How do I setup Entra ID authentication for my Azure Bastion VM?

azureuser01 16 Reputation points
2025-08-08T15:19:23.8866667+00:00

Currently I can RDP into my VM with simply the Virtual Machine User login, but I don't have the ability to bastion into the host using Microsoft Entra ID authentication.

How do I enable this option for bastion connect?
User's image

Thanks.

Azure Bastion
Azure Bastion
An Azure service that provides private and fully managed Remote Desktop Protocol (RDP) and Secure Shell (SSH) access to virtual machines.
{count} votes

1 answer

Sort by: Most helpful
  1. Anonymous
    2025-08-08T19:25:51.5233333+00:00

    Hello azureuser01

    To login with Microsoft Entra ID user via Bastion they need to use the Bastion native rdp client and Azure CLI.

    Please refer this document for more information.Configure Bastion for native client connections - Azure Bastion | Microsoft LearnWe request you to please validate the below details:

    To Enable Microsoft Entra ID Authentication for Bastion RDP Access:

    Here’s what you need to check and configure:

    1.Use Azure Bastion Standard SKU only the Standard SKU supports Entra ID authentication.

    You can upgrade from Basic to Standard if needed.

    2.The VM must be Microsoft Entra joined, or hybrid joined.

    Run this PowerShell command on the VM:

    PowerShelldsregcmd /statusShow more lines

    Look for AzureAdJoined : YES.

    3.Assign either of the following roles to the user.Virtual Machine Administrator Login

    Virtual Machine User Login.Use the Azure portal or CLI to assign these roles at the VM or resource group level.

    4.Enable Entra ID Login on the VM Use the Azure portal:

    Go to the VM → Configuration → Enable Login with Entra ID.


    I hope this helps! If these answers your query, do click the "Upvote" of which might be beneficial to other community members reading this thread.

    If the above is unclear or you are unsure about something, please add a comment below.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.