Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide

Quick Answer: To deploy PowerShell scripts via SCCM (ConfigMgr) without traditional packaging, use the built-in Run Scripts feature. Navigate to Software Library > Scripts > Create Script, paste your PowerShell code, approve the script (under a separate administrator account or with approval restrictions disabled), right-click a target device collection, select Run Script, and monitor real-time client results in the Script Status dashboard.

Managing devices at scale can be challenging, but SCCM simplifies this by allowing you to deploy PowerShell scripts directly to client machines. Whether you’re installing applications, modifying configurations, or collecting data, this feature is invaluable. Let’s walk through the process.

Prerequisites

Before you begin, ensure the following: 

  • SCCM Version: Your SCCM environment should be running version 1706 or later.

  • Client Requirements: Targeted client devices must have PowerShell version 3.0 or higher installed.

  • Permissions: You need appropriate permissions to create, approve, and run scripts within SCCM.

Step 1: Create the PowerShell Script

  1. Open the SCCM Console: Launch the SCCM console and navigate to the Software Library workspace.

  2. Access Scripts: In the left-hand pane, expand Software Library > Scripts.

  3. Create New Script:

    • On the Home tab, click Create Script.Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

    • In the Create Script wizard:

      • Script Name: Enter a descriptive name for your script.

      • Script Language: Select PowerShell.

      • Script Content: Paste your PowerShell code into the provided field.

POWERSHELL • Create-LocalUser.ps1
# Define Username and Secure Password
$username = "TechEUC"
$password = ConvertTo-SecureString "TechEUC.com!" -AsPlainText -Force

# Create the Local User Account
try {
    New-LocalUser -Name "$username" -Password $password -FullName "$username" -Description "TechEUC Test User" -ErrorAction Stop
    Write-Output "Local user '$username' created successfully."
    exit 0
} catch {
    Write-Error "Failed to create user: $_"
    exit 1
}

“Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

  • Click Next, review the summary, and then click Close to finish

 

Step 2: Approve the Script

  1. Select the Script: In the Scripts list, click on the script you just created.

  2. Approve Script:

    • On the Home tab, click Approve/Deny.

    • If you notice the Approve/Deny option is greyed out, then we need to allow the Author to approve own scripts.Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

    • Go to your Administration / Site / Hierarchy Setting. Then Disable “Script Authors require additional script approver”Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

    • Now the Approve/Deny option should be enabledDeploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

    • In the Approve or deny script dialog box:

      • Select Approve.

      • Optionally, enter a comment regarding the approval.

    • Click Next, review the summary, and then click Close.Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

Note: By default, script authors cannot approve their own scripts. This setting can be modified in the Hierarchy Settings if necessary

Step 3: Run the Script on Target Devices

  1. Navigate to Device Collections: In the SCCM console, go to Assets and Compliance > Device Collections.

  2. Select Target Collection: Right-click on the device collection you wish to target and choose Run Script.Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

  3. Choose Script:

    • In the Run Script wizard:

      • Select the approved script from the list.

      • Click Next.

      • Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

    • Review the summary and click Next to initiate the script deployment.

    • Click Close to exit the wizard.

Note: Scripts are executed immediately on online clients. Offline clients will execute the script once they come online, within a one-hour window.

Step 4: Monitor Script Execution

  1. Access Script Status: In the SCCM console, navigate to Monitoring > Script Status.

  2. Review Results:

    • Locate the script you ran in the list.

    • Click on it to view detailed execution results, including success rates and any error messages.

    • Deploying PowerShell Scripts via SCCM: A Step-by-Step Guide - Deploying Powershell Scripts Via Sccm A Step By Step Guide

Note: A script exit code of 0 typically indicates successful execution

Related SCCM & Automation Guides:

Next Steps in Production

When operationalizing SCCM Run Scripts across enterprise environments:

  • Dual-Administrator Approval: In production hierarchies, ensure script approvers differ from script authors to maintain security compliance.
  • Fast Channel Verification: Ensure client communication utilizes BGB (Big Green Button) fast notification channel so scripts trigger within seconds rather than waiting for machine policy intervals.
  • Output Sizing: Keep script standard output under 4 KB to prevent truncation in the SCCM administrative console and SQL reporting tables.
TechEUC - Atoofa Shaikh
FIVERR PRO VERIFIED 12+ YRS EXPERIENCE

Atoofa Shaikh

Senior Microsoft 365, EUC & Cloud Endpoint Architect

Need custom Win32 App Packaging, PowerShell Automation, Zero-Touch Intune Autopilot, or SCCM Co-Management for your enterprise or MSP? I specialize in production-grade deployment architectures with zero downtime.