Free tools Windows power users keep installed
One-click scans. No signup required.
For most device-wide deployments, package WinSCP’s MSI as a Configuration Manager application, use its MSI product code for detection, and set the deployment type to install for the system. This gives you native Windows Installer detection and uninstall handling. The alternative setup EXE can also install silently, but it needs more care with installation scope, detection, and uninstall paths. SCCM is the familiar name; current Microsoft documentation and console use Configuration Manager.
Choose the installer and deployment scope
WinSCP provides both an MSI for corporate administrators and a classic setup executable. The MSI installs the complete WinSCP package, including translations, tools, and extensions, and does not offer configuration options. For a typical all-users deployment to device collections, it is the simpler Configuration Manager option. Choose the EXE if you specifically need its installer options or the required release is available only as an EXE. WinSCP installation documentation
| Choice | Best suited to | Key trade-off |
|---|---|---|
| MSI application | Device-based, machine-wide deployment with Windows Installer detection and uninstall. | Does not expose WinSCP installer configuration options. |
| Setup EXE with a script-installer deployment type | A release or workflow requiring Inno Setup options such as choosing all-users or current-user installation. | You must maintain suitable detection and uninstall logic yourself. |
Before packaging, decide whether the install is machine-wide or per-user. For device collections and all-users availability, use a machine-wide installer mode and configure Configuration Manager for Install for system. Test the chosen mode under the Configuration Manager client context, not only in an interactive administrator session.
Prepare and validate the installer
Download the installer from WinSCP’s official source. Record the exact version and preserve the original filename; do not reuse an old product code or assume the latest version number in a long-lived deployment guide. WinSCP says its installer should be digitally signed by Martin Prikryl and documents checking its signature and SHA-256 hash. For an EXE, for example:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- The Anker Advantage: Join the 50 million+ powered by our leading technology.
- Massive Expansion: Equipped with a USB C PD-IN charging port, 2 USB-A data ports, 2 HDMI ports, an Ethernet port, and a microSD/SD card reader, giving you an incredible range of functions—all from a single USB-C port.
- Dual HDMI Display: Stream or mirror content to a single device in stunning 4K@60Hz, or hook up two displays to both HDMI ports in 4K@30Hz. Note: For macOS, the display on both external monitors will be identical.
- Power Delivery Compatible: Compatible with USB-C Power Delivery to provide high-speed pass-through charging up to 85W. Please note: 100W PD wall charger and USB-C to C cable required.
- Compatibility: Supports USB-C, USB4, and Thunderbolt connections. Compatible with Windows 10 and 11, ChromeOS, and laptops equipped with DP Alt Mode and Power Delivery. Note: This device is not compatible with Linux.
certutil.exe -hashfile WinSCP-<version>-Setup.exe SHA256
Keep each release in a versioned source folder on a stable network location, rather than a packaging administrator’s Downloads folder. For example:
\SCCM-SOURCEApplicationsWinSCP<version>
WinSCP-<version>.msi
Test the exact installer content on a clean test machine before distributing it. Make sure no WinSCP instance is running during installation or upgrade: WinSCP’s installer will not run if it finds a running instance. WinSCP installation documentation
Deploy the MSI (recommended)
Create the application from the MSI
- In the Configuration Manager console, open Software Library > Application Management > Applications, then select Create Application.
- Choose Windows Installer (*.msi file) and browse to the versioned WinSCP MSI.
- Review the imported application and deployment-type details, then complete the wizard and add suitable Software Center metadata.
- Check the deployment type’s content location and installation program. Use the MSI in the versioned folder as the content source.
Configuration Manager can create an application from installation files and supports deployment types with content, detection, user experience, requirements, return codes, and dependencies. Microsoft: Create applications
Set install, uninstall, and detection
Use a quiet, no-restart Windows Installer command:
msiexec.exe /i "WinSCP-<version>.msi" /qn /norestart
For a troubleshooting run, add verbose logging to a location writable by the system account:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minutemsiexec.exe /i "WinSCP-<version>.msi" /qn /norestart /L*v "%WINDIR%TempWinSCP-MSI.log"
Use the product code belonging to the exact MSI being packaged for uninstall:
msiexec.exe /x "{PRODUCT-CODE-GUID}" /qn /norestart
Do not copy a product code from another release. Let the MSI application wizard identify it, or extract it from the exact MSI. Configure the detection method as Windows Installer using that MSI product code. This is more reliable than checking only whether a file named WinSCP.exe exists: a stale executable or portable copy could satisfy a simple existence check. Microsoft documents MSI product-code detection and installation behavior options. Microsoft: Add-CMMsiDeploymentType
Rank #2
- Detachable 2-in-1 Design for Desk & Travel — Features a 13-in-1 desktop docking station with a detachable 6-in-1 portable hub that snaps off for on-the-go use. One docking station replaces two, covering both your home office setup and mobile work needs without buying separate devices.
