Get-PnPSiteTemplate : Attempted to perform an unauthorized operation and ACS token missing

%3CLINGO-SUB%20id%3D%22lingo-sub-2631095%22%20slang%3D%22en-US%22%3EGet-PnPSiteTemplate%20%3A%20Attempted%20to%20perform%20an%20unauthorized%20operation%20and%20ACS%20token%20missing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2631095%22%20slang%3D%22en-US%22%3E%3CP%3EI%20am%20trying%20to%20export%20a%20design%20template%20for%20a%20site%20that%20I%20am%20in%20the%20Owners%20group%20for%2C%20and%20I%20have%20Share%20Point%20Administrator%20role%20activated.%26nbsp%3B%20I%20am%20running%20the%20Powershell%20ISE%20as%20ADMIN%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20run%20the%20following%202%20powershell%20commands%3C%2FP%3E%3COL%3E%3CLI%3E%3CSTRONG%3E%3CEM%3EConnect-PnPOnline%20-Url%20%3C%2FEM%3E%3C%2FSTRONG%3E%3CA%20href%3D%22https%3A%2F%2FMyDomain.sharepoint.com%2Fsites%2FMySite%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3E%3CSPAN%3E%3CSTRONG%3E%3CEM%3Ehttps%3A%2F%2FMyDomain.sharepoint.com%2Fsites%2FMySite%2F%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FA%3E%3CSTRONG%3E%3CEM%3E%20-%3C%2FEM%3E%3C%2FSTRONG%3E%3CSTRONG%3E%3CEM%3EInteractive%20-ForceAuthentication%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3CLI%3E%3CSTRONG%3E%3CEM%3EGet-PnPSiteTemplate%20-Out%20C%3A%5CFolder%5CDesign.xml%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20starts%20running%20and%20the%20thermometer%20bar%2C%20reads%20'Site%20Security'%20and%20then%20fails%20immediately%20with%20the%20following%20error%3C%2FP%3E%3CP%3EGet-PnPSiteTemplate%20%3A%20Attempted%20to%20perform%20an%20unauthorized%20operation.%3C%2FP%3E%3CP%3EAt%20line%3A1%20char%3A1%3C%2FP%3E%3CP%3E%2B%20Get-PnPSiteTemplate%20-Out%3CSTRONG%3E%3CEM%3E%26nbsp%3B%3C%2FEM%3E%3C%2FSTRONG%3EC%3A%5CFolder%5CDesign.xml%3C%2FP%3E%3CP%3E%2B%20~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%2B%20CategoryInfo%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%20%26nbsp%3B%3A%20WriteError%3A%20(%3A)%20%5BGet-PnPSiteTemplate%5D%2C%20ServerUnauthorizedAccessException%3C%2FP%3E%3CP%3E%26nbsp%3B%20%26nbsp%3B%20%2B%20FullyQualifiedErrorId%20%3A%20EXCEPTION%2CPnP.PowerShell.Commands.Provisioning.Site.GetSiteTemplate%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20run%20the%20following%202%20powershell%20commands%3C%2FP%3E%3COL%3E%3CLI%3E%3CSTRONG%3E%3CEM%3EConnect-PnPOnline%20-Url%20%3C%2FEM%3E%3C%2FSTRONG%3E%3CA%20href%3D%22https%3A%2F%2FMyDomain.sharepoint.com%2Fsites%2FMySite%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3E%3CSPAN%3E%3CSTRONG%3E%3CEM%3Ehttps%3A%2F%2FMyDomain.sharepoint.com%2Fsites%2FMySite%2F%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FSPAN%3E%3C%2FA%3E%3CSTRONG%3E%3CEM%3E%20-%3C%2FEM%3E%3C%2FSTRONG%3E%3CSTRONG%3E%3CEM%3EuseWebLogin%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3CLI%3E%3CSTRONG%3E%3CEM%3EGet-PnPSiteTemplate%20-Out%20C%3A%5CFolder%5CDesign.xml%3C%2FEM%3E%3C%2FSTRONG%3E%3C%2FLI%3E%3C%2FOL%3E%3CP%3EThe%20connect-pnponline%20command%20suggests%20I%20use%20the%20-%3CEM%3EInteractive%3C%2FEM%3E%20flag%2C%20but%20it%20starts%20running%2C%20and%20gets%20further%20and%20the%20thermometer%20bar%20goes%20through%20'Site%20Security'%2C%20'Audit'%2C%20'Fields'%2C%26nbsp%3B'Content%20Types'%20and%20starts%20on%20'List%20Instances'%20and%20starts%20to%20list%20the%20lists%2C%20and%20fails%20on%20the%20first%20one%2C%20which%20is%20called%20'Confidential%20files'%26nbsp%3B%20with%20the%20following%20error%20%3A%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3EGet-PnPSiteTemplate%20%3A%20GetAccessTokenAsync()%20called%20without%20an%20ACS%20token%20generator.%20Specify%20in%20AuthenticationManager%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENo%20Output%20is%20saved%3C%2FP%3E%3CP%3EPowershell%20is%20version%26nbsp%3B5.1.18362.1593%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20ideas%20on%20how%20to%20fix%20this%2C%20or%20even%20to%20get%20more%20information%20on%20what%20unauthorised%20operation%20is%20running%2C%20or%20how%20to%20force%20the%20ACS%20Token%20wen%20I%20am%20querying%20lists%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20-%20Richard%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2631225%22%20slang%3D%22en-US%22%3ERe%3A%20Get-PnPSiteTemplate%20%3A%20Attempted%20to%20perform%20an%20unauthorized%20operation%20and%20ACS%20token%20missing%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2631225%22%20slang%3D%22en-US%22%3EI%20would%20suggest%20that%20you%20try%20using%20the%20new%20version%20of%20PnP%20PowerShell%20within%20PowerShell%20core%3A%20%3CA%20href%3D%22https%3A%2F%2Fpnp.github.io%2Fpowershell%2Farticles%2Finstallation.html%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fpnp.github.io%2Fpowershell%2Farticles%2Finstallation.html%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EWhen%20you%20connect%20using%20-UseWebLogin%2C%20you%20get%20an%20ACS%20generated%20token%2C%20which%20will%20not%20work%20for%20things%20like%20exporting%20the%20site%20headed%20and%20footer%20as%20it%20won't%20be%20able%20to%20acquire%20an%20access%20token%20for%20Graph%2C%20which%20is%20why%20it's%20recommended%20to%20use%20-Interactive.%3CBR%20%2F%3EI%20have%20done%20this%20multiple%20times%20recently%20and%20can%20confirm%20that%20it%20works%20fine%20with%20PnP.PowerShell%20in%20PowerShell%20core.%3CBR%20%2F%3EWhen%20you%20use%20-Interactive%2C%20you%20will%20be%20using%20the%20PnP%20Management%20Shell%20Azure%20app%20registration%20to%20connect%20as%20delegated%20permissions%2C%20so%20ensure%20that%20the%20app%20is%20granted%20permissions%20(should%20have%20requested%20you%20to%20approve%20the%20first%20time%20using%20an%20admin%20account)%20and%20also%20ensure%20that%20the%20user%20account%20has%20the%20required%20permissions%20on%20the%20site.%3C%2FLINGO-BODY%3E
New Contributor

I am trying to export a design template for a site that I am in the Owners group for, and I have Share Point Administrator role activated.  I am running the Powershell ISE as ADMIN 

 

When I run the following 2 powershell commands

  1. Connect-PnPOnline -Url https://MyDomain.sharepoint.com/sites/MySite/ -Interactive -ForceAuthentication
  2. Get-PnPSiteTemplate -Out C:\Folder\Design.xml

 

It starts running and the thermometer bar, reads 'Site Security' and then fails immediately with the following error

Get-PnPSiteTemplate : Attempted to perform an unauthorized operation.

At line:1 char:1

+ Get-PnPSiteTemplate -Out C:\Folder\Design.xml

+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    + CategoryInfo          : WriteError: (:) [Get-PnPSiteTemplate], ServerUnauthorizedAccessException

    + FullyQualifiedErrorId : EXCEPTION,PnP.PowerShell.Commands.Provisioning.Site.GetSiteTemplate

 

When I run the following 2 powershell commands

  1. Connect-PnPOnline -Url https://MyDomain.sharepoint.com/sites/MySite/ -useWebLogin
  2. Get-PnPSiteTemplate -Out C:\Folder\Design.xml

The connect-pnponline command suggests I use the -Interactive flag, but it starts running, and gets further and the thermometer bar goes through 'Site Security', 'Audit', 'Fields', 'Content Types' and starts on 'List Instances' and starts to list the lists, and fails on the first one, which is called 'Confidential files'  with the following error : 

Get-PnPSiteTemplate : GetAccessTokenAsync() called without an ACS token generator. Specify in AuthenticationManager

 

No Output is saved

Powershell is version 5.1.18362.1593

 

Any ideas on how to fix this, or even to get more information on what unauthorised operation is running, or how to force the ACS Token wen I am querying lists 

 

Thanks - Richard 

 

 

 

 

 

2 Replies
I would suggest that you try using the new version of PnP PowerShell within PowerShell core: https://pnp.github.io/powershell/articles/installation.html

When you connect using -UseWebLogin, you get an ACS generated token, which will not work for things like exporting the site headed and footer as it won't be able to acquire an access token for Graph, which is why it's recommended to use -Interactive.
I have done this multiple times recently and can confirm that it works fine with PnP.PowerShell in PowerShell core.
When you use -Interactive, you will be using the PnP Management Shell Azure app registration to connect as delegated permissions, so ensure that the app is granted permissions (should have requested you to approve the first time using an admin account) and also ensure that the user account has the required permissions on the site.
Our Admins found that the current PnP Management Shell screen in Portal.Azure.Com appeared to have changed from when they had originally granted permissions to the app. They noted that the list of potential permissions applicable to PnP Management Shell had increased. We can only surmise that this change had left a number of these ‘new’ permissions in an ‘ungranted’ state, and this is what caused the unauthorisation error.

The problem was fixed by regranting the permissions through the new interface.