I would like to propose an enhancement to the existing "Override credentials" feature in the Mass Config Push Advanced Settings. Currently, we can manually type or paste text into the username/password override fields. I would love to see an option to select already Stored Credentials from a dropdown list instead.
While I understand the previous decision to keep things simple (as discussed in the older "Run As" thread), the manual text override introduces a few challenges in daily enterprise operations:
- Security & Password Exposure: Manually copying and pasting highly privileged administrative passwords increases the risk of exposure (e.g., via clipboard history or accidental screen sharing).
- Password Rotation Complexity: In environments where admin passwords are rotated regularly, manual overrides become high-maintenance. If we could link the push to a Stored Credential set, we would only need to update the password once globally, and all corresponding push tasks would automatically use the updated password.
- Audit and Compliance: Selecting an existing object (Stored Credential) keeps configuration jobs cleaner and easier to audit compared to hardcoded text overrides.
Thank you for considering this enhancement!