Skip to main content

Invoke-IISCrypto

Description​

Checks or updates the Windows settings that control secure connections, using IIS Crypto templates.

You can:

  • View the current settings. Nothing is changed.
  • Apply a template from a web URL, a network share, or a local file.
  • Apply a template and view the results in a single run.

A setting that shows a value of null has not been changed. Windows is still using its default for that setting.

Requirements​

To apply a template, provide one of the following locations:

  • A download URL starting with http:// or https://
  • A network share, for example \fileserver\share\template.ictpl
  • A local file path, for example C:\Temp\template.ictpl

Prebuilt and custom templates are described in the Custom Templates section of this page: https://www.nartac.com/Products/IISCrypto

Applying a template may require a restart. Use AllowReboot to restart automatically, or restart the computer yourself afterwards.

Usage​

View the current IISCrypto configuration:

.\Invoke-IISCrypto.ps1 -Audit

Apply a template from a URL:

.\Invoke-IISCrypto.ps1 -ApplyTemplate -TemplateSource 'https://templateurl.com/template.ictpl'

Apply a template from a network share and allow an automatic restart:

.\Invoke-IISCrypto.ps1 -ApplyTemplate -TemplateSource '\\fileserver\share\template.ictpl' -AllowReboot

Apply a local template, choose the backup location, then view the new settings:

.\Invoke-IISCrypto.ps1 -ApplyTemplate -TemplateSource 'C:\Temp\template.ictpl' -Audit -RegistryBackupPath 'C:\Temp\backup.reg'

Existing calls that use -TemplateURL keep working. No changes are needed.

Parameters​

ParameterAliasRequiredDefaultTypeDescription
AuditFalseSwitchShows the current settings without changing anything
ApplyTemplateFalseSwitchApplies the template given by TemplateSource
TemplateSourceTemplateURLOnly with ApplyTemplateStringLocation of the template: a URL, network share, or local file
AllowRebootFalseSwitchRestarts the computer automatically after a template is applied
RegistryBackupPathFalsebackup.reg (next to the script)StringWhere to save the copy of settings made before applying a template

Output​

Where to find results, logs, and errors:

  • Settings: shown when Audit is used. Each setting appears with a name and value.
  • Logs: .\Invoke-IISCrypto-log.txt
  • Errors: .\Invoke-IISCrypto-error.txt
  • Backup: a copy of the previous settings, saved as backup.reg next to the script unless RegistryBackupPath is set.

Changelog​

2026-09-29​

  • Renamed TemplateURL to TemplateSource. The old parameter name still works.
  • Templates can now come from a URL, a network share, or a local file.
  • Added AllowReboot to allow an automatic restart after applying a template.
  • Added RegistryBackupPath to choose where the settings backup is saved.
  • When Audit and ApplyTemplate are used together, the template is applied first and the new settings are then shown.

2025-05-20​

  • Initial version of the document