The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Load IIS administrationImport-Module WebAdministrationView examples
List websitesGet-Website | Select-Object Name, Id, State, PhysicalPath, BindingsView examples
List site applicationsGet-WebApplication -Site 'CmdMemo'View examples
List site bindingsGet-WebBinding -Name 'CmdMemo' | Select-Object protocol, bindingInformation, sslFlagsView examples
Inspect pool stateGet-WebAppPoolState -Name 'CmdMemoPool'View examples
Read an effective settingGet-WebConfigurationProperty -PSPath ` 'IIS:\' -Location 'CmdMemo' -Filter 'system.webServer/directoryBrowse' -Name enabledView examples
Preview disabling browsingSet-WebConfigurationProperty -PSPath ` 'IIS:\' -Location 'CmdMemo' -Filter 'system.webServer/directoryBrowse' -Name enabled -Value false -WhatIfView examples
Back up IIS configurationBackup-WebConfiguration -Name 'Before-CmdMemo-20260812'View examples
List configuration backupsGet-WebConfigurationBackupView examples
Preview configuration restoreRestore-WebConfiguration -Name 'Before-CmdMemo-20260812' ` -WhatIfView examples
Create an application poolNew-WebAppPool -Name 'CmdMemoPool'View examples
Preview no managed runtimeSet-ItemProperty 'IIS:\AppPools\CmdMemoPool' -Name ` managedRuntimeVersion -Value '' -WhatIfView examples
Restart an application poolRestart-WebAppPool -Name 'CmdMemoPool'View examples
Create a websiteNew-Website -Name 'CmdMemo' -PhysicalPath ` 'C:\Sites\CmdMemo' -Port 80 -HostHeader ` 'app.example.com' -ApplicationPool 'CmdMemoPool'View examples
Create a web applicationNew-WebApplication -Name 'api' -Site 'CmdMemo' ` -PhysicalPath 'C:\Sites\CmdMemo\Api' -ApplicationPool ` 'CmdMemoPool'View examples
Add an SNI HTTPS bindingNew-WebBinding -Name 'CmdMemo' -Protocol https -Port 443 ` -IPAddress '*' -HostHeader 'app.example.com' -SslFlags ` 1View examples
Attach the TLS certificate$binding.AddSslCertificate($certificate.Thumbprint, ` 'My')View examples
Test an application URLInvoke-WebRequest -Uri 'https://app.example.com/health' ` -TimeoutSec 15View examples
Inspect active requestsGet-WebRequest -AppPool 'CmdMemoPool'View examples
Read recent IIS log lines$site = Get-Website -Name 'CmdMemo'; Get-Content -Path ` "C:\inetpub\logs\LogFiles\W3SVC$($site.Id)\u_ex*.log" ` -Tail 50View examples

IIS combines a hierarchical configuration system with runtime objects such as sites, bindings, application pools, workers, and requests. Import WebAdministration in an elevated Windows PowerShell session on a server with IIS management tools, identify the exact configuration location and inheritance boundary, capture a server-level backup, then make one reviewed change at a time. Site stops, pool restarts, binding edits, certificate association, and remote administration can interrupt every application sharing the affected object.

Step by step

Detailed examples

01

Inventory configuration and runtime state before changes

WebAdministration exposes the IIS:\ provider and task cmdlets only where IIS management scripting tools are installed. Run elevated for server changes. A site can contain multiple applications, a pool can serve multiple sites, and a binding's IP-port-host tuple determines traffic ownership. On a remote server, run the inventory inside an approved PowerShell remoting session and verify the reported computer name before changing anything.

Capture the IIS object graph
Import-Module WebAdministration
Get-Website | Select-Object Name, Id, State, PhysicalPath, Bindings
Get-WebApplication -Site 'CmdMemo'
Get-WebBinding -Name 'CmdMemo' | Select-Object protocol, bindingInformation, sslFlags
Get-WebAppPoolState -Name 'CmdMemoPool'
Back to quick reference ↑
02

Target the correct configuration hierarchy and location

IIS settings inherit from ApplicationHost.config and parent locations into sites, applications, and directories; locked sections cannot be overridden lower in the hierarchy. Read the effective property at the intended Location and inspect metadata or configuration location before writing. Use WhatIf to preview Set-WebConfigurationProperty, retain a backup, peer-review the filter and location, and verify whether the approved write causes application or pool recycling.

Read before a site-scoped write
$filter = 'system.webServer/directoryBrowse'
Get-WebConfigurationProperty -PSPath 'IIS:\' -Location 'CmdMemo' -Filter $filter -Name enabled
Get-WebConfigurationLock -PSPath 'IIS:\' -Location 'CmdMemo' -Filter $filter
Set-WebConfigurationProperty -PSPath 'IIS:\' -Location 'CmdMemo' -Filter $filter -Name enabled -Value false -WhatIf
Back to quick reference ↑
03

Capture and test server-level configuration recovery

Backup-WebConfiguration creates an IIS configuration backup on the local server; it is not an application-content, certificate-private-key, external-secret, or database backup. Use a unique change identifier and confirm the backup appears before mutation. Restore-WebConfiguration is server-wide and can overwrite unrelated changes made after the backup, so preview it with WhatIf and use it only through an approved recovery decision.

Create, enumerate, and preview a restore
$backupName = 'Before-CmdMemo-20260812'
Backup-WebConfiguration -Name $backupName
Get-WebConfigurationBackup | Where-Object Name -eq $backupName
Restore-WebConfiguration -Name $backupName -WhatIf
Back to quick reference ↑
04

Use application pools as explicit failure and identity boundaries

A dedicated pool can isolate process health and identity, but applications in the same pool still share its lifecycle and resource limits. Select pipeline, runtime, identity, recycling, and start behavior for the workload rather than copying defaults blindly. New-WebAppPool and Restart-WebAppPool do not provide a preview; Set-ItemProperty does. A restart interrupts or replaces workers and can drop in-memory state or cold-start every application in that pool.

Review a new pool and its disruptive activation steps
$pool = 'CmdMemoPool'
if (Test-Path "IIS:\AppPools\$pool") {
  Set-ItemProperty "IIS:\AppPools\$pool" -Name managedRuntimeVersion -Value '' -WhatIf
} else {
  Write-Warning "Pool must be approved and created first: $pool"
}
# Creation and restart do not support WhatIf:
# New-WebAppPool -Name $pool
# Restart-WebAppPool -Name $pool
Back to quick reference ↑
05

Validate content paths, identities, and namespace collisions

A site needs a unique binding and an accessible physical path; an application introduces its own configuration boundary and pool assignment. Confirm DNS, firewall, reserved ports, path ACLs for the pool identity, deployment contents, and existing bindings before creation. New-Website and New-WebApplication apply immediately and do not support WhatIf, so keep them gated until the exact definition has been reviewed.

Gate a site and application definition
$sitePath = 'C:\Sites\CmdMemo'
$apiPath = 'C:\Sites\CmdMemo\Api'
if (-not (Test-Path -LiteralPath $sitePath -PathType Container)) { throw "Missing path: $sitePath" }
if (-not (Test-Path -LiteralPath $apiPath -PathType Container)) { throw "Missing path: $apiPath" }
Get-Website -Name 'CmdMemo' -ErrorAction SilentlyContinue
Get-WebBinding | Where-Object bindingInformation -match ':80:app\.example\.com$'
# After approval; neither command supports WhatIf:
# New-Website -Name 'CmdMemo' -PhysicalPath $sitePath -Port 80 -HostHeader 'app.example.com' -ApplicationPool 'CmdMemoPool'
# New-WebApplication -Name 'api' -Site 'CmdMemo' -PhysicalPath $apiPath -ApplicationPool 'CmdMemoPool'
Back to quick reference ↑
06

Treat HTTPS binding creation and certificate association as two changes

New-WebBinding creates the protocol/IP/port/host tuple but does not by itself attach a usable server certificate. SslFlags 1 enables SNI, so clients must send the host name. Before calling AddSslCertificate, verify that the certificate is in LocalMachine\My, has a private key, matches the DNS name, is valid, chains correctly, and is approved for server authentication. Neither operation supports WhatIf; an incorrect or colliding binding can redirect or break remote traffic.

Validate a certificate before the gated association
$certificate = Get-Item 'Cert:\LocalMachine\My\THUMBPRINT'
$certificate | Format-List Subject, Issuer, Thumbprint, NotBefore, NotAfter, HasPrivateKey, EnhancedKeyUsageList
Get-WebBinding -Name 'CmdMemo' | Select-Object protocol, bindingInformation, sslFlags
# After collision checks and approval; these operations have no WhatIf support:
# New-WebBinding -Name 'CmdMemo' -Protocol https -Port 443 -IPAddress '*' -HostHeader 'app.example.com' -SslFlags 1
# $binding = Get-WebBinding -Name 'CmdMemo' -Protocol https -Port 443 -HostHeader 'app.example.com'
# $binding.AddSslCertificate($certificate.Thumbprint, 'My')
Back to quick reference ↑
07

Verify through the production path before changing more state

A Started site and pool do not prove that DNS, TLS, authentication, application startup, or upstream dependencies work. Request a dedicated health URL through the intended host name from an authorized client, inspect certificate and response details, then correlate active requests and the correct W3C log directory. W3SVC folder numbers are site IDs, not names; obtain the Id from Get-Website instead of assuming W3SVC1.

Correlate response, active work, and the site-specific log
$site = Get-Website -Name 'CmdMemo'
Get-WebAppPoolState -Name 'CmdMemoPool'
$response = Invoke-WebRequest -Uri 'https://app.example.com/health' -TimeoutSec 15
$response | Select-Object StatusCode, StatusDescription, Headers
Get-WebRequest -AppPool 'CmdMemoPool'
$logPattern = "C:\inetpub\logs\LogFiles\W3SVC$($site.Id)\u_ex*.log"
Get-Content -Path $logPattern -Tail 50
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftWebAdministration Modulelearn.microsoft.com
  2. MicrosoftGet-Websitelearn.microsoft.com
  3. MicrosoftNew-WebBindinglearn.microsoft.com
  4. MicrosoftBackup-WebConfigurationlearn.microsoft.com
  5. MicrosoftIIS Configuration Referencelearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback