by via SharePoint Pro
"Mr Sharepoint" is a blog based on RSS for everything related to sharepoint, it collects its posts from many sites in order to facilitate the updating to the latest technology
Friday, June 5, 2015
Has SharePoint Integration Driven You to Drink?
by via SharePoint Pro
Choices
I think there comes a point in everyone’s lives where they have to choose sides, and I don’t mean with political parties, or rugby games…
While we have free will, we have been carefully herded to live in constant fear; every system in place is to support us being afraid all the time and keep us in reaction mode. It takes a huge effort to see past this game and start living your own truly free life.
We are lead to believe that we need to fight against everything “out there” so that things can be right again. Stop the governments, stop the military-industrial machine, stop the crime, stop this, stop that! Fight, fight. fight! The list is endless and we’re always finding a new enemy to point fingers at; the problems become insurmountable, anger and hate build even more; the people at the top of the (perceived) food chain just wring their hands with glee. Have you tried to go up against a mega corporation alone? How did that work out for you? They can swat us like flies all day long.
But what if it’s as simple as stopping the duality in ourselves instead? There is a school of thought that says the world is just a reflection of how we really feel inside. You can only answer this for yourself – but how do you really feel inside? Are you living in constant fear, anger, hate, jealousy, resentment?
What if it’s about understanding – and accepting – that every single one of us has the ability to be endlessly compassionate, loving, caring and embracing; and at the same time, supremely cruel, hateful, greedy, manipulative? What if it’s about getting around your head that while we look at murderers, corporate thieves and environmental destructionists (made up word) as the “bad” guys here; we all have the ability to be those people?
Temptations abound of course. The promise of money, comfort, ‘security’ is very seductive, and when you’re desperate enough for that, you’ll do just about anything to get it. But then when you start tipping too far on the other end of the scale, too much money, comfort and security, it becomes a prison as you do anything not to lose that, which you also do at any cost. See how cleverly the system is designed against you?
Power is not ‘evil’, money is not ‘evil’, technology is not ‘evil’ – they are being used for ‘evil’ purposes. And this is where choice comes in. Every day in every way, we are faced with a new opportunity to exercise choice.
Social Media – the power to connect billions of people around the world to share ideas and come up with better ways of taking care of each and this planet. The power to make new friends and expand your horizons, share your knowledge with like-minded people. Yet the owners of this use it to collect and sell our information to the highest bidder, run experiments on us to see if they can change the global mood; throttle what you see to herd you into thinking certain things; help identify you as a ‘terrorist'; manipulate what gets shared and make people pay to get their message out where before it used to go everywhere.
Technology – the power to build machines that can keep coma victims alive while their bodies heal. To build machines that clean air and water making it safe for everyone. To build alternative energy like solar to halt the destruction of our planet in the quest for more energy. The power to look at the stars and map our place in the Universe. Yet it is being used to pollute our planet on every front and bring mankind to the brink of destruction. It’s being used to build weapons of mass destruction, to mass murder people of all nations for invented reasons.
Money – that we have given a stupid piece of paper backed by nothing so much power boggles my mind, but ok, here we are. The quest for more of it and its perceived power is the singular driving force on this planet right now. How much is enough? I was told recently to work work work very hard for years so I can sell my business for lots of money! How much money exactly? How much is enough?! We can use money to restore the environment, plant more trees, feed the hungry, put the homeless in houses. But instead, countries use economic warfare to keep nations in debt they can never repay. Young adults are duped into student loans they can never pay off. Governments puppets take bribes from the multinational mega corporations who pay to push agendas that feed their bottom lines only, and not in the best interests of the nations of this planet.
Food – we all need it to survive, we used to have the most incredible produce available to us. Small family farms fed the locals and most people prospered, people grew their own wherever they could. Enter the multinationals and we no longer have a food chain, we have a food-like chain. It’s filled with toxic chemicals and GMO’s; and animals are decimated in their billions to feed the fast food, city lifestyles we have been herded into whilst kept in shocking conditions before they are put down to feed us. Mono crops are destroying the environment and the small farmers at an unprecedented rate.
The media – there are so many people trying to make a difference on this planet, the media is an important tool to let others know where they are and what they can offer. But instead, we are bombarded with a campaign of buy buy buy that cripples your freedom of choice. We are lied to by mainstream media every single day. We are assaulted with messages of fear and hate every few minutes, all day every day on the radio, television, internet, magazines and newspapers to drive the military complex’s agenda.
