Monday, February 28, 2022

My terminal server is not connected

My terminal server is not connected

I have windows server 2008 64 bit.  I have configured terminal server. I have create one user add in remote desktop group and terminal group. I have insert the image, which i configured terminal server. when I

huz


Reply:
The which I inserted when i got clent site type 192.168.1.155/ts it show software but when i click on the icone its loading so much time

huz


------------------------------------

SQL server cluster setup

Hello,

i have 2 servers. I want a support of 7-10 Tb of data.

my application has single database.

I want a setup such as my mdf and ldf file are on SAN disc and sql server installed on both the servers and both active at the same time

Is it possible to do so? if yes will it handle the load? and how to configure this type of setup?


  • Edited by Rohitz Friday, April 20, 2012 5:10 AM

Reply:

Active / Active clusters does not share same resources ie it can't share same database - You might look for peer-peer / merge replications.

You can go for Active / Passive clustered where active node will take the ownership of resources and it requires single licence - but active /active clusters and replication requires a separate licensing for both servers

hope this helps you


http://uk.linkedin.com/in/ramjaddu


------------------------------------

CX600 stays in call when VDI session starting

Hello,  we have this issue :

a CX600 is connected with userA

this CX600 is connected with USB to a PCOIP

We restart the VMVIEW host on the PCOIP and log on with UserB

When Lync is starting and sign in the CX600 switch in "in call" but it's impossible to stop it. the only way is take the USB cable off.

We don't have this issue if we restart the Lync client on the DI session, it's only when the VDI session is restarted (as a reboot of PC)

Any clue?

Thanks

Jean-Marc

MS Clustering using SAN Storage

Hi,

I am new to clustering, can anyone please tell me how to configure a SAN storage to be accessed as Shared Storage in cluster?


Reply:
I need a step by step steps or document please

------------------------------------
Reply:

Hi,

SAN is a storage device, it is recommended that you contact your storage vendor to get the step by step guide.

If you are new to cluster, you can check the following guides.

Failover Clusters in Windows Server 2008

http://technet.microsoft.com/en-us/library/ff182326(WS.10).aspx

Failover Clustering(2008 R2)

http://technet.microsoft.com/en-us/library/cc725923(WS.10).aspx

Failover Clusters in Windows Server 2008 R2

http://technet.microsoft.com/en-us/library/ff182338(WS.10).aspx


Vincent Hu

TechNet Community Support


------------------------------------

Best practice admin of Exchange

Is there a top 10 checks to ensure our 3rd party IT support are using best practice management and administration of our exchange servers? What would the checks include?

Reply:
Very generic question, all I can say is train them, write documented procedures, send them on an Exch course.

Sukh


------------------------------------
Reply:
Very generic question, all I can say is train them, write documented procedures, send them on an Exch course.

Sukh

It was meant to be a very generic question. But you cant do an audit of how well a 3rd party is managing/admin'ing your exchange servers and go in and say "train them". I need some sort of best practice document to see if they are following best practice. Yet remarkably there seems next to NOTHING on the internet around auditing exchange!!

As exchange admins yourself I was hoping for something a bit more constructive on what you'd check (your top 20 checks) if you were auditing a 3rd party exchange admin/setup, not "train them".

  • Edited by cf090 Thursday, April 19, 2012 12:38 PM

------------------------------------
Reply:

It realy depends on what tasks the Exch admin will be performing, so I normally check their Change and see how the implementation plan is detailed and actioned.


Sukh


------------------------------------
Reply:

It realy depends on what tasks the Exch admin will be performing, so I normally check their Change and see how the implementation plan is detailed and actioned.


Sukh


So if you were tasked with doing an independant audit of an exchange setup and admin youd go in and do 1 check?

------------------------------------
Reply:

------------------------------------
Reply:

There'sd a difference between checking a Exch server's health and another Exch admins performing their duties.


Sukh


------------------------------------
Reply:

There'sd a difference between checking a Exch server's health and another Exch admins performing their duties.


Sukh


Your input into top 20 checks around health most welcome then....

------------------------------------
Reply:
  1. Exch BPA
  2. Perfom of Exch, AD, OS
  3. Capacity planning/usage
  4. Monitoring/Alerting
  5. DR process
  6. Backup/restore testing
  7. Patching (OS & Exch)
  8. Mailbox size/limits/folder counts/item count
  9. Permissions/rights for Exch admins
  10. AV/Spam update/patches

Sukh


------------------------------------
Reply:
  1. Exch BPA
  2. Perfom of Exch, AD, OS
  3. Capacity planning/usage
  4. Monitoring/Alerting
  5. DR process
  6. Backup/restore testing
  7. Patching (OS & Exch)
  8. Mailbox size/limits/folder counts/item count
  9. Permissions/rights for Exch admins
  10. AV/Spam update/patches

Sukh

Thats more like it!

Re 8, would you also audit "who can access each others mailbox?"

WHen you mention mailbox size/limits/folder counts/item count etc - what risk are you focusing on their?

And for 4 - what tools can be used for that, and what risks are you looking into...


------------------------------------
Reply:

More issues users would face with Outlook crashing, not seeing caledars items/missing items/different views etc...so not such as risk on the Exch side.

