182 commands · 11 cheat sheets · Windows

Identity, Access, and Security master quick reference

Browse 182 commands from 11 focused cheat sheets on page 1 of 1. Each example opens its matching detailed section.

Identity, Access, and Security · 16 commands

Active Directory Certificate Services Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Inspect AD CS featuresGet-WindowsFeature AD-Certificate,ADCS-Cert-AuthorityView examples
Inspect domain contextGet-CimInstance Win32_ComputerSystem | Select-Object Name,Domain,PartOfDomainView examples
Install CA binariesInstall-WindowsFeature ADCS-Cert-Authority ` -IncludeManagementTools -WhatIfView examples
Configure an enterprise subordinate CAInstall-AdcsCertificationAuthority -CAType ` EnterpriseSubordinateCA -CACommonName ` 'Contoso Issuing CA 01' -WhatIfView examples
Inspect CA serviceGet-Service CertSvcView examples
Read CA configurationcertutil.exe -getreg CAView examples
List issued templatesGet-CATemplateView examples
Publish a templateAdd-CATemplate -Name 'ContosoWebServer' -WhatIfView examples
Inspect pending requestscertutil.exe -view -restrict 'Disposition=9' -out ` 'RequestID,RequesterName,CommonName'View examples
Inspect issued requestscertutil.exe -view -restrict 'Disposition=20' -out ` 'RequestID,CommonName,NotAfter'View examples
Revoke a certificatecertutil.exe -revoke $Serial KeyCompromiseView examples
Publish a new CRLcertutil.exe -crlView examples
Verify certificate URLscertutil.exe -url '.\issued.cer'View examples
Back up CA database and keyBackup-CARoleService -Path 'E:\CA-Backup' -Password ` (Read-Host -AsSecureString)View examples
Export CA configurationreg.exe export ` 'HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration' ` '.\ca-config.reg' /yView examples
Read CA operational eventsGet-WinEvent -LogName 'Application' -ProviderName ` 'Microsoft-Windows-CertificationAuthority' -MaxEvents ` 100View examples

Identity, Access, and Security · 19 commands

Active Directory Users, Groups, and Computers PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Check the AD moduleGet-Module -ListAvailable ActiveDirectory | Select-Object Name, Version, PathView examples
Identify domain contextGet-ADDomain -Identity 'corp.example.com' -Server ` 'dc01.corp.example.com'View examples
Resolve one userGet-ADUser -Identity 'alice.chen' -Properties ` mail,Enabled,LastLogonDate -Server ` 'dc01.corp.example.com'View examples
Search users in an OUGet-ADUser -Filter 'Enabled -eq $true' -SearchBase ` 'OU=People,DC=corp,DC=example,DC=com' -Server ` 'dc01.corp.example.com'View examples
Find inactive usersSearch-ADAccount -UsersOnly -AccountInactive -TimeSpan ` (New-TimeSpan -Days 90) -SearchBase ` 'OU=People,DC=corp,DC=example,DC=com'View examples
Preview a disabled userNew-ADUser -Name 'Alice Chen' -SamAccountName ` 'alice.chen' -Path ` 'OU=People,DC=corp,DC=example,DC=com' -Enabled:$false ` -WhatIfView examples
Preview a user updateSet-ADUser -Identity 'alice.chen' -Department 'Finance' ` -Title 'Analyst' -Server 'dc01.corp.example.com' ` -WhatIfView examples
Preview account disableDisable-ADAccount -Identity 'alice.chen' -Server ` 'dc01.corp.example.com' -WhatIfView examples
Preview moving an objectMove-ADObject -Identity $user.ObjectGUID -TargetPath ` 'OU=Staged,DC=corp,DC=example,DC=com' -Server ` 'dc01.corp.example.com' -WhatIfView examples
Inspect a groupGet-ADGroup -Identity 'GG-Finance-Readers' -Properties ` GroupCategory,GroupScope,ManagedBy -Server ` 'dc01.corp.example.com'View examples
Expand nested membersGet-ADGroupMember -Identity 'GG-Finance-Readers' ` -Recursive -Server 'dc01.corp.example.com'View examples
List principal groupsGet-ADPrincipalGroupMembership -Identity 'alice.chen' -Server 'dc01.corp.example.com' | Sort-Object NameView examples
Preview group creationNew-ADGroup -Name 'GG-Finance-Readers' -GroupScope ` Global -Path 'OU=Groups,DC=corp,DC=example,DC=com' ` -WhatIfView examples
Preview adding a memberAdd-ADGroupMember -Identity $group.ObjectGUID -Members ` $user.ObjectGUID -Server 'dc01.corp.example.com' ` -WhatIfView examples
Preview removing a memberRemove-ADGroupMember -Identity $group.ObjectGUID ` -Members $user.ObjectGUID -Server ` 'dc01.corp.example.com' -WhatIfView examples
Search computer accountsGet-ADComputer -Filter ` 'OperatingSystem -like "Windows Server*"' -SearchBase ` 'OU=Servers,DC=corp,DC=example,DC=com'View examples
Preview a computer accountNew-ADComputer -Name 'APP-042' -Path ` 'OU=Staging,OU=Servers,DC=corp,DC=example,DC=com' ` -Enabled:$false -WhatIfView examples
Find inactive computersSearch-ADAccount -ComputersOnly -AccountInactive ` -TimeSpan (New-TimeSpan -Days 60) -SearchBase ` 'OU=Servers,DC=corp,DC=example,DC=com'View examples
Verify on another DCGet-ADUser -Identity $user.ObjectGUID -Properties ` Enabled,Department -Server 'dc02.corp.example.com'View examples

Identity, Access, and Security · 16 commands

Application Control, AppLocker, and WDAC Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Read effective AppLocker policyGet-AppLockerPolicy -Effective -XmlView examples
Read Code Integrity eventsGet-WinEvent -LogName ` 'Microsoft-Windows-CodeIntegrity/Operational' ` -MaxEvents 100View examples
Collect file identitiesGet-AppLockerFileInformation -Directory ` 'C:\Program Files\Contoso' -RecurseView examples
Generate audit policy XMLGet-AppLockerFileInformation -EventLog -EventType Audited | New-AppLockerPolicy -RuleType Publisher,Hash -User Everyone -XmlView examples
Test files against policyTest-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -Path ` 'C:\Apps\*' -User 'CONTOSO\PilotUser'View examples
Preview local AppLocker policySet-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -WhatIfView examples
Inspect Application IdentityGet-Service AppIDSvcView examples
Read AppLocker EXE eventsGet-WinEvent -LogName ` 'Microsoft-Windows-AppLocker/EXE and DLL' -MaxEvents ` 100View examples
Create candidate base policyNew-CIPolicy -ScanPath 'C:\Windows' -Level Publisher ` -Fallback Hash -FilePath '.\Base.xml' -UserPEsView examples
Keep audit mode enabledSet-RuleOption -FilePath '.\Base.xml' -Option 3View examples
Merge policy XMLMerge-CIPolicy -PolicyPaths ` '.\Base.xml','.\AuditAdditions.xml' -OutputFilePath ` '.\Merged.xml'View examples
Compile policy binaryConvertFrom-CIPolicy -XmlFilePath '.\Merged.xml' ` -BinaryFilePath '.\Merged.cip'View examples
List active App Control policiesCiTool.exe -lp -jsonView examples
Hash policy artifactGet-FileHash '.\Merged.cip' -Algorithm SHA256View examples
Summarize CI event IDsGet-WinEvent -LogName 'Microsoft-Windows-CodeIntegrity/Operational' -MaxEvents 500 | Group-Object IdView examples
Inspect PowerShell language mode$ExecutionContext.SessionState.LanguageModeView examples

Identity, Access, and Security · 16 commands

Just Enough Administration (JEA) Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Create a role templateNew-PSRoleCapabilityFile -Path '.\Maintenance.psrc'View examples
Test role syntaxTest-ModuleManifest '.\Contoso.JEA\Contoso.JEA.psd1'View examples
Expose constrained parametersVisibleCmdlets = @{ Name = 'Restart-Service'; Parameters ` = @{ Name = 'Name'; ValidateSet = 'Spooler' } }View examples
Expose wrapper functionsVisibleFunctions = 'Restart-PrintService'View examples
Create session configurationNew-PSSessionConfigurationFile -SessionType ` RestrictedRemoteServer -Path '.\Maintenance.pssc'View examples
Validate session syntaxTest-PSSessionConfigurationFile -Path ` '.\Maintenance.pssc'View examples
Register endpointRegister-PSSessionConfiguration -Name Maintenance -Path ` '.\Maintenance.pssc' -ForceView examples
List endpointsGet-PSSessionConfiguration | Select-Object Name,Permission,SessionTypeView examples
Enter a JEA sessionEnter-PSSession -ComputerName server01 ` -ConfigurationName MaintenanceView examples
Invoke a delegated taskInvoke-Command -ComputerName server01 -ConfigurationName ` Maintenance -ScriptBlock { Get-Service Spooler }View examples
Audit effective commandsGet-PSSessionCapability -ConfigurationName Maintenance ` -Username 'CONTOSO\JEA-Operators'View examples
Inspect role mappings(Get-PSSessionConfiguration -Name ` Maintenance).RoleDefinitionsView examples
Find recent transcriptsGet-ChildItem -LiteralPath 'C:\ProgramData\JEA\Transcripts' -File | Sort-Object LastWriteTime -DescendingView examples
Read remoting eventsGet-WinEvent -LogName ` 'Microsoft-Windows-PowerShell/Operational' -MaxEvents ` 100View examples
Remove an endpointUnregister-PSSessionConfiguration -Name Maintenance ` -WhatIfView examples
Inspect endpoint permissionGet-PSSessionConfiguration -Name Maintenance | Select-Object Name,PermissionView examples

Identity, Access, and Security · 18 commands

Microsoft Defender Antivirus PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Inspect protection healthGet-MpComputerStatus | Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, BehaviorMonitorEnabled, IsTamperProtectedView examples
Inspect Defender serviceGet-Service -Name WinDefend | Select-Object Name, Status, StartTypeView examples
Audit protection preferencesGet-MpPreference | Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableIOAVProtection, PUAProtectionView examples
Check intelligence freshnessGet-MpComputerStatus | Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated, AntivirusSignatureAgeView examples
Request an intelligence updateUpdate-MpSignatureView examples
Start a quick scanStart-MpScan -ScanType QuickScanView examples
Scan one approved pathStart-MpScan -ScanType CustomScan -ScanPath 'C:\Inbound'View examples
Review scan timestampsGet-MpComputerStatus | Select-Object QuickScanStartTime, QuickScanEndTime, FullScanStartTime, FullScanEndTimeView examples
List detection historyGet-MpThreatDetection | Sort-Object InitialDetectionTime -DescendingView examples
List known threatsGet-MpThreat | Select-Object ThreatID, ThreatName, SeverityID, CategoryID, IsActive, DidThreatExecuteView examples
Read key Defender eventsGet-WinEvent -FilterHashtable ` @{LogName='Microsoft-Windows-Windows Defender/Operational'; ` Id=1116,1117,1118,5007} -MaxEvents 100View examples
Inventory exclusionsGet-MpPreference | Select-Object ExclusionPath, ExclusionExtension, ExclusionProcessView examples
Add one narrow path exclusionAdd-MpPreference -ExclusionPath 'C:\Vendor\App\Cache'View examples
Remove one path exclusionRemove-MpPreference -ExclusionPath 'C:\Vendor\App\Cache'View examples
Check tamper protectionGet-MpComputerStatus | Select-Object IsTamperProtected, RealTimeProtectionEnabled, AntivirusEnabledView examples
Record Defender performanceNew-MpPerformanceRecording -RecordTo ` 'C:\Temp\Defender-scans.etl' -Seconds 120View examples
Report high-impact filesGet-MpPerformanceReport -Path ` 'C:\Temp\Defender-scans.etl' -TopFiles 20 ` -TopProcesses 20View examples
Start Defender OfflineStart-MpWDOScanView examples

Identity, Access, and Security · 16 commands

PowerShell SecretManagement and SecretStore Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Install pinned modulesInstall-PSResource Microsoft.PowerShell.SecretManagement ` -Version 1.1.2 -TrustRepositoryView examples
Register SecretStoreRegister-SecretVault -Name LocalStore -ModuleName ` Microsoft.PowerShell.SecretStore -DefaultVaultView examples
List registered vaultsGet-SecretVaultView examples
Test a vaultTest-SecretVault -Name LocalStoreView examples
Choose default vaultSet-SecretVaultDefault -Name LocalStoreView examples
Store a SecureStringSet-Secret -Name ApiToken -Secret (Read-Host 'Token' ` -AsSecureString) -Vault LocalStoreView examples
Store a credentialSet-Secret -Name ServiceCredential -Secret ` (Get-Credential) -Vault LocalStoreView examples
Prevent accidental overwriteSet-Secret -Name ApiToken -Secret $Token -Vault ` LocalStore -NoClobberView examples
Retrieve a protected value$Token = Get-Secret -Name ApiToken -Vault LocalStoreView examples
List metadata onlyGet-SecretInfo -Vault LocalStoreView examples
Convert only at boundary$Value = Get-Secret -Name ApiToken -Vault LocalStore ` -AsPlainTextView examples
Unlock SecretStoreUnlock-SecretStore -Password (Read-Host 'Vault password' ` -AsSecureString)View examples
Require password promptsSet-SecretStoreConfiguration -Authentication Password ` -Interaction Prompt -Confirm:$falseView examples
Replace a secretSet-Secret -Name ApiToken -Secret $Replacement -Vault ` LocalStoreView examples
Remove a secretRemove-Secret -Name RetiredToken -Vault LocalStore ` -WhatIfView examples
Unregister a vaultUnregister-SecretVault -Name LocalStore -WhatIfView examples

Identity, Access, and Security · 16 commands

Windows BitLocker and TPM PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Inspect TPM readinessGet-Tpm | Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated, RestartPending, LockedOutView examples
Audit BitLocker volumesGet-BitLockerVolume | Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, EncryptionMethod, EncryptionPercentageView examples
Check status with manage-bdemanage-bde.exe -status C:View examples
List protector metadata(Get-BitLockerVolume -MountPoint $env:SystemDrive).KeyProtector | Select-Object KeyProtectorId, KeyProtectorTypeView examples
Resolve recovery protector ID(Get-BitLockerVolume $env:SystemDrive).KeyProtector | Where-Object KeyProtectorType -eq 'RecoveryPassword' | Select-Object KeyProtectorIdView examples
Back up to Microsoft Entra IDBackupToAAD-BitLockerKeyProtector -MountPoint ` $env:SystemDrive -KeyProtectorId ` '{RECOVERY-PROTECTOR-GUID}'View examples
Back up to AD DSBackup-BitLockerKeyProtector -MountPoint ` $env:SystemDrive -KeyProtectorId ` '{RECOVERY-PROTECTOR-GUID}'View examples
Preview TPM enablementEnable-BitLocker -MountPoint $env:SystemDrive ` -EncryptionMethod XtsAes256 -TpmProtector ` -UsedSpaceOnly -WhatIfView examples
Preview adding recoveryAdd-BitLockerKeyProtector -MountPoint $env:SystemDrive ` -RecoveryPasswordProtector -WhatIfView examples
Preview one-reboot suspensionSuspend-BitLocker -MountPoint $env:SystemDrive ` -RebootCount 1 -WhatIfView examples
Preview protection resumeResume-BitLocker -MountPoint $env:SystemDrive -WhatIfView examples
Verify protection resumedGet-BitLockerVolume $env:SystemDrive | Select-Object MountPoint, VolumeStatus, ProtectionStatus, LockStatusView examples
Audit automatic unlockGet-BitLockerVolume | Select-Object MountPoint, VolumeType, AutoUnlockEnabled, ProtectionStatusView examples
Preview disabling auto-unlockDisable-BitLockerAutoUnlock -MountPoint 'D:' -WhatIfView examples
Preview BitLocker decryptionDisable-BitLocker -MountPoint 'D:' -WhatIfView examples
Read BitLocker eventsGet-WinEvent -LogName ` 'Microsoft-Windows-BitLocker/BitLocker Management' ` -MaxEvents 50View examples

