BPA at OOW 2008

Hello all,
for those of you who will attend Oracle Open World 2008 in SFO next month: we are going to present our methodology in combining business and IT oriented modelling using the BPA Suite.
http://www28.cplan.com/cc176/catalog.jsp?ilc=176-1&ilg=english&isort_sessions=&isort_demos=&isort_exhibitors=&is=yes&ip=%3C%2Fipresentations%3E&isort_sessions_type=&isort_exhibitors_type=&isort_demos_type=&search_sessions=yes&icriteria1=+&icriteria2=+&icriteria5=&icriteria4=+&icriteria8=&icriteria9=+&icriteria6=&icriteria3=+&icriteria7=analysis+suite
Dirk

Hi Kuba,
Steve Muench posted his talk here,
Chir Muir here
My guess is that we'll see others in a couple of day too.
Timo
Edited by: Timo Hahn on 29.09.2008 09:21

Similar Messages

  • Dreaded "must be configured to use a valid SSL cert" - 2008 R2

    Hello everybody,
    I've been browsing through hundreds of topics on the dreaded "The RD Gateway server must be configured to use
    a valid SSL certificate" error using BPA (Windows Server 2008 R2 Std), but still haven't found a proper solution.
    Here's the issue: RDGW not operating properly and sometime accepting connections, sometimes not. 
    I have an external domain example.com and internally, the domain is example.local. I have one server serving Exchange and RD, this is the server responding to mail.example.com and I have an StartSSL issued cert for mail.example.com, which is properly configured
    on the server (OWA is working properly with autodiscover etc.). SSL bindings seem alright, default site is using the mail.example.com SSL cert.
    If I open the RDGW Manager and go to the SSL Certificate tab, the system looks happy by having the cert installed, everything looks fine. Sometimes I even manage to connect - connection is successful, I can normally connect to any of the servers or computers.
    On a second attempt, I just get the message, that the logon attempt had failed. If I run BPA on the server, I get the error of not having a proper SSL cert. If I select a self-signed cert, then also the BPA goes through, but then I have problems with connections
    since everybody would need this cert to have installed.
    From what I read, my problems are related to the issue that the FQDN of my server is servername.example.local and the cert is issued to mail.example.com. How can I make the thing only to talk via the mail.example.com cert? I don't think I can get a cert
    that'd also contain a SAN of servername.example.local from the CA.
    What can I do?

    Hi Andrej,
    Thanks for posting in Windows Server Forum.
    Here providing you the article for BPA’s configuration logs, where you can check. It also states that certificate are main problem related to this error. Please check certificate which you have bound have FQDN name of gateway server, the certificate is SSL
    certificate and it’s a trusted certificate. Also check that certificate which you have importing to RD gateway must be in local computer/personal store. For more information refer below article.
    1. Using the Remote Desktop Services BPA to analyze a Remote Desktop Gateway
    implementation
    2. RDS: The RD Gateway server must be configured to use a valid SSL certificate
    In addition, you need to specify the FQDN name of RD gateway under
    DefaultTSgateway in IIS setting. Please go through below article for details.
    RD Gateway/Web Access Outside the Firewall
    Hope it helps!
    Thanks,
    Dharmesh

  • Oracle OpenWorld 2008 - presentations and demos

    Hi,
    Question to Oracle people - when can we expect publishing prresentations and demos from OOW 2008? [OOW On Demand Preview|http://ondemandpreview.vportal.net/] portal is still empty.
    Kuba

    Well the presentations and sound recording are accessible form here:
    http://www.cplan.com/oracleopenworld2008/sanfrancisco/ondemandlogon
    But you'll need a user/password
    Also remember that you only get voice and slides - you don't actually get to see live demos.

