For the complete documentation index, see llms.txt. This page is also available as Markdown.

Azure bastion host

Provision SSH access to your Azure VMs through a managed Azure Bastion host.

When you select the Azure bastion host connection type, P0 provisions SSH access through a managed Azure Bastion host. This page covers the requirements, permissions, and setup steps for that connection type.

This page is one of two connection types for bastion host configuration. For an overview and the shared subscription steps, start on the Configure bastion host integration page.

Prerequisites

You must have an Azure Bastion host already deployed in your Azure environment. P0 doesn't create the Bastion host for you — it connects to an existing one.

If you haven't yet deployed a Bastion host, see Microsoft's Bastion deployment guide to create one first.

Your existing Bastion host must meet the following requirements.

Requirement
Details

SKU type

Must be Standard or Premium (Basic SKU is not supported because it does not support tunneling)

Tunneling

Must be enabled in the Bastion host configuration

IP configuration

Must have at least one IP configuration

Subnet

Must have an IP configuration with the AzureBastionSubnet subnet

If any of these requirements are not met, P0 displays a specific error message during setup indicating which requirement failed. Update your Bastion host configuration in the Azure Portal and retry.

How the connection works

P0 supports two modes for the Azure bastion host connection type:

Mode
Description
When to use

Single bastion host

Points directly to a Bastion host resource in the subscription

The subscription has its own Bastion host deployed

Subscription bastion host

References another subscription that already has a single Bastion host configured

Multiple subscriptions share a single Bastion host deployed in a different subscription

Single bastion host is the default mode. Select this when your subscription has its own Bastion host. You provide the Bastion host's Azure resource ID, and P0 validates it against the requirements listed earlier in this topic.

Subscription bastion host allows you to reuse a Bastion host from another subscription. When you select this mode, P0 shows a dropdown of subscriptions that already have a single Bastion host configured. The selected subscription's Bastion host is used for SSH sessions in the current subscription.

A subscription bastion host can only reference a subscription with a single Bastion host. Chaining references (a subscription bastion host pointing to another subscription bastion host) is not supported.

Permissions

P0 creates a custom Azure role scoped to the target subscription during setup. This role grants P0 the minimum permissions needed to manage Bastion sessions.

Role name: P0 Bastion Host Management - {subscriptionId}

Required permissions:

Permission
Purpose

Microsoft.Network/bastionHosts/read

Read Bastion host configuration and status

Microsoft.Network/bastionHosts/disconnectActiveSessions/action

Disconnect active Bastion sessions during access revocation

This role is assigned to the service principal created during Azure app registration.

Setup steps

Complete the shared subscription steps first, then select Azure bastion host as the connection type and continue with the following steps.

  1. Run the Shell or Terraform steps to create the custom role and assign it to the P0 service principal.

  2. Enter the Role Definition ID of the custom role. Run the lookup command shown in the P0 UI to obtain it.

  3. Select the bastion host mode:

    • Single bastion host (default): Provide the Azure Bastion host resource ID. In the Azure Portal, go to the Bastions service, select your Bastion resource, and copy its Resource JSON to obtain the ID.

    • Subscription bastion host: Select from the dropdown of subscriptions that already have a single Bastion host configured.

    The Bastion host resource ID follows this format:

    /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupId}/providers/Microsoft.Network/bastionHosts/{bastionHostName}

    P0 validates the Bastion host against all requirements listed in the Prerequisites section. If validation fails, you see a specific error message indicating which requirement was not met.

The Bastion host configuration is now complete.

Troubleshooting

Error
Cause
Resolution

"Azure bastion host must be of 'Standard' or 'Premium' type"

The Bastion host uses the Basic SKU

Upgrade the Bastion host to Standard or Premium SKU in the Azure Portal

"Azure bastion host must have tunneling enabled"

Tunneling is disabled on the Bastion host

Enable tunneling in the Bastion host configuration

"Azure bastion host must have at least one IP configuration"

The Bastion host has no IP configuration

Verify the Bastion host is configured correctly in the Azure Portal

"Azure bastion host must have an IP configuration with the 'AzureBastionSubnet' subnet"

The Bastion host is not attached to the correct subnet

Attach the Bastion host to a subnet named AzureBastionSubnet

"Custom role not found in subscription"

The shell or Terraform commands did not complete

Re-run the install commands

"Custom role is not assigned to the App Client"

The role assignment was not created

Re-run the role assignment command

Next step

Proceed to Install SSH access control to connect P0 to your Azure VMs.

Last updated