The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Create a role templateNew-PSRoleCapabilityFile -Path '.\Maintenance.psrc'View examples
Test role syntaxTest-ModuleManifest '.\Contoso.JEA\Contoso.JEA.psd1'View examples
Expose constrained parametersVisibleCmdlets = @{ Name = 'Restart-Service'; Parameters ` = @{ Name = 'Name'; ValidateSet = 'Spooler' } }View examples
Expose wrapper functionsVisibleFunctions = 'Restart-PrintService'View examples
Create session configurationNew-PSSessionConfigurationFile -SessionType ` RestrictedRemoteServer -Path '.\Maintenance.pssc'View examples
Validate session syntaxTest-PSSessionConfigurationFile -Path ` '.\Maintenance.pssc'View examples
Register endpointRegister-PSSessionConfiguration -Name Maintenance -Path ` '.\Maintenance.pssc' -ForceView examples
List endpointsGet-PSSessionConfiguration | Select-Object Name,Permission,SessionTypeView examples
Enter a JEA sessionEnter-PSSession -ComputerName server01 ` -ConfigurationName MaintenanceView examples
Invoke a delegated taskInvoke-Command -ComputerName server01 -ConfigurationName ` Maintenance -ScriptBlock { Get-Service Spooler }View examples
Audit effective commandsGet-PSSessionCapability -ConfigurationName Maintenance ` -Username 'CONTOSO\JEA-Operators'View examples
Inspect role mappings(Get-PSSessionConfiguration -Name ` Maintenance).RoleDefinitionsView examples
Find recent transcriptsGet-ChildItem -LiteralPath 'C:\ProgramData\JEA\Transcripts' -File | Sort-Object LastWriteTime -DescendingView examples
Read remoting eventsGet-WinEvent -LogName ` 'Microsoft-Windows-PowerShell/Operational' -MaxEvents ` 100View examples
Remove an endpointUnregister-PSSessionConfiguration -Name Maintenance ` -WhatIfView examples
Inspect endpoint permissionGet-PSSessionConfiguration -Name Maintenance | Select-Object Name,PermissionView examples

Just Enough Administration delegates a narrow set of PowerShell tasks through constrained remoting endpoints. Its security depends on the complete command surface, parameter constraints, role merging, run-as identity, endpoint ACL, module search path, transcripts, and underlying operating-system permissions. Build wrapper functions around safe tasks, test as every mapped identity, and remember that registering or updating an endpoint restarts WinRM and disconnects active remoting sessions.

Step by step

Detailed examples

01

Package role capabilities in a trusted module

JEA is a Windows remoting technology commonly administered with Windows PowerShell 5.1; verify support before targeting a PowerShell 7 endpoint. It discovers .psrc files only in a RoleCapabilities folder inside a valid module on the target. Restrict ACLs so delegates cannot modify the module, roles, or exposed scripts: a writable path becomes code execution under the run-as identity. Role files should be source-controlled, reviewed, signed where required, and deployed protectively. Test-ModuleManifest checks syntax and metadata, not security.

Create the expected module layout
$ModuleRoot = 'C:\Program Files\WindowsPowerShell\Modules\Contoso.JEA\1.0.0'
# Administrator-only deployment operation:
# New-Item -ItemType Directory -Path (Join-Path $ModuleRoot 'RoleCapabilities') -Force
# New-ModuleManifest -Path (Join-Path $ModuleRoot 'Contoso.JEA.psd1') -RootModule 'Contoso.JEA.psm1'
# New-PSRoleCapabilityFile -Path (Join-Path $ModuleRoot 'RoleCapabilities\Maintenance.psrc')
# Test-ModuleManifest (Join-Path $ModuleRoot 'Contoso.JEA.psd1')
Back to quick reference ↑
02

Constrain parameters, values, providers, and language

VisibleCmdlets without parameter constraints can expose dangerous alternate paths. Prefer a wrapper function that validates a small domain object and calls fully qualified commands. Avoid exposing generic interpreters, editors, script invocation, module import, arbitrary paths, service names, registry providers, or commands with ScriptBlock parameters. JEA role capabilities merge permissively: if any applicable role exposes broader parameters, the user receives that broader union. Review every combination of nested group memberships.

Define a narrow wrapper rather than a generic restart
function Restart-PrintService {
    [CmdletBinding(SupportsShouldProcess)] param()
    if ($PSCmdlet.ShouldProcess('Spooler', 'Restart service')) {
        Microsoft.PowerShell.Management\Restart-Service -Name 'Spooler' -ErrorAction Stop
    }
}
# Export only this wrapper through FunctionsToExport and VisibleFunctions.
Back to quick reference ↑
03

Map identities to roles and choose run-as behavior

A RestrictedRemoteServer session limits language and starts with a small safe command set. RoleDefinitions maps users or groups to named capabilities. RunAsVirtualAccount creates a temporary local account that is normally local administrator on member servers; on domain controllers it belongs to Domain Admins by default, so use VirtualAccountGroups to reduce privilege. A gMSA gives a shared domain identity and network access but weakens per-user attribution. RequiredGroups can add conditional access based on group membership.

