Azure NSG allows broad RDP access

Restrict Azure NSG RDP access to approved administration paths and verify the VM’s actual connectivity and authentication settings.

Description

An NSG that allows TCP port 3389 from every source can let clients attempt RDP connections where the rule applies and a network path exists. External reachability also depends on NSG associations, rule priority, VM addresses, routing and the host firewall.

Restrict administrative RDP access to approved administrator addresses or controlled paths such as a VPN or Azure Bastion. Strong authentication and security updates remain necessary alongside network restrictions.

Potential impact

  • A reachable RDP service can receive more brute-force attempts or sign-in attempts using leaked credentials.
  • Service vulnerabilities or weak authentication may enable compromise of the VM and connected resources.

Remediation

  • Remove unnecessary all-source access and allow only sources required by the actual administration path. Prepare an alternative management connection before changing access.
  • Review effective NSG rules on the NIC and subnet, their priorities, and IPv4 and IPv6 access. A higher-priority allow rule takes effect before a later deny rule.
  • Test approved administrative access and blocked unwanted connections. Review VM authentication, patches and logs.

Examples

These alternatives configure rules on the same NSG; they do not associate it with a NIC or subnet. Review the required management path and any higher-priority, narrowly scoped allow rules separately.

Before

bicep
resource security_group 'Microsoft.Network/networkSecurityGroups@2020-11-01' = {
  name: 'rdp-security-group'
  location: resourceGroup().location
  tags: {}
  properties: {
    securityRules: [
      {
        properties: {
          description: 'access to RDP'
          protocol: 'Tcp'
          sourcePortRange: '*'
          destinationPortRange: '3389'
          sourceAddressPrefix: '*'
          destinationAddressPrefix: '*'
          access: 'Allow'
          priority: 301
          direction: 'Inbound'
        }
        name: 'rdp-rule'
      }
    ]
  }
}

Where this rule applies, it allows TCP port 3389 from every source.

After

bicep
resource security_group 'Microsoft.Network/networkSecurityGroups@2020-11-01' = {
  name: 'rdp-security-group'
  location: resourceGroup().location
  tags: {}
  properties: {
    securityRules: [
      {
        properties: {
          description: 'access to RDP'
          protocol: 'Tcp'
          sourcePortRange: '*'
          destinationPortRange: '3389'
          sourceAddressPrefix: '*'
          destinationAddressPrefix: '*'
          access: 'Deny'
          priority: 301
          direction: 'Inbound'
        }
        name: 'rdp-rule'
      }
    ]
  }
}

This denies TCP port 3389 traffic that has not matched a higher-priority rule. Before applying it, check that required management access will remain available.

References