Azure NSG does not restrict SSH sources

Restrict SSH access in Azure NSGs to required management addresses.

Description

An Azure NSG rule allowing inbound TCP port 22 from source * does not restrict SSH source addresses.

Potential impact

An SSH service reachable through a public route can be exposed to unnecessary login attempts and password guessing.

Remediation

Limit sources to required management IP addresses or subnets, or use a management path such as Azure Bastion. Check associated NSGs and rule priorities together.

Examples

Replace the documentation address 203.0.113.10/32 with the actual management address. Reachability depends on routing and the complete set of effective rules.

Before

bicep
resource security_group 'Microsoft.Network/networkSecurityGroups@2020-11-01' = {
  name: 'security-group'
  location: resourceGroup().location
  properties: {
    securityRules: [
      {
        properties: {
          protocol: 'Tcp'
          sourcePortRange: '*'
          destinationPortRange: '22'
          sourceAddressPrefix: '*'
          destinationAddressPrefix: '*'
          access: 'Allow'
          priority: 301
          direction: 'Inbound'
        }
        name: 'security-rule'
      }
    ]
  }
}

After

bicep
resource security_group 'Microsoft.Network/networkSecurityGroups@2020-11-01' = {
  name: 'security-group'
  location: resourceGroup().location
  properties: {
    securityRules: [
      {
        properties: {
          protocol: 'Tcp'
          sourcePortRange: '*'
          destinationPortRange: '22'
          sourceAddressPrefix: '203.0.113.10/32'
          destinationAddressPrefix: '*'
          access: 'Allow'
          priority: 301
          direction: 'Inbound'
        }
        name: 'security-rule'
      }
    ]
  }
}

References