SecuryBlack LogoSecuryBlack
← Blog/Security

How to Restrict SSH Access in Linux Using AllowGroups and Dedicated Users

·7 min read
How to Restrict SSH Access in Linux Using AllowGroups and Dedicated Users

On servers with multiple system users (service accounts, deployment tools, developers, or administrators), allowing any user to attempt SSH connections unnecessarily increases the attack surface. To maintain a fortified environment, it is essential to follow a well-defined Linux VPS security and hardening plan.

In this article, you will learn how to use the AllowGroups directive in OpenSSH to define a strict whitelist of users authorized to connect via SSH.


1. The principle of least privilege in SSH

By default, OpenSSH allows any user account created on the operating system (/etc/passwd) that has a valid shell to attempt logging in via SSH.

This means that if an application creates an unprivileged user or a system user without a strong password, an attacker could attempt to exploit that account.

The cleanest solution is the AllowGroups directive: restrict remote access exclusively to users who belong to a specific system group (for example, sshusers).


2. Step 1: Create the SSH security group

Create a new group on the server:

sudo groupadd sshusers

3. Step 2: Add authorized users to the group

Add your regular administrative user to the sshusers group:

sudo usermod -aG sshusers your_username

(Replace your_username with your actual username).

To verify that the user belongs to the group correctly:

groups your_username

4. Step 3: Configure OpenSSH (sshd_config)

Open the SSH daemon configuration file:

sudo nano /etc/ssh/sshd_config

Add the AllowGroups directive at the end of the file:

AllowGroups sshusers

(If you need to allow multiple groups, separate them with spaces, for example: AllowGroups sshusers sudo).


5. Step 4: Validate and restart the SSH service

Before applying the changes, test the syntax to avoid accidental lockouts:

sudo sshd -t

If the command returns no errors, restart the SSH service:

sudo systemctl restart ssh

6. Verifying the restriction

From this moment on:

  1. Users who belong to sshusers will be able to log in normally (using their SSH keys or credentials).
  2. Users who do not belong to sshusers will immediately receive a Permission denied (publickey) message during the SSH handshake, even if their password is valid.

7. Keep user access under control with SecuryBlack

Managing access permissions and auditing user accounts across multiple VPS servers can become complex over time.

With the SecuryBlack cloud dashboard and the open-source FerroSentry auditor agent, you get full visibility over your VPS user accounts, groups with sudo permissions, and SSH access configuration from a single centralized dashboard.