SSH is the usual way to administer an Azure Linux virtual machine from a terminal. The direct method requires a running VM, an SSH key pair, a reachable IP address, and an inbound Network Security Group (NSG) rule for the port SSH uses. A public IP is needed for direct Internet access, but it is not the only connection path: Azure Bastion, a VPN, ExpressRoute, peering, or another approved private network route can reach a VM without a public IP.
This guide covers the Azure portal, standard OpenSSH clients, Azure CLI, Microsoft Entra ID authentication, and the checks that explain common connection failures.
Before you connect
Confirm these items first:
- The VM is running. In the Azure portal, open Virtual machines > your VM and check Overview > Essentials > Status.
- You know the Linux username created on the VM.
- You have the matching private SSH key, or the VM is configured for Microsoft Entra ID login.
- You know the VM’s public IP address or DNS name for a direct connection.
- The NSG allows inbound TCP traffic on the SSH port. TCP 22 is the default, but a custom port may be configured.
Do not confuse the VM’s private IP with its public IP. A private address such as 10.0.1.4 is usable only from a machine that has network connectivity to the Azure virtual network.
Find the VM connection details in the Azure portal
- Sign in to the Azure portal.
- Open Virtual machines, then select the Linux VM.
- On the VM’s Overview page, note the Public IP address, if one is assigned.
- Select Connect > Native SSH.
- Review the connection information and run the VM Access check if it is offered. This check uses the VM’s configured settings to identify access problems.
If the VM has no public IP, select an appropriate private connection option such as Azure Bastion, or connect from a host that can route to the VM’s private address.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
- 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
- Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
- Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
- PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
- Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5
Connect with standard SSH and an existing key
Linux, macOS, WSL, and current Windows installations generally include an OpenSSH client. From a terminal, use:
ssh USERNAME@EXTERNAL_IP
For example:
ssh azureuser@20.51.230.13
Replace azureuser with the account created on the VM and replace the address with the VM’s actual public IP. If SSH listens on a nonstandard port, add -p:
ssh -p 2222 azureuser@20.51.230.13
The NSG must allow the same port. Allowing TCP 22 does not permit a connection to TCP 2222.
Connect with a specific private key
If the key is not in the SSH client’s normal search path, specify it with -i:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsssh -i ~/.ssh/myKey.pem azureuser@20.51.230.13
In Windows PowerShell, the equivalent is:
ssh -i .DownloadsmyKey.pem azureuser@20.51.230.13
The file does not have to be named myKey.pem. Azure-generated or downloaded keys may be named id_rsa, use an ED25519 format, or have another filename. The important requirement is that the private key matches the public key installed for that Linux user.
Prepare a downloaded key on Linux, macOS, or WSL
A portal-downloaded key may be in your Downloads directory. Move it into your SSH directory and restrict its permissions:
mv /Downloads/myKey.pem ~/.ssh/
chmod 400 ~/.ssh/myKey.pem
In WSL, a Windows Downloads directory is normally available under /mnt/c:
mv /mnt/c/Users/USERNAME/Downloads/myKey.pem ~/.ssh/
chmod 400 ~/.ssh/myKey.pem
Replace USERNAME with your Windows account name. OpenSSH can refuse a private key that other local users can read, producing an error such as “permissions are too open.”
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #2
- Cat 6 performance at a Cat5e price but with higher bandwidth
- High Performance Cat6, 30 AWG, RJ45 Ethernet Patch Cable provides universal connectivity for LAN network components such as PCs,computer servers,printers,routers,switch boxes,network media players,NAS,VoIP phones
- Jadaol cat6 standard cable support Cat8 and Cat7 network and provides performance of up to 250 MHz 10Gbps and is suitable for 10BASE-T, 100BASE-TX (Fast Ethernet), 1000BASE-T/1000BASE-TX (Gigabit Ethernet) and 10GBASE-T (10-Gigabit Ethernet)
- UTP(Unshielded Twisted Pair) patch cable with RJ45 gold-plated Connectors and are made of 100% bare copper wire, ensure minimal noise and interference
- The unique flat cable shape allows for a cleaner and safer installation. You can easily and seamlessly make the cable run along walls, follow edges & corners or even make it completely invisible by sliding it under a carpet.