Mailbox access can be audited, which is what I would include in point 9.  Generally admins can ahev access to everything using such service accounts or provledges etc...So I would check this too.

Point 4 - Usual tools, like SCOM, 3rd party tools like spotlight, there loads of scripts you can use, custom event trigger using event tasks.  As for the risk, could be anything from low disk space to transaction logs resets, runnng services, mounted stores etc...risk is to reduce to elminiate outage to prod env.


Sukh


------------------------------------
Reply:

More issues users would face with Outlook crashing, not seeing caledars items/missing items/different views etc...so not such as risk on the Exch side.

Mailbox access can be audited, which is what I would include in point 9.  Generally admins can ahev access to everything using such service accounts or provledges etc...So I would check this too.

Point 4 - Usual tools, like SCOM, 3rd party tools like spotlight, there loads of scripts you can use, custom event trigger using event tasks.  As for the risk, could be anything from low disk space to transaction logs resets, runnng services, mounted stores etc...risk is to reduce to elminiate outage to prod env.


Sukh

Thanks Sukh

I dont suppose if you have a spare 10 mins you could develop each of these top 10 into more specific checks for us?

i.e.for objective 2 -  2.1, 2.2, 2.3, 2.4 per each category that youve listed above?


------------------------------------
Reply:

In addition to your link use the link below, its been around its' a daily, monthly checklist for operations.

Microsoft Exchange Server (2003 | 2007 | 2010) - Operations Checklists

http://blogs.technet.com/b/spencervelastegui/archive/2010/12/14/microsoft-exchange-server-operations-checklists.aspx

That's alot to ask for someone to come up with a MOF framework on a forum. I did a MOF for 2003 back in the days here's a guideline topic of what you want to cover that I covered.

Table of Contents

Summary.

Objectives.

Operations Infrastructure.

Reporting Model

System Level Reporting.

Application Level Reporting.

Skill Requirements.

Change Management Process.

Receipt of Request for Change.

Change Analysis and Review..

Change Notification and Release.

Change Building, Testing, and Implementation Monitoring.

Change Outcome Notification.

Post-Implementation Evaluation.

Urgent Change Process.

Operational Activities <Product/Feature Solution 1>..

Ongoing Operations.

Systems Management

Backup and Recovery.

Maintenance.

Monitoring the System..

Securing the System..

Performance Planning.

Capacity Planning.

Problem Management

Configuration Management

Configuration Management Planning.

Configuration Identification.

Configuration Control

Configuration Status Accounting, Verification, and Auditing.

Service Level Management

Appendix – Monitoring Guidance.


James Chong MCITP | EA | EMA; MCSE | M+, S+ Security+, Project+, ITIL msexchangetips.blogspot.com



------------------------------------
Reply:

You can also look at this article

http://www.ucblogs.net/blogs/exchange/archive/2010/12/15/Operations-Checklists-for-Exchange-Server-2010_2F00_2007_2F00_2003.aspx


Please remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread. Hasnain Shaikh| My blogs: http://messagingserversupport.com


------------------------------------
Reply:

In addition to your link use the link below, its been around its' a daily, monthly checklist for operations.

Microsoft Exchange Server (2003 | 2007 | 2010) - Operations Checklists

http://blogs.technet.com/b/spencervelastegui/archive/2010/12/14/microsoft-exchange-server-operations-checklists.aspx

That's alot to ask for someone to come up with a MOF framework on a forum. I did a MOF for 2003 back in the days here's a guideline topic of what you want to cover that I covered.

Table of Contents

Summary.

Objectives.

Operations Infrastructure.

Reporting Model

System Level Reporting.

Application Level Reporting.

Skill Requirements.

Change Management Process.

Receipt of Request for Change.

Change Analysis and Review..

Change Notification and Release.

Change Building, Testing, and Implementation Monitoring.

Change Outcome Notification.

Post-Implementation Evaluation.

Urgent Change Process.

Operational Activities <Product/Feature Solution 1>..

Ongoing Operations.

Systems Management

Backup and Recovery.

Maintenance.

Monitoring the System..

Securing the System..

Performance Planning.

Capacity Planning.

Problem Management

Configuration Management

Configuration Management Planning.

Configuration Identification.

Configuration Control

Configuration Status Accounting, Verification, and Auditing.

Service Level Management

Appendix – Monitoring Guidance.


James Chong MCITP | EA | EMA; MCSE | M+, S+ Security+, Project+, ITIL msexchangetips.blogspot.com



James would you share your MOF for 2003? Or is it propriatery.

------------------------------------

firewall

"you must have an active internet connectionto validate your license please connect and try again"

Reply:

Thanks for that. And your question is?

This is a forum for Microsoft Exchange server issues, as it says at the top of the page, so unless the question is about Exchange or Outlook, then you have posted in the wrong place, as well not providing enough information.

Simon.


Simon Butler, Exchange MVP
Blog | Exchange Resources | In the UK? Hire Me.


------------------------------------

Best Practice Ntebooks on Domain

What is the best practice for Notebooks on Domain. Join domain or not?

