
Explanation:
Box 1: Microsoft Defender for Cloud
Restrict access to the virtual machines based on an originating IP address or a connection request by using just-in-time (JIT) VM access network- based controls.
Microsoft Defender for Cloud offers JIT. With JIT, you can lock down the inbound traffic to your VMs, reducing exposure to attacks while providing easy access to connect to VMs when needed.
Box 2: Microsoft Entra Privileged Identity Management (PIM)
Restrict access to the virtual machines based on role-based access control (RBAC) role assignments by using JIT VM access authorization controls.
Multilayered protection for Azure virtual machine access
This solution offers a multilayered strategy for protecting virtual machines (VMs) in Azure. Users need to connect to VMs for management and administrative purposes. It's crucial to maintain accessibility while minimizing the attack surface.
Reference:
https://learn.microsoft.com/en-us/azure/defender-for-cloud/just-in-time-access-overview
https://learn.microsoft.com/en-us/azure/architecture/solution-ideas/articles/multilayered- protection-azure-vm