Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Microsoft Intune can centrally enable PowerShell transcription on managed Windows devices. The recommended approach is an Intune Settings catalog profile configured for Windows 10 and later, with transcription enabled, optional invocation headers configured, and a controlled output directory specified.

Use a pilot group first. Confirm policy delivery in Intune, verify the device-side registry values, and then test with powershell.exe—Windows PowerShell 5.1—before expanding deployment. Transcripts are plaintext records and may contain sensitive information, so destination permissions and retention must be designed before production rollout.

What PowerShell transcription records

PowerShell transcription writes a text record of commands entered and output displayed during a PowerShell session. It can help with troubleshooting, administrative accountability, change review, incident response, and compliance evidence.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is not complete endpoint telemetry or a standalone forensic system. Transcription should be considered alongside:

#1 Best Overall
  • Script Block Logging, which records PowerShell script input in the Microsoft-Windows-PowerShell/Operational event log.
  • Module Logging, which provides module-focused logging.
  • Process-creation auditing and endpoint detection telemetry.
  • PowerShell operational events collected through your security-monitoring platform.

Script Block Logging complements transcription but does not provide the same console transcript. Microsoft also warns that invocation logging can create high event volume. See the Windows PowerShell policy documentation.

What the Intune policy does

The underlying ADMX-backed policy is EnableTranscripting, displayed in Intune as Turn on PowerShell Transcription. Microsoft documents it for Windows PowerShell, Windows PowerShell ISE, and other applications that use the Windows PowerShell engine.

Setting Purpose
EnableTranscripting Enables transcript creation for covered PowerShell sessions.
EnableInvocationHeader Adds invocation context to transcript files.
OutputDirectory Specifies where transcript files are written.

The policy maps to:

HKLMSOFTWAREPoliciesMicrosoftWindowsPowerShellTranscription

The main registry values are:

EnableTranscripting
EnableInvocationHeader
OutputDirectory

Microsoft states that enabling the policy has the same effect as invoking Start-Transcript for each covered Windows PowerShell session. If the policy is disabled, a user or script can still manually call Start-Transcript. Read the official policy and CSP documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Supported Windows versions and prerequisites

Microsoft’s applicability baseline lists:

  • Windows 10 version 2004 with KB5005101 or later.
  • Windows 10 version 20H2 with KB5005101 or later.
  • Windows 10 version 21H1 with KB5005101 or later.
  • Windows 11 version 21H2 or later.
  • Pro, Enterprise, Education, IoT Enterprise, and IoT Enterprise LTSC editions.

These are documentation baselines, not a guarantee that every current or future build behaves identically. Validate the exact Windows build during a pilot.

Before creating the profile, prepare:

  • Windows devices enrolled in Microsoft Intune.
  • Permission to create Windows configuration profiles.
  • Permission to assign profiles to the target Microsoft Entra ID group.
  • A small pilot device group and a known test device.
  • A planned local or network transcript destination.
  • Folder, NTFS, share, and—where applicable—network permissions.
  • A retention and access-control policy for transcript files.

Security warning: transcripts may contain secrets

Transcripts are plaintext records. They may capture passwords accidentally entered into commands, tokens, connection strings, personal data, file contents printed to the console, internal hostnames, paths, and administrative output.

Rank #2
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
  • 1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core
  • 4GB DDR4 System Memory; 128GB Solid State Drive
  • 11.6" HD (1366 x 768) Multi-Touch Display
  • Combo headphone/microphone jack - Noble Wedge Lock slot - HDMI; 2 USB 3.1 Gen 1
  • Windows 11 Pro

Restrict access to the destination, encrypt storage and transport, limit transcript readers, define retention and deletion rules, and avoid displaying secrets in the console. A centralized share is not automatically safer: overly broad ACLs could allow one user or computer to read another’s transcripts.

Create the Intune Settings Catalog profile

  1. Sign in to the Microsoft Intune admin center.
  2. Open Devices and the Windows configuration-profile area.
  3. Select Create profile.
  4. Choose Windows 10 and later as the platform.
  5. Choose Settings catalog as the profile type.
  6. Give the profile a descriptive name, such as PowerShell Transcription - Pilot.
  7. Select Settings or Add settings.
  8. Search for PowerShell Transcription. If necessary, browse the Windows PowerShell administrative-template category.

Intune labels can change, but the setting name and Microsoft policy mapping are more stable than the exact menu path. The original HTMD walkthrough is available at HTMD Blog’s PowerShell transcription guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Configure the three settings

Turn on PowerShell Transcription

Set Turn on PowerShell Transcription to Enabled. This activates transcript logging for the Windows PowerShell policy scope documented by Microsoft.

Include invocation headers

Enable Include invocation headers when investigations need additional context about command invocations. Disable it if lower transcript volume and less output noise are more important. Headers improve context but do not provide complete identity, process, network, or endpoint provenance.

Transcript output directory

For a pilot, use a short local path such as:

C:PSTranscripts

A local path simplifies troubleshooting and works when the device is offline. A UNC path can centralize collection, but it adds DNS, connectivity, share-permission, NTFS-permission, availability, and execution-context dependencies. Treat the destination as a separate folder-provisioning requirement; do not assume Intune will create every custom directory automatically.

Rank #3
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
  • 256 GB SSD of storage.
  • Multitasking is easy with 16GB of RAM
  • Equipped with a blazing fast Core i5 2.00 GHz processor.

When no custom location is supplied, Microsoft documents the default as the user’s Documents directory. Transcript filenames normally include PowerShell_transcript, the computer name, and the session start time.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Assign the profile to a pilot

  1. Assign the profile to a small device group, not all production devices.
  2. Review applicability and assignment filters if your tenant uses them.
  3. Create the profile.
  4. Trigger a device synchronization from Intune or Windows Settings.
  5. Wait for the device to check in and process the profile.

Do not rely on a fixed synchronization promise such as 15 minutes. Timing varies with device state, connectivity, tenant conditions, and whether synchronization was manually initiated.

Validate delivery on the device

1. Check Intune status

Confirm that the pilot device is included in the assignment and that the profile reports a successful or current applied status. Intune status alone is not proof that a transcript file is being created.

2. Inspect the registry

Run this read-only check in PowerShell:

$path = 'HKLM:SOFTWAREPoliciesMicrosoftWindowsPowerShellTranscription'

Get-ItemProperty -Path $path -ErrorAction Stop |
    Select-Object EnableTranscripting,
                  EnableInvocationHeader,
                  OutputDirectory

Expected output resembles:

EnableTranscripting     : 1
EnableInvocationHeader  : 1
OutputDirectory         : C:PSTranscripts

EnableInvocationHeader may be 0 if headers were intentionally disabled. If the registry key or values are absent, investigate assignment, synchronization, applicability, and policy conflicts before troubleshooting file creation.

3. Run a controlled Windows PowerShell test

Use powershell.exe for the baseline test because the Intune policy documentation is centered on Windows PowerShell behavior. In a controlled session, run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
15.6 Inch Laptop Computer, N4020, 4GB DDR4 RAM, 128GB eMMC,with Windows 11
  • EFFORTLESS EVERYDAY PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 Home system, delivering reliable, low-power efficiency for daily tasks like document editing, email, online classes, and web browsing
  • 15.6-INCH FULL HD DISPLAY: Enjoy immersive visuals on the 15.6" FHD (1920x1080) anti-glare screen with micro-edge bezels. Delivers clear details and comfortable viewing for long study sessions, working on spreadsheets, and video playback
  • RESPONSIVE MULTITASKING & STORAGE: Built with 4GB LPDDR4 RAM and 128GB eMMC storage for smooth daily essential use. Expand your storage by up to 1TB via the integrated TF card slot to easily store movies, photos, and working files
  • ADVANCED CONNECTIVITY: Outfitted with 2x Full-Featured Type-C ports for data transfer, fast charging, and dual-monitor output, alongside 2x USB 3.2 Gen1 ports and a 3.5mm audio jack for complete peripheral compatibility
  • LIGHTWEIGHT & SILENT OPERATION: Slim and portable for effortless travel or commuting. Features a 1MP HD webcam for remote meetings, 38Wh battery with 45W Type-C fast charging, and a fanless silent design for peaceful work environments.
$testPath = 'C:PSTranscriptspreflight.txt'

Start-Transcript -Path $testPath -Force
Get-Date
$PSVersionTable.PSVersion
Get-Location
Stop-Transcript

Test-Path $testPath
Get-Content $testPath

To test automatic naming and the output directory instead, run:

Start-Transcript -OutputDirectory 'C:PSTranscripts'
Get-Date
Stop-Transcript

See Microsoft’s Start-Transcript documentation for supported parameters and filename behavior.

What success looks like

  • The device is in the included pilot group.
  • The profile has been processed successfully.
  • The registry policy key exists.
  • EnableTranscripting equals 1.
  • The configured directory exists and is writable in the relevant context.
  • A .txt transcript is created.
  • The file contains the harmless test command and visible output.
  • Only approved users and services can read the file.

Troubleshoot missing transcript files

Intune reports success, but no file exists

  1. Confirm the device is actually included in the assignment.
  2. Check the device’s last check-in and synchronize again.
  3. Inspect the registry key and confirm EnableTranscripting is 1.
  4. Confirm the output folder exists.
  5. Check NTFS permissions.
  6. For a UNC path, check both share and NTFS permissions.
  7. Test network reachability and name resolution from the device.
  8. Test with powershell.exe, not only pwsh.exe.
  9. Check for conflicting configuration sources.
  10. Review Intune policy status and device-management diagnostic logs.
  11. Use manual Start-Transcript to separate policy-delivery problems from folder or shell problems.

The output directory does not exist

Create it through a remediation, device-management script, application deployment, provisioning process, or another controlled method before relying on automatic transcripts. Also verify that the account or process writing the transcript can access the path.

A UNC path fails

Common causes include an unavailable share, DNS failure, missing share or NTFS permissions, an unexpected user-versus-system execution context, offline startup, or a share that becomes available only after logon. Prove behavior with a local path first, then document the central share’s ACLs, availability, encryption, and retention model.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Windows PowerShell 5.1 versus PowerShell 7

Do not assume that a successful Windows PowerShell test proves coverage for every PowerShell 7 scenario. The Intune setting is documented under the Windows PowerShell ADMX policy. PowerShell 7 has its own configuration model and can require separate validation.

Best Value
Sale
15.6 Inch Win 11 Laptop Computer, N4020, 4GB DDR4 RAM, 128GB Storage
  • WINDOWS 11 | STABLE PERFORMANCE: Powered by Intel Celeron N4020 processor and Windows 11 system, this laptop delivers stable performance for everyday computing tasks. It supports web browsing, online learning, document editing, email communication, and basic office work with optimized power efficiency, providing a practical and reliable experience for essential daily use for daily use.
  • 15.6” FHD IPS DISPLAY: Features a 15.6-inch Full HD IPS display with narrow bezels, offering wider viewing angles and clearer image details compared to standard panels. The improved screen-to-body ratio enhances visual experience for study, reading, document work, and video playback, making it suitable for both productivity and entertainment use.
  • 4GB DDR4 + 128GB eMMC STORAGE: Equipped with 4GB DDR4 memory and 128GB eMMC storage for everyday basics such as browsing, documents, email, and online learning platforms. The built-in TF card slot supports storage expansion up to 1TB, giving you more flexibility for files, photos, videos, and daily documents. TF card not included.
  • CONNECTIVITY & PORTS: Includes 1× TF card slot, 2× USB 3.2 Gen1 ports, and 2× full-featured Type-C ports (USB 3.2 Gen1). The Type-C ports support data transfer, charging, and video output, enabling flexible connection with external devices such as monitors, storage, and peripherals for daily work and study use.
  • LIGHTWEIGHT DESIGN | ONLINE COMMUNICATION: Designed with a slim, portable profile, this laptop is easy to carry for school, commuting, and travel. A built-in 1MP front camera supports online classes, video meetings, remote communication, and everyday conferencing. The 3300mAh battery works with the low-power system design to support practical daily use, while thermal optimization helps maintain quieter operation during extended tasks.

Test pwsh.exe separately if it is in scope, record the exact PowerShell 7 version, and document the resulting behavior. Microsoft’s related references include PowerShell configuration documentation and PowerShell group-policy settings.

Custom OMA-URI fallback

Use a Custom OMA-URI profile only when Settings Catalog cannot provide the required setting. Microsoft documents the device path as:

./Device/Vendor/MSFT/Policy/Config/ADMX_PowerShellExecutionPolicy/EnableTranscripting

The corresponding user path is:

./User/Vendor/MSFT/Policy/Config/ADMX_PowerShellExecutionPolicy/EnableTranscripting

These are ADMX-backed policies. Microsoft specifies a special SyncML/XML payload and the chr data format. Do not use an invented generic Boolean payload: an incorrect encoding, node, or scope can produce a profile that appears configured but does not create the expected registry values.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Consult the current Microsoft CSP documentation, confirm device or user scope, test on one device, and validate both registry delivery and transcript creation.

Quick Recap

Bestseller No. 1
HP 14' HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
HP 14" HD Laptop, Windows 11, Intel Celeron Dual-Core Processor Up to 2.60GHz, 4GB RAM, 64GB SSD, Webcam, Dale Pink (Renewed)
14" diagonal, 1366x768 resolution, HD BrightView LED, Glossy NON-TOUCH Display
$249.99
Bestseller No. 2
Dell Latitude 3190 11.6' HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
Dell Latitude 3190 11.6" HD 2-in-1 Touchscreen Laptop Intel N5030 1.1Ghz 4GB Ram 128GB SSD Windows 11 Professional (Renewed)
1.1 GHz (boost up to 2.4GHz) Intel Celeron N5030 Quad-Core; 4GB DDR4 System Memory; 128GB Solid State Drive
$169.99
Bestseller No. 3
Dell Latitude 5420 14' FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
Dell Latitude 5420 14" FHD Business Laptop Computer, Intel Quad-Core i5-1145G7, 16GB DDR4 RAM, 256GB SSD, Camera, HDMI, Windows 11 Pro (Renewed)
256 GB SSD of storage.; Multitasking is easy with 16GB of RAM; Equipped with a blazing fast Core i5 2.00 GHz processor.
$309.00

Local versus centralized storage

Design Advantages Risks and costs
Local endpoint folder Simple pilot, works offline, easy diagnosis Harder central collection; local disk and tampering concerns
Protected UNC share Centralized collection and simpler retention review Depends on connectivity, permissions, and availability
Event-based logging Integrates with event collection and security analytics Does not provide the same complete console transcript
Endpoint detection telemetry Broader process and investigation context Separate platform and does not replace transcript content

Production rollout checklist

  • Validate the exact Windows editions and builds in scope.
  • Test Windows PowerShell 5.1 and PowerShell 7 separately where required.
  • Provision the output directory before enforcement.
  • Use least-privilege ACLs and protect network transport.
  • Define retention, deletion, encryption, and access review.
  • Explain to administrators that console output may be recorded.
  • Pair transcription with Script Block Logging and endpoint telemetry where appropriate.
  • Roll out in rings and monitor disk use, network traffic, policy failures, and sensitive-data exposure.
  • Keep Intune as the source of authority rather than permanently editing the registry manually.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.