Create a reviewable session configuration
$Roles = @{ 'CONTOSO\JEA-Operators' = @{ RoleCapabilities = 'Maintenance' } }
New-PSSessionConfigurationFile -Path '.\Maintenance.pssc' `
    -SessionType RestrictedRemoteServer -RunAsVirtualAccount `
    -RoleDefinitions $Roles `
    -TranscriptDirectory 'C:\ProgramData\JEA\Transcripts'
Test-PSSessionConfigurationFile -Path '.\Maintenance.pssc'
Back to quick reference ↑
04

Register endpoints only in a maintenance window

Register-PSSessionConfiguration requires local administrative rights and restarts WinRM. That terminates active PowerShell remoting sessions and can interrupt DSC operations, so drain work and announce the maintenance. Registration consumes the configuration; later editing the source .pssc does not update the endpoint. Changing role mappings requires unregistering and registering again. Back up the reviewed configuration, record its hash, and retain a tested administrative recovery path outside the constrained endpoint.

Preflight before the disruptive registration
if (-not (Test-PSSessionConfigurationFile '.\Maintenance.pssc')) { throw 'Invalid PSSC' }
Get-PSSessionConfiguration | Select-Object Name, Permission
Get-PSSession | Select-Object ComputerName, State, ConfigurationName
# Approved outage only; restarts WinRM:
# Register-PSSessionConfiguration -Name Maintenance -Path '.\Maintenance.pssc' -Force
Back to quick reference ↑
05

Test through the real endpoint as each persona

Local administrator tests do not demonstrate a delegate's effective surface. Connect using representative accounts for every direct and nested group mapping. Verify expected commands succeed, forbidden commands and parameters fail, file and registry providers are unavailable unless intended, network access matches the run-as choice, and transcripts are created. PowerShell remoting uses WinRM and requires network, firewall, authentication, SPN, and endpoint ACL configuration; avoid TrustedHosts shortcuts in domain environments.

Inventory the constrained session from the client
$Session = New-PSSession -ComputerName 'server01.contoso.example' `
    -ConfigurationName Maintenance
try {
    Invoke-Command -Session $Session -ScriptBlock { Get-Command -CommandType All }
}
finally { Remove-PSSession $Session }
Back to quick reference ↑
06

Audit both endpoint ACLs and role mappings

The WinRM endpoint ACL controls who may connect; RoleDefinitions controls capabilities after connection. They are separate and can drift. Get-PSSessionCapability models a specified user's effective commands, including the permissive merge of all matching roles. Re-run audits when group memberships, modules, role files, endpoint configuration, or Windows patches change. Ensure no writable command, script, function, provider, or module path can be repurposed to escape the intended task.

Compare connection rights and effective capabilities
$Endpoint = Get-PSSessionConfiguration -Name Maintenance
$Endpoint | Select-Object Name, Permission, RunAsUser
$Endpoint.RoleDefinitions.GetEnumerator() | Select-Object Name, Value
Get-PSSessionCapability -ConfigurationName Maintenance `
    -Username 'CONTOSO\JEA-Operators' | Sort-Object Name
Back to quick reference ↑
07

Protect transcripts and correlate multiple logs

JEA transcripts help attribute commands to connecting users even when a virtual account performs the action. They may also capture parameters, paths, business data, and accidentally supplied secrets. Store them on a protected, write-restricted location, forward promptly, define retention, and monitor collection failures. Correlate transcripts with PowerShell Operational, WinRM, security logon, and application events. A gMSA can obscure operating-system attribution because multiple users share one run-as account, making transcripts especially important.

Inventory evidence without dumping sensitive contents
Get-ChildItem 'C:\ProgramData\JEA\Transcripts' -File -Recurse |
    Select-Object FullName, Length, CreationTimeUtc, LastWriteTimeUtc
Get-WinEvent -LogName 'Microsoft-Windows-PowerShell/Operational' -MaxEvents 100 |
    Select-Object TimeCreated, Id, LevelDisplayName
Back to quick reference ↑
08

Plan safe updates and a break-glass path

There is no transaction or universal WhatIf for a JEA deployment. Test files in isolation, deploy to a canary, retest every persona, then register during an outage because WinRM restarts. Unregistering is also disruptive and can remove the only delegated path. Keep a protected, monitored break-glass administrator route and verify it before changes. Rollback means re-registering a known-good .pssc plus its exact module and RoleCapabilities version, not merely restoring one file.

Record artifacts before an endpoint change
Get-FileHash '.\Maintenance.pssc' -Algorithm SHA256
Get-FileHash 'C:\Program Files\WindowsPowerShell\Modules\Contoso.JEA\1.0.0\RoleCapabilities\Maintenance.psrc' -Algorithm SHA256
Get-PSSessionConfiguration -Name Maintenance | Format-List *
# Use Unregister-PSSessionConfiguration only in the approved rollback runbook.
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnJust Enough Administration overviewlearn.microsoft.com
  2. Microsoft LearnJEA role capabilitieslearn.microsoft.com
  3. Microsoft LearnJEA session configurationslearn.microsoft.com
  4. Microsoft LearnRegistering JEA configurationslearn.microsoft.com
  5. Microsoft LearnAuditing and reporting on JEAlearn.microsoft.com
  6. Microsoft LearnJEA security considerationslearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback