Password authentication is allowed for an Azure Linux VM

Prepare SSH-key access before disabling password logins that are not needed.

Description

Password authentication on a Linux VM requires protection against guessing, reuse and disclosure. Allowing passwords does not prevent SSH-key use and does not by itself expose the VM to the internet. Prefer protected SSH keys for operational access.

Potential impact

  • Weak or reused passwords can be exploited to compromise the administrator account.
  • Broadly exposed SSH access can attract automated login attempts.

Remediation

  • Register an approved admin_ssh_key and test key-based access before setting disable_password_authentication = true. Check whether the Terraform plan replaces the VM.
  • Protect private keys and revoke unused keys. Restrict the network sources permitted to reach administrative access.

Examples

These excerpts compare authentication only. They use the current Linux VM size argument and the same NIC; OS-disk and image settings are omitted. Supply an approved password input and actual public-key file.

Before

hcl
resource "azurerm_linux_virtual_machine" "example" {
  name                            = "${var.prefix}-vm"
  location                        = azurerm_resource_group.main.location
  resource_group_name             = azurerm_resource_group.main.name
  network_interface_ids           = [azurerm_network_interface.main.id]
  size                         = "Standard_DS1_v2"
  admin_username                  = "adminuser"
  admin_password                  = var.admin_password
  disable_password_authentication = false
}

After

hcl
resource "azurerm_linux_virtual_machine" "example" {
  name                  = "${var.prefix}-vm"
  location              = azurerm_resource_group.main.location
  resource_group_name   = azurerm_resource_group.main.name
  network_interface_ids = [azurerm_network_interface.main.id]
  size               = "Standard_DS1_v2"

  admin_username                  = "adminuser"
  disable_password_authentication = true

  admin_ssh_key {
    username   = "adminuser"
    public_key = file("~/.ssh/id_rsa.pub")
  }
}

Explanation:

  • Before: Password authentication is allowed.
  • After: An administrator public key is registered and password authentication is disabled.

References