A Windows computer can serve as a remote development node or home server. This guide covers public-key authentication, PowerShell 7, Windows Terminal, and laptop power management, including administrator accounts and Modern Standby.

1. Configure OpenSSH public-key authentication

Windows OpenSSH chooses a public-key file according to whether the account belongs to the local Administrators group. Standard accounts use ~/.ssh/authorized_keys; administrator accounts use C:\ProgramData\ssh\administrators_authorized_keys by default. Confirm which kind of account you use before configuring SSH. See Microsoft’s OpenSSH server configuration.

1.1 Set up the administrator public-key file

Open PowerShell as an administrator and add public keys to the shared administrator key file:

$keys = "$env:ProgramData\ssh\administrators_authorized_keys"
notepad $keys

Put each public key on its own line. The file’s ACL should grant access only to SYSTEM and the Administrators group:

icacls $keys /inheritance:r
icacls $keys /grant "Administrators:F" "SYSTEM:F"

The Windows OpenSSH service uses this restricted file. Do not add the currently logged-in account’s personal permissions to the shared administrator key file.

1.2 Set up a standard account’s public-key file

For a standard account, store the key in that account’s .ssh directory. These commands create the directory and file, then remove inherited permissions:

$sshDir = Join-Path $HOME ".ssh"
$keys = Join-Path $sshDir "authorized_keys"
New-Item -ItemType Directory -Path $sshDir -Force | Out-Null
New-Item -ItemType File -Path $keys -Force | Out-Null
notepad $keys

icacls $keys /inheritance:r
icacls $keys /grant:r "$($env:USERNAME):(F)" "SYSTEM:(F)"

Paste each public key as a single line and save the file. To confirm or change the public-key path, inspect the Match Group administrators block in %ProgramData%\ssh\sshd_config. After editing the configuration, restart the service from an elevated PowerShell session:

Restart-Service sshd

1.3 Avoid UTF-8 BOM parsing issues

Windows PowerShell 5.1 writes UTF-8 with a BOM when you use -Encoding UTF8; PowerShell 7 defaults to UTF-8 without a BOM. Keep authorized_keys plain and compatible by specifying utf8NoBOM in PowerShell 7, or use .NET to write UTF-8 without a BOM in Windows PowerShell 5.1. See PowerShell character encoding.

PowerShell 7:

# $keys points to the authorized_keys file selected in section 1.1 or 1.2.
(Get-Content "$HOME\.ssh\id_ed25519.pub" -Raw).Trim() |
    Set-Content $keys -Encoding utf8NoBOM

Windows PowerShell 5.1:

# $keys points to the authorized_keys file selected in section 1.1 or 1.2.
$publicKey = (Get-Content "$HOME\.ssh\id_ed25519.pub" -Raw).Trim()
[System.IO.File]::WriteAllText(
    $keys,
    $publicKey + [Environment]::NewLine,
    [System.Text.UTF8Encoding]::new($false)
)

2. Make PowerShell 7 the default OpenSSH shell

The Windows Terminal default only affects terminals opened locally. To start SSH sessions in PowerShell 7, set OpenSSH’s DefaultShell registry value. Open PowerShell as an administrator, find pwsh.exe, then write the registry value:

$pwshPath = (Get-Command pwsh.exe -ErrorAction SilentlyContinue).Source
if (-not $pwshPath) {
    $pwshPath = "C:\Program Files\PowerShell\7\pwsh.exe"
}

New-Item -Path "HKLM:\SOFTWARE\OpenSSH" -Force | Out-Null
New-ItemProperty `
    -Path "HKLM:\SOFTWARE\OpenSSH" `
    -Name DefaultShell `
    -Value $pwshPath `
    -PropertyType String `
    -Force

After disconnecting and reconnecting, the SSH session will use the new shell. If pwsh.exe is installed elsewhere, set $pwshPath to its actual location.

3. Configure Windows Terminal

A Windows Terminal profile can select the default shell and whether to run as administrator. Create or confirm a PowerShell 7 profile in Terminal’s settings, then set its GUID as defaultProfile. For example:

{
  "defaultProfile": "{YOUR-POWERSHELL-7-PROFILE-GUID}",
  "profiles": {
    "list": [
      {
        "guid": "{YOUR-POWERSHELL-7-PROFILE-GUID}",
        "name": "PowerShell 7",
        "commandline": "pwsh.exe",
        "elevate": false
      }
    ]
  }
}

Keep the profile’s other fields and profiles; do not replace the entire settings.json with this abbreviated example. Setting elevate to true starts that profile as an administrator by default. For routine development, keep it false. See Windows Terminal profile settings.

4. Use the Vim bundled with Git for Windows in PowerShell

If Git for Windows is installed, you can call its bundled Vim without adding the entire Git\usr\bin directory to the global PATH. Confirm Vim’s actual installation path, then add functions to your PowerShell profile:

$vimPath = "C:\Program Files\Git\usr\bin\vim.exe"
if (-not (Test-Path $vimPath)) {
    throw "Vim not found at $vimPath; update the path for this Git installation."
}

if (-not (Test-Path $PROFILE)) {
    New-Item -ItemType File -Path $PROFILE -Force | Out-Null
}

@"
function vim { & `"$vimPath`" `$args }
function vi  { & `"$vimPath`" `$args }
"@ | Add-Content -Path $PROFILE

Reopen PowerShell or run . $PROFILE to load the profile. If the same functions already exist, remove the old definitions before appending them again.

If you no longer need a separately installed Vim, first confirm the package ID and then uninstall it:

winget list --id vim.vim
winget uninstall --id vim.vim

Do not delete directories whose purpose is unclear just to remove Vim.

5. Configure a laptop as a remote node

Run powercfg /a to see which sleep states the computer supports. If you want the laptop to keep serving requests while its lid is closed, first confirm that its cooling, power supply, and network equipment can handle sustained operation. Disabling sleep increases power use and heat, and does not guarantee that every laptop will keep its network connection while closed.

5.1 Set the lid action and display timeout

The following settings take no action when the lid is closed on AC power, turn off the display after five minutes, and disable idle sleep on AC power:

powercfg /setacvalueindex SCHEME_CURRENT SUB_BUTTONS LIDACTION 0
powercfg /change monitor-timeout-ac 5
powercfg /change standby-timeout-ac 0
powercfg /setactive SCHEME_CURRENT

To also keep the laptop awake when the lid is closed on battery, you can set:

powercfg /setdcvalueindex SCHEME_CURRENT SUB_BUTTONS LIDACTION 0
powercfg /setactive SCHEME_CURRENT

Power plans and device firmware expose different options. After changing them, use powercfg /query to check the effective values, then test the SSH connection in the intended power state.

5.2 Understand Modern Standby’s network behavior

Windows and device firmware jointly manage network connectivity during Modern Standby. Current Windows versions adjust connectivity according to the power state; they do not guarantee that SSH or other services remain available during sleep. The older CONNECTIVITYINSTANDBY power setting does not apply to Modern Standby platforms running Windows 10 version 2004 and later. Do not treat it as a universal switch for keeping the network online. See Modern Standby network connectivity.

Use these commands to check sleep states and inspect standby connectivity information in the system power report:

powercfg /a
powercfg /spr

Whether a network adapter can stay connected during standby also depends on hardware and drivers. Consult the Modern Standby validation overview and test the actual device. If a service must remain continuously available, prevent the system from sleeping or use hardware designed for always-on service.

Conclusion

These settings cover several common parts of a Windows remote node:

  1. Use the correct OpenSSH key file and ACL for the account type.
  2. Keep SSH shell settings separate from the local Windows Terminal settings.
  3. Call the Vim bundled with Git for Windows from a PowerShell profile.
  4. Check the device’s sleep capabilities before changing its power plan, then test network availability on the actual device.

References