Review Azure VM network-interface attachment

Attach a valid NIC and configure subnet, NSG and routing controls separately.

Description

An Azure VM connects to a subnet and network paths through a network interface. Without a required NIC it cannot be deployed or communicate normally. Attaching a NIC does not automatically configure an NSG or secure access rules.

Potential impact

  • VM deployment, communication or management can fail.
  • Attaching a NIC without reviewing security rules can allow unintended access.

Remediation

  • Attach a valid NIC through network_interface_ids and configure the correct subnet and IP settings. Use resource references to express Terraform dependencies.
  • Review NSGs on the NIC or subnet and the routes, allowing only required traffic. Protect administrator authentication separately.

Examples

These excerpts compare network attachment on the legacy azurerm_virtual_machine resource. OS disks, images and credentials are omitted. The retained password-authentication setting needs separate review.

Before

hcl
resource "azurerm_virtual_machine" "example" {
  name                  = "${var.prefix}-vm"
  location              = azurerm_resource_group.main.location
  resource_group_name   = azurerm_resource_group.main.name
  network_interface_ids = []
  vm_size               = "Standard_DS1_v2"

  os_profile_linux_config {
    disable_password_authentication = false
  }
}

After

hcl
resource "azurerm_network_interface" "example" {
  name                = "${var.prefix}-nic"
  location            = azurerm_resource_group.main.location
  resource_group_name = azurerm_resource_group.main.name

  ip_configuration {
    name                          = "testconfiguration1"
    subnet_id                     = azurerm_subnet.internal.id
    private_ip_address_allocation = "Dynamic"
  }
}

resource "azurerm_virtual_machine" "example" {
  name                  = "${var.prefix}-vm"
  location              = azurerm_resource_group.main.location
  resource_group_name   = azurerm_resource_group.main.name
  network_interface_ids = [azurerm_network_interface.example.id]
  vm_size               = "Standard_DS1_v2"

  os_profile_linux_config {
    disable_password_authentication = false
  }
}

Explanation:

  • Before: The NIC list is empty, leaving required VM networking absent.
  • After: A NIC is created and attached. Configure NSGs and access rules separately.

References