Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

AD integration - ssh/sudoers using AD accounts

From Tech-Wiki


Join a Linux system to Microsoft Active Directory with realmd and SSSD, restrict logon to approved AD groups, and delegate sudo using least privilege.

ⓘ
Validation status
Reviewed against current Red Hat Enterprise Linux Active Directory integration guidance on 27 September 2026.
!
Use a dedicated administration group
Do not grant blanket Linux sudo rights to Domain Admins simply because the host is domain joined. Use an approved AD group dedicated to Linux administration and scope sudo privileges to the operational requirement.

Prerequisites

Before joining the domain:

  • Confirm DNS resolves the AD domain and domain controllers correctly.
  • Keep system time synchronized because Kerberos is sensitive to clock skew.
  • Confirm the Linux host name and DNS registration are correct.
  • Use an approved account that is permitted to join computers to the domain.

Install the integration components

On RHEL-family systems:

>_Install SSSD and realmd components
dnf install realmd oddjob oddjob-mkhomedir sssd adcli krb5-workstation

Discover and join the domain

>_Discover the domain
realm discover ad.example.com
>_Join Active Directory
realm join ad.example.com

The join command prompts for authorised credentials rather than requiring the password in the command line.

Verify identity resolution

>_Test an AD identity

Restrict logon access

>_Permit a dedicated AD group
realm permit -g "Linux [email protected]"

Delegate sudo

Create an approved file under /etc/sudoers.d/ and validate it with visudo.

%Linux\ [email protected] ALL=(ALL) ALL

SSH configuration

If direct root SSH access is not required:

PermitRootLogin no

Validate the SSH configuration before reloading it:

>_Validate sshd configuration
sshd -t

Official references