Skip to content
Franck SALLET edited this page Sep 5, 2026 · 2 revisions

PSWinOps

PSWinOps is a PowerShell module of utilities for Windows system administrators, published to the PowerShell Gallery.

This wiki documents the 14 function domains that make up the module: 139 public functions in total, one file per function under Public/<domain>/. Each domain page lists its functions with synopsis, syntax, and usage examples extracted directly from the in-module comment-based help.

Domains

Domain Description Functions
Active Directory User, group, and computer account management, auditing, replication, and site topology for AD DS. 22
Certificate Discovery of certificates nearing expiration across local certificate stores. 1
Event Log Mining the Windows Event Log for actionable signals (logon failures, crashes, Schannel errors, etc.). 9
Health Check Role-specific health checks (AD DC, ADFS, CA, Cluster, DFS, DHCP, DNS, Exchange, File Server, Hyper-V, IIS, Print Server, RDS, WSUS, generic services). 16
IIS Internet Information Services diagnostics: worker processes, app pools, logs, failed request tracing, certificate bindings. 9
Network Local network configuration, connectivity testing, routing, ARP, DNS, SSL, diagnostics. 26
NTP Windows Time service configuration, peer status, sync status, and resync actions. 5
Proxy WinHTTP/WinINET proxy configuration read, set, remove, and connectivity test. 4
RDP Remote Desktop session enumeration, history, lock state, and session actions. 6
Security Local/domain audit policy inspection. 1
System General Windows system administration (disk, software, drivers, services, tasks, reboot). 20
Utils Standalone utilities: passwords, string/encoding conversions, Markdown conversion. 4
VSS (Shadow Copy) Volume Shadow Copy Service: list, create, remove, restore, manage storage. 6
Windows Update Windows Update inspection and control, history, cache cleanup, component reset. 10

Total: 139 public functions across 14 domains.

Module particularities

  • Windows-only, PowerShell 5.1+ or 7+. The module loader (PSWinOps.psm1) hard-fails if loaded on non-Windows PowerShell Core. It dot-sources every script under Private/ then Public/, and registers live Active Directory argument completers for Identity parameters.
  • No noun prefix. Functions use plain singular nouns (Get-NTPConfiguration, not Get-PSWinOpsNTPConfiguration).
  • Standard output shape. Nearly every public function returns a [PSCustomObject] with, at minimum, ComputerName ($env:COMPUTERNAME for local targets) and Timestamp (ISO 8601, Get-Date -Format 'o'), plus domain-specific fields. Two categories are exempt from this shape: pure utilities (New-RandomPassword, ConvertFrom-MisencodedString, ConvertTo-Markdown, Remove-StringDiacritic) which return plain values, and interactive monitors (Show-PingMonitor, Show-NetworkStatisticMonitor, Show-SystemMonitor) which render to the console and return nothing structured.
  • Remote computer support. Most functions accept a pipeline-able -ComputerName array (defaulting to the local computer) and iterate per machine, so that a failure on one target does not stop the others — errors are written per machine via Write-Error and processing continues.
  • CIM, not WMI. Every CIM-based function uses Get-CimInstance/Invoke-CimMethod, never the legacy Get-WmiObject/Invoke-WmiMethod.
  • Session enumeration via quser.exe. RDP/session functions parse quser.exe output rather than querying Win32_LogonSession, which can carry stale or duplicate entries. Session output always includes a SessionId for pipeline chaining.
  • NTP via w32tm.exe. NTP functions read configuration and status through w32tm.exe /query rather than parsing the registry directly.
  • Optional/lazy dependencies. Role-specific modules (ActiveDirectory, WebAdministration/IISAdministration, Hyper-V, FailoverClusters, DhcpServer, DnsServer, FileServerResourceManager, Exchange tools, RemoteDesktop, UpdateServices, ADFS, PrintManagement, DFSN) are not listed in RequiredModules and are imported on demand, so the module stays loadable on hosts that only need a subset of functionality. Health-check functions in particular require the corresponding role/module to be present. See the project readme.md for the full install matrix.
  • State-changing functions support -WhatIf/-Confirm. Any function that writes to the registry, AD, services, or the filesystem implements SupportsShouldProcess.
  • Typed, formatted output. Every typed result carries a PSTypeName (see below) and a matching <View> in PSWinOps.Format.ps1xml, so Format-Table/Format-List render sensible default columns without any extra work from the caller.

About PSTypeName

Every structured object returned by PSWinOps carries a PSTypeName of the form PSWinOps.<ObjectType> (e.g. PSWinOps.ADUserInventory, PSWinOps.NtpSyncResult, PSWinOps.ActiveRdpSession). This is set directly in the function's [PSCustomObject] construction:

[PSCustomObject]@{
    PSTypeName   = 'PSWinOps.ActiveRdpSession'
    ComputerName = $computer
    SessionId    = $sessionId
    # ...
}

Why this matters as a consumer of the module:

  • Consistent, self-describing output. $result.PSObject.TypeNames[0] tells you exactly what kind of result you're holding, independent of which function produced it — useful when aggregating output from several functions in a pipeline or a report.
  • Automatic formatting. PSWinOps.Format.ps1xml defines a <TableControl> or <ListControl> view keyed on each PSTypeName, so Get-ADUserInventory and similar functions display readable default columns instead of a raw property dump — no manual Format-Table -Property ... required.
  • Safe Is-style checks. You can gate logic on type, e.g. $obj.PSObject.TypeNames -contains 'PSWinOps.WindowsUpdateFailure', instead of duck-typing on property names.
  • Discoverability. Because the type name mirrors the function name (Get-NTPPeer → PSWinOps.NtpPeer), it's predictable which function produced a given object even after it has been passed through several pipeline stages.

Two small, documented exception groups exist:

  • Pure utility functions (New-RandomPassword, ConvertFrom-MisencodedString, ConvertTo-Markdown, Remove-StringDiacritic) return a plain string — no PSTypeName, no ComputerName/Timestamp, since there is no "machine" the result is about.
  • RDP session action functions (Connect-RdpSession, Disconnect-RdpSession, Remove-RdpSession) all share one result type, PSWinOps.RdpSessionAction, rather than a distinct type per verb, since they return the same shape of success/failure result.
  • Interactive monitors (Show-PingMonitor, Show-NetworkStatisticMonitor, Show-SystemMonitor) render live to the console and return nothing, so no PSTypeName applies.

Getting started

Install-Module -Name PSWinOps -Scope CurrentUser
Import-Module PSWinOps

# Discover functions in a domain
Get-Command -Module PSWinOps -Noun 'AD*'

# Full help for any function
Get-Help Get-ADUserInventory -Full

PSWinOps Wiki

Home

Domains

Clone this wiki locally