{"id":194,"date":"2022-09-12T22:15:59","date_gmt":"2022-09-12T14:15:59","guid":{"rendered":"https:\/\/idez.biz\/?p=194"},"modified":"2022-09-14T10:04:40","modified_gmt":"2022-09-14T02:04:40","slug":"how-to-enable-azure-ad-login-for-a-linux-vm","status":"publish","type":"post","link":"https:\/\/idez.biz\/index.php\/how-to-enable-azure-ad-login-for-a-linux-vm\/","title":{"rendered":"How to enable Azure AD login for a Linux VM"},"content":{"rendered":"\n<p class=\"has-text-align-justify\">Linux VM has been able to authenticate to Active Directory via SSSD (System Security Services Daemon), and there has been many articles talking about this. With the infrastructure going towards cloud, the on-premises domain controller is losing its shine and relevance. <\/p>\n\n\n\n<p class=\"has-text-align-justify\">Microsoft&#8217;s alternative is to enable AD Domain Services, and there are articles readily available on the web to teach you how to do that. This requires the tenant administrator to enable AD Domain Services, which may not be available to you.<\/p>\n\n\n\n<p class=\"has-text-align-justify\">Over the last year, Microsoft has released another capability for Linux VM to integrate with Azure Active Directory, and this <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/devices\/howto-vm-sign-in-azure-ad-linux\">capability <\/a>is now generally available. Do note that there are some differences with joining to a domain controller:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>It uses OpenSSH certificate-based authentication to log in to Linux VM, and hence Putty based clients cannot be used to login to the VM<\/li>\n\n\n\n<li>The SSH authentication is via Azure AD authentication and through the use of short-lived keys which (in my opinion) is more secured. Details of it is found <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/active-directory\/fundamentals\/auth-ssh\">here<\/a>.<\/li>\n\n\n\n<li>Although it uses the RBAC way to configure sudo users, but it is an option for all or none, i.e. If the user is allowed to sudo, it gets administrator rights, if not, then otherwise. In sudo, there are options to sudo to a service account, but that is not available here.<\/li>\n<\/ol>\n\n\n\n<p class=\"has-text-align-justify\">Having stated the differences, let&#8217;s jump into how to configure an Azure hosted VM to authenticate to Azure AD. Although the link shared above do state the steps, I do find some difficulty in following them, so I am sharing what are some of the steps that I have taken.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Ensure that System assigned managed identity is selected<\/h2>\n\n\n\n<p>In the VM properties section, select <strong>Identity<\/strong>, then ensure that the <strong>Status<\/strong> is <strong>On<\/strong>. If it is not on, then turn it on.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"908\" data-attachment-id=\"195\" data-permalink=\"https:\/\/idez.biz\/index.php\/how-to-enable-azure-ad-login-for-a-linux-vm\/image-29\/#main\" data-orig-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image.png\" data-orig-size=\"1882,1669\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-300x266.png\" data-large-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-1024x908.png\" src=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-1024x908.png\" alt=\"\" class=\"wp-image-195\" srcset=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-1024x908.png 1024w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-300x266.png 300w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-768x681.png 768w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-1536x1362.png 1536w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image.png 1882w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Enable AADSSHLoginForLinux extension on the VM<\/h2>\n\n\n\n<p>To enable this extension, select <strong>Extensions + applications<\/strong>, then <strong>Add<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"701\" data-attachment-id=\"198\" data-permalink=\"https:\/\/idez.biz\/index.php\/how-to-enable-azure-ad-login-for-a-linux-vm\/image-3-5\/#main\" data-orig-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3.png\" data-orig-size=\"2466,1687\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-3\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3-300x205.png\" data-large-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3-1024x701.png\" src=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3-1024x701.png\" alt=\"\" class=\"wp-image-198\" srcset=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3-1024x701.png 1024w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3-300x205.png 300w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3-768x525.png 768w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3-1536x1051.png 1536w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-3-2048x1401.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-justify\">The type in <strong>ssh<\/strong>, in the search box, and the <strong>Azure AD based SSH Login<\/strong> will be presented. Click on the box, and <strong>Next<\/strong> will be able to click. Click <strong>Next<\/strong> to continue.