Wednesday, 20 April 2016

The search service is not able to connect to the machine that hosts the administration component. Verify that the administration component in search application 'Enterprise Search Service Application' is in a good state and try again.

Found this error on the APAC farm, The search service is not able to connect to the machine that hosts the administration component. Verify that the administration component  in search application 'Enterprise Search Service Application' is in a good state and try again.

After looking at the ULS log found the databases were not in compatibility mode.

You can go to Upgrade and Migration, Click on Review Databases , check if the search databases are in backward compatibility mode 


run psconfig if not upradge the databases manually this tends to happen when you have automated patching on the farm sometimes for windows updates.

Tuesday, 3 November 2015

Install Apache Server on Amazon AWS , Redhat , Centos

To install Apache Server, connect to your console ( bash )

yum install httpd

To start the Apache Server

Service httpd start

I will cover the configuration of Apache Server in my next article.

Wednesday, 9 September 2015

Delegate Rights Management Role in Office 365

In this article, we will cover how to delegate rights management role to a user

Only a Global Administrator can activate Rights Management Service in Office 365

To find how to Activate Rights Management, Click Here

Launch the Azure Active Directory Rights Management Powershell Module

Connect to Rights Management Service , enter your global admin credentials

connect-aadrmservice

To see who all have Rights Management Administrator Role,

get-aadrmrolebasedadministrator

To delegate Rights Management Admin, use this

add-aadrmrolebasedadministrator -emailaddress "johnsmith@contoso.com"

Activate Rights Management in Office 365

In this Article, we will cover the different options available to activate Rights Management.

Rights Management service can be integrated with 


  • Exchange Online
  • SharePoint Online 
  • Office 


There are two ways in which you activate rights management in Office 365.


  • Using Office 365 Admin Center 
  • Using Powershell

Note: Only a Global Administrator can activate Rights Management

Using Office 365 Admin Center:

Login to Office 365 Admin Center, Go to Services from the left hand panel

Click on Rights Management > Manage > Activate 



Using Powershell:

To Activate using Powershell, you will need to install the Azure Rights Management Administration Tool  i.e.  Windows Azure Rights Management Admin  Powershell module

Connect to Microsoft Online Service

Connect-Msolservice

Import the Rights Management Module

Import-module aadrm

Connect to Rights Management Service 

connect-aadrmservice

To Activate rights Management

Enable-aadrm

Now to Disconnect ,

disconnect-aadrmservice

Add , Remove , Get , Set Groups in Office 365

In this Article, we will cover the Powershell commands available from high level in Office 365 for Groups.

There are four types of msolgroup Commands available for Groups 

  • Adding a Group > New-MsolGroup
  • Removing a Group > Remove-MsolGroup
  • To update the Group Security > Set-MsolGroup
  • Get a Group details > Get-MsolGroup

For more information on the commands, refer to technet

Restore User in Office 365

In this Article, we will cover how to restore a user  using PowerShell in Office 365. 

In order to use the following command lets , the pre-requisite is to Install Windows Azure for Active Directory PowerShell, please refer to Microsoft TechNet Article.

Launch the Windows Azure for Active Directory Shortcut

Connect to Office 365 using the following command , and enter your credentials

Connect-msolservice 

When a user is removed, it goes into Recycle Bin where it's available for 30 days and is recoverable within 30 days from the time of deletion.

Once you are connected, you can use the following command to restore a user

To Get a list of removed users,

Get-MsolUser–returndeletedusers

To Restore a User,

Restore-MsolUser –UserPrincipalName JohnSmith@contoso.com

Remove User in Office 365

In this Article, we will cover how to remove users using PowerShell in Office 365. Users can be removed using Office 365 Admin Center as well.

In order to use the following command lets , the pre-requisite is to Install Windows Azure for Active Directory PowerShell, please refer to Microsoft TechNet Article.

Launch the Windows Azure for Active Directory Shortcut

Connect to Office 365 using the following command , and enter your credentials

Connect-msolservice 

Once you are connected, you can use the following command to remove a user

To Remove a User,

Remove-MsolUser –UserPrincipalName JohnSmith@contoso.com

This will prompt to remove any licenses that are assigned to the user. Once the account is removed, the user account is recoverable within 30 days from recycle bin

To Remove a User from Recycle Bin i.e. permanently delete

Remove-MsolUser –UserPrincipalName JohnSmith@contoso.com -RemoveFromRecycleBin

Adding Users in Office 365


There are various ways in which users can be added in Office 365. You can add the users using the following ways

  • Office 365 Admin Center
  • Bulk Import using CSV Files
  • Directory Sync
  • PowerShell

In this Article, we will cover how to add users using PowerShell

In order to use the following command lets , the pre-requisite is to Install Windows Azure for Active Directory PowerShell.

