Showing posts with label troubleshooting. Show all posts
Showing posts with label troubleshooting. Show all posts

Tuesday, July 28, 2015

Set-ExecutionPolicy: Can not set execution policy

Hello their maledetos nerds !!! ehehehehe
When trying to run a certain PS script remotely on an Exchange server, I came across the following error message:
. \ UpdateIndexAllMailboxDatabases.ps1: File C: \ Temp \ SCRIPTS \ EXCHANGE \UpdateIndexAllMailboxDatabases.ps1 can not be loaded. The file C: \ Temp \ SCRIPTS \ EXCHANGE \UpdateIndexAllMailboxDatabases.ps1 is not digitally signed. The script will not execute on the system. Please see "get-help about_signing" for more details ..
At line: 1 char: 37
... After a Get-ExecutionPolicy had the RemoteSigned return .There think twice !!! Set-ExecutionPolicy Unrestricted and was returned the following message:
Execution Policy Change
The execution policy helps protect you from scripts That You do not trust. Changing the execution policy might expose you to the security risks described in the help topic at about_Execution_Policies
http://go.microsoft.com/fwlink/?LinkID=135170 . Do you want to change the execution policy?
[Y] Yes [N] No [S] Suspend Help (default is "Y") [?] Y
Set-ExecutionPolicy: Windows PowerShell execution policy successfully updated your, but the setting is overridden by
the policy defined at a more specific scope. Due to the override, your shell will retain its current effective
execution of policy RemoteSigned. Type "Get-ExecutionPolicy -List" to view your execution policy settings.For more
information please see "Get-Help Set-ExecutionPolicy".
At line: 1 char: 1
+ Set-ExecutionPolicy Unrestricted
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo: PermissionDenied: (:) [Set-ExecutionPolicy] SecurityException
+ FullyQualifiedErrorId: ExecutionPolicyOverride, Microsoft.PowerShell.Commands.SetExecutionPolicyCommand
As recommended in the message, I ran the cmdlet to list the policy of execution policy by scope
Get-ExecutionPolicy -List
Scope ExecutionPolicy
- -----
MachinePolicy RemoteSigned
UserPolicy Undefined
Process Undefined
CurrentUser Undefined
LocalMachine RemoteSigned
... Immediately I performed the following Set-ExecutionPolicy -Scope MachinePolicy -executionpolicy Bypass command for the policy to be released ... ops:
Set-ExecutionPolicy: Can not set execution policy. Execution policies at the MachinePolicy or UserPolicy scopes must beset through Group Policy.
To correct this error, we are forced to make this modification directly in season record:
HKLM: \ Software \ Policies \ Microsoft \ Windows \ PowerShell and change the value ExecutionPolicy   toBypass.
By rerunning the command to list the scope for policy, we realize that now really the setting was uncommitted !!
Get-ExecutionPolicy -List
Scope ExecutionPolicy
- -----
MachinePolicy Bypass
UserPolicy Undefined
Process Undefined
CurrentUser Undefined
LocalMachine RemoteSigned
Then I could run my script and they all lived happily ever after!

Wednesday, February 1, 2012

Hyper-V error "User HAD not accepted the EULA"

These days I came across an error in Hyper-V installed on a server Windows Server 2008.A error "User not HAD accepted the EULA" appears on the console's initial Hyper-V and it was not possible to create virtual machines, errors MMC, compatibility of processors, etc ....

Solution:

Apply KB http://support.microsoft.com/?kbid=950050

Last Send Message

Follow link for the script that lists the date of the last message sent by the recipients! Very useful especially to find inactive objects.

Just run in PS, select your Hub-Transport's range and date.

http://msgdev.mvps.org/exdevblog/showlastsentrecv1.zip

Virtual Machine Manager error 19999

I had one problem that presented for the SCVMM error opening the console gerenciamento.Como is not enough, the service "Virtual Machine Manager" entered the state of restart (because of the recovery actions in the service properties).

In Event Viewer, I found the following errors:

ID 2604

Database operation failed.
Ensures that the SQL Server is running and configured Correctly, and try the operation again.

ID 19999

Virtual Machine Manager (vmmservice: 8300) has encountered an error and needed to exit the process. Windows generated an error report with the Following Parameters:
Event: VMM20
P1 (appName): vmmservice
P2 (appVersion): 2.0.4271.0
P3 (assemblyName): Utils
P4 (assemblyVer): 2.0.4276.0
P5 (methodName): MVDSqlRetryCommand.ExecuteNonQuery
P6 (ExceptionType): MVDB.NonFatalDbException
P7 (callstackHash): 3e7

The problem in my case it was caused by authentication problems was that the database on a SQL Server SCVMM separado.Os services were running with the LOCAL SYSTEM account ... is necessary in this case, creating a service account, apply rights to that account and specify the database to perform the same services.

