# Passing specific credentials to remote session

**URL:** <https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321>\
**Category:** PowerShell Help\
**Created:** [September 17, 2018, 7:55am UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321 "2018-09-17T07:55:01Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![juli-reid](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/juli-reid/32/149_2.png) [@juli-reid](https://forums.powershell.org/u/juli-reid)\
**Post date:** [September 17, 2018, 7:55am UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/1 "2018-09-17T07:55:01Z")

</div>

I have a sort of crazy situation. I have to run a powershell script from a SharePoint console app.

This will be running a remote session on a different server. I need to be able to run that remote session with a specific set of credentials in order to update an AD security group.

How can I do that?

Edit: This script is being triggered by a console app and needs to run unattended with no need to provide a password. The credentials will not change. I am looking for a way to provide the credentials via a token file or similar.

---

<div class="post-metadata">

**Author:** ![sam-boutros](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/sam-boutros/32/5_2.png) [@sam-boutros](https://forums.powershell.org/u/sam-boutros)\
**Post date:** [September 17, 2018, 7:59am UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/2 "2018-09-17T07:59:56Z")

</div>

```
$myRemoteSessionCredential = Get-Credential -UserName 'domain\user'

$myRemoteSession = New-PSSession -ComputerName 'myRemoteComputer.FQDN' -Credential $myRemoteSessionCredential

Invoke-Command -Session $myRemoteSession -ScriptBlock {

# my command list to be executed on the remote computer using my remote cred

}
```

---

<div class="post-metadata">

**Author:** ![juli-reid](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/juli-reid/32/149_2.png) [@juli-reid](https://forums.powershell.org/u/juli-reid)\
**Post date:** [September 17, 2018, 8:08am UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/3 "2018-09-17T08:08:32Z")

</div>

It would appear that I left out a critical component of the description. I need this to run without having to enter a password each time. It will be the same set of credentials and needs to be able to run unattended.

Can I take what you have above and create a token file that can be referenced and used?

---

<div class="post-metadata">

**Author:** ![kvprasoon](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/kvprasoon/32/4449_2.png) [@kvprasoon](https://forums.powershell.org/u/kvprasoon)\
**Post date:** [September 17, 2018, 8:18am UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/4 "2018-09-17T08:18:01Z")

</div>

You can build a Credential object. create a script like below

```
Param(
[Parameter(Mandatory)]
[system.Security.SecureString]$Password,

[Parameter()]
[string]UserName = 'domain\user'
)
$Credential = [PSCredential]::new('UserName',$Password)
Invoke-Command -Session $myRemoteSession -ScriptBlock { ... } -Credential $credential
```

Call **.\ThisScript.ps1**

for unattended **.\ThisScript.ps1 -Password (ConvertTo-SecureString -AsPlainText -Force -String ‘Password’)**

---

<div class="post-metadata">

**Author:** ![sam-boutros](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/sam-boutros/32/5_2.png) [@sam-boutros](https://forums.powershell.org/u/sam-boutros)\
**Post date:** [September 17, 2018, 8:29am UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/5 "2018-09-17T08:29:17Z")

</div>

```
Install-Module AZSBTools 

$myRemoteSessionCredential = Get-SBCredential -UserName 'domain\user'
$myRemoteSession = New-PSSession -ComputerName 'myRemoteComputer.FQDN' -Credential $myRemoteSessionCredential
Invoke-Command -Session $myRemoteSession -ScriptBlock {

# my command list to be executed on the remote computer using my remote cred

}
```

The Get-SBCredential cmdlet persists the encrypted credential object to disk for unattended execution (you type in the pwd the first time)

To update the persisted credential (on disk) - say after pwd change, use

```
Get-SBcredential -Refresh -UserName ‘domain\user’
```
  
use 
```
help Get-SBCredential -Show
```
 for built in help and examples  
Also see [https://superwidgets.wordpress.com/2016/08/05/powershell-script-to-provide-a-ps-credential-object-saving-password-securely/](https://superwidgets.wordpress.com/2016/08/05/powershell-script-to-provide-a-ps-credential-object-saving-password-securely/)

---

<div class="post-metadata">

**Author:** ![juli-reid](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/juli-reid/32/149_2.png) [@juli-reid](https://forums.powershell.org/u/juli-reid)\
**Post date:** [September 17, 2018, 8:35am UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/6 "2018-09-17T08:35:37Z")

</div>

Is it possible to do without 3rd party tools?

---

<div class="post-metadata">

**Author:** ![sam-boutros](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/sam-boutros/32/5_2.png) [@sam-boutros](https://forums.powershell.org/u/sam-boutros)\
**Post date:** [September 17, 2018, 8:39am UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/7 "2018-09-17T08:39:45Z")

</div>

Juli, your last question suggests that you did not read the Get-SBCredential function or understand what it does and how. I recommend that you do.

---

<div class="post-metadata">

**Author:** ![donj](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/donj/32/137_2.png) [@donj](https://forums.powershell.org/u/donj)\
**Post date:** [September 17, 2018, 12:31pm UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/8 "2018-09-17T12:31:15Z")

</div>

MS deliberately makes it difficult to persist credential objects, because of the security risk that represents. So there’s nothing native in PowerShell that makes it easy and straightforward and safe to keep a credential object on-disk.

The “right” way to do this is to use JEA, which is a Microsoft add-in for PowerShell. You can also set this up without JEA, it’s just a bit more manual; “Secrets of PowerShell Remoting” explains these “constrained endpoints.” The theory is that you set up an endpoint which has a persistent “run as” credential, and you let the script log into that to run its command. The credential is stored safely that way.

---

<div class="post-metadata">

**Author:** ![postanote](https://avatars.discourse-cdn.com/v4/letter/p/ebca7d/32.png) [@postanote](https://forums.powershell.org/u/postanote)\
**Post date:** [September 17, 2018, 6:31pm UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/9 "2018-09-17T18:31:45Z")

</div>

Take a look at

> Using Credential Manager in PowerShell https://bitsofwater.com/2018/02/16/using-credential-manager-in-powershell
> 
> Provides access to credentials in the Windows Credential Manager  
> [PowerShell Gallery | CredentialManager 2.0](https://www.powershellgallery.com/packages/CredentialManager/2.0)

  
&nbsp;

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:34pm UTC](https://forums.powershell.org/t/passing-specific-credentials-to-remote-session/11321/10 "2024-05-16T20:34:21Z")

</div>


