ExecutionPolicy in PowerShell
| Introduction | |
| Get-ExecutionPolicy | |
| Set-ExecutionPolicy | |
| Related Articles |
Introduction
Safety feature to control the conditions a script can run.
Prevent execution of malicious scripts.
Scope execution of scripts to specific sessions.
Execution policies for the local computer and current user are stored in the registry.
The execution policy is not a security system that restricts user actions.
On a Windows computer you can set an execution policy for the local computer, for the current user, or for a particular session.
On non-Windows computers, the default execution policy is Unrestricted and cannot be changed.
Enforcement of policies only occurs on Windows platforms
Existing Policies
- All Signed
- Bypass
- Remote Signed
- Restricted
- Unrestricted
All Signed Policy
- Scripts can execute
- Requires that all scripts and configuration files be signed by a trusted publisher
- Prompts you before running scripts not yet classified as trusted or untrusted
- Risk running signed malicious scripts
Policy Execution Order:
Process → CurrentUser → LocalMachine → Restricted
Wherever PowerShell is launched, I use the full command powershell for compatibility with older Windows systems, such as Windows 7.
If you have a relatively new Windows, you can use the alias pwsh
Get-ExecutionPolicy
Example of getting the current ExecutionPolicy
Get-ExecutionPolicy
Restricted
You can use -List to get a more detailed list.
PS C:\Users\Andrei> Get-ExecutionPolicy -List
Scope ExecutionPolicy ----- --------------- MachinePolicy Undefined UserPolicy Undefined Process Undefined CurrentUser Undefined LocalMachine RemoteSigned
Let's look at the file Test.ps1 with the following contents
Write-Host "Visit www.heihei.ru!" -f Green
.\Test.ps1
Visit www.heihei.ru!
If you now change the LocalMachine launch policy to Restricted from administrator mode, the script will not run.
Set-ExecutionPolicy Restricted
Get-ExecutionPolicy -List
Scope ExecutionPolicy ----- --------------- MachinePolicy Undefined UserPolicy Undefined Process Undefined CurrentUser Undefined LocalMachine Restricted
.\Test.ps1
.\Test.ps1: File C:\demo\Test.ps1 cannot be loaded because running scripts is disabled on this system. For more information, see about_Execution_Policies at https://go.microsoft.com/fwlink/?LinkID=135170.
Set-ExecutionPolicy
Can be assigned to the default scope or a specific scope
The default scope is LocalMachine, which affects everyone who uses the computer.
Execution policies can be used for a single PowerShell Session.
Get-ExecutionPolicy
Restricted
Set-ExecutionPolicy Unrestricted
Get-ExecutionPolicy
Unrestricted
By default, the policy is set for LocalMachine.
The execution policy can be explicitly set for a specific scope.
Set-ExecutionPolicy RemoteSigned -Scope LocalMachine
Set-ExecutionPolicy AllSigned -Scope CurrentUser
Get-ExecutionPolicy -List
Scope ExecutionPolicy ----- --------------- MachinePolicy Undefined UserPolicy Undefined Process Undefined CurrentUser AllSigned LocalMachine RemoteSigned
If you try to run the script Test.ps1 with this policy, an error will appear due to the fact that the file is not signed.
.\Test.ps1
.\Test.ps1: File C:\demo\Test.ps1 cannot be loaded. The file C:\demo\Test.ps1 is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https://go.microsoft.com/fwlink/?LinkID=135170.
In this situation, you need to remove the restriction from the CurrentUser area.
Set-ExecutionPolicy -ExecutionPolicy Undefined -Scope CurrentUser
.\Test.ps1
Visit www.heihei.ru!
Set ExecutionPolicy on a remote machine
Invoke-Command ` -ComputerName Computer ` -ScriptBlock { Get-ExecutionPolicy } | Set-ExecutionPolicy
To set ExecutionPolicy only for the current session, you need to run the following command
powershell -ExecutionPolicy RemoteSigned
Get-ExecutionPolicy
RemoteSigned
Now the current policy is RemoteSigned, despite the LocalMachine policy being Unrestricted and the CurrentUser policy being Undefined.
This happened because when we launched PowerShell with the policy specified, we set it in the Process scope.
Get-ExecutionPolicy -List
Scope ExecutionPolicy ----- --------------- MachinePolicy Undefined UserPolicy Undefined Process RemoteSigned CurrentUser Undefined LocalMachine Unrestricted
In this situation, we can set the launch policy to Restricted for CurrentUser and the script will still run.
Set-ExecutionPolicy -ExecutionPolicy Restriced -Scope CurrentUser
Get-ExecutionPolicy -List
Scope ExecutionPolicy ----- --------------- MachinePolicy Undefined UserPolicy Undefined Process RemoteSigned CurrentUser Restricted LocalMachine Unrestricted
.\Test.ps1
Visit www.heihei.ru!
Article author: Andrei Olegovich
| Windows | |
| PowerShell | |
| Alias | |
| Calling REST API | |
| Users | |
| Network | |
| Install | |
| Files | |
| Functions | |
| Loops | |
| ExecutionPolicy | |
| if | |
| GetType() | |
| param |