182 commands · 11 cheat sheets · Windows
Identity, Access, and Security master quick reference
Browse 182 commands from 11 focused cheat sheets on page 1 of 1. Each example opens its matching detailed section.
Identity, Access, and Security · 16 commands
Active Directory Certificate Services Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Inspect AD CS features | Get-WindowsFeature AD-Certificate,ADCS-Cert-Authority | View examples |
| Inspect domain context | Get-CimInstance Win32_ComputerSystem |
Select-Object Name,Domain,PartOfDomain | View examples |
| Install CA binaries | Install-WindowsFeature ADCS-Cert-Authority `
-IncludeManagementTools -WhatIf | View examples |
| Configure an enterprise subordinate CA | Install-AdcsCertificationAuthority -CAType `
EnterpriseSubordinateCA -CACommonName `
'Contoso Issuing CA 01' -WhatIf | View examples |
| Inspect CA service | Get-Service CertSvc | View examples |
| Read CA configuration | certutil.exe -getreg CA | View examples |
| List issued templates | Get-CATemplate | View examples |
| Publish a template | Add-CATemplate -Name 'ContosoWebServer' -WhatIf | View examples |
| Inspect pending requests | certutil.exe -view -restrict 'Disposition=9' -out `
'RequestID,RequesterName,CommonName' | View examples |
| Inspect issued requests | certutil.exe -view -restrict 'Disposition=20' -out `
'RequestID,CommonName,NotAfter' | View examples |
| Revoke a certificate | certutil.exe -revoke $Serial KeyCompromise | View examples |
| Publish a new CRL | certutil.exe -crl | View examples |
| Verify certificate URLs | certutil.exe -url '.\issued.cer' | View examples |
| Back up CA database and key | Backup-CARoleService -Path 'E:\CA-Backup' -Password `
(Read-Host -AsSecureString) | View examples |
| Export CA configuration | reg.exe export `
'HKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration' `
'.\ca-config.reg' /y | View examples |
| Read CA operational events | Get-WinEvent -LogName 'Application' -ProviderName `
'Microsoft-Windows-CertificationAuthority' -MaxEvents `
100 | View examples |
Identity, Access, and Security · 19 commands
Active Directory Users, Groups, and Computers PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Check the AD module | Get-Module -ListAvailable ActiveDirectory |
Select-Object Name, Version, Path | View examples |
| Identify domain context | Get-ADDomain -Identity 'corp.example.com' -Server `
'dc01.corp.example.com' | View examples |
| Resolve one user | Get-ADUser -Identity 'alice.chen' -Properties `
mail,Enabled,LastLogonDate -Server `
'dc01.corp.example.com' | View examples |
| Search users in an OU | Get-ADUser -Filter 'Enabled -eq $true' -SearchBase `
'OU=People,DC=corp,DC=example,DC=com' -Server `
'dc01.corp.example.com' | View examples |
| Find inactive users | Search-ADAccount -UsersOnly -AccountInactive -TimeSpan `
(New-TimeSpan -Days 90) -SearchBase `
'OU=People,DC=corp,DC=example,DC=com' | View examples |
| Preview a disabled user | New-ADUser -Name 'Alice Chen' -SamAccountName `
'alice.chen' -Path `
'OU=People,DC=corp,DC=example,DC=com' -Enabled:$false `
-WhatIf | View examples |
| Preview a user update | Set-ADUser -Identity 'alice.chen' -Department 'Finance' `
-Title 'Analyst' -Server 'dc01.corp.example.com' `
-WhatIf | View examples |
| Preview account disable | Disable-ADAccount -Identity 'alice.chen' -Server `
'dc01.corp.example.com' -WhatIf | View examples |
| Preview moving an object | Move-ADObject -Identity $user.ObjectGUID -TargetPath `
'OU=Staged,DC=corp,DC=example,DC=com' -Server `
'dc01.corp.example.com' -WhatIf | View examples |
| Inspect a group | Get-ADGroup -Identity 'GG-Finance-Readers' -Properties `
GroupCategory,GroupScope,ManagedBy -Server `
'dc01.corp.example.com' | View examples |
| Expand nested members | Get-ADGroupMember -Identity 'GG-Finance-Readers' `
-Recursive -Server 'dc01.corp.example.com' | View examples |
| List principal groups | Get-ADPrincipalGroupMembership -Identity 'alice.chen' -Server 'dc01.corp.example.com' |
