Using PowerShell -WhatIf and -Confirm to Preview Destructive Changes
Learn how to use PowerShell's -WhatIf and -Confirm switches to see what a command would do before it runs, reducing the risk of accidental data loss.
15 Jul 2025, 22:13 UTC

The problem: accidental bulk deletions
Administrators often need to clean up old files, stop services, or remove registry keys. Running a cmdlet such as Remove-Item or Stop-Service without first checking its scope can affect more objects than intended, leading to downtime or data loss. The risk grows when the command is part of a larger script or executed against a production environment.
How -WhatIf and -Confirm work
PowerShell includes two built‑in switches that turn many cmdlets into safe, auditable operations.
WhatIf: preview without execution
When a cmdlet supports -WhatIf, PowerShell shows what would happen to each target object without actually performing the action. The output describes the operation and the item that would be changed, allowing you to verify the scope before committing.
Confirm: interactive approval
The -Confirm switch prompts you for each individual change. You can approve (Y), skip (N), approve all (A), or stop the operation. This gives you a chance to keep or discard specific items while the command runs.
Worked example: cleaning old log files
Suppose you want to delete log files older than 30 days in C:\Logs. First, preview the deletion with -WhatIf.
# Run in a PowerShell console. You need read access to C:\Logs and permission to delete files.
Get-ChildItem -Path C:\Logs\*.log -File |
Where-Object {$_.LastWriteTime -lt (Get-Date).AddDays(-30)} |
Remove-Item -WhatIf
The command returns a list such as "What if: Performing the operation \"Remove File\" on target \"C:\Logs\old.log\"." No files are actually removed. If the list looks correct, you can run the same pipeline without -WhatIf to perform the deletion.
Adding confirmation for production runs
When you are ready to execute the change in a controlled environment, add -Confirm to receive a prompt for each file.
Get-ChildItem -Path C:\Logs\*.log -File |
Where-Object {$_.LastWriteTime -lt (Get-Date).AddDays(-30)} |
Remove-Item -Confirm
PowerShell will ask, for example, "Confirm\nAre you sure you want to perform this action?\nPerforming the operation \"Remove File\" on target \"C:\Logs\old.log\." You can type Y to delete that file, N to skip it, A to delete all remaining files, or L to list all affected items and then decide.
Limitations and verification
- Not every cmdlet implements
-WhatIfor-Confirm. Older or community‑maintained modules may lack the switches. Verify support by runningGet-Help cmdlet -Parameter WhatIfor checking the parameter list in the help. - If a script calls .NET methods directly (e.g.,
[System.IO.File]::Delete($path)) or invokes an external executable, the safety switches are bypassed because PowerShell does not intercept those calls. - Relying solely on the switches can give a false sense of safety if the underlying operation works outside the pipeline.
You can verify that the switches work as expected with a harmless cmdlet:
# Requires permission to query the service; no change is made.
Stop-Service -Name spooler -WhatIf
Stop-Service -Name spooler -Confirm
The first line should display a description of what would happen without stopping the service. The second line should prompt you for confirmation before any action is taken.
Actionable closing
Adopt a habit of previewing destructive commands with -WhatIf during development and adding -Confirm for production runs. Test on a small subset of data, log the output, and combine the switches with try/catch blocks for extra auditability. This simple practice turns risky one‑liners into safe, repeatable operations.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.