Verify the host fingerprint
On the first connection from an SSH client, OpenSSH displays the VM’s host fingerprint and asks whether you want to continue. Do not automatically accept an unexpected fingerprint: validating it helps protect against a man-in-the-middle attack.
To retrieve the VM’s ECDSA fingerprint, use the Azure portal’s Run Command:
- Open the VM in the Azure portal.
- Select Operations > Run Command.
- Choose RunShellScript.
- Run:
ssh-keygen -lf /etc/ssh/ssh_host_ecdsa_key.pub | awk '{print $2}'
Compare the result with the fingerprint shown by your local SSH client. Fingerprint verification is normally required only the first time that particular client connects to the VM.
Use password authentication
If the VM was created with password authentication enabled, the command is still:
ssh azureuser@20.51.230.13
SSH then prompts for the account password. Microsoft recommends SSH-key authentication instead because passwords are less secure and are more exposed to guessing and credential-reuse attacks.
If you have forgotten the username, password, or SSH key, open the VM and select Help > Reset password. The available modes include:
- Reset configuration only
- Reset SSH public key
- Reset password
Enter the required values and select Update. This page can also create a new sudo-capable user.
Connect with Azure CLI
The Azure CLI SSH extension can locate the VM and establish a connection without manually copying its public IP:
Rank #3
- Designed for Outdoor & Direct Burial Installations – Heavy-duty double-shielded Cat8 Ethernet cable minimizes EMI/RFI interference and delivers stable long-distance performance. Waterproof, anti-corrosion PVC jacket allows safe direct burial and reliable use in outdoor or indoor environments.
- 26AWG for Stable High-Load Networks – Thicker 26AWG conductors provide faster, more stable data transmission than standard 32AWG cables. Ideal for high-performance home networks, gaming setups, smart homes, and data-intensive applications.
- F/FTP Shielding & Hyper-Speed Performance: Cat8 Ethernet cable constructed with 4 shielded foiled twisted pairs and 26AWG OFC conductors; supports bandwidth up to 2000 MHz and data transmission speeds up to 40 Gbps, effectively reducing signal interference and ensuring stable connections. Ideal for low-latency gaming, 4K/8K streaming, and high-speed internet connections.
- RJ45 Connectors & Wide Compatibility: Cat8 Ethernet cable with two shielded RJ45 connectors; compatible with networking switches, IP cameras, routers, Nintendo Switch, modems, PS3, PS4, Xbox, patch panels, servers, smart TVs, and more; works with Cat7, Cat6, Cat5e, and Cat5 devices
- Weatherproof & UV Resistant: Outdoor-rated Cat8 Ethernet cable with UV-resistant PVC jacket; withstands direct sunlight, extreme cold, humidity, and hot weather; anti-aging and durable; Includes 18-month support.
az ssh vm -n myVM -g myResourceGroup
The az ssh commands are supplied by the Azure CLI ssh extension. The current extension requires Azure CLI 2.45.0 or later and installs automatically the first time an az ssh command is used. You can sign in first with:
az login
If the command reports an authentication or token-related error, check the CLI version:
az version
Upgrade Azure CLI if necessary, then retry. The command supports Linux Azure VMs and Azure Arc servers using Microsoft Entra-issued OpenSSH certificates. For Arc connections, use SSH extension version 2.0.4 or later; older versions no longer work for the affected Arc connection commands.
Connect with Microsoft Entra ID
Microsoft Entra login avoids managing a separate local SSH key for every authorized administrator, but it must be enabled and correctly authorized.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Configure the VM
The VM must have Microsoft Entra login enabled and a system-assigned managed identity. When creating a VM in the portal, these settings are found under the VM creation wizard’s Management section:
- Login with Microsoft Entra ID
- System assigned managed identity
The exact image choices in older Microsoft examples may be dated; the important requirements are the login setting and managed identity.
Assign an Azure RBAC role
Assign the connecting user or group one of these roles at the VM, resource-group, or subscription scope:
- Virtual Machine Administrator Login — permits administrator-level VM login.
- Virtual Machine User Login — permits standard VM login.
Having general access to the Azure subscription is not, by itself, sufficient. Without one of these VM login roles, authentication can fail with Permission denied (publickey), or the connection may close immediately after authentication.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #4
- Cat 8 Speed, Cat 5/5e Value Enjoy Cat 8 Ethernet cable performance at a Cat 5/5e-level value. With up to 40Gbps speed and 2000MHz bandwidth, this high speed internet cable delivers more bandwidth than standard Cat 5 and Cat 5e cables, helping support smooth gaming, streaming, video calls, large file transfers and everyday wired network use.
- 40Gbps Speed, Wide Compatibility This Cat 8 Ethernet cable supports up to 40Gbps data transfer and 2000MHz bandwidth for fast, reliable internet performance. Standard RJ45 connectors are backward compatible with Cat7, Cat6, Cat6a and Cat5e devices, including routers, modems, switches, gaming PCs, PS5, PS4, Xbox, smart TVs, laptops and printers.
- Stable U/FTP Shielding Each of the 4 twisted pairs is individually wrapped with aluminum foil to help reduce crosstalk, noise, and signal interference. Combined with RJ45 connectors on both ends, the U/FTP design helps maintain cleaner signal transmission for a stable and reliable wired network connection.
- Nylon Braided Durability The nylon braided jacket adds everyday durability while keeping the cable flexible and easy to route. Reinforced construction helps the cord handle bending, pulling and frequent plugging, making it a reliable choice for desks, gaming rooms, home offices and long-term network setups.
- 50ft Reach for More Setups The 50 ft length makes it easier to connect devices across rooms, along walls, under desks or around corners. Great for router-to-PC connections, modem-to-TV setups, gaming consoles, workstations, printers and other home network equipment that needs a longer Ethernet cable.
Start an Entra-authenticated session
- Install or update Azure CLI to the current supported version.
- Sign in:
az login
- Connect to the VM:
az ssh vm -n myVM -g AzureADLinuxVM
You can run the same commands in Azure Cloud Shell by selecting the shell icon in the upper-right corner of the portal. Cloud Shell does not support Conditional Access policies that require device compliance or Microsoft Entra hybrid join.
Generate an SSH configuration entry
To export an OpenSSH configuration for Entra certificate authentication, run:
az ssh config --file ~/.ssh/config -n myVM -g AzureADLinuxVM
For a private address, specify the IP directly:
az ssh config --file ~/.ssh/config --ip 10.11.123.456
The client must already have network connectivity to that private IP. Exporting the configuration does not create a VPN route, Bastion tunnel, peering connection, or other network path.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot an Azure SSH connection
| Symptom | Likely cause | What to check |
|---|---|---|
| Timeout, refusal, or unreachable host | Stopped VM, wrong address, blocked NSG port, or routing problem | Confirm Status: Running, verify the public IP, inspect the NSG, and use Network Watcher IP flow verify and Next hop. |
Permission denied (publickey) |
Wrong username or private key, missing authorized_keys entry, or missing Entra login role |
Confirm the local key matches the VM account and assign Virtual Machine User Login or Virtual Machine Administrator Login for Entra access. |
Connection closed by ... port 22 after az login |
Missing Microsoft Entra VM-login RBAC assignment | Assign one of the two VM login roles at an appropriate scope. |
KeyError: access_token |
Outdated Azure CLI | Upgrade Azure CLI; the current az ssh extension requires version 2.45.0 or later. |
| “Permissions are too open” for the private key | Other local users can read the key | On Linux, macOS, or WSL, run chmod 400 path-to-key. |
Check the NSG rule and route
Open the VM’s networking settings and inspect the effective inbound rules. The allow rule for SSH must apply to the VM’s NIC or subnet, use the correct destination port, and have a higher priority than a conflicting deny rule. In Azure NSGs, a lower numerical priority is evaluated first.
Recommended Free Tools
For a routing problem, use Network Watcher’s Next hop or inspect effective routes. For a security-rule problem, use IP flow verify with the client IP, VM IP, protocol, and destination port.
Repair SSH from the portal
If you cannot log in but the Linux VM Agent is installed and running, use VM > Operations > Run Command > RunShellScript. Run Command returns output in the portal and does not require sudo in its execution context.
Server-side permission errors can cause sshd to ignore host keys or reject configuration files. Microsoft’s documented repair sequence is:
chmod -R 644 /etc/ssh
chmod 600 /etc/ssh/ssh_host*key
chmod 600 /etc/ssh/sshd_config
chmod 755 /home/<username>
chmod 700 /home/<username>/.ssh
chmod 600 /home/<username>/.ssh/authorized_keys
cd /home
chown <username> <username>
systemctl restart sshd
This is a repair procedure, not a universal hardening script. Check distribution-specific ownership and permissions before applying it to a production system.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Best Value
- [Flat Design, Zero Cable Clutter] - Lies perfectly flat against walls, under rugs, along baseboards, and through tight spaces without kinks, tangles, or messy coils. Customers praise it for effortless installation and clean cable management that blends into any room.
- [REINFORCED BRAIDED CONSTRUCTION FOR LONG‑LASTING PERFORMANCE] - Premium cotton braided jacket paired with reinforced RJ45 connectors delivers outstanding durability, rigorously tested for over 15,000 bend cycles. Many customers describe this ethernet cable as rock‑solid and well‑crafted, ideal for long‑term daily use with no worries about premature wear‑and‑tear or connection failure
- [10GBPS SPEED & 600MHZ BANDWIDTH — GAMING, STREAMING & FIBER READY] - Delivers 10Gbps data transfer rate with 600MHz bandwidth for PS5, Xbox, 4K streaming, and fiber internet. Customers report stable performance and fast speeds. Backward compatible with Cat 6 and Cat 5e devices
- [STP SHIELDING & GOLD-PLATED RJ45 — MINIMIZES EMI/RFI INTERFERENCE] - 100% bare copper STP shielding helps protect signal integrity when routed near power cords. Gold-plated RJ45 connectors resist corrosion. Compatible with 2.5GB network card
- [Works with Everything — Router, Modem, PS5, Xbox, PC, Smart TV, Printer More ] - Full backward compatibility with Cat7, Cat6, Cat6a, and Cat5e devices means this one cable works with all your home or office equipment today, and future upgrades tomorrow. Works with 10/100/1000/10G/40G BASE-T speeds. Includes 36-month warranty with free replacement support
The SSH daemon’s runtime directory also varies by distribution:
| Distribution | Runtime directory |
|---|---|
| RHEL | /var/empty/sshd |
| SUSE | /var/lib/empty |
| Ubuntu | /var/run/sshd |
These directories must be owned by root and must not be group-writable or world-writable. On Ubuntu, /var/run/sshd is stored in memory and is recreated when the VM restarts.
If Serial Console and the Linux VM Agent are unavailable, Microsoft’s documented fallback is offline repair with az vm repair. For custom Linux images, the Azure Linux Agent must be version 2.0.5 or later for the documented SSH repair and access-extension workflow.
FAQ
Can I SSH to an Azure Linux VM without a public IP?
Yes. A public IP is required for the basic direct-Internet command, but you can use Azure Bastion, a VPN, ExpressRoute, peering, SSH forwarding, or another network path to the VM’s private IP.
What port does Azure SSH use?
TCP 22 is the default. If SSH has been configured to use another port, the NSG and the client command must use that port. For example: ssh -p 2222 azureuser@20.51.230.13.
Why do I get Permission denied (publickey)?
The most common causes are a wrong Linux username, the wrong private key, a missing public key in the account’s authorized_keys file, or missing Virtual Machine User Login or Virtual Machine Administrator Login permissions when using Microsoft Entra ID.
Where can I reset an Azure VM SSH key?
In the Azure portal, open the VM and select Help > Reset password. Choose Reset SSH public key, enter the username and new public key, then select Update.
Is password login recommended for an Azure Linux VM?
No. Microsoft documents password authentication, but recommends SSH keys because password authentication is less secure.
Can I use Azure Cloud Shell for SSH?
Yes. Open Cloud Shell from the shell icon in the Azure portal, run az login, and then use az ssh vm -n VM_NAME -g RESOURCE_GROUP. Conditional Access policies requiring device compliance or hybrid join are not supported through Cloud Shell.
The Bottom Line
For a normal public-IP connection, verify that the VM is running, copy the correct address and username, protect the private key with chmod 400, and run ssh -i PATH_TO_KEY USERNAME@EXTERNAL_IP. If the VM has no public IP, use a private network path or Azure Bastion. When using Microsoft Entra ID, enable the VM login feature, provide a managed identity, assign the correct VM login RBAC role, and connect with az ssh vm.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

