如何在包含PowerShell脚本的批处理文件中配置凭据,实现Windows AutoPilot信息采集的无交互自动化?
Got it, let's fix that double credential prompt you're hitting when running the -online parameter with Get-WindowsAutoPilotInfo.ps1. The script needs to authenticate twice (once for script execution permissions, once for uploading device data to Intune/Azure AD), but we can streamline this by passing a pre-defined credential object to avoid manual input. Here are the safest, most practical methods:
Method 1: Encrypted Credential File (Recommended)
This approach stores your credentials in an encrypted file (using Windows DPAPI, so only the user who created it on the same machine can decrypt it) to avoid plaintext exposure:
Step 1: Create the encrypted credential file (run once manually)
Open PowerShell as your target user and run:
$cred = Get-Credential -Message "Enter your Intune/Azure AD credentials" $cred | Export-Clixml -Path "C:\Safe\Path\To\AutoPilotCreds.xml"
Pick a secure location for the XML file (avoid public or shared folders).
Step 2: Update your batch file to use the encrypted credentials
Modify the final PowerShell call in your batch script to load the credential file and pass it to the script:
@ECHO OFF echo start powershell call powershell.exe -ExecutionPolicy ByPass -Command "$null=Install-Script -Name Get-WindowsAutoPilotInfo -force" call powershell.exe -ExecutionPolicy ByPass -Command "$cred = Import-Clixml -Path 'C:\Safe\Path\To\AutoPilotCreds.xml'; & $env:ProgramFiles\WindowsPowerShell\Scripts\Get-WindowsAutoPilotInfo.ps1 -online -Credential $cred"
This will automatically use the stored credentials without any prompts.
Method 2: Use Windows Credential Manager
If you prefer not to create a separate file, store your credentials in Windows Credential Manager and let the script pick them up automatically:
- Open Control Panel > Credential Manager > Windows Credentials
- Click Add a Windows credential
- For the Internet or network address, enter the relevant endpoint (e.g.,
https://enterpriseregistration.windows.netfor Azure AD) - Enter your full UPN username (like
user@domain.com) and password, then save
Update your batch script's final command to leverage stored credentials:
call powershell.exe -ExecutionPolicy ByPass -Command "$cred = Get-Credential -UserName 'your-username@domain.com' -Message 'Using stored credentials'; & $env:ProgramFiles\WindowsPowerShell\Scripts\Get-WindowsAutoPilotInfo.ps1 -online -Credential $cred"
When you run this, PowerShell will check Credential Manager for matching credentials and use them without prompting.
Method 3: Plaintext Credentials (NOT RECOMMENDED)
While technically functional, this method exposes your password in plaintext (visible in command history, process logs, etc.) and should never be used in production or shared environments:
call powershell.exe -ExecutionPolicy ByPass -Command "$username = 'your-username@domain.com'; $password = ConvertTo-SecureString 'your-plaintext-password' -AsPlainText -Force; $cred = New-Object System.Management.Automation.PSCredential ($username, $password); & $env:ProgramFiles\WindowsPowerShell\Scripts\Get-WindowsAutoPilotInfo.ps1 -online -Credential $cred"
内容的提问来源于stack exchange,提问作者Patrick de Lange

