{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/",
        "slug": "dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/"
        },
        "title": "Separate Bastion shareable-link access from target-machine credentials",
        "summary": "A shareable link removes the need to enter the Azure portal, but it does not contain the RDP or SSH credentials.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:37+00:00",
        "modified_at": "2026-09-10T02:01:56+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 238,
        "potentially_affected": "Supported Azure Bastion Standard shareable links for Azure VM or scale-set access.",
        "dse_recommendation": "Manage the link, target credentials and expiration as separate access-control decisions.",
        "primary_source": {
            "name": "Create a shareable link for Azure Bastion | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/bastion/shareable-link",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>A Bastion shareable link can open target-resource access without Azure credentials, but the user must authenticate to the target through RDP or SSH. The link contains no credentials; the configured target uses a username and password or private key.</p>\n<p>The feature requires Standard SKU and does not support Virtual WAN, cross-tenant peered networks or on-premises targets. A configured expiration prevents using that link to connect after its expiry and changes its resource status to Link expired. <a href=\"https://learn.microsoft.com/en-us/azure/bastion/shareable-link\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Confirm the target type, Bastion configuration and network topology. Distinguish permission to create or view links from permission to sign in to the target machine.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends assigning ownership for both the connection link and the separate credential handoff. Use an approved secure channel for target credentials and set a link lifetime appropriate to the authorized task. Keep credential retirement and link expiration as separate checklist entries rather than assuming one action proves the other was completed.</p>\n<h2>Verification</h2>\n<p>Test with a representative authorized user who follows the link and supplies the intended target authentication. Confirm a user without valid target credentials cannot complete the sign-in. After an approved test link expires, verify a new connection through it is refused. Record the target, link status and authentication outcome without retaining passwords, private keys or a usable access link in broadly shared evidence.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/bastion/shareable-link\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create a shareable link for Azure Bastion</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nA Bastion shareable link can open target-resource access without Azure credentials, but the user must authenticate to the target through RDP or SSH. The link contains no credentials; the configured target uses a username and password or private key.\nThe feature requires Standard SKU and does not support Virtual WAN, cross-tenant peered networks or on-premises targets. A configured expiration prevents using that link to connect after its expiry and changes its resource status to Link expired. Microsoft Learn.\nApplicability\nConfirm the target type, Bastion configuration and network topology. Distinguish permission to create or view links from permission to sign in to the target machine.\nDSE recommendation\nDSE recommends assigning ownership for both the connection link and the separate credential handoff. Use an approved secure channel for target credentials and set a link lifetime appropriate to the authorized task. Keep credential retirement and link expiration as separate checklist entries rather than assuming one action proves the other was completed.\nVerification\nTest with a representative authorized user who follows the link and supplies the intended target authentication. Confirm a user without valid target credentials cannot complete the sign-in. After an approved test link expires, verify a new connection through it is refused. Record the target, link status and authentication outcome without retaining passwords, private keys or a usable access link in broadly shared evidence.\nOfficial references\nMicrosoft Learn: Create a shareable link for Azure Bastion. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nA Bastion shareable link can open target-resource access without Azure credentials, but the user must authenticate to the target through RDP or SSH. The link contains no credentials; the configured target uses a username and password or private key.\n\nThe feature requires Standard SKU and does not support Virtual WAN, cross-tenant peered networks or on-premises targets. A configured expiration prevents using that link to connect after its expiry and changes its resource status to Link expired. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/bastion/shareable-link).\n\n## Applicability\n\nConfirm the target type, Bastion configuration and network topology. Distinguish permission to create or view links from permission to sign in to the target machine.\n\n## DSE recommendation\n\nDSE recommends assigning ownership for both the connection link and the separate credential handoff. Use an approved secure channel for target credentials and set a link lifetime appropriate to the authorized task. Keep credential retirement and link expiration as separate checklist entries rather than assuming one action proves the other was completed.\n\n## Verification\n\nTest with a representative authorized user who follows the link and supplies the intended target authentication. Confirm a user without valid target credentials cannot complete the sign-in. After an approved test link expires, verify a new connection through it is refused. Record the target, link status and authentication outcome without retaining passwords, private keys or a usable access link in broadly shared evidence.\n\n## Official references\n\n[Microsoft Learn: Create a shareable link for Azure Bastion](https://learn.microsoft.com/en-us/azure/bastion/shareable-link). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Separate Bastion shareable-link access from target-machine credentials",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/",
                "headline": "Separate Bastion shareable-link access from target-machine credentials",
                "description": "A shareable link removes the need to enter the Azure portal, but it does not contain the RDP or SSH credentials.",
                "abstract": "A shareable link removes the need to enter the Azure portal, but it does not contain the RDP or SSH credentials.",
                "articleBody": "Source facts\nA Bastion shareable link can open target-resource access without Azure credentials, but the user must authenticate to the target through RDP or SSH. The link contains no credentials; the configured target uses a username and password or private key.\nThe feature requires Standard SKU and does not support Virtual WAN, cross-tenant peered networks or on-premises targets. A configured expiration prevents using that link to connect after its expiry and changes its resource status to Link expired. Microsoft Learn.\nApplicability\nConfirm the target type, Bastion configuration and network topology. Distinguish permission to create or view links from permission to sign in to the target machine.\nDSE recommendation\nDSE recommends assigning ownership for both the connection link and the separate credential handoff. Use an approved secure channel for target credentials and set a link lifetime appropriate to the authorized task. Keep credential retirement and link expiration as separate checklist entries rather than assuming one action proves the other was completed.\nVerification\nTest with a representative authorized user who follows the link and supplies the intended target authentication. Confirm a user without valid target credentials cannot complete the sign-in. After an approved test link expires, verify a new connection through it is refused. Record the target, link status and authentication outcome without retaining passwords, private keys or a usable access link in broadly shared evidence.\nOfficial references\nMicrosoft Learn: Create a shareable link for Azure Bastion. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:25:37+00:00",
                "dateModified": "2026-09-10T02:01:56+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Separate Bastion shareable-link access from target-machine credentials"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 238,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create a shareable link for Azure Bastion | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/bastion/shareable-link"
                }
            }
        ]
    }
}