{
  "id": 13654671,
  "title": "Restrict SSH Logins with AllowUsers Without Locking Yourself Out",
  "url": "https://urgent.news/2026/10/11/restrict-ssh-logins-with-allowusers-without-locking-yourself-out",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-11T05:48:57.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/__3381495fd2b/restrict-ssh-logins-with-allowusers-without-locking-yourself-out-19a1"
  },
  "original_language": "en",
  "account": "AllowUsers is an OpenSSH server setting that filters which accounts are permitted to log in via SSH. It should be added to the server configuration file, not the client-side config. To limit remote access to specific users, list their login names after AllowUsers. For example, AllowUsers deploy would only allow the \"deploy\" account to connect.\n\nMultiple users can be allowed by separating their names with spaces: AllowUsers deploy admin monitoring. These names must match the actual login usernames on the server. Adding AllowUsers does not create accounts or grant them shell access. It only serves as an additional access control, so listed users still need to satisfy the server's authentication and account policies.\n\nOnce an AllowUsers list is active, accounts not matching it will be excluded from SSH login, regardless of valid credentials. To prevent locking out administrators and automation accounts, carefully consider all people, deployment processes, and recovery logins that need access.\n\nAccess can also be restricted by source address. For instance, AllowUsers deploy@192.0.2.10 limits the \"deploy\" account to connections originating from the IP address 192.0.2.10. CIDR address patterns like AllowUsers deploy@192.0.2.0/24 can restrict connections to a specific network segment.\n\nAfter adding restrictions, test from the intended network to ensure the pattern matches. AllowUsers can be combined with other directives like AllowGroups and DenyUsers, but Deny rules take precedence. Before applying changes, test the configuration with sudo sshd -t. Once verified, reload the SSH service and test fresh connections for each allowed account and source network.",
  "summary": "A valid SSH key or password does not guarantee that an account can log in. OpenSSH can apply an additional server-side filter: AllowUsers lists which accounts are eligible to connect. That makes it useful for limiting remote access on a shared server—but a typo or incomplete list can lock out administrators and automation. Treat it as an access-control change, not just a line to add to a config…",
  "key_points": [
    "AllowUsers restricts SSH logins to specified users.",
    "Multiple users can be allowed by separating names with spaces.",
    "Incorrectly configured AllowUsers can lock out legitimate users."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}