Quantcast
Channel: File Services and Storage forum
Viewing all 13580 articles
Browse latest View live

Error code: The server is too busy to handle sync requests. (‪0x80c8003e)

$
0
0

Work Folder issue: MS Enterprise clients environment using AD FS and Work Folder synchronization.

Client would not able to access the Work Folders files occasionally. Sync the Work Folders would be end with error: 

Error code:

Sync status: Sync stopped. A problem occurred <o:p></o:p>

 Authentication method: ADFS <o:p></o:p>

 Error code: The server is too busy to handle sync requests. (‪0x80c8003e)<o:p></o:p>

<o:p></o:p>

Tapped to sync but no avail no server response. Manage credentials password need is working. 

Any advice would be appreciated.

Thanks,


DAC Device Claims

$
0
0

Hello,

I've been having some trouble getting DAC device claims to work, and I was wondering whether anyone could point me in the right direction. 

The environment is configured as follows:

Domain Controllers (hostnames dc01, dc02, dc03)

  • Server 2016
  • Domain and Forest functional level = 2008 R2
  • KDC support for claims, compound authentication and Kerberos armoring set to "Enabled"/"Supported" via group policy
  • User based claim for attribute "l" enabled for users
  • Device based claim for attribute "location" enabled for computers

File server (hostname server01)

  • Server 2016
  • Shared directory (test_share) configured.
  • Share level permissions configured to allow Everyone full control.
  • File system permissions configured to allow user ab01 unconditional read/execute access
  • An additional ACL is configured to allow user ab01 full control conditional on either:
    1. user.l = "secure" or 
    2. device.location = "secure"
  • Conditional permissions are applied directly via security descriptor (i.e. no central access rules / policies are involved)
  • Kerberos client support for claims, compound authentication and Kerberos armoring set to "Enabled" via group policy
  • msDS-SupportedEncryptionTypes = 0x1c

Client machine (hostname pc01)

  • Windows 10
  • Attribute "location" set to "secure"
  • Kerberos client support for claims, compound authentication and Kerberos armoring set to "Enabled" via local policy
  • Support for compound authentication set to "Enabled"/"Always" via local policy.
  • msDS-SupportedEncryptionTypes = 0x1c

User account (ab01)

  • Account attribute "l" set to "secure"
  • Account supports Kerberos AES 128 and 256 bit encyrption
  • Use Kerberos DES encryption types for this account is unchecked.

Similar to a previous question along these lines (https://social.technet.microsoft.com/Forums/lync/en-US/1522933d-d004-430b-9251-6f7bcc6891f8/dac-device-claims-not-being-generatedpassed?forum=winserverDS), user based claims seem to work well: When the conditional permission based on a user claim is configured, then user ab01 has full control of test_share.

The effective permissions (evaluated on the file server) also appear to give the desired results: When conditional permissions are configured to use a device based claim (ab01 has full control when device.location="secure"), user ab01 is shown to have full control from pc01, but not from machines where device.location is undefined, or doesn't equal "secure". In real life however, user ab01 only has read/execute permissions when accessing test_share from pc01. Any attempt to create or modify files/folders generates a permissions error.

Various events with id 4626 show up at regular intervals in the logs on the file server and DCs: 

Subject:

Security ID: NULL SID

Account Name: -

Account Domain: -

Logon ID: 0x0

Logon Type: 3

New Logon:

Security ID: Domain01\ab01

Account Name: ab01

Account Domain: Domain01

Logon ID: 0x11111111

Event in sequence: 1 of 1

User Claims: ad://ext/l:1111111111111111 <String> : "secure"

Device Claims: -

Subject:

Security ID: NULL SID

Account Name: -

Account Domain: -

Logon ID: 0x0

Logon Type: 3

New Logon:

Security ID: Domain01\PC01$

Account Name: PC01$

Account Domain: Domain01

Logon ID: 0x111111

Event in sequence: 1 of 1

User Claims: ad://ext/location:1111111111111111 <String> : "secure"

Device Claims: -

Klist shows the following on PC01:

#4>  Client: ab01 @ Domain01

        Server: cifs/server01 @ Domain01

        KerbTicket Encryption Type: AES-256-CTS-HMAC-SHA1-96

        Ticket Flags 0x40a10000 -> forwardable renewable pre_authent name_canonicalize

        Start Time: 1/2/2020 5:15:40 (local)

        End Time:   1/2/2020 14:56:47 (local)

        Renew Time: 1/8/2020 19:11:48 (local)

        Session Key Type: AES-256-CTS-HMAC-SHA1-96

        Cache Flags: 0x40 -> FAST

        Kdc Called: dc03.domain01

Any advice on getting device claims working (or on how I can find more information about why they're not…) would be much appreciated.

Many thanks in advance


Migrating Redirected Folders to new server with remote users

$
0
0

I am in the process of migrating a customer from a small business server 2011 to server 2019. I have moved everything but the redirected folders and I am trying to figure out the best way to do this for my scenario.

After digging around online, I see people recommending to just check the option to move back to the local machine and move the data to the new location. There is around 30 users with 10 of them being remote and accessing the network through a vpn. Can I just move the data to the new server and manually point the remote users to the new redirected folder location? Will that cause sync issues or mess up the group policy? If i edit the group policy and have multiple people logging in at once, I would think the network would slow down dramatically and take forever to finish along with people killing the connection while its moving data.

Work Folders can't encrypt files on Windows 10 1903

$
0
0

Hi,

problems with WF encryption was discussed here many times before, but I think that now it's related to Windows 10 1903, because Windows 10 1809 is working fine.

Error message is still the same:

Sync failed. Work Folders path: C:\Users\MYUSER\Work Folders; Error: (0x80c80314) The Work Folders path has to be encrypted. You might have an application holding the Work Folders folder open or the folder might be compressed. Close File Explorer and any open files or apps, and check the folder's Advanced properties to ensure that the folder is not compressed. EventID 2100

I had tried Windows 10 1903 domain joined / not domain joined, followed tips on https://techcommunity.microsoft.com/t5/Storage-at-Microsoft/Troubleshooting-Work-Folders-on-Windows-client/ba-p/425627 but WF encryption is still failing.

Has anyone working WF on Windows 10 1903 with encryption enabled?

Best regards,

Jiri

Dealing with emails

$
0
0

Hello everyone. Hope you are doing well. See below for my question. Thank you in advance for your time and reply.

Before I get to my questions let me note one thing. I'm assuming that this forum 'File Services and Storage' is referring to the server role on windows server. It didn't seem like there was a better choice for my question so I placed it here but... My question is more regarding just file services and storage and messing around with files and directories and etc on the server while actually sitting there and logged in on the windows server computer. I'm not talking/asking about the file services and storage role nor about serving files/directories to client computers on the active directory network.

I was wondering if someone could point me in the direction of where to look or how to figure out how to write a simple script that copies emails from the email host onto some directory on the server? 

Seems simple enough but the task seems a little easier said than done for me.

I guess I'm having some problems with some gaps in knowledge and am struggling implementing what I am trying to do with regards to 'dealing with emails'.

One thing is, what exactly is an email? Not so much that, I get that it's just digits of information traveling across a network of nodes as a set of packets or whatever. But, how should I think about it in terms of the task described thus far? As just a simple text file that may or may not include lines of code, html/other? As an 'email' file (outlook saves emails to drive as *.msg)? 

Another thing is, perhaps following from the first, is what file type does the email host generally serve the emails so your email client of choice can read?

Another thing is, kinda related kinda unrelated, is windows server only saves 1 copy of each file on disk, right? If I have a single file of the same exact file copied into 100 directories, windows server only saves 1 copy of the file, right? I feel like I knew the answer to this at one point but can't remember.

So, I think that's it for the questions. Now about the implementation. As of now, I'm planning on handling my archiving/storage of emails by having a simple script running somewhere on the windows server computer that simply: (1) makes a folder with the name of each respective inbox; (2) Reads the email hosting server and copies/pastes every new email that hits its respective inbox into its respective step 1 folder stored on the server; and (3) reads through the email looking for keywords and copies appropriate emails into appropriate project folders (also stored on the server) based on the keywords.

That's about it. Some final things to note:

I did do a lot of searching trying to get this figured out before posting this. When trying to do individual searches on all these individual things, I feel like I'm wasting a lot of time reading through basic stuff that I either know already or a list of basic things that I have to choose from and I'm obviously never going to find a website that tells me how to do exactly what I want to do since it's somewhat custom. I guess I'm just looking for preferably someone who is reading this who has some experience managing a windows server network for a business/client that is trying to get email archiving figured out to read this and post a thoughtful reply answering the whole of the question as best as you can. Of course, anyone who feels they know enough about this that is willing to take their time typing out an answer is welcome and appreciated as well.

Also, the reason I'm going through all this trouble is because I'm working on a system that will hopefully have people working with it one day but there will certainly be shady people doing shady things and deleting emails and whatnot. I'm trying to get a communications system set up with this in mind. Was thinking I'd just have something simple that just auto copied (and never deleted) emails onto the server and kinda tried to get different emails copied into different project folders.

I know this one was long but I had to because the world is complicated. Thank you again for your time and thanks again in advance.

NFS + NTFS volumes using mountpoints and Linux

$
0
0

Hi all:

I'm having very wierd experiences using Mountpoints and Linux (CentOS7)

I have a lot of volumes mounted using "mountpoints", for example, "logs" volume is a 500GB volume mounted in D\Mountpoints\logs and shared using NFS.

I can mount this NFS using Linux with a standard command and it works well

mount -t xxx.xxx.xxx.xxx:/logs /mnt/NFS/logs

however, when I create textfiles using Linux the files are created like this "ゾtest.txt" and permissions are a bit confused, when I try to modify this file, the file "dissapear" in Linux, but I can see it in Windows, without modifications, and if I create files using Windows, I can't see it using Linux.

If I create NFS using "driveletters" it works well, for example, If I create NFS shares inside F:\logs or G:\logs and mount in Linux using the same command: mount -t xxx.xxx.xxx.xxx:/logs /mnt/NFS/logs

someone had similar experiences using mountpoints and Linux? Recommendations?


windows workstation share session not auto disconnect as expect

$
0
0

Dear

I know below command can setup idel time, then session will auto disconnect.

net config server /autodisconnect:15

My settings as below, but why I still see so long time of connection time and idle time in computer management -> share folder-> session?

over 1 day connection and over 1 hous idle.

how can I let it auto disconnect then have high performance to share.

Thank you.

++++++++++++++++++++++++++++++++++++++++++++

Server hidden                         No
Maximum Logged On Users               20
Maximum open files per session        16384

Idle session time (min)               20
The command completed successfully.

DFS replication not working

$
0
0

I am trying to replicate 1 drive to another location. This is a 

When I check event logs I get error below. I have another replication setup on this server that goes to the remote replication server this one points to and it is working just fine. I have tried to recreate the DFS many times but continue to get the same error. Both drives are hard drive image files where one was able to replicate and the other causes error below. Please advise what I can do to get this working as I do not want to have to replicate one folder at a time off the root.

Server OS is Windows Server 2012 R2

The DFS Replication service failed to replicate the replicated folder at local path H:\ because the local path is not the fully qualified path name of an existing, accessible local folder.
 
Additional Information:
Replicated Folder Name: Z
Replicated Folder ID: E3086529-AA91-4414-823C-B4368876541Z
Replication Group Name: CPM Drive Replication
Replication Group ID: AEDAA9C6-13B7-41D2-B8C8-988603F3E758
Member ID: F20BACB8-3B53-4C0F-9031-6C8DDAB3A1AB


Permission issue

$
0
0

Hi...

I am having windows server 2008 standard server with file server service installed on it.

I have root folder or disk shared with every one as readonly.

Sub folder shared with no inheritance from parent folder and is shared with on particular department as read only on top.

however there is another subfolder that has readonly access to department and write access to one user only(all at ntfs Level)

however when the user tries to write a file or create a file he gets an error access denied.

But when i give modify permission he can edit, write delete.

I would like to know where i am going wrong. because the effective permission on the file shows write access but in actual it gets denied. 

Please help need to fix as i have the request to create a write access only on that folder..

WSE 2016 VM - Windows Search problems

$
0
0

Hi all - 

Brand new Windows Server Essentials 2016 VM on Server 2019 Hyper-V, brand new Dell T340 - all SSD storage, very nice.

Windows Search is crapping out. Indexing about 600,000 items on two volumes, it works for a minute, and then searches return an unclickable list of files with white generic icons and no data. Restarting the service works for a while. I've reindexed a bunch.

Any thoughts or ideas? Thanks!

Server 2008 R2 Share

$
0
0

OK, this is an odd one but someone one may have come across it.

We have a fileshare on 2008 R2 whic has 1 single fileshare on it and was working fine untile a reboot, the permissions all look ok on the Share and NTFS, it doesnt have Enumeration enabled, both client (windows 7) and server (2008 r2) have had a considerable amount of updates and restarted a number of times, i i use a domain admin account i can connect without issue but if it uses an account which is part of a domain group assigned to thh folder permissions they get "ACCESS DENIED".

Any assistance would be great.

Cheers guys.

Nate

Domain Accounts Are Unable To Access Network PC's via IP Address but Can Access via ComputerName

$
0
0

Hello All,

As stated in the title, while logged in to a domain account (which is part of the domain admins group), I am unable to access network machines via their IP address ( \\x.x.x.x\c$ ) however, I am able to access the machines via their domain name (\\ComputerName\c$).  Also, while logged in as a LOCAL admin, I am able to access any network PC by either method. 

While logged in as a domain admin, if I attempt to navigate to \\x.x.x.x\, I receive an error stating:

"\\x.x.x.x is not accessible.  You might not have permission to use the network resource.  Contact the administrator of this server to find out if you have access permission. 

Account restrictions are preventing this user from signing in.  For example: blank passwords aren't allowed, sign-in times are limited, or a policy restriction has been enforced."

While logged in as a domain admin, if i attempt to navigated to \\x.x.x.x\c$, I receive an error stating:

"Windows cannot access \\x.x.x.x\c$.  Check the spelling of the name.  Otherwise, there might be a problem with your network.  To try to identify and resolve network problems, click Diagnose."

When I click on "see details" drop down, I see error code: 0x80004005 Unspecified Error.

While logged in as a local admin, I receive none of these issues. 

How do you translate abstracted hardware to the physical device?

$
0
0
How can I tell which physical device is \Device\RaidPort1 from an Event Viewer log?  It isn’t anywhere in device manager or the registry but I know it is an Emulex card.  I'm running Server 2008 R2.

DFSR Errors in event viewer

$
0
0

Hi All,

May I ask for your help on how can I create a powershell script that will send an email to me whenever dfsr encounter issues and logged in event viewer. already did research and I am having trouble on the smtp server. Currently our email use by our company is web based and online. so I'm wondering if its possible. Thank you.

Regards,

Pao

Subfolder was wiped out

$
0
0
I created a shared folder (\\<hostname>\Data2\Esri\gtg-resources\) on server A (Windows Server 2008).  I saved some XML files to the subfolder via servers B & C (Windows Server 2019).  Unfortunately, all of the XML files are missing.  The subfolder (gtg-resources) is empty.   I logged back onto servers B & C, I could see that records of files in that directory in the “Recent files” shortcut within Windows Explorer.  The other subfolders in \\<hostname>\Data2\Esri\ have nothing wrong.  I also checked recycle bin on server A, and it's empty.  Shadow Copies function is not enabled and there are no previous versions available on Server A.  IT nightly backups show empty folder as well.  

I was puzzled why files in the subfolder are missing?  How do I know what happened with the files? Can someone tell me what probably happened to the subfolder?  Is there any way to get them back if they were deleted accidentally?

Many thanks!

Charles

Need help to remove all file and folder from share folder after specific age (7 days old)

$
0
0

Need help to remove all file and folder from share folder after specific age (7 days old).

Is there any Scripts or GPO?

Thank You

Nur


NUR BD

DFS Replication - Compressing a folder participating in DFS Replication results to a zipped file twice as large as the folder itself

$
0
0

We're using this command to create a daily backup of a folder by zipping it:

[io.compression.zipfile]::CreateFromDirectory($Source, $destination)

We noticed that after setting up DFSR, the size of the zipped file becomes twice as large as zipped files from the previous days. When checking the folder itself, it's half of the newly created zipped file. There are also thrice as many files in the zipped folder when checking its Properties but judging from the contents, there are no extra files created.

I know that sometimes compression doesn't really result to a smaller file, but creating a file twice as large weirds me out. I wonder if the extra files it sees are from the branch server.

Does anyone have an idea?

Windows Admin Center 1910 / Storage Migration Service Download of error protocol failed

$
0
0

Hi,

last night, the 1st run of migration from our old fileserver to new one (Srv2019) was finished.

During run, several errors with different files occured, so we want to download the error protocol, but we can´t.

The downdoad runs into timeout, within the configured timeout of 1min, the download was not finished, as stated in the log message here:

Vergewissern Sie sich, dass Port TCP 445 (SMB-Dateifreigabe und -Druckfreigabe) auf dem Orchestratorserver geöffnet ist. (Check, that Port TCP 445 SMB File and Printer Sharing was opened on the orchestrator server)
Fehler: This request operation sent to net.tcp://localhost:28940/sms/service/1/transfer did not receive a reply within the configured timeout (00:01:00). The time allotted to this operation may have been a portion of a longer timeout. This may be because the service is still processing the operation or because the service was unable to send a reply message. Please consider increasing the operation timeout (by casting the channel/proxy to IContextChannel and setting the OperationTimeout property) and ensure that the service is able to connect to the client..

I just want to change the timeout setting as I found a note here:
https://social.msdn.microsoft.com/Forums/en-US/dc4a6bdc-4dd7-4e68-b24d-cd83a3bfece5/nettcp-operationtimeout-question?forum=wcf
, but I couldn´t find any config file for Admin Center, where I can put it in.

Anyone here, who got the same problem or knows about the config files of WAC/SMS?

NTFS Corruption EventIDs needed

$
0
0

Hello,

after studing the following MS article, I´m searching for the needed event-id´s in case of checkdisk detects some corruptions in file system during its on line background scan, so restart is needed to correct it while the volume is offline.

https://docs.microsoft.com/de-de/previous-versions/windows/it-pro/windows-server-2012-r2-and-2012/hh831536(v=ws.11)

-> ...Corruption correction: When the scan is completed, Windows Server 2012 informs the administrator (by using events and the management consoles)....

From my last years in IT business, I know the eventid 55, which I be informed about, but are there more and/or changed with the new version (ok, since 2012...) of checkdisk?

Thank you!

DFS - PermissionDenied when trying to delete a DFS Target folder

$
0
0

I'm trying to remove a DFS target folder in a process to migrate these to a new server.  I get an "Access Denied" when trying to do it from the DFS Management GUI.  I get a "PermissionDenied" when trying to do it from powershell using this command:

Remove-DfsnFolderTarget -Path "\\dfsshare.local\root\folder" -TargetPath "\\server\folder"
I've also tried from the machine itself in powershell using this command, with the same "Access is deneid":
"dfscmd.exe /remove \\dfsshare.local\root\folder \\server\folder"

Any idea what permissions I need to check/change in order to be able to remove this?  (I've also tried it with the share enabled and disabled on the target server.)

Viewing all 13580 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>