Sharing the experience search

Search sharing-the-experience.blogspot.com

Wednesday, November 2, 2011

Simple concept: Profile synchronization log file

[Question]:
The profile synchronization failed. I found an error in the Event log:



The management agent  failed on run profile "DS_FULLIMPORT" because of connectivity issues.

 Additional Information
 Discovery Errors       : "0"
 Synchronization Errors : "0"
 Metaverse Retry Errors : "0"
 Export Errors          : "0"
 Warnings               : "0"

 User Action
 View the management agent run history for details.



Where is the management agent?


[Answer]:


C:\Program Files\Microsoft Office Servers\14.0\Synchronization Service\UIShell\miisclient.exe

Service Application : Architecture in one picture

Recently, I have been studying the inner work of Service Applications in SharePoint 2010.
I have discovered several terms that can be confusing if you haven't dived yet into the theory.


Service application -  in the general case, are just a logical concept made up of one or more components, one of which may be an actual Service Application component that defines the configurations for a particular implementation of a specific Service Instance." (Gary Lapointe's book)


Service application (second meaning - most used) - a management interface with some SQL back end (_admin/ServiceApplications.aspx)


Service application Endpoint - IIS Virtual application - a WCF service (a WCF service per a service application)


Service instance  - a dll, register keys, binary files, timer job (_admin/Server.aspx)


(Got Access denied error on _admin/Server.aspx? - Read on Simple concept: Manage services on server link is missing)


Here is a simple picture to see the relationships between the components of the Service Application:



Tuesday, November 1, 2011

"SharePoint 2007 to 2010 Upgrade" online project (part 8) : How to start User Profile Synchronization service

[What you have]:
You have a 2010 farm.

[What you want]:
You want to pull users from AD into Profiles.

[What you want to know]: 
Here is a beautiful represenation of User Profile Architecture from UPA 2010 : Intro – Part1
In order to get AD connection configured, you want to configure User Profile Synchronization.
Before you get your hands dirty with that, the essential understanding of the User Profile architecture is required.

Terminology:

User Profile Application -  a logical set of functionality that allows to have profiles, and if needed social tagging, my site functionality (note: you can configure whether users will be able to create "my site" -Central Administration  Manage Profile Service: User Profile Service -> Manage User Permissions)

"A key thing to understand is that Service Applications, in the general case, are just a logical concept made up of one or more components, one of which may be an actual Service Application component that defines the configurations for a particular implementation of a specific Service Instance." (Gary Lapointe's book)

( you want more of that? - Service Application : Architecture in one picture)

What is the User Profile Synchronization service anyway? - just a wrapper for the ForeFront Identity Manager (FIM) services.

[What you want to do]:

Make sure that:
1. Start the “User Profile Service” first.
2. Create the “User Profile Service Application”
"You must create the User Profile Service Application while logged on as the Farm Account 
This is generally contrary to well-understood best practices that stipulate that you should never log as the Farm Account, but unfortunately, it is a neccessary eveil due to an issue with how the Service Application is created."
(Gary Lapointe's book)

Now you are ready to kick the User Profile Synchronization server off:

1. Make sure that A farm account is in the Farm Administrator group (/_layouts/people.aspx?MembershipGroupId=3).
2. Add temporarily a farm account into Local Administrators group on the application server where you want to run the User Profile Synchronization service.
3. You logged as a farm account into the application server where you want to start the User Profile Synchronization service.
4. Network service account is a member of WSP_WPG group on that application server
5. Don't forget to reset the application server if you have just added a member to the local group. I even would recommend to restart IIS and SharePoint 2010 Timer.

In case NetBIOS Name and FQDN mismatch:

Before Start User Profile Synchronization Service:
First, enable netbios name 
$UserProfileServiceApp = Get-SPServiceApplication | where {$_.TypeName -eq "User Profile Service Application"}                                                                                           
   $UserProfileServiceApp.NetBIOSDomainNamesEnabled = 1                                                                                                                                             
   $UserProfileServiceApp.Update()    


6. Run User Profile Synchronization service on the same application server where the User Profile Service is running.
7. IIS reset after the provisioning of User Profile Synchronization service
8. The permanent assigment "log on locally" must be granted to the Farm Account (Local Policies->User Rights Assignments - Allow Log on locally).
"Though adding the farm Account into the Local Administrator group does achieve this, do not be tempted to leave the Farm Account in the group as doing so is considered a security risk". (Gary Lapointe's book)

9.Check whether User Profile Synchronization works. If it does, remove the farm account from Local Administrator group, you don't need it anymore.

* Because User Profile Sync Service doesn't work with the managed account, if you ever change the farm account password, it will break the user profile synchronization

**Farm backup will stop the User Profile and after the backup job is done, it will try to start the User Profile Service. If at that time all required conditions (That mention above) don't meet, you will end up with broken USP after the farm backup. (Why SharePoint backups break the User Profile Sync Service and other mysteries solved (Todd Klindt))

[What you want to consider]:

To get more details on the topic - Rational Guide to implementing SharePoint Server 2010 User Profile Synchronization

To know exactly what's going on under the hood - refer to UPA 2010 : Setting up the User Profile Service Application

My personal respect to the  author of the post Forefront Identity Manager & User Profile Synchronization Service. This post is responsible for that I got the User Profile Synchronization running.

To encourage me to write you  helpful posts, you can acquire knowledge from a great book by Gary Lapoint through Amazon associate program. (just click this link and buy Automating SharePoint 2010 with Windows PowerShell 2.0)

Simple concept: Manage services on server link is missing

[Question]:
I have logged into Central Administration as a farm account but I can't see the link "Manage services on server".
The request of the page _admin/Server.aspx gives an error "Access denied".
Where the link to "Manage services on server"?


[Answer]:
First of all, I don't know the true nature of permission on the page _admin/Server.aspx. But I have discovered that my farm account can't get to it - Access denied.
In order to make it through:


I have added a farm account into Local Administrator group.(Btw, it goes against the Best Practices)


I have logged  as a farm account on the server  where Central Administration is running.


Vuala!


P.S.


As I understand the _admin/Server.aspx, it shows you the services that are running on the server and you can manage them. And because these services are really running on this box, I would say it makes sense to restrict the use of page only to local administrators.
The question is arising, why would you login as a farm account to manage services on server? And again I can see the reason behind it. For example, for user profile synchronization I heard it's needed to login as a farm account to start the service.





Friday, October 28, 2011

PowerShell: Add-SPSolution -force when wsp is already deployed

[What you have]:
A 2010 SharePoint Farm. A WSP file that you want to deploy. 

[What you want]:
You want to make sure that a wsp file will be deployed even the solution is already installed.

[What you want to know]: 
To add a solution to the farm - make use of Add-SPSolution. Notice that the Add-SPSolution cmdlet returns the SPSolution object. That means that you can pipe the result  - an added wsp - into Install-SPSolution. 
-LiteralPath - must be the full path.  You can make use of Resolve-Path to get a a full path from a relative

$path= Resolve-Path .\custom.wsp
$wsp = Add-SPSolution -LiteralPath $path

-local attribute in Install-SPSolution means that the wsp file will be deployed only on the server where the command gets run. That means if farm has more than one web front, all others will not get files installed on their SharePoint root. (what is the SharePoint - read on Best Practices 2010)

-GACDeployment . If wsp has a dll to put into GAC, but the parameter is no specified, an error will be returned. The same true for CASPolicies.

Remember that should do only one deployment at a time. The same true for re-traction.
To check the status of the deployment - use $wsp.Deployed property.

Uninstall-SPSolution will retract a wsp file. Remember to deactivate features first if you are not planing to deploy the wsp or a new version doesn't contain those features. Otherwise, you will leave those features in an invalid state.

Remove-SPSolution to delete the wsp file from the farm. The Farm solution must have been fully retracted before deletion.

Upgrade-SPSolution - will upgrade a solution. This is an alternative for retracting and uninstalling a wsp file before adding and installing a new version. Be mindful that Upgrade-SPSolution works only if you haven't  added a new feature\module to your solution. 


Do you want to know whether wsp will trigger IIS reset? Look at a attribute ResetWebServer in the Solution tag in the manifest.xml

[What you want to do]:
Run the following PowerShell script to deploy a wsp when the wsp is already deployed on the farm: PowerShell Script for SP2010: Add-SPSolution -force when wsp is already deployed

A quick note:
start-sleep ,in my case, helped me to avoid an error:
The solution cannot be removed when a job is scheduled or running

I haven't investigated the true nature of the error and its meaning.
The line Uninstall-SPSolution $wsp -AllWebApplications   -Confirm:$false generates an error:
Cannot uninstall the LanguagePack 0 because it is not deployed.
But still the code executes normally and adds the solution. Again, I haven't investigated the cause of the error. I appreciate your comments\feedback on that matter.

[What you want to consider]:
To get more skilled with PowerShell in SharePoint 2010 - highly recommend to read a book from Gary Lapointe.
Buy the book to support my effort in sharing the experience  through amazon associates:
Automating SharePoint 2010 with Windows PowerShell 2.0




Friday, October 21, 2011

BDCM: How to set permissions through the code?

[What you have]:
You have a BDCM file.


[What you want]:
You want to set permissions on the model and External Content Types (ECT) through the code.


[What you want to know]: 
You need to make sure that you have at least one access control entity with enough permission to avoid an error:
 At least one user/group in the Access Control List must have the SetPermissions right to avoid creating a non-manageable object.

There are 3 options how you can populate permissions through the code.

