The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect backup feature | Get-WindowsFeature Windows-Server-Backup | View examples |
| Read backup summary | Get-WBSummary | View examples |
| Inspect active job | Get-WBJob | View examples |
| Create editable policy | $Policy = New-WBPolicy | View examples |
| Add source volume | Add-WBVolume -Policy $Policy -Volume (Get-WBVolume `
-VolumePath 'D:') | View examples |
| Add file selection | Add-WBFileSpec -Policy $Policy -FileSpec (New-WBFileSpec `
-FileSpec 'D:\Data') | View examples |
| Include system state | Add-WBSystemState -Policy $Policy | View examples |
| Include bare-metal recovery | Add-WBBareMetalRecovery -Policy $Policy | View examples |
| Select backup target | $Target = New-WBBackupTarget -VolumePath 'E:' | View examples |
| Select network target | $Target = New-WBBackupTarget -NetworkPath `
'\backup01\wsb$' | View examples |
| Set policy schedule | Set-WBSchedule -Policy $Policy -Schedule 03:00 | View examples |
| Commit scheduled policy | Set-WBPolicy -Policy $Policy -WhatIf | View examples |
| Run one-time policy | Start-WBBackup -Policy $Policy -Async | View examples |
| List recoverable sets | Get-WBBackupSet -BackupTarget $Target | View examples |
| Mount backup for browsing | Get-WBBackupVolumeBrowsePath -BackupSet $BackupSet `
-VolumeInBackup $Volume | View examples |
| List wbadmin versions | wbadmin.exe get versions -backupTarget:E: | View examples |
| Inspect backup ACL | Get-Acl 'E:\WindowsImageBackup' | Format-List | View examples |
A backup is useful only when its scope, consistency, retention, isolation, and restore path are proven. Windows Server Backup supports volume, file, system state, bare-metal, and some application-aware scenarios through wbadmin and the WindowsServerBackup module. Build policies in memory, inspect them before committing, keep at least one independently protected copy, monitor every job, and rehearse restores on isolated systems. Backup targets, schedules, and recovery operations can overwrite or expose data.
Step by step
Detailed examples
Define recovery objectives and supported workload scope
Windows Server Backup is an installable feature and most operations require elevation plus Administrators, Backup Operators, or delegated rights. Define recovery point and recovery time objectives, required file, volume, system state, bare-metal, Hyper-V, and application recovery, encryption needs, retention, and offsite isolation. Confirm application VSS writer support; crash-consistent volume snapshots are not automatically application-consistent. Feature installation can request a restart depending on servicing state.
Get-WindowsFeature Windows-Server-Backup
Get-Volume | Select-Object DriveLetter, FileSystemLabel, FileSystem, HealthStatus, SizeRemaining
vssadmin.exe list writers
Get-CimInstance Win32_OperatingSystem | Select-Object Caption, Version, LastBootUpTime Monitor jobs and history as production signals
Get-WBSummary and Get-WBJob expose local status, but successful command submission is not proof of a valid restore point. Alert on missed schedules, warnings, VSS writer failures, target capacity, duration changes, and stale versions. Forward Microsoft-Windows-Backup events to protected monitoring. Async jobs require polling to a terminal state and checking error details; never start overlapping policies or assume a background job completed because the launching session exited.
Get-WBSummary | Format-List *
Get-WBJob | Format-List *
Get-WinEvent -LogName 'Microsoft-Windows-Backup' -MaxEvents 100 |
Select-Object TimeCreated, Id, LevelDisplayName, Message Build and inspect an in-memory policy
New-WBPolicy is safe until passed to Set-WBPolicy or Start-WBBackup. Add only reviewed volumes and file specifications, and verify exclusions do not remove dependencies. A volume containing backup storage should not also be a source. PowerShell object construction has no universal WhatIf because it does not itself write backup configuration; the risk begins when a policy is committed or executed. Keep policy-building scripts versioned and display the final source set for approval.
