I manage Windows Servers daily, and OpenSSH has become my default way in: for PowerShell remoting, file transfers and tunneling RDP when port 3389 is closed. This page bundles everything I wrote about SSH on Windows, from a first install to hardware-backed keys.
flowchart LR
HUB["OpenSSH on Windows"]
subgraph Setup["Install and configure"]
A["Install OpenSSH in Windows Server"]
end
subgraph Keys["Keys and authentication"]
B["SSH public key from Active Directory"]
C["YubiKey FIDO2 support"]
D["Share OpenSSH keys with WSL"]
end
subgraph Tunnels["Tunnels and remote management"]
E["Tunnel RDP through SSH and PuTTY"]
F["virt-manager over SSH"]
G["KVM host via SSH tunnel"]
end
subgraph Workstation["Your workstation"]
H["Windows 11 and WSL 2 DevOps environment"]
end
HUB --> Setup
HUB --> Keys
HUB --> Tunnels
HUB --> Workstation
A --> B
B --> C
C --> DInstall and configure OpenSSH Server
Windows ships OpenSSH as a built-in feature. Install OpenSSH in Windows Server shows how to install and enable it, move it to a custom directory, and set up your sshd_config.
SSH keys and authentication
- Retrieve SSH public key from Active Directory: manage public keys centrally instead of scattered
authorized_keysfiles. - YubiKey support in OpenSSH for Windows 11: move your private key to hardware with FIDO2.
- How to share OpenSSH keys with WSL: use the same keys in Windows and WSL 2.
Tunnels and remote management
- Tunnel RDP through SSH & PuTTY: reach Remote Desktop when port 3389 is blocked.
- Managing KVM VMs with virt-manager on Windows: manage KVM over
qemu+ssh://. - Connect to a KVM host through an ssh tunnel: the same over a non-standard port.
Your Windows workstation
- Windows 11 and WSL 2 DevOps environment: my complete setup for SSH, Git and DevOps tooling.