Review administrator SSH keys for Azure VMs

Configure approved administrator authentication and test key access before restricting password authentication.

Description

Prefer protected SSH keys for Linux VM administration. Keys or authentication may also be configured through other mechanisms when admin_ssh_key is absent, so verify the actual access method. If access relies on passwords, manage the risks of guessing, reuse and disclosure.

Potential impact

  • Weak or reused administrator passwords can be exploited to compromise accounts.
  • Disabling passwords before confirming key deployment can lock out administrators.

Remediation

  • When using SSH keys, configure an approved admin_ssh_key and username. Use an Ed25519 or at least 2048-bit RSA public key supported by current AzureRM, and protect the private key.
  • Test actual key access before disabling unnecessary password authentication. Manage and revoke per-user keys, and check Terraform VM-replacement plans when keys change.

Examples

These excerpts compare administrator authentication only; OS disks and images are omitted. Replace the public-key file path with an actual approved key.

Before

hcl
resource "azurerm_linux_virtual_machine" "example" {
  name                            = "example-vm"
  resource_group_name             = azurerm_resource_group.example.name
  location                        = azurerm_resource_group.example.location
  size                            = "Standard_F2"
  admin_username                  = "adminuser"
  admin_password                  = var.admin_password
  disable_password_authentication = false
  network_interface_ids           = [azurerm_network_interface.example.id]
}

After

hcl
resource "azurerm_linux_virtual_machine" "example" {
  name                            = "example-vm"
  resource_group_name             = azurerm_resource_group.example.name
  location                        = azurerm_resource_group.example.location
  size                            = "Standard_F2"
  admin_username                  = "adminuser"
  disable_password_authentication = true
  network_interface_ids           = [azurerm_network_interface.example.id]

  admin_ssh_key {
    username   = "adminuser"
    public_key = file("/secure/path/id_ed25519.pub")
  }
}

Explanation:

  • Before: Password authentication is allowed and a password input is used.
  • After: An administrator public key is specified and password authentication is disabled.

References