Restrict SSH Logins with AllowUsers Without Locking Yourself Out
A valid SSH key or password does not guarantee that an account can log in. OpenSSH can apply an additional server-side filter: AllowUsers lists which accounts are eligible to connect. That makes it useful for limiting remote access on a shared server—but a typo or incomplete list can lock out administrators and automation. Treat it as an access-control change, not just a line to add to a config…
AllowUsers is an OpenSSH server setting that filters which accounts are permitted to log in via SSH. It should be added to the server configuration file, not the client-side config. To limit remote access to specific users, list their login names after AllowUsers. For example, AllowUsers deploy would only allow the "deploy" account to connect.
Multiple users can be allowed by separating their names with spaces: AllowUsers deploy admin monitoring. These names must match the actual login usernames on the server. Adding AllowUsers does not create accounts or grant them shell access. It only serves as an additional access control, so listed users still need to satisfy the server's authentication and account policies.
Once an AllowUsers list is active, accounts not matching it will be excluded from SSH login, regardless of valid credentials. To prevent locking out administrators and automation accounts, carefully consider all people, deployment processes, and recovery logins that need access.
Access can also be restricted by source address. For instance, AllowUsers deploy@192.0.2.10 limits the "deploy" account to connections originating from the IP address 192.0.2.10. CIDR address patterns like AllowUsers deploy@192.0.2.0/24 can restrict connections to a specific network segment.
After adding restrictions, test from the intended network to ensure the pattern matches. AllowUsers can be combined with other directives like AllowGroups and DenyUsers, but Deny rules take precedence. Before applying changes, test the configuration with sudo sshd -t. Once verified, reload the SSH service and test fresh connections for each allowed account and source network.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.