Sort-Object Name | View examples |
| Preview group creation | New-ADGroup -Name 'GG-Finance-Readers' -GroupScope `
Global -Path 'OU=Groups,DC=corp,DC=example,DC=com' `
-WhatIf | View examples |
| Preview adding a member | Add-ADGroupMember -Identity $group.ObjectGUID -Members `
$user.ObjectGUID -Server 'dc01.corp.example.com' `
-WhatIf | View examples |
| Preview removing a member | Remove-ADGroupMember -Identity $group.ObjectGUID `
-Members $user.ObjectGUID -Server `
'dc01.corp.example.com' -WhatIf | View examples |
| Search computer accounts | Get-ADComputer -Filter `
'OperatingSystem -like "Windows Server*"' -SearchBase `
'OU=Servers,DC=corp,DC=example,DC=com' | View examples |
| Preview a computer account | New-ADComputer -Name 'APP-042' -Path `
'OU=Staging,OU=Servers,DC=corp,DC=example,DC=com' `
-Enabled:$false -WhatIf | View examples |
| Find inactive computers | Search-ADAccount -ComputersOnly -AccountInactive `
-TimeSpan (New-TimeSpan -Days 60) -SearchBase `
'OU=Servers,DC=corp,DC=example,DC=com' | View examples |
| Verify on another DC | Get-ADUser -Identity $user.ObjectGUID -Properties `
Enabled,Department -Server 'dc02.corp.example.com' | View examples |
Identity, Access, and Security · 16 commands
Application Control, AppLocker, and WDAC Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Read effective AppLocker policy | Get-AppLockerPolicy -Effective -Xml | View examples |
| Read Code Integrity events | Get-WinEvent -LogName `
'Microsoft-Windows-CodeIntegrity/Operational' `
-MaxEvents 100 | View examples |
| Collect file identities | Get-AppLockerFileInformation -Directory `
'C:\Program Files\Contoso' -Recurse | View examples |
| Generate audit policy XML | Get-AppLockerFileInformation -EventLog -EventType Audited |
New-AppLockerPolicy -RuleType Publisher,Hash -User Everyone -Xml | View examples |
| Test files against policy | Test-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -Path `
'C:\Apps\*' -User 'CONTOSO\PilotUser' | View examples |
| Preview local AppLocker policy | Set-AppLockerPolicy -XmlPolicy '.\AppLocker.xml' -WhatIf | View examples |
| Inspect Application Identity | Get-Service AppIDSvc | View examples |
| Read AppLocker EXE events | Get-WinEvent -LogName `
'Microsoft-Windows-AppLocker/EXE and DLL' -MaxEvents `
100 | View examples |
| Create candidate base policy | New-CIPolicy -ScanPath 'C:\Windows' -Level Publisher `
-Fallback Hash -FilePath '.\Base.xml' -UserPEs | View examples |
| Keep audit mode enabled | Set-RuleOption -FilePath '.\Base.xml' -Option 3 | View examples |
| Merge policy XML | Merge-CIPolicy -PolicyPaths `
'.\Base.xml','.\AuditAdditions.xml' -OutputFilePath `
'.\Merged.xml' | View examples |
| Compile policy binary | ConvertFrom-CIPolicy -XmlFilePath '.\Merged.xml' `
-BinaryFilePath '.\Merged.cip' | View examples |
| List active App Control policies | CiTool.exe -lp -json | View examples |
| Hash policy artifact | Get-FileHash '.\Merged.cip' -Algorithm SHA256 | View examples |
| Summarize CI event IDs | Get-WinEvent -LogName 'Microsoft-Windows-CodeIntegrity/Operational' -MaxEvents 500 |
Group-Object Id | View examples |
| Inspect PowerShell language mode | $ExecutionContext.SessionState.LanguageMode | View examples |
Identity, Access, and Security · 16 commands
Just Enough Administration (JEA) Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Create a role template | New-PSRoleCapabilityFile -Path '.\Maintenance.psrc' | View examples |
| Test role syntax | Test-ModuleManifest '.\Contoso.JEA\Contoso.JEA.psd1' | View examples |
| Expose constrained parameters | VisibleCmdlets = @{ Name = 'Restart-Service'; Parameters `
= @{ Name = 'Name'; ValidateSet = 'Spooler' } } | View examples |
| Expose wrapper functions | VisibleFunctions = 'Restart-PrintService' | View examples |
| Create session configuration | New-PSSessionConfigurationFile -SessionType `
RestrictedRemoteServer -Path '.\Maintenance.pssc' | View examples |
| Validate session syntax | Test-PSSessionConfigurationFile -Path `
