No more typing reviews! Try our Samantha, our new voice AI agent.

Azure Bastion vs Microsoft Entra Permissions Management [EOL] comparison

 

Comparison Buyer's Guide

Executive Summary

Review summaries and opinions

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Categories and Ranking

Azure Bastion
Average Rating
8.6
Reviews Sentiment
7.3
Number of Reviews
13
Ranking in other categories
Network Monitoring Software (46th), Remote Monitoring and Management (RMM) (13th), Microsoft Security Suite (26th)
Microsoft Entra Permissions...
Average Rating
7.0
Reviews Sentiment
7.0
Number of Reviews
2
Ranking in other categories
No ranking in other categories
 

Featured Reviews

Anand Yadav - PeerSpot reviewer
Manager Technical support at Softcell Technologies Limited
Secure remote access has reduced attack surface and simplifies privileged administration
The best features of Azure Bastion are secure browser-based RDP or SSH access, elimination of public IP exposure on VMs, and seamless integration with Azure networking. From a cybersecurity perspective, we especially value centralized access control, reduced attack surface, and the ability to provide privileged administrative access without deploying and maintaining traditional jump servers. Browser-based RDP or SSH through Azure Bastion has reduced operational overhead because administrators can securely access VMs without VPN dependency, jump servers, or exposed management ports. Centralized access through Azure role-based access control makes permission management much easier, allowing us to enforce least-privilege access and maintain consistent administrative controls across multiple customer environments. Another feature we find valuable in Azure Bastion is its ability to standardize secure administrative access across different customer environments. From a security operation perspective, it reduces dependency on legacy jump host architectures, simplifies access management, and helps enforce a consistent remote access security model across Azure workloads.
Sameer Bhat - PeerSpot reviewer
Vice President at Goldman Sachs
Provides resource-based access and security, but time-bound access can be a problem
Entra ID is the core of the identity management that we have. This is the key product that we are using. I am currently also looking into Entra Private Access because we are planning to deploy about 50,000 desktops into Azure and use Azure Virtual Desktop. We would like to give access to the users from the desktop to on-premises applications. I learned that Entra Private Access is a good solution. That is not yet GA, but that is what we are looking for. Entra provides a single pane of glass for managing user access, but because our company also integrates with Nebula API, only administrators use Entra's pane. A normal person who wants to get onboarded can do self-service using Nebula. The features for whitelisting and other things are definitely there. That is what we use specifically. Application IDs, enterprise applications, and all those things are already there, so we have more efficiency. There is also security because we usually do not allow user identities to get direct access to Azure resources. Usually, we use the service principles from Entra ID, so this way, it increases security. Entra has helped to save time for our IT administrators. We tend to automate a lot of things. We can do automation using Graph APIs and save time. It is hard to quantify the time savings, but there has been a medium amount of time savings. Entra has helped to save our organization money. We care about security and risk more than money, but it also saves money. We are premium customers, and because we have a commit-to-consume contract with Microsoft of multi-million dollars, the money does not come into it because we have to consume those resources.

Quotes from Members

We asked business professionals to review the solutions they use. Here are some excerpts of what they said:
 

Pros

"The most significant advantage lies in its runbook features, particularly beneficial for our infrastructure team."
"Azure Bastion is preferable because you just switch it on and off you go."
"The product's setup is easy."
"The ability to operate the product with scripting is excellent."
"As an Azure consultant, for me, it is the best way to give the administrator access as you can manage the permission - including who can access Bastion."
"It is very easy to use as it's in the browser; it is on the menu of the virtual machine, so you just need to type your username and password and you will have a full RDP experience."
"Azure Bastion makes it easy to provide quick virtual machine access to our customers."
"It provides all the security to us. Without getting on the internet, we can access our servers. We can access our desktop through our web browser. We don't need to run the mstsc command and login to the VM. All those things are not required."
"Multifactor authentication is valuable."
"The solution integrates well with our infrastructure and other systems without any issues."
 

Cons

"Currently, Azure Bastion does not allow for direct data transfer between desktops. A storage solution must be created to transfer data, and this requires additional permissions like ACL or NFS."
"The protocol speed could be faster."
"There is room for improvement with AI features. I would like to see integrated AI features with Azure Bastion, especially for connectivity issues."
"The solution breaks down sometimes."
"There are some challenges because Bastion is more compatible with Edge but not with the other browsers. As an organization, it doesn't make sense that we have to use only Edge. We should be able to access Bastion over Chrome, Mozilla, or Opera. It should be our choice."
"Azure Bastion does its job. However, it would be nice to have the capability to cut and paste across desktops, similar to old-fashioned Remote Desktop emulation."
"When you have a boot issue on Windows, you cannot use Azure Bastion to fix it. You have to use the Azure console or the VM console, and it is very limited."
"We are not able to copy and paste files directly into the server over the patch host. We have to transfer files over to Azure Storage."
"We use a third-party API called Nebula API to integrate the account for authorization. The time-bound access area in Entra can be a problem. It can be improved in terms of the granularity of the permissions."
"The solution's pricing and support services need improvement."
 

Pricing and Cost Advice

"It does not save money for us."
"The tool is cheaply priced. I would say that the product is free to use."
"The pricing is a lower decision point than high-quality security for our organization. Better security comes at a cost, but it's worth it, and that's what we tell our customers."
"Azure Bastion's pricing is good."
"We are a Fortune 500 company, so we always negotiate with Microsoft."
"The product cost is in the mid to high range."
report
Use our free recommendation engine to learn which Microsoft Security Suite solutions are best for your needs.
900,747 professionals have used our research since 2012.
 

Top Industries

By visitors reading reviews
Computer Software Company
11%
Financial Services Firm
11%
Comms Service Provider
10%
Construction Company
7%
Computer Software Company
19%
Financial Services Firm
16%
Government
9%
Healthcare Company
7%
 

Company Size

By reviewers
Large Enterprise
Midsize Enterprise
Small Business
By reviewers
Company SizeCount
Small Business5
Midsize Enterprise2
Large Enterprise6
No data available
 

Questions from the Community

What is your experience regarding pricing and costs for Azure Bastion?
Microsoft's pricing is on the higher side and could be more competitive. Startups and small organizations often prefer AWS ( /products/amazon-aws-reviews ) or GCP due to their lower costs, while la...
What needs improvement with Azure Bastion?
Azure Bastion could be improved with more granular session monitoring, rich audit capabilities, and deeper integration with security operation workflows. We would also appreciate enhanced reporting...
What is your primary use case for Azure Bastion?
Azure Bastion serves as our primary solution for providing secure administrative access to Azure VPNs and VMs without exposing RDP or SSH ports to the internet. From a cybersecurity perspective, it...
What is your experience regarding pricing and costs for Microsoft Entra Permissions Management?
The product cost is in the mid to high range. You need to have a good budget to implement it, so it is considered fairly expensive for our market. I rate the pricing a seven out of ten.
What needs improvement with Microsoft Entra Permissions Management?
The solution's pricing and support services need improvement.
What is your primary use case for Microsoft Entra Permissions Management?
Our clients primarily use the product from a security management perspective.
 

Also Known As

No data available
CloudKnox Permissions Management
 

Overview

Find out what your peers are saying about Microsoft and others in Microsoft Security Suite. Updated: June 2026.
900,747 professionals have used our research since 2012.