This guide describes how to install StrongDM on Windows. The primary download package includes the StrongDM Desktop application and a command-line interface (CLI). You can optionally download the CLI independently from the Admin UI.
If you intend to use StrongDM with Windows Subsystem for Linux (WSL) please see the WSL page for more information.
Use the following steps to the desktop app and CLI on Windows. To bypass the desktop app, you can download the CLI independently.
Open the invitation email you received for your StrongDM account.
Click the link included in the email to set your password.
Log in to StrongDM and go to the Download & Install page in the Admin UI.
Under Windows, click Download StrongDM for Windows to download the desktop app and CLI immediately, or click Show download options for other options.
EXE: This full installer version includes the desktop app and CLI together. Available for x86 architectures, the EXE is installed manually. When run as administrator, the EXE installs the StrongDM Virtual Network Adapter, which enables you to access Virtual Networking Mode resources that may be available to you. When run as a non-administrator, StrongDM is installed, but the adapter is not installed or updated. The EXE is the recommended installation option.
MSI: This installer version includes the desktop app and CLI together. Available for x86 architectures, the MSI provides easy prompts that guide you through the installation process.
CLI: The StrongDM CLI option includes only the CLI (not the desktop app) for x86-64 or ARM64 architectures. Download and install the CLI only if you don’t want to install the desktop app.
Once the download is successful, the file name appears as SDM-<VERSION_NUMBER>.msi or SDM-<VERSION_NUMBER>.exe, depending on the selected kind.
Optionally, check that the downloaded binary is legitimate and verify the checksum using PowerShell, as in the following example:
To install StrongDM with the full version (EXE), follow these steps.
Locate the downloaded EXE file (SDM-<VERSION_NUMBER>.exe), which is typically in your Downloads folder.
Right-click on the installer and select Run as Admistrator. A dialog box appears.
Follow the instructions to run the installation.
To install StrongDM from the Command Prompt, run the EXE installer as in the example shown.
SDM-21.58.0.exe
When run as administrator, the EXE installs the StrongDM Virtual Network Adapter, which enables you to access Virtual Networking Mode resources that may be available to you. If you want to install the desktop app without the adapter, don’t run it as administrator.
To install StrongDM (SDM) with the installer version (MSI), follow these steps.
Double-click the downloaded MSI file (SDM-<VERSION_NUMBER>.msi). The SDM Setup Wizard opens.
On the welcome screen, click Next.
Choose one of the following installation scopes and then click Next:
Install just for you installs StrongDM in a per-user folder that is available for only your user account (for example, C:\Users\<YOUR-NAME>\AppData\Local\Programs\SDM). This scope does not require local Administrator privileges.
Install for all users of this machine installs StrongDM in a per-machine folder by default that is available for all users. You can change the default installation folder. This scope requires that you have local Administrator privileges.
Use the Back button to review or change any of your installation settings, or click Cancel to exit the setup wizard. When you’re satisfied with your settings, click Install.
When installation is complete, the setup wizard provides the option to run StrongDM. If you wish to open the desktop app now, keep the Run SDM checkbox selected. If you don’t, uncheck Run SDM.
To install StrongDM with the full version (EXE), follow these steps.
Locate the downloaded EXE file (SDM-<VERSION_NUMBER>.exe), which is typically in your Downloads folder.
Right-click on the installer and select Run as Admistrator. A dialog box appears.
Follow the instructions to run the installation.
To install StrongDM from the Command Prompt, run the EXE installer as in the example shown.
SDM-21.58.0.exe
When run as administrator, the EXE installs the StrongDM Virtual Network Adapter, which enables you to access Virtual Networking Mode resources that may be available to you. If you want to install the desktop app without the adapter, don’t run it as administrator.
As a last installation step, you need to set the SDM_DOMAIN environment variable to tell your desktop app where to find your StrongDM service. This can be done automatically each time your computer is started by setting an environment variable.
In Windows, go to Control Panel > System > Advanced System Settings.
In Environment Variables, go to the System Variables section and create a new system variable SDM_DOMAIN with a value of uk.strongdm.com, then select OK.
To install StrongDM (SDM) with the installer version (MSI), follow these steps.
Double-click the downloaded MSI file (SDM-<VERSION_NUMBER>.msi). The SDM Setup Wizard opens.
On the welcome screen, click Next.
Choose one of the following installation scopes and then click Next:
Install just for you installs StrongDM in a per-user folder that is available for only your user account (for example, C:\Users\<YOUR-NAME>\AppData\Local\Programs\SDM). This scope does not require local Administrator privileges.
Install for all users of this machine installs StrongDM in a per-machine folder by default that is available for all users. You can change the default installation folder. This scope requires that you have local Administrator privileges.
Use the Back button to review or change any of your installation settings, or click Cancel to exit the setup wizard. When you’re satisfied with your settings, click Install.
When installation is complete, the setup wizard provides the option to run StrongDM. If you wish to open the desktop app now, keep the Run SDM checkbox selected. If you don’t, uncheck Run SDM.
Click Finish to exit the setup wizard.
As a last installation step, you need to set the SDM_DOMAIN environment variable to tell your desktop app where to find your StrongDM service. This can be done automatically each time your computer is started by setting an environment variable.
In Windows, go to Control Panel > System > Advanced System Settings.
In Environment Variables, go to the System Variables section and create a new system variable SDM_DOMAIN with a value of uk.strongdm.com, then select OK.
