The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect DHCP role state | Get-WindowsFeature -Name DHCP,RSAT-DHCP |
Select-Object Name, InstallState | View examples |
| Inspect DhcpServer module | Get-Module -ListAvailable -Name DhcpServer |
Select-Object Name, Version, Path | View examples |
| List authorized servers | Get-DhcpServerInDC | View examples |
| Preview authorization | Add-DhcpServerInDC -DnsName 'dhcp01.corp.example' `
-IPAddress '192.0.2.10' -WhatIf | View examples |
| List IPv4 scopes | Get-DhcpServerv4Scope -ComputerName `
'dhcp01.corp.example' | View examples |
| Inspect active leases | Get-DhcpServerv4Lease -ComputerName `
'dhcp01.corp.example' -ScopeId '192.0.2.0' -AllLeases | View examples |
| Read scope statistics | Get-DhcpServerv4ScopeStatistics -ComputerName `
'dhcp01.corp.example' -ScopeId '192.0.2.0' | View examples |
| Preview an inactive scope | Add-DhcpServerv4Scope -ComputerName 'dhcp01' -Name `
'VLAN-120' -StartRange 192.0.2.50 -EndRange `
192.0.2.199 -SubnetMask 255.255.255.0 -State InActive `
-WhatIf | View examples |
| Preview an exclusion | Add-DhcpServerv4ExclusionRange -ComputerName 'dhcp01' `
-ScopeId '192.0.2.0' -StartRange '192.0.2.1' -EndRange `
'192.0.2.49' -WhatIf | View examples |
| Inspect effective options | Get-DhcpServerv4OptionValue -ComputerName `
'dhcp01.corp.example' -ScopeId '192.0.2.0' -All | View examples |
| Preview common options | Set-DhcpServerv4OptionValue -ComputerName 'dhcp01' `
-ScopeId '192.0.2.0' -Router '192.0.2.1' -DnsServer `
'192.0.2.20','192.0.2.21' -WhatIf | View examples |
| Preview a reservation | Add-DhcpServerv4Reservation -ComputerName 'dhcp01' `
-ScopeId '192.0.2.0' -IPAddress '192.0.2.80' -ClientId `
'00-11-22-33-44-55' -WhatIf | View examples |
| Inspect DNS update policy | Get-DhcpServerv4DnsSetting -ComputerName `
'dhcp01.corp.example' -ScopeId '192.0.2.0' | View examples |
| Inspect failover | Get-DhcpServerv4Failover -ComputerName `
'dhcp01.corp.example' -ScopeId '192.0.2.0' | View examples |
| Preview load-balance failover | Add-DhcpServerv4Failover -ComputerName 'dhcp01' -Name `
'SITE-A' -PartnerServer 'dhcp02' -ScopeId 192.0.2.0 `
-SharedSecret '<approved-secret>' -WhatIf | View examples |
| Preview failover replication | Invoke-DhcpServerv4FailoverReplication -ComputerName `
'dhcp01.corp.example' -Name 'SITE-A' -WhatIf | View examples |
| Preview DHCP export | Export-DhcpServer -ComputerName 'dhcp01.corp.example' `
-File 'C:\DHCP-Backup\dhcp01.xml' -Leases -WhatIf | View examples |
| Read DHCP admin events | Get-WinEvent -LogName `
'Microsoft-Windows-DHCP Server Events/Admin' `
-MaxEvents 100 | View examples |
Windows DHCP changes can immediately alter addressing, routing, DNS registration, and network availability for an entire subnet. These examples target Windows Server 2016 through Windows Server 2025 and Windows PowerShell 5.1 with the DhcpServer module installed by the DHCP Server role or RSAT. Use an elevated session and delegated DHCP or local administrative rights; domain authorization additionally requires suitable Active Directory permissions. Domain-joined DHCP servers must be authorized before leasing addresses. Remote administration requires connectivity and authentication to the named server. Role installation normally needs no restart, but verify RestartNeeded. Replace all example server names, documentation addresses, client IDs, scopes, relays, and secrets after approved IPAM and network review. WhatIf is only a cmdlet-level preview: it cannot detect duplicate addresses on the wire, validate relay paths, simulate client renewal, prove DNS ownership, or guarantee failover synchronization.
