Learning state
Track this guide
Saved in this browser only. No account required.
Windows Server PowerShell Master Class
Engineering-grade reference manual for Windows Server operations with PowerShell: discovery, services, networking, roles, events, storage, Active Directory checks, remoting, and safe administration.
Overview
Windows Server infrastructure is best operated with evidence-first PowerShell. Use read-only commands to inspect state before changing services, roles, firewall rules, storage, or Active Directory. Run destructive or production mutations only after approval and rollback planning.
Host and OS Inventory
Show computer information:
Get-ComputerInfo
Show OS version:
Get-CimInstance Win32_OperatingSystem | Select-Object Caption,Version,BuildNumber,LastBootUpTime
Show hostname and domain:
Get-CimInstance Win32_ComputerSystem | Select-Object Name,Domain,PartOfDomain
Show installed hotfixes:
Get-HotFix | Sort-Object InstalledOn -Descending | Select-Object -First 20
Services and Processes
List running services:
Get-Service | Where-Object Status -eq Running
Inspect one service:
Get-Service -Name Spooler
Restart a service after approval:
Restart-Service -Name SERVICE_NAME
List top CPU processes:
Get-Process | Sort-Object CPU -Descending | Select-Object -First 10
Networking and Firewall
Show IP configuration:
Get-NetIPConfiguration
Show routes:
Get-NetRoute
Test TCP reachability:
Test-NetConnection HOSTNAME -Port 443
List firewall rules:
Get-NetFirewallRule | Select-Object DisplayName,Enabled,Direction,Action
Enable a firewall rule after approval:
Enable-NetFirewallRule -DisplayName "RULE_NAME"
Roles and Features
List installed roles and features:
Get-WindowsFeature | Where-Object Installed
Install a feature after approval:
Install-WindowsFeature -Name Web-Server -IncludeManagementTools
Inspect IIS websites when the WebAdministration module is installed:
Get-Website
Events and Logs
Read recent system errors:
Get-WinEvent -LogName System -MaxEvents 50 | Where-Object LevelDisplayName -eq Error
Read recent application errors:
Get-WinEvent -LogName Application -MaxEvents 50 | Where-Object LevelDisplayName -eq Error
Query a provider-specific log:
Get-WinEvent -ProviderName Microsoft-Windows-WinRM -MaxEvents 20
Storage
List volumes:
Get-Volume
List disks:
Get-Disk
List physical disks:
Get-PhysicalDisk
Show SMB shares:
Get-SmbShare
Active Directory Read-Only Checks
Import the AD module:
Import-Module ActiveDirectory
Show domain info:
Get-ADDomain
List domain controllers:
Get-ADDomainController -Filter *
Find locked users:
Search-ADAccount -LockedOut -UsersOnly
Show replication summary:
repadmin /replsummary
Remoting
Test WinRM:
Test-WSMan SERVER_NAME
Run a read-only command remotely:
Invoke-Command -ComputerName SERVER_NAME -ScriptBlock { hostname; Get-Date }
Create a persistent session:
New-PSSession -ComputerName SERVER_NAME
Safe Operating Pattern
- Capture
Get-ComputerInfo, network, storage, and event evidence first. - Prefer
Get-*,Test-*, and report commands for discovery. - Use
Set-*,New-*,Remove-*,Restart-*, and install commands only with approval. - Record exact server, scope, rollback, and verification before production changes.