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"768\" height=\"1024\" data-attachment-id=\"199\" data-permalink=\"https:\/\/idez.biz\/index.php\/how-to-enable-azure-ad-login-for-a-linux-vm\/image-4-5\/#main\" data-orig-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-4.png\" data-orig-size=\"1279,1706\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-4\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-4-225x300.png\" data-large-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-4-768x1024.png\" src=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-4-768x1024.png\" alt=\"\" class=\"wp-image-199\" srcset=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-4-768x1024.png 768w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-4-225x300.png 225w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-4-1152x1536.png 1152w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-4.png 1279w\" sizes=\"auto, (max-width: 768px) 100vw, 768px\" \/><\/figure>\n\n\n\n<p>Click on <strong>Review + create<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"511\" data-attachment-id=\"202\" data-permalink=\"https:\/\/idez.biz\/index.php\/how-to-enable-azure-ad-login-for-a-linux-vm\/image-6-4\/#main\" data-orig-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-6.png\" data-orig-size=\"1496,747\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-6\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-6-300x150.png\" data-large-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-6-1024x511.png\" src=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-6-1024x511.png\" alt=\"\" class=\"wp-image-202\" srcset=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-6-1024x511.png 1024w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-6-300x150.png 300w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-6-768x383.png 768w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-6.png 1496w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p>After the review is completed, you may click on <strong>Create <\/strong>to add the extension.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"532\" data-attachment-id=\"203\" data-permalink=\"https:\/\/idez.biz\/index.php\/how-to-enable-azure-ad-login-for-a-linux-vm\/image-7-4\/#main\" data-orig-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-7.png\" data-orig-size=\"1487,773\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"image-7\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-7-300x156.png\" data-large-file=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-7-1024x532.png\" src=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-7-1024x532.png\" alt=\"\" class=\"wp-image-203\" srcset=\"https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-7-1024x532.png 1024w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-7-300x156.png 300w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-7-768x399.png 768w, https:\/\/idez.biz\/wp-content\/uploads\/2022\/09\/image-7.png 1487w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"has-text-align-justify\">Once that is completed, you will be able to assign roles to the VM and assign groups of users who are administrators or users.<\/p>\n\n\n\n<p>I hope this has helped you.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Linux VM has been able to authenticate to Active Directory via SSSD (System Security Services Daemon), and there has been many articles talking about this. With the infrastructure going towards cloud, the on-premises domain controller is losing its shine and relevance. Microsoft&#8217;s alternative is to enable AD Domain Services, and there are articles readily available &#8230; <a title=\"How to enable Azure AD login for a Linux VM\" class=\"read-more\" href=\"https:\/\/idez.biz\/index.php\/how-to-enable-azure-ad-login-for-a-linux-vm\/\" aria-label=\"Read more about How to enable Azure AD login for a Linux VM\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[70,14,13],"tags":[47,72,71,73],"class_list":["post-194","post","type-post","status-publish","format-standard","hentry","category-active-directory","category-authentication","category-azure","tag-authentication","tag-azure-active-directory","tag-linux","tag-ssh"],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_likes_enabled":false,"jetpack-related-posts":[],"jetpack_shortlink":"https:\/\/wp.me\/pcj45d-38","_links":{"self":[{"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/posts\/194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/comments?post=194"}],"version-history":[{"count":3,"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/posts\/194\/revisions"}],"predecessor-version":[{"id":205,"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/posts\/194\/revisions\/205"}],"wp:attachment":[{"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/media?parent=194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/categories?post=194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/idez.biz\/index.php\/wp-json\/wp\/v2\/tags?post=194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}