Some lock operators must use a local SSH or RDP client instead of only the Azure portal browser. Which Bastion capability should the security engineer select?
Select an answer to reveal the explanation.
Short Explanation
Portal browser is fine for some shifts; others want their own SSH/RDP app. Pick the Bastion SKU that unlocks native client—still TLS through Bastion, still no public IP on the VM.
Full Explanation
Azure Bastion supports portal-based browser sessions and, with the appropriate SKU and features, native client connectivity (and related options such as IP-based connection) while traffic remains TLS-brokered through Bastion. Selecting that capability is a security-engineer feature choice for operators who must use local SSH or RDP clients. Re-exposing public management ports or replacing Bastion with an unrelated VDI design is not the intended remote-access control for private VMs in this bullet.