# Running Powershell script from command line with domain user credentials issue

**URL:** <https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634>\
**Category:** PowerShell Help\
**Created:** [July 6, 2020, 5:49am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634 "2020-07-06T05:49:37Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![amjadqau](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@amjadqau](https://forums.powershell.org/u/amjadqau)\
**Post date:** [July 6, 2020, 5:49am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/1 "2020-07-06T05:49:37Z")

</div>

I want to run a simple script from cmd using ad user/password, it fails and produces error of AccessDenied,PSSessionStateBroken.

command: PowerShell -ExecutionPolicy Bypass Invoke-Command -Credential (New-Object -TypeName System.Management.Automation.PSCredential -Argumentlist “domain\user”,($pw= ConvertTo-SecureString “password” -AsPlainText -Force)) -filepath ‘PATH\_OF\_SCRIPT\SCRIPT.ps1’ -computername “COMPUTER\_FQDN”

if i make this user as member of domain admins(group) the issue fixed but i need to run this script with simple ad user.

---

<div class="post-metadata">

**Author:** ![krzydoug](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/krzydoug/32/1008_2.png) [@krzydoug](https://forums.powershell.org/u/krzydoug)\
**Post date:** [July 6, 2020, 10:36am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/2 "2020-07-06T10:36:40Z")

</div>

Is the Path\_of\_script\script.ps1 a local folder or a shared folder?

---

<div class="post-metadata">

**Author:** ![amjadqau](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@amjadqau](https://forums.powershell.org/u/amjadqau)\
**Post date:** [July 7, 2020, 1:51am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/3 "2020-07-07T01:51:27Z")

</div>

[quote quote=240653]Is the Path\_of\_script\script.ps1 a local folder or a shared folder?

[/quote]  
Local folder

---

<div class="post-metadata">

**Author:** ![amjadqau](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@amjadqau](https://forums.powershell.org/u/amjadqau)\
**Post date:** [July 7, 2020, 6:07am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/4 "2020-07-07T06:07:03Z")

</div>

if i add this user in ‘domain admin’ group then i can run this script but if this user is simply member of domain user group then it gives error of access denied. so to be more accurate what privileges are needed for this user to be able to run the script?

---

<div class="post-metadata">

**Author:** ![medbouc](https://avatars.discourse-cdn.com/v4/letter/m/ecd19e/32.png) [@medbouc](https://forums.powershell.org/u/medbouc)\
**Post date:** [July 7, 2020, 7:41am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/5 "2020-07-07T07:41:14Z")

</div>

Invoke-Command uses WinRM as protocol and only BUILTIN\Administrators Group members can use WinRM, by default  
You should add this user to the BUILTIN\Remote Management Users Group  
Check with this command who can access the server through WinRM  
(Get-PSSessionConfiguration -Name Microsoft.PowerShell).Permission

---

<div class="post-metadata">

**Author:** ![krzydoug](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/krzydoug/32/1008_2.png) [@krzydoug](https://forums.powershell.org/u/krzydoug)\
**Post date:** [July 7, 2020, 7:02pm UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/6 "2020-07-07T19:02:37Z")

</div>

Perhaps this will help

```
Set-PSSessionConfiguration -Name Microsoft.PowerShell -showSecurityDescriptorUI
```

See this link for more info

> **[PowerShell Remoting via WinRM for Non-Admin Users | Windows OS Hub](http://woshub.com/powershell-remoting-via-winrm-for-non-admin-users/)**
>
> By default, to connect to a remote computer using PowerShell (PowerShell Remoting) you need the administrator privileges. In this article we’ll show how to allow remote connection using PowerShell Remoting…

---

<div class="post-metadata">

**Author:** ![amjadqau](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@amjadqau](https://forums.powershell.org/u/amjadqau)\
**Post date:** [July 8, 2020, 2:34am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/7 "2020-07-08T02:34:23Z")

</div>

> [@](#):
>
> e

Thanks for your response. (Get-PSSessionConfiguration -Name Microsoft.PowerShell).Permission returns

NT AUTHORITY\INTERACTIVE AccessAllowed, BUILTIN\Administrators AccessAllowed, BUILTIN\Remote Management Users AccessAllow  
ed

I added my user to the BUILTIN\Remote Management Users and BUILTIN\Administrators groups but no luck. still facing same error

---

<div class="post-metadata">

**Author:** ![amjadqau](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@amjadqau](https://forums.powershell.org/u/amjadqau)\
**Post date:** [July 8, 2020, 2:38am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/8 "2020-07-08T02:38:30Z")

</div>

[quote quote=240938]Perhaps this will help

Set-PSSessionConfiguration -Name Microsoft.PowerShell -showSecurityDescriptorUI See this link for more info

[http://woshub.com/powershell-remoting-via-winrm-for-non-admin-users/](http://woshub.com/powershell-remoting-via-winrm-for-non-admin-users/)

[/quote]  
Thanks for your response. it worked for me. but is there any way/command so that i do the manual work like (adding user and assign the execute(invoke) rights to the user) automatically through the script or command.

---

<div class="post-metadata">

**Author:** ![krzydoug](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/krzydoug/32/1008_2.png) [@krzydoug](https://forums.powershell.org/u/krzydoug)\
**Post date:** [July 8, 2020, 3:21am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/9 "2020-07-08T03:21:44Z")

</div>

Could you not assign a group the rights needed and then just add/remove users to that group?

---

<div class="post-metadata">

**Author:** ![amjadqau](https://avatars.discourse-cdn.com/v4/letter/a/b782af/32.png) [@amjadqau](https://forums.powershell.org/u/amjadqau)\
**Post date:** [July 8, 2020, 8:13am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/10 "2020-07-08T08:13:01Z")

</div>

[quote quote=241025]Could you not assign a group the rights needed and then just add/remove users to that group?

[/quote]  
i have add this user to a group having all access rights ‘full control’ checked but it didn’t work until i made this user member of ‘domain admins’ group.

---

<div class="post-metadata">

**Author:** ![krzydoug](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/krzydoug/32/1008_2.png) [@krzydoug](https://forums.powershell.org/u/krzydoug)\
**Post date:** [July 8, 2020, 9:51am UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/11 "2020-07-08T09:51:28Z")

</div>

If you need to make changes to multiple computers, you should use the group policy approach as described in the article I linked previously. If you want to use a group to control access, it needs to be a LOCAL group on each machine. That’s why it’s recommended to use the preconfigured “Remote Management Users” local group. You can even adjust the level of access that group has if you choose. You can replicate those custom permissions using the commands below, also outlined in the article.

```
# After making changes manually on a host, capture the custom SDDL
$SDDL = (Get-PSSessionConfiguration -Name "Microsoft.PowerShell").SecurityDescriptorSDDL

# You can export it if you like
$SDDL | Export-clixml d:\IT\custom-SDDL.xml

# You could change the permissions remotely from a privileged account
Invoke-Command -computername computer1,computer2,computer3 -scriptblock {
    Set-PSSessionConfiguration -Name Microsoft.PowerShell -SecurityDescriptorSddl $using:SDDL
}
```

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:29pm UTC](https://forums.powershell.org/t/running-powershell-script-from-command-line-with-domain-user-credentials-issue/14634/12 "2024-05-16T20:29:16Z")

</div>