All these people had a choice. What would you choose if you were in their shoes? If you had unequalled power of at your fingertips, what would you do with it?
But you see, it’s so much easier to just point fingers and complain bitterly from the armchair because the real path out of all of this, takes work; because the answer is not “out there”, it is in you! It takes every one of us looking at ourselves, accepting who we are in all forms and making peace with the parts of ourselves we find offensive. For when you are truly at peace with yourself, you start to see the world through different eyes. And if enough people do this, we have the ability to change everything.
It starts with you.
Well that’s what I think anyway…
Filed under: Leadership
by Veronique Palmer via Views from Veronique
Thursday, June 4, 2015
SPBiz Virtual Conference - 12 days to go!
With less than 2 weeks to go - SPBiz (June 17-18), preparations are frantic! We've been recording sessions, producing "intro" videos (a must-see), developing some fantastic features for our virtual conference platform, working with speakers, sponsors and anchors plus many more tasks to make this a success. Phew!
At this point, we are very excited about the event and would absolutely love for you to be there! Here are 3 reasons why you simply can’t miss it:
1: ONLINE …
No need to travel, book flights or hotels. Just book a room, or a sofa, sit back and get comfortable while watching some of the mastermind's of SharePoint!
2: COMPLIMENTARY …
Our super sponsors have ensured that we can offer this fantastic, first-rate event at no cost to delegates - we can't thank them enough!
3: FUN, SOCIAL and GOOD LOOKING …
The platform is custom built (on SharePoint 2013) and we’ve managed to build a gorgeous looking UI along with some great features such as Chat, Quizzes and of course Hugh Wood’s wonderful Heatmap ;). To make it even more fun there are also plenty of prizes up for grabs!
HOW TO REGISTER IN ONE MINUTE:
1. Go here: http://bit.ly/1AEwgbJ
2. Create an account (this guarantees you can login and access the sessions during the conference!).
3. All done! (Be sure to check your Junk folder in case our confirmation doesn’t arrive).
STILL NEED CONVINCING?
- Check out our amazing line-up of speakers: http://bit.ly/1H459Op
- See the Wednesday Agenda (17th June) : http://bit.ly/1KOCAqc
- See the Thursday Agenda - (18th June) : http://bit.ly/1dOP3wF
KNOW ANY COLLEAGUES THAT WOULD ENJOY SPBIZ?
SPBiz is aimed at people who use or work with SharePoint and want to be more productive! There are probably countless individuals sitting in your office right now that would enjoy the experience of learning from the best! If you think they'd enjoy it, can you spend a minute forward this?
Hope to see you there!
Mark
by Mark Jones via Everyone's Blog Posts - SharePoint Community
Route SharePoint Email from non-prod farms to mail enabled group or SP list.
Why do we need to route emails coming from SharePoint DEV & TEST farms to mail enabled group or SP list. This includes both Nintex and SharePoint alert mails.
Where this can be useful:
-
When carrying out testing for SharePoint alerts or Nintex workflows to confirm delivery of emails to users - this email routing will help validate this.
-
When we move site collections to non-prod farms from PROD accidental notifications to users will not occur.
-
Preventing emails reaching a larger audience sent mistakenly by a workflow or SharePoint alerts.
-
Gauging which users are active on non-prod site collections and notify them when we plan to implement changes to DEV and TEST SharePoint environment.
Issues this may cause:
-
Any power user/user trying to test something in non-prod will not receive emails, they will have to contact SharePoint Support for confirmation of emails or SharePoint support can forward that email to the user.
-
You need to provide “from address” to an SMTP server to the exchange admin and he can setup a rule to route these to a newly created mail enabled group also mention which group/list need to be part of these mail enabled group to receive emails.
