# Keep Bastion's target selector aligned with the required sign-in method

> Switching a native-client connection from VM resource ID to private IP changes the supported authentication and connection options.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-283-keep-bastion-s-target-selector-aligned-with-the-required-sign-in-method/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:27:13+00:00
- Modified: 2026-09-10T01:23:49+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Switching a native-client connection from VM resource ID to private IP changes the supported authentication and connection options.

## Potentially affected

Azure Bastion connections from Windows native clients to virtual machines, using Standard SKU or higher.

## DSE recommendation

Review target identity, authentication and connection options together before replacing a resource-ID target with an IP address.

## Article

## Source facts

Bastion native-client connections require Standard SKU or higher. Microsoft’s Windows native-client guidance permits a VM private-IP target instead of a resource ID, but excludes Microsoft Entra authentication and custom ports and protocols for that IP-based connection.

For Entra-joined Windows VM remote connections, Microsoft also requires a Windows 10-or-later client that is registered, joined or hybrid joined to the VM’s directory; the registered-client case starts with Windows 10 20H1. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/bastion/connect-vm-native-client-windows).

## Applicability

Identify the local Windows client, target VM, Bastion configuration and intended sign-in method. Use the documented connection combination rather than treating every target selector as interchangeable.

## DSE recommendation

DSE recommends keeping the VM resource ID in the approved connection record when Entra authentication is a requirement. Before proposing a private-IP alternative, review its exclusions and obtain approval for any changed authentication approach. Do not silently substitute local credentials to make a failed Entra workflow appear successful. Verify the documented roles and connectivity prerequisites for the selected method separately.

## Verification

Test the intended native-client path with an authorized test identity and record the target selector actually used. Confirm which authentication method completed the session and whether the expected destination was reached. If an IP-based path cannot meet the required sign-in policy, record that incompatibility explicitly. Keep the result separate from evidence about browser-based session recording or the safety of a received RDP file.

## Official references

[Microsoft Learn: Connect to a VM using Bastion – Windows native client](https://learn.microsoft.com/en-us/azure/bastion/connect-vm-native-client-windows). Source retrieved September 9, 2026.

## Primary reference

- Name: Connect to a VM using Bastion - Windows native client - Azure Bastion | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/bastion/connect-vm-native-client-windows
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep Bastion's target selector aligned with the required sign-in method,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-283-keep-bastion-s-target-selector-aligned-with-the-required-sign-in-method/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
