Category: SharePoint

  • What are the PowerShell cmdlets that correspond to STSADM commands?

    Now that SharePoint 2010 is intertwined with PowerShell have you been looking for that cipher that tells you what PowerShell command you can run to do all of the STSADM commands that you know and love from SharePoint 2007 in SharePoint 2010?  I was too!  Here is the list that I have come up with (combined with our good friends at TechNet):

    PowerShell cmdlets STSADM Commands
    Enable-SPFeature Activatefeature
    Enable-SPInfoPathFormTemplate Activateformtemplate
    New-SPAlternateUrl Addalternatedomain
    Mount-SPContentDatabase Addcontentdb
     
    New-SPContentDatabase
    Install-SPDataConnectionFile Adddataconnectionfile
    New-SPExcelFileLocation Add-ecsfiletrustedlocation
    New-SPExcelDataProvider Add-ecssafedataprovider
    New-SPExcelDataConnectionLibrary Add-ecstrusteddataconnectionlibrary
    New-SPExcelUserDefinedFunction Add-ecsuserdefinedfunction
    Add-SPInfoPathUserAgent Addexemptuseragent
    New-SPManagedPath Addpath
    None Addpermissionpolicy
    Add-SPSolution Addsolution
    Install-SPWebTemplate Addtemplate
    New-SPUser Adduser
    Install-SPWebPartPack Addwppack
    New-SPAlternateUrl Addzoneurl
    Set-SPInfoPathWebServiceProxy Allowuserformwebserviceproxy
     
    Use the AllowForUserForms and Identity parameters.
    Set-SPInfoPathWebServiceProxy Allowwebserviceproxy
     
    Use the AllowWebServiceProxy and Identity parameters.
    Set-SPWebApplication Authentication
     
    Use the AuthenticationMethod or AuthenticationProvider parameters.
    Backup-SPConfigurationDatabase Backup
     
    Backup-SPFarm
     
    Backup-SPSite
    Get-SPBackupHistory Backuphistory
    New-SPCentralAdministration Createadminvs
    New-SPSite Createsite
    New-SPSite Use the ContentDatabase parameter. Createsiteinnewdb
     
    New-SPContentDatabase
    New-SPWeb Createweb
    Disable-SPFeature Deactivatefeature
    Disable-SPInfoPathFormTemplate Deactivateformtemplate
    Remove-SPAlternateUrl Deletealternatedomain
    Remove-SPConfigurationDatabase Deleteconfigdb
    Dismount-SPContentDatabase Deletecontentdb
    Remove-SPManagedPath Deletepath
    Remove-SPSite Deletesite
    Remove-SPSolution Deletesolution
    Uninstall-SPWebTemplate Deletetemplate
    Remove-SPUser Deleteuser
    Remove-SPWeb Deleteweb
    Uninstall-SPWebPartPack Deletewppack
    Remove-SPAlternateUrl Deletezoneurl
    Install-SPSolution Deploysolution
    Install-SPWebPartPack Deploywppack
    Get-SPSolution Displaysolution
    Set-SPContentDeploymentPath Editcontentdeploymentpath
    Get-SPAlternateURL Enumalternatedomains
    Get-SPContentDatabase Enumcontentdbs
    Get-SPDataConnectionFileDependent Enumdataconnectionfiledependants
    Get-SPDataConnectionFile Enumdataconnectionfiles
    Get-SPInfoPathUserAgent Enumexemptuseragents
    Get-SPInfoPathFormTemplate Enumformtemplates
    Get-SPServiceInstance Enumservices
    Get-SPSiteAdministration (To run this cmdlet, you must be a member of the Farm Administrators group.) Enumsites
     
    Get-SPSite (To run this cmdlet, you must be a local administrator on the computer where SharePoint 2010 Products is installed.)
    Get-SPSolution Enumsolutions
    Get-SPWeb Enumsubwebs
    Get-SPWebTemplate Enumtemplates
    Get-SPUser Enumusers
    Get-SPWebPartPack Enumwppacks
    Get-SPAlternateURL Enumzoneurls
    Start-SPAdminJob Execadmsvcjobs
    Export-SPWeb Export
    New-SPWebApplication Extendvs
    New-SPWebApplicationExtension Extendvsinwebfarm
    Get-SPWebApplication Getadminport
     
    Use the following syntax:
     
    Get-SPWebApplication -IncludeCentralAdministration | ? {$_.IsAdministrationWebApplication -eq $true}
     
    Get-SPDataConnectionFile Getdataconnectionfileproperty property
     
    Use the following syntax:
     
    Get-SPDataConnectionFile | where {$_.Name -eq “dataConFileName”} | format-list
     
    Get-SPInfoPathFormTemplate Getformtemplateproperty property
     
    Use the following syntax:
     
    Get-SPInfoPathFormTemplate | where {$_.DisplayName -eq “formTemplateName”} | format-list
     
    Get-SPFarmConfig Getproperty
     
    Get-SPTimerJob
     
    Disable-SPTimerJob
     
    Enable-SPTimerJob
     
    Set-SPTimerJob
     
    Start-SPTimerJob
    Get-SPSiteAdministration Getsitelock
    Get-SPAlternateURL Geturlzone
    Import-SPWeb Import
    Install-SPFeature Installfeature
    Get-SPLogLevel Listlogginglevels
    Get-SPEnterpriseSearchSecurityTrimmer Listregisteredsecuritytrimmers
    Move-SPSite Mergecontentdbs
    Move-SPUser Migrateuser
    For the Osearch parameters farmcontactemail, farmperformancelevel, farmserviceaccount, and farmservicepassword, use the Get-SPEnterpriseSearchService and Set-SPEnterpriseSearchService cmdlets. Osearch
     
    For the Osearch parameters start and stop, use the Start-SPEnterpriseSearchServiceInstance and Stop-SPEnterpriseSearchServiceInstance cmdlets, respectively.
     
    For the Osearch parameter defaultindexlocation, use the Get-SPEnterpriseSearchServiceInstance and Set-SPEnterpriseSearchServiceInstance cmdlets.
    Use the Get-SPEnterpriseSearchServiceApplication cmdlet to retrieve the specific Search service application, and then use DiacriticSensitive parameter from the Set-SPEnterpriseSearchServiceApplication cmdlet. Osearchdiacriticsensitive
    Start-SPServiceInstance Provisionservice
    Stop-SPInfoPathFormTemplate Quiesceformtemplate
    Update-SPInfoPathFormTemplate Reconvertallformtemplates
    New-SPEnterpriseSearchSecurityTrimmer Registersecuritytrimmer
    Uninstall-SPDataConnectionFile Removedataconnectionfile
    Remove-SPExcelFileLocation Remove-ecsfiletrustedlocation
    Remove-SPExcelDataProvider Remove-ecssafedataprovider
    Remove-SPExcelDataConnectionLibrary Remove-ecstrusteddataconnectionlibrary
    Remove-SPExcelFileLocation Remove-ecsuserdefinedfunction
    Remove-SPInfoPathUserAgent Removeexemptuseragent
    Uninstall-SPInfoPathFormTemplate Removeformtemplate
    Rename-SPServer Renameserver
    Set-SPSite Renamesite
     
    Use the Url parameter.
    Set-SPWeb Renameweb
     
    Use the RelativeUrl parameter.
    Restore-SPFarm Restore
     
    Restore-SPSite
    Uninstall-SPSolution Retractsolution
    Start-SPContentDeploymentJob Runcontentdeploymentjob
    Install-SPFeature Scanforfeatures
     
    Use the Scanforfeatures parameter.
    Set-SPCentralAdministration Setadminport
    Connect-SPConfigurationDatabase Setconfigdb
    Set-SPContentDeploymentJob Setcontentdeploymentjobschedule
    Set-SPDataConnectionFile Setdataconnectionfileproperty
    Set-SPExcelFileLocation Set-ecsexternaldata
    Set-SPExcelServiceApplication Set-ecsloadbalancing
     
    Use the LoadBalancingScheme parameter.
    Set-SPExcelServiceApplication Set-ecsmemoryutilization
     
    Use the MemoryCacheThreshold and PrivateBytesMax parameters.
    Set-SPExcelServiceApplication Set-ecssecurity
     
    Use the CrossDomainAccessAllowed, EncryptedUserConnectionRequired, and FileAccessMethod parameters.
    Set-SPExcelServiceApplication Set-ecssessionmanagement
     
    Use the SessionsPerUserMax and SiteCollectionAnonymousSessionsMax parameters.
    Set-SPExcelServiceApplication Set-ecsworkbookcache
     
    Use the Workbookcache and WorkbookCacheSizeMax parameters.
    Set-SPInfoPathFormTemplate Setformtemplateproperty
    Set-SPLogLevel Setlogginglevel
    Set-SPFarmConfig Setproperty
     
    Get-SPTimerJob
     
    Disable-SPTimerJob
     
    Enable-SPTimerJob
     
    Set-SPTimerJob
     
    Start-SPTimerJob
    Set-SPSiteAdministration Setsitelock
     
    Use the LockState parameter.
    Get-SPSiteSubscription Setsiteuseraccountdirectorypath
     
    New-SPSiteSubscription
     
    Remove-SPSiteSubscription
    Set-SPWorkflowConfig Setworkflowconfig
    Set-SPSiteAdministration Siteowner
    Install-SPSolution Syncsolution
     
    Use the Synchronize parameter.
    Remove-SPWebApplication Unextendvs
    Uninstall-SPFeature Uninstallfeature
    Start-SPInfoPathFormTemplate Unquiesceformtemplate
    Remove-SPEnterpriseSearchSecurityTrimmer Unregistersecuritytrimmer
    Set-SPManagedAccount Updateaccountpassword
    Install-SPInfoPathFormTemplate Upgradeformtemplate
    Update-SPSolution Upgradesolution
    Install-SPInfoPathFormTemplate Uploadformtemplate
    Get-SPUser Userrole
     
    Move-SPUser
     
    New-SPUser
     
    Remove-SPUser
     
    Set-SPUser
    Test-SPInfoPathFormTemplate Verifyformtemplate
       
    Not made into PowerShell cmdlets  
    Binddrservice  
    Blockedfilelist  
    Canceldeployment  
    Changepermissionpolicy  
    Copyappbincontent  
    Creategroup  
    Databaserepair  
    Deleteadminvs  
    Deletegroup  
    Deletepermissionpolicy  
    Disablessc  
    Email  
    Enablessc  
    Enumdeployments  
    Enumgroups  
    Enumroles  
    Forcedeletelist  
    Getosearchsetting  
    Getsiteuseraccountdirectorypath  
    Listqueryprocessoroptions  
    Localupgradestatus  
    Managepermissionpolicylevel  
    Quiescefarm  
    Quiescefarmstatus  
    Refreshdms  
    Refreshsitedms  
    Registerwsswriter  
    Removedrservice  
    Removesolutiondeploymentlock  
    Retractwppack  
    Setapppassword  
    Setosearchsetting  
    Setqueryprocessoroptions  
    Unquiescefarm  
    Unregisterwsswriter  
    Updatealerttemplates  
    Updatefarmcredentials  
    Upgrade  
    Upgradetargetwebapplication
     

    As I was more than halfway through putting my list together for this blog I ran across the TechNet article where I sourced the links and some of the content for this posting: http://technet.microsoft.com/en-us/library/ff621084.aspx

    Just 3 articles away I ran across the Stsadm to Windows PowerShell mapping (SharePoint Foundation 2010) article which calls out the subset of commands that are available in SharePoint Foundation.

  • SharePoint 2010 and the Site Directory

    My colleague and friend, Derek Martin of Slalom Consulting, just posted about a bug that we found with SharePoint 2010 and the Site Directory. 

    The short story is when you enable the Site Directory and you are using SharePoint 2010 in Claims mode for your web apps (including the site that houses the site directory) Central Administration is in Classic mode (the default and recommended way) and actions that call a web service from CA that touch back to the Site Directory will fail with errors that do not give you any real clues as to what is going on.

    The bug has been logged with Microsoft and we are awaiting the Product Team’s acceptance the they will fix this with a patch, service pack or QFE.  More when we hear it.

    For the full details please check out Derek’s blog.

  • SharePoint 2010 Farm Service Account passwords expired?!?!?!?

    Scenario:

    Managed service accounts passwords expired.  Access to part of Central Administration are no longer accessible.  Sites are starting to go down because app pool passwords are managed accounts and have expired.

    Soapbox moment:

    Firstly, there is NO real excuse for this in SharePoint 2010 because the ability to have this done automagically for you is BUILT-IN, so either your farm admin is so over taxed (usually the case) or incompetent (the two aren’t mutually exclusive). 
    I take the liberty to say all of this as someone who has had this happen to them, otherwise I wouldn’t be able to write about it, right?

    Resolution:

    To start, you aren’t going to be able to do anything with SharePoint until you can get the Timer Job Service running again because everything is driven by timer jobs. 
    Using a credential that has full admin rights to the box and is a Farm admin, change the account the Timer Job Service runs as and start the service.  This must be done on all servers in the farm. 
    Don’t fret, the next things you are going to do is fix this back to the way it should be but you can’t do the next steps without the timer job service running, so just play along.

    Go to http://www.yourserver.com/_admin/ManagedAccounts.aspx and edit your farm service account and tell it to change the password now.

    Go to http://www.yourserver.com/_admin/FarmCredentialManagement.aspx and select Farm Account.  You will see your registered service account (the one that you just changed the password for) and click ok.  This will go reset your Timer Job Service account to the registered account which now is active and working.
    Next, create a text file called on your server which will be a list, one account per line, of service accounts that you are going to have auto-updated.

    Then using the SharePoint 2010 Management Shell interface change the passwords and set to auto change run using this variable script:

    foreach ($account in Get-Content driveletter:filename.txt)
    {
    Set-SPManagedAccount -Identity $account -AutoGeneratePassword -PreExpireDays n#days -Schedule “monthly between n#dayofthemonthvalue hh:mm:ss and n#dayofthemonthvalue hh:mm:ss” -confirm:$false
    }

    The script that I actually used, without the variables looks like this:

    foreach ($account in Get-Content c:managedaccounts.txt)
    {
    Set-SPManagedAccount -Identity $account -AutoGeneratePassword -PreExpireDays 30 -Schedule “monthly between 7 02:00:00 and 7 03:00:00” -confirm:$false
    }

    Once this command has completed successfully you will see that your last password change just happened and that your next password change is scheduled.  Make sure that if your next scheduled password change isn’t in conflict with a password change minimum group policy that won’t allow passwords to be changed before a minimum number of days or you will end up with some errors in your ULS Logs and some misfired password change attempts.

    Lastly, go to http://www.yourserver.com/_admin/FarmCredentialManagement.aspx and walk through all of the farm credentials and let the accounts get synced up.  This should re-spin up the app pools and get your users back into the site, but if not, do an IISRESET and things should be back online.

    Shout outs

    Huge thanks to my partners in crime on this one, Derek Martin and Trent Foley of Slalom Consulting, for helping with the out of the gate perfect PowerShell scripts that are referenced above.

    While I was busy figuring out how to break back in to Central Admin, they figured out the proper script to reset the passwords and set the auto change programmatically.  This script can be used in advance of this type of shenaniganal activity to ensure that while you are building your farm you get this set right the first time and not have to do it manually (which is often the excuse when you are using 30+ managed accounts in a farm).

  • Unable to access VMware Workstation Guest after Host Machine crash

    Scenario:

    While doing SharePoint 2010 development is now able to be done from within a Windows 7 64bit system and even inside of a Hyper-V VM, many of us in the wide world of computing are still using VMware Workstation, Fusion, Player, or even the old VMware GSX Server to run local development environments.  This post deals with how to get back into a VM that seems horribly locked after your workstation hosting your VM crashes hard.

    Symptom:

    System crashed while a VMware Workstation Guest was running. The VM now reports that it is in use by the current host. Taking ownership of the VM is not possible.  All hope is starting to fade…

    Solution:

    Go to the VM location and delete the .lck files and folders. This will unlock the VM Guest and allow you to boot in.  VMware treats this like a hard server reset, and offers safe mode booting at that point. If the system is able to recover cleanly, it gets you back to operational.

    Caveat:

    Just like anytime you hard reset a server you must be prepared to deal with the consequences.  Data loss, data corruption, and complete system failure is possible as a result of such action.

    However if you are left with the alternative of complete system rebuild already, it might be worth a shot.  Just don’t blame me if your system is toasty afterwards.

  • Windows with Claims User gets access denied to a site they had access to earlier in the day

    Scenario:

    Small Farm 3 tiered topology using Windows with Claims implementation aggregating AD with a custom LDAP database to create the claims roles.

    Symptom:

    Users of a SharePoint 2010 site get access denied to a site they could access earlier in the day.  As the day goes on, the number of users effected increases.  Eventually only users with full control policies can access the farm.

    ULS Log error:

    An exception occurred in Custom Roles claim provider when calling SPClaimProvider.FillResolve(): The underlying provider failed on Open..

    Root Cause:

    The 10 hour default session timeout for the user’s claim has been exceeded and the database housing the Role Data is no longer accessible.   In this case it was due to an expired SQL account password. Changing the password and updating the connection string or just unchecking the password expiry flag in the SQL account will resolve the issue.

    Notes from the field:

    There was one easy way to prevent this type of user facing outage.  Don’t allow SQL accounts to expire.  EVER.  They are horrible to diagnose because access to the SQL Server is still operational and access using AD authentication is going to throw you off the scent because the main farm access is still available.

    Read Scot Hillier’s blog on “Authorization Failures with Claims-Based Authentication in SharePoint 2010”.  Really useful stuff in there about how claims works and extending the timeouts.