Identity, Access, and Security · 14 commands

Windows Certificates and PowerShell Code Signing Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List store locationsGet-ChildItem Cert:\View examples
List user personal certificatesGet-ChildItem Cert:\CurrentUser\MyView examples
Find expiring certificatesGet-ChildItem Cert:\LocalMachine\My -ExpiringInDays 30View examples
Find code-signing certificatesGet-ChildItem Cert:\CurrentUser\My -CodeSigningCertView examples
Select exact thumbprintGet-Item Cert:\CurrentUser\My\THUMBPRINTView examples
Inspect certificate details$certificate | Format-List Subject, Issuer, Thumbprint, NotBefore, NotAfter, HasPrivateKey, EnhancedKeyUsageListView examples
Build a certificate chain$chain.Build($certificate)View examples
Preview certificate importImport-Certificate -FilePath '.\issuer.cer' ` -CertStoreLocation Cert:\CurrentUser\Root -WhatIfView examples
Import private-key packageImport-PfxCertificate -FilePath '.\signing.pfx' ` -CertStoreLocation Cert:\CurrentUser\My -Password ` $passwordView examples
Export public certificateExport-Certificate -Cert $certificate -FilePath ` '.\signer.cer'View examples
Inspect a file signatureGet-AuthenticodeSignature -LiteralPath '.\Deploy.ps1'View examples
Sign with timestampSet-AuthenticodeSignature -LiteralPath '.\Deploy.ps1' ` -Certificate $certificate -TimestampServer ` 'http://timestamp.example' -HashAlgorithm SHA256View examples
Hash the final fileGet-FileHash -LiteralPath '.\Deploy.ps1' -Algorithm ` SHA256View examples
Preview certificate removalRemove-Item Cert:\CurrentUser\My\THUMBPRINT -WhatIfView examples

Identity, Access, and Security · 12 commands

Windows File Permissions and ACLs PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Inspect an ACLGet-Acl -LiteralPath 'C:\Data\Reports' | Format-ListView examples
List access entries(Get-Acl -LiteralPath $path).Access | Format-Table IdentityReference, FileSystemRights, AccessControlType, IsInheritedView examples
Capture SDDL(Get-Acl -LiteralPath $path).Sddl | Set-Content -LiteralPath '.\acl.sddl'View examples
Back up a treeicacls C:\Data\Reports /save C:\Backup\reports.acl /t /cView examples
Create an allow rule$rule = ` [System.Security.AccessControl.FileSystemAccessRule]::new('CONTOSO\Analysts', ` 'ReadAndExecute', 'Allow')View examples
Add a rule in memory$acl.AddAccessRule($rule)View examples
Preview applying an ACLSet-Acl -LiteralPath $path -AclObject $acl -WhatIfView examples
Inspect owner(Get-Acl -LiteralPath $path).OwnerView examples
Disable inheritance in memory$acl.SetAccessRuleProtection($true, $true)View examples
Verify ACL canonical formicacls C:\Data\Reports /verify /tView examples
Inspect security groupswhoami /allView examples
Test actual accessTest-Path -LiteralPath 'C:\Data\Reports\summary.csv'View examples

Identity, Access, and Security · 17 commands

Windows Local Users and Groups PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
List local usersGet-LocalUser | Sort-Object NameView examples
Get one local userGet-LocalUser -Name 'ReportRunner'View examples
Resolve by SIDGet-LocalUser -SID 'S-1-5-21-...-1002'View examples
List local groupsGet-LocalGroup | Sort-Object NameView examples
Inspect group membershipGet-LocalGroupMember -Group 'Remote Desktop Users' | Select-Object Name, SID, ObjectClass, PrincipalSourceView examples
Preview user creationNew-LocalUser -Name 'ReportRunner' -Password $password ` -Description 'Runs local reports' -WhatIfView examples
Preview a disabled accountNew-LocalUser -Name 'StagedUser' -NoPassword ` -AccountNeverExpires -UserMayNotChangePassword -WhatIfView examples
Preview disabling a userDisable-LocalUser -Name 'ReportRunner' -WhatIfView examples
Preview enabling a userEnable-LocalUser -Name 'ReportRunner' -WhatIfView examples
Preview an account updateSet-LocalUser -Name 'ReportRunner' -Description ` 'Runs signed reporting jobs' -WhatIfView examples
Preview a password changeSet-LocalUser -Name 'ReportRunner' -Password $password ` -WhatIfView examples
Preview group creationNew-LocalGroup -Name 'Report Operators' -Description ` 'May run approved reports' -WhatIfView examples
Preview adding a memberAdd-LocalGroupMember -Group 'Report Operators' -Member ` '.\ReportRunner' -WhatIfView examples
Preview removing a memberRemove-LocalGroupMember -Group 'Report Operators' ` -Member '.\ReportRunner' -WhatIfView examples
Preview user removalRemove-LocalUser -Name 'ReportRunner' -WhatIfView examples
Preview group removalRemove-LocalGroup -Name 'Report Operators' -WhatIfView examples
Check module availabilityGet-Module -ListAvailable ` Microsoft.PowerShell.LocalAccountsView examples

