Azure Bastion
It can happen that an IT admin will need to perform some administrative tasks on a virtual desktop. Connecting in a secure way can be done by using Azure Bastion. This is a fully managed PaaS service, meaning that Microsoft manages the solution completely. This allows the IT admin to connect to the Azure virtual machine using a private IP address directly from the browser. This eliminates the need for a public IP address on the session host and adds more security to the virtual desktop.
Azure Bastion is available in three versions – Developer, Basic, and Standard – with each offering its own benefits. More information about the different versions can be found here: https://learn.microsoft.com/en-us/azure/bastion/bastion-overview.
In a typical hub-spoke network topology, the Bastion host is placed in the hub virtual network that is connected via virtual network peering to an AVD virtual network, as shown in Figure 8.13. The exception is the Developer...