Employees use the notebook at home and in business.
  • Changed type Bruce-Liu Friday, April 27, 2012 9:20 AM

Reply:
If users require access to resources in the domain then join them. They will have 2 profiles but the fact that it is a notebook instead of a desktop makes no difference.

------------------------------------
Reply:

You can join notebook PC to the domain considering you have some form of connectivity such as VPN (secure access)to access your internal network from the outside (home)network. You can also use encryption tool to encrypt data on the laptop, in case its stolen data is not been recovered.


Awinish Vishwakarma - MVP - Directory Services

My Blog: awinish.wordpress.com

Disclaimer This posting is provided AS-IS with no warranties/guarantees and confers no rights.


------------------------------------
Reply:
You can join notebook to domain and the same profile can be used both internall and externally however ensure that you have depoyed number of previous logon to cache(in case domain controller is not available).
http://technet.microsoft.com/en-us/library/cc755473(v=ws.10).aspx

You can also assign admin right to user as per requirement.

Best Regards,

Sandesh Dubey.

MCSE|MCSA:Messaging|MCTS|MCITP:Enterprise Adminitrator | My Blog

Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.


------------------------------------
Reply:

First you need to find out what OS is running on the netbooks. If you are running Windows 7 Starter you will not be able to join a domain.

http://windows.microsoft.com/en-US/windows7/Networking-in-Windows-7-Starter


------------------------------------
Reply:

Hello,

to be honest, i cannot understand the question here. As Notebook, netbook, desktop or whatever, important for domain join is the used OS version and not the belonging hardware.

And it is quite normal that users, working at home, have domain joined machines to belong to the company policies. I not lots of companies where this is default configuration and no problem to use.


Best regards

Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/

Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.


------------------------------------
Reply:
You can join notebook to domain and the same profile can be used both internall and externally however ensure that you have depoyed number of previous logon to cache(in case domain controller is not available).
http://technet.microsoft.com/en-us/library/cc755473(v=ws.10).aspx

You can also assign admin right to user as per requirement.

Best Regards,

Sandesh Dubey.

MCSE|MCSA:Messaging|MCTS|MCITP:Enterprise Adminitrator | My Blog

Disclaimer: This posting is provided "AS IS" with no warranties or guarantees , and confers no rights.


This solution works for an indefinite period?

------------------------------------
Reply:
This solution works for an indefinite period?

If users are working from home , They can login to the domain via VPN , and access the resources.

This solution works for an indefinite period?

 This Solution will not work for an indefinite period . For Eg - lets say , user account password is expried and he need to change the password . (Remember to change the password he has to be on the office network). In this situation user has to drop in to office and change the password.

 There are some workaround for this , from which you can open some ports on firewall so that User can login to the company network (Even If he is not on the domain network) and change the password. (But it might result into security breach).

Hope this will help you.

Regards,

_Prashant_


MCSA|MCITP SA|Microsoft Exchange 2003 Blog - http://prashant1987.wordpress.com Disclaimer: This posting is provided AS-IS with no warranties/guarantees and confers no rights. Email-giteepag@yahoo.co.in


------------------------------------
Reply:

Hello,

"This solution works for an indefinite period?"

With users that are working with cached credentials they can work WITHOUT any restrictions at home. There will be NO password change required/prompted during the time when the machine is not connected to the domain.

At the time the user connects back to the domain, and the password is expired, the user will immediately prompted to change it.


Best regards

Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/

Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.


------------------------------------
Reply:

Hello Prashant Girennavar,

"This Solution will not work for an indefinite period . For Eg - lets say , user account password is expried and he need to change the password . (Remember to change the password he has to be on the office network). In this situation user has to drop in to office and change the password."

This is NOT correct, the user is NOT required to go into the office and change the password. The cached credentials are NOT controlled and there is NO need to connect to the domain to change the password. That's the advantage of cached credentials on the local machine, no interaction with the domain so no password can be marked as expired for the user working with cached credentials.


Best regards

Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/

Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.


------------------------------------
Reply:

Hello Prashant Girennavar,

"This Solution will not work for an indefinite period . For Eg - lets say , user account password is expried and he need to change the password . (Remember to change the password he has to be on the office network). In this situation user has to drop in to office and change the password."

This is NOT correct, the user is NOT required to go into the office and change the password. The cached credentials are NOT controlled and there is NO need to connect to the domain to change the password. That's the advantage of cached credentials on the local machine, no interaction with the domain so no password can be marked as expired for the user working with cached credentials.


Best regards

Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/

Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.

Meinolf , I Agree. I am with you.

 I have seen some situation where , User account password expired and when user try to change the password he/she wont be able to change the password ( In some cases) . Ultimately we need to ask them to come to office to change the password

May be this will happen in rare cases ( Due to some connectivity problem)

Regards,

_Prashant_


MCSA|MCITP SA|Microsoft Exchange 2003 Blog - http://prashant1987.wordpress.com Disclaimer: This posting is provided AS-IS with no warranties/guarantees and confers no rights. Email-giteepag@yahoo.co.in


------------------------------------
Reply:

Hello Prashant Girennavar,

"I have seen some situation where , User account password expired and when user try to change the password he/she wont be able to change the password ( In some cases) "

The account on the domain of course will expire. Also the user is not able to change the password for cached credentials. But there is still no option that the user will be prompted to change the password if not connected to the domain.


