AD integration - ssh/sudoers using AD accounts
From Tech-Wiki
More actions
Join a Linux system to Microsoft Active Directory with realmd and SSSD, restrict logon to approved AD groups, and delegate sudo using least privilege.
Validation status
Reviewed against current Red Hat Enterprise Linux Active Directory integration guidance on 27 September 2026.
Use a dedicated administration group
Do not grant blanket Linux sudo rights to Domain Admins simply because the host is domain joined. Use an approved AD group dedicated to Linux administration and scope sudo privileges to the operational requirement.
Prerequisites
Before joining the domain:
- Confirm DNS resolves the AD domain and domain controllers correctly.
- Keep system time synchronized because Kerberos is sensitive to clock skew.
- Confirm the Linux host name and DNS registration are correct.
- Use an approved account that is permitted to join computers to the domain.
Install the integration components
On RHEL-family systems:
Install SSSD and realmd components
dnf install realmd oddjob oddjob-mkhomedir sssd adcli krb5-workstation
Discover and join the domain
Discover the domain
realm discover ad.example.com
Join Active Directory
realm join ad.example.com
The join command prompts for authorised credentials rather than requiring the password in the command line.
Verify identity resolution
Test an AD identity
Restrict logon access
Permit a dedicated AD group
realm permit -g "Linux [email protected]"
Delegate sudo
Create an approved file under /etc/sudoers.d/ and validate it with visudo.
%Linux\ [email protected] ALL=(ALL) ALL
SSH configuration
If direct root SSH access is not required:
PermitRootLogin no
Validate the SSH configuration before reloading it:
Validate sshd configuration
sshd -t