Identity, Access, and Security · 22 commands

Windows Managed Service Accounts and gMSA PowerShell Cheat Sheet

Open full cheat sheet
UseSyntaxExamples
Inspect AD platform levelsGet-ADForest | Select-Object ForestMode; Get-ADDomain | Select-Object DomainModeView examples
Check the AD moduleGet-Module -ListAvailable ActiveDirectory | Select-Object Name, Version, PathView examples
List KDS root keysGet-KdsRootKey | Select-Object KeyId, EffectiveTime, CreationTimeView examples
Create a production KDS keyAdd-KdsRootKey -EffectiveImmediatelyView examples
Check KDS operational eventsGet-WinEvent -FilterHashtable ` @{LogName='Microsoft-Windows-KdsSvc/Operational'; ` Id=4004} -MaxEvents 5View examples
Preview a host groupNew-ADGroup -Name 'GG-gmsaFinance-Hosts' -GroupScope ` DomainLocal -GroupCategory Security -WhatIfView examples
Preview host authorizationAdd-ADGroupMember -Identity 'GG-gmsaFinance-Hosts' ` -Members 'APP01$' -WhatIfView examples
Preview a gMSANew-ADServiceAccount -Name 'gmsaFinance' -DNSHostName ` 'finance.corp.example.com' -WhatIfView examples
Preview an sMSANew-ADServiceAccount -Name 'msaLegacy' ` -RestrictToSingleComputer -WhatIfView examples
Preview a dMSANew-ADServiceAccount -Name 'dmsaFinance' -DNSHostName ` 'dmsaFinance.corp.example.com' ` -CreateDelegatedServiceAccount -WhatIfView examples
Inspect a managed accountGet-ADServiceAccount -Identity 'gmsaFinance' -Properties ` PrincipalsAllowedToRetrieveManagedPassword,ServicePrincipalNamesView examples
Preview retrieval policySet-ADServiceAccount -Identity 'gmsaFinance' ` -PrincipalsAllowedToRetrieveManagedPassword ` 'GG-gmsaFinance-Hosts' -WhatIfView examples
Preview local installationInstall-ADServiceAccount -Identity 'gmsaFinance' -WhatIfView examples
Test local readinessTest-ADServiceAccount -Identity 'gmsaFinance'View examples
Check SPN ownershipsetspn.exe -Q 'HTTP/finance.corp.example.com'View examples
Register a unique SPNsetspn.exe -S 'HTTP/finance.corp.example.com' ` 'CORP\gmsaFinance$'View examples
Assign a Windows servicesc.exe config FinanceWorker obj= 'CORP\gmsaFinance$' ` password= ''View examples
Build a task principalNew-ScheduledTaskPrincipal -UserId 'CORP\gmsaFinance$' ` -LogonType Password -RunLevel LimitedView examples
Inspect service identityGet-CimInstance Win32_Service -Filter "Name='FinanceWorker'" | Select-Object Name, StartName, State; sc.exe qmanagedaccount FinanceWorkerView examples
Read Kerberos eventsGet-WinEvent -LogName ` 'Microsoft-Windows-Security-Kerberos/Operational' ` -MaxEvents 100View examples
Preview local uninstallUninstall-ADServiceAccount -Identity 'gmsaFinance' ` -WhatIfView examples
Preview directory removalRemove-ADServiceAccount -Identity 'gmsaFinance' -Server ` 'dc01.corp.example.com' -WhatIfView examples
CMDMEMO TERMINALREAD ONLY