The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect standalone DSC | dsc --version | View examples |
| Inspect legacy module | Get-Module -ListAvailable PSDesiredStateConfiguration |
Select-Object Name,Version,Path | View examples |
| List DSC 3 resources | dsc resource list | View examples |
| Inspect resource schema | dsc resource schema --resource Microsoft.DSC.Debug/Echo | View examples |
| Read current state | dsc config get --file .\server.dsc.yaml | View examples |
| Test desired state | dsc config test --file .\server.dsc.yaml | View examples |
| Apply desired state | dsc config set --file .\server.dsc.yaml | View examples |
| Supply parameter data | dsc config --parameters-file .\prod.parameters.yaml set `
--file .\server.dsc.yaml | View examples |
| Inspect Windows LCM | Get-DscLocalConfigurationManager | View examples |
| Test legacy configuration | Test-DscConfiguration -Path .\Compiled -Detailed | View examples |
| Apply compiled MOF | Start-DscConfiguration -Path .\Compiled -Wait -Verbose | View examples |
| Read last LCM run | Get-DscConfigurationStatus -All | View examples |
| Parse a configuration script | $null = `
[System.Management.Automation.Language.Parser]::ParseFile('.\Config.ps1',[ref]$null,[ref]$null) | View examples |
| Recognize WhatIf boundary | Get-Command Start-DscConfiguration |
Select-Object -ExpandProperty Parameters | View examples |
| Export discoverable state | dsc config export --file .\resources.yaml | View examples |
| Read DSC operational events | Get-WinEvent -LogName `
'Microsoft-Windows-DSC/Operational' -MaxEvents 50 | View examples |
Desired State Configuration makes machine state declarative and repeatable, but two distinct stacks now share the DSC name. Microsoft DSC 3 is a standalone, cross-platform command that consumes JSON or YAML and has no Local Configuration Manager. Windows PowerShell DSC 1.1 uses PowerShell configuration scripts, MOF documents, and the Windows LCM. Identify the engine and resource contract first, test before set, keep secrets out of documents and MOF, and stage every change with rollback evidence.
Step by step
Detailed examples
Choose the DSC engine deliberately
Microsoft DSC 3 is a standalone executable for Windows, Linux, and macOS. It accepts JSON or YAML configuration documents, discovers command resources on PATH, can adapt PowerShell resources, and runs only when invoked; it has no LCM service. Windows PowerShell DSC 1.1 ships with Windows PowerShell 5.1 and uses configuration scripts compiled to MOF for the LCM. PSDesiredStateConfiguration 2.x is separately installable for PowerShell 7. Do not assume documents, resources, scheduling, or security behavior transfer between these stacks.
$Standalone = if (Get-Command dsc -ErrorAction SilentlyContinue) { dsc --version } else { 'not installed' }
$Legacy = Get-Module -ListAvailable PSDesiredStateConfiguration |
Select-Object Name, Version, Path
[pscustomobject]@{ StandaloneDSC = $Standalone; PowerShellDSC = $Legacy } Discover resources and inspect their contracts
A resource name is not enough: pin or record its version, provider, schema, platform, and required privilege. DSC 3 discovers manifests on PATH and adapters may expose existing PowerShell resources. Capabilities show whether get, set, test, export, or other operations exist. Schema inspection prevents guessed property names and types. Resource installation changes the trusted code base and can introduce dependencies, so acquire modules or binaries through an approved repository and verify publisher provenance before production use.
dsc resource list
dsc resource schema --resource Microsoft.DSC.Debug/Echo
dsc resource get --resource Microsoft.DSC.Debug/Echo --input '{"text":"inventory"}' Get and test before enforcing
Use get to inventory actual state and test to compare it with desired state. Neither is a perfect preview of set: a flawed resource may have side effects, and test cannot predict every restart, lockout, or application consequence. Run under the same identity, architecture, environment, and resource versions intended for deployment. Capture structured output and exit status in the orchestration system, and treat validation errors or hadErrors as deployment failures rather than continuing blindly.