  • EPM Planning & Budgeting Partner Implementation Boot Camp Ready 2 Launch

    The Oracle PartnerNetwork launched a new Implementation Boot Camp program at OOW 2008. Since then Oracle has made available to partners ~8 different Boot Camps and expect to have near 20 by the end of February 2009.
    That said, we are close to finalizing the content for an EPM Planning & Budgeting Implementation Boot Camp, and I am interested to hear if there is any interest in this Boot Camp among this audience.
    Goals / Objectives
    The EPM Planning Bootcamp will provide implementation instruction on Oracle’s EPM System products Planning functionality. The bootcamp will be a fast-paced, five-day class, teaching students what they need to know in order to implement and manage EPM Planning applications. Goals for the bootcamp are described below.
    The Planning bootcamp is designed to take consultants through all the steps needed in an implementation of Hyperion Planning. The class begins with an overview of Essbase, the foundation of Hyperion Planning. It provides a general overview of Planning and Planning terms, the architecture of all the Planning components, and how they are commonly used. The course goes over all the steps to create an application from scratch. This involves some prep work outside of Planning and leads to developing the application in both the Planning Windows and Web clients. Participants will modify existing dimensions and build out the hierarchies using the Web client.
    Audience
    This bootcamp is intended for prospective users and implementers of the Planning and Budgeting functionality of Oracle EPM or implementers that are currently familiar with the basics of EPM Planning and looking to strengthen their base of knowledge in the product.
    Ideal participants are Oracle partners (SIs and resellers) with backgrounds in business information systems and a clientele of customers with ongoing or prospective EPM initiatives. Alternatively, partners with the background described above and an interest in evolving their practice to a similar profile are suitable participants.
    EPM Planning & Budgeting Bootcamp
    The bootcamp shows developers how to build out dimensions using Classic Planning and by using EPMA. It covers the mechanics and cover strategies for automating the build process such as interface tables. The reviews data loads using Load Rules to load the Planning database. The course focuses on tasks that end-users must perform during the planning cycle. It walks students through creating and modifying forms, working with forms to enter data, adding annotations, and the rest of the form features such as running business rules and managing task lists. It covers how to use the forms in the Smart View client and finishes up the end-user perspective by going through Workflow Management and the process of submitting a plan for review. The final section of the course covers Security and other administration topics such as automation and deployment.
    Applied Planning Course Topics:
    • Overview of Essbase & Planning
    • Application Design Overview
    • Essbase Spreadsheet Add-In & Smart View
    • Load Rules for loading data
    • Essbase Administration Services (EAS)
    • Architecture
    • Calculation Fundamentals
    • Overview of Planning
    • Setting up an Application
    • EPMA – Enterprise Performance Management Architect
    • Building Forms and Business Rules
    • Smart View Client
    • Workflow Management
    • Security and Administration
    Edited by: nkritiko on Nov 6, 2008 1:45 PM

    Nick,
    Can you let us have the schedule, location and duration of these Boot Camps?
    Thanks

  • R12 External Access

    Hi Hussein,
    In my test env, I have one single node instance of R12 (12.0.6) running over RHEL 5.3. This instance environment is wrapped within a VPN. I want to give access to R12 instance to some users for testing who are outside the VPN (through internet). I want to build a test environment to learn DMZ. R12 is configured using a dummy test domain for test instance by putting entries in hosts file at server as well as client side internally. I don't need any load balancing requirement at this point as it is only for testing.
    I just want to build a very simple configuration with minimum additional HW/SW which can meet my above requirement. Please help me with the following. Any step by step instructions or guide will be really appreciated.
    http://r12.west.domain.com - Current VPN access URL
    http://r12.domaon.com - Proposed external access URL
    Do I need a seperate server outside the VPN.
    How many additional public and Private IPs (VPN) needed.
    Do I need to have any Public Domain.
    Do I need to have any network component like switch/router.
    Any additional software component need to be installed.
    I have the following note for 11i from your previous post which I did not have a chance to implement as I upgraded the instance to R12.
    Note: 287176.1 - DMZ Configuration with Oracle E-Business Suite 11i
    https://metalink2.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=287176.1
    Please suggest/advise.
    Thanks
    -Samar-

    Hi Samar,
    There are many deployment options available for making Oracle E-Business Suite R12 accessible via the internet. The following document outlines these different scenarios in details.
    Note: 380490.1 - Oracle E-Business Suite R12 Configuration in a DMZ
    https://metalink2.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=380490.1
    The simplest configuration to make your TEST server accessible via internet is to change the IP Address to public and that is all, but as you know this option is not acceptable as it is unsecure, plus you are not gaining any extra knowledge when implementing it. Since you want to avoid reverse proxy and load balancers, then the only option you have is configuring an external web tier behind a DMZ external firewall (please refer to the document referenced above for details -- Option 2.2: Using Separate Oracle E-Business Suite Release 12 Web Tiers).
    Web cache could be used here as it can act as a reverse proxy, web caching, and load balancer. More details about this configuration can be found in the following document.
    Note: 380486.1 - Installing and Configuring Web Cache 10g and Oracle E-Business Suite 12
    https://metalink2.oracle.com/metalink/plsql/ml2_documents.showDocument?p_database_id=NOT&p_id=380486.1
    I would suggest you go through the documents/links referenced in this reply, and see if you could reconsider the configuration of this test environment you want to build. If you go with web cache for example, you may implement a reverse proxy or load balancer, and hence go with a different deployment option.
    What Does "DMZ Certification" Mean?
    http://blogs.oracle.com/stevenChan/2007/04/what_does_dmz_certification_me.html
    Troubleshooting DMZ Setups for Apps
    http://blogs.oracle.com/stevenChan/2007/09/troubleshooting_dmz_setups_for.html
    In-Depth: Demilitarized Zones and the E-Business Suite
    http://blogs.oracle.com/stevenChan/2006/05/indepth_demilitarized_zones_an.html
    Advanced Deployment Architectures for Oracle E-Business Suite
    http://blogs.oracle.com/stevenChan/2008/11/advanced_deployment_architectures_for_oracle_ebs.html
    Advanced Deployment Architectures for Oracle E-Business Suite
    http://www.oracle.com/technology/products/applications/events/oow-2008/EBS-Advanced-Configurations-IvoDujmovic.pdf
    Regards,
    Hussein

  • 1355 the spec domain could not be contacted 1355, other AD mess

    I've inherited a mess here.  What I have is an environment with 1) Windows Server 2003 Std (vm) 2) Server 2008 R2 (vm) running on a 2008 R2 Hyper V host.  Both servers were DC's.  The problem is that when pointing DNS to either DC, there would
    be all kinds of different errors such as access denied or domain controller couldn't be contacted, etc.  I also noticed that they were not replicating with each other for some time.  When specifying DNS to only use a specific DC, users could connect
    to shares on one server but not the other.
    I have run restores from the last good backups, but apparently this was a problem even at that point and restores would produce the same results.
    After running the BPA on the 2008 R2 OS for AD, it came up all errors.  I proceeded under the premise that this server was more corrupt than the other, and knowing I can still go back to the backups I do have, I decided to do a dcpromo /forceremoval
    after a graceful demotion wouldn't work.  At this point I was able to see that 1) was a GC, and it held all the fsmo roles.  
    I could also access ADUC and ADSS from 1) so I proceeded.  I ran a metadata cleanup on 1) and then proceeded.
    It's somewhat back as now I can access servers by dnsname (I couldn't before and that's what started all of this), but I can't add machines to the domain, nor can I promote the host OS to a DC (hoping that after a promo of a different server I could gracefully
    remove 1) ).
    I also saw that SYSVOL didn't show as a share on the 1) server although the directory exists.  I went to share it, but it couldn't populate a list of locations so I shared it to Everyone with Read access.
    I then ran dcdiag and get the following failures:
    Starting test: NetLogons
             Unable to connect to the NETLOGON share! (\\2003-DC-SERVER\netlogon)
             [2003-DC-SERVER] An net use or LsaPolicy operation failed with error 1203, 
    No network provider accepted the given network path..
             ......................... 2003-DC-SERVER failed test NetLogons
          Starting test: Advertising
             Fatal Error:DsGetDcName (2003-DC-SERVER) call failed, error 1355
             The Locator could not find the server.
             ......................... 2003-DC-SERVER failed test Advertising
    Starting test: frsevent
             There are warning or error events within the last 24 hours after the
             SYSVOL has been shared.  Failing SYSVOL replication problems may cause
             Group Policy problems.
             ......................... 2003-DC-SERVER failed test frsevent
    Starting test: systemlog
             An Error Event occured.  EventID: 0xC25A002E
                Time Generated: 10/01/2014   09:12:53
                (Event String could not be retrieved)
             An Error Event occured.  EventID: 0xC25A002E
                Time Generated: 10/01/2014   09:17:21
                (Event String could not be retrieved)
             ......................... 2003-DC-SERVER failed test systemlog
    Starting test: FsmoCheck
             Warning: DcGetDcName(GC_SERVER_REQUIRED) call failed, error 1355
             A Global Catalog Server could not be located - All GC's are down.
             Warning: DcGetDcName(TIME_SERVER) call failed, error 1355
             A Time Server could not be located.
             The server holding the PDC role is down.
             Warning: DcGetDcName(GOOD_TIME_SERVER_PREFERRED) call failed, error 135
    5
             A Good Time Server could not be located.
             Warning: DcGetDcName(KDC_REQUIRED) call failed, error 1355
             A KDC could not be located - All the KDCs are down.
             ......................... lia.local failed test FsmoCheck

    Hi,
    So you have tried to demote the 2008 R2 DC and failed then you force-remove it and cleanup metadata, but realized it was holding FSMO roles?
    Looks like all dcdiag tests are failing since you lost FSMO roles, realiable time source (which was this DC as PDC), GC. Kinda like a forest/domain recovery if i meay say.
    I believe you can to do a seize operations of FSMO roles to the DC that is still running, make it a GC and set it as NTP realiable time source for the domain. Then after you test health you can promote the 2008 R2 back under a different name as additional
    DC and go from there.
    More on seize FSMO roles on a 2003 DC.
    http://support.microsoft.com/kb/255504
    Hope it helps.
    Regards,
    Calin

  • Does biee 10g have mapviewer versions?how do i achieve map function?

    Does biee 10g have mapviewer versions?
    how do i achieve map function in biee 10 version?
    who can tell me what do i do and how to do it?or have some document about this.thanks very much!

    It does not.
    You can use the custom integration methods described in the OOW 2008 doc
    Integrating Oracle Business Intelligence Enterprise Edition with Oracle Fusion Middleware MapViewer

  • Outlook 2013 Constantly Prompting For Credentials - Exchange 2007 - Small Business Server 2008

    Hello, I am having a problem using Windows Small Business Server 2008 and Exchange 2007 with Outlook 2013. The issue is that a credentials box appears in Outlook 2013 when using there exchange account whilst connected to the domain. The box will randomly
    prompt for user credentials, once the user credentials are entered it will either pop back up again and if you enter the details in again it will continue to pop up for around 4 or 5 times before accepting the credentials. It will then pop back up within 15
    minutes and do the same thing, if you click "Cancel" on the box it will also go away and remain connected to exchange however a popup in the bottom right will appear asking for a password even though you can send / receive from the mailbox.
    I have looked into this issue for hours and hours and still can not find a resolution, I have tried re-installing Office 2013 and re-creating the Outlook Profile as-well as as the Windows 7 Profile. I have checked through all the SSL certificates in IIS
    and everything appear to be correct.
    Is this a common issue? Is there anything I can do to further diagnose or fix this issue without having to try to re-install both the server and machine?

    Hi James_wilson,
    Any update?
    Just additional, would you please let me know whether have installed all updates for Outlook 2013? If hasn’t, please install and then monitor the result.
    Please also check if you enable
    Always prompt for logon credentials setting in Outlook 2013. 
    If you enable this setting, please uncheck and check if this issue still persists. Meanwhile, please remove the old credential in
    Credential Manager, then add again. Then monitor the result
    By the way, please run the Exchange BPA on the SBS 2008 server and check if can find some issue.
    Hope this helps.
    Best regards,
    Justin Gu

  • Internet connection failed to configure DHCP ipv6 on Small business server 2008

    1. disabled ipv6 on nic and RESTARTED SERVER....
    2. realizing i did a mistake, i renabled ipv6 on nic after that
    3. now fix my network gives error report DHCP not configured properly for IPV6
    4. ipv4 has fixed ip address (192.168.43.9), router ip 192.168.43.254, i chose dynamic ip assignment for ipv6 (not sure should be static or dynamic).
    5. Fixed my network assigned fixed ip address automatically but failed to fix error DHCP for ipv6 for the network.
    6. i also tried internet connection wizard, which fails reporting error Internet connection wizard cannot configure dhcp for ipv6 sbs 2008. this
    error is received after click NEXT button on successfully server and router ip on Detecting Router and configuration page.
    Although I am not using IPV6 but server may be using it. Can someone please please help me.
    thanks

    Hi,
    I can find that there is a
    same thread that you posted in the forum. I had replied it. Please check if can help you. Just remind that please reboot when uncheck IPv6 option and monitor the result. Meanwhile, please check if can find some relevant issue when you run
    SBS 2008 BPA.
    In addition, please refer to the following thread and skip the DHCP check, then run the wizard. Please check
    if this wizard can be ran completely. If run successfully, then enable the DHCP
    again.
    SBS
    2011 is detecting DHCP on my network after I disable it and i cant continue setup
    Hope this helps.
    Best regards,
    Justin Gu

  • Sync TX to Outlook 2003 running on Small Business Server 2008

    I have a TX that worked fine syncing to Outlook 2003.  Our office just upgraded to Small Business Server 2008, and now I can't sync to Outlook. Reading through the manual & forums, it soundsl like I must use Microsoft Exchange ActiveSync.  Is this correct, or can I still HotSync it the way I used to before we were running exchange/SBS?  If so, is there any way to have my TX show more than 7 days of past calendar events, as I often need to look back at things over the past month or two. 

