# Plan Bastion Kerberos DNS changes as a redeployment dependency

> Microsoft warns that changed DNS server information does not propagate to an existing Bastion resource.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-352-plan-bastion-kerberos-dns-changes-as-a-redeployment-dependency/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:26:04+00:00
- Modified: 2026-09-10T02:01:55+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 1 minutes

## What you need to know

Microsoft warns that changed DNS server information does not propagate to an existing Bastion resource.

## Potentially affected

Azure Bastion Kerberos configurations using the Azure portal and supported Azure-hosted domain controllers.

## DSE recommendation

Include Bastion redeployment and an independently usable access path in the DNS change plan.

## Article

## Source facts

Microsoft states that DNS server changes do not propagate to Bastion and require deleting and recreating the Bastion resource. Its Kerberos configuration guidance requires an Azure-hosted domain-controller VM in the same virtual network as Bastion.

This Kerberos configuration uses the portal, not the native client, and requires Basic SKU or higher. Cross-realm authentication and VMs migrated from on-premises are not supported in the documented considerations. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/bastion/kerberos-authentication-portal).

## Applicability

Review the actual domain-controller location, virtual network, Bastion SKU and connection method. This is change planning for a documented dependency, not an instruction to delete a production access resource immediately.

## DSE recommendation

DSE recommends identifying this redeployment dependency before approving DNS-server changes. Preserve reviewed configuration, define an independently authorized administration path and agree on an access-restoration test. Coordinate the Bastion and directory owners rather than extending a propagation wait indefinitely. Keep unsupported authentication topologies out of the proposed acceptance plan.

## Verification

After an approved redeployment, test the intended domain-joined target through the portal and verify the actual authentication method. A successful session alone should not be substituted for the requested Kerberos evidence. Document the DNS configuration, recreated resource identity and controlled test results before closing the change.

## Official references

[Microsoft Learn: Configure Bastion for Kerberos authentication – Azure portal](https://learn.microsoft.com/en-us/azure/bastion/kerberos-authentication-portal). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure Bastion for Kerberos authentication - Azure portal - Azure Bastion | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/bastion/kerberos-authentication-portal
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Plan Bastion Kerberos DNS changes as a redeployment dependency,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-352-plan-bastion-kerberos-dns-changes-as-a-redeployment-dependency/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
