Monday, January 24, 2022

SCCM 1702 Update not visible in Console

SCCM 1702 Update not visible in Console

Folks,

After multiple times done the "Check for updates " SCCM Console still the 1702 update not appearing . so MS SCCM team posted powershell code to get it in seconds of time, The below link to get the powershell code.

Get-Code


Please click answer If it works Thanks KMI


Reply:

have you reviewed dmpdownloader.log?

make sure you run the powersehll console with elevated permissions.


------------------------------------
Reply:
That's because 1702 is currently considered "fast-ring" which means you need to explicitly opt in to receive the update at this time. This is the same process that was followed for both 1606 and 1602. Nothing new and clearly spelled out in the announcement posted by the product group.

Jason | http://blog.configmgrftw.com | @jasonsandys


------------------------------------
Reply:

True agree ..! Intension to create the discussion point " Share this powershell script to others too"


Please click answer If it works Thanks KMI


------------------------------------
Reply:
PowerShell script to enable fast-ring for 1702 can be found here: https://gallery.technet.microsoft.com/ConfigMgr-1702-Enable-c20180fd

------------------------------------
Reply:
Yes , same mentioned in my first itself - click on Get-Code , you will get same

Please click answer If it works Thanks KMI


------------------------------------
Reply:
Just a general question, is there any benefit from getting the update on the fast ring as supposed to waiting for the download to come through on its own?  Does the normal release contain updates based on feedback from the fast ring group or are they exactly the same?

JacquesB4


------------------------------------
Reply:

If (critical) bugs came up, they will be included in the normal release.

The fast rings becomes a fast ring update rollup in this case.


------------------------------------
Reply:
This worked for me.. Thanks!

------------------------------------
Reply:
PowerShell script to enable fast-ring for 1702 can be found here: https://gallery.technet.microsoft.com/ConfigMgr-1702-Enable-c20180fd

I receive the below when I go to this URL

This item is not yet published.

If you are the owner of this project, please sign in with the appropriate account. 


------------------------------------
Reply:
You don't need that script anymore. 1702 is already available for everyone.

------------------------------------

Migrating from Exchange 2003 to 2013

I know there isn't a migration path for Exchange 2003 but has anyone tried any type of work around?  I'm thinking about moving one of my customers users mailboxes to PST files and them importing them into Exchange 2013 on a 2012 server.  Has anyone had any experience doing this?  Below are the details of what I have and what I was thinking about doing:

Small Network - approx. 10 users

Server 2003 Sp3 standalone AD DC with Exchange 2003

Would like to move straight to Server 2012 with Exchange 2013

If I export the mailboxes and uninstall Exchange from the 2003 server will Server 2012 join the domain and upgrade the existing AD schema (forest and domain)?  If it would, could I then install Exchange 2013 on that server, create the mailboxes for the users and import the PST files?

Just wondering if anyone has tried this, or something similar.  They don't have an extra server to move everything to 2010 first so it's either a workaround or move them to Exchange 2010 (which Microsoft has quit selling).  I'm sure this will put a lot of small business VARs in a bad situation. 

(Just as a side note) Is it true that Dell and HP have quit selling Windows 7 Pro? My vendor still sells it and will for 18 more months.

  • Changed type Kimberlain Friday, December 14, 2012 9:29 PM Discussion

Reply:

Exporting to a PST and importing from a PST will work.  However, your users will likely have a miserable experience if you don't take care and retain their original legacyExchangeDN attribute as a proxy address of type X500 (no dot) when you recreate the mailboxes in Exchange 2013.  Also, I hope you don't have public folders, because they'll have to be exported and imported with permissions and e-mail addresses recreated.

Seriously, I believe you would find it easier to transition to Exchange 2010 and then to Exchange 2013.


Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."


------------------------------------
Reply:
I understand what you are saying.  There are no public folders, they are just using it for email, but I think you are correct.  I think it would take too much time and have too may 'bugs' to go straight to 2013.  Plus they don't have an extra server to go to 2010 first so we'll end up just upgrading them to 2010 and leave it for now.  Maybe in a few years they will purchase another server and be able to jump a couple of versions.  I can't find a feasible away round this one.

------------------------------------
Reply:
That is probably a wise path.

Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."


------------------------------------
Reply:

I've got same dilema, user has only 5 user accounts, very small setup but win 2008r2 is already joined to a domain, promoted to a DC. User wants to migrate to 2013 and since he can't i am looking what is the best way to do it. 

Since it's very small installation i would say the best way would be to install new separate forest, import PST files to newly created users and join all computers to a new domain.

Opinions?


------------------------------------
Reply:

Hi

That would be acceptable seeing as there are only 5 users - remember to keep the legacyExchangeDN and convert it to X500 proxy addresses.

Something that would be even more acceptable (or at least worth considering) is Office 365 - the cost for 5 users must be less than the licenses and maintenance of a local server.

Cheers, Steve


------------------------------------
Reply:

Hi Steve,

you sure i'll have legacyExchangeDN in new forest that does not have any relation to the existing 2003 forest?

Regards,

Damir


------------------------------------
Reply:

Hi Steve,

you sure i'll have legacyExchangeDN in new forest that does not have any relation to the existing 2003 forest?

Regards,

Damir


You will have a new legacyDN in the new Org but you should add the the legacyDN from the old Org as a x500 address for each user in the new Org.

Sukh


------------------------------------
Reply:

That approach is usually the worst way.


Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."


------------------------------------
Reply:

m$ really dropped the ball on this one not supporting a migration path from 2003 (or any other exchange product as of this writing actually). Dumping to PST and then importing PST is about the most labor intensive and time consuming method possible for us actually doing the work. If you have 5 mailboxes, sure. If you have 5 mailboxes, I am not sure why you are even using Exchange, but that's another story. When you have 5000+, please...

As far as microsoft "quit selling" exchange 2010 (and any other "legacy" product), that's not really true. If you buy the current version via volume licensing, you have downgrade rights and can install 2010, or 2007, or whatever. We just bought a bunch of SQL and Server licenses via volume select and have rights to use server 2008, sql2008, etc.


------------------------------------
Reply:

They didn't drop any ball at all.  I don't know of any product where they've supported direct upgrades from three versions back.


Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."


------------------------------------
Reply:

Hi,

We don't support an "upgrade" from Exchange 2003 to 2013, however, we do support a cross-forest migration. In fact, we support going from 2000, 2003, 2007, & 2010 directly to Exchange 2013 in a cross-forest scenario. Obviously, this would require a resource forest, however, it is still a viable option vs. having to migrate (i.e. move mailboxes) multiple times to jump versions and in some cases has less risk to the production AD/Exchange environment.

Link to product:

http://www.priasoft.com/

Link to more info on resource forests:

http://community.priasoft.com/blogs/exchange_migration_team_blog/archive/2010/05/20/using-a-dedicated-exchange-forest-resource-forest.aspx

Hope this helps, Cheers!


CJ www.priasoft.com


------------------------------------
Reply:

You can also try this tool for direct 2003 to 2013 migrations of Exchange:

http://www.codetwo.com/exchange-migration?sts=2948

However in this scenario it supports cross-forest migrations only. I believe it's because Exchange 2003 and 2013 can't co-exist in one forest...

Cheers


------------------------------------
Reply:

Just to be clear. My client purchased a new server that is part of the domain that they are going to use to run Exchange 2013 and aware they are many revisions behind on Exchange. They have fifteen user mailboxes that we will export to pst files. Upon export completion we will uninstall Exchange 2003. We will then install Exchange 2013 on the new server. Is there anything I am missing other than this is going to take some time?

Alex


------------------------------------
Reply:
Alex, I don't think your missing anything. However, the process you are suggesting is certainly not ideal and does carry some significant risks because there will be a long period of time where there will be no mail available in the domain. That may not only affect the users, but also applications that are installed in the environment an using Exchange as a relay point. If you must take that path, it should be possible to install 2013 once all the 2003 servers are out of the environment. That aside, for 15 users, there should be some serious consideration of going to 2010 or 365 as the other community members are suggesting.

-DK


------------------------------------
Reply:
The way that I would do it is install 2012 and create virtual server 2008 with exchange 2010 and then migrate to exchange 2010. Then decommission the 2003 and remove from domain. Then install 2013 on windows 2012 and migrate to 2013. Remove exchange from win2008 and decommission that virtual server and you have successfully migrated to exchange 2013 with out any loss of data and the users will not even know they are on a new server

------------------------------------
Reply:
*Plus the cost of licensing the swing Exchange 2010 server instance.

------------------------------------
Reply:

1. Exchange 2010 comes with 180 days trial (more than enough for such a project), so there is no licensing cost for the swing.

2. Obviously, you will need some preparation and planing for the Exchange 2010 swing and using a virtual machine is not a bad idea.

3. If you choose the Exchange 2010 path, you will not be pressed on time and the downtime will be minimal.


------------------------------------
Reply:

I concur with the migrate to Exchange 2010 first. However, I would stop there. Just stay with Exchange 2010 for now. Unless there is some specific feature you desperately need out of Exchange 2013, Exchange 2010 is what you want, really.

The users won't be clawing their eyes out and putting hate notes on your desktop over the OWA experience due to all the whiteness of the new Office 2013 look and feel. You won't be clawing your eyes out either when having to use ECP and will be able to use the much better EMC along with the additional toolsets (that aren't available in Exchange 2013, like the BPA). MAPI and other services will continue to work correctly. Most importantly, you won't have to endue the nearly endless stampede of CU bugs and pulled patches that seems to define Exchange 2013 as of late.

  • Edited by ABCFED Wednesday, August 21, 2013 11:35 PM asdfsd

------------------------------------
Reply:

I concur with the migrate to Exchange 2010 first. However, I would stop there. Just stay with Exchange 2010 for now. Unless there is some specific feature you desperately need out of Exchange 2013, Exchange 2010 is what you want, really.

The users won't be clawing their eyes out and putting hate notes on your desktop over the OWA experience due to all the whiteness of the new Office 2013 look and feel. You won't be clawing your eyes out either when having to use ECP and will be able to use the much better EMC along with the additional toolsets (that aren't available in Exchange 2013, like the BPA). MAPI and other services will continue to work correctly. Most importantly, you won't have to endue the nearly endless stampede of CU bugs and pulled patches that seems to define Exchange 2013 as of late.


Yes, and do not forget to move them back to Windows 95.  :)


Please "Vote As Helpful" and/or "Mark As Answer" if this post helped you.


------------------------------------
Reply:

I concur with the migrate to Exchange 2010 first. However, I would stop there. Just stay with Exchange 2010 for now. Unless there is some specific feature you desperately need out of Exchange 2013, Exchange 2010 is what you want, really.

The users won't be clawing their eyes out and putting hate notes on your desktop over the OWA experience due to all the whiteness of the new Office 2013 look and feel. You won't be clawing your eyes out either when having to use ECP and will be able to use the much better EMC along with the additional toolsets (that aren't available in Exchange 2013, like the BPA). MAPI and other services will continue to work correctly. Most importantly, you won't have to endue the nearly endless stampede of CU bugs and pulled patches that seems to define Exchange 2013 as of late.


