Instance Access & Security Management
Guide on MTN Cloud

Introduction

This document provides essential guidelines and procedures for managing user accounts and passwords on the MTN Cloud platform, specifically for Virtual Machines (VMs). Adhering strictly to this procedure reduces the risk of accidental lockouts, service disruption, and loss of administrative access.

Before You Start (prerequisites)

  1. Have an MTN Cloud Console login with the required role (permissions) to view Provisioning, e.g., the Customer Admin User role assigned.
  2. Have a provisioned virtual machine instance ready for configuration.

Windows VM Account Management & Best Practices

To avoid password expiration issues and enhance security, follow these account management guidelines for Windows VMs:

1. Change Administrator Password: Immediately after provisioning, change the default Administrator password to your preferred, complex password.
2. Disable Remote Desktop (RDP) for 'Administrator': For enhanced security, it is recommended to disable RDP access for the built-in "Administrator" account and use custom administrative accounts for remote management instead.
3. Maintain Fallback Administrative Accounts & Monitor Expiry: Always maintain at least two user accounts with Administrative privileges aside from the user (Administrator) on the VM. These serve as critical fallbacks if any of the accounts become locked or the password is lost. Additionally, monitor the password expiry dates for these accounts by using the command:
net user <username>

or by checking the account properties in Computer Management → Local Users and Groups → Users. Ensure the passwords for the two user accounts with administrative privileges do not expire at around the same time

Linux VM Account Management & Best Practices

Proper Linux account management is essential for avoiding permanent loss of access. The following established best practices are strongly recommended to ensure continuity of administrative access and secure operations.

  • Maintain at least two sudo-enabled users at all times
  • Do not delete or disable the originally provisioned user
  • Validate SSH access with the new password (or key, if applicable) before ending the active session
  • Where possible, prefer SSH keys over password authentication

Changing Your Virtual Machine (VM) Password

To successfully change your VM password, two updates are required: one inside the VM and one on the MTN Cloud platform. Both changes must be completed and verified before the password change is considered successful.

Step 1: Change the Password Inside the VM

Log in to the VM using your current credentials and change the password at the operating system level.

  • Windows VM:
    • Ctrl + Alt + Del → Change a password, or
    • Computer Management → Local Users and Groups → Users
  • Linux VM:
    • Run passwd <username> as the appropriate user or via sudo

Note: Do not log out immediately after changing the password.

Step 2: Validate Remote Access with the New Password

Before making any platform-side changes, confirm that remote access works using the newly set password:

  • Windows: RDP login using the new credentials
  • Linux: SSH login using the new credentials

This validation confirms the password was set correctly at the OS level and prevents accidental lockout.

If access fails after changing the password:

  • Do not touch or update MTN Cloud User Settings
  • Immediately change the password back inside the VM (if you are still logged in) or switch to a fallback administrative account to revert the account password
  • Verify that the login works again using RDP or SSH
  • Only after access is fully restored should you attempt the password change process again

Step 3: Update the Password on the MTN Cloud Platform

Once remote access is confirmed, you must update the same password in your User Settings on the MTN Cloud platform.

  • Navigate to User Settings (can be found at the top right corner of your screen when the dropdown beside name is clicked)
  • Locate the Linux Settings or Windows Settings section.
  • Update the password field to match exactly what was set inside the VM.
  • Click Save.

Important: The password configured inside the VM must exactly match the password set in the MTN Cloud platform User Settings. Any mismatch will prevent VM access on the cloud console and may interfere with automated management tasks.

Important Notes and Information

Once remote access is confirmed, you must update the same password in your User Settings on the MTN Cloud platform.

  • Default Password Policy: Please be aware that the default password expiration period for Windows VMs is 42 days.
  • Data Privacy: Never store passwords or sensitive credentials in plain text within the Wiki, Notes, or general documentation.
  • Secure Storage: Always utilise approved secure credential stores (such as Cypher) for managing sensitive access keys.
  • Access Control: Password visibility and credential management must be restricted to authorised administrative personnel only.

FLOWCHART

Once remote access is confirmed, you must update the same password in your User Settings on the MTN Cloud platform.

  • Default Password Policy: Please be aware that the default password expiration period for Windows VMs is 42 days.
  • Data Privacy: Never store passwords or sensitive credentials in plain text within the Wiki, Notes, or general documentation.
  • Secure Storage: Always utilise approved secure credential stores (such as Cypher) for managing sensitive access keys.
  • Access Control: Password visibility and credential management must be restricted to authorised administrative personnel only.