User Permissions for Azure Bastion
This document covers the permissions necessary to enable a user to access an Azure VM via Azure Bastion.
All permissions are granted via the Azure Portal, The user access is being granted to must have an account in the Azure AD tenant for the subscription the VM is in. They can be a guest user.
Bastion
Select the Bastions resource
Select the Bastion the VM uses
Select Access control (IAM)
Add
Add role assignment
Role - Reader
Assign access to - Azure AD user, group, or service principal
Select - the user or group
Save
Virtual Machine
Select the Virtual machines resource
Select the VM you want to grant access to
Select Access control (IAM)
Add
Add role assignment
Role - Virtual Machine User Login
Assign access to - Azure AD user, group, or service principal
Select - the user or group
Save
Virtual Machine NIC
Select the Virtual machines resource
Select the VM you want to grant access to
Select Networking
Select the "Network interface:"
Select Access control (IAM)
Add
Add role assignment
Role - Reader
Assign access to - Azure AD user, group, or service principal
Select - the user or group
Save
Ā© 2023 Foray, LLC - All Rights Reserved