Access denied
What “Access denied” usually means
When PuTTY reports Access denied, the client has already attempted a network or protocol step and failed before a normal interactive shell is available. This guide explains what the message usually means on Windows clients, which local settings to verify first, and when the problem is almost certainly on the server, firewall, or DNS path rather than inside the PuTTY GUI.
Authentication failed for the attempted credentials. Closely related to permission denied; some banners and keyboard-interactive flows surface this shorter phrase.
Independent resource: Putty.info is educational only and is not affiliated with the official PuTTY project. Compare symptoms against the official documentation for your installed version.
Symptoms you will see
Operators usually notice this failure in one of a few repeatable ways. Capture the exact dialog text, the hostname and port from the Session panel, and whether the failure happens before or after a username prompt—those details decide which checklist below applies.
- Password or keyboard-interactive prompt rejects the secret.
- Account may be valid but denied by policy after partial auth.
Likely causes ranked by frequency
Several independent conditions can produce the same client-facing wording. Work from the outside in: reachability first, protocol selection second, authentication third. Changing key files will not fix a TCP refusal, and opening a wider firewall will not fix a rejected public key.
- Typo in password, wrong keyboard layout, or Caps Lock.
- Expired password with forced change not reachable over this path.
- PAM or directory service rejection (AD/LDAP) independent of SSH keys.
- MFA plugin failure mid-keyboard-interactive.
Step-by-step client checks
Use this ordered checklist on a workstation you control. Prefer saved sessions so Host Name, Port, and Connection type stay consistent while you isolate one variable at a time.
- Reset local keyboard layout; try the password in a local notepad window carefully if policy allows testing (then clear it).
- Confirm you are authenticating as the correct username on the correct host.
- Switch to key-based auth with a known-good PPK if passwords are failing inconsistently.
- Check whether the account requires VPN + device posture before SSH is authorized.
- Review IdP/PAM logs when corporate directory auth is in the path.
- Avoid spraying passwords; lockouts make diagnosis harder.
Do not paste private keys, passphrases, or production passwords into Putty.info tools or contact forms. Diagnose locally with PuTTY, Plink, PSCP, or PSFTP from an official install.
When it is a server or network issue
Directory-integrated bastions often fail closed when LDAP binders break. Server owners should check PAM stacks and IdP health before blaming PuTTY.
If TCP connects from another network path but fails from yours, involve the network team with traceroute/path evidence rather than repeatedly regenerating keys. If authentication fails after a banner appears, collect the server sshd logs for the same timestamp and username—client-side retries alone rarely reveal AccountLocked, Match blocks, or AllowUsers denials.