6.5 Secure Administrative Access: Session Manager & EC2 Instance Connect

Key Takeaways

  • Session Manager needs the SSM Agent, instance permissions (instance profile or Default Host Management Configuration), and outbound HTTPS or VPC endpoints, but no inbound ports.

  • IAM conditions such as ssm:resourceTag limit which instances a user can open sessions to, and CloudTrail records every StartSession call.

  • Session preferences add KMS encryption, CloudWatch Logs or S3 session logging, an idle timeout of 1–60 minutes (default 20), and Run As users.

  • EC2 Instance Connect places a one-time SSH public key in instance metadata for 60 seconds; the ec2:osuser condition key limits the OS user.

  • EC2 Instance Connect Endpoints provide SSH or RDP to private instances, restricted by the remotePort, privateIpAddress, and maxTunnelDuration condition keys.

Last updated: September 2026

6.5 Secure Administrative Access: Session Manager & EC2 Instance Connect

Administrators still need shells on instances to troubleshoot, patch, and investigate. Skill 3.2.5 tests how you provide that access without inbound SSH or RDP from the internet, without long-lived SSH keys, and with every session tied to an IAM identity and logged. The two services named in the exam guide are AWS Systems Manager Session Manager and EC2 Instance Connect.


AWS Systems Manager Session Manager

Session Manager opens an interactive shell (or a port-forwarding tunnel) through the SSM Agent, which makes outbound HTTPS (443) connections to Systems Manager. The instance needs no inbound ports, no public IP address, no bastion host, and no SSH keys.

Requirements

  • SSM Agent installed and running (preinstalled on Amazon Linux, Ubuntu Server, and Windows Server AMIs from AWS).
  • Instance permissions: an instance profile with the AmazonSSMManagedInstanceCore managed policy, or the account-level Default Host Management Configuration, which gives instances Systems Manager permissions without an instance profile (IMDSv2 required).
  • Network path: outbound HTTPS to the Systems Manager endpoints. For instances in private subnets without a NAT gateway, create interface VPC endpoints for ssm and ssmmessages (older SSM Agent versions also use ec2messages), plus kms if sessions are KMS-encrypted and logs or an S3 gateway endpoint for session logging.

Controlling Who Can Start Sessions

IAM decides who can open a session to which instance. A common pattern allows sessions only to instances tagged for the user's team and only with approved session documents:

{
  "Effect": "Allow",
  "Action": "ssm:StartSession",
  "Resource": "arn:aws:ec2:us-east-1:111122223333:instance/*",
  "Condition": {
    "StringEquals": { "ssm:resourceTag/Team": "payments" },
    "BoolIfExists": { "ssm:SessionDocumentAccessCheck": "true" }
  }
}

Grant ssm:TerminateSession and ssm:ResumeSession only for the user's own sessions by matching the session's owner, so one administrator can't take over another's session.

Session Preferences (Account and Region Settings)

SettingSecurity Purpose
KMS encryptionEncrypts session data between the client and the instance with a customer managed key, in addition to TLS
Session loggingStreams or uploads session output to CloudWatch Logs or an encrypted S3 bucket
Idle session timeoutEnds inactive sessions after 1–60 minutes (default 20)
Maximum session durationCaps a session's total length
Run As (Linux)Starts sessions as a named OS user (for example, from an SSMSessionRunAs tag on the IAM principal) instead of the default ssm-user
Shell profileRuns commands at session start, such as setting a warning banner

CloudTrail records every StartSession, TerminateSession, and ResumeSession call, so each session is attributable to an IAM principal even when many people share an OS account.

Port Forwarding and SSH Through Session Manager

  • AWS-StartPortForwardingSession forwards a local port to a port on the instance (for example, RDP on 3389).
  • AWS-StartPortForwardingSessionToRemoteHost uses the instance as a jump host to a private endpoint, such as an Amazon RDS database, without exposing the database.
  • AWS-StartSSHSession tunnels SSH through Session Manager; restrict it if you want only audited shell sessions, because SSH tunneling can bypass session logging.

EC2 Instance Connect

EC2 Instance Connect keeps SSH but removes long-lived keys. An authorized user calls ec2-instance-connect:SendSSHPublicKey, which places a one-time public key in instance metadata for 60 seconds; the user must connect with the matching private key within that window. IAM can restrict the OS user with the ec2:osuser condition key and restrict instances by tag. The instance needs the EC2 Instance Connect package (included in Amazon Linux 2, Amazon Linux 2023, and Ubuntu AMIs).

Connecting from the console to a public instance requires the security group to allow SSH from the EC2 Instance Connect service's IP address range for the Region.

EC2 Instance Connect Endpoint (EICE)

An EC2 Instance Connect Endpoint reaches instances in private subnets over SSH (22) or RDP (3389) without public IP addresses, internet gateways, or bastion hosts. You create the endpoint in a subnet with its own security group, and the instance's security group allows traffic from the endpoint's security group. Users call ec2-instance-connect:OpenTunnel, which IAM can restrict with the condition keys ec2-instance-connect:remotePort, ec2-instance-connect:privateIpAddress, and ec2-instance-connect:maxTunnelDuration (up to 3,600 seconds).


Choosing an Approach

RequirementBest Fit
No inbound ports at all, full session transcriptsSession Manager
Teams require native SSH tooling but no stored keysEC2 Instance Connect
SSH or RDP to private instances without a bastion or public IPEC2 Instance Connect Endpoint (or Session Manager)
Private access to an RDS database for an administratorSession Manager port forwarding to a remote host
Windows GUI access through the consoleFleet Manager remote desktop, which uses Session Manager
Emergency OS-level recovery when networking is brokenEC2 serial console (disabled by default at the account level; enable only for break-glass use)

Specialty Exam Pitfalls

  1. Opening port 22 to 0.0.0.0/0 "for Session Manager": Session Manager needs no inbound rules; outbound HTTPS is enough.
  2. Private subnet with no path to Systems Manager: Without a NAT gateway or interface endpoints, the instance never registers and sessions fail.
  3. Unencrypted or missing session logs: Configure KMS encryption and logging in Session Manager preferences to meet audit requirements.
  4. Shared SSH keys on a bastion: Replace them with Session Manager or EC2 Instance Connect so each session maps to an IAM identity.
Loading diagram...
Keyless, Audited Administrative Access Paths
Test Your Knowledge

A company runs EC2 instances in private subnets with no NAT gateway. Administrators must open interactive shells without any inbound security group rules, bastion hosts, or SSH keys, and every session must be encrypted with a customer managed key and logged. The instances have the SSM Agent and an instance profile with AmazonSSMManagedInstanceCore, but they never appear as managed nodes. What is missing?

A

An inbound security group rule allowing TCP 22 from the administrators' IP range.

B

An Elastic IP address on each instance.

C

An internet gateway attached to the VPC.

D

Interface VPC endpoints for Systems Manager (ssm and ssmmessages, plus ec2messages for older agents) and for AWS KMS and CloudWatch Logs, with security groups allowing HTTPS from the instances.

Test Your Knowledge

A security team wants each operations engineer to open Session Manager sessions only to EC2 instances tagged Team=payments, and wants to stop engineers from terminating or resuming sessions that other engineers started. Which IAM design meets these requirements?

A

Allow ssm:StartSession on instances with the condition ssm:resourceTag/Team equal to payments, and allow ssm:TerminateSession and ssm:ResumeSession only on sessions owned by the calling user.

B

Allow ssm:* on all resources and rely on OS-level sudo rules.

C

Create a separate SSH key pair for each engineer and store the keys in Secrets Manager.

D

Allow ssm:StartSession only from the corporate IP range by using aws:SourceIp.

Test Your Knowledge

Developers need SSH and RDP access to EC2 instances in private subnets that have no public IP addresses. The company prohibits bastion hosts and internet gateways in these VPCs. Access must be restricted to port 22 or 3389 on specific private IP ranges, and no connection may last longer than one hour. Which solution meets these requirements?

A

Assign Elastic IP addresses temporarily and remove them after each session.

B

Deploy an EC2 Instance Connect Endpoint in each VPC and grant ec2-instance-connect:OpenTunnel with conditions on remotePort, privateIpAddress, and maxTunnelDuration of 3600 seconds.

C

Create a Network Load Balancer that forwards ports 22 and 3389 to the instances.

D

Use EC2 Instance Connect through the console, which requires opening port 22 to the internet.

Test Your Knowledge

An auditor asks how the company can prove which person ran commands on a Linux instance, given that all administrators log in to the operating system as the same ssm-user account. Sessions use Session Manager. Which evidence best answers the auditor?

A

The instance's /var/log/secure file, which shows ssm-user for every login.

B

VPC Flow Logs showing traffic on port 22.

C

CloudTrail StartSession events identifying each IAM principal, combined with Session Manager logs of session output in CloudWatch Logs or S3 keyed by session ID.

D

The EC2 console's instance status checks.

Sections you finish are checked off in the contents.