Azure bastion host
Provision SSH access to your Azure VMs through a managed Azure Bastion host.
When you select the Azure bastion host connection type, P0 provisions SSH access through a managed Azure Bastion host. This page covers the requirements, permissions, and setup steps for that connection type.
This page is one of two connection types for bastion host configuration. For an overview and the shared subscription steps, start on the Configure bastion host integration page.
Prerequisites
You must have an Azure Bastion host already deployed in your Azure environment. P0 doesn't create the Bastion host for you — it connects to an existing one.
If you haven't yet deployed a Bastion host, see Microsoft's Bastion deployment guide to create one first.
Your existing Bastion host must meet the following requirements.
SKU type
Must be Standard or Premium (Basic SKU is not supported because it does not support tunneling)
Tunneling
Must be enabled in the Bastion host configuration
IP configuration
Must have at least one IP configuration
Subnet
Must have an IP configuration with the AzureBastionSubnet subnet
If any of these requirements are not met, P0 displays a specific error message during setup indicating which requirement failed. Update your Bastion host configuration in the Azure Portal and retry.
How the connection works
P0 supports two modes for the Azure bastion host connection type:
Single bastion host
Points directly to a Bastion host resource in the subscription
The subscription has its own Bastion host deployed
Subscription bastion host
References another subscription that already has a single Bastion host configured
Multiple subscriptions share a single Bastion host deployed in a different subscription
Single bastion host is the default mode. Select this when your subscription has its own Bastion host. You provide the Bastion host's Azure resource ID, and P0 validates it against the requirements listed earlier in this topic.
Subscription bastion host allows you to reuse a Bastion host from another subscription. When you select this mode, P0 shows a dropdown of subscriptions that already have a single Bastion host configured. The selected subscription's Bastion host is used for SSH sessions in the current subscription.
A subscription bastion host can only reference a subscription with a single Bastion host. Chaining references (a subscription bastion host pointing to another subscription bastion host) is not supported.
Permissions
P0 creates a custom Azure role scoped to the target subscription during setup. This role grants P0 the minimum permissions needed to manage Bastion sessions.
Role name: P0 Bastion Host Management - {subscriptionId}
Required permissions:
Microsoft.Network/bastionHosts/read
Read Bastion host configuration and status
Microsoft.Network/bastionHosts/disconnectActiveSessions/action
Disconnect active Bastion sessions during access revocation
This role is assigned to the service principal created during Azure app registration.
Setup steps
Complete the shared subscription steps first, then select Azure bastion host as the connection type and continue with the following steps.
Run the Shell or Terraform steps to create the custom role and assign it to the P0 service principal.
Enter the Role Definition ID of the custom role. Run the lookup command shown in the P0 UI to obtain it.
Select the bastion host mode:
Single bastion host (default): Provide the Azure Bastion host resource ID. In the Azure Portal, go to the Bastions service, select your Bastion resource, and copy its Resource JSON to obtain the ID.
Subscription bastion host: Select from the dropdown of subscriptions that already have a single Bastion host configured.
The Bastion host resource ID follows this format:
/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupId}/providers/Microsoft.Network/bastionHosts/{bastionHostName}P0 validates the Bastion host against all requirements listed in the Prerequisites section. If validation fails, you see a specific error message indicating which requirement was not met.




The Bastion host configuration is now complete.
Troubleshooting
"Azure bastion host must be of 'Standard' or 'Premium' type"
The Bastion host uses the Basic SKU
Upgrade the Bastion host to Standard or Premium SKU in the Azure Portal
"Azure bastion host must have tunneling enabled"
Tunneling is disabled on the Bastion host
Enable tunneling in the Bastion host configuration
"Azure bastion host must have at least one IP configuration"
The Bastion host has no IP configuration
Verify the Bastion host is configured correctly in the Azure Portal
"Azure bastion host must have an IP configuration with the 'AzureBastionSubnet' subnet"
The Bastion host is not attached to the correct subnet
Attach the Bastion host to a subnet named AzureBastionSubnet
"Custom role not found in subscription"
The shell or Terraform commands did not complete
Re-run the install commands
"Custom role is not assigned to the App Client"
The role assignment was not created
Re-run the role assignment command
Next step
Proceed to Install SSH access control to connect P0 to your Azure VMs.
Last updated