Agent skill

Azure Bastion Jit

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

MITAuto-check passedDevOps & Cloud

Install Azure Bastion Jit

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill azure-bastion-jit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills azure-bastion-jit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/azure-bastion-jit .claude/skills/azure-bastion-jit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
azure-bastion-jit
GitHub stars
175
Token cost
~2.2k tokens
SKILL.md length
961 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

  • Works in 9 steps: Architecture. One Bastion per hub VNet… → Eliminate VM public IPs. Azure Policy:… → Bastion + Entra login on the VM. Combine… → …
  • Hybrid/SD-WAN VPN design
  • SKILL.md covers When to use, Bastion SKUs — pick by feature…, Approach and Guardrails, plus 3 more sections
  • Calls az

What it does

Azure Bastion Jit is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access. Covers Bastion SKU selection (Developer / Basic / Standard / Premium), IP-based and shareable-link connections, native client (RDP/SSH from local machine via az CLI), session recording (Premium), private-only deployment, JIT request workflow and policy, RBAC for connect operations, integration with Conditional Access (via Bastion + Entra login on the VM), Azure Policy enforcement to…

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Authorization and RBAC and Container orchestration. It works with Microsoft Azure, Microsoft Defender and Kubernetes. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Hybrid/SD-WAN VPN design
  • GSA Private Access (use entra-global-secure-access)
  • Cluster-only K8s access

Example prompts

  • “/azure-bastion-jit”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Architecture. One Bastion per hub VNet (or per spoke if traffic isolation
  2. Eliminate VM public IPs. Azure Policy: *Public IP addresses should not be
  3. Bastion + Entra login on the VM. Combine with `Microsoft Entra login for
  4. Configure JIT for every VM that's allowed RDP/SSH.
  5. RBAC on Bastion connect. Bastion connect is not the same as VM RBAC. Required
  6. Native client + IP-based + shareable links (Standard+).
  7. Session recording (Premium). Records video of administrator sessions to a Log
  8. JIT request workflow. Document for admins
  9. Monitor. Stream Bastion diagnostic logs (BastionAuditLogs) and JIT

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Azure Bastion Jit loads about 2.2k tokens when it runs. Until then it costs about 257 tokens; SKILL.md has 961 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~257
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 961 words, ~2,223 tokens.

Download SKILL.mdSave it as .claude/skills/azure-bastion-jit/SKILL.md (or your agent's skills folder).
name
azure-bastion-jit
description
Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access. Covers Bastion SKU selection (Developer / Basic / Standard / Premium), IP-based and shareable-link connections, native client (RDP/SSH from local machine via az CLI), session recording (Premium), private-only deployment, JIT request workflow and policy, RBAC for connect operations, integration with Conditional Access (via Bastion + Entra login on the VM), Azure Policy enforcement to require Bastion + JIT and prohibit public IP on VMs, and migration off VPN/jump-box patterns. WHEN: Azure Bastion design, Bastion SKU comparison, JIT VM access, just-in-time access Azure, Bastion shareable link, native client Bastion, session recording Bastion, eliminate public IP on VMs, replace jump host with Bastion, secure RDP SSH Azure, Bastion Premium recording. DO NOT USE for hybrid/SD-WAN VPN design, GSA Private Access (use entra-global-secure-access), or cluster-only K8s access.
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Azure Bastion + Just-In-Time VM Access

The combination of Azure Bastion (managed, browser/native-client jump service) and Defender for Cloud just-in-time (JIT) VM access (time-limited NSG allow-rules for management ports) eliminates the two most common Azure VM compromise paths: internet-exposed RDP/SSH and standing-open management ports.

When to use

Designing or hardening administrative access to Azure IaaS VMs and VMSS. Use this skill for SKU selection, JIT policy, public-IP elimination, and the operational workflow.

Do not use this skill for hybrid VPN/SD-WAN design, ZTNA replacement of VPN (entra-global-secure-access), or AKS-only access.

Bastion SKUs — pick by feature need

SKUCapabilities
DeveloperFree, ad-hoc, browser-only RDP/SSH to a single VM, single VNet, no scale, no shareable links
BasicRDP/SSH via portal, private-IP-only VMs supported, single-instance scale
Standard+ Native client, shareable links, IP-based connection, Kerberos, Linux file copy, custom port, scale up to 50 instances
Premium+ Session recording, private-only deployment, additional admin features

Rule of thumb: Standard for most enterprise; Premium where session recording or private-only deployment is required (regulated industries). Developer is for non-production / sandbox personal use.

