How to Enable OpenSSH Server in Windows 11
OpenSSH Server in Windows 11 lets you connect to your PC from another device using a secure, encrypted network connection. This built-in tool uses Secure Shell technology so you can run commands and move files from afar without needing a physical keyboard and mouse.
Windows 11 leaves this server turned off by default to save system resources. You can turn it on in under 3 minutes through your system settings or PowerShell (a command-line tool for system tasks).
Install OpenSSH Server via Settings by going to Apps Optional features, clicking View features, searching for OpenSSH Server, selecting it, and clicking Install. Alternatively, use PowerShell with the command Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0.
How to Install OpenSSH Server
This feature can be installed using the Settings menu or the command line. Admin privileges are required for these steps.
Method 1Using Windows Settings
1. Press Win+I to open Settings .
2. Go to Apps > Optional features.
3. Click View features, then search for OpenSSH Server.
4. Select the feature and click Next, then Install.





Method 2Using PowerShell (Fastest Way)
The OpenSSH server can be installed using PowerShell by entering the command `Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0`. This command adds the OpenSSH server to your Windows 11 system. Installing the OpenSSH server makes remote access possible.
Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0
Starting and Managing the Service
Starting the OpenSSH Server Windows 11 service lets other devices securely connect to your computer over a network. Open the Services app using the run command, find the OpenSSH SSH Server entry in the list, and change its startup type so it runs automatically whenever your PC turns on.
Head to the Windows Services app to get the server running. Press Win + R, type `services.msc`, and hit Enter. Right-click the service name and choose "Start." To ensure the service begins automatically when Windows 11 starts, right-click "OpenSSH SSH Server" again, select "Properties," and then set the "Startup type" to "Automatic."


Run `Get-Service sshd` in PowerShell to verify the service status.
Configuration and Security
The main configuration file, `sshd_config`, is usually found at `C:\ProgramData\ssh\sshd_config`. This file can be edited to change the default port or restrict access.
Setting up Key-Based Authentication
Passwords can be guessed. Using an SSH key pair is much safer. You generate a public and private key, then place the public key in `C:\Users\YourUsername\.ssh\authorized_keys`. This allows logging in without needing to type a password each time.
Troubleshooting
If you cannot connect, check your Windows Firewall. The installation usually creates a rule, but you might need to confirm that port 22 (or your custom port) is open. Use the command netsh advfirewall firewall show rule name=all to verify.
Summary
Setting up OpenSSH Server on Windows 11 provides a secure method for controlling your PC remotely. You can install it through Settings or PowerShell, then start the service and check your firewall. For better security, use key-based logins instead of passwords.
Was this guide helpful?
About the Author
Richard
Tech Writer, IT Professional
Richard is a writer at Geek Rewind who turns complex IT tasks into clear, step-by-step guides. He draws on years of hands-on experience in system administration and enterprise IT operations, focusing on Windows, Linux and WordPress: the problems people actually run into, and the fixes that work. His server and WordPress guides come from systems he runs himself. Richard builds and maintains the platform behind Geek Rewind, from its Ubuntu servers and Nginx configuration to its custom WordPress plugins. Many new tutorials start with readers' questions, and he's always glad to answer them in the comments.
how to connect ssh tunnel in cmd?
It says “Couldn’t install” 🙁 Is there a dependency? A running service maybe?
hi richard
what is the accoumd password here?
@melisa the Password is the same as you’ve set at your account on the machine to enter it locally