'.\Maintenance.pssc' | View examples |
| Register endpoint | Register-PSSessionConfiguration -Name Maintenance -Path `
'.\Maintenance.pssc' -Force | View examples |
| List endpoints | Get-PSSessionConfiguration |
Select-Object Name,Permission,SessionType | View examples |
| Enter a JEA session | Enter-PSSession -ComputerName server01 `
-ConfigurationName Maintenance | View examples |
| Invoke a delegated task | Invoke-Command -ComputerName server01 -ConfigurationName `
Maintenance -ScriptBlock { Get-Service Spooler } | View examples |
| Audit effective commands | Get-PSSessionCapability -ConfigurationName Maintenance `
-Username 'CONTOSO\JEA-Operators' | View examples |
| Inspect role mappings | (Get-PSSessionConfiguration -Name `
Maintenance).RoleDefinitions | View examples |
| Find recent transcripts | Get-ChildItem -LiteralPath 'C:\ProgramData\JEA\Transcripts' -File |
Sort-Object LastWriteTime -Descending | View examples |
| Read remoting events | Get-WinEvent -LogName `
'Microsoft-Windows-PowerShell/Operational' -MaxEvents `
100 | View examples |
| Remove an endpoint | Unregister-PSSessionConfiguration -Name Maintenance `
-WhatIf | View examples |
| Inspect endpoint permission | Get-PSSessionConfiguration -Name Maintenance |
Select-Object Name,Permission | View examples |
Identity, Access, and Security · 18 commands
Microsoft Defender Antivirus PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Inspect protection health | Get-MpComputerStatus |
Select-Object AMServiceEnabled, AntivirusEnabled, RealTimeProtectionEnabled, BehaviorMonitorEnabled, IsTamperProtected | View examples |
| Inspect Defender service | Get-Service -Name WinDefend |
Select-Object Name, Status, StartType | View examples |
| Audit protection preferences | Get-MpPreference |
Select-Object DisableRealtimeMonitoring, DisableBehaviorMonitoring, DisableIOAVProtection, PUAProtection | View examples |
| Check intelligence freshness | Get-MpComputerStatus |
Select-Object AntivirusSignatureVersion, AntivirusSignatureLastUpdated, AntivirusSignatureAge | View examples |
| Request an intelligence update | Update-MpSignature | View examples |
| Start a quick scan | Start-MpScan -ScanType QuickScan | View examples |
| Scan one approved path | Start-MpScan -ScanType CustomScan -ScanPath 'C:\Inbound' | View examples |
| Review scan timestamps | Get-MpComputerStatus |
Select-Object QuickScanStartTime, QuickScanEndTime, FullScanStartTime, FullScanEndTime | View examples |
| List detection history | Get-MpThreatDetection |
Sort-Object InitialDetectionTime -Descending | View examples |
| List known threats | Get-MpThreat |
Select-Object ThreatID, ThreatName, SeverityID, CategoryID, IsActive, DidThreatExecute | View examples |
| Read key Defender events | Get-WinEvent -FilterHashtable `
@{LogName='Microsoft-Windows-Windows Defender/Operational'; `
Id=1116,1117,1118,5007} -MaxEvents 100 | View examples |
| Inventory exclusions | Get-MpPreference |
Select-Object ExclusionPath, ExclusionExtension, ExclusionProcess | View examples |
| Add one narrow path exclusion | Add-MpPreference -ExclusionPath 'C:\Vendor\App\Cache' | View examples |
| Remove one path exclusion | Remove-MpPreference -ExclusionPath 'C:\Vendor\App\Cache' | View examples |
| Check tamper protection | Get-MpComputerStatus |
Select-Object IsTamperProtected, RealTimeProtectionEnabled, AntivirusEnabled | View examples |
| Record Defender performance | New-MpPerformanceRecording -RecordTo `
'C:\Temp\Defender-scans.etl' -Seconds 120 | View examples |
| Report high-impact files | Get-MpPerformanceReport -Path `
'C:\Temp\Defender-scans.etl' -TopFiles 20 `
-TopProcesses 20 | View examples |
| Start Defender Offline | Start-MpWDOScan | View examples |
Identity, Access, and Security · 16 commands
PowerShell SecretManagement and SecretStore Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Install pinned modules | Install-PSResource Microsoft.PowerShell.SecretManagement `
