Official agent skill

Azure Bastion

by MicrosoftDocs in MicrosoftDocs/Agent-Skills

Expert knowledge for Azure Bastion development including best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and integrations & coding patterns.

OfficialCC-BY-4.0Auto-check passedDevelopment

Install Azure Bastion

skills CLI
$ npx skills add MicrosoftDocs/Agent-Skills --skill azure-bastion -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MicrosoftDocs/Agent-Skills azure-bastion --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MicrosoftDocs/Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-bastion .claude/skills/azure-bastion && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-bastion
GitHub stars
777
Token cost
~1.8k tokens
SKILL.md length
534 words
Files
1
Skills in repo
149
Repo updated
First seen
Licence
CC-BY-4.0

At a glance

Expert knowledge for Azure Bastion development including best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and integrations & coding patterns.

  • Configuring Bastion for AKS private clusters
  • SKILL.md covers How to Use This Skill and Category Index
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Hub/spoke VNets

What it does

Azure Bastion is an agent skill from MicrosoftDocs/Agent-Skills, published by the product's own GitHub organization. Expert knowledge for Azure Bastion development including best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and integrations & coding patterns. Use when configuring Bastion for AKS private clusters, VM scale sets, Entra ID auth, hub/spoke VNets, or IP-based cross-VNet access, and other Azure Bastion related development tasks. Not for Azure Virtual Network (use azure-virtual-network), Azure Virtual Network Manager (use azure-virtual-network-manager), Azure…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires network access. Uses mcpmicrosoftdocs:microsoftdocsfetch or fetchwebpage to retrieve documentation.

It sits in Development, covering Design patterns. It works with Microsoft Azure and Microsoft Entra ID. The repository describes itself as: Curated Agent Skills for Microsoft & Azure – giving AI coding assistants structured, real-time expertise from Microsoft Learn docs. The licence is CC-BY-4.0.

When your agent uses it

  • Configuring Bastion for AKS private clusters
  • Hub/spoke VNets
  • IP-based cross-VNet access
  • Other Azure Bastion related development tasks

Example prompts

  • “/azure-bastion”

Requirements

  • Compatibility (from SKILL.md): Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.

What it can do on your machine

Read from SKILL.md and the folder at commit ba74e8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.

    From compatibility in the SKILL.md frontmatter.

Context cost

Azure Bastion loads about 1.8k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 534 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MicrosoftDocs/Agent-Skills at commit ba74e8f, republished under its CC-BY-4.0 licence (© MicrosoftDocs). 534 words, ~1,751 tokens.

Download SKILL.mdSave it as .claude/skills/azure-bastion/SKILL.md (or your agent's skills folder).
name
azure-bastion
description
Expert knowledge for Azure Bastion development including best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and integrations & coding patterns. Use when configuring Bastion for AKS private clusters, VM scale sets, Entra ID auth, hub/spoke VNets, or IP-based cross-VNet access, and other Azure Bastion related development tasks. Not for Azure Virtual Network (use azure-virtual-network), Azure Virtual Network Manager (use azure-virtual-network-manager), Azure VPN Gateway (use azure-vpn-gateway), Azure Firewall (use azure-firewall).
compatibility
Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation.
metadata.generated_at
2026-08-16
metadata.generator
docs2skills/1.0.0