Yes, and do not forget to move them back to Windows 95.  :)


Please "Vote As Helpful" and/or "Mark As Answer" if this post helped you.

No, I think Windows 7 is g-reat. No need to install Windows 95. But, um...not sure what problem you had with my points.

1. The new look and feel of the "new" OWA looks like Office 2013, which a number of users don't like. 

http://social.technet.microsoft.com/Forums/en-US/df70a27c-f3d3-41e8-a0ab-a408229b2b31/are-there-any-plans-to-add-more-office-2013-themes

2. The EMC is, even still, a better tool at presenting the data to the admins. Rather than a drop down box that hides the servers before you click it, you can see all the servers in a list in the EMC, for example. The EMC takes less mouse clicks to accomplish the same task. 

3. The toolbox is just plain gone now. The BPA is gone. All the neat tools are gone in Exchange 2013. There isn't a replacement. 

4. MAPI doesn't work now, so Exchange 2010 will support older clients and Exchange 2013 won't.

5. They just pulled the CU2 update and just a few days ago pulled another critical patch. Look at all this "wonderful" feedback they have received: 

http://blogs.technet.com/b/exchange/archive/2013/08/14/exchange-2013-security-update-ms13-061-status-update.aspx

All of those I listed above are reasons why one should stick with Exchange 2010. Being the "latest and greatest" in this case isn't a good thing. Skip Exchange 2013 until at least the SP1 comes out then re-evaluate it. It's just not baked yet. They've focused way too much development effort on their cloud on not enough for their onsite customers in this release. 

That's of course my opinion, others will of course have different opinions.

:)

  • Edited by ABCFED Thursday, August 22, 2013 1:48 AM asdasd

------------------------------------
Reply:

If you consider any of the following...

Initial costs.

Cost of ownership.

Compatibility with other email systems.

Security and responsiveness of vendor (MS) to known issues.

...any one of those issues is enough to drop (Virus) Exchange from consideration. Take a look at Kerio or Zimbra, both have migration tools. The typical uptime of either running on Linix or Ubuntu equals the age of the server. The mail systems need restart of services with upgrades but yes, the OS of my mail servers run for years without reboots.

I call BS here.  I'm not a lover of MS products, but Exchange is solid.  And if you're really running servers for years without reboots then you're not applying critical updates (yes, Linux has them too) in a timely manner. 

Uptime isn't the factor it used to be with virtual machines.  I can restart my Exchange environment in less than one minute.  Painless. 


------------------------------------
Reply:

If you consider any of the following...

Initial costs.

Cost of ownership.

Compatibility with other email systems.

Security and responsiveness of vendor (MS) to known issues.

...any one of those issues is enough to drop (Virus) Exchange from consideration. Take a look at Kerio or Zimbra, both have migration tools. The typical uptime of either running on Linix or Ubuntu equals the age of the server. The mail systems need restart of services with upgrades but yes, the OS of my mail servers run for years without reboots.

I call BS here.  I'm not a lover of MS products, but Exchange is solid.  And if you're really running servers for years without reboots then you're not applying critical updates (yes, Linux has them too) in a timely manner. 

Uptime isn't the factor it used to be with virtual machines.  I can restart my Exchange environment in less than one minute.  Painless. 

Well Said!

------------------------------------
Reply:
It's easy enough to stand up an Exchange 2010 server to perform intermediate migrations.

Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."


------------------------------------
Reply:

Hello sir.

I was so anxious to remove the Exchange 2003 that I completly forgot to write donw the LegacyExchangeDN values.

I simply removed Exchange 2003 and installed 2013. Now all the users can access OWA and Mobile Access but Outlook doesn't work at all. Please help!!


------------------------------------
Reply:

Hello

We are trying to do the exact same thing now.  Migrate from exchange 2003 to 2013 with around 10 mailboxes.  How many hours do you think would be appropriate to be billed for this labor?

Thanks in advance

Also note we have a new server already setup with 2012 R2 and vmware to move to.


  • Edited by alex98777 Thursday, January 28, 2016 2:33 PM

------------------------------------
Reply:
How long is a piece of string?  It really depends on how much freedom you have to act and how well you know what you're doing.

Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."
Celebrating 20 years of providing Exchange peer support!


------------------------------------
Reply:

<Leaving my comment in place even though the Priasoft shill deeted his message.>

Why do you guys post like you're giving an impartial endorsement when you work for the company you're touting?


Ed Crowley MVP "There are seldom good technological solutions to behavioral problems."
Celebrating 20 years of providing Exchange peer support!



------------------------------------
Reply:

Hey CJ.

Will you be required to install exchange 2013 on different forest or the same forest ?


------------------------------------
Reply:
I would have to be cross forest as Exchange 2013 will flat out refuse to install if the forest has a 2003 server within its records

Search, Recover, Export Mailboxes, Folders, Email, Contacts, Calendars, Tasks, etc. from Offline Exchange Databases (EDBs), On-Premise Exchange Servers and Office 365. Migrate/Recover direct from any offline EDB into any On-Premises Exchange Server, even cross version i.e. 2003 → 2007 → 2010 →2013 → 2016 → Office 365 with Lucid8's DigiScope


------------------------------------

Sharepoint Alert notification not working

Dear All,

I have a technical problem regarding a custom alert. The native sharepoint alert notification works very well (I tested it in a document library, no problem i receive an email).

