Showing posts with label sharepoint 2010. Show all posts
Showing posts with label sharepoint 2010. Show all posts

Wednesday, July 31, 2013

SharePoint 2010 Event ID 6801 FIMSynchronizationService

Our User Profile Synchronization service has been running without issues for quite a while, but in the last few days we started to seeing event id 6801 errors in the application event log:

Event ID 6801 FIMSynchronizationService

















Looking at the configuration of the service itself, there didn't appear to be any problems. The sync would run, but it would generate errors for every user it processed. It turns out the problem is with the proxy for the user profile service application. The proxy basically associates the User Profile Service Application to the Web application through membership in the a service application connection group. In most environments, this is the default group.

User Profile Service Application Proxy













The solution is to simply re-create the proxy using the following steps:

1. Delete the existing User Profile Service Application proxy using the following script. The name may be different in your farm, but you can verify by running Get-SPServiceApplication.

Note: If you've messed around with the service application associations and don't remember if you're still using the default group, go to Central Admin - Application Management - Service Applications and click on Configure service application associations. In the default config, it should look like this:

Service Application Associations


$proxy = Get-SPServiceApplicationProxy | where {$_.typename -eq "User Profile Service Application Proxy"}

Remove-SPServiceApplicationProxy -Identity $proxy -confirm:$false
2. Create a new User Profile Service Application Proxy using the following script and associate it with the default group:
$upa = Get-SPServiceApplication -Name "User Profile Service Application"
New-SPProfileServiceApplicationProxy -Name "User Profile Service Application Proxy" -ServiceApplication $upa -DefaultProxyGroup
3. Do an iisreset from the command prompt, then run a profile sync and check the errors are no longer being generated.

For other User Profile Synchronization issues we've looked at see:

http://imperfectit.blogspot.ca/2011/10/sharepoint-2010-user-profile.html
http://imperfectit.blogspot.ca/2010/03/setting-up-sharepoint-2010-user-profile.html
http://imperfectit.blogspot.ca/2011/03/sharepoint-2010-december-cumulative.html

Friday, June 28, 2013

SharePoint 2010 Event ID 6482

***Update: If this doesn't solve your problem, try the following.

We recently started to get the following application event log error:

Because it was a test environment we went ahead and reset the search index and restrated the search application, but the errors kept coming back.
 
The fix was to reset the cache on alll four servers in the farm. Once we did that the errors disappeared. To see directions on resetting the cache, have a look at the directions below, or go to http://support.microsoft.com/kb/939308
 
***Note*** Complete these steps on any server running the SharePoint Timer Service in the farm.
1.Stop the Timer service. To do this, follow these steps:

•Click Start, point to Administrative Tools, and then click Services.

•Right-click Windows SharePoint Services Timer, and then click Stop.

•Close the Services console.

2.On the computer that is running Microsoft Office SharePoint Server 2007 and on which the Central Administration site is hosted, click Start, click Run, type explorer, and then press ENTER.

3.In Windows Explorer, locate and then double-click the following folder:

Drive:\Documents and Settings\All Users\Application Data\Microsoft\SharePoint\Config\GUID

Notes

◦The Drive placeholder specifies the letter of the drive on which Windows is installed. By default, Windows is installed on drive C.

◦The GUID placeholder specifies the GUID folder.

◦The Application Data folder may be hidden. To view the hidden folder, follow these steps:

1.On the Tools menu, click Folder Options.

2.Click the View tab.

3.In the Advanced settings list, click Show hidden files and folders under Hidden files and folders, and then click OK.

◦In Windows Server 2008, the configuration cache is in the following location:

Drive:\ProgramData\Microsoft\SharePoint\Config\GUID

4.Back up the Cache.ini file.

5.Delete all the XML configuration files in the GUID folder. Do this so that you can verify that the GUID folder is replaced by new XML configuration files when the cache is rebuilt.

Note When you empty the configuration cache in the GUID folder, make sure that you do not delete the GUID folder and the Cache.ini file that is located in the GUID folder.

6.Double-click the Cache.ini file.

7.On the Edit menu, click Select All.

8.On the Edit menu, click Delete.

9.Type 1, and then click Save on the File menu.

10.On the File menu, click Exit.

11.Start the Timer service. To do this, follow these steps:

•Click Start, point to Administrative Tools, and then click Services.

•Right-click Windows SharePoint Services Timer, and then click Start.

•Close the Services console.

Note The file system cache is re-created after you perform this procedure. Make sure that you perform this procedure on all servers in the server farm.

12. Make sure that the Cache.ini file has been updated. For example it should no longer be 1 if the cache has been updated.

