Install PatchWalker on a Controller and enrol your first machine. The full administrator guide is built into the app under Manual.
You need one 64-bit Windows Server (Server 2016+, or Windows 10/11) to act as the Controller — the machine PatchWalker installs on. The installer is self-contained, so there’s no separate runtime to install. Each machine you want to manage needs only:
A Domain / gMSA install lets the Controller manage domain machines with its Kerberos identity; a Standalone install uses certificate-based WinRM and works in workgroups.
On first launch you’ll create the break-glass administrator — the always-available local admin account. Keep its password safe; it can’t be recovered if lost. From there you can add more users and roles, and optionally enable Microsoft Entra sign-in, under Admin → Authentication.