Securing PowerShell
Script Execution Policies¶
PowerShell's execution policies control which scripts can run, ensuring that only trusted scripts are executed. These policies are critical for preventing unauthorized or malicious script execution. The available execution policy settings include:
- Restricted: Default policy. Prevents running scripts from external sources. Only scripts signed by trusted publishers can run.
- RemoteSigned: Allows local scripts to run but requires remote scripts to be signed by a trusted publisher.
- Unrestricted: Allows all scripts to run but warns about unsigned scripts.
- AllSigned: Requires all scripts (local and remote) to be signed by a trusted publisher.
- Bypass: Disables execution policy checks entirely (not recommended for production environments).
Configuring Execution Policies¶
Use the Set-ExecutionPolicy cmdlet to configure the policy. For example:
RemoteSigned for the current user. Note that administrative privileges may be required for the LocalMachine scope.
Best Practices¶
- Use RemoteSigned for a balance between security and usability in most environments.
- Avoid Unrestricted or Bypass in production unless explicitly necessary.
- Test policies in a non-production environment first to avoid unintended disruptions.
Example: Checking Current Policy¶
This displays the current execution policy settings for all scopes.Module Signing¶
Module signing ensures that only trusted, verified modules are loaded into the PowerShell environment. This prevents unauthorized or malicious modules from being executed, even if they are placed in standard module paths.
Enforcing Module Signing¶
-
Enable module signing enforcement by configuring the registry (note: registry paths are version-dependent; use PowerShell's built-in module signing configuration methods if available):
This enforces that all modules must be signed by a trusted certificate authority (CA).
-
Verify module signatures using
Test-ModuleManifestorGet-Module -ListAvailable:
-
Configure trusted CAs by adding certificates to the local machine's trusted root store. Use
Import-Certificateto import trusted CA certificates. Ensure certificates are imported into the "Local Machine" store for module signing to work correctly.