The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect backup featureGet-WindowsFeature Windows-Server-BackupView examples
Read backup summaryGet-WBSummaryView examples
Inspect active jobGet-WBJobView examples
Create editable policy$Policy = New-WBPolicyView examples
Add source volumeAdd-WBVolume -Policy $Policy -Volume (Get-WBVolume ` -VolumePath 'D:')View examples
Add file selectionAdd-WBFileSpec -Policy $Policy -FileSpec (New-WBFileSpec ` -FileSpec 'D:\Data')View examples
Include system stateAdd-WBSystemState -Policy $PolicyView examples
Include bare-metal recoveryAdd-WBBareMetalRecovery -Policy $PolicyView examples
Select backup target$Target = New-WBBackupTarget -VolumePath 'E:'View examples
Select network target$Target = New-WBBackupTarget -NetworkPath ` '\backup01\wsb$'View examples
Set policy scheduleSet-WBSchedule -Policy $Policy -Schedule 03:00View examples
Commit scheduled policySet-WBPolicy -Policy $Policy -WhatIfView examples
Run one-time policyStart-WBBackup -Policy $Policy -AsyncView examples
List recoverable setsGet-WBBackupSet -BackupTarget $TargetView examples
Mount backup for browsingGet-WBBackupVolumeBrowsePath -BackupSet $BackupSet ` -VolumeInBackup $VolumeView examples
List wbadmin versionswbadmin.exe get versions -backupTarget:E:View examples
Inspect backup ACLGet-Acl 'E:\WindowsImageBackup' | Format-ListView examples

A backup is useful only when its scope, consistency, retention, isolation, and restore path are proven. Windows Server Backup supports volume, file, system state, bare-metal, and some application-aware scenarios through wbadmin and the WindowsServerBackup module. Build policies in memory, inspect them before committing, keep at least one independently protected copy, monitor every job, and rehearse restores on isolated systems. Backup targets, schedules, and recovery operations can overwrite or expose data.

Step by step

Detailed examples

01

Define recovery objectives and supported workload scope

Windows Server Backup is an installable feature and most operations require elevation plus Administrators, Backup Operators, or delegated rights. Define recovery point and recovery time objectives, required file, volume, system state, bare-metal, Hyper-V, and application recovery, encryption needs, retention, and offsite isolation. Confirm application VSS writer support; crash-consistent volume snapshots are not automatically application-consistent. Feature installation can request a restart depending on servicing state.

Inventory feature, volumes, and VSS writers
Get-WindowsFeature Windows-Server-Backup
Get-Volume | Select-Object DriveLetter, FileSystemLabel, FileSystem, HealthStatus, SizeRemaining
vssadmin.exe list writers
Get-CimInstance Win32_OperatingSystem | Select-Object Caption, Version, LastBootUpTime
Back to quick reference ↑
02

Monitor jobs and history as production signals

Get-WBSummary and Get-WBJob expose local status, but successful command submission is not proof of a valid restore point. Alert on missed schedules, warnings, VSS writer failures, target capacity, duration changes, and stale versions. Forward Microsoft-Windows-Backup events to protected monitoring. Async jobs require polling to a terminal state and checking error details; never start overlapping policies or assume a background job completed because the launching session exited.

Collect backup health without starting work
Get-WBSummary | Format-List *
Get-WBJob | Format-List *
Get-WinEvent -LogName 'Microsoft-Windows-Backup' -MaxEvents 100 |
    Select-Object TimeCreated, Id, LevelDisplayName, Message
Back to quick reference ↑
03

Build and inspect an in-memory policy

New-WBPolicy is safe until passed to Set-WBPolicy or Start-WBBackup. Add only reviewed volumes and file specifications, and verify exclusions do not remove dependencies. A volume containing backup storage should not also be a source. PowerShell object construction has no universal WhatIf because it does not itself write backup configuration; the risk begins when a policy is committed or executed. Keep policy-building scripts versioned and display the final source set for approval.

Construct a policy without applying it
$Policy = New-WBPolicy
$DataVolume = Get-WBVolume -VolumePath 'D:'
Add-WBVolume -Policy $Policy -Volume $DataVolume
$FileSpec = New-WBFileSpec -FileSpec 'D:\Data'
Add-WBFileSpec -Policy $Policy -FileSpec $FileSpec
$Policy | Format-List *
Back to quick reference ↑
04

Include system state and bare-metal data deliberately

System state contents vary by installed roles and can include AD DS, registry, boot files, SYSVOL, certificates, and other protected components. Bare-metal recovery adds critical volumes needed to restore the whole system through Windows Recovery Environment. These options increase time and storage and may require matching recovery media, drivers, firmware mode, and hardware planning. Domain controller recovery has authoritative and non-authoritative semantics that require an AD-specific runbook.

Review recovery additions before execution
$Policy = New-WBPolicy
Add-WBSystemState -Policy $Policy
Add-WBBareMetalRecovery -Policy $Policy
Get-WBSystemState -Policy $Policy
Get-WBBareMetalRecovery -Policy $Policy
$Policy | Format-List *
Back to quick reference ↑
05

Isolate targets and understand retention behavior

Dedicated disks and volumes provide versioned backups but may be reformatted, hidden, or reserved when assigned. A remote share typically retains only the latest backup for a machine/location and exposes backup traffic and credentials to network risk; use unique per-server paths and least-privilege ACLs. Confirm target capacity and filesystem support. Offline, immutable, or independently authenticated copies protect against ransomware and administrator compromise better than an always-mounted local disk.

Inventory candidate targets before selecting one
Get-WBDisk | Select-Object DiskName, DiskNumber, TotalSpace, FreeSpace
Get-WBBackupTarget -Policy (Get-WBPolicy -Editable -ErrorAction SilentlyContinue)
Test-Path '\backup01\wsb$'
# New-WBBackupTarget creates an object; committing a disk target can change storage use.
Back to quick reference ↑
06

Commit and run only in an approved window

Set-WBPolicy persists the schedule and target selection; use WhatIf and Confirm where supported, then review the exact target. Start-WBBackup begins real VSS snapshots and I/O and does not offer a dry-run equivalent. The -Async switch returns before completion. For application workloads, choose VSS copy or full semantics so you do not interfere with another backup product's log handling. Schedule around maintenance, replication, antivirus, and storage contention.

Preview policy commit and leave execution commented
Set-WBSchedule -Policy $Policy -Schedule 03:00
Set-WBPolicy -Policy $Policy -WhatIf
# Approved window only:
# Set-WBPolicy -Policy $Policy -Confirm
# Start-WBBackup -Policy $Policy -Async
Get-WBPolicy | Format-List *
Back to quick reference ↑
07

Rehearse restore without overwriting production

Enumerate backup sets and items before choosing a version. Mounting a backup for browsing is lower risk than restoring in place, but exposes protected data and requires cleanup. File, volume, application, system state, and bare-metal restores have different commands and overwrite risks. Restore to an alternate isolated location first when possible, validate ACLs and application consistency, malware-scan recovered content, measure timing, and record dependencies. Some system recovery operations run only in Windows Recovery Environment and require restart or downtime.

Inventory versions before a recovery decision
$Target = New-WBBackupTarget -VolumePath 'E:'
$Sets = Get-WBBackupSet -BackupTarget $Target
$Sets | Select-Object VersionId, BackupTime, BackupTarget
wbadmin.exe get versions -backupTarget:E:
# Do not invoke Start-WBFileRecovery or system recovery without a reviewed restore target.
Back to quick reference ↑
08

Protect backup data, credentials, and catalog integrity

Windows Server Backup data can contain every server secret and should be treated as highly privileged. Encrypt transport and storage through the surrounding platform when required, restrict Backup Operators, separate target credentials, audit reads and restores, and prevent ordinary server administrators from deleting all copies. A backup catalog is useful but not a substitute for the backup media; destructive wbadmin delete catalog and system-state deletion commands require separate approval. Test catalog-loss and alternate-host recovery procedures.

Collect integrity and access evidence
Get-Acl 'E:\WindowsImageBackup' -ErrorAction SilentlyContinue | Format-List
Get-ChildItem 'E:\WindowsImageBackup' -Force -ErrorAction SilentlyContinue |
    Select-Object Name, LastWriteTime, Attributes
Get-WinEvent -LogName 'Microsoft-Windows-Backup' -MaxEvents 50 |
    Group-Object Id | Sort-Object Count -Descending
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnWindowsServerBackup modulelearn.microsoft.com
  2. Microsoft LearnWindows Server Backup command referencelearn.microsoft.com
  3. Microsoft Learnwbadmin start backuplearn.microsoft.com
  4. Microsoft LearnGet-WBBackupSetlearn.microsoft.com
  5. Microsoft LearnStart-WBBackuplearn.microsoft.com
  6. Microsoft LearnWindows recovery environmentlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback