# Separate Bastion shareable-link access from target-machine credentials

> A shareable link removes the need to enter the Azure portal, but it does not contain the RDP or SSH credentials.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:37+00:00
- Modified: 2026-09-10T02:01:56+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

A shareable link removes the need to enter the Azure portal, but it does not contain the RDP or SSH credentials.

## Potentially affected

Supported Azure Bastion Standard shareable links for Azure VM or scale-set access.

## DSE recommendation

Manage the link, target credentials and expiration as separate access-control decisions.

## Article

## Source facts

A Bastion shareable link can open target-resource access without Azure credentials, but the user must authenticate to the target through RDP or SSH. The link contains no credentials; the configured target uses a username and password or private key.

The feature requires Standard SKU and does not support Virtual WAN, cross-tenant peered networks or on-premises targets. A configured expiration prevents using that link to connect after its expiry and changes its resource status to Link expired. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/bastion/shareable-link).

## Applicability

Confirm the target type, Bastion configuration and network topology. Distinguish permission to create or view links from permission to sign in to the target machine.

## DSE recommendation

DSE recommends assigning ownership for both the connection link and the separate credential handoff. Use an approved secure channel for target credentials and set a link lifetime appropriate to the authorized task. Keep credential retirement and link expiration as separate checklist entries rather than assuming one action proves the other was completed.

## Verification

Test with a representative authorized user who follows the link and supplies the intended target authentication. Confirm a user without valid target credentials cannot complete the sign-in. After an approved test link expires, verify a new connection through it is refused. Record the target, link status and authentication outcome without retaining passwords, private keys or a usable access link in broadly shared evidence.

## Official references

[Microsoft Learn: Create a shareable link for Azure Bastion](https://learn.microsoft.com/en-us/azure/bastion/shareable-link). Source retrieved September 9, 2026.

## Primary reference

- Name: Create a shareable link for Azure Bastion | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/bastion/shareable-link
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Separate Bastion shareable-link access from target-machine credentials,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-379-separate-bastion-shareable-link-access-from-target-machine-credentials/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
