PowerShell Desired State Configuration in 2026: Is It Still Worth It?

An honest assessment of PowerShell DSC in 2026: where it still earns its place, where Ansible or Intune fit better, and what to do with existing configurations.

PowerShell Desired State Configuration in 2026: Is It Still Worth It?

DSC arrived with a genuinely good idea. Describe the state a machine should be in, let something else make it so, and then spent years in an awkward position. Version 2 was tied to Windows PowerShell 5.1. Version 3 restructured things significantly. Meanwhile the industry largely settled on other tools.

So: is it worth learning in 2026? The honest answer is that it depends entirely on what you’re already running, and for a lot of teams the answer is no.

Quick Facts

  • DSC still works and is still supported. Nothing is being switched off.
  • DSC 3 decoupled it from Windows PowerShell and made it cross-platform, but it’s a meaningful change from v2.
  • For pure Windows estates already using it, it’s still a reasonable tool.
  • For new greenfield work, most teams pick Ansible, Intune or image-based deployment instead.
  • The concept matters more than the tool. Declarative configuration is worth understanding regardless.

What DSC actually does

You write a configuration describing the desired end state. This feature installed, this service running, this file present, and the Local Configuration Manager on each machine makes reality match, then keeps checking.

Configuration WebServer {
    Import-DscResource -ModuleName PSDesiredStateConfiguration

    Node 'WEB01' {
        WindowsFeature IIS {
            Ensure = 'Present'
            Name   = 'Web-Server'
        }

        Service W3SVC {
            Name      = 'W3SVC'
            State     = 'Running'
            DependsOn = '[WindowsFeature]IIS'
        }
    }
}

WebServer -OutputPath C:\DSC
Start-DscConfiguration -Path C:\DSC -Wait -Verbose

The appeal is idempotence: run it once or fifty times, the outcome is identical, and drift gets corrected automatically. That’s a genuinely better model than a setup script that assumes a clean machine.

Where it still earns its place

  • You already have DSC configurations in production. They work. There’s no urgency to rip them out.
  • Pure Windows Server estates where introducing a Linux control node for Ansible is unwelcome.
  • Azure Automanage Machine Configuration, which is built on DSC and is a reasonable path if you’re already in Azure.
  • Configuration drift matters to you and you want continuous correction rather than periodic reimaging.

Where something else fits better

SituationBetter fitWhy
Mixed Windows and LinuxAnsibleOne tool, agentless, larger community
Modern endpoint managementIntunePurpose-built, cloud-native, already licensed for most
Cloud infrastructureTerraform + image bakingImmutable beats configured
Containerised workloadsDockerfile / KubernetesConfiguration is the image
Simple one-off setupA plain PowerShell scriptDSC’s overhead isn’t justified

The pattern across most of those is a shift from configuring machines to replacing machines. If you can rebuild a server in ten minutes from an image, drift correction matters much less than it did when servers lived for years.

If you have existing DSC

Quick Steps

  1. Don’t panic-migrate. Working configurations aren’t a problem to solve this quarter.
  2. Document what they actually enforce, often more than anyone remembers.
  3. Decide direction before writing anything new. Adding to a system you plan to replace wastes effort twice.
  4. If you’re staying, look at DSC 3 and understand what changes, particularly around resources and the invocation model.
  5. If you’re leaving, migrate incrementally, one role at a time, keeping DSC in place until each replacement is proven.

Is the concept still worth learning?

Yes, and this is the part worth separating from the tool. Declarative configuration, idempotence and drift detection are the foundation of every modern infrastructure tool. Ansible playbooks, Terraform, Kubernetes manifests and Intune configuration profiles are all the same idea wearing different clothes.

Understanding why declaring end state beats scripting steps is genuinely valuable. Whether you express that in DSC specifically is a much smaller question, and for most people starting fresh in 2026, the answer is probably not.

Glossary

TermWhat it means
IdempotentRunning an operation repeatedly produces the same result as running it once.
LCMLocal Configuration Manager. The agent applying and enforcing DSC configurations.
MOFThe compiled file a DSC configuration produces and the LCM consumes.
Configuration driftGradual divergence of a system from its intended state.
Pull serverA central server machines fetch their configuration from.
Immutable infrastructureReplacing servers rather than modifying them.

Frequently asked questions

Is PowerShell DSC deprecated?

No. It’s supported and still developed. DSC 3 is a significant restructuring rather than an ending. But industry momentum has moved elsewhere, which affects community resources and hiring more than it affects whether it works.

Should I learn DSC or Ansible?

Ansible, if you’re choosing one and starting fresh. Broader applicability, larger community, and it handles Linux. Learn DSC if your employer already runs it.

What replaced DSC for Windows endpoints?

Intune, largely. For servers, it’s a mix of Ansible, image-based deployment and cloud-native tooling depending on where the workloads live.

Can I use DSC without a pull server?

Yes. Push mode with Start-DscConfiguration works fine for small estates. A pull server matters when you want machines to fetch and self-correct without being contacted.

Is it worth migrating working DSC configurations?

Not urgently. Migrate when you’re changing the workload anyway, or when maintaining DSC skills in your team becomes a genuine problem. Working automation is not technical debt just because it’s unfashionable.

🛠️

Gear We Recommend

Testing configuration management safely needs a lab. Here’s the kit ours runs on.

Browse our Home Lab picks on Amazon

As an Amazon Associate, TechyGeeksHome earns from qualifying purchases

Disclosure: this post may contain affiliate links. If you buy through one of them, we may earn a small commission at no extra cost to you. We only recommend products we’ve tested or genuinely rate.


Discover more from TechyGeeksHome

Subscribe to get the latest posts sent to your email.

Andrew Armstrong

Andrew Armstrong is a UK-based IT professional with 26+ years of hands-on experience in Windows, Windows Server, SCCM/ConfigMgr, Intune, Active Directory, PowerShell and enterprise infrastructure.

He founded TechyGeeksHome in 2010 and has published 770+ practical guides to real-world IT problems. He also builds free Windows utilities, including Ultimate Settings Panel, which has been downloaded over 850,000 times.

Leave a Reply

Your email address will not be published. Required fields are marked *