Skip to main content

PowerShell Execution Policy

·335 words·2 mins
Posts 101 cli powershell
Table of Contents
PowerShell’s execution policy is a safety feature that controls the conditions under which PowerShell loads configuration files and runs scripts.

Open PowerShell terminal, and run the cmdline below.

pwsh> ExecutionPolicy -List

        Scope ExecutionPolicy
        ----- ---------------
MachinePolicy    Unrestricted
   UserPolicy       Undefined
      Process       Undefined
  CurrentUser       Undefined
 LocalMachine       Undefined

The output means the system allows all PowerShell scripts to run without restrictions.

Execution Policy
#

PowerShell evaluates execution policies using a strict hierarchy. The top-most defined scope always overrides the scopes below it.

  • MachinePolicy is set to Unrestricted: This is a GPO applied at the computer level.
  • All other scopes are Undefined: : Because MachinePolicy is at the very top of the hierarchy, it completely overrides UserPolicy, Process, CurrentUser, and LocalMachine. Even if we try to change the local policy, the domain/system policy will block our changes.

Security Impact
#

An Unrestricted policy means any PowerShell script can run on this machine. This includes any unsigned scripts downloaded from the internet.

Windows will still show a warning prompt for unverified files downloaded from the web. And this setting significantly lowers the system’s built-in defenses against malicious scripts.

Never leave it Unrestricted. Should go with either AllSigned or RemoteSigned.

Recommendation
#

Fix the issue via Group Policy:

  1. Open Local Group Policy Editor (gpedit.msc)
  2. Navigate to: Computer Configuration > Administrative Templates > Windows Components > Windows PowerShell
  3. Turn on Script Execution
  4. Change it to Enabled and set the execution policy to Allow local scripts and remote signed scripts (RemoteSigned)

To use the Set-ExecutionPolicy cmdline, open PowerShell as Administrator.

This will change the policy for the entire computer:

pwsh> Set-ExecutionPolicy RemoteSigned -Scope LocalMachine

This will change it only for logged-in user account:

pwsh> Set-ExecutionPolicy RemoteSigned -Scope CurrentUser

To bypass restrictions for just your current open window:

Set-ExecutionPolicy Bypass -Scope Process

To lock down a specific session for testing:

powershell.exe -ExecutionPolicy RemoteSigned

Restricted: The most secure setting. It completely blocks all PowerShell scripts from running, allowing you to only type manual, single commands directly into the terminal window.

Links#

Related

Tunnelling with SSH Port Forwarding
·1310 words·7 mins
Posts 101 cli ssh tunnel
Quick notes on tunnelling with SSH port forwarding.
Encoding 101
·580 words·3 mins
Posts 101 cli encoding
Some notes about encoding: HTML encoding, URL encoding and ASCII encoding.
Podman 101
·1829 words·9 mins
Posts 101 podman cli tools
Docker alternative with Podman.