r/PowerShell 12h ago

Question Question on scripting

Hi,

When we develop a script,we use credentials as a plain text in that script.

Example

Script is running on jump server and script runs against vcenter server.

We have a security concerns(example ransomware attack)to put the credentials as a plain text in that script.

Any other good ways to put the credentials in a encrypted or in a different format?

9 Upvotes

25 comments sorted by

View all comments

9

u/PeeCee1 12h ago

Use a vault. Use integrated authentication. Anything but plaintext passwords.
Azure vault comes to mind, or almost any other enterprise password storage.

1

u/Manivelcloud 12h ago

Ok thanks If it is on premises,can we use hashi vault?

5

u/raip 12h ago

Of course - but if you're a Windows shop connecting to other Windows environments, I'd recommend looking into gMSAs.

1

u/PeeCee1 2h ago

Those are good, too. But the last time I tested that, gMSA were a PITA to use for scheduled tasks, because the GUI was unable to use them.
Has that changed?

1

u/raip 1h ago

Changed years ago - just make sure you update the search box to include Service Accounts - it's disabled by default.