Which Azure service provides secure access to Azure virtual machines using an HTML5 browser-based RDP and SSH connection without requiring public IP addresses?
Azure Bastion is the correct answer because it is a fully managed PaaS service that provides secure, browser-based RDP and SSH connectivity to Azure VMs directly from the Azure portal. It is deployed into a virtual network and allows VM access over TLS without requiring any public IP address to be assigned to the VM itself. Additionally, Bastion protects against port scanning and allows organizations to enforce Azure AD conditional access policies, making it the ideal solution for secure VM administration.
Why this answer
Azure Bastion is a fully managed PaaS service that provides secure and seamless RDP and SSH connectivity to Azure virtual machines directly through the Azure portal using an HTML5-based browser. It eliminates the need for public IP addresses on the VMs, as the connection is established over TLS within the same virtual network, bypassing exposure to the internet.
How to eliminate wrong answers
Option A is wrong because Azure VPN Gateway creates an encrypted tunnel between an on-premises network and Azure over the public internet, but it does not provide browser-based RDP/SSH access and still requires VMs to have private IP reachability, not eliminating the need for public IPs. Option C is wrong because Azure Private Link enables private connectivity to Azure services via private endpoints, but it does not offer RDP/SSH session management or a browser-based interface for VM access. Option D is wrong because Azure Active Directory Application Proxy provides secure remote access to on-premises web applications, not to Azure VMs via RDP/SSH, and it relies on public endpoints for the proxy service.