How to Restrict SSH Access in Linux Using AllowGroups and Dedicated Users
On servers with multiple system users (service accounts, deployment tools, developers, or administrators), allowing any user to attempt SSH connections unnecessarily increases the attack surface. To maintain a fortified environment, it is essential to follow a well-defined Linux VPS security and hardening plan.
In this article, you will learn how to use the AllowGroups directive in OpenSSH to define a strict whitelist of users authorized to connect via SSH.
1. The principle of least privilege in SSH
By default, OpenSSH allows any user account created on the operating system (/etc/passwd) that has a valid shell to attempt logging in via SSH.
This means that if an application creates an unprivileged user or a system user without a strong password, an attacker could attempt to exploit that account.
The cleanest solution is the AllowGroups directive: restrict remote access exclusively to users who belong to a specific system group (for example, sshusers).
2. Step 1: Create the SSH security group
Create a new group on the server:
sudo groupadd sshusers
3. Step 2: Add authorized users to the group
Add your regular administrative user to the sshusers group:
sudo usermod -aG sshusers your_username
(Replace your_username with your actual username).
To verify that the user belongs to the group correctly:
groups your_username
4. Step 3: Configure OpenSSH (sshd_config)
Open the SSH daemon configuration file:
sudo nano /etc/ssh/sshd_config
Add the AllowGroups directive at the end of the file:
AllowGroups sshusers
(If you need to allow multiple groups, separate them with spaces, for example: AllowGroups sshusers sudo).
5. Step 4: Validate and restart the SSH service
Before applying the changes, test the syntax to avoid accidental lockouts:
sudo sshd -t
If the command returns no errors, restart the SSH service:
sudo systemctl restart ssh
6. Verifying the restriction
From this moment on:
- Users who belong to
sshuserswill be able to log in normally (using their SSH keys or credentials). - Users who do not belong to
sshuserswill immediately receive aPermission denied (publickey)message during the SSH handshake, even if their password is valid.
7. Keep user access under control with SecuryBlack
Managing access permissions and auditing user accounts across multiple VPS servers can become complex over time.
With the SecuryBlack cloud dashboard and the open-source FerroSentry auditor agent, you get full visibility over your VPS user accounts, groups with sudo permissions, and SSH access configuration from a single centralized dashboard.