miércoles, 9 de octubre de 2013

FIM User Profile Synchronization Service Issue Resolved

I have found that my sync was working fine until I selected "Synchronize BCS Connections" in the configuration and it broke everything. I had to delete the service application and reinstall the user profile application.
How I fixed the issue: Symptoms: User Profile Sync doesn’t work. Forefront Identity Manager Synchronization Service Hangs User Profile Synchronization Service and User Profile Service hangs on “Central Admin > Services on Server” Lots and lots of errors in event log.. amongst others
Event 22. The Forefront Identity Manager Service cannot connect to the SQL Database Server.
Event 6398. The description for Event ID 6398 from source Microsoft-SharePoint Products-SharePoint Foundation cannot be found.
Event 3. .Net SqlClient Data Provider: System.Data.SqlClient.SqlException: Could not find stored procedure 'RegisterService'.
Event 2. The Forefront Identity Manager Service could not bind to its endpoints.  This failure prevents clients from communicating with the Web services.
Event 6324. The server encountered an unexpected error and stopped.
ERR: MMS(1956): sql.cpp(5580): Query (select count(*) from [mms_management_agent]) performed with error
ERR: MMS(1956): sql.cpp(5633): Invalid object name 'mms_management_agent'.
ERR: MMS(1956): sql.cpp(5641): hrError: 0x80040e37, dwMinor: 208
ERR: MMS(1956): sql.cpp(5796): SQL error: 42S02, native: 208
BAIL: MMS(1956): sql.cpp(2897): 0x80040e37 
BAIL: MMS(1956): sql.cpp(4114): 0x80040e37 
ERR: MMS(1956): sql.cpp(5580): Query (select fixed_schema_version_number from [mms_server_configuration] ) performed with error
ERR: MMS(1956): sql.cpp(5633): Invalid object name 'mms_server_configuration'.
ERR: MMS(1956): sql.cpp(5641): hrError: 0x80040e37, dwMinor: 208
ERR: MMS(1956): sql.cpp(5796): SQL error: 42S02, native: 208
BAIL: MMS(1956): sql.cpp(2897): 0x80040e37 
BAIL: MMS(1956): sql.cpp(2738): 0x80040e37 
BAIL: MMS(1956): storeimp.cpp(2485): 0x80040e37 
BAIL: MMS(1956): storeimp.cpp(293): 0x80040e37 
ERR: MMS(1956): server.cpp(294): Failed to connect to the database Sync DB on ****\SHAREPOINT
BAIL: MMS(1956): server.cpp(295): 0x80040e37 
BAIL: MMS(1956): server.cpp(3518): 0x80040e37 
BAIL: MMS(1956): service.cpp(1528): 0x80040e37 
ERR: MMS(1956): service.cpp(977): Error creating com objects. Error code: -2147217865. This is retry number 3.
BAIL: MMS(1956): service.cpp(991): 0x80040e37 
Forefront Identity Manager 4.0.2450.5"



Looks familiar?
Diagnosis:
Um.. something is wrong with FIM?
Solution:
I have tried to compile the list of things I did to sort this out.
Rule of thumb, shut down the offending services and then make the changes. I assume you have the correct SPadmin accounts and all the services have the right accounts assigned.
Edit: 2010-10-28. If you do this and it still doesn't work, try deleting the User Profile Service Application and recreating it, as described in the following post http://www.harbar.net/articles/sp2010ups.aspx Look under the "Create the UPS service application" section.
I also had to stop most of the user profile services and do a restart after deleting and reinstalling the UPS service, also the new application pool that was created was set to 32 bit, which I had to change. Fair enough, took me 3 hours, but I did not have to reinstall SP.. again..


0. Reset IIS.. (just in case something is running around in memory)
PS D:\> iisreset


1. A wild FIM Service Account appears.. I choose you SPadmin account.
2. Now I assign “Full control” for my SPadmin account to the following folder “C:\Program Files\Microsoft Office Servers\14.0”
3. Open IIS manager and make sure that for all the application pools the “Advanced Settings>General>Enable 32-Bit Applications” = False.
4. Open SP CA > “Services on Server” and make sure that “User Profile Synchronization Service” and “User Profile Service” is stopped. If they are just hanging, do this:
Open PowerShell on SP server.
a. Type:
get-spserviceinstance
Name                             Status   Id
--------                         ------   --
Managed Metadata Web Service     Online   82880b37-2cff-4a3c-94ca-922bb739ff27
User Profile Synchronization ... Provi... 03f49dd6-658e-44cd-a6f0-21c7560242ab
Business Data Connectivity Se... Online   901d17ff-471a-4557-80eb-befac3ffb396



b. Next, locate the GUID for the user profile synchronization service (it'll probably show a status of 'provisioning' in PowerShell) and use the following command:
c.
stop-spserviceinstance [userprofilesynchronizationservice GUID]


This will eventually stop the service and the status of the service on the SharePoint Manage services on server page will show a status of 'stopped'.
Also, the two Forefront services in the Windows Services console should be set back to a status of disabled.
5. Login as farm account
6. Backup the User Profile DB and the User Profile Sync DB
7. Stop the SharePoint 2010 Timer service:

PS D:\> net stop sptimerv4


8. Delete the data in the Sync DB using the following PowerShell script:

PS D:\> Get-SPDatabase


9. Copy the GUID associated with the User Profile Sync DB in the command line below

PS D:\> $syncdb=Get-SPDatabase -Id <GUID of User Profile Sync DB>


10. Execute these commands, in exactly the following order. This is not a script. So please cut and paste each of these commands one by one.

PS D:\> $syncdb.Unprovision()
PS D:\> $syncdb.Status='Offline'
PS D:\> Get-SPServiceApplication
#Copy the GUID associated with the User Profile Service and paste it after "Id" in the next command:

PS D:\> $upa=Get-SPServiceApplication -Id <GUID of User Profile Service
PS D:\> $upa.ResetSynchronizationMachine()
PS D:\> $upa.ResetSynchronizationDatabase()


11. Provision the Sync DB:

PS D:\> $syncdb.Provision()


12. Add the User Profile Synchronization service account (farm account) as the dbowner on the Sync DB (using SQL Server Management Studio).
13. Start the SharePoint 2010 Timer service

PS D:\> net start sptimerv4


14. Go to SP CA > Application Management > Manage Service Applications > Click on the right next to “User Profile Service” (Do not open it, just select it) > Administrators (on the ribbon) > Make sure your chosen account has full control
15. Start the User Profile Synchronization Service in the Central Administration UI.
16. After the User Profile Synchronization Service is started, reset IIS.
PS D:\> iisreset


17. Create connections to data sources in the Central Administration UI.
18. Run full user profile synchronization.
19. Open C:\Program Files\Microsoft Office Servers\14.0\Synchronization Service\UIShell\ miisclient.exe
I wish I could tell you that “Do this and it will work again” but I cannot guarantee this will solve your problem, it solved mine however.(this solution is pasted together from about 5 forums)
*Edit: see what happens if you talk to the right people*
Thank you Donald Farmer and Peter Willmot for pointing me in the right direction.. thank you
http://www.harbar.net/articles/sp2010ups.aspx
And of course, thank you Spencer Harbar for all the awesomeness

Assign Administration of a Service Application with PowerShell

$serviceapp = Get-SPServiceApplication <guid>
$security = Get-SPServiceApplicationSecurity
$serviceapp -Admin $principalUser1 = New-SPClaimsPrincipal -Identity "<domain\user>" -IdentityType WindowsSamAccountName Grant-SPObjectSecurity
$security -Principal $principalUser1 -Rights "Full Control" Set-SPServiceApplicationSecurity $serviceapp -ObjectSecurity $security -Admin

martes, 8 de octubre de 2013

Sharepoint 2010 + Infopath 2010: The operation could not be completed

 

En un formulario de Infopath, al crear una nueva conexión de extracción de datos, se presentó el siguiente mensaje de error:



En mi escenario, se creó un solo sitio de Project Web Application y un sitio secundario con una biblioteca de formularios. El mensaje de error se presenta cuando no se encuentra creada una colección de sitios en el sitio raiz de IIS.

Para solucionar el problema ejecutar el siguiente procesimiento:

- Utilizar la consola de Administración Central de Sharepoint para crear una colección de sitios en el sitio raiz de IIS (Sitio Web por Defecto).



- Crear nuevamente la conexión de recepción de información en el formulario de Infopath.



lunes, 7 de octubre de 2013

Auditing - A Built-in Feature of SharePoint

Introduction

In this article we explore the Audit feature of SharePoint 2010. This is a built-in feature and provides a great amount of flexibility for Administrators and Developers.

What is Auditing in SharePoint?

Auditing involves Activity Tracking inside the SharePoint environment. The auditing reports generated can be used by Administrators or Managers to determine the usage of SharePoint resources.
By enabling Auditing we can track activities like:
  • List Access
  • Library Access
  • Opening of Documents
  • Editing Items
  • Check In / Check Out
  • Copying / Moving / Deleting items
  • Searching
  • Editing Permissions
Following is a sample of how a detailed audit report looks like:

Under the hood, SharePoint uses events and a SQL Server table to retrieve and save the audit entries. Following are the topics we are discussing in this article:
  • Enable Audit
  • View Audit Entries
  • Custom Report
  • Server Object Models
  • Audit Event Types
  • Writing custom Audit entries

Enable Audit

We can enable audit for a site collection from the Site Settings > Audit Settings link.

From the Configure Audit Settings page opened, specify the events to be audited.

Once you have enabled Audit you can go ahead and try accessing/modifying existing list/library items. These activities should trigger the Audit entry creation.
Note: Please note that in real world scenarios you should only enable the events required. Too many event auditing queues causes more work to the server and can degrade the performance.

View Audit Entries

Now we can proceed to view the audit entries just created. You can use the Audit log reports from the Site Settings page.

In the appearing page View Auditing Reports you can see there are various categories of reports like:
  • Content Modification
  • Content Viewing
  • Deletion
  • Policy Modification etc.
Click on the Content Viewing as this time we are interested in only Viewing reports. In the appearing dialog, enter the document library where you want to save the report. Click OK to generate the report. (The report is a document and hence a document library is required to save it.)

Click on the Click here to view report link to view the report. It should open in an XLSX document. There are two tabs on the XLSX file – Summary and Detailed.

Custom Report

Now we can try using the Custom Report generation. This option is useful when we need to get a report based on / or a combination of:
  • Custom List
  • Particular user
  • Date Range
Please note that under the hood SharePoint has saved all the event records. The custom report will be filtering the records based on user selection.
To generate the custom report, go to Site Settings > Audit log reports > Run a custom report.

You should get the following page with filtering options:

You can choose Save Location, List, Dates, Users, and Events and click the OK button to generate the report as an XLSX file.

Server Object Models

The good thing is that we can use the Server Object Model to interact with Audit. Following are some of the important audit classes inside theMicrosoft.SharePoint namespace.
  • SPAudit
  • SPAuditEntry
  • SPAuditEventType
  • SPAuditQuery

SPAudit

SPAuditis the main class which can be used to access the audit settings for the associated object. The server object models like SPSite, SPWeb, SPList,SPDocumentLibrary contain a property named Audit which represents the underlying SPAudit settings.
TheSPAudit class contains methods for the following operations:
  • GetAuditEntries()to get the audit entries
  • Update()to update modifications to audit settings
Following is the code to get audit entries:
private void GetAuditEntriesButton_Click(object sender, EventArgs e)
{
    SPSite site = new SPSite("http://localhost");
    SPAudit audit = site.Audit;
    var collection = audit.GetEntries();
}
Following is the code to update audit settings for the site:
private void UpdateButton_Click(object sender, EventArgs e)
{
    SPSite site = new SPSite("http://localhost");
    SPAudit audit = site.Audit;
    audit.AuditFlags = SPAuditMaskType.None;
    audit.Update();
}
The above code clears all Audit Events by setting the AuditFlags property to None. After executing the code you can revisit the Site Collection Audit Settings to see that all the events are unchecked.
Note: You can use the SPAudit class to update audit settings across multiple site collections in one shot. Plus you can automate clearing the audit entries using the DeleteEntries() method.

SPAuditEventType

The enumeration SPAuditEventType is needed to specify the event type of the audit entry. The enumeration contains the following members:
public enum SPAuditEventType
{
    AuditMaskChange = 14,
    CheckIn = 2,
    CheckOut = 1,
    ChildDelete = 7,
    ChildMove = 0x10,
    Copy = 12,
    Custom = 100,
    Delete = 4,
    EventsDeleted = 50,
    FileFragmentWrite = 0x11,
    Move = 13,
    ProfileChange = 6,
    SchemaChange = 8,
    Search = 15,
    SecGroupCreate = 30,
    SecGroupDelete = 0x1f,
    SecGroupMemberAdd = 0x20,
    SecGroupMemberDel = 0x21,
    SecRoleBindBreakInherit = 40,
    SecRoleBindInherit = 0x27,
    SecRoleBindUpdate = 0x26,
    SecRoleDefBreakInherit = 0x25,
    SecRoleDefCreate = 0x22,
    SecRoleDefDelete = 0x23,
    SecRoleDefModify = 0x24,
    Undelete = 10,
    Update = 5,
    View = 3,
    Workflow = 11
}

SPAuditQuery

SPAuditQuery represents the class to do filter fetching of audit entries. It provides the following methods and properties:

You can see that the methods are similar to the options available in the custom report generation page. The sample code using SPAuditQuery is included in the source attachment.

Writing custom Audit entries

Occasionally we need to write custom audit information for a SharePoint solution. In this case we can reuse the Audit Server Object Model mechanism to perform the same.
Following is the code that writes to the Audit entry:
private void WriteAuditEvent_Click(object sender, EventArgs e)
{
    SPSite site = new SPSite("http://localhost");
    SPAudit audit = site.Audit;
    audit.WriteAuditEvent(SPAuditEventType.Custom, "MySource", "<xml/>");
}
After execution you can see the new entry through invocation of the GetAuditEntries()method. You can use the associated application to view the same.

Remark on Database Usage

The audit entries are stored inside the SharePoint database. You can view this database inside the SharePoint SQL Server instance. The table storing the Audit records is AuditData. For inserting your own records into the table, it is recommended to use the Server Object Model.

Summary

In this article we have explored the Audit feature of SharePoint. I believe now you will agree that it is a good feature that saves a lot of our time that otherwise would have been invested in writing events and persisting code.
The associated code contains the examples we have discussed.

viernes, 4 de octubre de 2013

Creating UDC in InfoPath forms

During development there is common requirement is to create InfoPath forms, those can be deployed into multiple servers. Once you completed the development in local DEV, the forms need to deploy in Stage and Prod. Here an issue arises, the connection. Since the path of different servers are different one need to create 'Universal Data Connection' (UDC)


1) Create a connection for submit data, and follow the wizard

2) Create a Connection Library, then click on the 'Convert' button, this will generate one XML file. Specify a name of the connection with extension UDCX

3) After creating the UDCX file, on the InfoPath form, add a new connection and browse all the connections on the server.

4) Important, for each server, Staging, Prod etc you have to create data connection file with the same name. In this example submit.udcx. The forms will pick dynamically the connection based the respective servers.

Configure service application associations

After the service application is created, we need to complete the last step of attaching the web application to the newly created service application. To do so, go back to "Application Management" in Central Administration. Under "Service Applications" click on "configure service application associations".



By default, the "default" connection will be selected. You can change it to "custom" and select all the service applications required for the web application including the custom, for example PerformancePoint service application. You can even set the custom service application as the default PerformancePoint service application. After selecting all the required service applications, click OK, and web application associations will be updated.

How to increase file upload size in InfoPath

By default there is a limit in file upload size in a InfoPath forms. If you drag a file upload control on a InfoPath form and start using it, you will notice that there is a limit in file uploading size. Now, follow these steps to increase the limit.

1. Go to Central Administration site of SharePoint server and select “Manage Web Application” under “Application Management”. Select respective Web Application then open Web Application general settings :
2. Set Maximum Upload Size to 50MB
3. Go back to Central Admin and click on “General Application settings”.Open “Configure info-path forms services” under “Info-path form services “.
4. Set Form Session State --> Maximum size of form session state value to 10240 KB( the default is 4096KB).