The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect DHCP role stateGet-WindowsFeature -Name DHCP,RSAT-DHCP | Select-Object Name, InstallStateView examples
Inspect DhcpServer moduleGet-Module -ListAvailable -Name DhcpServer | Select-Object Name, Version, PathView examples
List authorized serversGet-DhcpServerInDCView examples
Preview authorizationAdd-DhcpServerInDC -DnsName 'dhcp01.corp.example' ` -IPAddress '192.0.2.10' -WhatIfView examples
List IPv4 scopesGet-DhcpServerv4Scope -ComputerName ` 'dhcp01.corp.example'View examples
Inspect active leasesGet-DhcpServerv4Lease -ComputerName ` 'dhcp01.corp.example' -ScopeId '192.0.2.0' -AllLeasesView examples
Read scope statisticsGet-DhcpServerv4ScopeStatistics -ComputerName ` 'dhcp01.corp.example' -ScopeId '192.0.2.0'View examples
Preview an inactive scopeAdd-DhcpServerv4Scope -ComputerName 'dhcp01' -Name ` 'VLAN-120' -StartRange 192.0.2.50 -EndRange ` 192.0.2.199 -SubnetMask 255.255.255.0 -State InActive ` -WhatIfView examples
Preview an exclusionAdd-DhcpServerv4ExclusionRange -ComputerName 'dhcp01' ` -ScopeId '192.0.2.0' -StartRange '192.0.2.1' -EndRange ` '192.0.2.49' -WhatIfView examples
Inspect effective optionsGet-DhcpServerv4OptionValue -ComputerName ` 'dhcp01.corp.example' -ScopeId '192.0.2.0' -AllView examples
Preview common optionsSet-DhcpServerv4OptionValue -ComputerName 'dhcp01' ` -ScopeId '192.0.2.0' -Router '192.0.2.1' -DnsServer ` '192.0.2.20','192.0.2.21' -WhatIfView examples
Preview a reservationAdd-DhcpServerv4Reservation -ComputerName 'dhcp01' ` -ScopeId '192.0.2.0' -IPAddress '192.0.2.80' -ClientId ` '00-11-22-33-44-55' -WhatIfView examples
Inspect DNS update policyGet-DhcpServerv4DnsSetting -ComputerName ` 'dhcp01.corp.example' -ScopeId '192.0.2.0'View examples
Inspect failoverGet-DhcpServerv4Failover -ComputerName ` 'dhcp01.corp.example' -ScopeId '192.0.2.0'View examples
Preview load-balance failoverAdd-DhcpServerv4Failover -ComputerName 'dhcp01' -Name ` 'SITE-A' -PartnerServer 'dhcp02' -ScopeId 192.0.2.0 ` -SharedSecret '<approved-secret>' -WhatIfView examples
Preview failover replicationInvoke-DhcpServerv4FailoverReplication -ComputerName ` 'dhcp01.corp.example' -Name 'SITE-A' -WhatIfView examples
Preview DHCP exportExport-DhcpServer -ComputerName 'dhcp01.corp.example' ` -File 'C:\DHCP-Backup\dhcp01.xml' -Leases -WhatIfView examples
Read DHCP admin eventsGet-WinEvent -LogName ` 'Microsoft-Windows-DHCP Server Events/Admin' ` -MaxEvents 100View examples

Windows DHCP changes can immediately alter addressing, routing, DNS registration, and network availability for an entire subnet. These examples target Windows Server 2016 through Windows Server 2025 and Windows PowerShell 5.1 with the DhcpServer module installed by the DHCP Server role or RSAT. Use an elevated session and delegated DHCP or local administrative rights; domain authorization additionally requires suitable Active Directory permissions. Domain-joined DHCP servers must be authorized before leasing addresses. Remote administration requires connectivity and authentication to the named server. Role installation normally needs no restart, but verify RestartNeeded. Replace all example server names, documentation addresses, client IDs, scopes, relays, and secrets after approved IPAM and network review. WhatIf is only a cmdlet-level preview: it cannot detect duplicate addresses on the wire, validate relay paths, simulate client renewal, prove DNS ownership, or guarantee failover synchronization.

Step by step

Detailed examples

01

Confirm server role, module, elevation, and remote reachability

Use Windows PowerShell 5.1 on a supported Windows Server or an administrative workstation with RSAT DHCP tools. Read access can be delegated, while configuration ordinarily needs membership in DHCP Administrators or equivalent local/domain privileges and an elevated session. ComputerName and CimSession operations require network reachability, authentication, and management firewall rules. The DHCP server should use a stable address, and clients on other subnets need correctly configured relay paths. Install-WindowsFeature DHCP -IncludeManagementTools normally reports that no restart is required, but inspect its RestartNeeded result rather than assuming. Installation and post-install configuration are intentionally outside these examples.