13.Click Start, point to Programs, point to Administrative Tools, and then click SharePoint 3.0 Central Administration.

14.Click the Operations tab, and then click Timer job status under Global Configuration.

15.In the list of timer jobs, verify that the status of the Config Refresh entry is Succeeded.

16.On the File menu, click Close.

Monday, October 22, 2012

SharePoint 2010 Event ID 7043

We recently noticed the following error in the Application event log on our SharePoint 2010 servers:




A quick Google search turned up the following article on the SharePoint forum: http://social.technet.microsoft.com/Forums/en/sharepoint2010setup/thread/c894d98c-24ab-416c-aca9-ae57644deb5e

It turns out the issue is caused by bad code. Simply do a search for the file called TaxonomyPicker.ascx (C:\Program Files\Common Files\Microsoft Shared\Web Server Extensions\14\TEMPLATE\CONTROLTEMPLATES) and open it up in Notepad. Do a search for the characters “,” and replace it with a “,” (minus the quotation marks in both cases).

From this:


To this:



Thanks to Brian Lala, this can all be accomplished by creating and running the following script:

# Powershell script to implement the fix suggested in http://support.microsoft.com/kb/2481844

$TaxonomyPickerControl = "$env:CommonProgramFiles\Microsoft Shared\Web Server Extensions\14\TEMPLATE\CONTROLTEMPLATES\TaxonomyPicker.ascx"
Write-Host " - Making a backup copy of TaxonomyPicker.ascx..."
Copy-Item $TaxonomyPickerControl $TaxonomyPickerControl".bad"
$NewTaxonomyPickerControl = (Get-Content $TaxonomyPickerControl) -replace ',', ","
Write-Host " - Writing out new TaxonomyPicker.ascx..."
Set-Content -Path $TaxonomyPickerControl -Value $NewTaxonomyPickerControl
Write-Host " - Done! Press any key to exit..."
$null = $host.UI.RawUI.ReadKey("NoEcho,IncludeKeyDown")


Microsoft finally release a KB article on the issue which can be found here: http://support.microsoft.com/kb/2481844

Friday, June 22, 2012

SharePoint 2010 Event ID 6398



Although it shows up as a Crital error which can be a little alarming, there's nothing to worry about here. It's simply the Microsoft Cutomer Experience Improvement Program trying to collect data and send it back to the mother ship. We go ahead and disable the feature at the farm level, and at the web application level.

To disable at the farm level, go to Central Admin - System Settings - Configure privacy options and select "No, I don't wish to participate" and "Ignore errors and don't collect information".

To disable at the web app level, go to Central Admin - Manage Web Applications. Highlight each web app and select General Settings, then scroll to the bottom and say No where it asks if you want to enable the CEIP.

Tuesday, May 15, 2012

SharePoint 15 - What's Next?

*** UPDATE - July 18th****  http://technet.microsoft.com/en-us/library/cc303422(v=office.15. See also http://imperfectit.blogspot.ca/2012/07/sharepoint-2013.html

So you finally finished migrating all your SharePoint 2007 and WSS 3 sites to SharePoint 2010. Congratulations! The bad news (or good depending on how you look at it) is that the next version of SharePoint is right around the corner. Microsoft are very adept at keeping partners who've seen it quiet, but this is what's known so far. Keep in mind that all of this is based on leaks, and we won't know anything for sure until Microsoft announces it.
  • SharePoint 15 (as it's currently called) is scheduled to be Released to Manufacturing (RTM) November 12th. Only people who are involved in the Microsoft Technology Adoption Program (TAP) will have access to the bits before that. There are rumors the Beta will be realesed June 13th. 
  • SP 15 will include an application marketplace similar  to what you use with your mobile devices.
  • It will be better able to handle multi-tenant installations so hosters can get environments up and available faster and more securely. It will also make it easier to sell apps built on SharePoint to multiple companies.
  • It will be built to use an Oracle back-end (just kidding). Make sure you're running the latest version of SQL to speed your migration.
  • There are rumors there will be a an education module which allows schools to setup a virtual learning environment. Details here are murky.
  • More integration with Silverlight.
  • Built-in Information Rights Management.
  • Expansion of the cloud SharePoint offering (Office 365) and integration of on premise and cloud based SharePoint. It's clear Microsoft want to remove any objections companies have to moving their SharePoint environments into the cloud.
  • Better support and integration for mobile devices.
  • Simplified development tools. We would assume this means a new version of SharePoint Designer?
  • Tighter integration with the next version of Office (Office 15).
  • Expansion of the social networking capabilities. Weather this means a re-vamping of the existing My Sites or a complete overhaul is unclear. Maybe integration with Microsoft's partner Facebook? 
  • Minimal Download Strategy (MDS allows websites to take much less bandwidth than with traditional technologies.)
  • Site versioning (an extension of the existing document versioning).
So, lots to look forward to, but also a lot to wrap your head around. We'll continue to update this post as more information becomes available. In the meantime, you can subscribe to this twitter feed: http://twitter.com/#!/NextSharePoint and visit the following sites:

http://www.cmswire.com/cms/web-development/sharepoint-15-arriving-early-2013-according-to-leaked-ms-roadmap-015162.php
http://www.cmswire.com/cms/information-management/sharepoint-15-complete-with-app-marketplace-coming-late-2012-014682.php
http://redmondmag.com/articles/2012/04/01/whats-next-for-sharepoint.aspx

Be sure to let us know if you've heard anything we haven't mentioned here.

Wednesday, January 25, 2012

Select the credentials you want to use to logon to this SharePoint site

Our users came across the following error when they were trying to login to their My Site (http://mysite/):


We had recently had to restore the My Site from a backup and it appears the restore process had changed the authentication type the extended website http://mysite/ was using from Kerberos to NTLM. We have another version of the site published as http://mysite.domain.com/ which was still set to Kerberos hence the authentication error.

The fix was to go into Central Admin - Manage Web Application (My Site) and then select Authentication Providers. I selected the offending Intranet zone and changed it back to Negotiate (Kerberos) so it matched the other Custom zone:


After an IISRESET, the error stopped appearing.

Tuesday, October 18, 2011

SharePoint 2010 User Profile Synchronization Error

We recently started to notice the following "ma-extension-error" in ForeFront Identity Manager when we'd run a user profile synchronization with our Active Directory:
















System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.MissingMethodException: Method not found: 'Void Microsoft.Office.Server.UserProfiles.ProfileManagerBase.UpdateProfileWithBulkProperties(Int64, System.String, System.String, System.Collections.Hashtable)'.



at Microsoft.Office.Server.UserProfiles.ProfileImportExportService.UpdateWithProfileChangeData(Int64 importExportId, ProfileChangeData[] profileChangeData)


--- End of inner exception stack trace ---


at System.RuntimeMethodHandle._InvokeMethodFast(Object target, Object[] arguments, SignatureStruct& sig, MethodAttributes methodAttributes, RuntimeTypeHandle typeOwner)


at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture, Boolean skipVisibilityChecks)


at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object[] parameters, CultureInfo culture)


at Microsoft.Office.Server.WebServiceDirectProxy.WebMethodInfo.Invoke(Object webServiceInstance, Object[] args)


at Microsoft.Office.Server.WebServiceDirectProxy.Invoke(String methodName, Object[] args)


at Microsoft.Office.Server.UserProfiles.ManagementAgent.ProfileImportExportDirect.UpdateWithProfileChangeData(Int64 importExportId, ProfileChangeData[] profileChangeData)


at Microsoft.Office.Server.UserProfiles.ManagementAgent.ProfileImportExportExtension.Microsoft.MetadirectoryServices.IMAExtensibleCallExport.ExportEntry(ModificationType modificationType, String[] changedAttributes, CSEntry csentry)

After checking all the steps under the bible of User Profile configuration found here, we were fairly certain our configuration and accounts hadn't changed. It turns out the error was caused by a SharePoint 2010 security patch that had been applied to our servers as part of our regular patching process. Microsoft support confirmed this to be the case and even have an excellent post on it:
 
http://blogs.msdn.com/b/tehnoonr/archive/2011/09/19/september-security-bulletin-ms11-074-and-sharepoint-2010-issues.aspx
 
Basically we applied KB2560890 without applying several other patches. Simply apply the other patches (KB2494022, KB2560885, KB2566456, KB2566954, KB2566958, KB2566960) listed in the article above, and the error should go away.
 
A couple of notes:
  • After you apply the patches to all the servers in the farm, you need to run the SharePoint Configuration wizard on all the servers as well.
  • KB2566960 failed when we tried to install it because we don't use Office Web Apps in our farm.
  • You can Install SP1 and and the August CU to resolve this problem as well, but simply applying the patches is much less disruptive and less likely to cause new issues.
  • http://technet.microsoft.com/en-us/security/bulletin/ms11-074

Friday, September 23, 2011

How to Delete a SharePoint Site and All of It's Sub Sites

We were recently doing some maintenance cleaning up old sites when we noticed an annoying feature. When you try to delete a site that has numerous sub sites, SharePoint will continually kick out errors telling you it can't delete the current site because it has sub sites. This forces you to manually go through and delete the lower level sites, then work your way up.

I understand this is a "safety" feature to help make sure you don't delete any sub sites you didn't mean to, but I really want to get rid of this legacy site that's taking up a big chunk of SQL disk.

The solution? Run the following powershell command. Be sure you have a good backup in case you change your mind and substitute the site name (http://site/subsite) with the name of the sub site you want to nuke.

function RemoveSPWebRecursively(
  [Microsoft.SharePoint.SPWeb] $web)
{
Write-Debug "Removing site ($($web.Url))..."


$subwebs = $web.GetSubwebsForCurrentUser()


foreach($subweb in $subwebs)
{
RemoveSPWebRecursively($subweb)
$subweb.Dispose()
}

$DebugPreference = "SilentlyContinue"
Remove-SPWeb $web -Confirm:$false
$DebugPreference = "Continue"
}


$DebugPreference = "SilentlyContinue"
$web = Get-SPWeb "http://site/subsite"
$DebugPreference = "Continue"

If ($web -ne $null)
{
RemoveSPWebRecursively $web
$web.Dispose()
}

Wednesday, July 6, 2011

Service Pack 1 for SharePoint 2010 Products is Now Available for Download

Here's the info on where to get it and how to install directily from the SharePoint Team Blog

Download - http://technet.microsoft.com/en-us/office/ee748587.aspx

Known Issues - http://support.microsoft.com/kb/2532126

Directions:

Install the service packs in the following order on every server in the farm.


1. Service Pack 1 for SharePoint Foundation 2010
2. Service Pack 1 for SharePoint Foundation 2010 Language Pack (if applicable)
3. Service Pack 1 for SharePoint Server 2010
4. Service Pack 1 for SharePoint Server 2010 Language Pack (if applicable)

The SharePoint 2010 Products Configuration Wizard or "psconfig –cmd upgrade –inplace b2b -wait” should be run once on every server in the farm following the final update installed.

The version of content databases will be 14.0.6029.1000 after successfully installation. For more in-depth guidance for the update process, we recommend reviewing the following articles. These articles provide a correct way to deploy updates and identify known issues (and resolutions).



It is strongly recommended to install the June 2011 Cumulative Update immediately after the installation of Service Pack 1. The June Cumulative Update includes several important security and bug fixes that are not included Service Pack 1.

Thursday, May 26, 2011

SharePoint 2010 Service Pack 1 Will Be Available Shortly

According to the SharePoint Team Blog Service Pack 1 for SharePoint 2010 will be available towards the end of June and it promises stability, perfomance and security enhancements the community has been asking for.

Here are the highlights of what we can expect:

Site Recycle Bin
Service Pack 1 will introduce long awaited Site Recycle Bin functionality that enables self-service recovery of site collections and sites. In the past IT Professionals were tasked with restoring entire databases to recover deleted site collections and sites and would generally require expensive restore environments to support the task. Now in Service Pack 1 administrators can quickly and easily recover site collections and sites accidentally deleted by their owners in a process similar to that of the Recycle Bin we have for Lists, Libraries, and Documents.

Shallow Copy
If you’re using Remote BLOB Storage you’ve probably realized that when moving Site Collections (Move-SPSite) between content databases each unit of unstructured data (BLOB) was round tripped (I.e. uploaded and subsequently downloaded again) serially during the move. This operation was both time consuming and resource intensive. In Service Pack 1 we reduce that overhead by enabling “shallow copy” when moving Site Collections between databases where Remote BLOB Storage is used. New Shallow Copy functionality with the Move-SPSite CmdLet enables moving site collections between content databases without moving the underlying unstructured data, i.e. Microsoft Word documents, PowerPoint Presentations, etc. significantly increasing performance and reliability for organizations using Remote BLOB Storage by simply updating the pointers to those objects in the destination content database.

StorMan.aspx
In SharePoint 2010 we removed StorMan.aspx (Storage Space Allocation) (see http://support.microsoft.com/kb/982587/EN-US) which in previous versions of SharePoint enabled granular management and insight into storage. For example, the page would show you the top 100 documents or document libraries in terms of size. With that information end users could the page to clean up content from their site(s) by deleting the large content that they no longer needed. In Service Pack 1 we are bringing back an improved StorMan.aspx, enabling users to better understand where their quota is going and act upon that information to reduce the size of their sites.

New enhancements will improve the way you interact with information in SharePoint 2010. Service Pack 1 adds support for working with SharePoint and the Office Web Applications using Internet Explorer 9 and the Google Chrome browser (for a complete list of supported browsers for SharePoint 2010 see also http://technet.microsoft.com/en-us/library/cc263526.aspx), support for Open Document Format documents, and more.

There are also some unconfirmed reports of improvements to backup and restore, better Project/SharePoint integration and support for Google Chrome.

To read the official announcement click here and to be notified of updates sign up for the RSS feed here. Joel Oleson also has some information on his excellent SharePoint blog here.

Thursday, December 2, 2010

SharePoint 2010 October Cumulative Updates Re-Released

Microsoft have re-released the SharePoint 2010 October Cumulative Updates after fixing the issues I discussesd in my previous post (http://imperfectit.blogspot.com/2010/11/dont-install-sharepoint-2010-october.html).

You can get the updated bits here:

http://support.microsoft.com/kb/2449183

Cross your fingers and deploy! If you have problems, we'd love to hear about them.

If you want to see all updates available for the SharePoint suite, the following is a good place to start: http://technet.microsoft.com/en-us/office/ee748587.aspx

Friday, November 12, 2010

Don't Install the SharePoint 2010 October Cumulative Update!!!

****Update: December, 2010**** The October update issues have been addressed. See http://imperfectit.blogspot.com/2010/12/sharepoint-2010-october-cumulative.html

Just when we were thinking how it had been ages since a Microsoft update had broken our servers there are widespread reports of the October cumulative update wreaking havoc (User Profile Application in particular). Read the following from the SharePoint Team Blog to learn more:

http://blogs.msdn.com/b/sharepoint/archive/2010/11/06/details-and-workaround.aspx

We recommend installing http://support.microsoft.com/kb/2266423 followed by http://support.microsoft.com/kb/2352342 for now. As always, be sure to apply regular server OS security updates through Windows Update.

Tuesday, June 1, 2010

SharePoint 2010 Farm Backup Fails

I was successfully running backups of my SharePoint 2010 server for a few weeks, then all of a sudden I noticed they weren't finishing properly. They'd run through most of the backup process, then stall trying to backup the Search Service Application. When I looked at the backup log file it showed the following:

I also noticed the following event log error (Event ID: 67, Source: SharePoint Server Search) :



















After some investigation, I realized I had deleted my original Search Application and created a new one, but for some reason the old object still existed in SQL.

I tried a few methods to delete the old object, but nothing was working. When I manually tried to delete it through Central Admin it would pop up a screen saying it was processing, but it never did anything. A Google search turned up the following article: http://prequest01.wordpress.com/2008/08/16/unable-to-delete-shared-services/

I used the following stsadm command:

Stsadm -o deleteconfigurationobject -id “object GUID”

To find the object GUID, simply go into Central Admin - Manage Service Applications and highlight the offending legacy service application (Search Service Application in my case). You should now be able to see the GUID in the IE address bar. Run the command above, and try your backups again and all should be well.

You can also run the following command from the SharePoint PowerShell: Get-SPServiceApplication

If your backups are still failing, you can always increase the logging level to get more details about the Backup and Restore Process in the Diagnostics Logging Settings, from Errors only to Verbose. This will help troubleshooting. Once you find out the exact issue, you can bring logging back to default levels to reduce I/O and storage required for this extra activity.



Wednesday, March 31, 2010

Setting Up the SharePoint 2010 User Profile Service Application to Synch AD Users –Part II

Now that we have our connection to AD configured and the user profile service application is up and running, we’re ready to do our first import of users from AD.
1. In order to perform the synchronization, you’ll need to verify you have the following permissions:

• You must be a member of the Farm Administrators group on the computer that is running the SharePoint Central Administration Web site

• The Farm Administrator account must be a Service Administrator for the User Profile Service that you are configuring. For more information about how to set service permissions, see Assign administration of a User Profile service application (SharePoint Server 2010).

• The account that you use to synchronize profile information with Active Directory Domain Services (AD DS) must have Replicate Directory Changes permissions on the AD DS domains from which you want to import data. If the NETBIOS name is different from the domain name, the account that is used must also have Replicate Directory Changes permissions on the cn=configuration container. For more information about how to configure Replicate Directory Changes in AD DS, see How to grant the "Replicating Directory Changes" permission for the Microsoft Metadirectory Services ADMA service account (http://go.microsoft.com/fwlink/?LinkId=47854). Create All Child Objects permission is needed to export properties, such as profile pictures, from SharePoint Server to AD DS.

2. On the Central Administration Web site, in the Application Management section, click Manage service applications.

3. On the Manage Service Applications page, click in the Title column of the User Profile Service Application row to select it.

4. In the Operations group of the ribbon, click Manage.

5. On the Manage Profile Service page, in the Synchronization section, click Start Profile Synchronization.

6. On the Start Profile Synchronization page, select Start Incremental Synchronization to synch only user and group profile data that has changed or select Start Full Synchronization to synchronize all user profile data.


The Start Full Synchronization option is time and resource intensive. We do not recommend it unless absolutely required to reset data that is stored in user profiles or to do an initial synchronization of user profiles.

When using AD DS, you must run full synchronization any time a new profile property mapping is created.

7. Click OK.

After the Profile Synchronization job is finished, you can search for a known profile or for accounts that begin with a known domain name from the Manage User Profiles page.

Because the import uses MIIS/FIM you can also open the miisclient.exe application from C:\Program Files\Microsoft Office Servers\14.0\Synchronization Service\UIShell\miisclient.exe to verify that the sync was successful:

Tuesday, March 30, 2010

Setting Up the SharePoint 2010 User Profile Service Application to Synch AD Users - Part I

As part of our demo environment, I’ve been working on our configuration for the user profile service application to import users from our AD so we can start using MySite’s , Profile Pages, Social Tagging, etc… Here are the steps I followed from Microsoft plus some of my own comments:


The Environment & Requirements


• SharePoint 2010 Enterprise Beta server acting as Web and App.


• SQL 2008 SP1 CU2 (separate from SP2010 server)


• AD (domain functional level 2003)


• The account you use to connect to AD must have at least Replicate Directory Changes permissions on the AD DS domain(s) from which you wish to import data and on the cn=configuration container are needed for SharePoint Server 2010. For more information about how to configure Replicate Directory Changes in AD DS, see How to grant the "Replicating Directory Changes" permission for the Microsoft Metadirectory Services ADMA service account (http://go.microsoft.com/fwlink/?LinkId=47854). Create All Child Objects permission is needed to export properties, such as profile pictures, from SharePoint Server to AD DS.

For my lab environment, I'm ignoring profile pictures....for now.

•The farm is running either the Standard or Enterprise version of SharePoint Server 2010 and you have run the farm configuration wizard. Profile Synchronization does not work on a stand-alone installation for SharePoint Server 2010 Beta.


• An instance of the User Profile Service application exists and is started. For more information, see Create, edit, or delete a User Profile service application (SharePoint Server 2010).


• If you are using Microsoft SQL Server 2008, Microsoft SQL Server 2008 with Service Pack 1 (SP1) with Cumulative Update 2 (CU2) (http://go.microsoft.com/fwlink/?LinkId=165962) is required.


• The WCF hotfix (KB976462) for Windows Server 2008 R2 is installed.


• You must be a member of the Farm Administrators group on the computer that is running the SharePoint Central Administration Web site.


• The Farm Administrator account, which is created during the SharePoint farm setup, must also be a Local Administrator on the server where the User Profile Synchronization service is deployed


• The Farm Administrator account must be a Service Administrator for the User Profile Service that you are configuring. For more information about how to set service permissions, see Assign administration of a User Profile service application (SharePoint Server 2010).


• The Service Administrator account can log on locally to the server where Profile Synchronization will be deployed.


• If you are using a Windows Server 2003 AD DS forest, the Service Administrator account must be a member of the Pre-Windows 2000 Compatible Access group for the domain with which you are synchronizing. For more information about adding accounts to the Pre-Windows 2000 Compatible Access group, see Some applications and APIs require access to authorization information on account objects (http://go.microsoft.com/fwlink/?LinkId=179420).


Start the Required Services


1. Start the User Profile Synchronization service through Central Administration


• Confirm that the user account performing this procedure is a member of the Farm Administrators SharePoint group.


• On the SharePoint Central Administration Web site, click System Settings, and then on the System Settings page, in the Servers section, click Manage services on server.


• To change the server on which you want to start or stop the service, on the Server menu, click Change Server, and then click the server name that you want.


• By default, only configurable services are displayed. To view all services, on the View menu, click All.


• To start the service, click Start in the Action column of the relevant service.


• Click OK to start or stop the service. Be sure to enter the account info for the SharePoint farm admin account.






Wait about 10 minutes and verify the both ForeFront Identity Management services start up properly in services.msc. Once they start, do an IISRESET.




Create a Profile Synchronization Connection


1. Verify that you have the following administrative credentials:


• You must be a member of the Farm Administrators group on the computer that is running the SharePoint Central Administration Web site


• The Farm Administrator account must be a Service Administrator for the User Profile Service that you are configuring. For more information about how to set service permissions, see Assign administration of a User Profile service application (SharePoint Server 2010).


• If you are synchronizing profile information by using AD DS, the account that is used to connect to AD DS must have Replicate Directory Changes permissions in AD DS. This account must be the same as the farm administrator account or the User Profile Service administrator account and is required to do either full or incremental synchronization with AD DS. Create All Child Objects permission is needed to export properties, such as profile pictures, from SharePoint Server to AD DS.


2. Before proceeding, make sure that you have determined which directory service containers that you want synchronized with SharePoint Server. I have several test users already setup in an OU.


3. On the Central Administration Web site, in the Application Management section, click Manage service applications.


4. On the Manage Service Applications page, click the Name of the User Profile Service Application that you want to manage.


5. On the Manage Profile Service page, in the Synchronization section, click Configure Synchronization Connections.


6. On the Synchronizations Connections page, click Create New Connection.


7. On the Add new synchronization connection page, type a name for the synchronization connection in the Connection Name box.


8. From the Type list, select the kind of directory service to which you want to connect. AD in this case.


9. If the selected type is Business Data Connectivity, enter a name for the connection in the Name box. Select a Business Data Connectivity application from the Business Data Connectivity Entity box. Select whether the entity has a 1:1 mapping or a 1:many mapping, enter the appropriate profile property, and then click OK. Otherwise, continue with the following steps. - I'm ignoring this functionality for this post.

10. In the Connection Settings section, type the name of the directory service forest to which you want to connect (domain.com), the account credentials for the directory service (domain\admin), and the port that you want to use when you connect to the directory service (use the default) . Select Auto discover domain controller to automatically locate the domain controller for this forest or type the name of the domain controller in the Domain controller name box. - I don't recommend using the autodiscover. There have been other users who've reported problems, but I'll leave it up to you.


11. In the Connection Settings section, select the Use SSL-secured connection: check box, if needed, to use a Secure Socket Layer connection when you connect to the directory service.


12. In the Containers section, click Populate Containers and then select the containers from the directory service that you want to synchronize. Click Select All if you want to synchronize all containers. For example, if you only want to synchronize user information, you can select only those containers that have user profile information.



13. Click OK.


To configure Profile Synchronization settings




1. Verify that you have the following administrative credentials:


• You must be a member of the Farm Administrators group on the computer that is running the SharePoint Central Administration Web site


• You must be a Service Administrator with Full Control permissions for the User Profile Service that you are configuring. For more information about how to set Full Control permissions, see Assign administration of a User Profile service application (SharePoint Server 2010).


• The Farm Administrator account, which is created during the SharePoint farm setup, must also be a System Administrator (sysadmin) on Microsoft SQL Server 2005 or Microsoft SQL Server 2008


• If you are synchronizing profile information with AD DS, the account that is used must have Replicate Directory Changes permissions. This account must be the same as the farm administrator account or the User Profile Service administrator account and is required to do either full or incremental synchronization with AD DS. Create All Child Objects permission is needed to export properties, such as profile pictures, from SharePoint Server to AD DS.


2. On the Central Administration Web site, in the Application Management section, click Manage service applications.


3. On the Manage Service Applications page, click the Name of the User Profile Service Application that you want to manage.


4. On the Manage Profile Service page, in the Synchronization section, click Configure Synchronization Settings.


5. On the Configure Synchronization Settings page, in the Synchronization Entities section, select Users and Groups to synchronize both user information and group information or select Users to synchronize only user information.


You should first do a full synchronization of users only. Once this is complete, run an incremental synchronization of both users and groups.


6. On the Configure Synchronization Settings page, in the Synchronize BDC Connections section, click to clear the Include existing BDC connections for synchronization? check box if you want to exclude data import from the Business Data Connectivity service. - No BDC for now.


7. On the Configure Synchronization Settings page, in the External Identity Manager section, select Use SharePoint Profile Synchronization to use the Profile Synchronization engine in SharePoint Server 2010 or select Enable External Identity Manager to use an external synchronization application such as Microsoft Identity Lifecycle Manager 2007.


Enabling an external identity manager disables all Profile Synchronization options and the status display in SharePoint Server 2010.





8. Click OK.


In Part II of this blog I'll go through the steps to do the initial synchronization and show you how to use the MIIS client to verify it's working properly.

Monday, March 29, 2010

SharePoint 2010 Architecture Drawing

I've recently been working on an architecture drawing for our SharePoint 2010 environment and I thought I'd post it here. The drawing covers all aspects of our environment from development to our internal environment (intranet) to our external facing public website. Take a look and feel free to post your comments.


Friday, March 26, 2010

Automate SharePoint 2010 Farm Backups with Powershell

***Update (01/07/2013): We recently noticed that installing KB2506143 (Windows Management Framework 3.0) breaks the ability for SharePoint Powershell to run the backup. Uninstall it and the script should start working again.***

We've had a lot of requests for more details on how to setup automated SharePoint backups with PowerShell, so we've gone ahead and created a detailed ebook which outlines the steps and permissions you need to get your backups up and running. In addition to screen shots, there are also copies of the scripts we use as well as an email notification section that will let you know if your backups failed. Simply click on the Buy Now button below and you can pay with your Paypal account or credit card. At only $9.99 USD, it's thousands cheaper than a 3rd party solution and will let you sleep a little sounder at night. If you're not satisfied, we'll gladly refund your money! For the basic steps minus some of the more advanced funtionality, see below.


I recently built several server farms for our developers to work on. In order to make sure I could restore the farms to their original condition, I setup the following automated backup process. Below is a brief outline of the steps.

1. Create a folder on a local drive of the SharePoint 2010 server called backups (E:\backups). Share that folder as "backups" and give the account you used to install SharePoint as well as the farm and SQL database accounts full access (share permissions and NTFS).

2. Create a folder in E:\backups called Scripts. Inside there you create 4 files:

• backupsharepointfarm.ps1 – This script will backup your entire farm to the share you created. This script will contain the following:

Add-PsSnapin Microsoft.SharePoint.Powershell
Backup-SPFarm -Directory \\ServerName\Backups -BackupMethod full

• cleanbackups.ps1 – This script will check the spbrtoc.xml file and delete backups older than 7 days so you don’t run out of disk space. You can change $days value. This script will contain the following:

# Location of spbrtoc.xml
$spbrtoc = "E:\Backups\spbrtoc.xml"

# Days of backup that will be remaining after backup cleanup.
$days = 7

# Import the Sharepoint backup report xml file
[xml]$sp = gc $spbrtoc

# Find the old backups in spbrtoc.xml
$old = $sp.SPBackupRestoreHistory.SPHistoryObject |
? { $_.SPStartTime -lt ((get-date).adddays(-$days)) }
if ($old -eq $Null) { write-host "No reports of backups older than $days days found in spbrtoc.xml.`nspbrtoc.xml isn't changed and no files are removed.`n" ; break}

# Delete the old backups from the Sharepoint backup report xml file
$old | % { $sp.SPBackupRestoreHistory.RemoveChild($_) }

# Delete the physical folders in which the old backups were located
$old | % { Remove-Item $_.SPBackupDirectory -Recurse }

# Save the new Sharepoint backup report xml file
$sp.Save($spbrtoc)
Write-host "Backup(s) entries older than $days days are removed from spbrtoc.xml and harddisc."

• Backup.bat – This is a simple batch file to run the above backupsharepointfarm.ps1 script. Create a scheduled task to run it every night. The file contains the following:

powershell -command E:\Backups\Script\BackupSharePointFarm.ps1

• Clean.bat – This batch file will run the script to clean out older backup files (cleanbackup.ps1). The file contains the following:

powershell -command E:\Backups\Script\cleanbackups.ps1

3. Create a scheduled task that will run both of the .bat files you created and set them to run at night when no one’s around. You have to make sure the scheduled tasks are set to run with the SharePoint farm account. After a full week you’ll have a directory with 7 days worth of backups similar to the following:







Note: In order to run PowerShell commands on your server, you need to open powershell and execute the following command: Set-ExecutionPolicy Unrestricted

There are several factors involved in running a successful scripted backup which are covered by Todd Klindt in the following Microsoft SharePoint forum thread: http://social.technet.microsoft.com/Forums/en-US/sharepoint2010setup/thread/f755e7c1-bd0a-4c00-9be6-bbca83cf666b/.

1.Your Central Admin app pool account must have read/write access to the location of the backups.

2.Your SQL Service account must have read/write access to the location of the backups.

3.If you're running a farm backup from STSADM or Windows PowerShell, the account you're running it as must have read/write access to the location of the backups

4.The location must be accessible from the SharePoint machine the backup is running on.

5.The location must be accessible from the SQL instance that SharePoint is trying to back up.

6.This is why all the examples are UNCs, \\server\share, and not local paths, C:\backups

That’s about it. Give it a try and let me know if you have any problems. The file and share permissions are critical!