Instance Access & Security Management
Guide on MTN Cloud
Introduction
This document provides essential guidelines and procedures for managing user accounts and passwords on the MTN Cloud platform, specifically for Virtual Machines (VMs). Adhering strictly to this procedure reduces the risk of accidental lockouts, service disruption, and loss of administrative access.
Before You Start (prerequisites)
- Have an MTN Cloud Console login with the required role (permissions) to view Provisioning, e.g., the Customer Admin User role assigned.
- Have a provisioned virtual machine instance ready for configuration.
Windows VM Account Management & Best Practices
To avoid password expiration issues and enhance security, follow these account management guidelines for Windows VMs:
or by checking the account properties in Computer Management → Local Users and Groups → Users. Ensure the passwords for the two user accounts with administrative privileges do not expire at around the same time
Linux VM Account Management & Best Practices
Proper Linux account management is essential for avoiding permanent loss of access. The following established best practices are strongly recommended to ensure continuity of administrative access and secure operations.
- Maintain at least two sudo-enabled users at all times
- Do not delete or disable the originally provisioned user
- Validate SSH access with the new password (or key, if applicable) before ending the active session
- Where possible, prefer SSH keys over password authentication
Changing Your Virtual Machine (VM) Password
To successfully change your VM password, two updates are required: one inside the VM and one on the MTN Cloud platform. Both changes must be completed and verified before the password change is considered successful.
Step 1: Change the Password Inside the VM
Log in to the VM using your current credentials and change the password at the operating system level.
- Windows VM:
- Ctrl + Alt + Del → Change a password, or
- Computer Management → Local Users and Groups → Users
- Linux VM:
- Run passwd <username> as the appropriate user or via sudo
Note: Do not log out immediately after changing the password.
Step 2: Validate Remote Access with the New Password
Before making any platform-side changes, confirm that remote access works using the newly set password:
- Windows: RDP login using the new credentials
- Linux: SSH login using the new credentials
This validation confirms the password was set correctly at the OS level and prevents accidental lockout.
If access fails after changing the password:
- Do not touch or update MTN Cloud User Settings
- Immediately change the password back inside the VM (if you are still logged in) or switch to a fallback administrative account to revert the account password
- Verify that the login works again using RDP or SSH
- Only after access is fully restored should you attempt the password change process again
Step 3: Update the Password on the MTN Cloud Platform
Once remote access is confirmed, you must update the same password in your User Settings on the MTN Cloud platform.
- Navigate to User Settings (can be found at the top right corner of your screen when the dropdown beside name is clicked)
- Locate the Linux Settings or Windows Settings section.
- Update the password field to match exactly what was set inside the VM.
- Click Save.
Important: The password configured inside the VM must exactly match the password set in the MTN Cloud platform User Settings. Any mismatch will prevent VM access on the cloud console and may interfere with automated management tasks.
Important Notes and Information
Once remote access is confirmed, you must update the same password in your User Settings on the MTN Cloud platform.
- Default Password Policy: Please be aware that the default password expiration period for Windows VMs is 42 days.
- Data Privacy: Never store passwords or sensitive credentials in plain text within the Wiki, Notes, or general documentation.
- Secure Storage: Always utilise approved secure credential stores (such as Cypher) for managing sensitive access keys.
- Access Control: Password visibility and credential management must be restricted to authorised administrative personnel only.
FLOWCHART
Once remote access is confirmed, you must update the same password in your User Settings on the MTN Cloud platform.
- Default Password Policy: Please be aware that the default password expiration period for Windows VMs is 42 days.
- Data Privacy: Never store passwords or sensitive credentials in plain text within the Wiki, Notes, or general documentation.
- Secure Storage: Always utilise approved secure credential stores (such as Cypher) for managing sensitive access keys.
- Access Control: Password visibility and credential management must be restricted to authorised administrative personnel only.