OpenSSH on Windows: install, keys, tunnels and WSL

I manage Windows Servers daily, and OpenSSH has become my default way in: for PowerShell remoting, file transfers and tunneling RDP when port 3389 is closed. This page bundles everything I wrote about SSH on Windows, from a first install to hardware-backed keys.

flowchart LR
    HUB["OpenSSH on Windows"]

    subgraph Setup["Install and configure"]
        A["Install OpenSSH in Windows Server"]
    end

    subgraph Keys["Keys and authentication"]
        B["SSH public key from Active Directory"]
        C["YubiKey FIDO2 support"]
        D["Share OpenSSH keys with WSL"]
    end

    subgraph Tunnels["Tunnels and remote management"]
        E["Tunnel RDP through SSH and PuTTY"]
        F["virt-manager over SSH"]
        G["KVM host via SSH tunnel"]
    end

    subgraph Workstation["Your workstation"]
        H["Windows 11 and WSL 2 DevOps environment"]
    end

    HUB --> Setup
    HUB --> Keys
    HUB --> Tunnels
    HUB --> Workstation
    A --> B
    B --> C
    C --> D

Install and configure OpenSSH Server

Windows ships OpenSSH as a built-in feature. Install OpenSSH in Windows Server shows how to install and enable it, move it to a custom directory, and set up your sshd_config.

SSH keys and authentication

Tunnels and remote management

Your Windows workstation