Azure Bastion Skill

This skill provides expert guidance for Azure Bastion. Covers best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and integrations & coding patterns. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
Best PracticesL35-L39Guidance on reducing Azure Bastion costs through sizing, scaling, and usage patterns while maintaining secure remote access and compliance best practices.
Decision MakingL40-L46Guidance on choosing and upgrading Bastion SKU tiers and using IP-based Bastion connections across VNets, subscriptions, and environments.
Architecture & Design PatternsL47-L53Architectural options and patterns for Azure Bastion: hub/spoke and peered VNets, private-only deployments, network/topology design, and deployment guidance for secure remote access.
Limits & QuotasL54-L58Configuring Azure Bastion host scaling limits, including max concurrent RDP/SSH sessions, connection thresholds, and how to adjust or plan capacity for different SKUs.
SecurityL59-L65Configuring secure Azure Bastion access: Entra ID auth setup, NSG rule hardening, and applying security benchmark best practices for Bastion deployments.
ConfigurationL66-L77Configuring Bastion settings, Kerberos, monitoring/diagnostics, metrics/logs, native client access, session monitoring/recording, and shareable links for secure remote access.
Integrations & Coding PatternsL78-L85Using Bastion with AKS private clusters, VM scale sets, and native Windows/Linux clients, including RDP/SSH setup and file transfer workflows through Bastion.
Best Practices
TopicURL
Optimize Azure Bastion costs without reducing securityhttps://learn.microsoft.com/en-us/azure/bastion/cost-optimization
Show full SKILL.md (209 more words)Show less
Decision Making
TopicURL
Select the appropriate Azure Bastion SKU tierhttps://learn.microsoft.com/en-us/azure/bastion/bastion-sku-comparison
Use Azure Bastion IP-based connections across environmentshttps://learn.microsoft.com/en-us/azure/bastion/connect-ip-address
View and upgrade Azure Bastion SKU tiers safelyhttps://learn.microsoft.com/en-us/azure/bastion/upgrade-sku
Architecture & Design Patterns
TopicURL
Understand Azure Bastion deployment architectureshttps://learn.microsoft.com/en-us/azure/bastion/design-architecture
Design and deploy private-only Azure Bastionhttps://learn.microsoft.com/en-us/azure/bastion/private-only-deployment
Use Azure Bastion with VNet peering architectureshttps://learn.microsoft.com/en-us/azure/bastion/vnet-peering
Limits & Quotas
TopicURL
Configure Azure Bastion host scaling limitshttps://learn.microsoft.com/en-us/azure/bastion/configure-host-scaling
Security
TopicURL
Configure Entra ID authentication for Azure Bastionhttps://learn.microsoft.com/en-us/azure/bastion/bastion-entra-id-authentication
Configure Azure Bastion NSG rules for secure accesshttps://learn.microsoft.com/en-us/azure/bastion/bastion-nsg
Secure Azure Bastion deployments using benchmark guidancehttps://learn.microsoft.com/en-us/azure/bastion/secure-bastion
Configuration
TopicURL
Understand and manage Azure Bastion configuration settingshttps://learn.microsoft.com/en-us/azure/bastion/configuration-settings
Configure Kerberos authentication for Azure Bastionhttps://learn.microsoft.com/en-us/azure/bastion/kerberos-authentication-portal
Configure monitoring and diagnostics for Azure Bastionhttps://learn.microsoft.com/en-us/azure/bastion/monitor-bastion
Reference Azure Bastion monitoring metrics and logshttps://learn.microsoft.com/en-us/azure/bastion/monitor-bastion-reference
Configure Azure Bastion for native client accesshttps://learn.microsoft.com/en-us/azure/bastion/native-client
Monitor and manage active Azure Bastion sessionshttps://learn.microsoft.com/en-us/azure/bastion/session-monitoring
Configure and use Azure Bastion session recordinghttps://learn.microsoft.com/en-us/azure/bastion/session-recording
Create and manage Azure Bastion shareable linkshttps://learn.microsoft.com/en-us/azure/bastion/shareable-link
Integrations & Coding Patterns

© MicrosoftDocs, CC-BY-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-bastion of MicrosoftDocs/Agent-Skills.

Open the folder on GitHubat commit ba74e8f

Compare with similar skills

Azure Bastion next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Bastion compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Bastion this skillMicrosoftDocs/Agent-Skills777—~1.8kAutomated safety check: PassCC-BY-4.0
Azure Storage Loaderrajbos/ai-engineering-fluency116—~3kAutomated safety check: PassMIT
Entra Agent Idmicrosoft/GitHub-Copilot-for-Azure2553 repos~4kAutomated safety check: PassMIT
Azure App Service Securityvinayaklatthe/microsoft-security-skills175—~1.9kAutomated safety check: PassMIT
Azure Identity Dotnetmicrosoft/skills3.1k6 repos~2.5kAutomated safety check: PassMIT
Azure Postgres TSmicrosoft/skills3.1k5 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • Azure Storage Loader

    rajbos/ai-engineering-fluency

    Load token usage data from Azure Table Storage for faster iteration and analysis in chat conversations

    116 GitHub stars~3k tokensUpdated today
    DevelopmentAuto-check passed
  • Entra Agent Id

    microsoft/GitHub-Copilot-for-Azure

    Official

    Provision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token exchange (fmipath, OBO, cross-tenant)…

    255 GitHub starsUsed in 3 repos~4k tokens
    Backend & APIsAuto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    DevOps & CloudAuto-check passed
  • Azure Identity Dotnet

    microsoft/skills

    Official

    Azure Identity library for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 6 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Azure Postgres TS

    microsoft/skills

    Official

    Connect to Azure Database for PostgreSQL Flexible Server from Node.js/TypeScript using the pg (node-postgres) package.

