The most simple solution is to host a jumpbox on the virtual network of the data management landing zone or data landing zone to connect to the data services through private endpoints. Azure Bastion provides a few other core security benefits, including: * The service integrates with native security appliances for an Azure virtual network, such as Azure Firewall. Note: * Platform landing zones: Subscriptions deployed to provide centralized services, often operated by a central team, or a number of central teams split by function (e.g. networking, identity), which will be used by various workloads and applications. Platform landing zones represent key services that often benefit from being consolidated for efficiency and ease of operations. Examples include networking, identity, and management services. * The Azure App Service landing zone accelerator is an open-source collection of architectural guidance and reference implementation to accelerate deployment of Azure App Service at scale. It can provide a specific architectural approach and reference implementation via infrastructure as code templates to prepare your landing zones. The landing zones adhere to the architecture and best practices of the Cloud Adoption Framework. Reference: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/scenarios/cloud-scale- analytics/architectures/connect-to-environments-privately https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/ready/landing-zone/ https://learn.microsoft.com/en-us/security/benchmark/azure/overview-v3 https://learn.microsoft.com/en-us/azure/architecture/framework/