Remote Connectivity Analyzer

This URL is in the Toolbox Exchange Server 2010. ...

A good site to have to Favorites:

https://www.testexchangeconnectivity.com

We are offering Z1br recovery service bases...

We (Z1br) offering recovery service corrupted Exchange databases. ... When the ESEUTIL and isinteg does not work, it's always good to have a letter (Z1br) up his sleeve! Contact http://z1br.com.br

ExchangeStoreDB ID 123

Personal

Follow the link to problem solving in catalog corrupted members of DAG in Exchange Server 2010. The error occurs at the time of activation of the database in another member of the DAG.

http://technet.microsoft.com/en-us/library/ee633475.aspx

I hope it's useful!

Exchange Network Port Reference

Follow the link for all ports used by Exchange 2007 and 2010:

http://technet.microsoft.com/en-us/library/bb331973.aspx

Default permissions of the Sysvol folder

They follow a standard NTFS permissions of the SYSVOL folder:

% SystemRoot% \ Windows \ Sysvol

  • Clear the Allow inheritable permissions from parent to propagate to this object check box
  • Administrators: Full Control
  • Authenticated Users: Read, Read & Execute, List Folder Contents and
  • Creator Owner: Nothing selected
  • Server Operators: Read, Read & Execute, List Folder Contents and
  • System: Full Control

% SystemRoot% \ Windows \ Sysvol \ Sysvol

  • Clear the Allow inheritable permissions from parent to propagate to this object check box

% SystemRoot% \ Winnt \ Sysvol \ Sysvol \ domain

  • Clear the Allow inheritable permissions from parent to propagate to this object check box

% SystemRoot% \ Winnt \ Sysvol \ Sysvol \ domain \ Policies

  • Clear the Allow inheritable permissions from parent to propagate to this object check box
  • Administrators: Full Control
  • Authenticated Users: Read, Read & Execute, List Folder Contents and
  • Creator Owner: Nothing selected
  • Group Policy Creator Owners: Read, Read & Execute, List Folder Contents, Modify, and Write
  • Server Operators: Read, Read & Execute, List Folder Contents and
  • System: Full Control

For each file or folder that is located in the% SystemRoot% \ Winnt \ Sysvol \ Sysvol \ domain \ Policies

  • Check the Allow inheritable permissions from parent to propagate to this object check box

Sysvol share permissions:

  • Administrators: Full Control
  • Authenticated Users: Full Control
  • Everyone: Read

Reference: http://truetechsolutions.supersized.org/archives/8-Default-Permissions-for-Sysvol.html

MSExchange ADAccess 2114

In a recent project, I experienced a problem (at least by the messages on the Installation Wizard on eSales and Viewer - see image below).. This problem occurred (at least in my case) the installation of the Hub-Transport. Below is the message displayed EventViewer ...

MSEXCHANGEADTOPOLOGYSERVICE.EXE Process (PID = 1256). Topology discovery failed, error 0x80040a02 (DSC_E_NO_SUITABLE_CDC). Look up the Lightweight Directory Access Protocol (LDAP) error code specified in the event description. To this, use Microsoft Knowledge Base article 218185, "Microsoft LDAP Error Codes." Use the information in That article to learn more about the cause and resolution to this error. Use the Ping or PathPing command-line tools to test network connectivity to local domain controllers.

... Such an error occurs in Exchange Server 2007.2010. The resolution is put to the same Exchange server account in the Domain Admin group. After inclusion of the server group, restart the server and reinstall Exchange (if the problem has been presented in time of installation.).

Also spent a similar problem with Exchange Server 2003 ... in this case, the situation was regarding the deletion of an account of the Exchange server object AD.A restoration was carried out via ADRESTORE and even after inclusion of the restored object in the security groups required for Exchange Server Exchange services failed to initialize ....

Appears in the Event Viewer event ID 2114 MSExchange DSAccess.

In this case, I performed the following procedures:

  1. After the deletion of the object, restore the same with ADRESTORE;
  2. Add in the server security groups required (in some cases, these steps alone are enough to return to normal services);
  3. Remove the network cable from the Exchange server;
  4. Place the Exchange server in Workgroup and restart the server, without attaching the network cable;
  5. In AD, reset the account of the Exchange server;
  6. Plug the cable into the Exchange server and put it back in the field;
  7. Restart the server;

After these procedures, the services back to work!

Another very common procedure for troubleshooting permissions on an Exchange organization, and runs the setup / domainprep command again in DC.

Hope that helps!

Resolve NetBIOS names to VPN

After questioning several times regarding this topic of NetBIOS name resolution when connected to a VPN Server and ISA or TMG, I decided to stop being bum and post the settings needed to solve this problema.Na fact, it is a simple single configuration!

The nature of the problem is as follows:

When connected to the VPN, you can just drop the equipment on the internal network via the IP address and the FQDN of the machine (eg server.domain.local) is not possible to resolve NetBIOS names of the form (eg server). For this to happen, we must make the following configuration on the VPN client connection:

In the Connection Properties, click the tab and then the NETWORKING PROPERTIES TCP/IPv4 protocol. ... Click on the ADVANCED tab and DNS. Check the option DNS suffix for this connection, the DNS domain suffix, as in the image below!

Capture

Libraries and removes the Control Panel icon from the desktop

Personal

This tip can be useful when we set a very restrictive policy in Windows 7 ... .. when we forced the classic theme, the system includes a shortcut on the desktop shell of theLibraries folder and Control Panel. Via GPO until you remove the shortcuts, but it is also remove any link placed on the desktop, even if it is created via logon script ...

The method I found to solve this hurdle, it was deleting the following registry keys:

Remove icon library:

Remove icon in Control Panel:

For those who need to do a VBS for this ... ... follows:

Const HKEY_LOCAL_MACHINE = & H80000002
strComputer = "."
on error resume next
Set oReg = GetObject ("winmgmts: {ImpersonationLevel = impersonate}! \ \" & _
strComputer & "\ root \ default: StdRegProv")
strKeyPath =
strKeyPath =
strKeyPath =
oReg.DeleteKey HKEY_LOCAL_MACHINE, strKeyPath

I hope it's useful!

Description of the status codes of Microsoft Internet Information Services (IIS) 5. 0 and 6.0

Follow the link for error codes displayed by IIS:

http://support.microsoft.com/?id=318380

Monday, March 28, 2011

0 × 00000024 (Kaspersky 0x001904AA ...

I had an experience at least annoying with Windows Server 2008 and Kaspersky antivirus, the research I did, the same problem occurs with Windows Vista.

The symptom is continuous reboot server.The server boots into SAFE MODE normally, but in normal mode remains at the logon screen for some time and the system reboots after showing a blue screen.

The error code shown on the blue screen 0 × 00000024 (0x001904AA ...(the rest of the code may vary).

The solution to the problem was removing the Kaspersky antivirus from the server, using the procedures listed in the following sitehttp://hubpages.com/hub/How-to-uninstall-or-remove-Kaspersky-totally

Another method I found but have not tested, is to rename or delete the file% windir% \ system32 \ drivers \ klif.sys in SAFE MODE and reboot the server.

I hope this is helpful!

Task Sequence Error 0 × 80070032

Guys,

Making tests deploy OSD in SCCM 2007 R2 SP2, I came across the error 0 × 80070032 Task Sequence to run the image capture.

The problem is related (at least in my case) not on the machine running SYSPREP reference.

Tuesday, December 28, 2010

List of Log Files in Configuration Manager 2007

 

Here's a link for the list of logs Configuration Manager 2007, both for the server and its functions as related to clients.

http://technet.microsoft.com/en-us/library/bb892800.aspx

Error when upgrading, installing and uninstalling or SCCM 2007

 

In some cases you may find the following records (below) inConfigmgrSetup.log when installing, upgrading and uninstalling or SCCM.

<11-22-2010 11:40:41> failed with 1300 AdjustTokenPrivileges
<11-22-2010 11:40:41> Could not verify an open MMC instance due to the error.
<11-22-2010 11:40:41> Exiting THREAD_Deinstall.

... Such a problem occurs due to lack of administrative law of the user running the setup, more specifically the right to "Debug programs" on the server.

To assign the right to run secpol.msc and navigate to Local Policies \ User Rights Assignment on the option DEBUG PROGRAMS add the user running the setup.

I hope this is helpful!

Saturday, November 20, 2010

Techniques for troubleshooting

 

During all these years, which I am directly involved with environments and technology professionals, either within a classroom or in day to day work I realize some confusion on the part of analysts infrastructure for troubleshooting problems. don't believe a master in the matter concerned, despite being one of the bases of my work as a consultant; but realize that this deficiency is related to lack of vision on troubleshooting flow …. i.e. the analyst does not know where to begin and for this reason often ignores critical steps in the process of troubleshooting, logging procedures aimlessly and without needs, often causing other problems beyond those already mapped.

The resolution of problems in production environments is critical for the downtime of the service and or resources (such as applications, asset management, users, etc.), directly impacting on business. for this reason, the analyst should solve a problem more quickly and effectively, preventing a considerable impact on the productivity of users ' activities. Nowadays many companies invest in monitoring products, methodologies, processes, specialized training of professionals, as well as other various devices so that this impact is reduced and or non-existent.

A vital concept for troubleshooting is the concept of incident and problem, so commonly ITIL discussed and other methodologies. this concept consists primarily define incident as an isolated fact, something not widespread and or recurring (ex: A user has opened a call for a configuration problem on your Outlook) and problem relates to something widespread and or applicant (ex: Multiple users open called for the same problem in their Outlook's or a user always the same error reporting). So let's get straight to the point! …

1. Investigating the occurrence. is paramount raising information concerning problem, classic questions as: what time the problem occurred? what has changed on your computer and or the environment just before this period that could have caused the error (an installation and software update, or change any configuration of system or network, etc.)? … Anyway, gather as much information as possible; When we are "by interrogating" a user, it is essential to communicate with the same with terms that are understood by him, because technical terms will only confuse the user stopping us from getting the information you need.

2. Checking the breadth of the error. at this point we can verify that this is an incident or a problem, if customer is an error, network or server must check if the error occurs with a single user, if it occurs with a set of users (if it occurs with more than one user, check out what these resources has in common … is an application, VLAN group or switches, OR in ad, etc) or is referring to an application or service specific network So we can evaluate. on that point and how we will act to resolve the error.

3. technical survey of the error. In this step, we will search the messages and characteristics of the error in question (error POPUPS, log's application concerned, system logs, etc.), as well as the impact generated. This is important for "away scot-free" this information with information collected previously and in conjunction with data spanning problem. the product of this information is essential for a correct search incident resolution and or problem (e.g. Outlook user is presenting the XYZ error but this error may be due to a setting Outlook and failure or server in the Organization, etc…). We currently use diagnostic tools provided by the manufacturer and or third parties.

4. application of the solution. Good, we come to a crucial point for resolving a problem, the application of the solution before the resolution itself a problem and or incident, we verify some important points:

a. what impact the implementation of the solution. It is essential the mapping of the impact on the application of possible solutions to the problem or incident; some of them may entail on reboot a server backup, restore, rewriting some parameter of an application and or network service, change the permissions of a user, etc. the mapping is important for us to organise for when we will be able to apply the solution (ex: a solution that involves a boot server in production may result in their implementation outside of business hours). we must expect to correct an error, when the correction process impact at the moment is greater than the impact of the error.

b. which solution to implement. Depending on the issue in question, we can count on more than one solution (some of them definitive and other palliative). But there is always the best solution to be applied; Depending on your situation, we are forced to run a stopgap solution or simply a solution that is not the best. This must be assessed in light of the impact of each solution X urgency (SLA) for the resolution of the problem. However, if it is not possible to apply the best solution at the time, you should schedule the application to which a workaround does not become a definitive solution.

c. how to apply the solution. The process of implementing a solution is very important. implementation of the solution must be clean and without errors; the most suitable is searching for a step-by-step (preferably of manufacturer of the active application or solution with error) without errors at the time of the execution process. it would be interesting depending on the criticality of the environment, test the fix in an environment of approval before applying the same production. shouldn't be generalists in order to simplify the application (e.g. the documentation says that to solve a problem the user needs a specific permission on A FILE and to "simplify" you just assigning permission to ENTIRE FOLDER), with this we can significantly increase the impact caused by application of the fix, and cause problems related to security settings, best practices, etc.

5. verification of the results. After applying the fix, we should check the following points:

a. If symptoms of the problem or incident disappeared. We can verify the disappearance of the symptoms of the error by checking event logs (application, system, etc.), no incidence of error popups, resource utilization that before not worked, etc.

b. monitoring solution. Verify that there is a recurrence of error after applying the solution, check the performance of the application and solution, or service that was showing errors and feedback from users and analysts involved.

Described above some basic points that should be followed to resolve problems and incidents to be in our work and clients or course each situation can present quite particular and that solving contains several strands as disaster recovery, contingency, etc… but the development of these activities must be performed in an organized way, safe and aligned with a good technical background about the technologies involved.