy Choices Opt-Out Icon Your Privacy Choices
Consumer Health Privacy Sitemap Contact Us Privacy & Cookies Terms of Use About our ads Manage cookies