[What you want to do]:


1. PowerShell:


 $userAccountAdministrator = "{Domain}\{AdminUser}"; 
 $allUsers = "NT AUTHORITY\Authenticated Users";

 $userAdministrator=[Microsoft.SharePoint.BusinessData.Infrastructure.BdcAccessControlList]::TranslateFriendlyStringToEncodedClaim($userAccountAdministrator);
 $allUsers=[Microsoft.SharePoint.BusinessData.Infrastructure.BdcAccessControlList]::TranslateFriendlyStringToEncodedClaim($allUsers);

 $bdcRightsAdministrator= @([Microsoft.BusinessData.Infrastructure.BdcRights]::Execute, [Microsoft.BusinessData.Infrastructure.BdcRights]::Edit,[Microsoft.BusinessData.Infrastructure.BdcRights]::SetPermissions,[Microsoft.BusinessData.Infrastructure.BdcRights]::UseInBusinessDataInLists,[Microsoft.BusinessData.Infrastructure.BdcRights]::SelectableInClients); 
 $bdcRightsAllUsers= [Microsoft.BusinessData.Infrastructure.BdcRights]::Execute; 


 $aceAdministrator = New-Object "Microsoft.SharePoint.BusinessData.Infrastructure.IndividualAccessControlEntry" -arg $userAdministrator,$bdcRightsAdministrator ;
 $aceAllUsers=New-Object "Microsoft.SharePoint.BusinessData.Infrastructure.IndividualAccessControlEntry" -arg $allUsers,$bdcRightsAllUsers ;

$models=@(
"{Your model1}",
"{Your model2}",
"{Your model3}"
);


foreach ($modelName in $models)
{
$Model = Get-SPBusinessDataCatalogMetadataObject -BdcObjectType "Model" -name $modelName -ServiceContext {web app url}


$lbsAcl=$Model.GetAccessControlList();                                                                                                                                                                                                                           
$lbsAcl.Add($aceAdministrator);                                                                                                                                                                                                                                                        
$Model.SetAccessControlList($lbsAcl);                                                                                                                                                                                                                           


$entities=$Model.AllEntities;


foreach ($entity in $entities)
    {
      Write-Host $entity.DefaultDisplayName 


      $acl= $entity.GetAccessControlList(); 
      $acl.Add($aceAdministrator);
      $acl.Add($aceAllUsers);                                                                                                                                                                                                                                                           
      $entity.SetAccessControlList($acl);                                                                                                                                                                                                                                         
      $entity.CopyAclAcrossChildren();                                                                                                                                                                                                                                               
    }
}




2.  Feature receiver
Code Snippet: Add an Access Control Entry to a MetadataObject Using the Administration Object Model
  You can copy paste the code into your custom feature receiver.

3. Declaratively in a BDC Model:

  <AccessControlList>
    <AccessControlEntry Principal="{domain}\{AdminUser}">
      <Right BdcRight="Edit" />
      <Right BdcRight="Execute" />
      <Right BdcRight="SetPermissions" />
      <Right BdcRight="SelectableInClients" />
    </AccessControlEntry>
  </AccessControlList>


The BDC Model has a element <AccessControlList> in several places:
1. Permissions on the Model: inside <Model> tag
2. Permissions on External Content Type: inside <Entity> tag
3. Permissions on the method of ECT (in UI if the options is selected "Propagate permissions to all methods of this external content type. Doing so will overwrite existing permissions"): inside <Method> and <MethodInstance>


"SharePoint 2007 to 2010 Upgrade" online project (part 7) : In-place upgrade BDC failed: the bdc service application is not accessible There are no addresses available for this application

[What you have]:
 An Upgraded 2007 farm by means in-place upgrade model ("SharePoint 2007 to 2010 Upgrade" online project (part 3): "Theory"). After you have upgraded the farm, you have
[name of your 2007 SharedServices] - Business Data Connectivity Service where all converted BDC files reside.  On click on that service you are getting the error: 
the bdc service application is not accessible. There are no addresses available for this application

[What you want]:
Fix the error and use the the converted BDC files.

[What you want to know]: 

You may first try to google the error itself. My google findings couldn't  fix the errors. And I ended up removing the broken BDC service. But before removing I exported all converted BDCM files. This post is all about How to export BDCM out of the broken BDCS.
(Btw, still confused with BDC and similar abbreviation? - welcome to read post on SharePoint 2010: BCS and BDC)

[What you want to do]:
Firstly, try to export BDCM using SPD 2010. My attempt has failed. And I happily returned to PowerShell to get my BDCM files out of the Business Connectivity Service 
(Want a quick intro into PowerShell and SharePoint - PowerShell and SharePoint: What, Why and How)


Here is the code to export BDC models:


$models=@(
#array of your model names
);
foreach ($modelName in $models)
{
$path =  "G:\temp\LOCAL\BDCM\{0}.bdcm" -f $modelName;
$Model = Get-SPBusinessDataCatalogMetadataObject -BdcObjectType "Model" -name $modelName -ServiceContext {your web application URL}
if ($Model -ne $null)
{
Export-SPBusinessDataCatalogModel -Identity $Model -Path $path -force
Write-Host "The model $modelName has been exported";
}
}