The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
List registry drivesGet-PSDrive -PSProvider RegistryView examples
Use a full hive pathGet-Item -LiteralPath ` 'Registry::HKEY_CURRENT_USER\Software'View examples
List immediate subkeysGet-ChildItem -LiteralPath 'HKCU:\Software'View examples
Find descendant keysGet-ChildItem -LiteralPath 'HKCU:\Software\Acme' ` -RecurseView examples
Test a key pathTest-Path -LiteralPath 'HKCU:\Software\Acme'View examples
Inspect a key objectGet-Item -LiteralPath 'HKCU:\Software\Acme'View examples
Read key valuesGet-ItemProperty -LiteralPath 'HKCU:\Software\Acme'View examples
Read one raw valueGet-ItemPropertyValue -LiteralPath 'HKCU:\Software\Acme' ` -Name 'Theme'View examples
Preview key creationNew-Item -Path 'HKCU:\Software\Acme' -WhatIfView examples
Preview a string valueNew-ItemProperty -LiteralPath 'HKCU:\Software\Acme' ` -Name 'Theme' -Value 'Dark' -PropertyType String ` -WhatIfView examples
Preview a DWORD valueNew-ItemProperty -LiteralPath 'HKCU:\Software\Acme' ` -Name 'PageSize' -Value 25 -PropertyType DWord -WhatIfView examples
Preview changing a valueSet-ItemProperty -LiteralPath 'HKCU:\Software\Acme' ` -Name 'Theme' -Value 'Light' -WhatIfView examples
Preview renaming a valueRename-ItemProperty -LiteralPath 'HKCU:\Software\Acme' ` -Name 'Theme' -NewName 'ColorTheme' -WhatIfView examples
Preview clearing dataClear-ItemProperty -LiteralPath 'HKCU:\Software\Acme' ` -Name 'Theme' -WhatIfView examples
Preview removing a valueRemove-ItemProperty -LiteralPath 'HKCU:\Software\Acme' ` -Name 'Theme' -WhatIfView examples
Preview removing a keyRemove-Item -LiteralPath 'HKCU:\Software\Acme' -Recurse ` -WhatIfView examples
Export a key treereg.exe export 'HKCU\Software\Acme' '.\Acme-backup.reg' ` /yView examples
Capture selected stateGet-ItemProperty -LiteralPath 'HKCU:\Software\Acme' | Select-Object Theme, PageSizeView examples

PowerShell exposes registry keys as provider items and registry values as item properties. Read exact paths first, work under HKCU when machine-wide state is unnecessary, preserve value kinds, preview mutations with WhatIf, and record recoverable state before consequential changes.

Step by step

Detailed examples

01

Treat keys as items and values as properties

HKLM: maps HKEY_LOCAL_MACHINE and HKCU: maps HKEY_CURRENT_USER. Registry keys form the provider hierarchy; named registry values are properties on those items, not child items. Provider-qualified Registry:: paths expose full hive names and work even when a convenient drive is not mapped. These commands apply only on Windows.

Inspect mapped hives and one full key
Get-PSDrive -PSProvider Registry
Get-Item -LiteralPath 'Registry::HKEY_CURRENT_USER\Software' |
    Select-Object Name, SubKeyCount, ValueCount
Output
# Registry drives normally include HKCU and HKLM.
# The key object reports its full name and counts.
Back to quick reference ↑
02

Discover exact keys before changing them

Get-ChildItem returns subkeys, while -Recurse can be expensive and may encounter inaccessible keys. LiteralPath prevents wildcard interpretation in names containing bracket characters. Test-Path is useful for branching but state can change afterward, so operations must still handle provider errors.

Find matching current-user product keys
$root = 'HKCU:\Software'
Get-ChildItem -LiteralPath $root |
    Where-Object Name -Like '*Acme*' |
    Select-Object Name, SubKeyCount, ValueCount
Test-Path -LiteralPath 'HKCU:\Software\Acme'
Output
# Output depends on the current user's registry hive.
Back to quick reference ↑
03

Read structured values without parsing display text

Get-Item returns the key; Get-ItemProperty returns a PSCustomObject containing its values plus provider metadata. Get-ItemPropertyValue returns one value's raw .NET representation. A value can exist with empty data, so distinguish a missing property from a present empty value through error handling.

