Introduction
Ansible automates Windows servers just as effectively as Linux — managing configuration, deploying software, and orchestrating updates across your entire Windows fleet. Unlike Linux (which uses SSH), Windows automation uses WinRM (Windows Remote Management) for communication.
Prerequisites
WinRM Setup on Windows Targets
Windows targets need WinRM enabled. Run this PowerShell script on each target:
# Enable WinRM with HTTPS
winrm quickconfig -transport:https
# Or use the Ansible setup script
Invoke-WebRequest -Uri https://raw.githubusercontent.com/ansible/ansible/devel/examples/scripts/ConfigureRemotingForAnsible.ps1 -OutFile ConfigureRemotingForAnsible.ps1
.\ConfigureRemotingForAnsible.ps1
Ansible Controller Setup
# Install pywinrm on the Ansible controller
pip install pywinrm
# Or with Kerberos support
pip install pywinrm[kerberos]
Inventory Configuration
# inventory.ini
[windows]
win01.example.com
win02.example.com
[windows:vars]
ansible_user=ansible_admin
ansible_password="{{ vault_win_password }}"
ansible_connection=winrm
ansible_winrm_transport=ntlm
ansible_winrm_server_cert_validation=ignore
ansible_port=5986
Verify Connectivity
- name: Test Windows connectivity
hosts: windows
tasks:
- name: Ping Windows host
ansible.windows.win_ping:
ansible windows -m win_ping -i inventory.ini
Essential Windows Modules
| Module | Purpose |
|---|---|
win_ping | Test connectivity |
win_copy | Copy files to Windows |
win_file | Manage files and directories |
win_user | Manage local users |
win_group | Manage local groups |
win_service | Manage Windows services |
win_chocolatey | Install software via Chocolatey |
win_updates | Manage Windows Updates |
win_reboot | Reboot Windows hosts |
win_command | Run commands |
win_shell | Run PowerShell commands |
win_regedit | Manage registry keys |
win_feature | Manage Windows features/roles |
win_stat | Get file information |
win_template | Deploy Jinja2 templates |
win_get_url | Download files |
win_robocopy | Robocopy file sync |
win_scheduled_task | Manage scheduled tasks |
win_firewall_rule | Manage firewall rules |
win_dsc | Apply DSC resources |
Tutorials by Category
Getting Started
- Install Ansible on Windows 10 WSL
- Install Ansible on Windows 11 WSL
- Configure Windows Host for Ansible (WinRM)
- Ansible vs Ansible-Core Packages
- Test Windows Host: win_ping Module
System Administration
- Reboot Windows: win_reboot
- Install Software: win_chocolatey
- Install Docker on Windows
- Install Google Chrome on Windows
- Check .NET Framework Version
- Manage Windows Registry
- Rolling Windows Updates
- win_command vs win_shell
File Management
- Check Directory Exists: win_stat
- Copy Files from Windows: fetch
- Create Directories: win_file
- Download Files: win_get_url
- Backup with Robocopy
- Copy Files to Windows: win_copy
User & Group Management
- Create Local Users: win_user
- Manage Local Groups: win_group
- Change User Password
- Remove Local Users
- Remove Local Groups
Troubleshooting
Common Patterns
Windows Server Baseline
---
- name: Windows server baseline
hosts: windows
tasks:
- name: Install essential software
chocolatey.chocolatey.win_chocolatey:
name:
- 7zip
- notepadplusplus
- git
state: present
- name: Enable Windows features
ansible.windows.win_feature:
name:
- NET-Framework-45-Core
- Web-Server
state: present
- name: Configure Windows Firewall
community.windows.win_firewall_rule:
name: Allow HTTPS
localport: 443
protocol: tcp
direction: in
action: allow
state: present
- name: Set timezone
community.windows.win_timezone:
timezone: "Eastern Standard Time"
Windows Update with Reboot
- name: Patch Windows servers
hosts: windows
serial: 2
tasks:
- name: Install security updates
ansible.windows.win_updates:
category_names:
- SecurityUpdates
- CriticalUpdates
reboot: true
reboot_timeout: 1800
register: update_result
- name: Show update summary
ansible.builtin.debug:
msg: "Installed {{ update_result.installed_update_count }} updates, reboot {{ 'required' if update_result.reboot_required else 'not needed' }}"
Linux vs Windows Module Mapping
| Task | Linux Module | Windows Module |
|---|---|---|
| Test connection | ping | win_ping |
| Copy files | copy | win_copy |
| Manage files | file | win_file |
| Install packages | apt/dnf | win_chocolatey |
| Manage services | service | win_service |
| Manage users | user | win_user |
| Run commands | command | win_command |
| Run shell | shell | win_shell |
| Get file info | stat | win_stat |
| Reboot | reboot | win_reboot |
| Templates | template | win_template |
| Download files | get_url | win_get_url |
Related Articles
- Install Software: win_chocolatey
- Reboot Windows: win_reboot
- Test Windows: win_ping
- Ansible Best Practices Guide
- Ansible Roles Explained
Conclusion
Ansible automates Windows just as effectively as Linux — you just need WinRM instead of SSH and win_* modules instead of their Linux equivalents. Start with WinRM configuration and win_ping verification, then move to software management with Chocolatey, Windows Updates for patching, and registry/service management for configuration. The module mapping between Linux and Windows is nearly 1:1, making it easy for existing Ansible users to extend their automation to Windows environments.