Install and Scope OpenSSH Server on Windows
Windows OpenSSH Server provides SSH-based remote administration alongside Windows’ other management options. This tutorial installs the optional capability, starts the sshd service, narrows its inbound firewall rule to an approved management subnet, and verifies access from an authorized client.
Run the setup in an elevated PowerShell session on a supported Windows client or Server release. Use a dedicated administrative account, prefer key-based authentication according to your organization’s policy, and avoid exposing SSH to the public Internet without a reviewed access design.
Step 1: Check and Install the OpenSSH Server Capability
Confirm the Capability State Before Installing
InstallationCheck whether OpenSSH Server is already installed. If it is absent, install the server capability; do not install the client capability unless this computer also needs to initiate SSH sessions.
Get-WindowsCapability -Online | Where-Object Name -like 'OpenSSH.Server*' | Select-Object Name, State
Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0❯ View Expected Console Output
Name : OpenSSH.Server~~~~0.0.1.0State : InstalledStep 2: Start sshd and Inspect Its Firewall Rule
Set the Service to Start Automatically
Service SetupStart the SSH service and configure automatic startup if this host is intended to accept SSH after reboot. Windows setup may create a default inbound firewall rule; inspect it before enabling remote access.
Set-Service -Name sshd -StartupType AutomaticStart-Service sshdGet-Service sshdGet-NetFirewallRule -Name 'OpenSSH-Server-In-TCP' -ErrorAction SilentlyContinue | Select-Object Name, Enabled, Profile, Direction, Action❯ View Expected Console Output
Status Name DisplayName------ ---- -----------Running sshd OpenSSH SSH ServerStep 3: Restrict Inbound SSH to the Management Range
Replace the Broad Rule Scope with an Approved Subnet
Firewall ScopeIf the default rule exists, restrict its remote addresses to your trusted management subnet. The example uses 10.20.30.0/24; substitute the actual range and choose the profile that applies to this host’s management network. A workgroup server commonly uses Private rather than Domain. If there is no rule, create one with a scoped address filter instead of allowing any source.
$ManagementSubnet = '10.20.30.0/24'# Use the profile that applies to the management interface.# For a domain-connected interface use Domain; a workgroup may use Private.$FirewallProfile = 'Domain'$FirewallProfile
$SshRule = Get-NetFirewallRule -Name 'OpenSSH-Server-In-TCP' -ErrorAction SilentlyContinue
if ($SshRule) { $SshRule | Set-NetFirewallRule -Enabled True -Profile $FirewallProfile $SshRule | Get-NetFirewallAddressFilter | Set-NetFirewallAddressFilter -RemoteAddress $ManagementSubnet} else { New-NetFirewallRule -Name 'OpenSSH-Server-In-TCP-Scoped' ` -DisplayName 'OpenSSH Server - Management Subnet Only' ` -Enabled True -Direction Inbound -Protocol TCP -LocalPort 22 ` -RemoteAddress $ManagementSubnet -Profile $FirewallProfile -Action Allow}
Get-NetFirewallRule -Name 'OpenSSH-Server-In-TCP*' | Get-NetFirewallAddressFilter❯ View Expected Console Output
RemoteAddress : 10.20.30.0/24Step 4: Test SSH from an Authorized Client
Verify the Listener and User Login
VerificationConfirm the service is listening on TCP port 22, then connect from a client in the permitted subnet. Check the server’s OpenSSH configuration under C:\ProgramData\ssh\sshd_config if authentication or the default shell does not behave as expected.
Get-NetTCPConnection -State Listen -LocalPort 22❯ View Expected Console Output
The SSH client prompts for the configured authentication method and opens a Windows shell after successful authentication.
Figure 1: The Windows SSH service is running, its firewall rule is scoped to the management subnet, and port 22 is listening.
See Microsoft’s OpenSSH first-use guide and server configuration guide for supported settings.