Tuesday, 30 November 2010

Loopback GPOs

To apply user policies to specific computers:

Source URL: http://poweredbyapathy.com/loopback-gpos-applying-user-policies-to-specific-computers/

LEAP Documents 2003 - MS Word integration

After installing the Leap Documents 2003 Client you may encounter some errors when you attempt to open Word documents that are part of Matters.

These relate to an incompatibility with Leap and a particular windows update - this is resolved by applying a fix which can be downloaded from the Leap website - under "Leap Tools" >  KBLD1051 Reg Fix.zip.
Once that has been applied, the next time Leap runs it will install a patch that will undo the effects of the offending update.
Close and re-open Leap again and Click "Help" > "About" > Click "Rebuild All". This will replace all Office add-ins and macros, etc.

We also need to make sure the Trust and Add-in settings are correct for Word
1. Close Leap.
2. Go into Word Options > Trust Center > Trust Center Settings... > Select Enable all macros
3. Word Options > Add-Ins > Make sure the Leap plugin is not disabled.

That should sort the problems out - this is relevant for Leap Documents v6.3.279.


GPO Errors - Event ID 1058 and 1030

If you see a stack of 1058 and 1030 Userenv errors in the Application log on servers - run through these troubleshooting steps to resolve:

Source URL: http://support.microsoft.com/kb/887303

You will probably need the Resource Kit and Support Tools installed to run some of these checks.

Tuesday, 23 November 2010

SBS 2008 Console and integration with WSUS

SBS 2008 uses WSUS 3.0 as its backend for the Windows Small Business Server (Windows SBS) Update Services component. The Updates section on the SBS Console is a wrapper for the WSUS system and relies on a set configuration within WSUS and GPOs - if you make changes to WSUS outside of the SBS Console the SBS Update Services will deactivate ustil the configuration is returned to its former state and may lead to unexpected behaviour.

The required settings are detailed at http://blogs.technet.com/b/sbs/archive/2009/06/23/update-services-in-sbs-2008.aspx

Wednesday, 27 October 2010

MYOB AE - Error 'Environment Error 1. Database has not been successfully converted'


Summary
  The following information is only of relevance if you use Contacts or Viztopia with Compliance Integration to access AE Tax. The error message 'Environment Error 1. Database has not been successfully converted' may appear when opening Contacts. This error indicates the data files are in a prior version in relation to your program files.
  Detail
 

When opening Contacts, Configuration, Viztopia Client Compliance or Viztopia Compliance Management, the following error message may be displayed:

Environment Error 1

Database has not been successfully converted. Please contact your System Administrator and quote this number.

Found version 42 [PDTSYS] Require version 43.

The error indicates the data files are in an earlier version to your program files. This indicates that the database has not been upgraded to the latest installed release or service pack version,

OR

You are using a desktop shortcut that is pointing to an old program location.

To resolve this issue you need to:

First check if any shortcuts to Contacts or Configuration on your Desktop open old, invalid, copies of the MYOB AE software. If they do, the please delete these shortcuts.

If this is not the case, then you will need to re-convert the database and reinstall the upgrade (for cases where this procedure has not completed successfully).

Steps:

1.      Locate the Program Directory;

2.      Re-convert the Databases;

3.      Reinstall the Integrated Release (if it was interrupted by the error 'Environment Error 1').

How to locate the bin folder, ie the Profiles program directory

Note: The following instructions do not apply to Terminal Server sites. For Terminal Server users, the required ceedata.ini file is located in the path:
C:\Documents and Settings\{username}\WINDOWS

1.      At the Windows Desktop, click Start and select Run.
The Run window appears.

2.      Type ceedata.ini in the Open field and click OK.
The ceedata.ini window appears.

3.      Note the PROGRAM_DIR directory (e.g. S:\MYOB\bin) and the CHOME directory (e.g. S:\Data\).

Note: Please make sure that you DO NOT have a UNC path for either the PROGRAM_DIR or CHOME directories, eg \\servername\sharename in the ceedata.ini file. If a UNC path is present for either directory, this MUST be replaced by the absolute path, eg S:\MYOB\bin and then your changes must be saved via the menu path File > Save.

4.      From the File menu, select Exit.

How to re-convert the database

1.      Open Windows Explorer, and browse to the Profiles program directory identified above, eg S:\MYOB\bin.

2.      Double-click on the file DatabaseSetup.exe to start the Database Upgrade. Select the required database(s) (start with the database stated in CHOME path), and step through the upgrade wizard. It is recommended that you select to convert just one database at a time at this stage.

3.      If the Database conversion wizard does not open, then there may be a licensing issue which can be corrected by running the Register.bat file. This file is also located in the Profiles bin folder. You should be able to step through this wizard by accepting the current details.
The Select Components window is displayed.

5.      Click Next.
The Register Solution 6 Software window appears.

6.      Enter the Registration Code provided by MYOB and click Finish.
The message "Your registration code has been accepted" appears.

7.      Click OK.
The system may take a few minutes to process.

Note: If you get any errors during steps 2 to 5, please submit a support request quoting article number 13652 with the details of the error.

How to run the Application Finder

Note: If during the conversion of the database, a message states that the database is locked, please follow the instructions below to find the user that has it open, otherwise skip this section.

1.      From DataSafe, click Support Tools.
The MYOB Database Utilities window appears.

2.      Select Application Finder from the Utility drop-down list and then click Run Now.
The Application Finder window appears.

3.      Note the programs running and shut down all applications, except for DataSafe which is denoted by the 'backup.exe' record in the Application column.

4.      Click Refresh.
Only DataSafe which is denoted by the 'backup.exe' record in the Application column should be displayed.

5.      Click Close.
The DataSafe Utilities window appears.

6.      Click OK.
The Windows Desktop appears.

To confirm that the database has been upgraded correctly, please open Contacts (it will open if the installation failed). Close it again and reinstall the Integrated Release if the installation has not been completed successfully.

MYOB AE - "Error: The user profile could not be written. "

If you continue with the existing workpath, the error 'Cannot login without a valid workpath.' occurs and you are then returned to the System Services login gate. Changing the workpath in the field provided, returns the error, 'This location is read only'. The errors will then continue preventing access to System Release for that user.

This error is due to an existing corruption in the ds6op050 file. This file contains information relating to users':

·         Customized toolbars;

·         Navigation favourites; and

·         Window sizes.

To correct this issue the ds6op050 will need to be renamed.

Renaming the ds6op050 file

1.      Double-click the My Computer icon and navigate to the drive on which your Sol64 folder is located.
The contents of the drive appears.

2.      Double-click the Sol64 folder.
The contents of the Sol64 folder appear.

3.      Right-click the ds6op050 file and select Rename.
The file name changes to edit mode.

4.      Rename the file to ds6op050.old and press ENTER.
The change to the file name is saved.

Open System Release in the usual method and access is now possible.

Customised toolbars and navigation favourites will then need to be manually recreated.

Monday, 11 October 2010

Configure Access to Entire Exchange 2007 Mailbox Database

Source URL:
http://technet.microsoft.com/en-us/library/bb310792%28EXCHG.80%29.aspx

* In the Exchange Management Shell, use the following command to
allow access to all mailboxes on a given mailbox store:
Add-ADPermission -identity "mailbox database" -user
"serviceaccount" -ExtendedRights Receive-As

* In the Exchange Management Shell, use the following command to
allow access to an individual mailbox:
Add-MailboxPermission -identity "user" -user "serviceaccount"
-AccessRights FullAccess

To do the same for Public Folders:

*To add AllExtendedRights permissions for the user Chris to access
the public folder named Marketing, run the following command:
Add-PublicFolderAdministrativePermission -Identity "\Marketing"
-User "Chris" -AccessRights AllExtendedRights -Inheritance SelfAndChildren

Tuesday, 17 August 2010

SBS 2008 Monitoring Database Maintenance

If you find that the SBSMONITORING instance of SQL Server is using up more than its fair share of resources (1.5GB+ RAM) and the
"SBSMonitoring.mdf" and "SBSMonitoring_log.LDF" files are over 4GB in size you need to run a maintenance script on the database and then shrink it.

SQL Server Express supports a maximum data file size of 4GB - once this limit is reached the SBS monitoring stops working.

To resolve this download this sql script:
http://cid-d5fe25afb6c3615f.skydrive.live.com/self.aspx/.Public/updateSBSMonitoring.sql

Run this script using:
Sqlcmd -S %computername%\SBSMonitoring -E  -i c:\path\to\updateSBSMonitoring.sql

If this runs successfully you should see:
Changed database context to 'SBSMonitoring'
(1 rows affected)

This can take a while to process (45min on a large database)

This will ensure that the database will contain no more than 90 days worth of data.

Source URL: http://blogs.technet.com/b/sbs/archive/2009/07/14/sbs-2008-console-may-take-too-long-to-display-alerts-and-security-statuses-display-not-available-or-crash.aspx

Next we need to shrink the database size:

Run the "SQL server management studio express
Ensure that "SERVERNAME\SBSMONITORING" is selected and "Windows Authentication" is used and click "Connect"
Expand Databases and find the SBSMonitoring, right click it and choose Tasks -> Shrink -> Database

This will run for a while (20min) after which the database size should reduce to a much smaller size (about 300MB or so in some cases)

Source URL: http://www.eggheadcafe.com/software/aspnet/35793646/sbs-monitoring-4gb-2008-now-what.aspx

Monday, 16 August 2010

Copy TS client license

Source URL: http://support.microsoft.com/kb/323597


If we have a broken Terminal Server that cannot issue client licenses - causing RDP connection errors for new client PCs.

Export the "HKEY_LOCAL_MACHINE\Software\Microsoft\MSLicensing" key from a working machine on the network and import it onto the new client PC. This should resolve the RDP certificate issue and allow the client to connect.

NOTE: The real solution would be to resolve the TS Licensing issue - Restore the TS Licensing or re-activate the server using the TS CALs, etc.

Enable Quicklaunch toolbar and Clock for Terminal Server users


To enable the clock and Quicklaunch bar we need to make sure the following GPO are set as follows:

User Configuration > Administrative Templates > Start Menu and Taskbar
DISABLE: Do not display any custom toolbars in the taskbar (This allows the user to activate the QL bar and others if needed - does not turn it on)
DISABLE: Hide the notification area
ENABLE: Prevent changes to Taskbar and Start Menu Settings
DISABLE: Remove Clock from the system notification area (This setting allows user to turn the clock on - does not actually turn it on)

Right, from a GPO point of view the user should be able to see the QL bar and clock. However you may find that neither the clock nor the QL bar is displayed. To force them to be displayed we need to do the following:

Export the following registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StuckRects2

You'll see a "Settings" value, which contains something like this:
28 00 00 00 ff ff ff ff 02 00 00 00 03 00 00 00 6d 00 00 00 20 00 00 00 00 00 00 00 e0 03 00 00 00 05 00 00 00 04 00 00

The nineth pair of digits determines the Taskbar properties. Possible values are:
Always on top = 0x02
Auto hide = 0x01
Show small icons in Start menu = 0x04
Hide clock = 0x08

Combine the properties you want and set the byte. For example:
Always on top + Show small icons + Show clock = 06
Always on top + Show small icons + Hide clock = 0e

Note that the changes do not take effect immediately, you have to restart Explorer, or logoff and logon again to see the changes.

I set it to 02 (Allways on top)

Save this to a .reg file in NETLOGON

Next for the QL bar:

Logon to admin and make sure the QL bar is active
Export the following key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop

to another .reg file in NETLOGON

Next we need to create a user LOGOFF script GPO and link it to the relevant user accounts. The script should push the required registry settings on logoff (we need explorer to be closed for the settings to remain as explorer updates these keys on closing and reads them only at startup)

The script should "regedit /s file.reg" the reg files created above this will add the keys silently.

The settings should apply the next time on user logon after the script as run.