Read-only readiness check
$target = 'dhcp01.corp.example'
Get-WindowsFeature -ComputerName $target -Name DHCP,RSAT-DHCP |
  Select-Object Name, InstallState
Get-Module -ListAvailable -Name DhcpServer |
  Select-Object Name, Version, Path
Test-NetConnection -ComputerName $target -Port 135
Back to quick reference ↑
02

Separate Active Directory authorization from service installation

A DHCP service on a domain-joined computer must be authorized in Active Directory before it leases addresses. Authorization writes an AD object and triggers the service to recheck authorization; it therefore needs appropriate directory rights in addition to local DHCP rights. Match both FQDN and static address to the intended server, inspect the existing list first, and allow AD replication. Workgroup DHCP deployments do not use AD authorization. Add-DhcpServerInDC supports WhatIf, but a preview cannot prove directory replication, service contact, network uniqueness, or that a rogue non-Windows DHCP server is absent.

Audit and preview domain authorization
$dnsName = 'dhcp01.corp.example'
$address = '192.0.2.10'
Get-DhcpServerInDC | Sort-Object DnsName
Resolve-DnsName -Name $dnsName -Type A -DnsOnly
Add-DhcpServerInDC -DnsName $dnsName -IPAddress $address -WhatIf
Back to quick reference ↑
03

Inventory scopes, leases, reservations, and utilization together

Scope state alone does not show exhaustion or conflicts. Compare the configured range, exclusions, reservations, lease states, and utilization, and reconcile them with authoritative IPAM and subnet/VLAN data. AllLeases includes more than active leases and is useful for diagnosis. ScopeId is the network identifier, not the first assignable address. Read from the intended server explicitly; in failover, compare both partners because their lease databases are independent but synchronized.

Read-only scope health snapshot
$server = 'dhcp01.corp.example'
$scope = '192.0.2.0'
Get-DhcpServerv4Scope -ComputerName $server -ScopeId $scope | Format-List *
Get-DhcpServerv4ScopeStatistics -ComputerName $server -ScopeId $scope
Get-DhcpServerv4ExclusionRange -ComputerName $server -ScopeId $scope
Get-DhcpServerv4Reservation -ComputerName $server -ScopeId $scope
Get-DhcpServerv4Lease -ComputerName $server -ScopeId $scope -AllLeases |
  Group-Object AddressState
Back to quick reference ↑
04

Create scopes inactive and validate the entire address plan

An active scope can begin answering clients as soon as relay and network paths permit. Create it inactive, then verify network ID, mask, range, exclusions, gateway, DNS servers, lease duration, relay targets, existing static assignments, and overlap with every other scope. Use documentation subnet values here only as placeholders. WhatIf previews the DHCP database operation but cannot ARP-probe for duplicate addresses, query switches or IPAM, test a relay, or model client renewals. Activating a scope normally needs no service restart; perform activation as a separately approved change.

Preview an inactive scope and infrastructure exclusion
$server = 'dhcp01.corp.example'
$scope = '192.0.2.0'
Add-DhcpServerv4Scope -ComputerName $server -Name 'VLAN-120' `
  -StartRange '192.0.2.50' -EndRange '192.0.2.199' `
  -SubnetMask '255.255.255.0' -LeaseDuration 1.00:00:00 -State InActive -WhatIf
Add-DhcpServerv4ExclusionRange -ComputerName $server -ScopeId $scope `
  -StartRange '192.0.2.1' -EndRange '192.0.2.49' -WhatIf
Back to quick reference ↑
05

Apply options at the narrowest intended level and validate client identifiers

DHCP options can be defined at server, scope, reservation, policy, vendor-class, or user-class levels; the effective client result depends on precedence. Explicitly include ScopeId for scope settings. A reservation is exclusive to its ClientId, which Windows clients commonly derive from the MAC address, but other devices can use different identifiers. Confirm the identifier from an observed lease and ensure the address lies within the scope without colliding with another reservation or static host. WhatIf does not calculate every client's effective option set or verify the gateway and DNS addresses.

Inspect, then preview scope options and a reservation
$server = 'dhcp01.corp.example'
$scope = '192.0.2.0'
Get-DhcpServerv4OptionValue -ComputerName $server -ScopeId $scope -All
Set-DhcpServerv4OptionValue -ComputerName $server -ScopeId $scope `
  -Router '192.0.2.1' -DnsServer '192.0.2.20','192.0.2.21' `
  -DnsDomain 'corp.example' -WhatIf
Add-DhcpServerv4Reservation -ComputerName $server -ScopeId $scope `
  -IPAddress '192.0.2.80' -ClientId '00-11-22-33-44-55' `
  -Name 'printer01' -Description 'Asset CM-0000' -WhatIf
Back to quick reference ↑
06

Coordinate DHCP dynamic DNS updates and record ownership

DHCP can update A and PTR records for clients and optionally discard records when leases are deleted. Inspect server, scope, and policy settings before changing behavior. In a failover pair, both partners must use the same dedicated DNS update credentials; otherwise one partner may not own and therefore cannot update records created by the other. Avoid highly privileged credentials and coordinate DNS aging intervals with DHCP lease and update behavior. A WhatIf preview of a DHCP setting cannot validate DNS ACLs, credential rights, reverse-zone presence, scavenging, or record ownership.

Audit scope DNS policy and credential presence
$server = 'dhcp01.corp.example'
$scope = '192.0.2.0'
Get-DhcpServerv4DnsSetting -ComputerName $server -ScopeId $scope | Format-List *
Get-DhcpServerDnsCredential -ComputerName $server |
  Select-Object UserName, DomainName
Get-DhcpServerv4OptionValue -ComputerName $server -ScopeId $scope `
  -OptionId 6,15
Back to quick reference ↑
07

Operate DHCPv4 failover from a declared source of truth

Windows DHCP failover supports IPv4 scopes only and one relationship is always between two servers; a server supports up to 31 relationships. Both partners must reach each other on TCP 647, have synchronized time, and be reachable by clients directly or through relays. Supplying SharedSecret enables message-digest authentication; retrieve the string through an approved secret workflow and keep it out of source control, transcripts, and command history. Creation copies the selected scopes to the partner. Later configuration changes are not automatically replicated: Invoke-DhcpServerv4FailoverReplication overwrites partner scope settings from the server where replication starts, so identify the authoritative source first. Lease synchronization and configuration replication are distinct. WhatIf cannot simulate partner loss, detect all split-brain risk, validate a shared secret, or guarantee client continuity.

Audit partners before previewing a relationship
$primary = 'dhcp01.corp.example'
$partner = 'dhcp02.corp.example'
$scope = '192.0.2.0'
$sharedSecret = '<retrieve-from-approved-secret-store>'
Get-DhcpServerv4Failover -ComputerName $primary
Test-NetConnection -ComputerName $partner -Port 647
Get-Date
Add-DhcpServerv4Failover -ComputerName $primary -Name 'SITE-A' `
  -PartnerServer $partner -ScopeId $scope -LoadBalancePercent 50 `
  -MaxClientLeadTime 01:00:00 -AutoStateTransition $true `
  -StateSwitchInterval 01:00:00 -SharedSecret $sharedSecret -WhatIf
Remove-Variable sharedSecret
Preview one-way configuration replication
$source = 'dhcp01.corp.example'
Get-DhcpServerv4Failover -ComputerName $source -Name 'SITE-A' | Format-List *
Invoke-DhcpServerv4FailoverReplication -ComputerName $source -Name 'SITE-A' -WhatIf
Back to quick reference ↑
08

Export configuration and leases before risky changes, then monitor

Export-DhcpServer can include configuration and leases; its File path is interpreted on the target DHCP server, so pre-create and protect the directory there. An XML export is valuable migration and recovery input but is not a substitute for tested server, Active Directory, IPAM, relay, credential, and change documentation. Import can overwrite or merge consequential state and must be rehearsed separately. WhatIf previews supported export or import intent but does not create a restorable artifact. Verify the file, protect it as sensitive operational data, document restore order, and correlate DHCP Admin, Operational, and audit logs plus failover counters.

Preview export and collect a health snapshot
$server = 'dhcp01.corp.example'
Export-DhcpServer -ComputerName $server `
  -File 'C:\DHCP-Backup\dhcp01.xml' -Leases -WhatIf
Get-Service -ComputerName $server -Name DHCPServer
Get-WinEvent -ComputerName $server `
  -LogName 'Microsoft-Windows-DHCP Server Events/Admin' -MaxEvents 100
Get-DhcpServerv4ScopeStatistics -ComputerName $server
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftDhcpServer PowerShell modulelearn.microsoft.com
  2. MicrosoftInstall and configure DHCP Server on Windows Serverlearn.microsoft.com
  3. MicrosoftAdd-DhcpServerv4Scopelearn.microsoft.com
  4. MicrosoftSet-DhcpServerv4OptionValuelearn.microsoft.com
  5. MicrosoftDHCP failover overviewlearn.microsoft.com
  6. MicrosoftManage DHCP failover relationshipslearn.microsoft.com
  7. MicrosoftExport-DhcpServerlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback