Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Webinars
  • Linux Security: Locking Down Admin Access with SSH and Sudo current page
Link copied

Linux Security: Locking Down Admin Access with SSH and Sudo

with Randy Franklin Smith, CEO, Monterey Technology Group, Inc. CISA, SSCP, Security MVP; Patrick Schneider, Sr. Solutions Architect
Webinars default
Linux Security: Locking Down Admin Access with SSH and Sudo

Get Instant Access to this Content

Learn more about how to secure your business from threats in places you didn't even know existed.

This webinar was hosted by Ultimate IT Security

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied

The 2 native tools to Linux for securing privileged access are SSH and Sudo. SSH is how you get into the system securely in terms of authentication and network security and Sudo is what enforces least privilege once you are in. In this real training for free session, we will dive into the details of secure admin access to Linux as a whole, with these 2 tools as the essential building blocks.

SSH

Secure Shell (SSH) is a network protocol that provides login, remote command line execution and file transfer. SSH replaced Telnet for this purpose a long time ago. On your local endpoint you run some kind of SSH client such as PuTTY and it connects over port 22 to the Linux system you want to administer – specifically the sshd which is the Secure Shell Daemon running the server-side component of SSH. We will focus on sshd and the security configuration options of ssh such as:

  • Port
  • Permitting root login
  • Authentication: password, ssh keys and beyond
  • Port forwarding
  • AllowGroups / DenyGroups
  • Logging

For basic authentication, SSH supports password or self-generated ssh keys, but this is just the beginning. Authentication is a big part of SSH security with many different options, depending on your environment and level of integration with things like your PKI and Active Directory.

Sudo

The base layer of Linux – like UNIX – is monolithic in terms of privilege. You are either root or you’re not. There’s no in between and thus sudo was developed to granularly delegate privileged access. Instead of running commands directly, you prefix them with “sudo”. Sudo then compares your identity and the command you’ve specified to policies in the sudoers file. If permitted it uses system calls like setuid() to change effective user id – usually to root – and then executes the command. As with all security, the devil’s in the details. You can use sudo all day long but accomplish nothing in terms of security if the sudoers file is too permissive or configured incorrectly. We will look at how sudo works and the format of the sudoers file and other sudo configurations.

Securing privileged access on Linux doesn’t have to be complex—but it does require intentional configuration and an understanding of how SSH and Sudo work together to enforce strong security boundaries.

But it’s also important to understand that these are foundation tools built for a different time, so they do have limitations in the context of today’s risk landscape and enterprise scale.

SSH and sudo are the standards for most Linux administrators for accessing remote systems and managing root privileges on those systems. But these tools weren't designed for enterprise scale or for modern governance and compliance requirements. So BeyondTrust was the perfect sponsor for this real training for free session, and Patrick Schneider, Sr Solutions Architect, discusses how these tools are typically used by large enterprises today, and how companies can make improvements in their overall security by adjusting how they manage secure access to and privilege management on their Linux systems.

Meet the Speakers

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
Randy Franklin Smith
Randy Franklin Smith
CEO, Monterey Technology Group, Inc. CISA, SSCP, Security MVP
Randy Franklin Smith is an internationally recognized expert on the security and control of Windows and Active Directory security who specializes in Windows and Active Directory security. He performs security reviews for clients ranging from small, p ... read more

Randy Franklin Smith is an internationally recognized expert on the security and control of Windows and Active Directory security who specializes in Windows and Active Directory security. He performs security reviews for clients ranging from small, privately held firms to Fortune 500 companies, national, and international organizations.

Randy Franklin Smith is an internationally recognized expert on the security and control of Windows and Active Directory security who specializes in Windows and Active Directory security. He performs security reviews for clients ranging from small, p ... read more
Randy Franklin Smith
CEO, Monterey Technology Group, Inc. CISA, SSCP, Security MVP

Randy Franklin Smith is an internationally recognized expert on the security and control of Windows and Active Directory security who specializes in Windows and Active Directory security. He performs security reviews for clients ranging from small, privately held firms to Fortune 500 companies, national, and international organizations.

×
Patrick Schneider
Patrick Schneider
Sr. Solutions Architect
Patrick Schneider is a Senior IGA professional, with 30 years of experience in the Information Technology industry. Prior to joining BeyondTrust as a Senior Solutions Architect, Patrick was a Senior Solutions Engineer for the Security portfolio of a ... read more

Patrick Schneider is a Senior IGA professional, with 30 years of experience in the Information Technology industry. Prior to joining BeyondTrust as a Senior Solutions Architect, Patrick was a Senior Solutions Engineer for the Security portfolio of a major IAM solutions provider. Patrick holds many industry certifications such as Comptia+, MCP, Certified Directory Engineer, Certified Linux Engineer and more.


Patrick Schneider is a Senior IGA professional, with 30 years of experience in the Information Technology industry. Prior to joining BeyondTrust as a Senior Solutions Architect, Patrick was a Senior Solutions Engineer for the Security portfolio of a ... read more
Patrick Schneider
Sr. Solutions Architect

Patrick Schneider is a Senior IGA professional, with 30 years of experience in the Information Technology industry. Prior to joining BeyondTrust as a Senior Solutions Architect, Patrick was a Senior Solutions Engineer for the Security portfolio of a major IAM solutions provider. Patrick holds many industry certifications such as Comptia+, MCP, Certified Directory Engineer, Certified Linux Engineer and more.


×

Recommended Resources

White chain icon to symbolize the ability to copy a link
Link copied
Check mark to visually show text has been copied
On-Demand Webinar
Don’t Buy a Breach: Securing Identity in M&A from Due Diligence to Day One 
On-Demand Webinar
Tech Talk Tuesday: Privilege Centric Identity Security with Pathfinder
On-Demand Webinar
Benefitting from AI in IT Support
Podcasts
Ep. 95 - Phishing 2.0, Deepfakes, and the Death of 'Trust But Verify' // Tim Chase
Podcasts
Ep. 94 – Mistakes, Malware and Missile Industry Day // Silas Cutler
Podcasts
Ep. 93 - From Pwn2Own to Pwning AI // Aaron Portnoy
Blog
Managing Identity Risks for Industrial Operational Technology Cybersecurity
Blog
Privilege Escalation Attack & Defense Explained
Blog
Operational Technology (OT) Security: Why Smarter OT Remote Access Should Top Your Priority List
Latest
  • The Ghost in the Machine (Securing Non-Human Identities)
    Jun 18, 2026 The Ghost in the Machine (Securing Non-Human Identities)
    Webinar
Related
  • FIPS Validated vs FIPS Compliant: What's the Difference & Why does it Matter for Vendor Remote Access?
    Jun 2, 2021 FIPS Validated vs FIPS Compliant: What's the Difference & Why does it Matter for Vendor Remote Access?
    On-demand we...
    26m
Share this Article
  • Link

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.