Maintained with ☕️ by
IcePanel logo

Public Preview: Managed identity support for graphical session recording

Share

Services

Today, we are announcing Azure Bastion now supports managed identities for graphical session recording. Azure Bastion graphical session recording now supports write access to storage accounts using managed identities. With this update, users have the option to configure managed identities during session recording setup and specify the storage account container for storing VM recordings. Once the managed identity is authenticated to WRITE recordings to the storage container, Azure Bastion will authenticate without requiring a SAS token. * Stronger security posture: Removes shared, time‑bound SAS URLs in favor of identity‑based authorization tied to the Bastion resource. * Reduced operational overhead: Eliminates token creation, rotation, and expiry management, making session recording easier to operate at scale. [Learn more](https://review.learn.microsoft.com/en-us/azure/bastion/session-recording?branch=pr-en-us-310197&tabs=msi).