如何配置Azure IMDS防火墙规则仅允许本地系统账户获取托管身份令牌
仅允许本地系统账户访问Azure IMDS的Windows防火墙配置方案
你的场景下三个业务服务均以*本地系统(Local System)*账户运行,可通过Windows Defender防火墙的基于身份的出站过滤规则,实现仅Local System可访问Azure IMDS固定端点(169.254.169.254),其余所有账户访问IMDS的请求都会被拦截,从根源上避免其他应用获取托管标识令牌访问SQL托管实例。
配置步骤
所有操作需要在Azure VM上以管理员权限运行PowerShell执行:
- 第一步:创建全局阻止所有账户访问IMDS的出站规则,设置较低优先级
New-NetFirewallRule -DisplayName "Block all access to Azure IMDS" -Direction Outbound -RemoteAddress 169.254.169.254 -Action Block -Profile Any -Enabled True -Priority 20 - 第二步:创建仅允许本地系统账户访问IMDS的出站放行规则,设置更高优先级
New-NetFirewallRule -DisplayName "Allow Local System access to Azure IMDS" -Direction Outbound -RemoteAddress 169.254.169.254 -Action Allow -Profile Any -Enabled True -User "NT AUTHORITY\SYSTEM" -Priority 10
规则生效验证
- 以普通管理员账户打开PowerShell,执行IMDS查询命令:
Invoke-RestMethod -Headers @{"Metadata"="true"} -Uri "http://169.254.169.254/metadata/instance?api-version=2021-02-01" -Method Get
请求会被拦截,返回连接失败错误,说明非Local System账户访问已被阻止。 - 以Local System身份启动PowerShell(可借助PsExec工具执行
psexec -s -i powershell.exe实现),执行相同的IMDS查询命令,可正常返回实例元数据,说明放行规则生效。
内容的提问来源于stack exchange,提问作者Sathish M
相关产品推荐
相关产品推荐

