The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Test WSManTest-WSMan -ComputerName 'server01'View examples
Run one commandInvoke-Command -ComputerName 'server01' -ScriptBlock { ` Get-Date }View examples
Pass argumentsInvoke-Command -ComputerName 'server01' -ScriptBlock { ` param($name) Get-Service -Name $name } -ArgumentList ` 'Spooler'View examples
Fan out to hostsInvoke-Command -ComputerName 'server01','server02' ` -ScriptBlock { hostname }View examples
Create a persistent session$session = New-PSSession -ComputerName 'server01'View examples
Enter interactivelyEnter-PSSession -Session $sessionView examples
Close a sessionRemove-PSSession -Session $sessionView examples
Prompt for credentials$credential = Get-CredentialView examples
Connect over SSHNew-PSSession -HostName 'server01' -UserName 'deploy' ` -SSHTransportView examples
Copy into a sessionCopy-Item -LiteralPath '.\config.json' -Destination ` 'C:\Temp\config.json' -ToSession $sessionView examples
Stop on remote non-terminating errorsInvoke-Command -Session $session -ScriptBlock { Get-Item ` C:\missing -ErrorAction Stop }View examples
List endpointsGet-PSSessionConfigurationView examples

PowerShell remoting executes commands under a remote security context and serializes most returned objects. Confirm transport, authentication, endpoint, and authorization before execution; avoid broad TrustedHosts exceptions; use reusable sessions intentionally; and remove them when their work is complete.

Step by step

Detailed examples

01

Separate network reachability from remoting authorization

Test-WSMan confirms a WSMan listener response but not that a particular identity can enter an endpoint. Domain Kerberos is preferred for Windows-to-Windows authentication where available. HTTPS or SSH provides transport alternatives; TrustedHosts weakens mutual identity assurance and is not a blanket fix.

Resolve and test the endpoint
Resolve-DnsName -Name 'server01'
Test-NetConnection -ComputerName 'server01' -Port 5985
Test-WSMan -ComputerName 'server01'
Back to quick reference ↑
02

Pass data explicitly into remote scope

A remote script block does not share the caller's local scope. Use parameters and ArgumentList or the using scope for simple captured values. Avoid constructing remote code strings from untrusted input. Returned objects are generally deserialized snapshots without live instance methods.

Query one named service on two hosts
$serviceName = 'Spooler'
Invoke-Command -ComputerName 'server01','server02' -ScriptBlock {
  param($name)
  Get-Service -Name $name | Select-Object MachineName, Name, Status
} -ArgumentList $serviceName
Back to quick reference ↑
03

Use persistent sessions for stateful sequences

New-PSSession creates a remote runspace whose variables and imported modules persist between calls. Sessions consume local and remote resources and can disconnect according to configuration. Name, inspect, and remove sessions rather than leaving anonymous runspaces behind.

Reuse and clean up a session
$session = New-PSSession -ComputerName 'server01' -Name 'Audit'
try {
  Invoke-Command -Session $session -ScriptBlock { $env:COMPUTERNAME; Get-Date }
} finally {
  Remove-PSSession -Session $session
}
Back to quick reference ↑
04

Choose transport and credentials from the trust model

Get-Credential avoids plaintext literals but credentials still require protection. Kerberos delegation, NTLM, certificate endpoints, and SSH keys have different identity and second-hop behavior. Do not enable CredSSP solely to bypass a second-hop problem without accepting its credential exposure model.

SSH transport with explicit identity
$session = New-PSSession -HostName 'server01' -UserName 'deploy' -SSHTransport
try { Invoke-Command -Session $session -ScriptBlock { $PSVersionTable.PSVersion } }
finally { Remove-PSSession $session }
Back to quick reference ↑
05

Plan for serialization and file transfer

Remoting serializes most objects into property snapshots, so type methods may not survive. Perform method-dependent work remotely and return simple data. Copy-Item ToSession and FromSession use an existing authenticated channel; validate destination paths and hashes for deployment artifacts.

Copy and verify through one session
$session = New-PSSession -ComputerName 'server01'
try {
  Copy-Item -LiteralPath '.\config.json' -Destination 'C:\Temp\config.json' -ToSession $session
  Invoke-Command -Session $session -ScriptBlock { Get-FileHash -LiteralPath 'C:\Temp\config.json' }
} finally { Remove-PSSession $session }
Back to quick reference ↑
06

Preserve remote error context

Transport errors, authorization failures, and command errors are distinct. Set ErrorAction Stop for operations that must be caught and inspect FullyQualifiedErrorId, PSComputerName, and remote streams. Use endpoint and event-log inspection before changing firewall or authentication policy.

Catch a remote command failure
try {
  Invoke-Command -ComputerName 'server01' -ScriptBlock {
    Get-Item -LiteralPath 'C:\missing' -ErrorAction Stop
  } -ErrorAction Stop
} catch {
  $_ | Format-List FullyQualifiedErrorId, CategoryInfo, PSComputerName, Exception
}
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoftabout_Remotelearn.microsoft.com
  2. MicrosoftInvoke-Commandlearn.microsoft.com
  3. MicrosoftNew-PSSessionlearn.microsoft.com
  4. MicrosoftPowerShell Remoting over SSHlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback