Introduction

Ansible automates Windows servers just as effectively as Linux — managing configuration, deploying software, and orchestrating updates across your entire Windows fleet. Unlike Linux (which uses SSH), Windows automation uses WinRM (Windows Remote Management) for communication.

Prerequisites

WinRM Setup on Windows Targets

Windows targets need WinRM enabled. Run this PowerShell script on each target:

# Enable WinRM with HTTPS
winrm quickconfig -transport:https

# Or use the Ansible setup script
Invoke-WebRequest -Uri https://raw.githubusercontent.com/ansible/ansible/devel/examples/scripts/ConfigureRemotingForAnsible.ps1 -OutFile ConfigureRemotingForAnsible.ps1
.\ConfigureRemotingForAnsible.ps1

Ansible Controller Setup

# Install pywinrm on the Ansible controller
pip install pywinrm

# Or with Kerberos support
pip install pywinrm[kerberos]

Inventory Configuration

# inventory.ini
[windows]
win01.example.com
win02.example.com

[windows:vars]
ansible_user=ansible_admin
ansible_password="{{ vault_win_password }}"
ansible_connection=winrm
ansible_winrm_transport=ntlm
ansible_winrm_server_cert_validation=ignore
ansible_port=5986

Verify Connectivity

- name: Test Windows connectivity
  hosts: windows
  tasks:
    - name: Ping Windows host
      ansible.windows.win_ping:
ansible windows -m win_ping -i inventory.ini

Essential Windows Modules

ModulePurpose
win_pingTest connectivity
win_copyCopy files to Windows
win_fileManage files and directories
win_userManage local users
win_groupManage local groups
win_serviceManage Windows services
win_chocolateyInstall software via Chocolatey
win_updatesManage Windows Updates
win_rebootReboot Windows hosts
win_commandRun commands
win_shellRun PowerShell commands
win_regeditManage registry keys
win_featureManage Windows features/roles
win_statGet file information
win_templateDeploy Jinja2 templates
win_get_urlDownload files
win_robocopyRobocopy file sync
win_scheduled_taskManage scheduled tasks
win_firewall_ruleManage firewall rules
win_dscApply DSC resources

Tutorials by Category

Getting Started

System Administration

File Management

User & Group Management

Troubleshooting

Common Patterns

Windows Server Baseline

---
- name: Windows server baseline
  hosts: windows
  tasks:
    - name: Install essential software
      chocolatey.chocolatey.win_chocolatey:
        name:
          - 7zip
          - notepadplusplus
          - git
        state: present

    - name: Enable Windows features
      ansible.windows.win_feature:
        name:
          - NET-Framework-45-Core
          - Web-Server
        state: present

    - name: Configure Windows Firewall
      community.windows.win_firewall_rule:
        name: Allow HTTPS
        localport: 443
        protocol: tcp
        direction: in
        action: allow
        state: present

    - name: Set timezone
      community.windows.win_timezone:
        timezone: "Eastern Standard Time"

Windows Update with Reboot

- name: Patch Windows servers
  hosts: windows
  serial: 2
  tasks:
    - name: Install security updates
      ansible.windows.win_updates:
        category_names:
          - SecurityUpdates
          - CriticalUpdates
        reboot: true
        reboot_timeout: 1800
      register: update_result

    - name: Show update summary
      ansible.builtin.debug:
        msg: "Installed {{ update_result.installed_update_count }} updates, reboot {{ 'required' if update_result.reboot_required else 'not needed' }}"

Linux vs Windows Module Mapping

TaskLinux ModuleWindows Module
Test connectionpingwin_ping
Copy filescopywin_copy
Manage filesfilewin_file
Install packagesapt/dnfwin_chocolatey
Manage servicesservicewin_service
Manage usersuserwin_user
Run commandscommandwin_command
Run shellshellwin_shell
Get file infostatwin_stat
Rebootrebootwin_reboot
Templatestemplatewin_template
Download filesget_urlwin_get_url

Conclusion

Ansible automates Windows just as effectively as Linux — you just need WinRM instead of SSH and win_* modules instead of their Linux equivalents. Start with WinRM configuration and win_ping verification, then move to software management with Chocolatey, Windows Updates for patching, and registry/service management for configuration. The module mapping between Linux and Windows is nearly 1:1, making it easy for existing Ansible users to extend their automation to Windows environments.