Concept and mechanism
A job does not necessarily have an interactive session’s agent, account, or files. BatchMode helps prevent execution waiting for passwords or interactive confirmations. It neither authorizes an unknown identity nor creates credentials: trust and authentication must be prepared. Exit status and logs should distinguish connection, authentication, and remote-command failures. Status 255 suggests an SSH client error, but analysis must also use context because the remote command can return the same value.
Guided application
Before changing sshd configuration, retain an approved recovery path and a valid administrative session where appropriate. Validate syntax and keys with sshd -t; inspect effective options with sshd -T and connection context when Match rules apply. Passing syntax validation does not prove that a new session for the required account will be accepted. Test the real condition after controlled application before abandoning existing access. Service names and reload commands vary by distribution; consult installed-platform procedures rather than copying a universal command.
A Match rule permits personal interactive access but blocks the job account. Evaluating only global configuration misses the difference.
Common pitfalls
Assuming interactive success proves job success; closing the last session before validating new access.
Related topics: SSH connection and server identity · Key authentication and remote accounts
Validate syntax, context, and a new session; prepare recovery before changing access.
Reference: sshd(8): server operation · OpenSSH concepts and OpenBSD-current manuals consulted 2026-09-29; distribution defaults vary