Using variables in a shell app script
Shell app scripts receive variables as PowerShell parameters, not as ambient variables. The script must declare a Param() block matching the variables it uses:
[CmdletBinding()]
Param (
[string] $SecureVar_Variable1,
[string] $InheritedVar_Variable1,
[string] $EnvironmentalVar_TenantId
)
Variable prefixes for shell apps are singular, with an underscore: $SecureVar_, $InheritedVar_, $EnvironmentalVar_. Referencing a variable in the script body without declaring the corresponding parameter does not raise an error -- the value is simply unavailable.
Once a parameter block is present, the script editor detects and validates the variables used and reports their status (healthy/unhealthy, unknown variable names).
Nerdio Manager allows you to manage Global Secure Variables. These secure variables can be passed to scripted actions or shell apps. The variables are stored securely in the Azure Key Vault and can be passed to scripted actions using the $SecureVar.Variable_Name variable name.
Note
Secure variables are not supported for shell apps targeting Intune-managed devices. If a shell app version references a secure variable, it does not appear as a selectable app when creating a deployment policy for Intune devices -- there is no error message; the app is simply absent from the list. Use an inherited variable instead, or target the credential to AVD session hosts or Azure VM-based devices only.
Tip
This feature is especially helpful if you want to pass sensitive information to a scripted action without passing it via clear text.
Secure variables limitations
The following are the limitations of secure variables.
Variable names
-
20-character limit
-
Alphanumeric characters are allowed
-
Hyphens - are allowed
-
Underscores _ are not allowed
-
Special characters and punctuation are not allowed (for example, ~!@#$%^&*()[]{},.<>/?\|`)
Variable values
-
Alphanumeric, special characters, punctuation, underscores, and hyphens are all allowed
To manage global secure variables:
-
At the MSP or Account level, navigate to System > System Settings > Integrations.
-
In the Secure, Inherited and Environment variables for scripted actions area, select the action (add, edit, or remove) you wish to perform.
-
To add or edit a global secure variable, enter the following information:
-
Name: Type the name of the variable.
Note
The variable name must be between 1 and 20 alphanumeric characters.
-
Value: Type the variable's value.
-
Variable type: Select the desired variable type.
-
Allow usage within shell apps: Select this option to make the variable available in Shell Apps.
-
Windows scripts: From the drop-down list, select which Windows scripted action(s) the variable is passed to.
-
Azure runbooks: From the drop-down list, select which Azure runbooks the variable is passed to.
Note
If no scripts are selected, the variable is not passed to any script. The default value is All Scripts.
-
-
When you have entered the desired information, select OK.
To copy the Shell Apps variable name to the clipboard:
-
At the MSP or Account level, navigate to System > System Settings > Integrations.
-
In the Secure, Inherited and Environment variables for scripted actions area, locate the variable you wish copy. .
-
Select the Shell Apps copy icon to copy the variable name to the clipboard. For example, $SecureVar_BPCustomerUID.
Comments (0 comments)