Best regards

Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/

Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.


------------------------------------
Reply:

To securely access intranet files, you have to use VPN or you can make use of directaccess feature available with windows7/2008 R2.

http://www.microsoft.com/download/en/details.aspx?id=24144

You need to connect the domain joined notebook once in a month to your office network for the machine password refresh for better security and manageability. Machine can be disconnected from the long but yes, patching, antivirus should be updated. Accessing official data from the non domain joined machine can be a risk. 


Awinish Vishwakarma - MVP - Directory Services

My Blog: awinish.wordpress.com

Disclaimer This posting is provided AS-IS with no warranties/guarantees and confers no rights.


------------------------------------
Reply:

Hello Prashant Girennavar,

"I have seen some situation where , User account password expired and when user try to change the password he/she wont be able to change the password ( In some cases) "

The account on the domain of course will expire. Also the user is not able to change the password for cached credentials. But there is still no option that the user will be prompted to change the password if not connected to the domain.


Best regards

Meinolf Weber
MVP, MCP, MCTS
Microsoft MVP - Directory Services
My Blog: http://msmvps.com/blogs/mweber/

Disclaimer: This posting is provided AS IS with no warranties or guarantees and confers no rights.

I Agree. You are Absoultely Right.

Regards,

_Prashant_ 


MCSA|MCITP SA|Microsoft Exchange 2003 Blog - http://prashant1987.wordpress.com Disclaimer: This posting is provided AS-IS with no warranties/guarantees and confers no rights.


------------------------------------

How can I get UserProfiles from UserProfileServiceApplication in sharepoint?

Hi all,

I passed 'employeeID'  to GetUserProfile function instead of userName. But I unable to get userprofile details. It through's exception.

Below  code I used.

            long employeeID = 987;
            SPSite _site = SPContext.Current.Site;
            Microsoft.SharePoint.SPServiceContext serverContext = Microsoft.SharePoint.SPServiceContext.GetContext(_site);
            UserProfileManager myUserProfile = new UserProfileManager(serverContext);
            UserProfile currentUserUserProfile = myUserProfile.GetUserProfile(employeeID);

            string accountName = string.Empty;
            if (currentUserUserProfile[PropertyConstants.AccountName].Value != null)
                accountName = currentUserUserProfile[PropertyConstants.AccountName].Value.ToString();
            
Please help me.         

   


Reply:

Do employeeID is equal to the recordID of that user in user profile service?

http://msdn.microsoft.com/en-us/library/microsoft.office.server.userprofiles.userprofilemanager.getuserprofile.aspx

Find above link contains all override methods for getuserprofile method.


Regards, Dharnendra Shah "strong belief is the only way to success"


------------------------------------
Reply:

Thanks  dharnendra , for your replay!

EmployeeID is not equal to the recordID(Both are different ) of that user in user profile service.

Regards,

Srinu



------------------------------------

TMG Load Balance with VPN IPSec

Hi,

 

I installed an another link in my TMG Firewall. I enabled it as Load Balance ISP Redundancy. The both are working normally when the internal desktop try to access the internet. However,  the VPN IPSec with the branch office doesn't work. The curious is when I  disable an other NIC, which is not used to establish the VPN, the tunnel is established normally. When I enabled this NIC again, after 5 minutes the VPN is down.

 

Someone know who is this ?

 

Regards,


Wilson NF


Reply:

Hi,

Thank you for the post.

"I installed an another link in my TMG Firewall. I enabled it as Load Balance ISP Redundancy" – do you mean you have installed two external NIC and configured ISP redundancy? If yes, which mode you have used, load balancing of Failover?

Regards,


Nick Gu - MSFT


------------------------------------

Check if the user have an account on the Exchange server or not.

Hello Fellow Developers,

What i am doing now is using "Exchange Server 2007 SDK" (Web exchnage Service) to connect to the Web Exchange server.

i am calling/Using the "Credentials" method of "ExchangeServiceBinding". what i want is just to check if there is any user with those credentials over the Web exchnage server or not?

Already tried to find help over the internet but nothing (Might be doing it the wrong way).

Anytype of help will be appriciated.

Thanks and regards.

TROUBLESHOOTING: failed to retrieve schema or cannot connect to database when creating FIM MA

All,

we have been seeing a lot of cases come into support about this issue after installing Update 2. Here is a wiki that will walk you through the resolution steps.

TROUBLESHOOTING: Failed to retrieve schema or cannot connect to database while creating a FIM MA

http://social.technet.microsoft.com/wiki/contents/articles/9112.troubleshooting-failed-to-retrieve-schema-or-cannot-connect-to-database-while-creating-a-fim-ma.aspx


Timothy P Macaulay, MCSD, MCSD.NET, MCAD, MCP


Reply:

I now cannot refresh the FIM MA. I have swapped those two lines in the config file but it makes no difference. Should this fix also apply to refreshing?

