Linux VM login with Entra ID, PIM, and Azure Bastion

Overview

This pattern allows operators to SSH to Azure Linux virtual machines using their Microsoft Entra ID identity instead of local VM accounts or long-lived SSH keys.

The access path looks like this:

  1. A Linux VM has the AADSSHLoginForLinux extension installed.
  2. Entra ID security groups are created for the required access levels.
  3. Users are made eligible for those groups through Privileged Identity Management.
  4. Azure RBAC grants the groups VM login rights.
  5. Reader access is granted on the resource group so users can discover the VM and related network resources.
  6. Users connect through Azure Bastion with --auth-type AAD.

The result is a clean just-in-time access flow: users activate access in PIM, authenticate with Entra ID, and connect privately through Bastion without exposing SSH to the internet.

Components

Linux VM extension

The Linux server needs the Microsoft Entra login extension:

AADSSHLoginForLinux

This extension integrates SSH login with Entra ID. When a user connects, the VM validates the Entra token and maps the user’s Azure RBAC login role to the local Linux access level.

Microsoft documentation: Sign in to a Linux virtual machine in Azure by using Microsoft Entra ID and OpenSSH

Entra ID security groups

Create separate Entra ID security groups for each access level.

Example:

sg-vm-linux-user-login
sg-vm-linux-admin-login

Using groups instead of direct user assignments keeps Azure RBAC clean. The VM and resource group only need role assignments for the groups, while user access is controlled by group membership.

Privileged Identity Management

Users should not be permanent members of the VM access groups.

Instead, add users as eligible members in Privileged Identity Management. When someone needs access, they activate the relevant group membership for a limited period.

Typical flow:

  1. User opens PIM.
  2. User activates membership in the VM login group.
  3. PIM applies the temporary group membership.
  4. User connects to the VM using Entra authentication.
  5. Access expires automatically when the PIM activation ends.

This gives the team just-in-time access with approval, MFA, justification, and auditability depending on the PIM policy.

Azure RBAC assignments

Two Azure built-in roles control the Linux login level.

RolePurpose
Virtual Machine User LoginAllows standard, non-admin login to the VM.
Virtual Machine Administrator LoginAllows administrator-level login to the VM.

Assign these roles to the Entra ID groups, not directly to users.

Example role model:

Entra ID groupAzure role
sg-vm-linux-user-loginVirtual Machine User Login
sg-vm-linux-admin-loginVirtual Machine Administrator Login

Microsoft recommends assigning these roles at the resource group, subscription, or management group level rather than on individual VMs. The assignment scope must include the VM and its associated resources such as the virtual network, network interface, public IP, or load balancer.

Reader access requirement

In addition to the VM login role, users usually need Reader access on the resource group that contains the VM and related resources.

This does not grant operating system access. It allows Azure Portal, Azure CLI, and Bastion workflows to read the VM and network metadata needed to start the connection.

Without Reader access, the user may have the correct VM login role but still fail to select, resolve, or connect to the VM because Azure cannot read supporting resources such as the network interface.

Recommended baseline:

ScopeRoleAssignee
VM resource groupReaderLogin security group or a separate reader group
VM resource groupVirtual Machine User LoginUser login group
VM resource groupVirtual Machine Administrator LoginAdmin login group

Bastion connection

After the user activates the required PIM group membership, they can connect through Azure Bastion using Entra ID authentication.

Example:

az network bastion ssh \
  --name bas-example-region \
  --subscription 00000000-0000-0000-0000-000000000000 \
  --resource-group rg-example-connectivity \
  --target-resource-id "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-example-vms/providers/Microsoft.Compute/virtualMachines/vm-linux-example" \
  --auth-type AAD

Important details:

  • --name is the Bastion host name.
  • --resource-group is the resource group where the Bastion host lives.
  • --target-resource-id is the full Azure resource ID of the VM.
  • --auth-type AAD tells Bastion and SSH to use Microsoft Entra authentication.

Microsoft documentation: Connect to a VM using Bastion and the native client

Why this is useful

This design removes a lot of old SSH access pain.

  • No shared local Linux accounts.
  • No standing SSH private keys to distribute or rotate.
  • No inbound SSH exposure from the internet.
  • Access can require PIM activation before login.
  • Azure RBAC controls who can log in and at what privilege level.
  • Entra ID sign-in logs and PIM audit history give better traceability.

It also separates responsibilities cleanly:

LayerControl
IdentityEntra ID user account
EligibilityPIM group assignment
AuthorizationAzure RBAC login role
Network pathAzure Bastion
OS integrationAADSSHLoginForLinux extension

Troubleshooting checklist

If login does not work, check the following:

  1. The VM has the AADSSHLoginForLinux extension installed and healthy.
  2. The user activated the correct PIM group membership.
  3. The activated group has either Virtual Machine User Login or Virtual Machine Administrator Login.
  4. The user or group has Reader access on the VM resource group.
  5. The role assignment scope includes the VM and its related network resources.
  6. The Bastion host supports native client connections.
  7. The connection uses --target-resource-id, not only a private IP address, when using Entra ID authentication.
  8. Azure CLI and the Bastion extension are up to date.

Mental model

Think of the setup as three gates:

  1. PIM decides whether the user is currently in the access group.
  2. Azure RBAC decides whether that group can log in as a user or administrator.
  3. Bastion provides the private SSH transport path to the VM.

All three gates need to line up before the login succeeds.