User's path is as follows:

If a user wants to receive an alert notification on a page,  he just needs to check a box (custom development on the page based on SharePoint's standard alert notification feature).

So when a user edits this page and he has checked the box before, he doesn' t receive any emails.

Do you have an idea where could it come from?

Thank u very much in advance for your help.


Reply:

Hi Valerie- need clarification. Are you saying if you perform the same steps as the user, then it works for you? Or, are you saying that you're just setting up an alert the usual way and it works, but you haven't tested the user's way?

The first thing I'd check is to see whether the user's alert actually got saved. Take a look at the site settings under user alerts and see if they have one.

What is your custom development? Can you provide it so we can look it over?

If none of that is the issue, then my best guess would be that his email is getting bounced. Check the server to see if that's the case. Or, if there's a duplicate account/similar account to the user's.


cameron rautmann


------------------------------------
Reply:

Hi Cameron,

Thank you for your quick reply. I will check what you suggest "The first thing I'd check is to see whether the user's alert actually got saved. Take a look at the site settings under user alerts and see if they have one." :)

To answer your question:

I cannot provide the custom development. I didn't do this development. But I think that this checkbox is a control in the page. So instead of defining an alert for a page from the Sharepoint ribbon (the standard way which can be less user friendly for users), the developers created a control in the page (a checkbox to be checked). So if a user wants to be alerted when a change is made in the page. he has to check this box. And then if this user himself or another user edits the page and change anything in the page, the person who asked to receive an alert for any changes, must receive an email. Developers say that this custom control (the checkbox) works with the SharePoint standard alert system.

 I can confirm that the alert system on my platform works perfectly well : I defined an alert in a standard document library, and made a change in the property of a document, and I received the email notification confirming my change.

Don't you think that it could be a problem of webconfig? 

Question : how can i check the server to see that the mail is getting bounced? where should i go?

If none of that is the issue, then my best guess would be that his email is getting bounced. Check the server to see if that's the case

Thank you again for your help.




------------------------------------
Reply:
Step 1: go to the gear icon and select site settings> Site Administration> user alerts. Check to see if users actually have alerts under their name in there.

cameron rautmann


------------------------------------
Reply:

Thank you Cameron. I checked the user alerts. No alert is created in the site settings. I don't know if user alerts are created/saved when the subscription to the alert is made through a control in the page (in my case, a checkbox to be checked)?

And I tried to set an alert on this page from the ribbon (usual way), but I received a mail :)

So I think that the problem comes from the development.

Valérie


------------------------------------
Reply:
Yep, definitely a development issue. Unfortunately I can't help you with that on my end. If you provide the code I might be able to decipher it and see what's wrong.

cameron rautmann


------------------------------------
Reply:
Unfortunately, I cannot provide you with the code. Another IT company did it. I asked this company to fix the problem. Thank you for all your quick replies. Kind regards :)

------------------------------------

RED X bug in defalt view in Control Panel\Network and Internet\Network Connections

When we view the default view on Control Panel\Network and Internet\Network Connections

We see red X's on nic 6(the last nic) and the team vm_trunk (Microsoft Network Adapter Multiplexor Driver)


We had this on 3 of our 4 nodes

If we switch the View, the red X's show for a second or two then go away.

We switch back to default view and they are still there, switch back to any other view and all clear.

This team is part of our virtual network switch in hyper-v

I was hunting down drive, cabling, switch issues for a good while before I finally changed the view and poof!  Gone.



  • Edited by Fenrik Thursday, December 20, 2012 8:16 PM

Reply:

Hi,

I would like to confirm if the network card driver is up to date? If not, please update it for Windows Server 2012 first.

If the issue persists, please also try to remove and reinstall the virtual network cards, TRUNK_NIC6 and VM_TRUNK to check the result.

Regards,


Arthur Li

TechNet Community Support


------------------------------------
Reply:

Thanks for the reply Arthur.

All nodes in the cluster are fully patched, all the same.

I confirmed all nic's are on latest drivers/firmware.

I did remove suspect nic from team, reboot, added back, error returned.  Again only in default view.

I removed all nic teaming, removed hyper-v role, cluster role, rebooted. Went through setting it all back up again.  Same way I did on the two that didn't get the nic 6 red X.

Again it came back, again only showing RED X on nic 6 only in the default view.

To sum up  4 node hypv 2012 cluster..(RED X) on nic 6 on two, no red x on two.

All 4 dell R720 same specs, server 2012 installed from same image, same Dell SUU update repository (created the day of install)

Everything is the same on network side, had our network team check the switches (all teams even split over same two switches)

Cables were replaced.

Just to clarify, all nic teams are fully functional.  We have no logged errors for the two nic 6 showing RED X's or VM_TRUNK.

The only indication of an issue is the Red X on nic 6 and the VM_TRUNK, and only in medium icon view of "Control Panel\Network and Internet\Network Connections"

Spoke to soon, double checking the views as I wright this, X's are showing in two of the eight views.

Extra large icons = no RED X's

Large icons= no RED X's

Medium icons = RED X's

Small icons = no RED X's

List = no RED X's

Details = no RED X's

Title = RED X's

Content = no RED X's

I will continue to double check for discrepancies.

Sorry for the abundant details, this is just weird and wanted you to have all the info.

I have turned this "bug" over to our in house Technical Account Manager for Microsoft Premier Services.

We Are in the process of reporting it now.

Find A bug Get An XBOX!?  ß Joke J

Thanks for the help!


  • Edited by Fenrik Friday, December 21, 2012 3:09 PM

------------------------------------
Reply:

Hi Fenrik,

Have you solve your problem ?  I have a Dell PE2950 III with Windows Server 2012 Datacenter and I have the same problem.

If I delete my team (LACP team), the 2 separate NICs work fine and I don't have red X on my NICs.  I create my Team with 2 NICs and one nic get a red X.

The server is up to date and Broadcom nic also.

Steve


Steve


------------------------------------
Reply:
Same issue here. No idea what's causing it, This is a fresh install of 2012 on a dell R610 Blade. 

------------------------------------
Reply:
I am having the same problem with 2 identical HP Proliant DL585 G7's... One has the issue, one doesn't.  Even though this seems like a display bug it makes me hesitant to build my cluster off of it.  Instead of trunking I have teaming enabled but everything else is the same.  I have updated the drivers to the latest off the HP web site and still nothing.  All servers are patched identically.  Hope someone is able to resolve this... while it may be just an arbitrary thing... psychologically I don't like Red X's :) 

------------------------------------
Reply:

I had to rebuild this cluster later for an unrelated issue, this time I didn't get the same RED X issue.  Two things Changed, no updated brodcon nic drivers, we did have a IP issue.  it was  long time ago so I apologize I don't remember the details but I believe we were issued an IP for DTC that was already used.  I don't believe we had gotten to that point yet on first build so DTC wasn't the issue.  unfortunately (or not) I wasn't able to recreate after rebuild, MS had nothing to trouble shoot with me. I closed the case. 

Good luck,


------------------------------------
Reply:

I encountered the same issue on a Windows Server 2012 R2. 1 of NIC showed red X after I configured 2 NIC teaming. Not only red X issue, but also intermittent timeout for ping after teaming.

The issues have been fixed after I uninstall the red X NIC from Device Manager and re-boot the host. After that, re-config the NIC teaming. 


Microsoft


------------------------------------

Share/sync mail categories among pst files in real time

Hi all,

I've spent a lot hours trying to do this, but I've unable to, I hope someone can lend me a hand.

SCENARIO: I have four computers with Windows 10 and Office 2016. The same gmail account is configured in all them using POP3, so this account is shared between four users, all them receives the same mails, etc.

Those users mark the received mails categoryzing them with colors (red, yellow, blue...). In this way they can identify the state every mail is in (answered by himself, answered by other user, don't need answer...).

PROBLEM: Since those marks are made locally in the pst file, when a user mark a mail in a color, the other users doesn't see this mark, so the have to ask mail by mail to the colleages about every mail (up to hundred per day).

NEED: I need those colors/flags/categories of inbox mailbox to be shared/syncronyzed among the four computers (the content of inbox folder is the same in all computers since it's the same mail account).



I've try a few third party programs that promised to do it, but none of them works, the others options seems to be:

1.- Using IMAP instead of POP3, problem: given the huge quantity of mails, when I tryed this some time ago it didn't work well, everything went very slow outlook even gets frozen sometimes. Besides that, IMAP doesn't support color categories.

2.- Using Exchange Server? This could be a solution (I'm not sure), but I'm afraid it requires a domain and a Windows server O.S, but we have a workgroup and Windows 10 Professional. Of course, if it would be my only solution I'd have to do this.

I hope someone can lend me a hand, may thanks in advace.

VMM Admin Consoles crash for specific VM

Hi All,

When i try to access the properties of VM (Windows server 2008), then my VMM GUI console gets closed. This is happening to few VMs. But if do force remove VM then im able to access the VM properties without any issue. 

I wanted to know the reason why this is happening. 

VMM version: 3.3.8292.0 (System center 2012R2)

Virtual machine VM additions : 6.3.9600.18080


Remote Desktop connection configuration

Hello!!! 

I have som problem when i try to configure remote desktop connection for a program in server.

Basically i need to share a program for users installed in server and using the remote desktop connection for users access.

I wait for an help!!!

  • Changed type Vanasantonio Wednesday, December 28, 2016 11:11 PM

Reply:

Hi,

This may help

http://stackoverflow.com/questions/1226772/can-rdp-clients-launch-remote-applications-and-not-desktops

------------------------------------------------------------------------------------------------------------
If you found this post helpful, please give it a "Helpful" vote. 
Please remember to mark the replies as answers if they help.
(nedimmehic.org)


------------------------------------

DFS and backup

I have alredy set up my dfs servers. How to backup my dfs data.

CM execmgr log parse (and learning to use powershell)

Hello,

I am making an initial post, and hope to learn about power shell scripting.  I have some basic understanding of commandlets and .PS1 files, mostly for each loops for repetitive tasks in AD and Exchange.  However, my job role has grown to encompass  SCCM 2012 R2 management.  The tasks I am attempting now are more complicated (and often involve PSEXEC, but I digress...)  Here is today's situation...

I have deployed a script via package.  A large number of failures have come back. I have looked at a few samples, and believe this is in most cases related to a user log off, or shut down.  I would like to XCOPY a large number of machines cm execmgr log files to my local machine (or if it is easier, Access them remotely) and parse for specific text to support my theory.

So, for example, a variable set to collect a CSV file of computer names,

$logpath = Path to directory of multiple log files

GC $logpath foreach 

select-string "Script for Package: XXX123" AND ("user logged off" OR "Shutdown")  -simplematch | select -expand line | $_.timestamp -gt (get-date)

write-output "C:\Masterlog.log"

I realize that in a best case scenario this might be considered vague program logic to indicate what I would like to do, and not in any way functional.  But that is what I am trying to learn how to do.  Understand how to build relationships between statements and not just execute single line commandlets.  Any help on this specific topic, as well as, more general advice about how to go about learning powershell (or other) programming/scripting is appreciated!

