Linux VM login with Entra ID, PIM, and Azure Bastion
Overview
This pattern allows operators to SSH to Azure Linux virtual machines using their Microsoft Entra ID identity instead of local VM accounts or long-lived SSH keys.
The access path looks like this:
- A Linux VM has the
AADSSHLoginForLinuxextension installed. - Entra ID security groups are created for the required access levels.
- Users are made eligible for those groups through Privileged Identity Management.
- Azure RBAC grants the groups VM login rights.
- Reader access is granted on the resource group so users can discover the VM and related network resources.
- Users connect through Azure Bastion with
--auth-type AAD.
The result is a clean just-in-time access flow: users activate access in PIM, authenticate with Entra ID, and connect privately through Bastion without exposing SSH to the internet.
Components
Linux VM extension
The Linux server needs the Microsoft Entra login extension:
AADSSHLoginForLinuxThis extension integrates SSH login with Entra ID. When a user connects, the VM validates the Entra token and maps the user’s Azure RBAC login role to the local Linux access level.
Microsoft documentation: Sign in to a Linux virtual machine in Azure by using Microsoft Entra ID and OpenSSH
Entra ID security groups
Create separate Entra ID security groups for each access level.
Example:
sg-vm-linux-user-login
sg-vm-linux-admin-loginUsing groups instead of direct user assignments keeps Azure RBAC clean. The VM and resource group only need role assignments for the groups, while user access is controlled by group membership.
Privileged Identity Management
Users should not be permanent members of the VM access groups.
Instead, add users as eligible members in Privileged Identity Management. When someone needs access, they activate the relevant group membership for a limited period.
Typical flow:
- User opens PIM.
- User activates membership in the VM login group.
- PIM applies the temporary group membership.
- User connects to the VM using Entra authentication.
- Access expires automatically when the PIM activation ends.
This gives the team just-in-time access with approval, MFA, justification, and auditability depending on the PIM policy.
Azure RBAC assignments
Two Azure built-in roles control the Linux login level.
| Role | Purpose |
|---|---|
Virtual Machine User Login | Allows standard, non-admin login to the VM. |
Virtual Machine Administrator Login | Allows administrator-level login to the VM. |
Assign these roles to the Entra ID groups, not directly to users.
Example role model:
| Entra ID group | Azure role |
|---|---|
sg-vm-linux-user-login | Virtual Machine User Login |
sg-vm-linux-admin-login | Virtual Machine Administrator Login |
Microsoft recommends assigning these roles at the resource group, subscription, or management group level rather than on individual VMs. The assignment scope must include the VM and its associated resources such as the virtual network, network interface, public IP, or load balancer.
Reader access requirement
In addition to the VM login role, users usually need Reader access on the resource group that contains the VM and related resources.
This does not grant operating system access. It allows Azure Portal, Azure CLI, and Bastion workflows to read the VM and network metadata needed to start the connection.
Without Reader access, the user may have the correct VM login role but still fail to select, resolve, or connect to the VM because Azure cannot read supporting resources such as the network interface.
Recommended baseline:
| Scope | Role | Assignee |
|---|---|---|
| VM resource group | Reader | Login security group or a separate reader group |
| VM resource group | Virtual Machine User Login | User login group |
| VM resource group | Virtual Machine Administrator Login | Admin login group |
Bastion connection
After the user activates the required PIM group membership, they can connect through Azure Bastion using Entra ID authentication.
Example:
az network bastion ssh \
--name bas-example-region \
--subscription 00000000-0000-0000-0000-000000000000 \
--resource-group rg-example-connectivity \
--target-resource-id "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/rg-example-vms/providers/Microsoft.Compute/virtualMachines/vm-linux-example" \
--auth-type AADImportant details:
--nameis the Bastion host name.--resource-groupis the resource group where the Bastion host lives.--target-resource-idis the full Azure resource ID of the VM.--auth-type AADtells Bastion and SSH to use Microsoft Entra authentication.
Microsoft documentation: Connect to a VM using Bastion and the native client
Why this is useful
This design removes a lot of old SSH access pain.
- No shared local Linux accounts.
- No standing SSH private keys to distribute or rotate.
- No inbound SSH exposure from the internet.
- Access can require PIM activation before login.
- Azure RBAC controls who can log in and at what privilege level.
- Entra ID sign-in logs and PIM audit history give better traceability.
It also separates responsibilities cleanly:
| Layer | Control |
|---|---|
| Identity | Entra ID user account |
| Eligibility | PIM group assignment |
| Authorization | Azure RBAC login role |
| Network path | Azure Bastion |
| OS integration | AADSSHLoginForLinux extension |
Troubleshooting checklist
If login does not work, check the following:
- The VM has the
AADSSHLoginForLinuxextension installed and healthy. - The user activated the correct PIM group membership.
- The activated group has either
Virtual Machine User LoginorVirtual Machine Administrator Login. - The user or group has
Readeraccess on the VM resource group. - The role assignment scope includes the VM and its related network resources.
- The Bastion host supports native client connections.
- The connection uses
--target-resource-id, not only a private IP address, when using Entra ID authentication. - Azure CLI and the Bastion extension are up to date.
Mental model
Think of the setup as three gates:
- PIM decides whether the user is currently in the access group.
- Azure RBAC decides whether that group can log in as a user or administrator.
- Bastion provides the private SSH transport path to the VM.
All three gates need to line up before the login succeeds.