What you need to know
Switching a native-client connection from VM resource ID to private IP changes the supported authentication and connection options.
Potentially affected
Azure Bastion connections from Windows native clients to virtual machines, using Standard SKU or higher.
DSE recommendation
Review target identity, authentication and connection options together before replacing a resource-ID target with an IP address.
Source facts
Bastion native-client connections require Standard SKU or higher. Microsoft’s Windows native-client guidance permits a VM private-IP target instead of a resource ID, but excludes Microsoft Entra authentication and custom ports and protocols for that IP-based connection.
For Entra-joined Windows VM remote connections, Microsoft also requires a Windows 10-or-later client that is registered, joined or hybrid joined to the VM’s directory; the registered-client case starts with Windows 10 20H1. Microsoft Learn.
Applicability
Identify the local Windows client, target VM, Bastion configuration and intended sign-in method. Use the documented connection combination rather than treating every target selector as interchangeable.
DSE recommendation
DSE recommends keeping the VM resource ID in the approved connection record when Entra authentication is a requirement. Before proposing a private-IP alternative, review its exclusions and obtain approval for any changed authentication approach. Do not silently substitute local credentials to make a failed Entra workflow appear successful. Verify the documented roles and connectivity prerequisites for the selected method separately.
Verification
Test the intended native-client path with an authorized test identity and record the target selector actually used. Confirm which authentication method completed the session and whether the expected destination was reached. If an IP-based path cannot meet the required sign-in policy, record that incompatibility explicitly. Keep the result separate from evidence about browser-based session recording or the safety of a received RDP file.
Official references
Microsoft Learn: Connect to a VM using Bastion – Windows native client. Source retrieved September 9, 2026.
Review the official source
Connect to a VM using Bastion - Windows native client - Azure Bastion | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE