# Is hosting (bind) officially supported on Windows? ZDEW vs. ziti-edge-tunnel run-host

**URL:** <https://openziti.discourse.group/t/is-hosting-bind-officially-supported-on-windows-zdew-vs-ziti-edge-tunnel-run-host/5966>\
**Category:** Ziti Desktop Edge for Windows\
**Created:** [July 24, 2026, 10:10am UTC](https://openziti.discourse.group/t/is-hosting-bind-officially-supported-on-windows-zdew-vs-ziti-edge-tunnel-run-host/5966 "2026-07-24T10:10:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![muekat](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@muekat](https://openziti.discourse.group/u/muekat)\
**Post date:** [July 24, 2026, 10:10am UTC](https://openziti.discourse.group/t/is-hosting-bind-officially-supported-on-windows-zdew-vs-ziti-edge-tunnel-run-host/5966/1 "2026-07-24T10:10:05Z")

</div>

Hi all,

I'm planning a small deployment and would like to confirm an architectural assumption before building.

**Setup:**

- ~15 mobile users (iOS/Android) running Ziti Mobile Edge
- Ziti Controller + Edge Router on a VPS
- One on-prem **Windows** server that should _host_ (bind) a single HTTP upload service. Company policy forbids opening any inbound port on site, so the on-prem side must dial out only.

**What I found so far:**

- The Windows tunneler docs describe ZDEW purely as an _intercepting_ tunneler; hosting/bind is not mentioned.
- `ziti-edge-tunnel run-host` exists and there are Windows builds.
- [This topic](https://openziti.discourse.group/t/hosting-ad-related-services-via-ziti-edge-tunnel-on-any-domain-joined-windows-host-dc-or-member-server-breaks-cloud-kerberos-trust-ticket-issuance-for-entra-id-joined-dial-clients-same-configuration-on-an-edge-router-works/5843) shows someone successfully hosting services on Windows, but only after switching to a beta Windows tunneler, while the same config on a Linux edge router worked immediately.

**Questions:**

1. Is bind/hosting on Windows officially supported, or is it best-effort?
2. If supported: ZDEW, or standalone `ziti-edge-tunnel run-host` installed as a Windows service? Which is recommended for an unattended server role?
3. Any known caveats for production use (service restarts, updates, running under a service account)?
4. Would you generally recommend putting the hosting side on a small Linux VM instead and keeping Windows out of the Ziti path?

Thanks!

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [July 24, 2026, 12:01pm UTC](https://openziti.discourse.group/t/is-hosting-bind-officially-supported-on-windows-zdew-vs-ziti-edge-tunnel-run-host/5966/2 "2026-07-24T12:01:29Z")

</div>

Hi @muekat, welcome to the community and to OpenZiti!

> [@muekat](#):
>
> - The Windows tunneler docs describe ZDEW purely as an _intercepting_ tunneler; hosting/bind is not mentioned.

They do? Interesting, that seems like something I'll want to fix. Would you point out exactly what docs led you to believe that? 🙂 I didn't think that we put something like that into our doc...

> [@muekat](#):
>
> 1. Is bind/hosting on Windows officially supported, or is it best-effort?

Certainly. It always has (thus my confusion from your prior 'intercepting only' comment). I use it routinely for RDP myself to get back to my home windows server (or my mother's laptop for support) etc.

> [@muekat](#):
>
> 1. If supported: ZDEW, or standalone `ziti-edge-tunnel run-host` installed as a Windows service? Which is recommended for an unattended server role?

This is a minor misunderstanding. 'run-host' is available only as a command line option at this time and is NOT implemented in the ZDEW yet but it's usually not what you want. run-host mode **prevents interception** while still allowing for hosting. It just makes the ziti-edge-tunnel **exit only**. I'd say that's usually not what people want anyway. I never run in `run-host` mode for normal operation.

> [@muekat](#):
>
> 1. Any known caveats for production use (service restarts, updates, running under a service account)?

No? None I can think of. If the machine restarts ZDEW restarts too so you'll eventually regain access after a reboot. ZDEW always runs as SYSTEM anyway and it's a system-wide installation. That's the only caveat I can think of with respect to a server, if you use terminal services and if other users RDP there, there is only one instance of ZDEW per **machine** so all users would have access to the same services.

> [@muekat](#):
>
> 1. Would you generally recommend putting the hosting side on a small Linux VM instead and keeping Windows out of the Ziti path?

I mean, that's just entirely up to you. If you like linux - sure. If you prefer windows, use windows. 🙂 The only difference might be once you want to allow connections from inside that VPC you might find it helpful to run a router inside your private networking space for inbound (and outbound) OpenZiti connectivity and for that you need linux. We don't currently support running a controller or router on windows for numerous reasons. You **CAN** do that too if you like, it's just not something we provide (you'd have to figure out your own service/updates etc on windows).

hth!

---

<div class="post-metadata">

**Author:** ![TheLumberjack](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/thelumberjack/32/113_2.png) [@TheLumberjack](https://openziti.discourse.group/u/TheLumberjack)\
**Post date:** [July 24, 2026, 12:02pm UTC](https://openziti.discourse.group/t/is-hosting-bind-officially-supported-on-windows-zdew-vs-ziti-edge-tunnel-run-host/5966/3 "2026-07-24T12:02:23Z")

</div>

relevant RDP example on YouTube if you are interested

[![](https://global.discourse-cdn.com/free1/uploads/netfoundry/original/2X/e/eb0be1d79824ba2d6c70edb4c1c668f496da9c64.jpeg "Walkthrough - Windows Remote Desktop using ZAC - Apr 2024") ](https://www.youtube.com/watch?v=dKXNZxneko4)

---

<div class="post-metadata">

**Author:** ![frm](https://avatars.discourse-cdn.com/v4/letter/f/b9bd4f/32.png) [@frm](https://openziti.discourse.group/u/frm)\
**Post date:** [July 27, 2026, 5:32am UTC](https://openziti.discourse.group/t/is-hosting-bind-officially-supported-on-windows-zdew-vs-ziti-edge-tunnel-run-host/5966/4 "2026-07-27T05:32:03Z")

</div>

> [@muekat](#):
>
> 1. Any known caveats for production use (service restarts, updates, running under a service account)?

You probably want to delete the file "Ziti Desktop Edge" in "shell:common startup". This will start the GUI part of the ZDEW and every user is able to stop the service.

The file pops up at every update of ZDEW.

@TheLumberjack In my opinion it is desirable to have the possiblity to restrict actions/access to administrators only. Especially for the binding site of an tunnel, e.g. Windows terminal servers, where users without administrative permissions can close the terminator.
