Keep Bastion's target selector aligned with the required sign-in method

Switching a native-client connection from VM resource ID to private IP changes the supported authentication and connection options.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 2 min read
Executive summary

What you need to know

Switching a native-client connection from VM resource ID to private IP changes the supported authentication and connection options.

Potentially affected

Azure Bastion connections from Windows native clients to virtual machines, using Standard SKU or higher.

DSE recommendation

Review target identity, authentication and connection options together before replacing a resource-ID target with an IP address.

Source facts

Bastion native-client connections require Standard SKU or higher. Microsoft’s Windows native-client guidance permits a VM private-IP target instead of a resource ID, but excludes Microsoft Entra authentication and custom ports and protocols for that IP-based connection.

For Entra-joined Windows VM remote connections, Microsoft also requires a Windows 10-or-later client that is registered, joined or hybrid joined to the VM’s directory; the registered-client case starts with Windows 10 20H1. Microsoft Learn.

Applicability

Identify the local Windows client, target VM, Bastion configuration and intended sign-in method. Use the documented connection combination rather than treating every target selector as interchangeable.

DSE recommendation

DSE recommends keeping the VM resource ID in the approved connection record when Entra authentication is a requirement. Before proposing a private-IP alternative, review its exclusions and obtain approval for any changed authentication approach. Do not silently substitute local credentials to make a failed Entra workflow appear successful. Verify the documented roles and connectivity prerequisites for the selected method separately.

Verification

Test the intended native-client path with an authorized test identity and record the target selector actually used. Confirm which authentication method completed the session and whether the expected destination was reached. If an IP-based path cannot meet the required sign-in policy, record that incompatibility explicitly. Keep the result separate from evidence about browser-based session recording or the safety of a received RDP file.

Official references

Microsoft Learn: Connect to a VM using Bastion – Windows native client. Source retrieved September 9, 2026.

Primary reference

Review the official source

Connect to a VM using Bastion - Windows native client - Azure Bastion | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE