6.5 Secure Administrative Access: Session Manager & EC2 Instance Connect
Key Takeaways
Session Manager needs the SSM Agent, instance permissions (instance profile or Default Host Management Configuration), and outbound HTTPS or VPC endpoints, but no inbound ports.
IAM conditions such as ssm:resourceTag limit which instances a user can open sessions to, and CloudTrail records every StartSession call.
Session preferences add KMS encryption, CloudWatch Logs or S3 session logging, an idle timeout of 1–60 minutes (default 20), and Run As users.
EC2 Instance Connect places a one-time SSH public key in instance metadata for 60 seconds; the ec2:osuser condition key limits the OS user.
EC2 Instance Connect Endpoints provide SSH or RDP to private instances, restricted by the remotePort, privateIpAddress, and maxTunnelDuration condition keys.
6.5 Secure Administrative Access: Session Manager & EC2 Instance Connect
Administrators still need shells on instances to troubleshoot, patch, and investigate. Skill 3.2.5 tests how you provide that access without inbound SSH or RDP from the internet, without long-lived SSH keys, and with every session tied to an IAM identity and logged. The two services named in the exam guide are AWS Systems Manager Session Manager and EC2 Instance Connect.
AWS Systems Manager Session Manager
Session Manager opens an interactive shell (or a port-forwarding tunnel) through the SSM Agent, which makes outbound HTTPS (443) connections to Systems Manager. The instance needs no inbound ports, no public IP address, no bastion host, and no SSH keys.
Requirements
- SSM Agent installed and running (preinstalled on Amazon Linux, Ubuntu Server, and Windows Server AMIs from AWS).
- Instance permissions: an instance profile with the
AmazonSSMManagedInstanceCoremanaged policy, or the account-level Default Host Management Configuration, which gives instances Systems Manager permissions without an instance profile (IMDSv2 required). - Network path: outbound HTTPS to the Systems Manager endpoints. For instances in private subnets without a NAT gateway, create interface VPC endpoints for
ssmandssmmessages(older SSM Agent versions also useec2messages), pluskmsif sessions are KMS-encrypted andlogsor an S3 gateway endpoint for session logging.
Controlling Who Can Start Sessions
IAM decides who can open a session to which instance. A common pattern allows sessions only to instances tagged for the user's team and only with approved session documents:
{
"Effect": "Allow",
"Action": "ssm:StartSession",
"Resource": "arn:aws:ec2:us-east-1:111122223333:instance/*",
"Condition": {
"StringEquals": { "ssm:resourceTag/Team": "payments" },
"BoolIfExists": { "ssm:SessionDocumentAccessCheck": "true" }
}
}
Grant ssm:TerminateSession and ssm:ResumeSession only for the user's own sessions by matching the session's owner, so one administrator can't take over another's session.
Session Preferences (Account and Region Settings)
| Setting | Security Purpose |
|---|---|
| KMS encryption | Encrypts session data between the client and the instance with a customer managed key, in addition to TLS |
| Session logging | Streams or uploads session output to CloudWatch Logs or an encrypted S3 bucket |
| Idle session timeout | Ends inactive sessions after 1–60 minutes (default 20) |
| Maximum session duration | Caps a session's total length |
| Run As (Linux) | Starts sessions as a named OS user (for example, from an SSMSessionRunAs tag on the IAM principal) instead of the default ssm-user |
| Shell profile | Runs commands at session start, such as setting a warning banner |
CloudTrail records every StartSession, TerminateSession, and ResumeSession call, so each session is attributable to an IAM principal even when many people share an OS account.
Port Forwarding and SSH Through Session Manager
AWS-StartPortForwardingSessionforwards a local port to a port on the instance (for example, RDP on 3389).AWS-StartPortForwardingSessionToRemoteHostuses the instance as a jump host to a private endpoint, such as an Amazon RDS database, without exposing the database.AWS-StartSSHSessiontunnels SSH through Session Manager; restrict it if you want only audited shell sessions, because SSH tunneling can bypass session logging.
EC2 Instance Connect
EC2 Instance Connect keeps SSH but removes long-lived keys. An authorized user calls ec2-instance-connect:SendSSHPublicKey, which places a one-time public key in instance metadata for 60 seconds; the user must connect with the matching private key within that window. IAM can restrict the OS user with the ec2:osuser condition key and restrict instances by tag. The instance needs the EC2 Instance Connect package (included in Amazon Linux 2, Amazon Linux 2023, and Ubuntu AMIs).
Connecting from the console to a public instance requires the security group to allow SSH from the EC2 Instance Connect service's IP address range for the Region.
EC2 Instance Connect Endpoint (EICE)
An EC2 Instance Connect Endpoint reaches instances in private subnets over SSH (22) or RDP (3389) without public IP addresses, internet gateways, or bastion hosts. You create the endpoint in a subnet with its own security group, and the instance's security group allows traffic from the endpoint's security group. Users call ec2-instance-connect:OpenTunnel, which IAM can restrict with the condition keys ec2-instance-connect:remotePort, ec2-instance-connect:privateIpAddress, and ec2-instance-connect:maxTunnelDuration (up to 3,600 seconds).
Choosing an Approach
| Requirement | Best Fit |
|---|---|
| No inbound ports at all, full session transcripts | Session Manager |
| Teams require native SSH tooling but no stored keys | EC2 Instance Connect |
| SSH or RDP to private instances without a bastion or public IP | EC2 Instance Connect Endpoint (or Session Manager) |
| Private access to an RDS database for an administrator | Session Manager port forwarding to a remote host |
| Windows GUI access through the console | Fleet Manager remote desktop, which uses Session Manager |
| Emergency OS-level recovery when networking is broken | EC2 serial console (disabled by default at the account level; enable only for break-glass use) |
Specialty Exam Pitfalls
- Opening port 22 to 0.0.0.0/0 "for Session Manager": Session Manager needs no inbound rules; outbound HTTPS is enough.
- Private subnet with no path to Systems Manager: Without a NAT gateway or interface endpoints, the instance never registers and sessions fail.
- Unencrypted or missing session logs: Configure KMS encryption and logging in Session Manager preferences to meet audit requirements.
- Shared SSH keys on a bastion: Replace them with Session Manager or EC2 Instance Connect so each session maps to an IAM identity.
A company runs EC2 instances in private subnets with no NAT gateway. Administrators must open interactive shells without any inbound security group rules, bastion hosts, or SSH keys, and every session must be encrypted with a customer managed key and logged. The instances have the SSM Agent and an instance profile with AmazonSSMManagedInstanceCore, but they never appear as managed nodes. What is missing?
An inbound security group rule allowing TCP 22 from the administrators' IP range.
An Elastic IP address on each instance.
An internet gateway attached to the VPC.
Interface VPC endpoints for Systems Manager (ssm and ssmmessages, plus ec2messages for older agents) and for AWS KMS and CloudWatch Logs, with security groups allowing HTTPS from the instances.
A security team wants each operations engineer to open Session Manager sessions only to EC2 instances tagged Team=payments, and wants to stop engineers from terminating or resuming sessions that other engineers started. Which IAM design meets these requirements?
Allow ssm:StartSession on instances with the condition ssm:resourceTag/Team equal to payments, and allow ssm:TerminateSession and ssm:ResumeSession only on sessions owned by the calling user.
Allow ssm:* on all resources and rely on OS-level sudo rules.
Create a separate SSH key pair for each engineer and store the keys in Secrets Manager.
Allow ssm:StartSession only from the corporate IP range by using aws:SourceIp.
Developers need SSH and RDP access to EC2 instances in private subnets that have no public IP addresses. The company prohibits bastion hosts and internet gateways in these VPCs. Access must be restricted to port 22 or 3389 on specific private IP ranges, and no connection may last longer than one hour. Which solution meets these requirements?
Assign Elastic IP addresses temporarily and remove them after each session.
Deploy an EC2 Instance Connect Endpoint in each VPC and grant ec2-instance-connect:OpenTunnel with conditions on remotePort, privateIpAddress, and maxTunnelDuration of 3600 seconds.
Create a Network Load Balancer that forwards ports 22 and 3389 to the instances.
Use EC2 Instance Connect through the console, which requires opening port 22 to the internet.
An auditor asks how the company can prove which person ran commands on a Linux instance, given that all administrators log in to the operating system as the same ssm-user account. Sessions use Session Manager. Which evidence best answers the auditor?
The instance's /var/log/secure file, which shows ssm-user for every login.
VPC Flow Logs showing traffic on port 22.
CloudTrail StartSession events identifying each IAM principal, combined with Session Manager logs of session output in CloudWatch Logs or S3 keyed by session ID.
The EC2 console's instance status checks.
Sections you finish are checked off in the contents.