Plan Bastion Kerberos DNS changes as a redeployment dependency

Microsoft warns that changed DNS server information does not propagate to an existing Bastion resource.

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureGuide · 1 min read
Executive summary

What you need to know

Microsoft warns that changed DNS server information does not propagate to an existing Bastion resource.

Potentially affected

Azure Bastion Kerberos configurations using the Azure portal and supported Azure-hosted domain controllers.

DSE recommendation

Include Bastion redeployment and an independently usable access path in the DNS change plan.

Source facts

Microsoft states that DNS server changes do not propagate to Bastion and require deleting and recreating the Bastion resource. Its Kerberos configuration guidance requires an Azure-hosted domain-controller VM in the same virtual network as Bastion.

This Kerberos configuration uses the portal, not the native client, and requires Basic SKU or higher. Cross-realm authentication and VMs migrated from on-premises are not supported in the documented considerations. Microsoft Learn.

Applicability

Review the actual domain-controller location, virtual network, Bastion SKU and connection method. This is change planning for a documented dependency, not an instruction to delete a production access resource immediately.

DSE recommendation

DSE recommends identifying this redeployment dependency before approving DNS-server changes. Preserve reviewed configuration, define an independently authorized administration path and agree on an access-restoration test. Coordinate the Bastion and directory owners rather than extending a propagation wait indefinitely. Keep unsupported authentication topologies out of the proposed acceptance plan.

Verification

After an approved redeployment, test the intended domain-joined target through the portal and verify the actual authentication method. A successful session alone should not be substituted for the requested Kerberos evidence. Document the DNS configuration, recreated resource identity and controlled test results before closing the change.

Official references

Microsoft Learn: Configure Bastion for Kerberos authentication – Azure portal. Source retrieved September 9, 2026.

Primary reference

Review the official source

Configure Bastion for Kerberos authentication - Azure portal - Azure Bastion | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE