Azure VM RDP doesn't require 'Virtual Machine Admin/User Login' roles despite what documentation says

41 views Asked by At

Microsoft documentation says "To allow a user to sign in to the VM over RDP, you must assign the Virtual Machine Administrator Login or Virtual Machine User Login role to the Virtual Machine resource."

However, this is not the behavior I'm seeing, i.e. created a VM and can RDP to it without having any of the 'Virtual Machine Admin/User Login' roles. This is a problem because I was hoping to use this role assignment for restricting who can access the VM.

Here are more details about how the VM is configured:

  1. Runs Windows 11 image
  2. Created an NSG to restrict IP addresses that can RDP to VM
  3. Microsoft Entra ID is enabled, and the VM is joined to MyDomain domain (Settings > Accounts > Access work or school > Connect > Join this device to Microsoft Entra ID)
  4. Added "NT AUTHORITY\Authenticated Users" to Remote Desktop Users
0

There are 0 answers