[2026.3.3] Get-PSUIdentity -Integrated in .universal config scripts fails with "Unauthenticated" under Permissive security model

[2026.3.3] Get-PSUIdentity -Integrated in .universal config scripts fails with "Unauthenticated" under Permissive security model

avatar

Version: 2026.3.3 (also 2026.3.2). Last working version: 2026.2.4
Hosting: Docker (Linux container), 2-node cluster, PostgreSQL plugin, Git sync (OneWay, Data__Mode=Manual)
Security model: API__SecurityModel=Permissive, API__TrustCertificate=true (set as environment variables; verified inside both containers with docker exec <container> env)

Problem
Since upgrading from 2026.2.4 to 2026.3.x, every configuration load fails on both nodes for all universal scripts that call a PSU cmdlet with -Integrated. The admin console shows:

Invalid configuration: /root/.PowerShellUniversal/Repository/.universal/eventHubs.ps1
Unauthenticated. Specify an app token, use default credentials or enable permissive security model. (Computer: node-01)


The same error appears for roles.ps1 and publishedFolders.ps1, on both nodes. These are exactly
the three config scripts that call Get-PSUIdentity -Integrated. All other config scripts load fine.

Minimal repro
.universal/roles.ps1:

$identities = Get-PSUIdentity -Integrated
New-PSURole -Name "Test" -Description "Test"


Start the server with API__SecurityModel=Permissive -> the configuration load of roles.ps1 fails with "Unauthenticated".

Expected
According to the docs, with the Permissive model cmdlets run as the System user, and -Integrateduses the backchannel; authorization is only performed in the Strict model. The configuration should load, as it did in 2026.2.4.

Actual
The configuration load is rejected as unauthenticated, although the error message itself suggests enabling the permissive model, which is already enabled.

Impact
Event hubs, roles and published folders defined in these scripts are not registered, so agents can't connect to their event hubs. We can't upgrade our test/production instances.

Notes

  • Not intermittent: it happens on every container start/configuration reload.
  • The 2026.3.2 fix ("Integrated API Security Model not being honored by PSU cmdlets") and the 2026.3.3 fix ("Integrated API Security Model and -Integrated enforcing permissions incorrectly") did not resolve it.
  • Possibly related: 56550 (Invoke-PSUScript -Integrated authorizing the caller, fix announced for 2026.3.3) and 56545 (same "Unauthenticated" message, but reported only for non-Permissive models). In our case Permissive is set and the error still occurs on every configuration load.
  • Before 2026.2 we had to add -Integrated to these calls because the external API (gRPC via Api.Url) failed during configuration load, so dropping -Integrated is not an option.


Is there a supported workaround (other than switching to API__SecurityModel=Integrated, which affects Send-PSUEvent -ComputerName routing in our multi-node setup)?

Best Regards
Andreas

All Comments (1)

avatar

Hello @Andreas

Thank you for the detailed report and for including a minimal reproduction. The information you provided is sufficient for us to begin validating this behavior on our side.

We will focus the initial reproduction on the specific configuration-load scenario you described, using API__SecurityModel=Permissive and Get-PSUIdentity -Integrated from a .universal configuration file.

We will also compare the behavior across the relevant versions, including 2026.2.4 as the last version you reported working and the 2026.3.x versions where the issue occurs. We will first isolate the behavior in a minimal Docker environment before adding the multi-node and PostgreSQL variables if they are required to reproduce it.

The 2026.3.2 and 2026.3.3 release notes do include changes related to the Integrated API Security Model and -Integrated behavior, so we want to verify specifically whether the configuration-load context is still producing an authentication failure under the Permissive model.

At this point, I do not need additional information from you. I will update the thread once we have results from the reproduction.

References:
https://devolutions.net/powershell-universal/release-notes/

Best regards,
Ruben Tapia