|
From Address |
mail enabled group |
Members of the group |
|
DEV FARM: SP2010Dev@contoso.com |
SharePoint Dev Alerts |
|
|
DEV Nintex: SP2010Dev@contoso.com |
|
|
|
TST Farm: SP2010Test@contoso.com |
SharePoint Test Alerts |
|
|
TST Nintex: SP2010Test@contoso.com |
|
by Venu M Gummalla via Everyone's Blog Posts - SharePoint Community
Wednesday, June 3, 2015
Microsoft Ignite & SharePoint/O365 - Outcomes
Well this blog post is coming in quite late as Microsoft Ignite was a little less than a month ago. But I believe in better late than never and there are some good topics that I wanted to follow up with. I was lucky enough to attend Ignite with a great group of folks from Concurrency and was also able to do some great networking to meet new folks in the SharePoint and O365 collaboration world. My initial reaction of Ignite was that it was a little overwhelming at times. Coming from the world of smaller SharePoint conferences having 20k+ people in a giant building with all different types of Microsoft technology led to some long walks and not many deep dive sessions. With the amount of announcements in the Office 365 and SharePoint Server 2016 space that were being discussed it was and still is a challenge to keep up with. Looking at the conference from a strictly SharePoint perspective it felt limited at times. Many of the primary SharePoint sessions were packed to the brim and had to be held in overflow areas. I think this directly spoke to the overwhelming usage that SharePoint has in the enterprise still. I am now very excited to attend the smaller SharePoint specific conferences such as SharePoint Fest and SPTechCon to dig deep into the new experiences. I have been trying to go through all of the videos on Channel 9 but there are so many good ones. If you want to download the videos and slides directly here is a link for instructions on how to do it.
In this post I will try to highlight what I believe to be the best sessions for collaboration around SharePoint and Office 365 and also review my pre-conference predictions.
My prediction outcomes
NextGen Portals
Ok we all knew they were already going to announce something but this still was an exciting topic. The new Knowledge Management portal currently called Codename “InfoPedia” was demonstrated. It was apparent that this portal was still in the early stages of development but their strategy to deploy a KM could be great. The new KM portal will consist of Boards, Articles and Microsites in which users are empowered to generate content quickly in a standardized and already styled way. This leads to a more organically and horizontal growing solution rather than a pre-determined hierarchical solution. Here a great post from Benjamin Niaulin about this topic.
Recommended sessions for this topic:
- Intelligent, Ready-to-Go NextGen Portal in Office 365
- The New Knowledge Management Portal in Office 365
- Behind the Scenes: Engineering NextGen Portal
- Big Bang: The New Universe of Finability and Discoverability
OneDrive for Business Sync Updates
Again we knew this coming but everything announced here was great news. I could write multiple blog posts on all of the new stuff they announced around this topic but here are the juicy highlights. The new OD4B sync client will use the current OneDrive protocol. There will be a unified sync client across OneDrive and OneDrive for Business platforms and the preview and RTM client will be available by end of year. Some other important things to note with the new client:
- Selective sync (everyone have a round of applause for this one)
- No more 20k file limit
- Support for up to 10GB files
- Blocking of unmanaged PCs
- Includes PC and Mac
Recommended sessions for this topic:
- A File’s Future with OneDrive for Business
- I Sync, Therefore I Am: A Deep Dive on OneDrive Sync Capabilities and Roadmap
Simplified Hybrid with SharePoint
I attended the SharePoint Hybrid pre-conference at Ignite and got to see first hand what is coming with hybrid in SharePoint and Office 365. Overall the strategy is clear to me that hybrid will be the new on-premises. There are features that will only be available in Office 365 and Microsoft’s strategy is not to bring you to the cloud but bring the cloud to you. This will allow enterprises to opt-in to hybrid on your own terms. This was very obvious in their hybrid strategy moving forward. Microsoft is trying to make they hybrid experience transparent. I won’t go deep into any of these strategies but if you want to discuss them just shoot me an email or a tweet. Their primary pillars are:
- Hybrid Search
- Hybrid OneDrive
- Hybrid Extranet
- Hybrid Team Sites
- Cloud-drive Hybrid Picker
- In the future with no further info yet…
- Hybrid taxonomy story
- Hybrid DLP
- Hybrid eDiscovery
Recommended sessions for this topic:
- Hybrid Business Connectivity Services with SharePoint Online
- Implementing Next Generation SharePoint Hybrid Search with the Cloud Search Service Application
- MVP Panel: SharePoint On-Premises, Online and Everything in Between
What I hoped to see
Future of Forms
Isn’t this everyone’s favorite SharePoint topic? I came in hoping to hear something about forms, or at least anything. With the incredible amount of announcements there was still nothing new on forms. The current state still exists in which InfoPath 2013 will continue to work in Office 365 and SharePoint Server 2016. The only time I heard forms being discussed in a session was during the MVP panel that I linked to above. The panel confirmed the current state and provided similar input to what I am currently telling my clients. If it is a small list form customization go ahead with InfoPath. If you have a larger and more long term forms requirement it is time to look at a 3rd party or custom development.
Future of SharePoint Workflow
There were not architectural changes announced during Ignite. With a total of 0 sessions and 0 discussions about workflow during Ignite I would tend to lean towards the thought that there will be no architectural changes. Workflow will continue to run on Workflow Foundation 4 as an external resource as it does today on-premises and in Office 365. Now there was some news that will affect workflow creators.
There will not be a SharePoint Designer 2016 but SharePoint Designer 2013 will continue to be supported.
I think this is an important step in the evolution of productivity in SharePoint and Office 365. Obviously SharePoint Designer was built with on-premises as its base. That much control is unnecessary in a cloud solution like Office 365. So on that side it makes sense to start bringing in limits. And of course anyone who has used SharePoint Designer heavily in the past knows it was a very buggy product that loved to crash. It is important to remember that we are over a year away from the release of SharePoint Server 2016 so there will be more news around this topic.
As far as workflow creation, I do believe that this is a step in the right direction and hope to see a browser based workflow creation experience. I will also use this time to plug my session at SPBiz that is directly related to SharePoint Designer workflows. This should be a great free online conference.
Future of Yammer
I was very wrong with my prediction here. I was leaning towards the thought that brand for “Yammer” itself would be going away. It was stated pretty loud and clear that this was not the case. There were multiple sessions around this solution including the Yammer Roadmap. Yammer is here to stay and will have a place in the Office 365 ecosystem. Each experience that comes with Office 365 does have its appropriate use cases. The challenge that we currently are and will continue to face is the confusion around when and where to use an experience. There was even a session around this topic titled How to Decide When to Use SharePoint and Yammer and Office 365 Groups and Outlook and Skype. Obviously if we had to have a major session on this topic there is confusion on what to do. I hope this vision continues to clear moving forward.
One item of note around Yammer and Office 365 is that the UI for Yammer is changing to align better with the rest of Office 365. If you are a part of the Office 365 Network (and if you’re reading my blog and are not, go join it now) you are already seeing these changes happening.
The Site Actions Menu in SharePoint Server 2016 not changing locations from the top right
I can confirm that it is staying in the right from the demos performed. No need for any panic from the community.
Anything else interesting?
I think the winner of most interesting topic during Ignite and so far after Ignite has been Office 365 Groups. Microsoft is putting a ton of time and effort into this collaboration experience. I believe that Office 365 Groups still need some help around the governance and control but they will be a go to solution in the future. Here is a link to a great blog post from Nik Patel that will go into a little more detail. Overall groups will be an experience that encompasses nearly all aspects of Office 365.
Recommended sessions for this topic:
- Microsoft Office 365 Groups Overview and Roadmap
- Microsoft Office 365 Groups Deep Dive
- Collaborate on files and Information within Office 365 Groups
- Evolving Distribution Lists with Office 365 Groups
Here are some other interesting topics and some sessions about each.
SharePoint Server 2016
- The Evolution of SharePoint: Overview and Roadmap
- What’s New for IT Professionals in SharePoint Server 2016
Office 365 Security
- Enterprise Grade Data Protection and Compliance with Office 365: Today and Beyond
- End-to-End Data Loss Prevention
- Ten Ways to Secure Your Office 365 Tenants
- eDiscovery Redefined: Real Time and In-Place
- First Look at Advanced Threat Protection in Office 365 to Stop Unknown Malware and Phishing Attacks
Office 365 Migration API
I look forward to the next Microsoft Ignite conference in 2016 coming back to Chicago on May 9-13. It will be interesting to look back on this post and see how different the landscape moves in just 1 year.
Originally Posted
Microsoft Ignite & SharePoint/O365 - Outcomes
by Drew Madelung via Everyone's Blog Posts - SharePoint Community
Tuesday, June 2, 2015
Configuring Kerberos Constrained Delegation with Protocol Transition and the Claims to Windows Token Service using Windows PowerShell
Recently I’ve done a few pieces of work with SharePoint 2013 Business Intelligence and I have also delivered the “legendary”* Kerberos and Claims to Windows Service talk a few times this year. This reminded me to post my Windows PowerShell snippets for the required Active Directory configuration.
This topic area is perhaps one of the most misunderstood areas of SharePoint Server, and there is an utterly staggering amount of misinformation, out of date information, single server documentation and good old fashioned 100% bullshit out there. That’s a surprise with SharePoint stuff, huh?
Every guide or document out there that I could find talks to configuring Delegation using Active Directory Users and Computers (ADUC). They all also reference configuring Local Security Policy manually, or via Group Policy (without providing the details).
Of course there’s nothing wrong with doing it that way, and it sure makes for a better explanation of the concepts. However back in 2009 when we were working pre-release materials I put together some Windows PowerShell to achieve the same configuration. So here there are in all their very simple glory.
* “Legendary” – I don’t know about that so much, but the Kerberos talks and in particular the AuthN+Z module of the SharePoint 2007, 2010 and 2013 MCM programs were recently described to me as such by five different SharePoint luminaries with rock solid credibility. Those people know who they are.
Every time I give this talk I get hassled for the “magic scripts”. They aren’t magic, but they always seem to surprise people as there is a misconception that delegation settings cannot be set using Windows PowerShell!
As you should be aware, in order to configure identity delegation for a Web Application in Claims mode within SharePoint Server 2010 or 2013 we must configure Kerberos Constrained Delegation with Protocol Transition. No ifs, no buts. It’s the only way it can work because in Claims mode there is no identity with which to perform either impersonation, basic delegation or true Constrained Delegation using Kerberos.
Thus, we make use of a component of the Windows Identity Framework, the Claims to Windows Token Service (C2WTS) to mock real delegation using a Windows Logon Token. C2WTS itself makes use of Service For User (S4U). S4U does NOT perform real delegation, it cannot because there are no user credentials to delegate. It instead grabs a bunch of SIDs for the user (in this case a service identity). What all this means is that there is a hard requirement to use Protocol Transition. Protocol Transition is named in the UI of ADUC as “Use any authentication protocol”.
Thus, in order to set things up, our settings in Active Directory for the C2WTS service identity and the application pool identity of the service application endpoint must be configured to perform Kerberos Constrained Delegation using Protocol Transition to the back end services.
In the example below I am allowing the C2WTS account to delegate to SQL Server Database Services and SQL Server Analysis Services using the SPNs which already exist on their service accounts. I of course repeat the exact same configuration on the application pool identity of the service application endpoint.
In order to complete this configuration using ADUC we are told we must create a “mock” or “fake” SPN on the accounts first. Otherwise the Delegation tab in the account properties does not show up.
The reality is we can easily configure the attributes we are interested in using ADUC in Advanced Features mode, or ADSIEdit. However, there must be an SPN for the delegation to succeed. So it’s not a “mock” SPN at all. It’s not just about exposing the delegation tab. We must have a SPN!
It’s a complete breeze to configure the same settings using the Active Directory module for Windows PowerShell.
- The services to delegate to are exposed by the AD schema extended attribute msDS-AllowedToDelegateTo. This can be manipulated using the standard Set-ADUser –Add pattern.
- The setting for Protocol Transition is actually a UserAccountControl attribute. It’s ADS_UF_TRUSTED_FOR_DELEGATION or 524288. Remember this attribute is a cumulative bitmask. But the thing is we DON’T need to care! We don’t need some stinky “library” or utility function to manage the bitmask stuff or any of that noise. It can all be handled with the Set-ADAccountControl cmdlet with the –TrustedToAuthForDelegation parameter.
- Note TrustedToAuthForDelegation == Protocol Transition, –TrustedForDelegation == Kerberos Only
And that’s it. Two cmdlets basically. A complete snap. Now as always, there’s some slinging needed to do this neatly for real requirements and perform end to end configuration. Here’s the Windows PowerShell script I use for basic setups:
<#
Configures accounts in Active Directory to support identity delegation
spence@harbar.net
February 16th 2009
1. Configures SPNs for SQL DB and SQL AS
- does not check for duplicates
2. Configures SPNs for SharePoint service identities
(C2WTS and Service App Endpoint Identity)
3. Configures Kerberos Constrained Delegation with
Protocol Transition to SPNs in #2
#>
Import-Module ActiveDirectory
## VARS
$sqlDBaccount = "sqldb"
$sqlASaccount = "sqlas"
$c2wtsAccount = "c2wts"
$servicesAccount = "sppservices"
$c2wtsSpn = "SP/c2wts"
$servicesSpn = "SP/Services"
$sqlDbSpns = @("MSSQLSvc/fabsql1.fabrikam.com:1433", "MSSQLSvc/fabsql1:1433")
$sqlAsSpns = @("MSOLAPSvc.3/fabsql1.fabrikam.com", "MSOLAPSvc.3/fabsql1")
$delegateToSpns = $sqlDbSpns + $sqlAsSpns
## END VARS
$delegationProperty = "msDS-AllowedToDelegateTo"
Write-Host "Configuring SPNs for SQL Server Services..."
