-
Notifications
You must be signed in to change notification settings - Fork 0
VSS
Volume Shadow Copy Service: listing, creating, removing shadow copies, restoring files, and managing shadow storage allocation.
6 function(s) in Public/vss/.
-
Get-ShadowCopy— List existing Volume Shadow Copies on local or remote Windows computers -
Get-ShadowCopyStorage— Show VSS storage allocation per volume on local or remote computers -
New-ShadowCopy— Create a VSS shadow copy on a specified volume -
Remove-ShadowCopy— Remove one or more VSS shadow copies from target computers -
Restore-ShadowCopyFile— Restore a file from a VSS shadow copy snapshot to a destination path -
Set-ShadowCopyStorage— Configure the maximum shadow copy storage size for a specified drive
List existing Volume Shadow Copies on local or remote Windows computers.
Retrieves all Volume Shadow Copy snapshots using Win32_ShadowCopy via CIM. Supports filtering by drive letter, remote execution via Invoke-RemoteOrLocal, and pipeline input for multiple computer names.
Syntax
Get-ShadowCopy [-ComputerName <string[]>] [-DriveLetter <string>]Examples
Get-ShadowCopyLists all shadow copies on the local computer.
Get-ShadowCopy -ComputerName 'SRV01' -DriveLetter 'C'Lists shadow copies for the C: drive on remote server SRV01.
'SRV01', 'SRV02' | Get-ShadowCopy -Credential (Get-Credential)Lists all shadow copies on SRV01 and SRV02 using alternate credentials.
Output: PSWinOps.ShadowCopy
Returns objects with ComputerName, ShadowCopyId, DriveLetter, VolumeName, CreationTime, DeviceObject, ProviderName, State, and Timestamp properties.
Show VSS storage allocation per volume on local or remote computers.
Retrieves Volume Shadow Copy storage allocation details using Win32_ShadowStorage via CIM. Reports used space, allocated space, maximum space, and snapshot count per volume. Supports filtering by drive letter and remote execution via Invoke-RemoteOrLocal.
Syntax
Get-ShadowCopyStorage [-ComputerName <string[]>] [-DriveLetter <string>]Examples
Get-ShadowCopyStorageShows VSS storage allocation for all volumes on the local computer.
Get-ShadowCopyStorage -ComputerName 'SRV01' -DriveLetter 'C'Shows VSS storage allocation for the C: drive on remote server SRV01.
'SRV01', 'SRV02' | Get-ShadowCopyStorage -Credential (Get-Credential)Shows VSS storage allocation on SRV01 and SRV02 using alternate credentials.
Output: PSWinOps.ShadowCopyStorage
Returns objects with ComputerName, DriveLetter, UsedSpaceBytes, UsedSpaceMB, AllocatedSpaceMB, MaxSpaceMB, UsedPercent, SnapshotCount, and Timestamp properties.
Create a VSS shadow copy on a specified volume.
Creates a Volume Shadow Copy Service (VSS) snapshot for the specified drive letter on one or more computers. Uses CIM methods to invoke Win32_ShadowCopy.Create and returns a structured result object with the shadow copy ID and status information.
Syntax
New-ShadowCopy -DriveLetter <string> [-ComputerName <string[]>]Examples
New-ShadowCopy -DriveLetter 'C'Creates a shadow copy of volume C: on the local computer.
New-ShadowCopy -DriveLetter 'D' -ComputerName 'SRV01'Creates a shadow copy of volume D: on the remote server SRV01.
'SRV01', 'SRV02' | New-ShadowCopy -DriveLetter 'C' -Credential (Get-Credential)Creates a shadow copy of volume C: on SRV01 and SRV02 using explicit credentials.
Output: PSWinOps.ShadowCopyResult
Returns one object per target computer with ComputerName, DriveLetter, ShadowCopyId, CreationTime, Success, ReturnCode, ReturnMessage and Timestamp.
Remove one or more VSS shadow copies from target computers.
Deletes Volume Shadow Copy Service snapshots either by their specific shadow copy ID or by drive letter with an optional age filter. Supports pipeline input from Get-ShadowCopy for streamlined bulk removal workflows.
Syntax
Remove-ShadowCopy -ShadowCopyId <string[]> -DriveLetter <string> [-OlderThanDays <int>] [-ComputerName <string[]>]Examples
Remove-ShadowCopy -ShadowCopyId '{AB12CD34-EF56-7890-AB12-CD34EF567890}'Removes a specific shadow copy by ID on the local computer.
Remove-ShadowCopy -DriveLetter 'C' -ComputerName 'SRV01'Removes all shadow copies for volume C: on the remote server SRV01.
Get-ShadowCopy -ComputerName 'SRV01' | Remove-ShadowCopyPipes shadow copy objects from Get-ShadowCopy to remove them.
Remove-ShadowCopy -DriveLetter 'D' -OlderThanDays 30 -ComputerName 'SRV01', 'SRV02'Removes shadow copies older than 30 days on volume D: across two remote servers.
Output: PSWinOps.ShadowCopyRemoveResult
Returns one object per shadow copy processed with ComputerName, ShadowCopyId, DriveLetter, Removed, ErrorMessage and Timestamp properties.
Restore a file from a VSS shadow copy snapshot to a destination path.
Restores a specific file from a Volume Shadow Copy snapshot identified by its ShadowCopyId. The SourcePath is relative to the drive root of the shadow copy volume. The function locates the shadow copy device object, constructs the full shadow path, and copies the file to the specified destination. Supports -Force to overwrite existing files.
Syntax
Restore-ShadowCopyFile -ShadowCopyId <string> -SourcePath <string> -DestinationPath <string> [-Force] [-ComputerName <string[]>]Examples
Restore-ShadowCopyFile -ShadowCopyId '{AB12CD34-EF56-7890-AB12-CD34EF567890}' -SourcePath 'Data\report.xlsx' -DestinationPath 'C:\Restore\report.xlsx'Restores report.xlsx from the specified shadow copy to C:\Restore on the local machine.
Restore-ShadowCopyFile -ShadowCopyId '{AB12CD34-EF56-7890-AB12-CD34EF567890}' -SourcePath 'Logs\app.log' -DestinationPath 'D:\Recovery\app.log' -Force -ComputerName 'SRV01'Restores app.log from a shadow copy on SRV01, overwriting any existing file.
Get-ShadowCopy -DriveLetter 'C' | Select-Object -First 1 | Restore-ShadowCopyFile -SourcePath 'Config\settings.json' -DestinationPath 'C:\Backup\settings.json'Restores settings.json using shadow copy information piped from Get-ShadowCopy.
Output: PSWinOps.ShadowCopyRestoreResult
Returns an object with ComputerName, ShadowCopyId, SourcePath, DestinationPath, Restored, SizeBytes, SizeMB, ErrorMessage, and Timestamp properties.
Configure the maximum shadow copy storage size for a specified drive.
Sets or modifies the maximum shadow copy (VSS) storage allocation for a given drive letter. Uses vssadmin resize shadowstorage which is more reliable than Set-CimInstance for modifying Win32_ShadowStorage. Supports both explicit size limits and unbounded storage.
Syntax
Set-ShadowCopyStorage -DriveLetter <string> -MaxSizeMB <long> -Unbounded [-ComputerName <string[]>]Examples
Set-ShadowCopyStorage -DriveLetter 'C' -MaxSizeMB 20480Sets the VSS max storage for drive C: to 20480 MB on the local machine.
Set-ShadowCopyStorage -DriveLetter 'D' -Unbounded -ComputerName 'SRV01'Sets the VSS storage for drive D: to unbounded on remote server SRV01.
'SRV01', 'SRV02' | Set-ShadowCopyStorage -DriveLetter 'C' -MaxSizeMB 10240Sets the VSS max storage for drive C: to 10240 MB on multiple remote servers.
Output: PSWinOps.ShadowCopyStorageResult
Returns an object with ComputerName, DriveLetter, PreviousMaxSpaceMB, NewMaxSpaceMB, Success, Message, and Timestamp properties.
Domains
- Active Directory (22)
- Certificate (1)
- Event Log (9)
- Health Check (16)
- IIS (9)
- Network (26)
- NTP (5)
- Proxy (4)
- RDP (6)
- Security (1)
- System (20)
- Utils (4)
- VSS (Shadow Copy) (6)
- Windows Update (10)