Create and manage Windows Server VMs
Stay organized with collections
Save and categorize content based on your preferences.
Windows
Compute Engine provides
public images with Windows Server
that you can use to create instances. For instructions on how to create a
Windows Server instance with SQL Server preinstalled, see
Creating SQL Server instances.
For more general information about Windows Server instances
and Windows applications that you can run on Compute Engine, see
Windows on Compute Engine.
Pricing
Windows Server images are premium images, and using them results in
additional charges.
If you haven't already, set up authentication.
Authentication verifies your identity for access to Google Cloud services and APIs. To run
code or samples from a local development environment, you can authenticate to
Compute Engine by selecting one of the following options:
Select the tab for how you plan to use the samples on this page:
Console
When you use the Google Cloud console to access Google Cloud services and
APIs, you don't need to set up authentication.
gcloud
Install the Google Cloud CLI.
After installation,
initialize the Google Cloud CLI by running the following command:
To use the Go samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Java samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Node.js samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Python samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To create an instance with Windows Server, specify the image
family for the specific version of Windows that you need.
Compute Engine offers several versions of Windows Server, most of
which are available as
Shielded VM images.
Shielded VM images offer security features like UEFI-compliant
firmware, Secure Boot, and vTPM-protected Measured Boot. For a list of the
available image families, see
public images.
If you plan on using Microsoft Active Directory (AD) with your new instance,
make sure the instance name is no longer than 15 characters, to meet the stated
maximum name length restrictions
of the system.
AD uses the NetBIOS names of machines, which are generated as the instance name
truncated to 15 characters. As a result, you might encounter the following error
when trying to sign in as a domain user:
The Security Database on the Server does not have a Computer Account for this Workstation Trust Relationship.
Create a Windows Server instance that uses an external IP to activate
This section describes how to create a Windows Server instance that has an
external IP address. Your VPC network must be configured to
allow access to kms.windows.googlecloud.com.
Create a Windows Server instance that uses an internal IP address to activate
Before you can create a Windows Server instance that has only an internal IP
address, you must verify or configure routes and firewall rules in your
VPC network to
allow access to kms.windows.googlecloud.com. Additionally, you
must enable Private Google Access
for subnets in your VPC network that contain Windows instances
with only internal IP addresses.
Because this instance does not have an external IP address, you cannot connect
to it directly over the Internet. You can connect from another network connected
to your VPC network by using
Cloud Interconnect or
Cloud VPN,
or you can first connect to a bastion instance over RDP and then connect to the
instance that has only an internal IP address.
For Windows activation and renewal, your VPC network must meet
the following routing and firewall rule requirements.
Routing requirements
Your Windows instances must be able to reach kms.windows.googlecloud.com
(35.190.247.13 or 2001:4860:4802:32::86) through a route whose next hop is the default Internet
gateway. You cannot activate Windows instances using an instance based NAT
gateway or Cloud NAT because kms.windows.googlecloud.com rejects
activation requests from IP addresses that are not confirmed to be
Compute Engine instances.
You can use the default route in your
VPC network to route traffic directly to
kms.windows.googlecloud.com. If you remove this route, or if you plan to do so
in the future,
create a custom static route with destination 35.190.247.13
or 2001:4860:4802:32::86, and next hop set to default Internet gateway, as
follows:
Replace ipv4-network or ipv6-network with the name
of your VPC network.
Either the default route or a custom static route permit
instances with external IP addresses to reach kms.windows.googlecloud.com. If
you have Windows instances without external IP addresses or using
Cloud NAT, you must also
enable Private Google Access
so that instances with only internal IP addresses can send traffic to the
external IP address for kms.windows.googlecloud.com (35.190.247.13 or
2001:4860:4802:32::86).
Firewall rule requirements
The implied allow egress firewall
rule allows instances to make requests and receive established responses. Unless
you have created custom firewall rules that deny egress, your Windows instances
can communicate with kms.windows.googlecloud.com.
If you customize firewall rules, it's a good practice to create a high priority
egress allow rule that explicitly permits communication with 35.190.247.13 or 2001:4860:4802:32::86.
This way, as you modify your firewall rules, you won't accidentally disable
Windows activation.
The following gcloud examples creates the recommended allow egress rule with
the highest priority:
Replace ipv4-network or ipv6-network with the name
of your VPC network.
Verifying that an instance has successfully started
Windows instances experience a longer startup time because of the sysprep
process. The Google Cloud console might show that the instance is running
even if the sysprep process is not yet complete. To check if your instance has
successfully started and is ready to be used, check the serial port output
with the following command:
Replace INSTANCE_NAME with the name of the instance that
you want to verify.
...[snip]...
Running schtasks with arguments /run /tn GCEStartup
--> SUCCESS: Attempted to run the scheduled task "GCEStartup".
-------------------------------------------------------------
Instance setup finished. INSTANCE_NAME is ready to use.
-------------------------------------------------------------
Enabling and disabling Windows instance features
If you have Windows instances with image versions v20170509 and later or
with agent version 4.1.0 and later, you can set instance configuration
in a config file or in
project or instance custom metadata.
The config file is in INI
format, and is located at the following path:
The system overrides configuration settings in the following order of priority
from the highest priority to the lowest priority:
Configuration parameters that you set in the config file
Configuration parameters set in instance-level custom metadata
Configuration parameters set in project-level custom metadata
For example, if you can enable the accountManager feature in a config file,
your instance ignores parameters that you set in custom metadata to disable
that feature.
One benefit of setting these parameters in the config file is that those
settings persist when you create a custom image for a Windows Server instance.
Instance-level custom metadata does not persist beyond the life of the instance.
You can disable different Windows instance features using the following
examples.
In custom metadata, set disable-account-manager to true in metadata.
Disable the address manager
Config file entry:
[addressManager]disable=true
In custom metadata, set disable-address-manager to true in metadata.
Windows Server Failover Clustering
Enable the Windows Server Failover Clustering agent:
Config file entry:
[wsfc]enable=true
In custom metadata, set enable-wsfc to true in metadata.
Using multiple internal load balancers
Specify the IP address of the internal load balancing instance
for failover clustering. This is an advanced configuration that
you don't need to set for a dedicated failover cluster.
Normally you use an instance of internal load balancing to direct
network traffic to one VM instance at a time. If you add
a second instance of internal load balancing that uses the failover
clustering VM instances as part of a load-balanced website backend,
you would have two internal load balancing IP addresses. If failover clustering
uses 10.0.0.10 and the website's load balancer uses 10.0.0.11,
you must specify the IP address of the load balancer that you use for failover
clustering. This disambiguates which address is in use for the cluster.
Config file entry:
[wsfc]addresses=10.0.0.10
In custom metadata, set wsfc-addrs to a 10.0.0.10.
Changing the clustering agent port
Set the failover clustering agent port. The default port is 59998.
You need to specify a port only when you want to use a different port:
Config file entry:
[wsfc]port=12345
In custom metadata, set wsfc-agent-port to the port number.
Image version notes
Older images don't use a config file and only have a subset of features.
Image versions between version v20160112 and version v20170509, or
Windows agent version between 3.2.1.0 and 4.0.0 require you to use the
following custom metadata values:
Set disable-account-manager to true in instance metadata to disable
the account manager.
Set disable-address-manager to true in instance metadata to disable
the address manager.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-09-30 UTC."],[],[]]