you have an azure subscription that contains a virtual network named vnet1. vnet1 uses the following address spaces: 10.10.1.0/24 10.10.2.0/28 vnet1 contains the following subnets: subnet1- has an address space of 10.10.1.0/24 subnet2- has an address space of 10.10.2.0/28 to subnet1, you deploy a virtual machine named vm1 that runs windows server 2022. vm1 has remote desktop enabled. vm1 does not have a public ip address. you need to be able to deploy azure bastion to protect vm1. what should you do first?