To install StrongDM with the full version (EXE), follow these steps.
Locate the downloaded EXE file (SDM-<VERSION_NUMBER>.exe), which is typically in your Downloads folder.
Right-click on the installer and select Run as Admistrator. A dialog box appears.
Follow the instructions to run the installation.
To install StrongDM from the Command Prompt, run the EXE installer as in the example shown.
SDM-21.58.0.exe
When run as administrator, the EXE installs the StrongDM Virtual Network Adapter, which enables you to access Virtual Networking Mode resources that may be available to you. If you want to install the desktop app without the adapter, don’t run it as administrator.
As a last installation step, you need to set the SDM_DOMAIN environment variable to tell your desktop app where to find your StrongDM service. This can be done automatically each time your computer is started by setting an environment variable.
In Windows, go to Control Panel > System > Advanced System Settings.
In Environment Variables, go to the System Variables section and create a new system variable SDM_DOMAIN with a value of eu.strongdm.com, then select OK.
To install StrongDM (SDM) with the installer version (MSI), follow these steps.
Double-click the downloaded MSI file (SDM-<VERSION_NUMBER>.msi). The SDM Setup Wizard opens.
On the welcome screen, click Next.
Choose one of the following installation scopes and then click Next:
Install just for you installs StrongDM in a per-user folder that is available for only your user account (for example, C:\Users\<YOUR-NAME>\AppData\Local\Programs\SDM). This scope does not require local Administrator privileges.
Install for all users of this machine installs StrongDM in a per-machine folder by default that is available for all users. You can change the default installation folder. This scope requires that you have local Administrator privileges.
Use the Back button to review or change any of your installation settings, or click Cancel to exit the setup wizard. When you’re satisfied with your settings, click Install.
When installation is complete, the setup wizard provides the option to run StrongDM. If you wish to open the desktop app now, keep the Run SDM checkbox selected. If you don’t, uncheck Run SDM.
Click Finish to exit the setup wizard.
As a last installation step, you need to set the SDM_DOMAIN environment variable to tell your desktop app where to find your StrongDM service. This can be done automatically each time your computer is started by setting an environment variable.
In Windows, go to Control Panel > System > Advanced System Settings.
In Environment Variables, go to the System Variables section and create a new system variable SDM_DOMAIN with a value of eu.strongdm.com, then select OK.
Use these steps to launch the desktop app on Windows. When you launch the application, all authentications and resource access get routed through StrongDM.
Open the Start menu and search for SDM or navigate to the Downloads folder. Click to launch the SDM application.
Click the sdm icon in the tray.
Enter the email and password created during the email invitation step. You may also be redirected to your single sign-on (SSO) provider.
After logging in, a list of resources you have permission to access appears in the Resource Center.
Click one of these resources to enable a connection and gain access. A green lightning bolt icon appears next to the connected resource.
You can now connect to the resource on your machine using your preferred tool. When prompted for connection information, you can usually use localhost for the hostname/IP, leave the username and password blank, and specify the port listed next to the resource in StrongDM Desktop. If the connection fails using these defaults, check the Connect to Resources documentation for more information.
If you click a website resource, it launches in your default browser. To disconnect from any resource, click the named instance in the desktop app and the green connection icon disappears. Any existing connections from your local machine to the resource are immediately disabled.
By default, StrongDM requires a manual launch whenever your Windows machine is started or restarted. With the following steps, you can optionally configure StrongDM to automatically run at startup.
Open the Windows search and type run. Launch the Run application. You can also use the shortcut Windows logo button + R.
Type shell:common startup and click OK. The Startup folder opens.
Copy the SDM shortcut from the app menu (for example, C:\Users\[user]\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\StrongDM) and paste it in the Startup folder. When you restart your computer, the StrongDM Desktop app appears in the taskbar. Depending on your network settings, you may have to allow access for the sdm32.exe file.
Windows 10 and 11 come with OpenSSH already installed. However, the executable is not where StrongDM looks for it by default. In order to use sdm ssh commands, a symbolic link to the ssh.exe binary must be created in the WindowsApps path.
This can be accomplished by opening PowerShell (as Administrator) and running the following command:
On Windows, you can bypass the desktop app and download the CLI independently. Use the following steps to install the CLI only.
Open the invitation email you received for your StrongDM account.
Click the link included in the email to set your password.
Log in to StrongDM and go to the Download & Install page in the Admin UI.
Under Windows, click Show download options.
From the Download the StrongDM CLI section, download the StrongDM CLI for your architecture (x86-64 or x86). The files are downloaded to a zipped folder on your computer. This depends on your architecture, but the folder name appears as sdmcli_<VERSION_NUMBER>_windows_amd64, with a file similar to sdm.amd64.exe inside. Unzip the files.
Take the unzipped sdm.amd64.exe file and copy it to a directory in your PATH parameter. The suggested location is C:\Users\[user]\AppData\Local\Microsoft\WindowsApps\sdm.exe, but any location specified in PATH is acceptable.
Name the copied file sdm rather than sdm.amd64 so that you can call it via sdm commands. This change is consistent with CLI usage throughout the StrongDM documentation.
Test that the CLI is installed correctly by running sdm --version. If it is correctly installed, the version displays.
The CLI does not update automatically. To ensure that it is up to date, periodically run sdm update.