Approach

  1. Architecture. One Bastion per hub VNet (or per spoke if traffic isolation requires). Required subnet: AzureBastionSubnet /26 minimum. NSG on the subnet follows the documented allow rules — don't write "deny all from internet" without the documented allow exceptions or Bastion breaks.

  2. Eliminate VM public IPs. Azure Policy: Public IP addresses should not be associated with virtual machines — set to Deny in production scopes. New VMs are private-only; admin access is via Bastion + JIT.

  3. Bastion + Entra login on the VM. Combine with Microsoft Entra login for Windows/Linux VM extension so RDP/SSH authenticates with Entra credentials, honoring Conditional Access (MFA, device compliance, named locations) on the VM sign-in itself. This is the missing leg most "Bastion-only" deployments forget.

  4. Configure JIT for every VM that's allowed RDP/SSH.

    • Default ports: RDP 3389, SSH 22, WinRM 5985/5986.
    • Max request window: 3 hours.
    • Source: Requestor's IP (or Bastion subnet, since requests come from there).
    • Approval: implicit by RBAC, or add a manual approval step for tier-0 VMs.
  5. RBAC on Bastion connect. Bastion connect is not the same as VM RBAC. Required roles:

    • Reader on the Bastion + the VM + its NIC + its VNet.
    • Virtual Machine User Login (Linux) / Virtual Machine Administrator Login for Entra-based VM sign-in.
    • JIT request: Microsoft.Security/locations/jitNetworkAccessPolicies/initiate/action. Bake into a custom role per persona to avoid over-granting.
  6. Native client + IP-based + shareable links (Standard+).

    • Native client (az network bastion rdp/ssh): admins use local mstsc/SSH tooling; better UX than browser tab. CA still applies via VM sign-in.
    • IP-based connection: Bastion to peered on-prem VMs over ExpressRoute/VPN.
    • Shareable links: time-bound URL for break-glass to a contractor. Disable unless explicitly needed; audit usage.
  7. Session recording (Premium). Records video of administrator sessions to a Log Analytics workspace / Storage. Required for some regulated industries; review retention and access controls.

  8. JIT request workflow. Document for admins:

    • Open Defender for Cloud → JIT VM access → Request access → port + window.
    • Connect via Bastion within window.
    • NSG rules auto-revert on expiry.
  9. Monitor. Stream Bastion diagnostic logs (BastionAuditLogs) and JIT activity-log events to Sentinel. Detect: requests outside business hours from unexpected IPs, rapid sequential VMs by one principal.

Show full SKILL.md (438 more words)Show less

Guardrails

  • Don't write a deny-all NSG on the AzureBastionSubnet. It must allow specific service tags / ports; the documented rules are required for the service to work.
  • JIT changes NSG rules, not Azure Firewall / NVA rules. If management traffic flows through a firewall, JIT alone won't open it. Either layer firewall policy or route management traffic via Bastion only.
  • Bastion alone is not Conditional Access. Without Entra login on the VM, you've removed public exposure but a stolen VM credential still works. Combine.
  • Shareable links bypass MFA on the originating user unless paired with Entra VM login. Avoid for sensitive VMs.
  • Premium session recording is a heavy storage commitment. Plan retention and cost.
  • Don't deploy Bastion in every spoke VNet "for convenience." One per hub with peering is usually right; the per-instance cost adds up.
  • JIT request from a shared NAT IP opens the port for everyone behind that NAT during the window. Combine with named locations and CA.
  • Public IP on a VM and Bastion peer access "as backup" — defeats the model. Pick one path.

Common anti-patterns

  • "Bastion + public IP on VMs left in place 'just for break-glass'" — break-glass is a procedure, not an unmonitored open RDP port.
  • "JIT request window = 8 hours, source = any" — that's an open port for a working day from the internet.
  • "Bastion without Entra VM login" — local admin password compromise is still game-over.
  • "Shareable links shared by email forever" — turn into permanent backdoors. Time- bound + audit.
  • "Recorded all sessions to a workspace anyone can read" — recording reveals privileged actions and credentials.
  • "Standalone Bastion per dev VM" — uneconomical and noisy. One per hub.
  • "Skipped Sentinel/log integration" — Bastion sessions invisible to SOC.
  • "Used Bastion for AKS API server access" — wrong tool; use private cluster + GSA Private Access or jumpbox + kube-config.

