Skip to content
WindowsIntermediate

How to Set Up an FTP Server on Windows 10, 11, and Windows Server

Quick Answer You can configure Windows 10, Windows 11, or Windows Server 2019, 2022, and 2025 as an FTP server using the FTP Service component of Internet In...

BI
Bison Technical Team Enterprise IT specialists
Updated 05 Oct 2026 11 min read 15 total views
Structured technical guidanceSafety notes included where requiredSources listed below

Quick Answer

You can configure Windows 10, Windows 11, or Windows Server 2019, 2022, and 2025 as an FTP server using the FTP Service component of Internet Information Services (IIS). Install the service and IIS Management Console, create a dedicated folder and user account, add an FTP site, and configure permissions and firewall access.

For encrypted transfers, configure explicit FTPS: FTP secured with Transport Layer Security (TLS). Require encryption, select a server certificate, and connect with an FTPS-capable client. This guide uses TCP port 21 for the control connection and an example passive data range of TCP 50000–50100. :chatgpt-content-reference{index="0"}

Advertisement

Before You Begin

  • Administrator access: Required to install Windows components, create accounts, and change server or firewall settings.
  • Operating system: The desktop instructions require the FTP Service and IIS Management Console features to be available in your Windows edition. The Windows Server instructions assume Desktop Experience; Server Core requires a different management workflow.
  • Stable address: Give the server a static local IP address or DHCP reservation.
  • Server name: Choose a DNS hostname that clients can resolve and that matches the server certificate.
  • Storage: Use a dedicated folder on an NTFS volume, with sufficient free space and appropriate backups.
  • Client: Use an application supporting explicit FTP over TLS, such as WinSCP.

Windows 10 support: Standard Windows 10 support ended on October 14, 2025. For a new deployment, prefer a supported Windows 11 release or Windows Server. If retaining Windows 10, verify the exact edition’s lifecycle and applicable Extended Security Updates coverage. Installing IIS does not extend operating-system support. :chatgpt-content-reference{index="1"}

Understand FTP, FTPS, and SFTP

Protocol Protection Use in this guide
FTP Ordinary FTP does not encrypt credentials or transferred content. Do not use it for sensitive transfers.
Explicit FTPS Upgrades the FTP connection to TLS and can encrypt both commands and file transfers. The configuration used here, starting on TCP 21.
SFTP Transfers files through SSH; it is a different protocol. Requires an SSH/SFTP server, rather than the IIS FTP service.

The IIS interface uses the label SSL for its FTP encryption settings. Configure Require SSL so clients cannot fall back to an unencrypted session. Explicit FTPS does not require opening port 990, which is associated with implicit FTPS. :chatgpt-content-reference{index="2"}

1. Install the IIS FTP Service

Windows 10 and Windows 11

  1. Open Control Panel → Programs → Programs and Features → Turn Windows features on or off.
  2. Expand Internet Information Services → FTP Server.
  3. Select FTP Service.
  4. Expand Web Management Tools and select IIS Management Console.
  5. Click OK and complete installation.

Windows Server 2019, 2022, and 2025

  1. Open Server Manager → Manage → Add Roles and Features.
  2. Select Role-based or feature-based installation and choose the destination server.
  3. Select Web Server (IIS) and accept the required management tools.
  4. Under role services, select FTP Server → FTP Service and ensure IIS Management Console is included.
  5. Finish the wizard and install the selected components.

Open Internet Information Services (IIS) Manager from Start after installation. These installation paths are also documented in WinSCP’s Windows IIS guide. :chatgpt-content-reference{index="3"}

FTP Extensibility is unnecessary for this basic Windows-account configuration. It is relevant when using additional authentication providers, such as IIS Manager authentication. :chatgpt-content-reference{index="4"}

2. Prepare a Dedicated Account and Folder

The example below uses a local account named ftpuser and a folder named C:\FTPData. These are administrator-chosen examples, not required Windows defaults.

  1. On a standalone PC or member server, open Computer Management → Local Users and Groups → Users.
  2. Create a standard account named ftpuser with a strong, unique password. Do not add it to Administrators.
  3. Ensure the account is enabled and its password is ready for use. An FTP client cannot complete the normal Windows password-change-at-first-logon workflow.
  4. Create C:\FTPData in File Explorer.
  5. Open the folder’s Properties → Security → Edit and add the account.
  6. For downloads only, allow Read & execute, List folder contents, and Read.
  7. If users must upload, edit, rename, and delete files, grant Modify on this dedicated folder.

On a domain controller, local user accounts are unavailable; use an appropriately restricted domain account. A dedicated member server is the recommended deployment choice for this guide.

Permission warning: Modify permission includes deletion. Back up important files, review inherited access, and avoid granting Everyone or ordinary FTP users Full control. For upload-only access without deletion, design and test custom NTFS permissions separately.

Access must pass both IIS FTP authorization and NTFS folder permissions. Granting access in only one place is insufficient. :chatgpt-content-reference{index="5"}

3. Prepare a TLS Certificate

For production, obtain a server certificate from a certificate authority trusted by the connecting clients. Its DNS names must include the hostname clients will use, and the server must have its corresponding private key.

  1. In IIS Manager, select the server node and open Server Certificates.
  2. If your administrator supplied a PFX certificate file containing the private key, use Import and provide its password securely.
  3. Confirm that the imported certificate appears before creating the FTP site.

A self-signed certificate is suitable for a controlled test only when clients verify and explicitly trust it. Do not train users to accept unknown certificate warnings. WinSCP documents certificate trust and hostname checks for TLS connections. :chatgpt-content-reference{index="6"}

4. Create the FTP Site

  1. In IIS Manager, right-click Sites → Add FTP Site.
  2. Enter a site name, such as BISONKB FTP, and select C:\FTPData as its physical path.
  3. Select the server’s local IP address and set the port to 21. Leave virtual host names disabled for this single-site configuration.
  4. Select your certificate and choose Require SSL.
  5. On the authentication page, select Basic and leave Anonymous unchecked.
  6. For authorization, choose Specified users and enter the dedicated account.
  7. Allow Read. Add Write only if required.
  8. Finish the wizard and confirm that the site is started.

For an unambiguous account name, use SERVERNAME\ftpuser for a local account or DOMAIN\username for a domain account, substituting your actual names. :chatgpt-content-reference{index="7"}

Open the site’s FTP SSL Settings and confirm that encryption is required for both the control and data channels. Encrypting credentials alone does not protect subsequent file transfers. :chatgpt-content-reference{index="8"}

5. Configure Passive Data Ports

FTP uses a control connection for commands and separate data connections for directory listings and file transfers. In passive mode, the client initiates both connections. Consequently, a successful login does not prove that transfers will work.

  1. In IIS Manager, select the server node.
  2. Open FTP Firewall Support.
  3. Set Data Channel Port Range to 50000-50100, provided this example range is suitable for your environment.
  4. Click Apply.
  5. Open the Windows Services console and restart Microsoft FTP Service after completing the firewall configuration below.

The passive range is a server-wide setting. Size it for the expected transfer workload and coordinate changes with administrators of other FTP sites. Restarting the service interrupts existing FTP sessions. :chatgpt-content-reference{index="9"}

6. Allow the Required Firewall Traffic

Network exposure: Firewall exceptions make the service reachable. Limit access to the required client addresses or networks. Keep Windows Firewall enabled and review existing broad FTP rules before adding narrower rules.

For this example configuration, allow inbound TCP traffic to the server on:

  • 21: The explicit FTPS control connection.
  • 50000–50100: The passive data connections.

As an administrator, open Windows Defender Firewall with Advanced Security → Inbound Rules → New Rule. Create a Port rule using TCP and the required local ports, choose Allow the connection, and select only the appropriate network profiles. Give it a recognizable name, such as BISONKB FTPS. In the rule’s properties, use Scope to restrict remote IP addresses.

Apply equivalent allowances to any intervening network firewall. Encrypted FTPS cannot rely on a firewall inspecting ordinary FTP commands to discover and open data ports automatically. :chatgpt-content-reference{index="10"}

If Clients Connect Through a Router or NAT

For LAN-only access, router port forwarding is unnecessary. For external IPv4 access through network address translation (NAT):

  1. Forward TCP 21 and TCP 50000–50100 to the FTP server’s reserved local IP address.
  2. In the FTP site’s FTP Firewall Support, enter the router or firewall’s public IPv4 address as the External IP Address of Firewall.
  3. Ensure the public DNS hostname resolves to the correct public address.
  4. Test from a genuinely external network as well as from the LAN.

The site-level external address tells passive clients where to connect. It must remain correct when the public address changes. :chatgpt-content-reference{index="11"}

If your connection uses carrier-grade NAT or an upstream router you do not control, local port forwarding alone may be insufficient. Confirm the network arrangement with your provider or administrator. For private organizational transfers, consider providing access through a managed VPN.

7. Connect and Verify File Transfers

In WinSCP, create a connection with these settings:

Setting Value
File protocol FTP
Encryption TLS/SSL Explicit encryption
Host name Your server’s DNS name, matching its certificate
Port 21
User name The authorized local or domain account
Password The account password
Transfer mode Passive

Connect and check the certificate identity before proceeding. Windows Hello PINs are not substitutes for the FTP account password. :chatgpt-content-reference{index="12"}

Use harmless test files to verify the complete setup:

  1. Confirm that the client establishes a TLS-protected session.
  2. List the remote directory.
  3. Download a small test file and check its contents.
  4. If uploads are permitted, upload a uniquely named test file and confirm it appears in the server folder.
  5. For a read-only account, confirm that uploading is denied.
  6. Test access from each intended network location.

Check TCP Connectivity Separately

On a Windows client, run the following in PowerShell, replacing the example hostname. Administrator privileges are normally unnecessary:

Test-NetConnection -ComputerName ftp.example.com -Port 21

TcpTestSucceeded : True confirms that a TCP connection to port 21 succeeded. It does not verify the certificate, credentials, permissions, or passive data connections. If it is False, check DNS resolution, routing, the site binding, service status, and firewall rules before investigating account permissions. :chatgpt-content-reference{index="13"}

Troubleshoot Common Problems

Symptom What to check
Connection refused or timed out Confirm the FTP site and Microsoft FTP Service are running. Check the destination address, binding, port, firewall profile, and network path.
Login succeeds, but directory listing hangs Check passive data ports, matching firewall allowances, NAT forwarding, and the advertised external address.
425 response A data connection could not be established. Investigate the passive data path.
530 response Login failed. Check account credentials, authentication settings, authorization, and the accompanying server message.
550 response Check whether the requested file exists and whether FTP authorization and NTFS permissions allow the operation.
Certificate warning or TLS failure Check the hostname, expiry, certificate chain, private key, and client/server TLS compatibility. Do not resolve this by allowing plaintext access.
Works internally but fails externally Check public DNS, NAT rules, the public IPv4 setting, and upstream filtering.

For server-side detail, open FTP Logging on the site and check its configured log location. Microsoft documents the default parent directory as %SystemDrive%\inetpub\logs\LogFiles. Review both the FTP status and substatus: substatus 1 indicates authorization denial, while substatus 2 indicates file-system denial. Treat logs as sensitive because they can contain usernames, addresses, and filenames. :chatgpt-content-reference{index="14"}

If explicit port rules are correct but FTPS negotiation or transfers still fail, have the network administrator inspect FTP-aware filtering or an FTP application-layer gateway. Older inspection mechanisms can interfere with encrypted sessions. Change inspection settings only after assessing other services that depend on them. :chatgpt-content-reference{index="15"}

Maintain and Secure the Service

  • Keep Windows and the client application updated.
  • Monitor certificate expiry and test connections after certificate renewal.
  • Remove authorization for accounts that no longer need access.
  • Monitor failed logins, storage use, and unexpected uploads.
  • Keep backups separate from the writable FTP folder.
  • Record site settings, permissions, firewall rules, and NAT mappings.

If several users need private directories, configure FTP User Isolation with the required directory structure and NTFS permissions. Adding several authorized accounts to the same shared root does not automatically isolate their files. :chatgpt-content-reference{index="16"}

Disable or Roll Back the Configuration

  1. Stop the FTP site in IIS Manager.
  2. Disable or remove the firewall exceptions and NAT mappings created for this deployment.
  3. Remove the dedicated account’s FTP authorization and folder access when no longer required.
  4. Disable the dedicated account if nothing else uses it.
  5. Remove the FTP site after confirming that its configuration is no longer needed.
  6. Uninstall FTP Service only if no other FTP sites depend on it.

Preserve the data folder and backups until retention requirements are satisfied. Do not remove certificates, accounts, or IIS components shared with other services. If you changed a server-wide passive range, restore its previous value only after checking the needs of the remaining FTP sites.

Frequently Asked Questions

Do I need to host a website to run the FTP server?

No. IIS can host a standalone FTP site without a corresponding HTTP website. You do not need to open HTTP or HTTPS ports solely for these FTPS transfers. :chatgpt-content-reference{index="17"}

Must the server remain powered on?

Yes. The computer must remain awake, connected to the network, and running the FTP service. A sleeping laptop is unsuitable for transfers that must be available continuously.

Can several people use the same FTP account?

They can, but individual accounts are preferable because access can be revoked separately and activity is easier to attribute. Use a shared folder only when those users are intended to access the same files.

Sources

YOUR FEEDBACK

Was this guide useful?

Your answer helps us keep BISONKB accurate and practical.

THE BISON BRIEF

Practical IT knowledge, once a week.

New troubleshooting guides, scripts and infrastructure notes. No noise.

By subscribing, you agree to our privacy policy. Unsubscribe at any time.