Support

Support forum for Devolutions PowerShell Universal

avatar

realslacker

Using the API to enter and leave maintenance?

We have scheduled database server maintenance and we can script a pre and post action. I would like to use the API to enter and leave maintenance on all of the PSU servers while the database server is down. I've tried calling PUT /api/v1/computer?id={id}&maintenance=true however this just results in a new computer object being created in the database, so I can't imagine this is the correct way to do this.

36

3

avatar

Adam Driscoll

avatar

krle

SSH keys are broken in 2026.3.2 - maybe earlier

Hi, Trying to setup github integration from one of our PSU containers, but its failing. [image] Tried with: New SSH keys and added it to github as deploy keys Ensured that the pod / container have access to github.com on port 22 Cleared the .git folder in the Repository folder Deleted the git settings, and then created a new key and tried to enable git again The notifications is showing: SSH key error: The configured SSH key is invalid or not accepted by the remote. Verify your SSH key configuration. But the key was created in PSU itself, and the public key was copied to github and ensured it have Read/Write

53

8

avatar

Adam Driscoll

avatar

tholabrk

User language settings, a way to persist?

Hi, I think it's great that PSU supports localization, especially for some of our users, but it becomes very disorienting for me as an administrator. When I change it from my language back to English, it is automatically set back to Danish the next time i open PSU. From reading some documentation i can understand it's using the browser locale, but this is currently being enforced by my organization, is there any other way to change it as a user, without affecting localization in PSU as a whole?

31

2

avatar

tholabrk

avatar

realslacker

2026.3.1 has been a disaster, what are the implications for rolling back to 2026.2.x?

Do I need to worry about database schema? Can I just install 2026.2.5 and be up and running?

94

3

avatar

rubentapia

avatar

Matthew Morrow

[2026.3.2.0] Set-PSUCache not working in 'apps'

i am still having trouble with set-psucache, "Permission denied. The role specified does not have access to this resource." adding -Integrated does not help [image]

44

6

avatar

rubentapia

avatar

scheived

API endpoints can't be edited using VS Vode

Editing an API endpoint using VS Code and PSU Extension doesn't work. When creating an API endpoint I tried supplying a Path: testendpoint.ps1. However in vs code the file it seems to be editing is not the file live on powershell universal. How is this supposed to work?

109

10

avatar

viktorkiss

avatar

viktorkiss

Bug or undocumented procedure - file system watcher

Dear team, I experienced some behavior which I can't tell if the feature works as expected and it's just not documented or if it's a possible bug. Findings According to the official docs the file system watcher is activated by default and from what I saw in the UI you can either chose to enable / disable " Auto-reload ". With the "auto-reload" and file system watcher enabled, my understanding would be that if I make some changes through an editor on the file itself and save the changes, my changes should applied automatically. To test this, I added a new endpoint to the default endpoints.ps1 file (no custom path) by simply editing and saving the file on the local instance through VSCode. Regardless if the "auto-reload " feature is enabled or disabled while I do see the changes in the history tab: [image] Before config the reload: Get-PSUEndpoint -UseDefaultCredentials | Select-Object -Property Url Url --- /VSCodeExtensionTest/defaultEndpointsFile /VSCodeExtensionTest/customEndpointsFile /FileWatcherTest/defaultEndpointsFile /FileWatcherTest/newEndpointAgain After the config reload: Get-PSUEndpoint -UseDefaultCredentials | Select-Object -Property Url Url --- /VSCodeExtensionTest/defaultEndpointsFile /VSCodeExtensionTest/customEndpointsFile /FileWatcherTest/defaultEndpointsFile /FileWatcherTest/newEndpointAgain /FileWatcherTest/newEndpointPSModuleCheck # <-- manually added endpoint However, the newly added endpoint doesn't show up in the APIs->Endpoints section (neither in the PSU Admin UI nor if I check it through the PSU PowerShell module) until I explicitly reload the endpoints configuration: [image] If I check the endpoints.ps1 in the UIs Settings->Files section though, I see the changes I made previously even before the config reload so assume that it isn't a permission issue or a user error. Setup PSU Version: Version 2026.2.4 Developer License (although issue seems to be identical on our productive server) Windows Server Version 24H2 (OS Build 26100.33158) VSCode Version: 1.134.0 Questions Since I couldn't find further details in the official docs it raises some questions for me: Does this feature work as expected? If so, what exactly does the "auto-reload" feature / explicit "Pending Reload" actually apply / change? Could you point me out where I can find more detailed infos in the official docs? If it's not and a bug: Is it already a known issue and if so is there an ETA for the fix? Please let me know if you need any further infos and thank you in advance for your efforts. Best regards, Viktor

93

5

avatar

viktorkiss

avatar

Matthew Morrow

sign out on nested IIS goes to 404

nested IIS site is missing after logout however mike has a server that does work, mine does not 26.3.1.0

66

10

avatar

Adam Driscoll

avatar

russellreid1

error in vs code extension after upgrade to 2026.3.0

I just updated my local developer instance to 2026.3.0 so i can use the updated vs code extension. the automatic instance discovery worked and it shows me the connection. but when i try to drill into the apps or settings i get an error: "Failed to connect to http://localhost:5006. PSU request failed (400 Bad Request): An HTTP/1.x request was sent to an HTTP/2 only endpoint." The remote connection to the instance on my jumpbox connects without error. That is also upgraded to 2026.3.0. So local connection errors but remote does not. Not sure what this error means. i did a search on the net for this related to vs code but there are no settings in vs code for HTTP/1.x or HTTP/2. Any ideas on how to resolve?

75

9

avatar

russellreid1

avatar

Mordecai

An early API login as the configured default admin permanently prevents the local admin account from being created (the web UI is protected, the API is not)

Hi, i found a "strange" bug that i was finally able to reproduce on different containers about the local admin creation (troubleshooting was done in relation `Set-PSUIdentity -Password` does not update `PasswordLastSet` (the reset page does) - Devolutions Forum ) ENVIRONMENT PowerShell Universal: 2026.2.5 Host: Linux container (Rocky-based image), PowerShell 7.6.3 Database: SQLite, empty (first run) Configuration: PSUDefaultAdminName / PSUDefaultAdminPassword set via environment SUMMARY On a first run against an empty database, PowerShell Universal creates the local administrator account from PSUDefaultAdminName / PSUDefaultAdminPassword roughly 110 seconds after the service starts (slow developer notebook with a lot of containers too). If an authentication request using that same user name reaches the API before then (READ or Get-PSUIdentity), the ClaimsEvaluator inserts a claims identity under that name, and the first-run creation afterwards fails: ClaimsEvaluator psu_admin is not in the database. Adding identity. System.Exception: Identity 'psu_admin' already exists. at PowerShellUniversal.Authentication.IdentityService.CreateIdentity(Identity identity) in .../PowerShellUniversal.Authentication/IdentityService.cs:line 120 The instance is left with an identity of that name that is not a local account and has no password. Nobody can log in with it, and a restart does not repair it, because PSUDefaultAdmin* are only consulted while no administrator account exists - and now one does. The database has to be recreated. THREE RUNS, SAME IMAGE, ONLY THE EARLY REQUEST DIFFERS Run During startup Identity table afterwards ----------- --------------------------------- -------------------------------------- control nothing psu_admin LocalAccount=1, password set API basic auth as psu_admin at ~t+79s psu_admin LocalAccount=0, no password browser repeated visits to the login page psu_admin LocalAccount=1, password set The browser run could not reproduce it, and that appears to be by design: for the whole startup window GET /login answers 302 to /first-run, which shows "PowerShell Universal is starting..." and offers no login form. The user is simply held there until the account exists. Basic authentication against the API has no such gate. Polled every 3 seconds from the first second, GET /api/v1/accessible with the admin name and password returned: t+ 0s 401 (server not up) t+ 79s 200 <-- account does not exist yet; this is the request that breaks it t+148s 401 STEPS TO REPRODUCE 1. Start an instance with an empty database and PSUDefaultAdminName/Password set. 2. From the first second, send basic-auth requests with that user name to any API endpoint - we used GET /api/v1/accessible. 3. Let startup finish, then inspect the Identity table or try to log in. EXPECTED An authentication attempt should not be able to prevent the account from being created. Either the first-run creation wins, or it completes the existing identity into a local account. A 200 for an account that does not exist yet also looks wrong on its own. IMPACT Easy to hit unintentionally on a new deployment: a health check, a monitoring probe or a deployment script that authenticates as the admin during the first two minutes is enough, and the damage is permanent for that database. We hit it with an automated readiness check; interactive users never did, because the /first-run gate protects them. QUESTION Is there a supported way to recover an instance already in this state, short of recreating the database - for example removing the identity and restarting? Thanks, René

33

1

avatar

rubentapia

avatar

lloydmitchell

Resolved

Assembly loading error after trying to connect to Exchange Online in script when calling from app

UPDATE: Solved - see my follow up Struggling with this one! I have a script that pulls mailbox details from Exchange Online using a certificate and app-registration in Azure (so it's non-interactive, but don't think this is relevant). The script runs by itself (directly) without issue. However, if I try and call it from an app I get an error. Command: $session:UserMailbox = Invoke-PSUScript -Name 'Exchange\Get-ExoMailbox.ps1' -Parameter @{ Email = ($session:User).mail } -Wait -TrustCertificate -Environment 'PowerShell 7 - Exchange' Error: Could not load file or assembly 'Microsoft.Exchange.Management.ExoPowershellGalleryModule, Version=15.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35'. Assembly with same name is already loaded I've specified different environments for both app and script, so should be in their own runspaces. But the error seems to indicate otherwise... The 'PowerShell 7 - Exchange' environment is set to load the ExchangeOnlineManagement module. I've also tried loading it directly in the script. Either way, same problem. Version: 2026.2.4

32

1

avatar

lloydmitchell

avatar

btull

AntDesign Issues

Get-PSUInformation Version BuildVersion ------- ------------ 2026.2.2 28618653519 Currently having some issues with styles/themes. While looking at the build in '/Apps/Docs' Buttons page the colors listed are very differently from the standard AntDesign theme. Currently trying to achieve the button colors from that page but I can't seem to find the best way in the MaterialUI file. [image] [image] (The 'success' button is currently being hovered over and is slightly darker than normal) Currently, in my setup, the 'success' and 'error' do not change font color, nor does the hover make the color darker, it actually uses the standard 'blue' color somehow. [image] Has anyone found a good way to mimic this using AntDesign? I was able to edit the borderRadius in the MUI file to round the buttons to match.

43

4

avatar

rubentapia

avatar

denistiri

Implemented

Did $EventData in UDSelect change in 2026.3.0.0?

After updating to 2026.3.0.0 a screen didn't work for me anymore. After debugging I found that the $EventData variable in the -onchange of the UDSelect now returns "string" instead of string. So it includes double quotes in the variable itself. So if I use my UDSelect to select for instance value abcdef then "abcdef" gets returned instead of abcdef in the $EventData So char 34 in front and in the back. Is this by design? I fixed my screen by inserting a .Trim('"') later in the code where I needed that variable.

66

6

avatar

rubentapia

avatar

Matthew Morrow

Implemented

setting "SecurityModel": "Integrated", makes me use -Integrated

i get an error when i use set-psucache in a script i shouldnt have to use ` -Integrated` to get my script to run, error: 15:43:52.003 ERROR Invalid URI: The format of the URI could not be determined. 2026.3.1.0 --- even with copilot i do not feel like making 120+ code changes

42

2

avatar

Matthew Morrow

avatar

simon

Problem with Modules on PSU Host

Hello, I've upgraded to the latest PSU Version 2026.3.0 and now the Scripts using installed modules on the PSU Host cannot be found anymore. I'm getting the following error: [image] Inside the script im just using the Connect-MgGraph cmdlet. Running the script on the Host directly in Power Shell works without problems, also running the cmdlets works. In Manage > Modules in PSU the Modules are available for both integrated and Power Shell 7 Environments: [image] [image]

61

5

avatar

rubentapia

avatar

Mordecai

`Set-PSUIdentity -Password` does not update `PasswordLastSet` (the reset page does)

Hi Support, we have found a problem with the Password Reset for the builtin/local admin account and documentation issues. Title: Set-PSUIdentity -Password does not update PasswordLastSet (the reset page does) ENVIRONMENT PowerShell Universal: 2026.2.5 Host: Linux container (Rocky-based image), PowerShell 7.6.3 Database: SQLite (default) Client: PowerShell 7.5 on Windows, management API via -ComputerName / -Credential Settings: PasswordExpirationDays = 1095, PasswordLength = 12 Account: local account, Administrator role, created at first run from PSUDefaultAdminName / PSUDefaultAdminPassword SUMMARY Two ways of changing a local account's password behave differently, and only one of them keeps the expiration clock consistent: Path Password changes PasswordLastSet updated --------------------------- ---------------- ----------------------- /reset-password page yes YES Set-PSUIdentity -Password yes NO Because expiration is evaluated against PasswordLastSet, an account whose password is rotated programmatically will still be forced through the reset page once the configured period elapses - even though its password was changed the day before. STEPS TO REPRODUCE 1. Configure PasswordExpirationDays. 2. Note PasswordLastSet: Get-PSUIdentity | Where-Object Name -eq '<name>' 3. Set-PSUIdentity -Id <id> -Password (ConvertTo-SecureString '<new>' -AsPlainText -Force) 4. Confirm the change took effect - the new password authenticates, the old one returns 401. 5. PasswordLastSet is unchanged. Verified both through Get-PSUIdentity and by reading the Identity table in the SQLite database directly, across two changes on the same day. 6. For contrast, set PasswordLastSet to a date beyond the expiration period, log in through the web UI, and complete the reset the product offers. PasswordLastSet is updated correctly. EXPECTED Set-PSUIdentity -Password updates PasswordLastSet, exactly as the reset page does. Your release notes suggest the same gap existed elsewhere and was fixed. From 2025.11.0: "Fixed an issue where the ResetAdminAccount environment variable process would not set PasswordLastSet". SECOND OBSERVATION, POSSIBLY BY DESIGN With PasswordLastSet beyond the expiration period, the two entry points disagree: - The login page redirects to /reset-password with "Your password has expired." - Basic authentication against GET /api/v1/accessible still returns 200 with that same expired password, before and after a service restart. Is the API deliberately exempt from expiration, or is the check not applied on that path? DOCUMENTATION NOTE The Local Accounts page (https://docs.devolutions.net/powershell-universal/security/local-accounts) states that for an account created from PSUDefaultAdminName / PSUDefaultAdminPassword "password restrictions are not enforced", and describes expiration on that same page as one of those restrictions. Such an account does expire, as the redirect above shows. PasswordExpirationDays and PasswordLength also exist as Set-PSUSetting parameters but appear nowhere in the documentation. Thanks for your support, René

33

1

avatar

Adam Driscoll

avatar

mfutrowsky

PowerShell Universal on offline system

Trying to run PowerShell Universal on offline system (Windows 2022) and can't get past the first run. Version 2026.3 just sticks on a website with a black square in the top left with "Connecting" or "Reconnecting". Using 2025.2.3 results in a full black page. Only issue in the log file is that it can't check for an update or connect to devolutions.net:443.

34

1

avatar

rubentapia

avatar

wwong1

PowerShell Universal 2026.3 - Official gMSA Support and Recommended Installation Configuration

We are an existing PowerShell Universal Enterprise customer from Ironman Software and are currently planning/upgrading our deployment to PowerShell Universal 2026.3. We would like clarification on Devolutions' current support stance and recommended configuration for using a Group Managed Service Account (gMSA) with PSU. Specifically, can you confirm the supported and recommended configurations for the following? Running the PowerShell Universal Windows service itself under a gMSA Is this officially supported in PSU 2026.3? Are there any known limitations compared with running the service as LocalSystem? Are there specific Windows rights, filesystem ACLs, registry permissions, or other configuration requirements that should be applied? Using gMSAs for RunAs / automation execution Is the recommended model to run PSU itself as LocalSystem and use separate gMSAs for scripts, endpoints, or jobs that need domain access? Can RunAs gMSAs be used when the PSU service itself is running under another gMSA or traditional domain service account? Are there any restrictions on this configuration in 2026.3? Secret Management Are there known limitations with PowerShell SecretManagement / SecretStore when the PSU service runs under a gMSA? Does the built-in PSU secret functionality fully support a gMSA service identity, including after automatic gMSA password rotation? Are there any vault types or configurations that you recommend or specifically discourage when PSU runs under a gMSA? Known-good / recommended installation pattern If available, could you provide the currently recommended enterprise deployment pattern for PSU 2026.3 where domain resources such as Active Directory, SQL Server, file shares, etc. need to be accessed? For example, is the preferred architecture: LocalSystem -> PSU -> RunAs gMSA(s) for privileged/domain actions or PSU gMSA -> domain resources directly or another configuration? I have reviewed the documentation and searched the Ironman Software forums. There are several older discussions where users report successfully using gMSAs, including password-less RunAs credentials, but there also appear to be issues or caveats around the PSU service identity, RunAs behavior, and Secret Management. Before we standardize our 2026.3 installation, we would like to understand the officially supported and tested configuration from Devolutions , rather than relying on older community posts. Thanks.

77

4

avatar

rubentapia

avatar

paulcaligari

Workflow activities missing activity options

I'm running a licensed version 2026.2.3 of Powershell Universal Server. I am looking to set up some workflows for chaining some scripts together which have some dependencies on each other. For some reason I don't see all of the Activity options available under the Activity Palette. I only see the Ai Prompt Activity, the Parallel and Decision activities are not listed. I would like to create a workflow with the Parallel activity. Does this require some additional licensing? Many thanks for any advice. [image]

19

1

avatar

rubentapia

avatar

mshepard70

Operator role required for Get-PSUCache in 2026.2.1?

It seems like we need the operator role in order for users to execute Get-PSUCache in an app in 2026.2.1. Line 15 in the function is a Get-PSUCache call ( $CPM = Get-PSUCache -Key CPM ) [9/21/2026 10:08:11 AM] [Error] [App-CRM Banking Dashboard] at Get-CPMTable, E:\psuSites\JHBDashboard_data\UniversalAutomation\Repository\dashboards\CRMBankingDashboard\modules\CPMBackEnd\1.0.0\Public\Get-CPMTable.ps1: line 15 at dynamicCPMTable: line 4 at dynamicCPMTable: line 3 at dynamicCPMTable: line 1 at CPM.ps1 [9/21/2026 10:08:11 AM] [Error] [App-CRM Banking Dashboard] Permission denied. The role specified does not have access to this resource. [File]: CPM.ps1 [Endpoint]: dynamicCPMTable [Page]: b1c7879d-5fea-4f55-8d58-66bc9a85dc0d The description for Operator says it can add or remove psu resources like scripts or endpoints. That seems like way too much power for someone who needs to access cache programmatically.

34

5

avatar

rubentapia

avatar

denistiri

Continuous workflow runs steps at same time instead of step by step?

I have this problem where I defined a workflow with 4 steps in a continuous schedule, but at least two steps run simultaneously. Not only in this screen, but I can see live in the Job log due timestamps on that they are actually running at same time. [image]

48

6

avatar

denistiri

avatar

bmetz

Resolved

Fallback License

I have a PowerShell Universal Subscription for individuals that will be expiring soon. I am on 5.6.13 and am wondering what is going to happen after my subscription expires. $100 a year was perfectly fine but $500 is just too much for just me. When I purchased the software several years ago it said I would have a fallback perpetual license will that take over so I can continue using the product. Will it fallback to that still? I wanted to open a standard support ticket but it now says I do not have an account on the support portal and I saw no way for an older customer like me to create one.

45

1

avatar

Marc-Antoine Dubois

avatar

davestephenson

Resolved

Does anyone know what "-PaperStyle" can be used for in Show-UDModal?

I'm working on redesigning one of our wizard driven experiences and had a crazy thought of putting a "translucent wallpaper" behind the modal so it could dynamically display the Hypervisor they're working in/on. Show-UDModal | Devolutions PowerShell Universal | Product guides & reference [image] Here is a rough thing I put together in a screenshot tool. Obviously, the images would be more transparent as to not interfere with the form. But, I think you get the idea. [image]

43

2

avatar

davestephenson

avatar

daniel2

Editing script code after changing to edit mode

Hi. We have our PSU git connection set up to manual commits, so if we haven't first klicked the "Edit" button we can't edit scripts but just view them. This is perfectly fine, the problem is that when I'm viewing a script and then click "Edit" I still can't edit the script without first leaving the script and then going back to it. Is this intended behaviour or just a glitch? The buttons on the top row changes, so I can for example edit script properties, but not the code itself, it still says "Cannot edit in read-only editor". This is on version 2026.2.3

75

5

avatar

daniel2

avatar

KST

Resolved

Developer licenses no longer exists in latest versions? (coming from 5.5.2)

Hello, I am a paying customer with 2 licenses. One for each environment (labo/prod). I have some developer zip instances that i run on a separate machine. They are only used for development. I used to generate a dev license for this from within the PSU interface. The last 8 months I haven't been available to develop more in PSU but now I have. I updated one of those zip instances to the latest version just to explore. I can no longer find the option to create a dev license. I found a page https://devolutions.net/powershell-universal/?fromPsu that seems to offer a dev license but i don't see where? If i press download it just offers the same page i used to download the original zip i used to update the dev instance. What am i missing?

Recommended Answer

10 days ago

Hello KST, Upgrading to the latest version of PowerShell Universal (2026.1 or better) the dev licence requires a Devolutions account on our portal. Here's the procedure to create your account : https://docs.devolutions.net/portal If you are still not able to retrieve the licence, you can contact us directly at sales@devolutions.net and we will help you with this! Thanks,

71

2

avatar

KST

1 - 25 of 1995 items