Session
Azure Bastion & PIM: Eliminating Standing Privileged Access to Cloud Resources
Two of the most persistent findings in cloud security assessments are public management ports (RDP/SSH exposed to the internet) and standing administrative access (accounts that are always "admin," whether they need to be or not). This session tackles both problems together, since they're frequently two sides of the same risk.
We'll start with Azure Bastion: how it provides browser-based, SSL-secured RDP/SSH access to VMs without ever assigning a public IP to the VM itself, and how it fits into a broader network architecture (including cost and scaling considerations for large environments — Bastion SKUs, session limits, and native client support). From there, we shift to identity: Privileged Identity Management (PIM), and how it transforms admin access from an always-on standing privilege into a just-in-time, time-bound, and optionally approval-gated activation.
We'll walk through configuring PIM for both Azure AD roles and Azure resource roles, setting up approval workflows, and configuring access reviews to catch privilege creep over time.
The session closes with a live demo combining both controls — an administrator activating PIM for a limited window and connecting to a VM via Bastion, with no public IP and no standing access involved at any point.
Santhoshkumar Anandakrishnan
Lead Cloud Architect
Melbourne, Australia
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top