The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Install pinned modulesInstall-PSResource Microsoft.PowerShell.SecretManagement ` -Version 1.1.2 -TrustRepositoryView examples
Register SecretStoreRegister-SecretVault -Name LocalStore -ModuleName ` Microsoft.PowerShell.SecretStore -DefaultVaultView examples
List registered vaultsGet-SecretVaultView examples
Test a vaultTest-SecretVault -Name LocalStoreView examples
Choose default vaultSet-SecretVaultDefault -Name LocalStoreView examples
Store a SecureStringSet-Secret -Name ApiToken -Secret (Read-Host 'Token' ` -AsSecureString) -Vault LocalStoreView examples
Store a credentialSet-Secret -Name ServiceCredential -Secret ` (Get-Credential) -Vault LocalStoreView examples
Prevent accidental overwriteSet-Secret -Name ApiToken -Secret $Token -Vault ` LocalStore -NoClobberView examples
Retrieve a protected value$Token = Get-Secret -Name ApiToken -Vault LocalStoreView examples
List metadata onlyGet-SecretInfo -Vault LocalStoreView examples
Convert only at boundary$Value = Get-Secret -Name ApiToken -Vault LocalStore ` -AsPlainTextView examples
Unlock SecretStoreUnlock-SecretStore -Password (Read-Host 'Vault password' ` -AsSecureString)View examples
Require password promptsSet-SecretStoreConfiguration -Authentication Password ` -Interaction Prompt -Confirm:$falseView examples
Replace a secretSet-Secret -Name ApiToken -Secret $Replacement -Vault ` LocalStoreView examples
Remove a secretRemove-Secret -Name RetiredToken -Vault LocalStore ` -WhatIfView examples
Unregister a vaultUnregister-SecretVault -Name LocalStore -WhatIfView examples

SecretManagement supplies a common command surface over extension vaults; SecretStore is Microsoft's local, current-user vault extension. As of 2026 the modules are feature-complete and receive only security and critical fixes, with latest published versions 1.1.2 and 1.0.6 respectively. A vault reduces accidental exposure but does not solve identity, authorization, rotation, recovery, or host compromise. Choose a vault appropriate to interactive or unattended use and minimize every plaintext lifetime.

Step by step

Detailed examples

01

Install and register per-user vault tooling

SecretManagement and SecretStore are Gallery modules for supported Windows PowerShell 5.1 and PowerShell 7 environments, not built into every installation. The documented latest versions are SecretManagement 1.1.2 and SecretStore 1.0.6; they are feature-complete rather than actively developed. Installation normally needs repository and module-path write rights but no Windows role, domain membership, elevation, remote service, or reboot when installed for the current user. Verify repository trust and package signatures. Registration is per-user and does not migrate secrets or grant service identities access.

Install reviewed versions and register a local vault
# Run only after repository and package provenance review.
Install-PSResource Microsoft.PowerShell.SecretManagement -Version 1.1.2
Install-PSResource Microsoft.PowerShell.SecretStore -Version 1.0.6
Import-Module Microsoft.PowerShell.SecretManagement
Register-SecretVault -Name LocalStore `
    -ModuleName Microsoft.PowerShell.SecretStore -DefaultVault
Back to quick reference ↑
02

Treat registrations as routing metadata

SecretManagement routes commands to extension modules. Get-SecretVault shows registrations, not an inventory of remote access rights or stored values. A default vault removes ambiguity only for the current user; production scripts should usually specify Vault explicitly. Test-SecretVault behavior depends on the extension and may contact an external service. Register, default, test, and unregister cmdlets support WhatIf in documented parameter sets, but backend-specific calls can still prompt or perform reads.

Inventory and test vaults explicitly
$Vaults = Get-SecretVault
$Vaults | Select-Object Name, ModuleName, IsDefaultVault
foreach ($Vault in $Vaults) {
    [pscustomobject]@{ Name = $Vault.Name; Healthy = Test-SecretVault -Name $Vault.Name }
}
# Set-SecretVaultDefault -Name LocalStore -WhatIf
Back to quick reference ↑
03

Create secrets without literals or pipeline leakage

Set-Secret accepts byte arrays, strings, SecureString, PSCredential, and hashtables, although an extension vault may support fewer types. Prompt interactively or obtain values from an approved bootstrap identity; never put secret literals in scripts, command-line arguments, transcripts, CI variables that echo, or shell history. NoClobber protects initial creation from an accidental overwrite, subject to the vault's name matching rules. SecretStore names are case-insensitive.

Store a credential and metadata safely
$Credential = Get-Credential -Message 'Service identity credential'
try {
    Set-Secret -Name ServiceCredential -Secret $Credential `
        -Vault LocalStore -NoClobber -Metadata @{ Owner = 'Platform'; Purpose = 'API' }
}
finally { Remove-Variable Credential -ErrorAction SilentlyContinue }
Back to quick reference ↑
04

Retrieve the narrowest value needed

Use Get-SecretInfo for discovery because it avoids loading values. Get-Secret returns the stored type, such as SecureString or PSCredential. Keep it in a local variable only long enough to pass to a command that supports that type, avoid formatting or verbose splats that reveal it, and remove references afterward. PowerShell memory is not a hardened secret enclave, and an administrator or compromised process can often inspect the session or impersonate its identity.

Use a stored credential without plaintext conversion
$Credential = Get-Secret -Name ServiceCredential -Vault LocalStore
try {
    Invoke-Command -ComputerName 'server01.contoso.example' `
        -Credential $Credential -ScriptBlock { Get-Date }
}
finally { Remove-Variable Credential -ErrorAction SilentlyContinue }
Back to quick reference ↑
05

Make plaintext conversion an explicit boundary

AsPlainText is convenient but creates an ordinary String that can be copied, logged, interned, dumped, or retained. Use it only for an API that cannot accept SecureString, PSCredential, or a token callback. Do not pass plaintext on a process command line because other users or telemetry may observe it. Redact exception messages and HTTP headers. Removing a variable shortens accidental exposure but does not guarantee memory erasure.

Constrain plaintext lifetime around an API boundary
$PlainToken = Get-Secret -Name ApiToken -Vault LocalStore -AsPlainText
try {
    $Headers = @{ Authorization = "Bearer $PlainToken" }
    Invoke-RestMethod -Uri 'https://api.example.com/health' -Headers $Headers
}
finally {
    $Headers.Clear(); Remove-Variable PlainToken -ErrorAction SilentlyContinue
}
Back to quick reference ↑
06

Choose interactive or unattended SecretStore behavior

SecretStore is local to the current user and encrypts its data with .NET cryptography. Authentication can be Password or None; interaction can be Prompt or None, with a password timeout. Password plus Prompt suits interactive sessions. Unattended automation cannot respond to prompts, while Authentication None weakens protection to the security of the Windows account and machine. Set-SecretStoreConfiguration can reset the store in some parameter sets, which is destructive; back up recovery material and test the exact identity and logon context first.

Inspect configuration before proposing a change
$Current = Get-SecretStoreConfiguration
$Current | Select-Object Scope, Authentication, PasswordTimeout, Interaction
# Interactive user scenario only; changes configuration:
# Set-SecretStoreConfiguration -Authentication Password `
#     -Interaction Prompt -PasswordTimeout 900 -Confirm:$false
Back to quick reference ↑
07

Rotate atomically and revoke at the source

A useful rotation creates the replacement at the upstream service, stores and verifies it, moves consumers, then revokes the old credential. Simply overwriting a vault entry does not invalidate the old token. Set-Secret overwrites by default; use NoClobber only for creation. Remove-Secret deletes the vault entry but not cached copies, downstream sessions, or the external credential. WhatIf previews SecretManagement routing but cannot prove the extension's entire external behavior, so test the chosen vault.

Stage a rotation without displaying either value
$Replacement = Read-Host 'Replacement token' -AsSecureString
try {
    Set-Secret -Name ApiToken.Next -Secret $Replacement -Vault LocalStore -NoClobber
    if (-not (Get-Secret -Name ApiToken.Next -Vault LocalStore)) { throw 'Verification failed' }
    # Move consumers, revoke old token upstream, then remove old entries in an approved runbook.
}
finally { $Replacement.Dispose() }
Back to quick reference ↑
08

Plan identity, backup, and recovery before automation

A scheduled task, service account, remoting endpoint, and interactive administrator are different users with different vault registrations and profiles. Configure and test the vault under the exact execution identity. SecretStore is not a multi-user enterprise key vault, and unregistering it removes routing metadata rather than guaranteeing data deletion. Document how to recover or replace every external secret if the host, user profile, vault password, or backing store is lost. Prefer workload identity or federated credentials when supported.

Preflight the automation identity and vault
[pscustomobject]@{
    Identity = [Security.Principal.WindowsIdentity]::GetCurrent().Name
    Edition = $PSVersionTable.PSEdition
    PowerShell = $PSVersionTable.PSVersion.ToString()
}
Get-SecretVault | Select-Object Name, ModuleName, IsDefaultVault
if (-not (Test-SecretVault -Name LocalStore)) { throw 'Vault test failed' }
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Microsoft LearnGet started with the SecretStore modulelearn.microsoft.com
  2. Microsoft LearnMicrosoft.PowerShell.SecretManagement modulelearn.microsoft.com
  3. Microsoft LearnMicrosoft.PowerShell.SecretStore modulelearn.microsoft.com
  4. Microsoft LearnSet-Secretlearn.microsoft.com
  5. Microsoft LearnGet-Secretlearn.microsoft.com
  6. Microsoft LearnSet-SecretStoreConfigurationlearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback