After Hours

10 PowerShell commands every Windows admin should know

PowerShell combines the speed of the command line with the flexibility of a scripting language, making it a valuable Windows administration tool. Here are a few basic commands you'll want to master.

Over the last few years, Microsoft has been trying to make PowerShell the management tool of choice. Almost all the newer Microsoft server products require PowerShell, and there are lots of management tasks that can't be accomplished without delving into the command line. As a Windows administrator, you need to be familiar with the basics of using PowerShell. Here are 10 commands to get you started.

Note: This article is also available as a PDF download.

1: Get-Help

The first PowerShell cmdlet every administrator should learn is Get-Help. You can use this command to get help with any other command. For example, if you want to know how the Get-Process command works, you can type:

Get-Help -Name Get-Process

and Windows will display the full command syntax.

You can also use Get-Help with individual nouns and verbs. For example, to find out all the commands you can use with the Get verb, type:

Get-Help -Name Get-*

2: Set-ExecutionPolicy

Although you can create and execute PowerShell scripts, Microsoft has disabled scripting by default in an effort to prevent malicious code from executing in a PowerShell environment. You can use the Set-ExecutionPolicy command to control the level of security surrounding PowerShell scripts. Four levels of security are available to you:

  • Restricted -- Restricted is the default execution policy and locks PowerShell down so that commands can be entered only interactively. PowerShell scripts are not allowed to run.
  • All Signed -- If the execution policy is set to All Signed then scripts will be allowed to run, but only if they are signed by a trusted publisher.
  • Remote Signed -- If the execution policy is set to Remote Signed, any PowerShell scripts that have been locally created will be allowed to run. Scripts created remotely are allowed to run only if they are signed by a trusted publisher.
  • Unrestricted -- As the name implies, Unrestricted removes all restrictions from the execution policy.

You can set an execution policy by entering the Set-ExecutionPolicy command followed by the name of the policy. For example, if you wanted to allow scripts to run in an unrestricted manner you could type:

Set-ExecutionPolicy Unrestricted

3: Get-ExecutionPolicy

If you're working on an unfamiliar server, you'll need to know what execution policy is in use before you attempt to run a script. You can find out by using the Get-ExecutionPolicy command.

4: Get-Service

The Get-Service command provides a list of all of the services that are installed on the system. If you are interested in a specific service you can append the -Name switch and the name of the service (wildcards are permitted) When you do, Windows will show you the service's state.

5: ConvertTo-HTML

PowerShell can provide a wealth of information about the system, but sometimes you need to do more than just view the information onscreen. Sometimes, it's helpful to create a report you can send to someone. One way of accomplishing this is by using the ConvertTo-HTML command.

To use this command, simply pipe the output from another command into the ConvertTo-HTML command. You will have to use the -Property switch to control which output properties are included in the HTML file and you will have to provide a filename.

To see how this command might be used, think back to the previous section, where we typed Get-Service to create a list of every service that's installed on the system. Now imagine that you want to create an HTML report that lists the name of each service along with its status (regardless of whether the service is running). To do so, you could use the following command:

Get-Service | ConvertTo-HTML -Property Name, Status > C:\services.htm

6: Export-CSV

Just as you can create an HTML report based on PowerShell data, you can also export data from PowerShell into a CSV file that you can open using Microsoft Excel. The syntax is similar to that of converting a command's output to HTML. At a minimum, you must provide an output filename. For example, to export the list of system services to a CSV file, you could use the following command:

Get-Service | Export-CSV c:\service.csv

7: Select-Object

If you tried using the command above, you know that there were numerous properties included in the CSV file. It's often helpful to narrow things down by including only the properties you are really interested in. This is where the Select-Object command comes into play. The Select-Object command allows you to specify specific properties for inclusion. For example, to create a CSV file containing the name of each system service and its status, you could use the following command:

Get-Service | Select-Object Name, Status | Export-CSV c:\service.csv

8: Get-EventLog

You can actually use PowerShell to parse your computer's event logs. There are several parameters available, but you can try out the command by simply providing the -Log switch followed by the name of the log file. For example, to see the Application log, you could use the following command:

Get-EventLog -Log "Application"

Of course, you would rarely use this command in the real world. You're more likely to use other commands to filter the output and dump it to a CSV or an HTML file.

9: Get-Process

Just as you can use the Get-Service command to display a list of all of the system services, you can use the Get-Process command to display a list of all of the processes that are currently running on the system.

10: Stop-Process

Sometimes, a process will freeze up. When this happens, you can use the Get-Process command to get the name or the process ID for the process that has stopped responding. You can then terminate the process by using the Stop-Process command. You can terminate a process based on its name or on its process ID. For example, you could terminate Notepad by using one of the following commands:

Stop-Process -Name notepad
Stop-Process -ID 2668

Keep in mind that the process ID may change from session to session.

Additional PowerShell resources

About

Brien Posey is a seven-time Microsoft MVP. He has written thousands of articles and written or contributed to dozens of books on a variety of IT subjects.

15 comments
jcwfbi
jcwfbi

Still trying to figure out how to export to pst from windows 7 though.

TravisFx
TravisFx

Brian - ok... I'll admit that I'm not in mainstream IT anymore, but still maintain a finger or 2 in it... So pardon my ignorance if it shows...but I don't get this. Why is the GUI King MS switching gears and going the way of Unix, Linux - ala cmd line for admins?? This seems totally against everything the've stood for since the dying dos days... and gui took over. This seems like a step back. Why is everyone ok with this? Seems like a pain in the ass!

trevor217
trevor217

The article states that the default execution policy is Restricted. I think that statement is only true for PS 1.0 I believe in PS 2.0 the default execution policy is RemoteSigned.

CharlieSpencer
CharlieSpencer

I'm looking for recommended manuals or downloads. This article is a start, but I'm looking for something both meatier and more introductory. Thanks.

pgraunke
pgraunke

Indispensable for obtaining the methods and events of an object. As in: get-process|get-member

neilb
neilb

Microsoft finally recognised that some System Admins weren't limited to the GUI and wanted a tool that could really allow us to administrate. It was also obvious that the various GUI management tools lacked scope as the systems became more complex and that there was a need for consistency. I'm more that "OK" with PowerShell. I can use PowerShell command line for those things that I'd normally do with the management GUI and I can also write and reuse scripts to do more complex tasks. And I can do it for Exchange, SQL server, AD, VMware, Operations Manager, MS Clustering, WMI... WITH A SINGLE TOOL. I could go on but you probably get the point. :)

trevor217
trevor217

Depending on how in depth you want to get there are many resources.. if you want just a simple introduction just google "powershell tutorial" and pick one. If however you want a more in depth primer that will take some time to work through i suggest the Powershell Owners Manual on technet: http://technet.microsoft.com/en-us/library/ee221100.aspx

ICan2
ICan2

powersell.com

snideley59
snideley59

And that evil Windows explorer interface as well. Far better to build the commands and switches at the command line than let the GUIs do it for you. As a Linux/Windows admin, I'm a big fan of PowerShell. Large step forward

CharlieSpencer
CharlieSpencer

The 'book is available for free' link returns a 404. I can find links to the second book referenced (PowerShell for servers), but apparently the first one has gone the way of out own "E Lie" discussion. Thanks anyway.

ultimitloozer
ultimitloozer

Go to the second blog entry (for the server stuff) and download from there. It includes the first (general) book as well as the second (server) book.