Need to understand Azure Standard Bastion pricing

Varishh Bahl 0 Reputation points
2023-04-11T14:49:21.3433333+00:00

Hello , I need some help in identifying the costs incurred on one of our bastion which is standard sku and I noticed that the instance count was increased to 22.. I checked the activity logs and couldnt get any info on who /when it was increased. Also I noticed that there was a component called standard additional gateway which was incurring majority of the cost for bastion. Can someone please clarify how this gateway functions and will reducing the instance count reduce the billing.

Azure Bastion
Azure Bastion
An Azure service that provides private and fully managed Remote Desktop Protocol (RDP) and Secure Shell (SSH) access to virtual machines.
247 questions
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 24,231 Reputation points Microsoft Employee
    2023-04-12T00:37:41.35+00:00

    @Varishh Bahl Welcome to the Microsoft Q&A forum. Based on your questions above:

    Also I noticed that there was a component called standard additional gateway which was incurring majority of the cost for bastion. Can someone please clarify how this gateway functions and will reducing the instance count reduce the billing.

    Azure Bastion pricing is a combination of SKU selected, number of scale units configured, and data transfer rates. For the latest pricing information, see the Azure Bastion pricing page. Yes, reducing the instance count will reduce cost of Azure Bastion resources. The standard additional gateway component refers to the charge acquired due to these additional instance count.

    I checked the activity logs and couldnt get any info on who /when it was increased.

    I did a test regarding this and I was able to see this update in my bastions activity logs. I increased the instance count from 2 to 6. Below is the Activity log screenshot
    User's image

    Possible reason you might not be able to view the log might be due to the retention period of the activity logs. Activity log events are retained in Azure for 90 days and then deleted. For more functionality, such as longer retention, create a diagnostic setting and route the entries to another location based on your needs. This is documented here. Please let me know if you need any additional information here. To prevent this issue in future, you can explore RBAC roles available in Azure which is an authorization system you use to manage access to Azure resources. These are the required roles to access a virtual machine via Bastion resource. Additional reference https://video2.skills-academy.com/en-us/azure/role-based-access-control/rbac-and-directory-admin-roles#azure-roles Just in case if you need any additional assistance regarding any billing issue. You can create a billing related support request as Azure provides Billing and Subscription management support for all the customers. More information here : https://azure.microsoft.com/en-us/support Hope this helps! Please let me know if you have any questions. Thank you!​​ Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments