Skip to main content
AD Academy
DHCP and Network Preparation
Intermediate15 minLast updated: Topic 3 of 5

Managing DHCP with PowerShell

Installation, Authorization, Scopes, Options, backup and monitoring.

Not read

What you will learn here

  • Installation and Authorization
  • Creating a Scope and setting Options
  • Dynamic DNS and Credentials

Worth reading first:Rogue DHCP and Network Threats

The DhcpServer module lets you set up and manage a full DHCP server from the terminal. The commands below are arranged in the natural workflow order — from installation to monitoring.

Installation and Authorization

# Install DHCP Role
Install-WindowsFeature DHCP -IncludeManagementTools

# Authorize the server in Active Directory
Add-DhcpServerInDC -DnsName "dhcp01.lab.local" -IPAddress 192.168.10.5

# Display all authorized servers
Get-DhcpServerInDC
powershell

Creating a Scope and setting Options

# Create Scope for Office Network
Add-DhcpServerv4Scope -Name "Office-LAN" `
  -StartRange 192.168.10.100 -EndRange 192.168.10.200 `
  -SubnetMask 255.255.255.0 -State Active

# Exclude addresses for servers and network equipment
Add-DhcpServerv4ExclusionRange -ScopeId 192.168.10.0 `
  -StartRange 192.168.10.100 -EndRange 192.168.10.110

# Gateway, DNS and Domain name
Set-DhcpServerv4OptionValue -ScopeId 192.168.10.0 `
  -Router 192.168.10.1 -DnsServer 192.168.10.10 -DnsDomain "lab.local"

# Static reservation for printer by MAC
Add-DhcpServerv4Reservation -ScopeId 192.168.10.0 `
  -IPAddress 192.168.10.150 -ClientId "00-15-5D-01-02-03" -Name "Printer-01"
powershell

Dynamic DNS and Credentials

# Automatic DNS update for all clients
Set-DhcpServerv4DnsSetting -ScopeId 192.168.10.0 `
  -DynamicUpdates Always -DeleteDnsRROnLeaseExpiry $true

# Dedicated service account for DNS updates (not Domain Admin!)
Set-DhcpServerDnsCredential -Credential (Get-Credential) -ComputerName "dhcp01.lab.local"
powershell

Monitoring, backup and troubleshooting

# Scope Utilization
Get-DhcpServerv4ScopeStatistics

# All Active Leases
Get-DhcpServerv4Lease -ScopeId 192.168.10.0

# Server Configuration Backup and Restore
Backup-DhcpServer -Path "C:\Backup\DHCP"
Restore-DhcpServer -Path "C:\Backup\DHCP"

# From the client side — address renewal
ipconfig /release; ipconfig /renew; ipconfig /registerdns
powershell
Architecture and Theory — Under the Hood

PowerShell's DhcpServer module covers 100% of the functionality — from Install-WindowsFeature to exporting/importing the entire database. Recommended for Multi-Server management and DR.

Practical Configuration (PowerShell / GUI)
# Installation and Authorization
Install-WindowsFeature DHCP -IncludeManagementTools
Add-DhcpServerInDC
Add-DhcpServerSecurityGroup
Set-ItemProperty HKLM:\SOFTWARE\Microsoft\ServerManager\Roles\12 -Name ConfigurationState -Value 2

# Scope Creation
Add-DhcpServerv4Scope -Name 'HQ-Users' -StartRange 10.0.10.50 -EndRange 10.0.10.250 \
  -SubnetMask 255.255.255.0 -LeaseDuration 08:00:00
Set-DhcpServerv4OptionValue -ScopeId 10.0.10.0 -Router 10.0.10.1 -DnsServer 10.0.0.10 -DnsDomain corp.local

# Reservation
Add-DhcpServerv4Reservation -ScopeId 10.0.10.0 -IPAddress 10.0.10.60 \
  -ClientId 'AA-BB-CC-11-22-33' -Description 'Printer-HR'

# Backup / Restore
Backup-DhcpServer -Path C:\Backup\DHCP
Export-DhcpServer -File C:\Backup\dhcp.xml -Leases
powershell
Real-world Scenarios in an Organization
  • Onboarding a new branch: one script sets up Scope + Options + Failover + Reservations.
  • Migration from an old server: Export-DhcpServer on Server 2012 → Import on Server 2022.
  • Monitoring: Scheduled Task that runs daily and reports on Scopes with over 85% utilization.
Diagnosis and Troubleshooting
  • -ForceUpdateDns = $true if DNS records are not synchronizing.
  • Get-DhcpServerv4FreeIPAddress -ScopeId ... before creating a Reservation.
  • Repair-DhcpServerv4IPRecord for a stuck record.
Glossary and Quick Command Line
  • Get-DhcpServerv4Scope / Statistics / Lease / Reservation / Failover — daily commands.

Check yourself

Which command authorizes a DHCP server against Active Directory?

Which command shows how many addresses remain available in a Scope?

Was this page helpful?