Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Severity Level: Warning
Default state: Always enabled
Description
This rule detects the AllowUnencryptedAuthentication parameter used with Invoke-WebRequest and
Invoke-RestMethod cmdlets. When AllowUnencryptedAuthentication is used, it permits credentials
and secrets to be transmitted over unencrypted connections, creating a security risk.
Avoid using this parameter unless you must maintain compatibility with legacy systems that require unencrypted authentication.
To learn more, see Invoke-WebRequest and Invoke-RestMethod.
Example
Noncompliant
Invoke-WebRequest foo -AllowUnencryptedAuthentication
Compliant
Invoke-WebRequest foo
Configure rule
This rule is always enabled and isn't configurable. Use one of the following methods to avoid using this rule:
- Create a custom rule configuration file to include only the rules you want or exclude the rules you don't want.
- Add the appropriate rule suppression attributes to your code to suppress the rule for specific code blocks. For more information, see the Suppressing rules section of Using PSScriptAnalyzer.