The error I get now is "Failed to connect to the specified database".


http://www.wapshere.com/missmiis


------------------------------------
Reply:
Hi Carol,
 
Does the account have the correct user rights on the machine?
<o:p></o:p>

Cheers,<o:p></o:p>


(HOPEFULLY THIS INFORMATION HELPS YOU!)
Jorge de Almeida Pinto | MVP Identity & Access - Directory Services

-------------------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always evaluate/test yourself before using/implementing this!
* DISCLAIMER:
http://jorgequestforknowledge.wordpress.com/disclaimer/
-------------------------------------------------------------------------------------------------------
################# Jorge's Quest For Knowledge ###############
###### BLOG URL:
http://JorgeQuestForKnowledge.wordpress.com/ #####
#### RSS Feed URL:
http://jorgequestforknowledge.wordpress.com/feed/ ####
-------------------------------------------------------------------------------------------------------
<o:p></o:p>

"Carol Wapshere [MVP]" wrote in message news:3d0148e9-43b6-4287-84e5-fee07c877eae@communitybridge.codeplex.com...

I now cannot refresh the FIM MA. I have swapped those two lines in the config file but it makes no difference. Should this fix also apply to refreshing?

The error I get now is "Failed to connect to the specified database".


http://www.wapshere.com/missmiis


Jorge de Almeida Pinto [MVP-DS] | Principal Consultant | BLOG: http://jorgequestforknowledge.wordpress.com/

------------------------------------
Reply:

Hi Carol,

No.  This fix should not apply to refreshing the schema.  If you are getting "Failed to connect to the specified database" during a refresh of the schema it may be a couple different things.

1. Ensure that the account mentioned in the FIM MA is the same as the account that you specified during the installation of the FIM Service and Portal.

FIM 2010 - How to validate FIM Service Management Agent Account: http://social.technet.microsoft.com/wiki/contents/articles/7348.fim-2010-how-to-validate-fim-service-management-agent-account.aspx

2. If the SQL Server is remote, ensure that you can reach the SQL Server from the FIM Synchronization Service server.

  • See if you can ping the SQL Server from the FIM Synchronization Service server
  • Use a UDL file and see if you can connect to the SQL Server while logged into the FIM Synchronization Service server as the account specified in the FIM Service Managment Agent. 
  • Ensure that the SQL Server Service is started
  • Use SQL Profiler to see if you can trace the account logging into the SQL Server

I hope that helps.

Cheers,

Tim Macaulay, Microsoft Support - Identity Support Team


Timothy P Macaulay, MCSD, MCSD.NET, MCAD, MCP


------------------------------------
Reply:
OK but the FIM MA account did not change in any way. It was working perfectly on imports and exports - then I make a change to the Portal schema, get an app-store-import-error, go to refresh the FIM MA schema and can't do it. Rolled back the database to before the schema change and the FIM MA works fine. Why would it work on imports and exports but not on a scheme refresh? 

http://www.wapshere.com/missmiis



------------------------------------
Reply:

Hi Carol,

What build of FIM 2010 were you working on prior to the 4.00.3606.2 update (FIM 2010 Update 2)?

FIM 2010 RTM (4.00.2592.0) did not experience the problem with the difference in the FIM Service Management Agent (FIM MA) account, and the account specified during installation.  They actually could be different.  However, in later builds FIM got more strict on things like the FIM MA account matching the account used during the installation.  You would not see the problem until you did something like refresh the schema of the FIM MA, or did a change to the schema in the FIM Portal, or experienced some other problem in the FIM Portal or FIM Service.

So if you upgraded from 2592 to 3531 (Update 1) and did not make any changes, then Imports and Exports would work. 

This is most likely why you are experiencing the problem now, is that you are attempting to refresh the schema. 


Timothy P Macaulay, MCSD, MCSD.NET, MCAD, MCP


------------------------------------
Reply:
This server was installed fresh a couple of weeks ago with the sync and portal configs imported from the dev environment. I initially put update rollup 2 straight on it then couldn't create the fim ma. So after wasting an entire day on that I reinstalled the server, created the fim ma first, and then installed update rollup 2, and then re-migrated my configs. I tested a schema refresh then and it was fine - however there were no schema updates to apply, so I don't know if that makes a difference. All the work since then has been testing with only minor changes and I do not believe there have been any changes made to the fim ma account. Which was of course the one I specified during installation (and I've gone and compared the SIDs and accountnames just to be extra sure).

http://www.wapshere.com/missmiis



------------------------------------
Reply:
Dang it someone had changed something! Logon locally rights were revoked since I was last there - maybe a group policy change or something. After all the fuss I had initially with the FIMMA and rollup 2 I thought it was the same problem, but no, just a garden variety rights issue. Sorry for clogging up this thread with something unrelated..

http://www.wapshere.com/missmiis


------------------------------------
Reply:
that�??s why I said....�?�Does the account have the correct user rights on the machine?�?�
 
whenever I get the error you got, I check the following:
 
* server name and instance on the FIM MA
* service address on the FIM MA
* permissions config on SQL
* user rights config on windows
 
most of the times it is the last one!

<o:p></o:p>

Cheers,<o:p></o:p>


(HOPEFULLY THIS INFORMATION HELPS YOU!)
Jorge de Almeida Pinto | MVP Identity & Access - Directory Services

-------------------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always evaluate/test yourself before using/implementing this!
* DISCLAIMER:
http://jorgequestforknowledge.wordpress.com/disclaimer/
-------------------------------------------------------------------------------------------------------
################# Jorge's Quest For Knowledge ###############
###### BLOG URL:
http://JorgeQuestForKnowledge.wordpress.com/ #####
#### RSS Feed URL:
http://jorgequestforknowledge.wordpress.com/feed/ ####
-------------------------------------------------------------------------------------------------------
<o:p></o:p>

"Carol Wapshere [MVP]" wrote in message news:96cef66d-4fe4-479a-af19-d094d51e9828@communitybridge.codeplex.com...
Dang it someone had changed something! Logon locally rights were revoked since I was last there - maybe a group policy change or something. After all the fuss I had initially with the FIMMA and rollup 2 I thought it was the same problem, but no, just a garden variety rights issue. Sorry for clogging up this thread with something unrelated..

http://www.wapshere.com/missmiis


Jorge de Almeida Pinto [MVP-DS] | Principal Consultant | BLOG: http://jorgequestforknowledge.wordpress.com/

------------------------------------

Custom gridview click row not trigger, not highlight and not break at selectedindexchanged event

Custom gridview click row not trigger, not highlight and not break at selectedindexchanged event

what is missing and how to make it have selectedindexchanged event again like normal gridview


Reply:

Wilson,

This seems to be a .net issue rather than a SharePoint and I guess that's why you didn't recieve any reply yet.

Did you try to use the code in normal asp.net application?

Regards,

Hiren


------------------------------------
Reply:
finally use back normal control in asp .net application, but need to use large cell spacing

------------------------------------

OS deployment

Hi,

Anybody know whether the OS deployment can be made from SCCM(Either 2007 or 2012) via internet to the client machine?


  • Edited by Esh M Monday, April 16, 2012 10:50 AM

Reply:

2007: No.

2012: No, although there was some initial research done to enable this in the early Betas.

Is deploying a 2.3GB+ WIM over the Internet really feasible though? Not mention connecitivity and security in general?

The usual solution for disconnected clients is using stand-alone media.


Jason | http://blog.configmgrftw.com | Twitter @JasonSandys


------------------------------------
Reply:

Thanks a lot for your valuable information Sandy.

And hence OS deployment over internet feature is not included in SCCM 2012 ?

Or is it possible to push an image around 4 to 6GB provided the internet is fast enough ?


Murugeswaran M


------------------------------------
Reply:
No, to my knowledge, they pulled this functionality before RTM although there were hints that the SDK may provide the ability to do this - -haven't looked myself. The preview release of the SDK was released this week.

Jason | http://blog.configmgrftw.com | Twitter @JasonSandys


------------------------------------

Why you should NOT use InfoPath 2010 if a repeating table is required.

Does anyone have any feedback on this?

Why you should NOT use InfoPath 2010 if a repeating table is required


Jeffrey T McFarland


Reply:

Not so, you just need the right companion tool set.  For example, you can submit the forms to the form lib, and a copy of the xml to a SQL2005(and beyond) table using the xml data type.  From there you can perform xquery to 'shred' the forms and report as needed.

We use IP extensively, and this approach has served us well.  

There are 3rd party tools to assist with this IP form shredding (QDabra), or you can roll yer own as we did.


/bac


------------------------------------
Reply:
I've very interested in trying this technique for myself. Bob and you please give me some details on how this works and what steps you used to implement it?

Jeffrey T McFarland


------------------------------------
Reply:
The post outlines issues when attempting to store a form containing a repeating table within a List.   But the point is that InfoPath stores data in XML , so it makes more sense to store the form output as a file in a document library - you can still get at this information by accessing the information directly i.e. either with or without InfoPath. 

------------------------------------
Reply:

Ted,

I understand your point. Can you give me an example of accessing the repeating table data without InfoPath? Also, would you use InfoPath 2010 when a repeating table was required and you knew that later on down the road you might need to access the repeating table data outside of InfoPath?


Jeffrey T McFarland


------------------------------------
Reply:

I'm working on a white paper on this process, but the general overview is:

  • Save form to SharePoint (so you can benefit from SP workflows, alerts,...)
  • Save a mirror copy of the form xml to a SQL table xml data type, with appropriate xml indexing. 
  • Perform reporting from the SQL xml table using xQuery.

HTH


/bac


------------------------------------
Reply:

Jeffrey,

You will need to do in code.  Having saved to a Document Library, you will be able to access the XML - for instance, if you view the content for the library and download a copy of the XML stored, and edit with Notepad, you will see the XML data structure for the form. You can use c# XML to access and also modify the XML if required.   In answer to your second question, yes - but obviously InfoPath is not always the best tool to use for a form.


------------------------------------
Reply:
Bob I'd like to see your white paper on this as soon as you complete it. I don't know how to do what you described in the 2nd and 3rd bullet points. Thanks for the feedback.

Jeffrey T McFarland


------------------------------------
Reply:
Ted, I don't follow you. Can you please describe your technique in more detail?

Jeffrey T McFarland


------------------------------------

List group membership for all Contacts in an OU

Hi there, I need to output a list of all the groups that each contact (in a specific OU) belongs to.