    Hi James_wilson,
    Any update?
    Just additional, would you please let me know whether have installed all updates for Outlook 2013? If hasn’t, please install and then monitor the result.
    Please also check if you enable
    Always prompt for logon credentials setting in Outlook 2013. 
    If you enable this setting, please uncheck and check if this issue still persists. Meanwhile, please remove the old credential in
    Credential Manager, then add again. Then monitor the result
    By the way, please run the Exchange BPA on the SBS 2008 server and check if can find some issue.
    Hope this helps.
    Best regards,
    Justin Gu

  • SBS 2008 - SBS Console and AD errors after migration to new hardware

    Hi there,
    I'm trying to work out how to fix some of the errors and random behaviour I'm experiencing with the SBS 2008 console and AD related matters since I had to quickly migrate SBS 2008 to new hardware using Windows Server Backup after a failure of the old server.
    In my haste to get our email and ftp services back up and running (which use Smartermail and Filezilla respectively instead of Exchange etc) I overlooked the fact that the new server had 3 NICs installed and not one and so restored SBS 2008 and loaded up new
    drivers for those and other hardware that had changed (such as the graphics card and mobo. I have since removed the two additional NICs by disabling them on the mobo).
    Whilst I got the server up and running again with email and ftp services, even though I currently don't use any AD related stuff directly I have since noted that if I try to say view a list of users that I had previously created via the SBS console, more often
    than not it will show no users, and then randomly it will (but when you do see them you can't edit or delete them. I'm aware that I have probably broken a number of golden rules in doing this 'migration' but having a metaphorical gun to my head meant that
    I rushed things out of desperation. 
    Common errors that I experience generally will say things like 'Current security connect is not associated with an Active Directory domain or forest' if I try to list users, or DC not found for domain "xyz.local' etc. I have been searching the net and
    trying out some things to fix this but I'm like a dog chasing its tail as I'm not so clued up on server related issues as I am with workstation problems, so if anyone could at least point me in the right direction I would be very grateful. If you require any
    info from me (eg diag logs etc) I will be happy to provide them!
    Regards,
    Dave

    Hi Dave,
    Based on current situation, please run SBS BPA and fix all that it can find, then monitor the result. For more details, please refer to the following KB.
    Windows SBS Best Practices Analyzer (BPA)
    Meanwhile, please refer to the following article and repair SBS console.
    Repair the Windows SBS 2008 Console
    By the way, I noticed that you had got some error messages (such as: “DC not found for domain” and so on). Would you please let me know complete error messages? In addition, when you migrate SBS 2008 to the new hardware, had you done any preparation for
    that Source Server? For more details, please refer to the following article.
    Migrate Windows Small Business Server 2008 to New Hardware
    If any update, please feel free to let me know.
    Hope this helps.
    Best regards,
    Justin Gu

  • Exchange BPA Errors (Exchange server is a virtual machine but the additional tools are not installed and The 'Services' string type value located in 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ExchangeServer\v14\Setup\Services' registry key is missing)

    Hi,
    I am running BPA on My Exchange 2010 VM (Server 2008 R2 VM on Hyper-V) and get the following errors:
    The 'Services' string type value located in 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ExchangeServer\v14\Setup\Services' registry key is missing or inaccessible. The Microsoft Exchange Information Store service won't start. As a result, all services that depend
    on this service won't be able to start
    Exchange server [Exchange Server FQDN] is a virtual machine but the additional tools are not installed. This configuration is not supported. Install Virtual Machine Additions for this guest.
    Problem is that, for the first, that Key exists and the service is actually running fine. And for the second my VM tools are already installed.
    Hopefully someone out there has had the same issue and can assist.
    Pete

