Windows Server administration from a Mac
RDP for the desktop sessions, PowerShell over SSH for everything scriptable: Windows Server in tabs of the same Mac window.
By Lucas Russo, developer of SSHive · Updated
Windows Server has shipped an OpenSSH server since 2019, which gives you PowerShell over SSH next to the classic RDP desktop. The split works well from a Mac: SSH for scripted work and quick checks, RDP for what really needs the graphical session, such as Server Manager, IIS Manager or the Active Directory tools.
SSHive does both, in tabs of the same window, with a profile per server. Its RDP client signs in with Network Level Authentication and Active Directory accounts; it is part of Pro, as is RDP in the iPhone and iPad app.
Turn on OpenSSH on Windows Server
On Windows Server 2025, OpenSSH is already installed: enable it in Server Manager > Local Server > Remote SSH Access. On 2019 and 2022, install it from an elevated PowerShell with
Add-WindowsCapability -Online -Name OpenSSH.Server~~~~0.0.1.0, then run Start-Service sshd and Set-Service -Name sshd -StartupType Automatic. Setup creates the OpenSSH-Server-In-TCP firewall rule for port 22.
The default shell is cmd. To land in PowerShell instead:
New-ItemProperty -Path "HKLM:\SOFTWARE\OpenSSH" -Name DefaultShell -Value "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -PropertyType String -Force
For key logins with an administrator account, the public key goes in C:\ProgramData\ssh\administrators_authorized_keys, not in the user's own .ssh folder.The desktop over RDP
Create an RDP profile with the server name, the user and the password, and for a domain account the domain in the Domain field (leave it empty for a local account). The session opens in a tab. The resolution fits the window or a size you choose, a quality setting trades sharpness for bandwidth and lowers itself on a slow link, text copied on either side pastes on the other, and a button sends Ctrl+Alt+Del. SSHive also remembers the server's certificate and stops if it changes, telling you whether it looks like a routine renewal or a different machine.
Over the internet, do not expose port 3389. Since the server runs OpenSSH, tunnel RDP through it: a local tunnel from 13389 to
localhost:3389 on the SSH profile, and the RDP profile pointed at localhost:13389. The RDP guide has the details.What is free here, and what needs Pro
The PowerShell side is free: SSH, SFTP to copy files to the server with uploads of up to 10 MB per file, and one local tunnel per profile. The RDP desktop is SSHive Pro, a one-time $12.99 that unlocks RDP on the Mac, iPhone and iPad together.
Frequently asked questions
Does it work with hosts joined to Microsoft Entra ID?+
SSHive signs in with an Active Directory domain account or a local account, over NLA. It does not do the Microsoft Entra ID web sign-in (formerly Azure AD). For a host that accepts nothing else, use Windows App (formerly Microsoft Remote Desktop).
Can I manage the server from my iPhone as well?+
Yes. The iPhone and iPad remote desktop app does RDP with NLA and Active Directory too, and the same Pro purchase unlocks it on both. SSH is there as well for the PowerShell side.
Related SSHive features
Step-by-step guides
Try SSHive Free for macOS
Get the all-in-one SSH, SFTP, RDP and VNC client for Mac. Free download, no signup required.