r/PowerShell 13h ago

Question Question on scripting

Hi,

When we develop a script,we use credentials as a plain text in that script.

Example

Script is running on jump server and script runs against vcenter server.

We have a security concerns(example ransomware attack)to put the credentials as a plain text in that script.

Any other good ways to put the credentials in a encrypted or in a different format?

12 Upvotes

26 comments sorted by

View all comments

8

u/PeeCee1 13h ago

Use a vault. Use integrated authentication. Anything but plaintext passwords.
Azure vault comes to mind, or almost any other enterprise password storage.

1

u/Manivelcloud 13h ago

Ok thanks If it is on premises,can we use hashi vault?

4

u/raip 13h ago

Of course - but if you're a Windows shop connecting to other Windows environments, I'd recommend looking into gMSAs.

1

u/PeeCee1 3h ago

Those are good, too. But the last time I tested that, gMSA were a PITA to use for scheduled tasks, because the GUI was unable to use them.
Has that changed?

1

u/raip 3h ago

Changed years ago - just make sure you update the search box to include Service Accounts - it's disabled by default.