Step by step
Detailed examples
Confirm server role, module, elevation, and remote reachability
Use Windows PowerShell 5.1 on a supported Windows Server or an administrative workstation with RSAT DHCP tools. Read access can be delegated, while configuration ordinarily needs membership in DHCP Administrators or equivalent local/domain privileges and an elevated session. ComputerName and CimSession operations require network reachability, authentication, and management firewall rules. The DHCP server should use a stable address, and clients on other subnets need correctly configured relay paths. Install-WindowsFeature DHCP -IncludeManagementTools normally reports that no restart is required, but inspect its RestartNeeded result rather than assuming. Installation and post-install configuration are intentionally outside these examples.
$target = 'dhcp01.corp.example'
Get-WindowsFeature -ComputerName $target -Name DHCP,RSAT-DHCP |
Select-Object Name, InstallState
Get-Module -ListAvailable -Name DhcpServer |
Select-Object Name, Version, Path
Test-NetConnection -ComputerName $target -Port 135 Separate Active Directory authorization from service installation
A DHCP service on a domain-joined computer must be authorized in Active Directory before it leases addresses. Authorization writes an AD object and triggers the service to recheck authorization; it therefore needs appropriate directory rights in addition to local DHCP rights. Match both FQDN and static address to the intended server, inspect the existing list first, and allow AD replication. Workgroup DHCP deployments do not use AD authorization. Add-DhcpServerInDC supports WhatIf, but a preview cannot prove directory replication, service contact, network uniqueness, or that a rogue non-Windows DHCP server is absent.
$dnsName = 'dhcp01.corp.example'
$address = '192.0.2.10'
Get-DhcpServerInDC | Sort-Object DnsName
Resolve-DnsName -Name $dnsName -Type A -DnsOnly
Add-DhcpServerInDC -DnsName $dnsName -IPAddress $address -WhatIf Inventory scopes, leases, reservations, and utilization together
Scope state alone does not show exhaustion or conflicts. Compare the configured range, exclusions, reservations, lease states, and utilization, and reconcile them with authoritative IPAM and subnet/VLAN data. AllLeases includes more than active leases and is useful for diagnosis. ScopeId is the network identifier, not the first assignable address. Read from the intended server explicitly; in failover, compare both partners because their lease databases are independent but synchronized.
$server = 'dhcp01.corp.example'
$scope = '192.0.2.0'
Get-DhcpServerv4Scope -ComputerName $server -ScopeId $scope | Format-List *
Get-DhcpServerv4ScopeStatistics -ComputerName $server -ScopeId $scope
Get-DhcpServerv4ExclusionRange -ComputerName $server -ScopeId $scope
Get-DhcpServerv4Reservation -ComputerName $server -ScopeId $scope
Get-DhcpServerv4Lease -ComputerName $server -ScopeId $scope -AllLeases |
Group-Object AddressState Create scopes inactive and validate the entire address plan
An active scope can begin answering clients as soon as relay and network paths permit. Create it inactive, then verify network ID, mask, range, exclusions, gateway, DNS servers, lease duration, relay targets, existing static assignments, and overlap with every other scope. Use documentation subnet values here only as placeholders. WhatIf previews the DHCP database operation but cannot ARP-probe for duplicate addresses, query switches or IPAM, test a relay, or model client renewals. Activating a scope normally needs no service restart; perform activation as a separately approved change.
$server = 'dhcp01.corp.example'
$scope = '192.0.2.0'
Add-DhcpServerv4Scope -ComputerName $server -Name 'VLAN-120' `
-StartRange '192.0.2.50' -EndRange '192.0.2.199' `
-SubnetMask '255.255.255.0' -LeaseDuration 1.00:00:00 -State InActive -WhatIf
Add-DhcpServerv4ExclusionRange -ComputerName $server -ScopeId $scope `
-StartRange '192.0.2.1' -EndRange '192.0.2.49' -WhatIf Apply options at the narrowest intended level and validate client identifiers
DHCP options can be defined at server, scope, reservation, policy, vendor-class, or user-class levels; the effective client result depends on precedence. Explicitly include ScopeId for scope settings. A reservation is exclusive to its ClientId, which Windows clients commonly derive from the MAC address, but other devices can use different identifiers. Confirm the identifier from an observed lease and ensure the address lies within the scope without colliding with another reservation or static host. WhatIf does not calculate every client's effective option set or verify the gateway and DNS addresses.
$server = 'dhcp01.corp.example'
$scope = '192.0.2.0'
Get-DhcpServerv4OptionValue -ComputerName $server -ScopeId $scope -All
Set-DhcpServerv4OptionValue -ComputerName $server -ScopeId $scope `
-Router '192.0.2.1' -DnsServer '192.0.2.20','192.0.2.21' `
-DnsDomain 'corp.example' -WhatIf
Add-DhcpServerv4Reservation -ComputerName $server -ScopeId $scope `
-IPAddress '192.0.2.80' -ClientId '00-11-22-33-44-55' `
-Name 'printer01' -Description 'Asset CM-0000' -WhatIf Coordinate DHCP dynamic DNS updates and record ownership
DHCP can update A and PTR records for clients and optionally discard records when leases are deleted. Inspect server, scope, and policy settings before changing behavior. In a failover pair, both partners must use the same dedicated DNS update credentials; otherwise one partner may not own and therefore cannot update records created by the other. Avoid highly privileged credentials and coordinate DNS aging intervals with DHCP lease and update behavior. A WhatIf preview of a DHCP setting cannot validate DNS ACLs, credential rights, reverse-zone presence, scavenging, or record ownership.
$server = 'dhcp01.corp.example'
$scope = '192.0.2.0'
Get-DhcpServerv4DnsSetting -ComputerName $server -ScopeId $scope | Format-List *
Get-DhcpServerDnsCredential -ComputerName $server |
Select-Object UserName, DomainName
Get-DhcpServerv4OptionValue -ComputerName $server -ScopeId $scope `
-OptionId 6,15 Operate DHCPv4 failover from a declared source of truth
Windows DHCP failover supports IPv4 scopes only and one relationship is always between two servers; a server supports up to 31 relationships. Both partners must reach each other on TCP 647, have synchronized time, and be reachable by clients directly or through relays. Supplying SharedSecret enables message-digest authentication; retrieve the string through an approved secret workflow and keep it out of source control, transcripts, and command history. Creation copies the selected scopes to the partner. Later configuration changes are not automatically replicated: Invoke-DhcpServerv4FailoverReplication overwrites partner scope settings from the server where replication starts, so identify the authoritative source first. Lease synchronization and configuration replication are distinct. WhatIf cannot simulate partner loss, detect all split-brain risk, validate a shared secret, or guarantee client continuity.
$primary = 'dhcp01.corp.example'
$partner = 'dhcp02.corp.example'
$scope = '192.0.2.0'
$sharedSecret = '<retrieve-from-approved-secret-store>'
Get-DhcpServerv4Failover -ComputerName $primary
Test-NetConnection -ComputerName $partner -Port 647
Get-Date
Add-DhcpServerv4Failover -ComputerName $primary -Name 'SITE-A' `
-PartnerServer $partner -ScopeId $scope -LoadBalancePercent 50 `
-MaxClientLeadTime 01:00:00 -AutoStateTransition $true `
-StateSwitchInterval 01:00:00 -SharedSecret $sharedSecret -WhatIf
Remove-Variable sharedSecret $source = 'dhcp01.corp.example'
Get-DhcpServerv4Failover -ComputerName $source -Name 'SITE-A' | Format-List *
Invoke-DhcpServerv4FailoverReplication -ComputerName $source -Name 'SITE-A' -WhatIf Export configuration and leases before risky changes, then monitor
Export-DhcpServer can include configuration and leases; its File path is interpreted on the target DHCP server, so pre-create and protect the directory there. An XML export is valuable migration and recovery input but is not a substitute for tested server, Active Directory, IPAM, relay, credential, and change documentation. Import can overwrite or merge consequential state and must be rehearsed separately. WhatIf previews supported export or import intent but does not create a restorable artifact. Verify the file, protect it as sensitive operational data, document restore order, and correlate DHCP Admin, Operational, and audit logs plus failover counters.
$server = 'dhcp01.corp.example'
Export-DhcpServer -ComputerName $server `
-File 'C:\DHCP-Backup\dhcp01.xml' -Leases -WhatIf
Get-Service -ComputerName $server -Name DHCPServer
Get-WinEvent -ComputerName $server `
-LogName 'Microsoft-Windows-DHCP Server Events/Admin' -MaxEvents 100
Get-DhcpServerv4ScopeStatistics -ComputerName $server Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- MicrosoftDhcpServer PowerShell modulelearn.microsoft.com
- MicrosoftInstall and configure DHCP Server on Windows Serverlearn.microsoft.com
- MicrosoftAdd-DhcpServerv4Scopelearn.microsoft.com
- MicrosoftSet-DhcpServerv4OptionValuelearn.microsoft.com
- MicrosoftDHCP failover overviewlearn.microsoft.com
- MicrosoftManage DHCP failover relationshipslearn.microsoft.com
- MicrosoftExport-DhcpServerlearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



