Description
An Azure network security rule that allows connections to the RDP port from every address can expose the management service more broadly than necessary. If external clients can actually connect, it may face password guessing, use of leaked credentials or exploitation of vulnerabilities.
Actual connectivity depends on NSG associations and effective rule priorities, routing, host firewalls and the RDP service state. Network permission alone does not authorize a login.
Potential impact
- The service may receive unnecessary external RDP login attempts.
- Compromise of an account or service can lead to access to the system and internal resources.
Remediation
Remove unnecessary RDP allow rules and permit only approved management addresses where access is required. Use a management path such as Azure Bastion or a VPN, and apply the same access intent in NSGs and host firewalls. Verify that required administrative connections succeed and connections from unapproved addresses are blocked.
Examples
This narrows only the allowed source on the same rule. Replace 10.20.0.0/24 with the actual approved management network and provide its connectivity path.
Before
resource "azurerm_network_security_rule" "rdp_open" {
name = "allow-rdp"
priority = 100
direction = "Inbound"
access = "Allow"
protocol = "TCP"
source_port_range = "*"
destination_port_range = "3389"
source_address_prefix = "*"
destination_address_prefix = "*"
resource_group_name = azurerm_resource_group.example.name
network_security_group_name = azurerm_network_security_group.example.name
}
This permits TCP 3389 connections from all sources.
After
resource "azurerm_network_security_rule" "rdp_open" {
name = "allow-rdp"
priority = 100
direction = "Inbound"
access = "Allow"
protocol = "TCP"
source_port_range = "*"
destination_port_range = "3389"
source_address_prefix = "10.20.0.0/24"
destination_address_prefix = "*"
resource_group_name = azurerm_resource_group.example.name
network_security_group_name = azurerm_network_security_group.example.name
}
This restricts sources to the management subnet. Verify that its users need RDP access and that no other broad allow rule defeats the restriction.