  • Changed type Bill_Stewart Monday, May 22, 2017 3:27 PM
  • Moved by Bill_Stewart Monday, May 22, 2017 3:27 PM This is not "scripts on demand"

Reply:

This forum is designed to answer specific scripting questions.


-- Bill Stewart [Bill_Stewart]


------------------------------------
Reply:

that is a specific scripting question... let me rephrase.  How would I script something to generate multiple xcopy log files and then parse them for specific keywords. Or, if that is not specific enough, why does this just print all of the above to the shell when I run it in PSE

$logpath = C:\EXECMGR.LOG

$outpath = C:\Compilation.LOG

Get-Content $logpath |

Select-String "Script for Package:XXX123" -SimpleMatch |

select -expand line |

foreach {

$_ -match '(.+)\s\[Script for package:XXX123\]\s\.\s(.+)' | out-null

New-Object psobject -property@{timestamp = [datetime]$Matches[1];Error = $Matches[2]] |

where {$_.timestamp -gt (get-date).AddDays(-1)}

}

write-output $outpath



  • Edited by Vukovi Tuesday, April 11, 2017 5:36 AM

------------------------------------
Reply:

It is a request for a script solution which s not a question. A question is of the form: "How/what/where/when". 

If you are trying to ask how to use a CmdLet Hen start by reading the help:

Help gc -Full.

The fundamental question seems to be something about "How" to learn PowerShell but event that is very vague.

I recommend any of the available books or online tutorials.  You can also spend some time learning how to use the Internet which  has a "search" capability using any of many search providers.  They can be very helpful once you learn to use them.

Here is an example: https://www.google.com/?gws_rd=ssl#newwindow=1&q=how+can+I+learn+PowerSHell&spf=68


\_(ツ)_/


------------------------------------
Reply:
In the meantime, I have posted a very specific question regarding the above script.

------------------------------------
Reply:

" How would I script something" is not a script question it is a request for a solution.  XCOPY does not produce a log file so you will have to figure out what creating a log file means.

I recommend using RoboCopy which can produce a log file.

You can capture the output of XCOPY  like this:

$results = XCOPY <cource> >destination>

You can parse like this:

$results = XCOPY <cource> >destination> | Select-String <pattern>

Try using help to learn how the CmdLets work.


\_(ツ)_/


------------------------------------

Need DAX formula on SSAS tabular Model grand total should show last month Value like bank balance

Hi,

It is on SSAS tabular model. I need to create measure which shows sum value on each month and grand total

Month              Employee count

201701           100

201702           101

201703           110

Grand Total     110

here each month we are showing number employees. Employees may quit or join.

In grand total always should show last month value that is 110. It is like balance of bank statement

Can you please help me  DAX formula which shows grand total as similar to last month value.

Thanks,

Manjunath

Reading View Settings Moved

In 1607 Reading View Settings were under the ellipsis > (Edge) Settings and the heading Reading.  Here one could select desired text size & background colour.

In 1703 such Reading View options have been relocated.  Now, open Reading View, click in/on the body of the article and a black bar will appear at the top; (click again and it disappears).  At the right end of said bar is a printer icon for the article and to the left of it another icon of the letter 'A', 2 of them, one big & one small... this is (now) where Reading View options for text size & page colour are found.

Cheers,
Drew

Drew MS Partner / MS Beta Tester / Pres. Computer Issues Pres. Computer Issues www.drewsci.com

How do I edit this Query - Dates

HI

I want to be able to edit this query to retrieve the last 11 days past and 3 days forward. The field I want to use is the MeetingDate

let   Source = Json.Document(Web.Contents("https://api.tatts.com/sales/vmax/web/data/racing/")),   RaceDays = Source[RaceDays],   #"Converted to Table" = Table.FromList(RaceDays, Splitter.SplitByNothing(), null, null, ExtraValues.Error),   #"Expanded Column1" = Table.ExpandRecordColumn(#"Converted to Table", "Column1", {"MeetingDate", "CurrentDay", "Meetings"}, {"MeetingDate", "CurrentDay", "Meetings"}),   #"Expanded Meetings" = Table.ExpandListColumn(#"Expanded Column1", "Meetings"),   #"Expanded Meetings1" = Table.ExpandRecordColumn(#"Expanded Meetings", "Meetings", {"Abandoned", "MeetingId", "MeetingCode", "MeetingType", "VenueName", "WeatherChanged", "Races"}, {"Abandoned", "MeetingId", "MeetingCode", "MeetingType", "VenueName", "WeatherChanged", "Races"}),   #"Expanded Races" = Table.ExpandListColumn(#"Expanded Meetings1", "Races"),   #"Expanded Races1" = Table.ExpandRecordColumn(#"Expanded Races", "Races", {"FeatureRaceBonusActive", "FixedOdds", "Status", "RaceNumber", "RaceTime", "RaceName"}, {"FeatureRaceBonusActive", "FixedOdds", "Status", "RaceNumber", "RaceTime", "RaceName"}),   #"Expanded FixedOdds" = Table.ExpandRecordColumn(#"Expanded Races1", "FixedOdds", {"HasFixedPrice"}, {"HasFixedPrice"})  in   #"Expanded FixedOdds"    

So from a prior question I know the function to use is

DateTime.LocalNow() - #duration(14, 0, 0, 0).

But where in the query do I do this?



Taking my C# further


  • Edited by SaythJ Wednesday, April 12, 2017 4:42 AM

Reply:

You first need to turn the MeetingDate in an actual date field: tab Transform - Date - Parse.

Then you can filter and make sure to use 1 data type.

My suggestion is to use date type (not datetime) and add lines to your query:

 #"Parsed Date" = Table.TransformColumns(#"Expanded FixedOdds",{{"MeetingDate", each Date.From(DateTimeZone.From(_)), type date}}),   #"Filtered Rows" = Table.SelectRows(#"Parsed Date", each [MeetingDate] >= Date.AddDays(DateTime.Date(DateTime.LocalNow()),-11) and [MeetingDate] <= Date.AddDays(DateTime.Date(DateTime.LocalNow()),3))  in   #"Filtered Rows"


------------------------------------

Forwarding username from WAP to Application Server

Hi ,


I believe this is the way Web Application Proxy acts a forward proxy as well as reverse proxy.

  1. The client device attempts to access a published web application on a particular resource URL

The resource URL is a public address on which Web Application Proxy listens for incoming HTTPS requests.

If HTTP to HTTPS redirection is enabled, Web Application Proxy will also listen for incoming HTTP requests.

  1. Web Application Proxy redirects the HTTPS request to the AD FS server with URL encodedparameters, including the resource URL and the appRealm (a relying party identifier).

The user authenticates using the authentication method required by the AD FS server; for example, user name and password, two-factor authentication with a one-time password, and so on.

  1. After the user is authenticated, the AD FS server issues a security token, the 'edge token', containing the following information and redirects the HTTPS request back to the Web Application Proxy server:
    • The resource identifier that the user attempted to access.
    • The user's identity as a user principal name (UPN).
    • The expiry of the access grant approval; that is, the user is granted access for a limited period of time, after which they are required to authenticate again.
    • Signature of the information in the edge token.
  2. Web Application Proxy receives the redirected HTTPS request from the AD FS server with the edge token and validates and uses the token as follows:
    • Validates that the edge token signature is from the federation service that is configured in the Web Application Proxy configuration.
    • Validates that the token was issued for the correct application.
    • Validates that the token has not expired.
    • Uses the user identity when required; for example to obtain a Kerberos ticket if the backend server is configured to use Integrated Windows authentication.
  3. If the edge token is valid, Web Application Proxy forwards the HTTPS request to the published web application using either HTTP or HTTPS .
  4. The client now has access to the published web application; however, the published application may be configured to require the user to perform additional authentication. If, for example, the published web application is a SharePoint site and does not require additional authentication, the user will see the SharePoint site in the browser.
  5. Web Application Proxy saves a cookie on the client device. The cookie is used by Web Application Proxy to identify that this session has already been preauthenticated and that no further preauthentication is required. 

Now in our environment, I want to change step 5 a bit, which should be "If the edge token is valid, Web Application Proxy forwards the request to the published web application with USER_CN="AD UserID" added to the request header".

Can you please suggest, how that can be done? What further configuration, should I to put into the WAP ?


Thanks in advance



  • Edited by khoka Monday, December 19, 2016 11:38 AM

Reply:

Did you ever get an answer or solution for this? I have a web app sitting behind the WAP that requires the same thing

Thanks!


------------------------------------

**** Windows Vista support has ended ****

**** Windows Vista support has ended ****

where is the box?

I can't find where I can check for rdp to see my ports (local devices and resources).  I can connect just fine, but it doesn't recognize my home computer to download files from work.

Reply:

Hi,

Please make sure you did not miss any steps as below:

Click Options to expand the RDP connection window.

• Click the Local Resources tab. Under Local devices and resources, tick "Clipboard" and click More.

• In the new window, click Drives. Click OK to close.

• Go back to General tab and click Save to save the settings for next time.

And try to use Task Manager to kill and restart the rdpclip.exe process on local and remote machines if it doesn't work.

Best Regards,

Alvin Wang


Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.


------------------------------------
Reply:

Hi,

Just checking in to see if the information provided was helpful. Please let us know if you would like further assistance.

Best Regards,

Alvin Wang


Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.


------------------------------------

Cumulative Update KB4015583, Windows 10 ver 1703 OS Build 15063.138

KB4015583 is what you need to bring your Windows 10 to version 1703 OS Build 15063.138

If Windows Update is not yet offering, you can have it from Microsoft Update Catalog.

Direct download links :

Download KB4015583 MSU for Windows 10 Version 1703 32-bit (x86) - 51.8 MB

Download KB4015583 MSU for Windows 10 Version 1703 63-bit (x64) - 114.4 MB

How can I include . (dot) in file names and still compress or ZIP the files?

How can I include . (dot) in file names and still compress or ZIP the files?

I have a folder with files names that include a . (dot) and when I try to compress the folder it says the files cannot be compressed because of the . (Dot) in the files names. This is annoying. Is there a way where I can include . (Dot) in the files names and still compress the folder or files?

Ex file names:

1. First lesson.pdf
2. Second lesson.pdf

Please advise. 

I am on Windows 10 Pro 


Reply:
No problem here right click files or folders with dots and Send to > Compressed (zipped) folder. So how are you trying to zip this files \ folders?

------------------------------------
Reply:

A PDF file on my computer was sent to the desk top as a short cut. A right click renamed the file first lesson.pdf. Another right click send to compressed zip folder created a zip file.

So it works.

See what happens if you duplicate the steps by first sending to the desk top as a short cut and then creating a zip file.

https://1drv.ms/u/s!AhdfDD74t_q2jTEnAKexHUHUstqS

https://1drv.ms/u/s!AhdfDD74t_q2jTKkbOLs2m8cpZMa


------------------------------------

Needed privileges for an Service account to call on WMI on remote machines

Hi,

I have an interesting power shell query taken from the web that worked out well with my windows ID needless to say i belong to the Admin group on almost all the servers on the domain.

The script is located on one central server on the domain and has an notepad with all the server name and the powershell script on the server would call on this text file that contains the server list and brings the output. 

Below are the WMI that the script calls for -

Get-WmiObject -ComputerName $computer -Class Win32_LogicalDisk -Filter "DriveType = 3" 
Get-WmiObject -ComputerName $computer -Class Win32_OperatingSystem
Get-WmiObject -ComputerName $computer -Class Win32_Processor 
Get-WmiObject -ComputerName $computer -Class Win32_Processor 

Currently all was well as i have an scheduled windows task to call on the powershell script and it runs on my context ID successfully.

However compliance team wants all reports to be done via an service account and has asked me to get the same achieved with least amount of privileges, when i had the job configured via this service account which i had added as power users under each of the servers windows group it still fails as Access is denied.

I am sure that the compliance might not approve an RDP access for this ID, can any of you help me what all privileges my service account lacks and is it possible to get the job accomplished with minimal privilege as  adding the service account into the power users group doesn't help me in my scenario

Thank you

Eben




Reply:
Power Users is no longer a valid group. You will most likely need to add user to the DCOM group, and also set WMI permissions, by going to computer management --> services and applications, right click on WMI Control and select properties, select the Security tab. Do some research for those classes and try to only apply to what is needed and not root, I believe they all belong to DEFAULT.

If you find that my post has answered your question, please mark it as the answer. If you find my post to be helpful in anyway, please click vote as helpful. (99,108,97,121,109,97,110,50,64,110,121,99,97,112,46,114,114,46,99,111,109|%{[char]$_})-join''


  • Edited by clayman2 Tuesday, April 11, 2017 12:14 PM typo

------------------------------------
Reply:

Execute methods, Full write,Partial write,Provider write,Remote enable,Read security,Edit security, Special permissions

Above are available options on the default security for the service account when added . Would execute methods alone suffice -any idea ?

Cheers

Eben


------------------------------------
Reply:
The security has to be set ON WMI not on the service account.

\_(ツ)_/


------------------------------------

Definitive guide how to fix errors "The application-specific permission settings do not grant Local Launch permission for the COM Server application"

Hello guys. While dealing with Windows errors I often see errors like this one:

The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID
{05D1D5D8-18D1-4B83-85ED-A0F99D53C885}
 and APPID
{AD65A69D-3831-40D7-9629-9B0B50A93843}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.

Most topics about such errors simply point you to DCOM Config to fix permissions, but in many cases all settings for failed component are grayed out so you can't change anything here. This guide is about how to fix it completely all at once regardless of exact error message as this solution is universal.

So, if you've found what component settings are grayed out, this means what permissions for component's registry key restrict you from modifying it. We have to fix it first so we could fix DCOM configuration of component.


1) Launch Regedit as Administrator. Search key name with given CLSID (in this case it's {05D1D5D8-18D1-4B83-85ED-A0F99D53C885}). Write down component's name from it's registry key, you will need it later.

2) Open permissions for this key and check them. In most cases you could see what both SYSTEM and Administrators haven't any permissions to change this key. 

3) Enter advanced permissions and check the key owner. In most cases it's TrustedInstaller. Take ownership of this key by setting the owner to Administrators group. Also set "Replace owner on subcontainer and objects" checkbox. Close all permissions settings and open them again.

4) Now grant full permissions over this key to SYSTEM and Administrators group. Also remove any unknown user accounts if some of them is on list. Replace permissions for subcontainers and objects of this key.

5) Now repeat same procedure for component's APPID key (in this case it's {AD65A69D-3831-40D7-9629-9B0B50A93843})


Now back to DCOM Config. Launch it as Administrator. If you have troubles doing it, you could do it by simply launching cmd as Administrator and then entering "dcomcnfg". This will do the trick. Now:

6) Expand Component Services -> Computers -> My Computer -> DCOM Config.

7) Click View -> Detail -> now you will see both Application Name and Application ID in the list.

8) Find needed component using it's name which you've written down. Compare it's CLSID with yours as where could be many components with same name but different CLSID (it happens sometimes).

9) Right Click -> Properties and select the Security tab. All settings should be accessible for you to change them.

10) Now you need the box with permissions which has been mentioned in error message (in this case it's Local Launch so we need a "Launch & Activation Permission" box). Click "Customize" there.

11) Check if user list contains needed account, mentioned in error message (in this case it's NT AUTHORITY\SYSTEM). In most cases it's absent. Add it to list if so.

12) Now grant permissions mentioned in error message to this account (in this case it's Local Launch). In most cases it's also worth to grant same type of activation permission. So in this case we will set both Local Launch and Local Activation.


Problem solved.


Reply:

Hi, 

Thanks for your sharing here on this issue. 

This is really general issue in Windows, and the step by step guide can help others who may encounter the similar issue here. 


Please remember to mark the replies as answers if they help.
If you have feedback for TechNet Subscriber Support, contact tnmff@microsoft.com.


------------------------------------

No comments:

Post a Comment

Setup is Split Across Multiple CDs

Setup is Split Across Multiple CDs Lately I've seen a bunch of people hitting installation errors that have to do with the fact th...