Launch the Windows Azure for Active Directory Shortcut

Connect to Office 365 using the following command , pand enter your credentials

Connect-msolservice 

Once you are connected, you can use the following command to create a new user
New-MsolUser –UserPrincipalName “JohnSmith@Contoso.com”–Displayname “John Contoso” –Fristname “John” – Lastname “Smith”

Note:  the user account will be created , a random password is generated,  in Windows Azure Active Directory but no licenses are assigned to the user. 

Some other commands to get some help, which I find really helpful are:

For Help > Get-Help  New-MsolUser

For Examples > Get-Help New-MsolUser –examples 

Fore More Information > Get-Help New-MsolUser –detailed 

For Technical Information > Get-Help New-MsolUser –full  

For Online help > Get-Help New-Msoluser –online


Thursday, 27 August 2015

SharePoint 2016 Preview New Integartion Capability

SharePoint 2016 preview is out and SharePoint professional across the world out there aredoing a deep dive to get up to speed to understand the newer capabilities of what platform has to offer.

Biggest one which I See , based on what I have seen is

Integration capabilities

Hybrid Integration

Project Server is now fully integrated by default on 2016, how the licensing will be interesting to see.

Here is a screen capture of the Project Server Integration



Some of the capabilities may change when RTM is released not covered here.

Friday, 24 April 2015

SharePoint 2013 update conflict has occurred, and you must re-tr this action. The object SPWebApplication Name

While running the command to remove the dodgy extranet web app, got this error

Remove-SPWebApplication : An update conflict has occurred, and you must re-tr
this action. The object SPWebApplication Name=extranetppd.contoso.com was updated by Service Account, in the w3wp
(6180) process, on machine Contoso001.  View the tracing log for more
information about the conflict.
At line:1 char:1

Clear the SharePoint cache , refer to the technet article

Ran the command again, works absolutely fine

Remove-SPWebApplication https://extranetppd.contoso.com/  -Confirm -DeleteIISSite -RemoveContentDatabases

Thursday, 23 April 2015

Delete / Force / Remove Rogue or Orphaned Site Collection in SharePoint 2013

Whilst provisioning app catalog site, encountered an issue with the database permissions. Aftering sorting that out, whilst re-provisioning the app catalog site , found the previous attempt added a rogue / orphaned site colleciton.

Though the site colleciton was visible in central admin, however, the option to delete was graded out.

Use the following Powershell, this did the trick.

$site = Get-SPSite https://intranet.contoso.com/apps/appstore
$siteId = $site.Id
$siteDatabase = $site.ContentDatabase
$siteDatabase.ForceDeleteSite($siteId, $false, $false)

Monday, 26 January 2015

Error while crawling LOB contents. ( Error caused by exception: Microsoft.BusinessData.Infrastructure.BdcException The shim execution failed unexpectedly - Exception has been thrown by the target of an invocation..: System.Net.WebException The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.; SearchID

Error while crawling LOB contents. ( Error caused by exception: Microsoft.BusinessData.Infrastructure.BdcException The shim execution failed unexpectedly - Exception has been thrown by the target of an invocation..: System.Net.WebException The underlying connection was closed: Could not establish trust relationship for the SSL/TLS secure channel.; SearchID 

The issue with the certificates not being recognized as trusted in the SharePoint Farm. To resolve this:


  • Go the the Certificate, Click on Certificate Path 
  • Select the Root Certifcate, Double Click on it
  • Click on Details 
  • Click on Copy to File
  • Save the file
  • Now Go to SharePoint > Security > Manage Trust
  • Create a New Trust >  Import the Root certificate
  • Click oK
  • Run and iisreset on the SharePoint servers
  • Run a full crawl now


Issue resolved for me.

Check the ULS to find more information , may have to switch on verbose extended logging, but generally speaking, the cause of the issue will be the certificates.

Friday, 22 August 2014

THE EXECUTE permission was denied on the object 'proc_GetProductVersions' Database '_Config', schema 'dbo'.

We had an issue where search was being used as a core component on the home page for one of the solution's. On further research we identified the it was an access issue on the database side. We are using SharePoint 2013 Enterprise Search which is on Always on Availability Group.

Here are the two errors we got

Error 1: 'The EXECUTE permission was denied on the object 'proc_MSS_GetLease', 

Error 2: THE EXECUTE permission was denied on the object 'proc_GetProductVersions' Database '_Config', schema 'dbo'.

For the Error 1, the search service account needs to have access on SPSearchDBAdmin role on the following databases
  • _Search
  • _Search_AnalyticsReportingStore
  • _Search_CrawlStore
  • _Search_LinksStore
For the Error 2, the search service account needs to have  access on WSS_Content_Application_Pools role  for the following databases 


  • _Config
  • _Admin

After giving the access, bounced the IIS , issue resolved for us. Check the logs to identify the problem.

Saturday, 5 April 2014

SharePoint 2013 Service Pack 1 Withdrawn

Microsoft has withdrawn Service Pack 1 from general public availability as it will block or won't allow future public or cumulative updates  from installing. There are no other issues reported as per the notes. They are going to release a new version of Service Pack in future no timeline defined for this yet.

There are no clear notes about how to roll back for clients who have already implemented it on their farms.

The download links are broken.

A call with MS Support team may guide them on next steps stay tuned.

Service Pack 1 Update on 08/04/2014:  Checked with  Microsoft's Technical Account Manager and subsequently a call with Suppor Team. "Guidance is not to rollback as the existing Service Pack 1 won't affect anything apart from stopping future upgrades. Once the re-released version of Service Pack 1 / hotfix is available , customers can install it. There is no ETA on the release date" .


"We have recently uncovered an issue with this Service Pack 1 package that may prevent customers who have Service Pack 1 from deploying future public or cumulative updates. As a precautionary measure, we have deactivated the download page until a new package is published. "

Links: 

http://support.microsoft.com/kb/2817429/en-gb

http://blogs.technet.com/b/office_sustained_engineering/archive/2014/02/25/announcing-the-release-of-service-pack-1-for-office-2013-and-sharepoint-2013.aspx

Service Pack 1 Update: Microsoft has re-released a newer version of the service pack with the fix i.e. to allow installing future CU's. The challenge we had was to re-install newer version of service pack 1 on all of our SharePoint Farms which comprises of 40 plus servers. I would have expected Microsoft to release a hot-fix for customers who have already installed Service Pack instead of going for a full blown deployment of Service Pack. This caused enormous time to coordinate the deployment of service pack going through CAB, deployment etc.




Friday, 4 April 2014

SharePoint 2013 Service Pack 1 Fails

Rolled out Service Packs on  6 DEV Servers , Shared Services UAT farm all went well apart from couple of niggling issues like the following but overall it was successful:

Search Host Controller Service stuck in Starting State
User Profile Sync Service stuck in Starting state

Those were pretty straight forward to fix but the killer one appeared on the Pre-Prod environment which connects to Production domain controller. Everything looked good  till we ran Product and Config Wizard I reckon that's where all the Fun starts huh :). Failed at the Last step.

“   Unable to create a Service Connection Point in the current Active Directory domain. Verify that the SharePoint container exists in the current domain and that you have rights to write to it.
Microsoft.SharePoint.SPException: The object LDAP://CN=Microsoft SharePoint Products,CN=System,DC=emea,DC=cbre,DC=net doesn't exist in the directory.
   at Microsoft.SharePoint.Administration.SPServiceConnectionPoint.Ensure(String serviceBindingInformation)

   at Microsoft.SharePoint.PostSetupConfiguration.UpgradeTask.Run() “

The container Microsoft SharePoint Products was missing in ADSI Active Directory Service Interface Editor. 

As it's a Shared Services environment and so many install / farms account and Pre-Prod environment for Shared Services leveraged across Intranet and Extranet farms,  it made sense to create an Active Directory Group called as SharePointFarmAdmins and add all install and farms accounts in it.

Once that was done, our AD guy created the container and granted the required ( write on the container ) permissions to SharePointFarmAdmins group. 

Re-ran the Product Configuration Wizard success. 

There are some specific Power Shell command let's which allows you to Get  and Set the Service Connection Point SCP which you can run from SharePoint 2013 Management Shell. 

To Get: 

Get-SPFarmConfig -ServiceConnectionPoint 

To Set : 

 Set-SPFarmConfig -ServiceConnectionPointBindingInformation StringwithBindingInformation


To create the Microsoft SharePoint Products container in ADSI  ,  follow the instructions from here: http://technet.microsoft.com/en-us/library/ff730261(v=office.14).aspx

The roll out of Service Packs , Cumulative updates , solutions  etc.. to go through a SDLC process etc.... emphasizes the importance of having a Pre-Prod environments which I have seen some organization ignores due to cost related issues or awareness of how it will play a pivotal role.

PS: Make sure WSS Usage DB is not part of Always On Group in case you're using Availability Groups in SQL Server 2012

Thursday, 6 March 2014

SharePoint 2013 PowerPivot Configuration Tool: the user is not a farm administrator

Got this error while configuring the PowerPivot Configuration Tool  on the Development environment using a Developers account setup with farm account permissions

SharePoint 2013 PowerPivot Configuration Tool  the user is not a farm administrator

It was  quite bizarre the Developer's account had all the required rights on SQL Server , Local Admin on the box and Part of Farm Admin Group.

After further research tried running the PowerPivot Configuration Tool using Farm Account it didn't give any errors. Found that you need to be a Site Collection Administrator of Central Admin in order to run the PowerPivot Configuration Tool successfully.

Performed the following steps to resolve this

Launch the Central Admin
Go the Site Settings  > Site Collection Administrators
Add the User Account you're using to run the PowerPivot Configuration Tool  as Site Collection Admin
Click Ok

This resolved the issue was able to run the PowerPivot Configuration Tool Successfully.


Wednesday, 26 February 2014

User Profile Replication Service : Can not access Destination web service SharePoint 2013 farms

Got the error Start-SPProfileServiceFullReplication : Can not access Destination web service whilst performing one way User Profile Replication between two SharePoint 2013 farm's for About Me and PictureURL properties This worked beautifully whilst performing the Replication on Pre-Prod Farm but not on Prod farms

Did check various bits and pieces for permissions for the farm account as listed on various blogs but was of not much help. 

Performed the following steps to resolve this

Launch SharePoint 2013 Management Shell

Changed the Directory to  C:\Program Files\Microsoft\SharePoint 2010 Administration Toolkit\Replication Engine

Added the PS Snap in

Add-PSSnapin Microsoft.Office.Server.AdministrationToolkit.ReplicationEngine

Tried the command 

Start-SPProfileServiceFullReplication -Destination https://mydestination.contoso.com  -Source http://mysource.contotos.com -EnableInstrumentation -MaxNumberOfThreads 15 -Properties "AboutMe", "PictureURL" -DoSocialReplication

Didn't work, tried accessing the My Site from the server that didn't load even though loop back was disabled.

Was able to access My Site User Profile Service from an end user machine which indicated there was no issue the web service as it was accessible.

Found that the Proxy Server in Internet Explorer Connection Settings was enabled and set to the proxy server on the Front End server from where I was running the command.

Disabled the Proxy in IE, executed the command again boom replication started and was successful. 

At times there are some specific settings which cause the issue. Another day another dollar.

User Profile Synchronization Service stuck in stopping state in SharePoint 2013 farm

We had this issue of User Profile Synchronization Service stuck in stopping state in one of the  SharePoint 2013 farms. Performed the following steps to resolve this.

Log on to the Server where User Profile Synchronization Service was stuck in stopping state.

Make sure the Forefront Identity Manager and Forefront Identity Manager Synchronization Service are using the farm account as the service account

Launch SharePoint 2013 Management Shell

Get the GUID for User Profile Synchronization Service
Get-SPServiceInstance | Select-Object TypeName, ID

Check the status of User Profile Synchronization Service

Get-SPServiceInstance -Identity GUIDOfUserProfileSynchronization

To stop this , type the GUID of User Profile Synchronization Serviec

Stop-SPServiceInstance -Identity GUIDOfUserProfileSynchronization

IISRESET on the front end servers.

Spencer Harbar's article is a must read to understand and troubleshoot the issue.

Wednesday, 5 February 2014

Failed to load protocol handler OSearch15.HttpHandler.1. Error description: The parameter is incorrect.

Got this error on one of the development machine on SharePoint 2013 while crawling a content source for SharePoint sites.
 
Failed to load protocol handler OSearch15.HttpHandler.1. Error description: The parameter is incorrect.
 
SharePoint Search Content Account had Full Read access on the Web Application.
Tried various steps starting , restarting the following services in the hope this may resolve the issue
 
  • SharePoint Server Search 15
  • SharePoint Search Host Controller
  • SharePoint Timer Service
IISRESET

None worked.
 
Tried stopping and starting the following from Manage Services on Server from Central Admin, no go
  • Search Host Controller Service 
  • Search Query and Site Settings Service 
Deleted the Search Service Application, Proxy and Re-created the Search Service Application with new Search Proxy

Same error while crawling the Content Source for SharePoint sites.
Deleted the Search Service App Again

Launched ULS Logs while re-creating Search Service Application.

Found that Indexer was already there on C:\Program Files\Microsoft Office Servers\15.0\Data\Office Server\Applications for the old rogue Search Service App and search had to re-create a new one and there was some conflict

Deleted Search Service App one last time

Took a copy of all the files at C:\Program Files\Microsoft Office Servers\15.0\Data\Office Server\Applications
Deleted all the files from here

Re-created the Search Service App with new Proxy and specified the Index file path to different location i.e. D:\Index\ via PowerShell check MSDN for the commands

Deleted the Search Center site , re-created a new one

Ran the crawl , worked fine without any issues.

This solution may not work in your environment, check the ULS to identify and troubleshoot the issue.