    3.1k GitHub starsUsed in 5 repos~3.3k tokens
    DatabasesAuto-check passed

More from MicrosoftDocs/Agent-Skills

All 149 skills in this repo
  • Azure Personalizer

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Personalizer development including troubleshooting, decision making, security, configuration, and integrations & coding patterns.

    777 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Azure Architecture Advisor

    MicrosoftDocs/Agent-Skills

    Official

    Guides Azure solution design by category, from reference architectures and design patterns to technology choices and migrations, fetching current Microsoft Learn pages over the network.

    777 GitHub stars~15k tokensUpdated 2 days ago
    Auto-check passed
  • Azure Advisor Guidance

    MicrosoftDocs/Agent-Skills

    Official

    Reference guidance for Azure Advisor work: recommendations, alerts and digests, workbooks, RBAC access and sovereign-cloud limits, fetched from Microsoft Learn.

    777 GitHub stars~1.7k tokensUpdated 2 days ago
    Auto-check passed
  • Azure AI Vision Reference

    MicrosoftDocs/Agent-Skills

    Official

    Looks up Microsoft Learn guidance for Azure AI Vision: Image Analysis, Read OCR containers, smart-crop thumbnails, background removal and video frame analysis, plus limits and deployment.

    777 GitHub stars~1.6k tokensUpdated 2 days ago
    Auto-check passed
  • Azure Analysis Services

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Analysis Services development including troubleshooting.

    777 GitHub stars~608 tokensUpdated 2 days ago
    Auto-check passed
  • Azure Anomaly Detector

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure AI Anomaly Detector development including troubleshooting, best practices, limits & quotas, configuration, and deployment.

    777 GitHub stars~1.1k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Azure Bastion

What does Azure Bastion do?

Expert knowledge for Azure Bastion development including best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and integrations & coding patterns. Azure Bastion is an agent skill from MicrosoftDocs/Agent-Skills, published by the product's own GitHub organization. Expert knowledge for Azure Bastion development including best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, and integrations & coding patterns.

When should I use Azure Bastion?

Azure Bastion fits situations like: configuring Bastion for AKS private clusters; hub/spoke VNets; IP-based cross-VNet access; other Azure Bastion related development tasks.

How do I install Azure Bastion in Claude Code?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-bastion -a claude-code`. Or copy the skill folder (skills/azure-bastion in MicrosoftDocs/Agent-Skills) into .claude/skills/azure-bastion in your project. Claude Code loads it when a task matches its description.

How do I install Azure Bastion in Codex?

Run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-bastion -a codex`. Or copy the skill folder (skills/azure-bastion in MicrosoftDocs/Agent-Skills) into .agents/skills/azure-bastion in your project. Codex loads it when a task matches its description.

Can I use Azure Bastion in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MicrosoftDocs/Agent-Skills --skill azure-bastion -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-bastion, .gemini/skills/azure-bastion, .github/skills/azure-bastion and .opencode/skills/azure-bastion in your project.

What does Azure Bastion need to run?

SKILL.md names no scripts, command-line tools or credentials: Azure Bastion is instructions for the agent only. Compatibility (from SKILL.md): Requires network access. Uses mcp_microsoftdocs:microsoft_docs_fetch or fetch_webpage to retrieve documentation..

Does Azure Bastion access the network?

SKILL.md names 2 domains. As links in the text: learn.microsoft.com and github.com. This is read from the text; nothing was executed.

Is Azure Bastion safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Bastion use?

Azure Bastion is published under the CC-BY-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Bastion use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Bastion?

Skills that share tags, products or a category with Azure Bastion: Azure Storage Loader (rajbos/ai-engineering-fluency, 116 stars), Entra Agent Id (microsoft/GitHub-Copilot-for-Azure, 255 stars), Azure App Service Security (vinayaklatthe/microsoft-security-skills, 175 stars) and Azure Identity Dotnet (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Bastion?

MicrosoftDocs (a GitHub organization, an official publisher) maintains it in MicrosoftDocs/Agent-Skills, which has 777 GitHub stars. The repository holds 149 skills in this directory. The repository was last updated on October 5, 2026.

Source: MicrosoftDocs/Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.