# Remote script execution on behalf of a local account

**URL:** <https://forums.powershell.org/t/remote-script-execution-on-behalf-of-a-local-account/18596>\
**Category:** PowerShell Help\
**Created:** [February 16, 2022, 9:01am UTC](https://forums.powershell.org/t/remote-script-execution-on-behalf-of-a-local-account/18596 "2022-02-16T09:01:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![BigSmoke](https://avatars.discourse-cdn.com/v4/letter/b/85f322/32.png) [@BigSmoke](https://forums.powershell.org/u/BigSmoke)\
**Post date:** [February 16, 2022, 9:01am UTC](https://forums.powershell.org/t/remote-script-execution-on-behalf-of-a-local-account/18596/1 "2022-02-16T09:01:28Z")

</div>

hello everyone, I have created a script to remove the certificate on remote computers.  
I want to run this script on a remote PC under a local account. But it does not work, if the same script is run from a domain account, then everything is ok.  
and I need from local. The local entry is a member of the Administrators group.

```auto
$del_cert_veeam = {$Path = 'Cert:\LocalMachine\My\'

$CertList = Get-ChildItem -Path $Path | Where-Object {$_.Issuer -like "CN=Veeam*"}

    remove-item "$($Path)$($CertList.Thumbprint)" -Force
}
$password = ConvertTo-SecureString "Qwerty@12" -AsPlainText -Force
$Cred = New-Object System.Management.Automation.PSCredential ("testpc01\user1", $password)
Invoke-Command -ComputerName testpc01.com.lan -Credential $Cred -ScriptBlock $del_cert_veeam

```

Error

```auto
[testpc01.com.lan] Connecting to remote server testpc01.com.lan failed with the following error message : WinRM cannot process t
he request. The following error with errorcode 0x80090311 occurred while using Kerberos authentication: There are currently no logon ser
vers available to service the logon request.  
 Possible causes are:
  -The user name or password specified are invalid.
  -Kerberos is used when no authentication method and no user name are specified.
  -Kerberos accepts domain user names, but not local user names.
  -The Service Principal Name (SPN) for the remote computer name and port does not exist.
  -The client and remote computers are in different domains and there is no trust between the two domains.
After checking for the above issues, try the following:
  -Check the Event Viewer for events related to authentication.
  -Change the authentication method; add the destination computer to the WinRM TrustedHosts configuration setting or use HTTPS transport
.
Note that computers in the TrustedHosts list might not be authenticated.
   -For more information about WinRM configuration, run the following command: winrm help config. For more information, see the about_Re
mote_Troubleshooting Help topic.

```

---

<div class="post-metadata">

**Author:** ![tonyd](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/tonyd/32/1041_2.png) [@tonyd](https://forums.powershell.org/u/tonyd)\
**Post date:** [February 16, 2022, 5:59pm UTC](https://forums.powershell.org/t/remote-script-execution-on-behalf-of-a-local-account/18596/3 "2022-02-16T17:59:12Z")

</div>

Have you tried adding:

```auto
-Authentication 'Negotiate'

```

To Invoke-Command?

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:19pm UTC](https://forums.powershell.org/t/remote-script-execution-on-behalf-of-a-local-account/18596/4 "2024-05-16T20:19:32Z")

</div>