-Version 1.1.2 -TrustRepository | View examples |
| Register SecretStore | Register-SecretVault -Name LocalStore -ModuleName `
Microsoft.PowerShell.SecretStore -DefaultVault | View examples |
| List registered vaults | Get-SecretVault | View examples |
| Test a vault | Test-SecretVault -Name LocalStore | View examples |
| Choose default vault | Set-SecretVaultDefault -Name LocalStore | View examples |
| Store a SecureString | Set-Secret -Name ApiToken -Secret (Read-Host 'Token' `
-AsSecureString) -Vault LocalStore | View examples |
| Store a credential | Set-Secret -Name ServiceCredential -Secret `
(Get-Credential) -Vault LocalStore | View examples |
| Prevent accidental overwrite | Set-Secret -Name ApiToken -Secret $Token -Vault `
LocalStore -NoClobber | View examples |
| Retrieve a protected value | $Token = Get-Secret -Name ApiToken -Vault LocalStore | View examples |
| List metadata only | Get-SecretInfo -Vault LocalStore | View examples |
| Convert only at boundary | $Value = Get-Secret -Name ApiToken -Vault LocalStore `
-AsPlainText | View examples |
| Unlock SecretStore | Unlock-SecretStore -Password (Read-Host 'Vault password' `
-AsSecureString) | View examples |
| Require password prompts | Set-SecretStoreConfiguration -Authentication Password `
-Interaction Prompt -Confirm:$false | View examples |
| Replace a secret | Set-Secret -Name ApiToken -Secret $Replacement -Vault `
LocalStore | View examples |
| Remove a secret | Remove-Secret -Name RetiredToken -Vault LocalStore `
-WhatIf | View examples |
| Unregister a vault | Unregister-SecretVault -Name LocalStore -WhatIf | View examples |
Identity, Access, and Security · 16 commands
Windows BitLocker and TPM PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Inspect TPM readiness | Get-Tpm |
Select-Object TpmPresent, TpmReady, TpmEnabled, TpmActivated, RestartPending, LockedOut | View examples |
| Audit BitLocker volumes | Get-BitLockerVolume |
Select-Object MountPoint, VolumeType, VolumeStatus, ProtectionStatus, EncryptionMethod, EncryptionPercentage | View examples |
| Check status with manage-bde | manage-bde.exe -status C: | View examples |
| List protector metadata | (Get-BitLockerVolume -MountPoint $env:SystemDrive).KeyProtector |
Select-Object KeyProtectorId, KeyProtectorType | View examples |
| Resolve recovery protector ID | (Get-BitLockerVolume $env:SystemDrive).KeyProtector |
Where-Object KeyProtectorType -eq 'RecoveryPassword' |
Select-Object KeyProtectorId | View examples |
| Back up to Microsoft Entra ID | BackupToAAD-BitLockerKeyProtector -MountPoint `
$env:SystemDrive -KeyProtectorId `
'{RECOVERY-PROTECTOR-GUID}' | View examples |
| Back up to AD DS | Backup-BitLockerKeyProtector -MountPoint `
$env:SystemDrive -KeyProtectorId `
'{RECOVERY-PROTECTOR-GUID}' | View examples |
| Preview TPM enablement | Enable-BitLocker -MountPoint $env:SystemDrive `
-EncryptionMethod XtsAes256 -TpmProtector `
-UsedSpaceOnly -WhatIf | View examples |
| Preview adding recovery | Add-BitLockerKeyProtector -MountPoint $env:SystemDrive `
-RecoveryPasswordProtector -WhatIf | View examples |
| Preview one-reboot suspension | Suspend-BitLocker -MountPoint $env:SystemDrive `
-RebootCount 1 -WhatIf | View examples |
| Preview protection resume | Resume-BitLocker -MountPoint $env:SystemDrive -WhatIf | View examples |
| Verify protection resumed | Get-BitLockerVolume $env:SystemDrive |
Select-Object MountPoint, VolumeStatus, ProtectionStatus, LockStatus | View examples |
| Audit automatic unlock | Get-BitLockerVolume |
Select-Object MountPoint, VolumeType, AutoUnlockEnabled, ProtectionStatus | View examples |
| Preview disabling auto-unlock | Disable-BitLockerAutoUnlock -MountPoint 'D:' -WhatIf | View examples |
| Preview BitLocker decryption | Disable-BitLocker -MountPoint 'D:' -WhatIf | View examples |
| Read BitLocker events | Get-WinEvent -LogName `
'Microsoft-Windows-BitLocker/BitLocker Management' `
-MaxEvents 50 | View examples |
Identity, Access, and Security · 14 commands