Read selected application settings
$path = 'HKCU:\Software\Acme'
if (Test-Path -LiteralPath $path) {
    Get-ItemProperty -LiteralPath $path | Select-Object Theme, PageSize
    Get-ItemPropertyValue -LiteralPath $path -Name 'Theme'
}
Output
# Existing value data is returned as PowerShell objects.
Back to quick reference ↑
04

Create keys and typed values explicitly

New-Item creates a key; New-ItemProperty creates a value on it. PropertyType maps to kinds such as String, ExpandString, Binary, DWord, MultiString, and QWord. Choose the kind expected by the consumer and avoid Force unless replacement is intended. Start with WhatIf, then remove it only after reviewing the exact HKCU or HKLM target.

Preview a per-user key and values
$path = 'HKCU:\Software\Acme'
New-Item -Path $path -WhatIf
New-ItemProperty -LiteralPath $path -Name 'Theme' -Value 'Dark' -PropertyType String -WhatIf
New-ItemProperty -LiteralPath $path -Name 'PageSize' -Value 25 -PropertyType DWord -WhatIf
Output
What if: Performing the operation ...
# No registry state changes while WhatIf is present.
Back to quick reference ↑
05

Preserve semantics when changing data or names

Set-ItemProperty changes data and normally preserves the value kind. Rename-ItemProperty changes the value name, which can immediately break consumers expecting the old name. Capture current data and type first, preview the operation, and coordinate application restarts or policy refresh only when their documentation requires it.

Capture and preview a settings change
$path = 'HKCU:\Software\Acme'
$current = Get-ItemProperty -LiteralPath $path -Name 'Theme' -ErrorAction Stop
$current | Select-Object Theme
Set-ItemProperty -LiteralPath $path -Name 'Theme' -Value 'Light' -WhatIf
Rename-ItemProperty -LiteralPath $path -Name 'Theme' -NewName 'ColorTheme' -WhatIf
Output
# Current data is shown, followed by WhatIf previews.
Back to quick reference ↑
06

Distinguish clearing data from deleting values or keys

Clear-ItemProperty retains the value but resets its data; Remove-ItemProperty deletes it. Remove-Item targets a key and -Recurse includes descendants, making exact path review essential. Prefer WhatIf and a recoverable export, and never apply a recursive command to a path assembled from unchecked input.

Preview three different removal scopes
$path = 'HKCU:\Software\Acme'
Clear-ItemProperty -LiteralPath $path -Name 'Theme' -WhatIf
Remove-ItemProperty -LiteralPath $path -Name 'Theme' -WhatIf
Remove-Item -LiteralPath $path -Recurse -WhatIf
Output
# Each command reports its proposed target without changing it.
Back to quick reference ↑
07

Export recoverable state and verify afterward

reg.exe export creates a textual .reg backup of a key tree, but it may contain sensitive configuration and is not a system backup. Check the native exit code immediately and protect the file. After an authorized change, read exact values again and compare their data and kinds with the intended result.

Export and check the native command result
$backup = Join-Path $PWD 'Acme-backup.reg'
reg.exe export 'HKCU\Software\Acme' $backup /y
$exitCode = $LASTEXITCODE
if ($exitCode -ne 0) { throw "Registry export failed with exit code $exitCode" }
Get-Item -LiteralPath $backup | Select-Object FullName, Length
Output
# A successful export creates the backup and returns native exit code 0.
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft Learnabout_Registry_Providerlearn.microsoft.com
  2. Microsoft LearnGet-ItemPropertylearn.microsoft.com
  3. Microsoft LearnNew-ItemPropertylearn.microsoft.com
  4. Microsoft LearnSet-ItemPropertylearn.microsoft.com
  5. Microsoft LearnRemove-ItemPropertylearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback