To roll out the Windows Server 2012 IPAM feature should be "a walk in the park" and it normally is but a while ago I was really struggling helping a customer out with this. I had made the configuration using GPO's and verified my settings several times but I kept getting the error "Unblock IPAM Access":
The solution was actually ridiculously simple. Editing the problem server in the IPAM Server Inventory panel to untick DNS - OK - then reticked DNS fixed it.
Blog to share tips and tricks that I come across in my role as a Technical Architect at Knowledge Factory.
Monday, 24 February 2014
Thursday, 13 February 2014
AD DS operation failed - Dcpromo error - FSMO role broken
I was about to remove a domain controller of a customer so many times before when the error below appeared.
Active Directory Domain Services Installation Wizard
---------------------------
The operation failed because:
Active Directory Domain Services could not transfer the remaining data in directory partition DC=ForestDnsZones,DC=company,DC=com to
Active Directory Domain Controller \\DC.company.com.
"The directory service is missing mandatory configuration information, and is unable to determine the ownership of floating single-master operation roles."
Very strange considering that running "netdom query fsmo" gives the result that one of the other domain controllers owns all FSMO roles. The Event Viewer is in this case your best friend.
The DC mentioned in the Event Viewer warning was an old Windows Server DC removed more than 5 years ago!
Let's move on, make sure to open ADSIEdit on the affected FSMO Role owner and make the necessary changes there.
How to obtain the correct setting:
Once the above steps were completed on the FSMO Role owner for Infrastructure I was able to properly demote the DC.
Active Directory Domain Services Installation Wizard
---------------------------
The operation failed because:
Active Directory Domain Services could not transfer the remaining data in directory partition DC=ForestDnsZones,DC=company,DC=com to
Active Directory Domain Controller \\DC.company.com.
"The directory service is missing mandatory configuration information, and is unable to determine the ownership of floating single-master operation roles."
Very strange considering that running "netdom query fsmo" gives the result that one of the other domain controllers owns all FSMO roles. The Event Viewer is in this case your best friend.
Log Name: Directory ServiceSource: Microsoft-Windows-ActiveDirectory_DomainServiceDate: 2014-02-01 14:44:13Event ID: 2091Task Category: ReplicationLevel: WarningKeywords: ClassicUser: ANONYMOUS LOGONComputer: DC.COMPANY.COMDescription:Ownership of the following FSMO role is set to a server which is deleted or does not exist.
The DC mentioned in the Event Viewer warning was an old Windows Server DC removed more than 5 years ago!
Let's move on, make sure to open ADSIEdit on the affected FSMO Role owner and make the necessary changes there.
How to obtain the correct setting:
- On the affected role owner open ADSIEdit.
- Click on Default Naming Context [DC.Company.Com].
- Click on DC=Company,DC=Com.
- Double click on CN=Infrastructure at the bottom of the list of folders.
- Locate the fSMORoleOwner attribute and click on it.
- Click the Edit button.
- CTRL+C to copy the contents of the attribute.
- Click CANCEL twice.
- Correct the problematic settings:
- Right click the ADSI Edit root and click on Connect to…
- Use the following connection point:
- DC=DomainDNSZones,DC=Company,DC=Com
- Click on Default Naming Context [DC.Company.Com] to populate it.
- Click on DC=DomainDNSZones,DC=Company,DC=Com folder.
- Double click on CN=Infrastructure.
- Locate the fSMORoleOwner attribute and click on it.
- Click the Edit button.
- CTRL+V to paste the correct setting.
- Click OK and then Apply.
- Repeat steps 2.1-2.9 to correct DC=ForestDNSZones,DC=Comapny,DC=Com.
Once the above steps were completed on the FSMO Role owner for Infrastructure I was able to properly demote the DC.
Monday, 27 January 2014
Windows Server 2012 R2 - Virtual hard disk sharing limitations
There is quite a lot written about how good the new "virtual harddisk sharing" feature is in Windows Server 2012 R2, and I agree that it is very good feature but there is not as much written about the limitations. When you enable the function it says "Some virtual machine and virtual hard disk features will be disabled when this setting is enabled". Already known limititations and already published on other blogs are:
There are also some limitations for virtual machines managed by VMM:
However you can change properties of a virtual machine managed by VMM with powershell.
- You cannot do host-level backups of the guest cluster. This is the same as it always was. You will have to install backup agents in the guest cluster nodes and back them up as if they were physical machines.
- You cannot perform a hot-resize of the shared VHDX. But you can hot-add more shared VHDX files to the clustered VMs.
- You cannot Storage Live Migrate the shared VHDX file. You can move the other VM files and perform normal Live Migration
There are also some limitations for virtual machines managed by VMM:
- You cannot create a checkpoint on a virtual machine that has shared virtual hard disks.
- You cannot change properties of a virtual machine with shared virtual hard disks.
However you can change properties of a virtual machine managed by VMM with powershell.
Monday, 20 January 2014
KMS server "STATUS_SUCCESS" error
The error message below has to be one of the most funnier in a long time ...
So did I succeed or not? It says "Success" but at the same time it's an error. Confusing is surely the least one can say ;)
So what was I doing then? Well, I was about to move / re-install a KMS server on Windows Server 2012 R2 and when I got to the last page and clicked "commit", I got the error message.
The cause of the error and also visible in the picture below is that the wizard does not enter the right "KMS TCP listening port" automatically. The port should be 1688 and if you enter this the wizard goes through.
So did I succeed or not? It says "Success" but at the same time it's an error. Confusing is surely the least one can say ;)
So what was I doing then? Well, I was about to move / re-install a KMS server on Windows Server 2012 R2 and when I got to the last page and clicked "commit", I got the error message.
The cause of the error and also visible in the picture below is that the wizard does not enter the right "KMS TCP listening port" automatically. The port should be 1688 and if you enter this the wizard goes through.
Wednesday, 15 January 2014
Empty "Add Storage Devices Wizard" in SCVMM 2012 R2
The other day, I would configure an SMI-S connection from SCVMM 2012 R2 to the customer's HP P2000 G3 MSA SAN. I could run through the "Add Storage Devices Wizard" and added the SAN without any problem but it could not find neither vDisk's or any LUN's. I verified the following:
• SMI-S was enabled in the SAN
• The Run As account had SMI-S access to the SAN
The solution: To connect using Telnet to the SAN and run the command "reset SMIS-configuration" for both controllers. Next, the wizard could find vDisk's and LUN's in the SAN.
• SMI-S was enabled in the SAN
• The Run As account had SMI-S access to the SAN
The solution: To connect using Telnet to the SAN and run the command "reset SMIS-configuration" for both controllers. Next, the wizard could find vDisk's and LUN's in the SAN.
Monday, 28 October 2013
Event ID 12339 and 12344: File Server Resource Manager failed to find claim list
Problem: You are running a Windows Server 2012 file server and you see the error messages in your logs every 15 minutes or so.
1) Event ID: 12339
File Server Resource Manager failed to find the claim list 'Global Resource Property List' in Active Directory (ADsPath: LDAP://dc1.domain.local/CN=Global Resource Property List,CN=Resource Property Lists,CN=Claims Configuration,CN=Services,CN=Configuration,DC=domain,DC=local). Please check that the claims list configured for this machine in Group Policy exists in Active Directory.
2) Event ID: 12344
File Server Resource Manager finished syncing claims from Active Directory and encountered errors during the sync (0x80072030, There is no such object on the server.) Please check previous event logs for details.
Solution: You can either upgrade the Active Directory schema to version 56 (Windows Server 2012) or safely ignore the error messages.
If you can update the schema of your domain. Follow these steps:
1)
log on to Windows Server 2012 as Administrator of your domain
2)
Copy from "support \adprep" in the media of Windows Server 2012 to "c:\"
3)
run this command
c:\adprep\adprep.exe /forestprep
1) Event ID: 12339
File Server Resource Manager failed to find the claim list 'Global Resource Property List' in Active Directory (ADsPath: LDAP://dc1.domain.local/CN=Global Resource Property List,CN=Resource Property Lists,CN=Claims Configuration,CN=Services,CN=Configuration,DC=domain,DC=local). Please check that the claims list configured for this machine in Group Policy exists in Active Directory.
2) Event ID: 12344
File Server Resource Manager finished syncing claims from Active Directory and encountered errors during the sync (0x80072030, There is no such object on the server.) Please check previous event logs for details.
Solution: You can either upgrade the Active Directory schema to version 56 (Windows Server 2012) or safely ignore the error messages.
If you can update the schema of your domain. Follow these steps:
1)
log on to Windows Server 2012 as Administrator of your domain
2)
Copy from "support \adprep" in the media of Windows Server 2012 to "c:\"
3)
run this command
c:\adprep\adprep.exe /forestprep
Monday, 21 October 2013
Event ID 12306 FSRM SMTP cannot send email
File Server Resource Manager Windows Server 2012 - SMTP cannot send email to Exchange Server 2007
Problem:
Event ID: 12306
Event Source: SRMSVC
Event Viewer Application logs:
A File Server Resource Manager Service email action could not be run.
Error-specific details:
Error: IFsrmEmailExternal::SendMail, 0x8004531c, Mailbox unavailable. The server response was: 5.7.1 Client does not have permissions to send as this sender.
Solution:
The problem is that your file server does not have the rights to authenticate against an Exchange Server using the computer account (domain\computername$ format) account of the server. This computer account must be granted send as permissions on the mailbox that you are trying to send as, or it will fail with this error. What you need to do is to run the command below on the mailbox you would like to send as, on your Exchange server.
Add-ADPermission -Identity "Mailbox Display Name" -user "Domain\ServerName$" -extendedrights "Send-as"
Add-ADPermission -Identity "Mailbox Display Name" -user "Domain\ServerName$" -extendedrights "Send-as"
Subscribe to:
Posts (Atom)