Windows Certificates and PowerShell Code Signing Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| List store locations | Get-ChildItem Cert:\ | View examples |
| List user personal certificates | Get-ChildItem Cert:\CurrentUser\My | View examples |
| Find expiring certificates | Get-ChildItem Cert:\LocalMachine\My -ExpiringInDays 30 | View examples |
| Find code-signing certificates | Get-ChildItem Cert:\CurrentUser\My -CodeSigningCert | View examples |
| Select exact thumbprint | Get-Item Cert:\CurrentUser\My\THUMBPRINT | View examples |
| Inspect certificate details | $certificate |
Format-List Subject, Issuer, Thumbprint, NotBefore, NotAfter, HasPrivateKey, EnhancedKeyUsageList | View examples |
| Build a certificate chain | $chain.Build($certificate) | View examples |
| Preview certificate import | Import-Certificate -FilePath '.\issuer.cer' `
-CertStoreLocation Cert:\CurrentUser\Root -WhatIf | View examples |
| Import private-key package | Import-PfxCertificate -FilePath '.\signing.pfx' `
-CertStoreLocation Cert:\CurrentUser\My -Password `
$password | View examples |
| Export public certificate | Export-Certificate -Cert $certificate -FilePath `
'.\signer.cer' | View examples |
| Inspect a file signature | Get-AuthenticodeSignature -LiteralPath '.\Deploy.ps1' | View examples |
| Sign with timestamp | Set-AuthenticodeSignature -LiteralPath '.\Deploy.ps1' `
-Certificate $certificate -TimestampServer `
'http://timestamp.example' -HashAlgorithm SHA256 | View examples |
| Hash the final file | Get-FileHash -LiteralPath '.\Deploy.ps1' -Algorithm `
SHA256 | View examples |
| Preview certificate removal | Remove-Item Cert:\CurrentUser\My\THUMBPRINT -WhatIf | View examples |
Identity, Access, and Security · 12 commands
Windows File Permissions and ACLs PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Inspect an ACL | Get-Acl -LiteralPath 'C:\Data\Reports' | Format-List | View examples |
| List access entries | (Get-Acl -LiteralPath $path).Access |
Format-Table IdentityReference, FileSystemRights, AccessControlType, IsInherited | View examples |
| Capture SDDL | (Get-Acl -LiteralPath $path).Sddl |
Set-Content -LiteralPath '.\acl.sddl' | View examples |
| Back up a tree | icacls C:\Data\Reports /save C:\Backup\reports.acl /t /c | View examples |
| Create an allow rule | $rule = `
[System.Security.AccessControl.FileSystemAccessRule]::new('CONTOSO\Analysts', `
'ReadAndExecute', 'Allow') | View examples |
| Add a rule in memory | $acl.AddAccessRule($rule) | View examples |
| Preview applying an ACL | Set-Acl -LiteralPath $path -AclObject $acl -WhatIf | View examples |
| Inspect owner | (Get-Acl -LiteralPath $path).Owner | View examples |
| Disable inheritance in memory | $acl.SetAccessRuleProtection($true, $true) | View examples |
| Verify ACL canonical form | icacls C:\Data\Reports /verify /t | View examples |
| Inspect security groups | whoami /all | View examples |
| Test actual access | Test-Path -LiteralPath 'C:\Data\Reports\summary.csv' | View examples |
Identity, Access, and Security · 17 commands
Windows Local Users and Groups PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| List local users | Get-LocalUser | Sort-Object Name | View examples |
| Get one local user | Get-LocalUser -Name 'ReportRunner' | View examples |
| Resolve by SID | Get-LocalUser -SID 'S-1-5-21-...-1002' | View examples |
| List local groups | Get-LocalGroup | Sort-Object Name | View examples |
| Inspect group membership | Get-LocalGroupMember -Group 'Remote Desktop Users' |
Select-Object Name, SID, ObjectClass, PrincipalSource | View examples |
| Preview user creation | New-LocalUser -Name 'ReportRunner' -Password $password `
-Description 'Runs local reports' -WhatIf | View examples |
| Preview a disabled account | New-LocalUser -Name 'StagedUser' -NoPassword `
-AccountNeverExpires -UserMayNotChangePassword -WhatIf | View examples |
| Preview disabling a user | Disable-LocalUser -Name 'ReportRunner' -WhatIf | View examples |
| Preview enabling a user | Enable-LocalUser -Name 'ReportRunner' -WhatIf | View examples |
| Preview an account update | Set-LocalUser -Name 'ReportRunner' -Description `
'Runs signed reporting jobs' -WhatIf | View examples |
| Preview a password change | Set-LocalUser -Name 'ReportRunner' -Password $password `
-WhatIf | View examples |
| Preview group creation | New-LocalGroup -Name 'Report Operators' -Description `
'May run approved reports' -WhatIf | View examples |
| Preview adding a member | Add-LocalGroupMember -Group 'Report Operators' -Member `
'.\ReportRunner' -WhatIf | View examples |
| Preview removing a member | Remove-LocalGroupMember -Group 'Report Operators' `
-Member '.\ReportRunner' -WhatIf | View examples |
| Preview user removal | Remove-LocalUser -Name 'ReportRunner' -WhatIf | View examples |
| Preview group removal | Remove-LocalGroup -Name 'Report Operators' -WhatIf | View examples |
| Check module availability | Get-Module -ListAvailable `
Microsoft.PowerShell.LocalAccounts | View examples |
Identity, Access, and Security · 22 commands
Windows Managed Service Accounts and gMSA PowerShell Cheat Sheet
| Use | Syntax | Examples |
|---|---|---|
| Inspect AD platform levels | Get-ADForest |
Select-Object ForestMode; Get-ADDomain |
Select-Object DomainMode | View examples |
| Check the AD module | Get-Module -ListAvailable ActiveDirectory |
Select-Object Name, Version, Path | View examples |
| List KDS root keys | Get-KdsRootKey |
Select-Object KeyId, EffectiveTime, CreationTime | View examples |
| Create a production KDS key | Add-KdsRootKey -EffectiveImmediately | View examples |
| Check KDS operational events | Get-WinEvent -FilterHashtable `
@{LogName='Microsoft-Windows-KdsSvc/Operational'; `
Id=4004} -MaxEvents 5 | View examples |
| Preview a host group | New-ADGroup -Name 'GG-gmsaFinance-Hosts' -GroupScope `
DomainLocal -GroupCategory Security -WhatIf | View examples |
| Preview host authorization | Add-ADGroupMember -Identity 'GG-gmsaFinance-Hosts' `
-Members 'APP01$' -WhatIf | View examples |
| Preview a gMSA | New-ADServiceAccount -Name 'gmsaFinance' -DNSHostName `
'finance.corp.example.com' -WhatIf | View examples |
| Preview an sMSA | New-ADServiceAccount -Name 'msaLegacy' `
-RestrictToSingleComputer -WhatIf | View examples |
| Preview a dMSA | New-ADServiceAccount -Name 'dmsaFinance' -DNSHostName `
'dmsaFinance.corp.example.com' `
-CreateDelegatedServiceAccount -WhatIf | View examples |
| Inspect a managed account | Get-ADServiceAccount -Identity 'gmsaFinance' -Properties `
PrincipalsAllowedToRetrieveManagedPassword,ServicePrincipalNames | View examples |
| Preview retrieval policy | Set-ADServiceAccount -Identity 'gmsaFinance' `
-PrincipalsAllowedToRetrieveManagedPassword `
'GG-gmsaFinance-Hosts' -WhatIf | View examples |
| Preview local installation | Install-ADServiceAccount -Identity 'gmsaFinance' -WhatIf | View examples |
| Test local readiness | Test-ADServiceAccount -Identity 'gmsaFinance' | View examples |
| Check SPN ownership | setspn.exe -Q 'HTTP/finance.corp.example.com' | View examples |
| Register a unique SPN | setspn.exe -S 'HTTP/finance.corp.example.com' `
'CORP\gmsaFinance$' | View examples |
| Assign a Windows service | sc.exe config FinanceWorker obj= 'CORP\gmsaFinance$' `
password= '' | View examples |
| Build a task principal | New-ScheduledTaskPrincipal -UserId 'CORP\gmsaFinance$' `
-LogonType Password -RunLevel Limited | View examples |
| Inspect service identity | Get-CimInstance Win32_Service -Filter "Name='FinanceWorker'" |
Select-Object Name, StartName, State; sc.exe qmanagedaccount FinanceWorker | View examples |
| Read Kerberos events | Get-WinEvent -LogName `
'Microsoft-Windows-Security-Kerberos/Operational' `
-MaxEvents 100 | View examples |
| Preview local uninstall | Uninstall-ADServiceAccount -Identity 'gmsaFinance' `
-WhatIf | View examples |
| Preview directory removal | Remove-ADServiceAccount -Identity 'gmsaFinance' -Server `
'dc01.corp.example.com' -WhatIf | View examples |



