Skip to content

Securing PowerShell

Script Execution Policies

PowerShell's execution policies control which scripts can run, ensuring that only trusted scripts are executed. These policies are critical for preventing unauthorized or malicious script execution. The available execution policy settings include:

  • Restricted: Default policy. Prevents running scripts from external sources. Only scripts signed by trusted publishers can run.
  • RemoteSigned: Allows local scripts to run but requires remote scripts to be signed by a trusted publisher.
  • Unrestricted: Allows all scripts to run but warns about unsigned scripts.
  • AllSigned: Requires all scripts (local and remote) to be signed by a trusted publisher.
  • Bypass: Disables execution policy checks entirely (not recommended for production environments).

Configuring Execution Policies

Use the Set-ExecutionPolicy cmdlet to configure the policy. For example:

Set-ExecutionPolicy RemoteSigned -Scope CurrentUser
This sets the policy to RemoteSigned for the current user. Note that administrative privileges may be required for the LocalMachine scope.

Best Practices

  • Use RemoteSigned for a balance between security and usability in most environments.
  • Avoid Unrestricted or Bypass in production unless explicitly necessary.
  • Test policies in a non-production environment first to avoid unintended disruptions.

Example: Checking Current Policy

Get-ExecutionPolicy -List
This displays the current execution policy settings for all scopes.


Module Signing

Module signing ensures that only trusted, verified modules are loaded into the PowerShell environment. This prevents unauthorized or malicious modules from being executed, even if they are placed in standard module paths.

Enforcing Module Signing

  1. Enable module signing enforcement by configuring the registry (note: registry paths are version-dependent; use PowerShell's built-in module signing configuration methods if available):

    Set-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\PowerShell\3\ShellIds\Microsoft.PowerShell" -Name "ModuleSigningPolicy" -Value "AllSigned"
    
    This enforces that all modules must be signed by a trusted certificate authority (CA).

  2. Verify module signatures using Test-ModuleManifest or Get-Module -ListAvailable:

    Test-ModuleManifest -Path "C:\Modules\MyModule\MyModule.psd1"
    

  3. Configure trusted CAs by adding certificates to the local machine's trusted root store. Use Import-Certificate to import trusted CA certificates. Ensure certificates are imported into the "Local Machine" store for module signing to work correctly.

Example: Checking Module Signatures

Get-Module -ListAvailable | Where-Object { $_.Signed -eq $false }
This identifies unsigned modules that violate the signing policy.