`Set-PSUIdentity -Password` does not update `PasswordLastSet` (the reset page does)
Hi Support,
we have found a problem with the Password Reset for the builtin/local admin account and documentation issues.
Title: Set-PSUIdentity -Password does not update PasswordLastSet (the reset page does)
ENVIRONMENT
PowerShell Universal: 2026.2.5
Host: Linux container (Rocky-based image), PowerShell 7.6.3
Database: SQLite (default)
Client: PowerShell 7.5 on Windows, management API via -ComputerName / -Credential
Settings: PasswordExpirationDays = 1095, PasswordLength = 12
Account: local account, Administrator role, created at first run from
PSUDefaultAdminName / PSUDefaultAdminPassword
SUMMARY
Two ways of changing a local account's password behave differently, and only one of them
keeps the expiration clock consistent:
Path Password changes PasswordLastSet updated
--------------------------- ---------------- -----------------------
/reset-password page yes YES
Set-PSUIdentity -Password yes NO
Because expiration is evaluated against PasswordLastSet, an account whose password is
rotated programmatically will still be forced through the reset page once the configured
period elapses - even though its password was changed the day before.
STEPS TO REPRODUCE
1. Configure PasswordExpirationDays.
2. Note PasswordLastSet: Get-PSUIdentity | Where-Object Name -eq '<name>'
3. Set-PSUIdentity -Id <id> -Password (ConvertTo-SecureString '<new>' -AsPlainText -Force)
4. Confirm the change took effect - the new password authenticates, the old one returns 401.
5. PasswordLastSet is unchanged. Verified both through Get-PSUIdentity and by reading the
Identity table in the SQLite database directly, across two changes on the same day.
6. For contrast, set PasswordLastSet to a date beyond the expiration period, log in through
the web UI, and complete the reset the product offers. PasswordLastSet is updated correctly.
EXPECTED
Set-PSUIdentity -Password updates PasswordLastSet, exactly as the reset page does.
Your release notes suggest the same gap existed elsewhere and was fixed. From 2025.11.0:
"Fixed an issue where the ResetAdminAccount environment variable process would not set
PasswordLastSet".
SECOND OBSERVATION, POSSIBLY BY DESIGN
With PasswordLastSet beyond the expiration period, the two entry points disagree:
- The login page redirects to /reset-password with "Your password has expired."
- Basic authentication against GET /api/v1/accessible still returns 200 with that same
expired password, before and after a service restart.
Is the API deliberately exempt from expiration, or is the check not applied on that path?
DOCUMENTATION NOTE
The Local Accounts page
(https://docs.devolutions.net/powershell-universal/security/local-accounts)
states that for an account created from PSUDefaultAdminName / PSUDefaultAdminPassword
"password restrictions are not enforced", and describes expiration on that same page as one
of those restrictions. Such an account does expire, as the redirect above shows.
PasswordExpirationDays and PasswordLength also exist as Set-PSUSetting parameters but appear
nowhere in the documentation.
Thanks for your support,
René
@Mordecai Thank you for reporting these issues. I've verified both of those are, in fact, bugs and opened an issue to get them resolved. I will also make sure the documentation gets updated today with information about the fields you mentioned.
Adam Driscoll
PowerShell Expert and Software Architect at Devolutions