Windows Server2 min read217 lines

Learning state

Track this guide

Saved in this browser only. No account required.

Windows Server PowerShell Master Class

Engineering-grade reference manual for Windows Server operations with PowerShell: discovery, services, networking, roles, events, storage, Active Directory checks, remoting, and safe administration.

Overview

Windows Server infrastructure is best operated with evidence-first PowerShell. Use read-only commands to inspect state before changing services, roles, firewall rules, storage, or Active Directory. Run destructive or production mutations only after approval and rollback planning.

Host and OS Inventory

Show computer information:

Get-ComputerInfo

Show OS version:

Get-CimInstance Win32_OperatingSystem | Select-Object Caption,Version,BuildNumber,LastBootUpTime

Show hostname and domain:

Get-CimInstance Win32_ComputerSystem | Select-Object Name,Domain,PartOfDomain

Show installed hotfixes:

Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 20

Services and Processes

List running services:

Get-Service | Where-Object Status -eq Running

Inspect one service:

Get-Service -Name Spooler

Restart a service after approval:

Restart-Service -Name SERVICE_NAME

List top CPU processes:

Get-Process | Sort-Object CPU -Descending | Select-Object -First 10

Networking and Firewall

Show IP configuration:

Get-NetIPConfiguration

Show routes:

Get-NetRoute

Test TCP reachability:

Test-NetConnection HOSTNAME -Port 443

List firewall rules:

Get-NetFirewallRule | Select-Object DisplayName,Enabled,Direction,Action

Enable a firewall rule after approval:

Enable-NetFirewallRule -DisplayName "RULE_NAME"

Roles and Features

List installed roles and features:

Get-WindowsFeature | Where-Object Installed

Install a feature after approval:

Install-WindowsFeature -Name Web-Server -IncludeManagementTools

Inspect IIS websites when the WebAdministration module is installed:

Get-Website

Events and Logs

Read recent system errors:

Get-WinEvent -LogName System -MaxEvents 50 | Where-Object LevelDisplayName -eq Error

Read recent application errors:

Get-WinEvent -LogName Application -MaxEvents 50 | Where-Object LevelDisplayName -eq Error

Query a provider-specific log:

Get-WinEvent -ProviderName Microsoft-Windows-WinRM -MaxEvents 20

Storage

List volumes:

Get-Volume

List disks:

Get-Disk

List physical disks:

Get-PhysicalDisk

Show SMB shares:

Get-SmbShare

Active Directory Read-Only Checks

Import the AD module:

Import-Module ActiveDirectory

Show domain info:

Get-ADDomain

List domain controllers:

Get-ADDomainController -Filter *

Find locked users:

Search-ADAccount -LockedOut -UsersOnly

Show replication summary:

repadmin /replsummary

Remoting

Test WinRM:

Test-WSMan SERVER_NAME

Run a read-only command remotely:

Invoke-Command -ComputerName SERVER_NAME -ScriptBlock { hostname; Get-Date }

Create a persistent session:

New-PSSession -ComputerName SERVER_NAME

Safe Operating Pattern

  • Capture Get-ComputerInfo, network, storage, and event evidence first.
  • Prefer Get-*, Test-*, and report commands for discovery.
  • Use Set-*, New-*, Remove-*, Restart-*, and install commands only with approval.
  • Record exact server, scope, rollback, and verification before production changes.