Build Azure Bastion host configs with SKU selection, scale units, tunneling, IP Connect, Kerberos, and NSG rules.
Build Azure Bastion host configs with SKU selection, scale units, tunneling, IP Connect, Kerberos, and NSG rules.
Required Fields
nameresourceGrouplocationskuvirtualNetwork.bastionSubnet.addressPrefixpublicIpAddress.nameOutput will appear here...Build Azure Bastion host configs with SKU selection, scale units, tunneling, IP Connect, Kerberos, and NSG rules. This tool helps Azure engineers generate valid configurations quickly without consulting documentation, reducing errors and accelerating infrastructure deployment. All processing runs in your browser with no data sent to external servers.
Yes. The output is plain text containing only configuration — no Azure credentials, subscription IDs (unless you typed them), or secrets are included. Treat it like any other infrastructure-as-code artifact: review in pull requests, gate on validation, apply via your change process.
No — generating a Bastion configuration is independent of the role required to apply it. Apply the output with a principal that has the documented permissions for that service. For least-privilege scoping, Azure's built-in roles and the Privileged Identity Management 'just enough access' workflows give you a starting point.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.