Example prompts

  • Design Bastion + JIT for a 3-hub multi-region landing zone with a 2,000-VM estate.
  • Migrate from a self-managed Windows jump host to Bastion + Entra VM login + JIT.
  • Eliminate public IP on Linux VMs via Azure Policy and roll out private-only access.
  • Configure session recording on Bastion Premium with 1-year retention to Storage.
  • Build a custom RBAC role for "VM Operator via Bastion" combining Bastion connect + Entra login + JIT request only.
  • Sentinel detections: JIT request out-of-hours, rapid sequential VM access by one principal, shareable link creation.
  • Compare Bastion shareable link vs Entra Private Access for occasional contractor access.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/azure-bastion-jit of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Azure Bastion Jit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Azure Bastion Jit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Azure Bastion Jit this skillvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Mirrord Operatormetalbear-co/mirrord5.4k1 repos~4.6kAutomated safety check: PassMIT
Akka.NET Management and DiscoveryAaronontheweb/dotnet-skills1.2k1 repos~2.5kAutomated safety check: PassMIT
Provider API Call Dedupmondoohq/mql412—~7.7kAutomated safety check: PassCustom licence
Loki Config Generatorakin-ozer/cc-devops-skills320—~4.6kAutomated safety check: PassApache-2.0
Mimirgrafana/skills282—~1.2kAutomated safety check: PassApache-2.0

Similar skills

  • Mirrord Operator

    metalbear-co/mirrord

    Help users install and configure the mirrord Operator for team/enterprise environments.

    5.4k GitHub starsUsed in 1 repo~4.6k tokens
    DevOps & CloudAuto-check passed
  • Akka.NET Management and Discovery

    Aaronontheweb/dotnet-skills

    Sets up Akka.Management and Cluster.Bootstrap so Akka.NET clusters form through service discovery on Kubernetes, Azure or config instead of static seed nodes.

    1.2k GitHub starsUsed in 1 repo~2.5k tokens
    DevOps & CloudAuto-check passed
  • A skill your agent uses when a provider scan is slow, times out, or trips rate limits (429, throttling, Retry-After), when the same request URL appears many times in a debug log, when an asset's…

    412 GitHub stars~7.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Loki Config Generator

    akin-ozer/cc-devops-skills

    Generate/create Loki configs — ingester, querier, compactor, ruler, S3/GCS/Azure backends.

    320 GitHub stars~4.6k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Mimir

    grafana/skills

    Official

    Stand up Grafana Mimir for horizontally scalable, multi-tenant, long-term Prometheus + OTLP metrics storage.

    282 GitHub stars~1.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Azure Cloud Migrate

    microsoft/GitHub-Copilot-for-Azure

    Official

    Assess and migrate cross-cloud workloads to Azure with reports and code conversion.

    255 GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Firewall

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Firewall — managed cloud-native L3-L7 stateful network firewall for centralised egress, east-west, and ingress control.

    175 GitHub stars~1.7k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Azure Bastion Jit

What does Azure Bastion Jit do?

Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access. Azure Bastion Jit is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

When should I use Azure Bastion Jit?

Azure Bastion Jit fits situations like: hybrid/SD-WAN VPN design; GSA Private Access (use entra-global-secure-access); cluster-only K8s access.

How do I install Azure Bastion Jit in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-bastion-jit -a claude-code`. Or copy the skill folder (skills/azure-bastion-jit in vinayaklatthe/microsoft-security-skills) into .claude/skills/azure-bastion-jit in your project. Claude Code loads it when a task matches its description.

How do I install Azure Bastion Jit in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-bastion-jit -a codex`. Or copy the skill folder (skills/azure-bastion-jit in vinayaklatthe/microsoft-security-skills) into .agents/skills/azure-bastion-jit in your project. Codex loads it when a task matches its description.

Can I use Azure Bastion Jit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill azure-bastion-jit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/azure-bastion-jit, .gemini/skills/azure-bastion-jit, .github/skills/azure-bastion-jit and .opencode/skills/azure-bastion-jit in your project.

What does Azure Bastion Jit need to run?

Going by SKILL.md and its folder, Azure Bastion Jit needs the command-line tools its instructions call (az).

Does Azure Bastion Jit access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Azure Bastion Jit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Azure Bastion Jit use?

Azure Bastion Jit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Azure Bastion Jit use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Azure Bastion Jit?

Skills that share tags, products or a category with Azure Bastion Jit: Mirrord Operator (metalbear-co/mirrord, 5.4k stars), Akka.NET Management and Discovery (Aaronontheweb/dotnet-skills, 1.2k stars), Provider API Call Dedup (mondoohq/mql, 412 stars) and Loki Config Generator (akin-ozer/cc-devops-skills, 320 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Azure Bastion Jit?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.