Skip to content
Franck SALLET edited this page Sep 5, 2026 · 1 revision

VSS (Shadow Copy)

Volume Shadow Copy Service: listing, creating, removing shadow copies, restoring files, and managing shadow storage allocation.

6 function(s) in Public/vss/.

Functions

Reference

Get-ShadowCopy

List existing Volume Shadow Copies on local or remote Windows computers.

Retrieves all Volume Shadow Copy snapshots using Win32_ShadowCopy via CIM. Supports filtering by drive letter, remote execution via Invoke-RemoteOrLocal, and pipeline input for multiple computer names.

Syntax

Get-ShadowCopy [-ComputerName <string[]>] [-DriveLetter <string>]

Examples

Get-ShadowCopy

Lists all shadow copies on the local computer.

Get-ShadowCopy -ComputerName 'SRV01' -DriveLetter 'C'

Lists shadow copies for the C: drive on remote server SRV01.

'SRV01', 'SRV02' | Get-ShadowCopy -Credential (Get-Credential)

Lists all shadow copies on SRV01 and SRV02 using alternate credentials.

Output: PSWinOps.ShadowCopy

Returns objects with ComputerName, ShadowCopyId, DriveLetter, VolumeName, CreationTime, DeviceObject, ProviderName, State, and Timestamp properties.


Get-ShadowCopyStorage

Show VSS storage allocation per volume on local or remote computers.

Retrieves Volume Shadow Copy storage allocation details using Win32_ShadowStorage via CIM. Reports used space, allocated space, maximum space, and snapshot count per volume. Supports filtering by drive letter and remote execution via Invoke-RemoteOrLocal.

Syntax

Get-ShadowCopyStorage [-ComputerName <string[]>] [-DriveLetter <string>]

Examples

Get-ShadowCopyStorage

Shows VSS storage allocation for all volumes on the local computer.

Get-ShadowCopyStorage -ComputerName 'SRV01' -DriveLetter 'C'

Shows VSS storage allocation for the C: drive on remote server SRV01.

'SRV01', 'SRV02' | Get-ShadowCopyStorage -Credential (Get-Credential)

Shows VSS storage allocation on SRV01 and SRV02 using alternate credentials.

Output: PSWinOps.ShadowCopyStorage

Returns objects with ComputerName, DriveLetter, UsedSpaceBytes, UsedSpaceMB, AllocatedSpaceMB, MaxSpaceMB, UsedPercent, SnapshotCount, and Timestamp properties.


New-ShadowCopy

Create a VSS shadow copy on a specified volume.

Creates a Volume Shadow Copy Service (VSS) snapshot for the specified drive letter on one or more computers. Uses CIM methods to invoke Win32_ShadowCopy.Create and returns a structured result object with the shadow copy ID and status information.

Syntax

New-ShadowCopy -DriveLetter <string> [-ComputerName <string[]>]

Examples

New-ShadowCopy -DriveLetter 'C'

Creates a shadow copy of volume C: on the local computer.

New-ShadowCopy -DriveLetter 'D' -ComputerName 'SRV01'

Creates a shadow copy of volume D: on the remote server SRV01.

'SRV01', 'SRV02' | New-ShadowCopy -DriveLetter 'C' -Credential (Get-Credential)

Creates a shadow copy of volume C: on SRV01 and SRV02 using explicit credentials.

Output: PSWinOps.ShadowCopyResult

Returns one object per target computer with ComputerName, DriveLetter, ShadowCopyId, CreationTime, Success, ReturnCode, ReturnMessage and Timestamp.


Remove-ShadowCopy

Remove one or more VSS shadow copies from target computers.

Deletes Volume Shadow Copy Service snapshots either by their specific shadow copy ID or by drive letter with an optional age filter. Supports pipeline input from Get-ShadowCopy for streamlined bulk removal workflows.

Syntax

Remove-ShadowCopy -ShadowCopyId <string[]> -DriveLetter <string> [-OlderThanDays <int>] [-ComputerName <string[]>]

Examples

Remove-ShadowCopy -ShadowCopyId '{AB12CD34-EF56-7890-AB12-CD34EF567890}'

Removes a specific shadow copy by ID on the local computer.

Remove-ShadowCopy -DriveLetter 'C' -ComputerName 'SRV01'

Removes all shadow copies for volume C: on the remote server SRV01.

Get-ShadowCopy -ComputerName 'SRV01' | Remove-ShadowCopy

Pipes shadow copy objects from Get-ShadowCopy to remove them.

Remove-ShadowCopy -DriveLetter 'D' -OlderThanDays 30 -ComputerName 'SRV01', 'SRV02'

Removes shadow copies older than 30 days on volume D: across two remote servers.

Output: PSWinOps.ShadowCopyRemoveResult

Returns one object per shadow copy processed with ComputerName, ShadowCopyId, DriveLetter, Removed, ErrorMessage and Timestamp properties.


Restore-ShadowCopyFile

Restore a file from a VSS shadow copy snapshot to a destination path.

Restores a specific file from a Volume Shadow Copy snapshot identified by its ShadowCopyId. The SourcePath is relative to the drive root of the shadow copy volume. The function locates the shadow copy device object, constructs the full shadow path, and copies the file to the specified destination. Supports -Force to overwrite existing files.

Syntax

Restore-ShadowCopyFile -ShadowCopyId <string> -SourcePath <string> -DestinationPath <string> [-Force] [-ComputerName <string[]>]

Examples

Restore-ShadowCopyFile -ShadowCopyId '{AB12CD34-EF56-7890-AB12-CD34EF567890}' -SourcePath 'Data\report.xlsx' -DestinationPath 'C:\Restore\report.xlsx'

Restores report.xlsx from the specified shadow copy to C:\Restore on the local machine.

Restore-ShadowCopyFile -ShadowCopyId '{AB12CD34-EF56-7890-AB12-CD34EF567890}' -SourcePath 'Logs\app.log' -DestinationPath 'D:\Recovery\app.log' -Force -ComputerName 'SRV01'

Restores app.log from a shadow copy on SRV01, overwriting any existing file.

Get-ShadowCopy -DriveLetter 'C' | Select-Object -First 1 | Restore-ShadowCopyFile -SourcePath 'Config\settings.json' -DestinationPath 'C:\Backup\settings.json'

Restores settings.json using shadow copy information piped from Get-ShadowCopy.

Output: PSWinOps.ShadowCopyRestoreResult

Returns an object with ComputerName, ShadowCopyId, SourcePath, DestinationPath, Restored, SizeBytes, SizeMB, ErrorMessage, and Timestamp properties.


Set-ShadowCopyStorage

Configure the maximum shadow copy storage size for a specified drive.

Sets or modifies the maximum shadow copy (VSS) storage allocation for a given drive letter. Uses vssadmin resize shadowstorage which is more reliable than Set-CimInstance for modifying Win32_ShadowStorage. Supports both explicit size limits and unbounded storage.

Syntax

Set-ShadowCopyStorage -DriveLetter <string> -MaxSizeMB <long> -Unbounded [-ComputerName <string[]>]

Examples

Set-ShadowCopyStorage -DriveLetter 'C' -MaxSizeMB 20480

Sets the VSS max storage for drive C: to 20480 MB on the local machine.

Set-ShadowCopyStorage -DriveLetter 'D' -Unbounded -ComputerName 'SRV01'

Sets the VSS storage for drive D: to unbounded on remote server SRV01.

'SRV01', 'SRV02' | Set-ShadowCopyStorage -DriveLetter 'C' -MaxSizeMB 10240

Sets the VSS max storage for drive C: to 10240 MB on multiple remote servers.

Output: PSWinOps.ShadowCopyStorageResult

Returns an object with ComputerName, DriveLetter, PreviousMaxSpaceMB, NewMaxSpaceMB, Success, Message, and Timestamp properties.


PSWinOps Wiki

Home

Domains

Clone this wiki locally