I can list the contacts in both the Exchange Management Shell, and using the Quest cmdlets, using the following commands:

Get-Contact -ResultSizeUnlimited -OrganizationalUnit "Domain/OrganizationalUnit"

get-QADObject -SizeLimit 0 -Type 'contact' -OrganizationalUnit "Domain/OrganizationalUnit"

How do I then output each contact's group membership?

Thanks in advance.


Reply:

put those contacts in a csv file.

contacts

externaluser1@compan1.com

externuser2@company2.com

import-csv testfile.txt |foreach {get-qadobject $_.contacts} |select name, memberof


James Chong MCITP | EA | EMA; MCSE | M+, S+ Security+, Project+, ITIL msexchangetips.blogspot.com


------------------------------------
Reply:

Thanks so much James, this is perfect!

For anybody else, I've been able to combine this into two lines that perform what I need - using the Quest cmdlets:

get-QADObject -SizeLimit 0 -Type 'contact' -OrganizationalUnit "YourDomain/OrganizationalUnitName" | Export-CSV Contacts.txt

import-csv Contacts.txt |foreach {get-QADobject $_.PrimarySMTPAddress} | ft name, memberof -wrap >contactgroupmembership.txt

Obviously would need to change "YourDomain/OrganizationalUnitName" to your domain name & OU.

Thanks again James!


------------------------------------

Out of sync audio and Video when live streaming

Hi team.

 I have a issue with Expression Encoder 4 Pro.

  When I broadcast live streaming by using EE4 Pro SP, Pinnacle Studio Movieboard plus and Sony HandyCam Sony HDR-CX130E to record  Video but when I start live streaming and end user view streaming on Windows media player, appear out of sync video and audio

My config

Input



Output



Please give me a recommendation.

Thanks team.


Reply:

Hi,

I would suggest open a new thread on Expression forums below for further support:
http://social.expression.microsoft.com/Forums/en-US/categories

Best regards,


Rex Zhang

TechNet Community Support


------------------------------------
Reply:
Thanks Zhang.

------------------------------------

PEAP-TLS authentication issue with Cisco WLC and NPS

2008 R2 NPS server

Windows 7 pro client

2008 AD

2008 R2 enterprise CA in the domain.

Having a weird issue with PEAP-TLS.

I have configured this multiple times before with no issue.

This time I experience som weird issues.

WLC gives this message RADIUS server xxx.xxx.xxx.xxx:1812 failed to respond to request (ID 17) for client XX:XX:XX:XX:XX:XX / user 'unknown'

NPS Logs has no entries.

Change the configuration to PEAP MSchap v2 and authentication works, but only for user authentication.

NPS logs for computer authentication tells me that the computer account is denied by default Network policy. which means that my Network policy is not triggered by the computer authetication request.
I have domain users OR domain computers under conditions.

When I create another Network policy and use Machine Groups with domain computers as condition, computer authentication works.

Change back to peap-tls, nothing works. No nps logs and RADIUS server xxx.xxx.xxx.xxx:1812 failed to respond to request (ID 17) for client XX:XX:XX:XX:XX:XX / user 'unknown' is back in WLC logs.

I'm thinking certificate issue here. But I have tripple verified all certificate settings and enrollment policies.

NPS server get certificate from a copy of RAS and IAS Server template, Users gets from a duplicate of Users template and computers gets from a duplicate of computers. All settings are from official technet guides and have worked fine several times before.

I cant wrap my head around why I need to specify a separate network policy with machine groups as condition to get computer authetication to work.

And why does not Certificate authentication work when all settings are exactly the same as another installation that is working just fine?

Are there any logs on the NPS server I can check for error messages which can give me some input on what is going wrong?


Reply:

I assume it's a v2 certificate?

.

Have you called or placed a TAC with Cisco support for assistance? Usually with Cisco, your 24/7 Gold goes a long way and they'll take whatever time it takes to help resolve it, even configuring the NPS and other Windows side settings, server and clients.

http://support.cisco.com

.


Ace Fekay
MVP, MCT, MCITP Enterprise Administrator, MCTS Windows 2008 & Exchange 2007 & Exchange 2010, Exchange 2010 Enterprise Administrator, MCSE & MCSA 2003/2000, MCSA Messaging 2003
Microsoft Certified Trainer
Microsoft MVP - Directory Services
Complete List of Technical Blogs: http://www.delawarecountycomputerconsulting.com/technicalblogs.php

This posting is provided AS-IS with no warranties or guarantees and confers no rights.

FaceBook Twitter LinkedIn


------------------------------------

Who's going to The 2012 Experts Conference in San Diego?

My colleague Carol and myself (from the land of Oz) will be presenting a couple of sessions ... see http://www.theexpertsconference.com/us/2012/directory-identity/session-abstracts/ ... and I for one would be keen to know who will be there so I can put some faces to the names on this forum :).

Please post here (a) if you're going, and (b) if you're keen to catch up ... I will be staying on for an extra day or so if anyone is keen to meet somewhere for a general natter after the conference.


Bob Bradley (FIMBob @ http://thefimteam.com/) ... now using Event Broker 3.0 @ http://www.fimeventbroker.com/ for just-in-time delivery of FIM 2010 policy via the sync engine


Reply:
I�??m going! Oh, and I�??m also presenting 2 AD DR sessions and 2 AD DR workshops!
 
See you there!
 

<o:p></o:p>

Cheers,<o:p></o:p>


(HOPEFULLY THIS INFORMATION HELPS YOU!)
Jorge de Almeida Pinto | MVP Identity & Access - Directory Services

-------------------------------------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always evaluate/test yourself before using/implementing this!
* DISCLAIMER:
http://jorgequestforknowledge.wordpress.com/disclaimer/
-------------------------------------------------------------------------------------------------------
################# Jorge's Quest For Knowledge ###############
###### BLOG URL:
http://JorgeQuestForKnowledge.wordpress.com/ #####
#### RSS Feed URL:
http://jorgequestforknowledge.wordpress.com/feed/ ####
-------------------------------------------------------------------------------------------------------
<o:p></o:p>

"UNIFYBob" wrote in message news:126e9000-61a5-41c2-92fb-856c13fdaa65@communitybridge.codeplex.com...

My colleague Carol and myself (from the land of Oz) will be presenting a couple of sessions ... see http://www.theexpertsconference.com/us/2012/directory-identity/session-abstracts/ ... and I for one would be keen to know who will be there so I can put some faces to the names on this forum :).

Please post here (a) if you're going, and (b) if you're keen to catch up ... I will be staying on for an extra day or so if anyone is keen to meet somewhere for a general natter after the conference.


Bob Bradley (FIMBob @ http://thefimteam.com/) ... now using Event Broker 3.0 @ http://www.fimeventbroker.com/ for just-in-time delivery of FIM 2010 policy via the sync engine


Jorge de Almeida Pinto [MVP-DS] | Principal Consultant | BLOG: http://jorgequestforknowledge.wordpress.com/

------------------------------------
Reply:

I'll be there. It would be great to meet some of the people on this forum.

Thanks,

Mark


Mark Creekmore - BlueVault Software http://www.bluevaultsoftware.com


------------------------------------
Reply:
Will be there

My Book - Active Directory, 4th Edition
My Blog - www.briandesmond.com


------------------------------------

Will Microsoft stop the support if I use undocumented Procedures

Hi, 

During a recent search I found out that Microsoft says that that it does not support the use of undocumented procedures in production. It says that to ensure the performance and stability we should use only the documented stuff. 

  1. Does that mean, if I use undocumented procedure (it could be simple as sp_MSForeachDB) It is considered as a violation to the the agreement?
  2. Will use of undocumented features harm the support we receive? (I understand MSFT may not support if our server crashes, slowed down because of the use of those procedures, but it is a different story) 

What the official position of Microsoft?

   


Cheers, Preethiviraj Kulasingham


Reply:

Related discussion: "With regard to these undocumented stored procedures can I
legally use them in my programs? "

I would not use them in production. I would use them as ad-hoc scripts in my DBA work.

WHILE loop with dynamic SQL is an easy replacement for sp_MSforeachxxx:

http://www.sqlusa.com/bestpractices2008/rebuild-all-indexes/


Kalman Toth SQL SERVER & BI TRAINING


------------------------------------

How to sequence the System Center Configuration Manager 2007 R3 Admin Console

Just an FYI that we published a KB article today that has a recipe for sequencing the ConfigMgr 2007 admin console:

http://blogs.technet.com/b/appv/archive/2012/04/19/kb-how-to-sequence-the-microsoft-system-center-configuration-manager-2007-r3-admin-console-using-microsoft-app-v.aspx

J.C. Hornbeck | System Center & Security Knowledge Engineer

Get the latest System Center news on Facebook and Twitter:

clip_image001 clip_image002

App-V Team blog: http://blogs.technet.com/appv/
ConfigMgr Support Team blog: http://blogs.technet.com/configurationmgr/
DPM Team blog: http://blogs.technet.com/dpm/
MED-V Team blog: http://blogs.technet.com/medv/
Orchestrator Support Team blog: http://blogs.technet.com/b/orchestrator/
Operations Manager Team blog: http://blogs.technet.com/momteam/
SCVMM Team blog: http://blogs.technet.com/scvmm
Server App-V Team blog: http://blogs.technet.com/b/serverappv
Service Manager Team blog: http://blogs.technet.com/b/servicemanager
System Center Essentials Team blog: http://blogs.technet.com/b/systemcenteressentials
WSUS Support Team blog: http://blogs.technet.com/sus/

The Forefront Server Protection blog: http://blogs.technet.com/b/fss/
The Forefront Endpoint Security blog : http://blogs.technet.com/b/clientsecurity/
The Forefront Identity Manager blog : http://blogs.msdn.com/b/ms-identity-support/
The Forefront TMG blog: http://blogs.technet.com/b/isablog/
The Forefront UAG blog: http://blogs.technet.com/b/edgeaccessblog/

No comments:

Post a Comment

Setup is Split Across Multiple CDs

Setup is Split Across Multiple CDs Lately I've seen a bunch of people hitting installation errors that have to do with the fact th...