- Triple Display with Flexible Monitor Setup — Connect up to 3 monitors via 2× HDMI ports and 1x DisplayPort for a full desktop workstation. Supports up to 4K@60Hz (single display) or dual 2K@60Hz (dual displays) or triple 1080P@60hz (triple display). Perfect for data analysts, traders, and content creators who need screen real estate. (Note: macOS supports mirrored mode only on multiple external displays).
- All the Ports You Need in One Dock — 1× USB C upstream, 2× USB C Data at 5Gbps and 10Gbps, 3× USB-A, 2× HDMI, 1× DisplayPort, 1× Gigabit Ethernet, 1× 3.5mm audio, SD/TF card slots, and DC power input. Connect your monitors, keyboard, mouse, webcam, headphones, and wired network — all through a single USB C cable to your laptop.
- 100W Laptop Charging + 10Gbps Data Transfer — Delivers up to 100W Power Delivery to charge your laptop while running all connected peripherals. Includes a 140W power adapter to ensure stable performance under full load. One USB C Data port transfers files at 10Gbps — move a 1GB video in under 2 minutes.
- Wide Compatibility & Complete Package — Works with Dell XPS, Lenovo ThinkPad, HP Spectre, and most Windows laptops with USB C. Includes: Nano Docking Station (13-in-1), 3ft USB C cable (10Gbps), 140W power adapter with 5ft power cord, welcome guide, and 18-month warranty. Set up in under 2 minutes — plug and play, no drivers needed.
Set the deployment type for device deployment
For deployment to devices, configure Installation behavior: Install for system and Logon requirement: Whether or not a user is logged on. Choose Hide all for user notifications if the deployment is intended to be fully silent. Set reboot behavior according to organizational policy; the commands above request no restart. Microsoft defines system installation as installing once for availability to all users, unlike user installation, which targets the specified user. Microsoft: Add-CMMsiDeploymentType
Add only requirements your environment genuinely needs, such as a supported Windows OS. An unnecessary requirement can make the application unavailable or non-compliant even when the installer itself is fine.
Deploy the setup EXE silently (alternative)
For an all-users installation with the classic WinSCP setup executable, use:
WinSCP-<version>-Setup.exe /VERYSILENT /ALLUSERS /NORESTART
For a troubleshooting run, add the installer log switch:
WinSCP-<version>-Setup.exe /VERYSILENT /ALLUSERS /NORESTART /LOG="%WINDIR%TempWinSCP-Setup.log"
WinSCP’s Inno Setup-based installer documents /SILENT, /VERYSILENT, /ALLUSERS, /CURRENTUSER, /NORESTART, and /LOG. /VERYSILENT hides the progress window as well as prompts; /ALLUSERS selects administrative installation mode. Do not combine /ALLUSERS and /CURRENTUSER. WinSCP installation documentation
In the console, create the application by manually specifying its information, add a Script Installer deployment type, point content to the versioned source folder, and enter the silent install command. Configure a custom detection method that confirms the intended installation and version; a file-version rule is stronger than file existence alone. Verify the actual install path and registry view on each supported OS and installation mode instead of assuming a fixed path.
Rank #3
- 5-in-1 Connectivity: Equipped with a 4K HDMI port, a 5 Gbps USB-C data port, two 5 Gbps USB-A ports, and a USB C 100W PD-IN port. Note: The USB C 100W PD-IN port supports only charging and does not support data transfer devices such as headphones or speakers.
- Powerful Pass-Through Charging: Supports up to 85W pass-through charging so you can power up your laptop while you use the hub. Note: Pass-through charging requires a charger (not included). Note: To achieve full power for iPad, we recommend using a 45W wall charger.
- Transfer Files in Seconds: Move files to and from your laptop at speeds of up to 5 Gbps via the USB-C and USB-A data ports. Note: The USB C 5Gbps Data port does not support video output.
- HD Display: Connect to the HDMI port to stream or mirror content to an external monitor in resolutions of up to 4K@30Hz. Note: The USB-C ports do not support video output.
- What You Get: Anker 332 USB-C Hub (5-in-1), welcome guide, our worry-free 18-month warranty, and friendly customer service.
The classic installer places unins000.exe in the WinSCP installation directory, and its uninstaller accepts the same silent-style parameters apart from /LOADINF and /SAVEINF. A typical command is:
unins000.exe /VERYSILENT /NORESTART
Do not assume that executable is at one fixed path. Use the uninstall string recorded for the installed instance or a wrapper that resolves the actual path; test the command and detection under the same system or user context as the deployment.
Distribute content and deploy to a pilot
- Distribute the application content to the required distribution point or distribution point group.
- Wait for content status to confirm availability before targeting clients.
- Deploy as Available to a small test device collection first, so an administrator can install it from Software Center and validate behavior.
- After testing, deploy as Required to pilot and then broader production collections using the organization’s rollout schedule.
An Available deployment is installed when the user initiates it; a Required deployment installs by its configured deadline, though users may often start it earlier in Software Center. A client receiving policy is not the same as a client having downloaded content or successfully enforcing the installation. Microsoft: Understand application deployment installation
Verify installation and diagnose the client
On a pilot client, you can request evaluation without waiting for normal polling: open Control Panel > Configuration Manager > Actions, then run Machine Policy Retrieval & Evaluation Cycle and Application Deployment Evaluation Cycle.
Recommended Free Tools
- Confirm WinSCP appears in Installed Apps or Programs and Features, launches as a standard user, and reports the packaged version.
- Confirm Software Center and Configuration Manager detect the application as installed.
- Run enforcement again and verify it does not reinstall an already detected application.
- For machine-wide deployment, verify availability for a standard user who was not the installing administrator.
- Test uninstall on a non-production machine and check for an unexpected restart or lost configuration.
Review the client logs by stage: PolicyAgent.log for policy retrieval; LocationServices.log for distribution-point location; CAS.log and ContentTransferManager.log for content; AppEnforce.log for the command and exit code; and AppDiscovery.log for detection. Configuration Manager runs detection after enforcement to verify the installation, so an installer exit code alone does not establish that the app is installed. Microsoft: Understand application deployment installation
Upgrade WinSCP with a controlled release process
WinSCP says installing a newer version over an existing installation normally preserves and upgrades its configuration. Validate this for the specific MSI and installation modes you use. WinSCP installation documentation
Rank #4
- 14-in-1 Connectivity: Bring together all your devices with a 14-in-1 solution, perfect for charging, transferring data quickly, and managing dual displays.
- Ultra-Fast Docking Station: Deliver a powerful charge with 160W of total output, capable of charging up to four devices simultaneously through three USB-C ports at 100W max each and one USB-A port at 12W max.
- Master Your Data Flow with 11 Ports: Efficiently manage data across multiple devices with versatile ports offering speeds up to 10Gbps, complemented by dual 4K display and audio options.
- Dual Display: Connect to the dual HDMI ports to enjoy crystal-clear streaming or mirroring across 2 displays at up to 2K@60Hz with a DP 1.4 laptop or 1080p@60Hz with a DP 1.2 laptop. Note: This product does not support a 5120*1440 monitor.
- Compatibility: Supports USB-C, USB4, and Thunderbolt connections. Compatible with Windows 10 and 11, ChromeOS, and laptops that support DP Alt Mode and Power Delivery. Note: 1. For macOS, the displays on the both external monitors are identical. 2. This device is not compatible with Linux.
For controlled servicing, create a new Configuration Manager application for each materially different release, use its own versioned content and exact MSI product-code detection, and test it before rollout. Supersedence gives the old and new releases a distinct audit trail. Begin with uninstall of the superseded application disabled; enable it only if testing shows the new MSI cannot upgrade the prior version in place. Keep an older application available as a rollback target where your servicing policy allows it.
With EXE packaging, ensure detection is version-aware or an older installation may be reported as compliant. Recheck content, product code, and detection whenever the installer changes. Schedule upgrade enforcement when WinSCP is not expected to be running; do not terminate the process without accepting the risk of interrupting a transfer.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Keep user configuration separate from application deployment
A machine-wide WinSCP installation deploys binaries; it does not create the same saved sessions or preferences for every user. WinSCP supports registry-based configuration and INI files. Its /ini option selects an INI file, while /ini=nul uses defaults without saving settings on exit. WinSCP command-line documentation
winscp.exe /ini="C:ProgramDataWinSCPWinSCP.ini"
Treat a shared INI file as a security and administration decision: users may need write access, users can overwrite one another’s preferences, and saved credentials or sessions may expose sensitive information. Do not put passwords in an SCCM command line, broadly readable package source, or shared INI file. Handle hostnames, usernames, private-key paths, proxy settings, and credentials according to their different security needs.
Keep file-transfer automation separate
Installing WinSCP through Configuration Manager does not run a transfer. Automated transfers are a separate workflow using winscp.com or winscp.exe with /script or /command. WinSCP scripting documentation
option batch abort
option confirm off
open sftp://[email protected]/ -hostkey="ssh-ed25519 255 xx:xx:xx:xx:xx"
put "C:Sourcefile.txt" "/remote/path/"
exit
"C:Program Files (x86)WinSCPWinSCP.com" /ini=nul /script="C:ProgramDataWinSCPtransfer.txt" /log="C:ProgramDataWinSCPtransfer.log"
Verify the executable path on the target installation. WinSCP advises verifying the SSH host key on first connection; automation must specify and validate it rather than treating installation as proof of a trusted endpoint. Keep transfer scheduling and credentials in a separately managed workflow. WinSCP scripting documentation
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Best Value
- Powerful compatibility: Power essential productivity across the AI PC workplace. The Dell Pro Dock offers enhanced compatibility and drives up to 100W of power to new mainstream Dell AI PCs and non-Dell PCs.
- Modern manageability: The Dell Pro Dock is part of the world’s most manageable commercial docking family, with flexible management capabilities, designed to uplevel IT efficiency and keep users working without disruption.
- Thoughtful design: Configure your workspace with an ambidextrous USB-C cable that can be routed left or right. Features a new robust USB-C connector, designed for enhanced durability.
- A leader in sustainable innovation: Experience up to 72% reduction in power consumption on standby mode. Built with at least 65% postconsumer recycled materials and packaged with 100% recycled or renewable packaging.
- Upgraded for modern work: Expand your views with native support for up to four high-res displays. Keep your PC accessories connected and charged with the latest ports, while staying productive with faster USB and network speeds.
Troubleshoot common deployment failures
Configuration Manager says Failed, but WinSCP is installed
Compare AppEnforce.log and AppDiscovery.log, then verify the actual version and installation scope. Common causes include a product code from a different MSI, a detection rule targeting the wrong version or registry view, or an EXE detection script that returns the wrong result. Run the detection logic under the same system context as Configuration Manager.
The installation does not start or content cannot be found
Check that distribution completed, the device can locate a distribution point through its boundary group, the deployment targets the intended collection, requirements are satisfied, and the deployment type is enabled and applicable. Use CAS.log, ContentTransferManager.log, LocationServices.log, and PolicyAgent.log to identify whether the failure is in policy, location, or content transfer.
The install hangs or an upgrade refuses to run
Close WinSCP before retrying. Its installer will not run while a WinSCP instance is open. Schedule deployment outside expected use or use a process check and a controlled retry strategy. Avoid forced termination if a transfer could be interrupted. WinSCP installation documentation
The install appears for only one user
Check both sides of installation scope: the Configuration Manager deployment type should use Install for system, and an EXE intended for all users should include /ALLUSERS, not /CURRENTUSER. A successful interactive test in the packaging administrator’s account does not verify system-context behavior.
Settings change or disappear
Configuration can differ when changing between per-user and all-users modes, switching between registry and INI configuration, uninstalling, or downgrading. WinSCP warns that a downgrade can lose some configuration and recommends backing it up beforehand. WinSCP installation documentation
The installer succeeds but WinSCP is not usable
Confirm the executable launches and the expected version is present. Application installation does not establish network access, SFTP permissions, credential validity, host-key trust, or a working transfer. Validate those separately without using a production transfer as an installation test.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