$Policy = New-WBPolicy
$DataVolume = Get-WBVolume -VolumePath 'D:'
Add-WBVolume -Policy $Policy -Volume $DataVolume
$FileSpec = New-WBFileSpec -FileSpec 'D:\Data'
Add-WBFileSpec -Policy $Policy -FileSpec $FileSpec
$Policy | Format-List * Include system state and bare-metal data deliberately
System state contents vary by installed roles and can include AD DS, registry, boot files, SYSVOL, certificates, and other protected components. Bare-metal recovery adds critical volumes needed to restore the whole system through Windows Recovery Environment. These options increase time and storage and may require matching recovery media, drivers, firmware mode, and hardware planning. Domain controller recovery has authoritative and non-authoritative semantics that require an AD-specific runbook.
$Policy = New-WBPolicy
Add-WBSystemState -Policy $Policy
Add-WBBareMetalRecovery -Policy $Policy
Get-WBSystemState -Policy $Policy
Get-WBBareMetalRecovery -Policy $Policy
$Policy | Format-List * Isolate targets and understand retention behavior
Dedicated disks and volumes provide versioned backups but may be reformatted, hidden, or reserved when assigned. A remote share typically retains only the latest backup for a machine/location and exposes backup traffic and credentials to network risk; use unique per-server paths and least-privilege ACLs. Confirm target capacity and filesystem support. Offline, immutable, or independently authenticated copies protect against ransomware and administrator compromise better than an always-mounted local disk.
Get-WBDisk | Select-Object DiskName, DiskNumber, TotalSpace, FreeSpace
Get-WBBackupTarget -Policy (Get-WBPolicy -Editable -ErrorAction SilentlyContinue)
Test-Path '\backup01\wsb$'
# New-WBBackupTarget creates an object; committing a disk target can change storage use. Commit and run only in an approved window
Set-WBPolicy persists the schedule and target selection; use WhatIf and Confirm where supported, then review the exact target. Start-WBBackup begins real VSS snapshots and I/O and does not offer a dry-run equivalent. The -Async switch returns before completion. For application workloads, choose VSS copy or full semantics so you do not interfere with another backup product's log handling. Schedule around maintenance, replication, antivirus, and storage contention.
Set-WBSchedule -Policy $Policy -Schedule 03:00
Set-WBPolicy -Policy $Policy -WhatIf
# Approved window only:
# Set-WBPolicy -Policy $Policy -Confirm
# Start-WBBackup -Policy $Policy -Async
Get-WBPolicy | Format-List * Rehearse restore without overwriting production
Enumerate backup sets and items before choosing a version. Mounting a backup for browsing is lower risk than restoring in place, but exposes protected data and requires cleanup. File, volume, application, system state, and bare-metal restores have different commands and overwrite risks. Restore to an alternate isolated location first when possible, validate ACLs and application consistency, malware-scan recovered content, measure timing, and record dependencies. Some system recovery operations run only in Windows Recovery Environment and require restart or downtime.
$Target = New-WBBackupTarget -VolumePath 'E:'
$Sets = Get-WBBackupSet -BackupTarget $Target
$Sets | Select-Object VersionId, BackupTime, BackupTarget
wbadmin.exe get versions -backupTarget:E:
# Do not invoke Start-WBFileRecovery or system recovery without a reviewed restore target. Protect backup data, credentials, and catalog integrity
Windows Server Backup data can contain every server secret and should be treated as highly privileged. Encrypt transport and storage through the surrounding platform when required, restrict Backup Operators, separate target credentials, audit reads and restores, and prevent ordinary server administrators from deleting all copies. A backup catalog is useful but not a substitute for the backup media; destructive wbadmin delete catalog and system-state deletion commands require separate approval. Test catalog-loss and alternate-host recovery procedures.
Get-Acl 'E:\WindowsImageBackup' -ErrorAction SilentlyContinue | Format-List
Get-ChildItem 'E:\WindowsImageBackup' -Force -ErrorAction SilentlyContinue |
Select-Object Name, LastWriteTime, Attributes
Get-WinEvent -LogName 'Microsoft-Windows-Backup' -MaxEvents 50 |
Group-Object Id | Sort-Object Count -Descending Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- Microsoft LearnWindowsServerBackup modulelearn.microsoft.com
- Microsoft LearnWindows Server Backup command referencelearn.microsoft.com
- Microsoft Learnwbadmin start backuplearn.microsoft.com
- Microsoft LearnGet-WBBackupSetlearn.microsoft.com
- Microsoft LearnStart-WBBackuplearn.microsoft.com
- Microsoft LearnWindows recovery environmentlearn.microsoft.com
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



