!Order matters. Subsystem sftp internal-sftp must appear ABOVE this Match block, never inside it. Reversing the order will fail sshd startup.
!This block goes at the END of sshd_config. Once a Match section starts, only Match-legal directives are allowed until the next Match block or end of file.
!Chroot ownership. The chroot directory must be owned by root:root and not writable by group or others, or SSH will refuse the login.
!Test before you restart. Run sudo sshd -t to check syntax first. Run sudo systemctl reload sshd rather than restart where possible, and keep a second terminal session open in case something's wrong.