$Document = '.\server.dsc.yaml'
dsc config get --file $Document
if ($LASTEXITCODE -ne 0) { throw 'DSC get failed' }
dsc config test --file $Document
if ($LASTEXITCODE -ne 0) { throw 'DSC test failed' } Separate configuration from environment data
Parameter files let one reviewed document serve several environments without string substitution. Keep credentials and private keys out of configuration files, parameters, process arguments, logs, generated MOF, and source control; use a resource's supported secret-reference mechanism or the orchestrator's protected channel. DSC 3 validates before set and tests each resource, but set is still an operational mutation. Use a maintenance window, a canary, a backup, and a documented recovery path. DSC 3 has no general WhatIf mode.
dsc config --parameters-file .\prod.parameters.yaml test --file .\server.dsc.yaml
if ($LASTEXITCODE -ne 0) { throw 'Desired-state test failed' }
# Run the following only in an approved change window:
# dsc config --parameters-file .\prod.parameters.yaml set --file .\server.dsc.yaml Understand the Windows Local Configuration Manager
The LCM is the legacy Windows agent that receives MOF, applies configuration, and can monitor or auto-correct drift according to meta-configuration. Get-DscLocalConfigurationManager and Test-DscConfiguration require Windows PowerShell DSC support and commonly require elevation or delegated remoting rights. LCM modes such as ApplyAndAutoCorrect can repeatedly undo emergency changes, so coordinate break-glass procedures. Changing LCM settings can affect scheduled enforcement and may restart services depending on resources; inspect the generated meta-MOF before applying it.
$Lcm = Get-DscLocalConfigurationManager
$Lcm | Select-Object ConfigurationMode, RefreshMode, RebootNodeIfNeeded
Test-DscConfiguration -Path '.\Compiled' -Detailed Treat MOF compilation and application as separate trust steps
A PowerShell configuration block compiles a document; Start-DscConfiguration applies the resulting MOF. Compilation can execute PowerShell code, and MOF can expose sensitive values unless credential encryption is configured correctly with target certificates. Review both the source and compiled artifact. Applying normally requires elevation on the node or configured remoting authorization. A resource can request a reboot; RebootNodeIfNeeded controls LCM behavior, so never assume no restart merely because the command lacks a reboot switch.
Get-ChildItem -LiteralPath '.\Compiled' -Filter '*.mof' |
Select-Object Name, Length, LastWriteTime
# Approved elevated maintenance window only:
# Start-DscConfiguration -Path '.\Compiled' -Wait -Verbose
Get-DscConfigurationStatus -All | Select-Object -First 5 Validate syntax, idempotence, and blast radius
Parsing proves only PowerShell grammar. Compilation validates more of a legacy configuration, and test validates state, but none replaces staging. Run test, set, test again, then repeat set in a disposable environment to detect non-idempotent resources. Review which account executes, remote transport, file ACLs, required modules, supported Windows edition, and restart behavior. WhatIf support belongs to individual resource implementations, not to DSC as a universal transaction or rollback facility.
$Tokens = $null
$Errors = $null
[void][System.Management.Automation.Language.Parser]::ParseFile(
'.\Config.ps1', [ref]$Tokens, [ref]$Errors)
if ($Errors.Count) { $Errors | Format-List; throw 'Parse failed' } Operate DSC as privileged automation
Configuration engines frequently run with administrative or system authority. Restrict write access to documents, parameter files, resource packages, PATH directories, pull locations, certificates, and transcript or event data. Sign and version artifacts where policy requires it. Exported state can include hostnames, paths, and settings that are sensitive. DSC 3 has no background consistency agent, while legacy LCM does; schedule DSC 3 through an external orchestrator with locking and alerting, and monitor legacy LCM events plus configuration status for drift and failures.
Get-DscConfigurationStatus -All |
Select-Object Status, StartDate, Type, RebootRequested
Get-WinEvent -LogName 'Microsoft-Windows-DSC/Operational' -MaxEvents 50 |
Select-Object TimeCreated, Id, LevelDisplayName, Message Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- Microsoft LearnMicrosoft Desired State Configuration overviewlearn.microsoft.com
- Microsoft LearnGet started with DSClearn.microsoft.com
- Microsoft Learndsc config command referencelearn.microsoft.com
- Microsoft LearnPowerShell Desired State Configuration overviewlearn.microsoft.com
- Microsoft LearnGet-DscLocalConfigurationManagerlearn.microsoft.com
- Microsoft LearnStart-DscConfigurationlearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



