The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Load IIS administration | Import-Module WebAdministration | View examples |
| List websites | Get-Website |
Select-Object Name, Id, State, PhysicalPath, Bindings | View examples |
| List site applications | Get-WebApplication -Site 'CmdMemo' | View examples |
| List site bindings | Get-WebBinding -Name 'CmdMemo' |
Select-Object protocol, bindingInformation, sslFlags | View examples |
| Inspect pool state | Get-WebAppPoolState -Name 'CmdMemoPool' | View examples |
| Read an effective setting | Get-WebConfigurationProperty -PSPath `
'IIS:\' -Location 'CmdMemo' -Filter 'system.webServer/directoryBrowse' -Name enabled | View examples |
| Preview disabling browsing | Set-WebConfigurationProperty -PSPath `
'IIS:\' -Location 'CmdMemo' -Filter 'system.webServer/directoryBrowse' -Name enabled -Value false -WhatIf | View examples |
| Back up IIS configuration | Backup-WebConfiguration -Name 'Before-CmdMemo-20260812' | View examples |
| List configuration backups | Get-WebConfigurationBackup | View examples |
| Preview configuration restore | Restore-WebConfiguration -Name 'Before-CmdMemo-20260812' `
-WhatIf | View examples |
| Create an application pool | New-WebAppPool -Name 'CmdMemoPool' | View examples |
| Preview no managed runtime | Set-ItemProperty 'IIS:\AppPools\CmdMemoPool' -Name `
managedRuntimeVersion -Value '' -WhatIf | View examples |
| Restart an application pool | Restart-WebAppPool -Name 'CmdMemoPool' | View examples |
| Create a website | New-Website -Name 'CmdMemo' -PhysicalPath `
'C:\Sites\CmdMemo' -Port 80 -HostHeader `
'app.example.com' -ApplicationPool 'CmdMemoPool' | View examples |
| Create a web application | New-WebApplication -Name 'api' -Site 'CmdMemo' `
-PhysicalPath 'C:\Sites\CmdMemo\Api' -ApplicationPool `
'CmdMemoPool' | View examples |
| Add an SNI HTTPS binding | New-WebBinding -Name 'CmdMemo' -Protocol https -Port 443 `
-IPAddress '*' -HostHeader 'app.example.com' -SslFlags `
1 | View examples |
| Attach the TLS certificate | $binding.AddSslCertificate($certificate.Thumbprint, `
'My') | View examples |
| Test an application URL | Invoke-WebRequest -Uri 'https://app.example.com/health' `
-TimeoutSec 15 | View examples |
| Inspect active requests | Get-WebRequest -AppPool 'CmdMemoPool' | View examples |
| Read recent IIS log lines | $site = Get-Website -Name 'CmdMemo'; Get-Content -Path `
"C:\inetpub\logs\LogFiles\W3SVC$($site.Id)\u_ex*.log" `
-Tail 50 | View examples |
IIS combines a hierarchical configuration system with runtime objects such as sites, bindings, application pools, workers, and requests. Import WebAdministration in an elevated Windows PowerShell session on a server with IIS management tools, identify the exact configuration location and inheritance boundary, capture a server-level backup, then make one reviewed change at a time. Site stops, pool restarts, binding edits, certificate association, and remote administration can interrupt every application sharing the affected object.
Step by step
Detailed examples
Inventory configuration and runtime state before changes
WebAdministration exposes the IIS:\ provider and task cmdlets only where IIS management scripting tools are installed. Run elevated for server changes. A site can contain multiple applications, a pool can serve multiple sites, and a binding's IP-port-host tuple determines traffic ownership. On a remote server, run the inventory inside an approved PowerShell remoting session and verify the reported computer name before changing anything.
Import-Module WebAdministration
Get-Website | Select-Object Name, Id, State, PhysicalPath, Bindings
Get-WebApplication -Site 'CmdMemo'
Get-WebBinding -Name 'CmdMemo' | Select-Object protocol, bindingInformation, sslFlags
Get-WebAppPoolState -Name 'CmdMemoPool' Target the correct configuration hierarchy and location
IIS settings inherit from ApplicationHost.config and parent locations into sites, applications, and directories; locked sections cannot be overridden lower in the hierarchy. Read the effective property at the intended Location and inspect metadata or configuration location before writing. Use WhatIf to preview Set-WebConfigurationProperty, retain a backup, peer-review the filter and location, and verify whether the approved write causes application or pool recycling.
$filter = 'system.webServer/directoryBrowse'
Get-WebConfigurationProperty -PSPath 'IIS:\' -Location 'CmdMemo' -Filter $filter -Name enabled
Get-WebConfigurationLock -PSPath 'IIS:\' -Location 'CmdMemo' -Filter $filter
Set-WebConfigurationProperty -PSPath 'IIS:\' -Location 'CmdMemo' -Filter $filter -Name enabled -Value false -WhatIf Capture and test server-level configuration recovery
Backup-WebConfiguration creates an IIS configuration backup on the local server; it is not an application-content, certificate-private-key, external-secret, or database backup. Use a unique change identifier and confirm the backup appears before mutation. Restore-WebConfiguration is server-wide and can overwrite unrelated changes made after the backup, so preview it with WhatIf and use it only through an approved recovery decision.
$backupName = 'Before-CmdMemo-20260812'
Backup-WebConfiguration -Name $backupName
Get-WebConfigurationBackup | Where-Object Name -eq $backupName
Restore-WebConfiguration -Name $backupName -WhatIf Use application pools as explicit failure and identity boundaries
A dedicated pool can isolate process health and identity, but applications in the same pool still share its lifecycle and resource limits. Select pipeline, runtime, identity, recycling, and start behavior for the workload rather than copying defaults blindly. New-WebAppPool and Restart-WebAppPool do not provide a preview; Set-ItemProperty does. A restart interrupts or replaces workers and can drop in-memory state or cold-start every application in that pool.
$pool = 'CmdMemoPool'
if (Test-Path "IIS:\AppPools\$pool") {
Set-ItemProperty "IIS:\AppPools\$pool" -Name managedRuntimeVersion -Value '' -WhatIf
} else {
Write-Warning "Pool must be approved and created first: $pool"
}
# Creation and restart do not support WhatIf:
# New-WebAppPool -Name $pool
# Restart-WebAppPool -Name $pool Validate content paths, identities, and namespace collisions
A site needs a unique binding and an accessible physical path; an application introduces its own configuration boundary and pool assignment. Confirm DNS, firewall, reserved ports, path ACLs for the pool identity, deployment contents, and existing bindings before creation. New-Website and New-WebApplication apply immediately and do not support WhatIf, so keep them gated until the exact definition has been reviewed.
$sitePath = 'C:\Sites\CmdMemo'
$apiPath = 'C:\Sites\CmdMemo\Api'
if (-not (Test-Path -LiteralPath $sitePath -PathType Container)) { throw "Missing path: $sitePath" }
if (-not (Test-Path -LiteralPath $apiPath -PathType Container)) { throw "Missing path: $apiPath" }
Get-Website -Name 'CmdMemo' -ErrorAction SilentlyContinue
Get-WebBinding | Where-Object bindingInformation -match ':80:app\.example\.com$'
# After approval; neither command supports WhatIf:
# New-Website -Name 'CmdMemo' -PhysicalPath $sitePath -Port 80 -HostHeader 'app.example.com' -ApplicationPool 'CmdMemoPool'
# New-WebApplication -Name 'api' -Site 'CmdMemo' -PhysicalPath $apiPath -ApplicationPool 'CmdMemoPool' Treat HTTPS binding creation and certificate association as two changes
New-WebBinding creates the protocol/IP/port/host tuple but does not by itself attach a usable server certificate. SslFlags 1 enables SNI, so clients must send the host name. Before calling AddSslCertificate, verify that the certificate is in LocalMachine\My, has a private key, matches the DNS name, is valid, chains correctly, and is approved for server authentication. Neither operation supports WhatIf; an incorrect or colliding binding can redirect or break remote traffic.
$certificate = Get-Item 'Cert:\LocalMachine\My\THUMBPRINT'
$certificate | Format-List Subject, Issuer, Thumbprint, NotBefore, NotAfter, HasPrivateKey, EnhancedKeyUsageList
Get-WebBinding -Name 'CmdMemo' | Select-Object protocol, bindingInformation, sslFlags
# After collision checks and approval; these operations have no WhatIf support:
# New-WebBinding -Name 'CmdMemo' -Protocol https -Port 443 -IPAddress '*' -HostHeader 'app.example.com' -SslFlags 1
# $binding = Get-WebBinding -Name 'CmdMemo' -Protocol https -Port 443 -HostHeader 'app.example.com'
# $binding.AddSslCertificate($certificate.Thumbprint, 'My') Verify through the production path before changing more state
A Started site and pool do not prove that DNS, TLS, authentication, application startup, or upstream dependencies work. Request a dedicated health URL through the intended host name from an authorized client, inspect certificate and response details, then correlate active requests and the correct W3C log directory. W3SVC folder numbers are site IDs, not names; obtain the Id from Get-Website instead of assuming W3SVC1.
$site = Get-Website -Name 'CmdMemo'
Get-WebAppPoolState -Name 'CmdMemoPool'
$response = Invoke-WebRequest -Uri 'https://app.example.com/health' -TimeoutSec 15
$response | Select-Object StatusCode, StatusDescription, Headers
Get-WebRequest -AppPool 'CmdMemoPool'
$logPattern = "C:\inetpub\logs\LogFiles\W3SVC$($site.Id)\u_ex*.log"
Get-Content -Path $logPattern -Tail 50 Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