    Hi Pete,
    For the first error message, please try the following steps:
    Make sure the Information Store service is in Starting status,
    Automatic startup type and works well, as a test we can try to
    restart the Infroamtion Store service and verify the service works well.
    Start
    Registry Editor, find the registry key “Services” under “HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\ExchangeServer\v14\Setup”, its value is “C:\Program
    files\Microsoft\Exchange Server\v14”(default install location), please check your registry, make sure the key “Services” exist and value is the Exchange Server install location and the
    location is accessible;
    Start
    Registry Editor, and locate the following registry key:
    HKEY_LOCAL_MACHINE\Software\Microsoft\Exchange\Setup
    Use the
    Permission option under the Security tab to check the permission setting on this key. Make sure
    System is in the list with Full Control permissions if the service account is Local System. If you are not using Local System as the service account, check the existence of the corresponding account in the list and ensure that
    it has Full Control permissions. Please refer to this article:
    Title: Exchange Store Does Not Start: Errors 7024, 1026, 9542, and 5000
    Link:
    http://support.microsoft.com/kb/285116
    Start
    ADSI Edit, and then browse to the following location:
    Domain.com/Configuration/Services/Microsoft Exchange/Org/Administrative Groups/AdminGroup/Servers/Server Name
    Right-click the
    server name, and then click Properties.
    Click the
    Security tab, make sure this own server’s server object have
    full control permission on its own server.
    If not or the object is missing, please modify the permission or click
    Add, locate the computer account for the Exchange Server computer, add it to the Permissions list with full control.
    Click OK, and then close ADSI Edit.
    Use
    Active Directory Users and Computers to add the current affected
    Exchange Server computer account to the Exchange Servers(previous version should be “Exchange Domain Servers”) group in the
    Microsoft Exchange Security Groups( or Users) OU. Refer to this article:
    http://support.microsoft.com/kb/297295.
    Restart the Exchange Server computer, then rerun the ExBPA.
    For the second error message, Microsoft don’t recommend to install Exchange Server on virtual machine without additional tools, so the error message occurs. We can just ignore
    this message, it will not affect the Exchange servers.
    Regards, Eric Zou

  • Server Core 2008 R2 SP1 - AD DS Best Practice Analyzer Scans Don't Produce Any Output

    Hi,
    This is a re-post moving this discussion to the recommended forum "Server Core" from here:
    http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/cc33d429-88e0-4450-a73c-361e395fd217.
    I am having problems producing any output for any AD DS Best Practice Analyzer Scans on a Windows Server Core 2008 R2 SP1 Domain Controller.
    I have imported the "ServerManager" and "BestPractices" PS modules on that Server by running the following commands:
    Import-Module ServerManager
    Import-Module BestPractices
    I've then run
    get-BPAModel, to find out what best practice scan models are availale, this returns the following output:
    Id                                                       
    LastScanTime
    Microsoft/Windows/DirectoryServices     Never
    Microsoft/Windows/DNSServer               Never
    I then run all the BPA scans on that box:
    Get-BPAModel | Invoke-BPAModel
    This returns the following output:
    ModelId                                          
    Success  Detail
    Microsoft/Windows/DirectoryServices True       (InvokeBpaModelOutputDetail)
    Microsoft/Windows/DNSServer          True       (InvokeBpaModelOutputDetail)
    Since the BPA invocation results weren’t displayed automatically, I entered the following command to see them:
    Get-BPAModel | Get-BPAResult | Out-File "D:\Source\BPA.txt"
    This command will create a text file with the scan results but I only see the results of the DNSServer scan, not the DirectoryServices scan.
    I have also tried to view the results in a HTML format by running the following command but still only see the DNSServer scan results:
    Get-BPAModel | Get-BPAResult | ConvertTo-Html | Set-Content d:\Source\BPA.htm
    I have also tried exeucuting the scan ONLY for the "Microsoft/Windows/DirectoryServices" model but can't get any results to be returned.  I have also connected using server manager from a Full install of Server 2008 R2 SP1 but that
    doesn't seem to show any results under the "Best Practices Analyzer" section when the "Active Directory Domain Services" node is selected, all 4 tabs ("Noncompliant", "Excluded", "Compliant" and "All") show zero (0).  However, the summary text above the
    tabs does show when the last scan was performed. which seems to be correct.
    Is there something special that needs to be done to produce the BPA results for the "Microsoft/Windows/DirectoryServices" BPA model on Server Core 2008 R2 SP1?
    BTW: The Forest/Domain is W2K3R2 Native, this is the first W2K8R2 DC in the environment and I have installed .NET 4 framework (Server Core) to support Powershell 3, also installed.
    Thanks, Paul.
    belpad

    Hi Diana,
    OK, pretty sure I've now found the root cause of the issue I've described above.
    I was also looking into Windows Update Agent issues for these W2K8R2 Server Core DC's, where no updates would be applied via WSUS (configured via GPO) and would fail with "FATAL: CBS called Error with 0x8000ffff windows update agent server
    core". 
    Yesterday, I managed to get one of the W2K8R2 Server Core DC's (WSUS updates) working again by removing one of the .NET 4 Framework security updates (KB2600211) which was manually applied when the server was initially setup.  .NET 4 (Server Core Edition
    http://www.microsoft.com/en-us/download/details.aspx?displaylang=en&id=22833) was installed as a pre-requisitie for Powershell 3.  Once this update was removed, the affected server core DC was restarted and WSUS updates started to get applied.
    So I followed the same procedure on the other server core DC but this did not resolve the WSUS issue this time.  Next, I did further investigation into the Windows Update Agent problem.  This led me to the following article:
    http://blogs.technet.com/b/brad_rutkowski/archive/2008/07/03/windows-update-fails-with-8000ffff-e-unexpected.aspx which described an issue with NTFS permissions being set incorrectly on C: drive, with the "BUILTIN\Users" group completely
    missing on the C: drive.
    I found the affected Server Core DC also had this issue and when the "BUILTIN\Users" was assigned permissions on the C: drive as described above, and the Windows Update Agent re-started, the Server Core DC started to install all required updates
    configured via WSUS.
    Next, I ran the Directory Service BPA, which now produces the desired output either locally or remotely via Server Manager.
    Therefore, I can only assume that the Directory Service BPA also uses "Network Service" much like WUAUSERV (Windows Update Agent), which requires access to the C: drive via the "BUILTIN\Users" assignment.
    So this has subsequently led me to check the C: drive (%systemdrive%) permissions across multiple W2K8R2 machines, all of which showed differing assigned permissions, as follows:
    1. W2K8R2 Server Core DC - With Directory Services BPA and Windows Update Agent Not Working
    C:\>icacls c:\
    c:\ BUILTIN\Administrators:(OI)(CI)(F)
        CREATOR OWNER:(OI)(CI)(IO)(F)
        NT AUTHORITY\INTERACTIVE:(OI)(CI)(RX)
        NT AUTHORITY\SYSTEM:(OI)(CI)(F)
    2. W2K8R2 Server Core DC - With Directory Services BPA and Windows Update Agent Working OK
    C:\>icacls c:\
    c:\ NT AUTHORITY\SYSTEM:(OI)(CI)(F)
        BUILTIN\Administrators:(OI)(CI)(F)
        BUILTIN\Users:(OI)(CI)(RX)
        BUILTIN\Users:(CI)(AD)
        BUILTIN\Users:(CI)(IO)(WD)
        CREATOR OWNER:(OI)(CI)(IO)(F)
    3. W2K8R2 Full DC - With Directory Services BPA and Windows Update Agent Working OK
    C:\>icacls c:
    c: NT SERVICE\TrustedInstaller:(F)
       NT SERVICE\TrustedInstaller:(CI)(IO)(F)
       NT AUTHORITY\SYSTEM:(M)
       NT AUTHORITY\SYSTEM:(OI)(CI)(IO)(F)
       BUILTIN\Administrators:(M)
       BUILTIN\Administrators:(OI)(CI)(IO)(F)
       BUILTIN\Users:(RX)
       BUILTIN\Users:(OI)(CI)(IO)(GR,GE)
       CREATOR OWNER:(OI)(CI)(IO)(F)
    4. W2K8R2 Server Core DHCP Server (Migrated from W2K3 with Server Migration Tools) - With DHCP BPA and Windows Update Agent Working OK
    C:\>icacls c:
    c: NT AUTHORITY\SYSTEM:(OI)(CI)(F)
       BUILTIN\Administrators:(OI)(CI)(F)
    5. W2K8R2 Server Core DHCP Server (Migrated from W2K3 with netsh) - With DHCP BPA and Windows Update Agent Working OK
    C:\>icacls c:
    c: NT AUTHORITY\SYSTEM:(OI)(CI)(F)
       BUILTIN\Administrators:(OI)(CI)(F)
       BUILTIN\Users:(OI)(CI)(RX)
       BUILTIN\Users:(CI)(AD)
       BUILTIN\Users:(CI)(IO)(WD)
       CREATOR OWNER:(OI)(CI)(IO)(F)
    None of the above servers have a Group Policy or any in-house scripts defined that configure C: drive permissions.  It seems odd that there should be such a variance in the C: (%systemdrive%) drive permissions across the above servers, with only
    scenarios 2 and 5 above have matching permissions.  I can only imagine that maybe some software or software update might be causing this.
    By reviewing the above output, it seems there is also a difference between the C: drive permissions of W2K8R2 Server Core and W2K8R2 Full.  Not sure if this is by design? 
    Is there any Microsoft Documentation describing what the default %systemdrive% NTFS permissions should be for W2K8R2 Server Core and Full.  Furthermore, do these permissions change when the various infrastructure roles are installed and enabled i.e.
    Domain Controller, DHCP etc.  I ask, since I would like to use the correct set of permissions for %systemroot% in each scenario. Please advise if I should be asking this question in a different forum?
    belpad

  • BPA for SQL Server

    Hi Experts,
    Need to configure BPA 2008 R2 and 2012. Can you please help confirm if needed to run this tool for remote scan of SQL Servers,i.e install BPA on one central server and use it to scan the rest of the SQL servers in the environment, it is needed to run the
    below metioned command on the remote servers through powershell :
    1. Enable Remoting using "Enable-PSRemoting".
    2. Configure MaxShellsPerUser using "winrm set winrm/config/winrs `@`{MaxShellsPerUser=`"10`"`}" .
    a)Is there anything else needed to be done on the remote servers to allow BPA to run.
    b)Does it differ operating system wise.
    b)How do i reverse these commands after my scan is done.
    Thanks

    Hi,
    The latest version of Best Practices Analyzer for SQL Server is SQL Server 2012 Best Practices Analyzer.
    You can download it from
    http://www.microsoft.com/en-us/download/details.aspx?id=29302
    I will update this thread when there is any update for SQL Server 2014 version.
    Thanks.
    Tracy Cai
    TechNet Community Support

  • Windows Server 2008 Ent to Windows server 2012 R2 std Migration

    Dear All,
    We have windows server 2008 x64 Ent with SP2 it's working fine and perfectly . Presently we implemented new data center also we installed windows server 2012R2 Std . we would like to migrate windows form old data center to new data center .
    I would like to tell  you my current setup :
    we have  Windows 2008 Ent SP2 server 3 number all are  GC  domain controller it's working perfectly .
    IP Address : 192.168.33.121 , 192.168.33.122 , 192.168.33.123
    we have more than 2000 domain users and PC's all clients PC's are using static IP with domain DNS
    My new data center Server windows 2012R2 STD 
    Static IP : 192.168.200.115
    Here my doubt :
    1. How can we migrate 
    2. how can we assign new DNS address to all clients more than 2000 PC's
    Please could you tell me best way to solve this issue ..
    Best Regards
    Subash

    Hello
    tip:
    1 check all old application, server /like old Linux samba, exch2003/ to support 2012 dc
    2 all firewall add same rule as old DC /if have domain trust open firewall./
    3 prompt to dc and gc the new server
    4 check DNS server /DNS forwarder if have/ and AD  logs
    5 run BPA for AD and DNS
    6 create gpo or startup script to add/change dns settings on client.
    sorry my english

Maybe you are looking for

  • How do I install Firefox on my laptop? I'm running Linux.

    <blockquote>Locking duplicate thread.<br> Please continue here: [[/questions/859774]]</blockquote> I downloaded the new version of Firefox. The download put it in a folder on my desktop. Now what? How do I install it on the computer?

  • How to upload the  data into SAP R/3 System

    I have a scenario to  upload the flat file data into SAP R/3 System. I will describe my complete scenario here so that it will be better understanding for you to suggest the solution. The  segments that relevant for the upload of customer master data

  • Lost Ability to Stack

    Not only did I lose the ability to stack, but all the hard work I put into stacking and organizing (*)appears to have been lost. Symptoms: 1. None of the images in my catalog are stacked any longer. 2. If I go to Photo > Stacking, all of the options

  • My parents have forgot they admin password

    my parents did set on parent control but they have forgot the password and my password and username will not work to get this deleted, help me!!!!!!

  • Contribute connection problems, http proxy?

    I've been trying to set up a contribute connection on a client machine for a while now without any luck, Adobe support haven't been much help at all. We're using CS4 on a vista machine, connecting to a website via normal FTP. The FTP connection itsel