$account = Get-ADUser $sqlDBaccount
$sqlDbSpns | % {Set-AdUser -Identity $account -ServicePrincipalNames @{Add=$_}}
$account = Get-ADUser $sqlASaccount
$sqlAsSpns | % {Set-AdUser -Identity $account -ServicePrincipalNames @{Add=$_}}
function ConfigKCDwPT($account, $spn) {
$account = Get-ADUser $account
$account | Set-ADUser -ServicePrincipalNames @{Add=$spn}
$account | Set-ADObject -add @{$delegationProperty=$delegateToSpns}
Set-ADAccountControl $account -TrustedToAuthForDelegation $true
}
Write-Host "Configuring KCDwPT for C2WTS and Services Account..."
ConfigKCDwPT $c2wtsAccount $c2wtsSpn
ConfigKCDwPT $servicesAccount $servicesSpn
Write-Host "KCDwPT configuration complete!"
OK, so that’s the AD account configuration settings all taken care of. What about the C2WTS itself?
If we run C2WTS as it’s default identity, LocalSystem we don’t need to do anything. But that’s a really stupid configuration. Why? Because in a real farm you have more than one machine running C2WTS. That means multiple points of configuration (on each computer object in AD). In addition any mistakes you make during configuration (say you fat finger the SPN) require a machine restart for corrections to take effect. Thus there is a compromise between manageability, configuration approach and security.
The reality is that the security element of the compromise is completely null and void from a technical or information security perspective. The old arguments about TCB are now completely out-dated, and besides were invented by people who didn’t know information security and were designed for single server solutions! However, if you are unlucky enough to work with those customers with out-dated security policies so it remains part of the compromise on those grounds alone.
Everyone else with any sense will change the identity to a named service account. If we do this, we also have to grant additional User Rights Assignments to the account in order for it to be able to call S4U. These are Act as part of the Operating System and Impersonate a Client after Authentication. The account must also be a member of the Local Administrators group on each server it runs. All of this can be done via Computer Management and Local Security Policy, or properly via Group Policy.
However it’s also a complete snap to configure this stuff using Windows PowerShell, making use of an old school utility or the Carbon library. Here’s the script:
<#
Configures C2WTS service identity with appropriate user rights
spence@harbar.net
February 16th 2009
1. Configures Local Admins memebership
2. Configures User Rights Assignments using NTRights
(update with path to WSRK)
3. Configures User Rights Assignments using Carbon
(http://ift.tt/1AJFuJG
Third-Party-Sources/http://ift.tt/1AJFx8h)
#>
asnp Microsoft.SharePoint.PowerShell
## VARS
$user = "fabrikam\c2wts"
$CarbonDllPath = "C:\Tools\Carbon-1.6.0\Carbon\bin\Carbon.dll"
## END VARS
# adds user to local admins group
NET LOCALGROUP Administrators $user /ADD
# sets up the neccessary local user rights assignments using NTRights
C:\Tools\rk\NTRights.exe" +r SeImpersonatePrivilege -u $user
C:\Tools\rk\NTRights.exe +r SeTcbPrivilege -u $user
# sets up the neccessary local user rights assignments
[Reflection.Assembly]::LoadFile($CarbonDllPath)
[Carbon.Lsa]::GrantPrivileges($user, "SeImpersonatePrivilege")
[Carbon.Lsa]::GrantPrivileges($user, "SeTcbPrivilege")
Note we do NOT have to set the c2wts account to Logon as a Service, as this User Right Assignment is granted when we change the service identity within SharePoint…..
On a related note, I’ve also been asked for my snippets for managing the c2wts process identity. TechNet has incorrect scripts for this work, which will only ever work on a single server farm (ooops!). Here’s how to change it properly, and also how to reset it back to LocalSystem (properly!).
<#
Configures C2WTS service identity
spence@harbar.net
February 16th 2009
1. Sets dependency
2. Sets desired process identity
#>
asnp Microsoft.SharePoint.PowerShell
## VARS
$accountName = "FABRIKAM\c2wts"
$serviceInstanceType = "Claims to Windows Token Service"
## END VARS
sc config c2wts depend=CryptSvc
# configure to use a managed account
# Should use farm, otherwise in multi server farm you have an array of objects!
$farmServices = Get-SPFarm
$c2wts = $farmServices.Services | Where {$_.TypeName -eq $serviceInstanceType}
$managedAccount = Get-SPManagedAccount $accountName
$c2wts.ProcessIdentity.CurrentIdentityType = "SpecificUser";
$c2wts.ProcessIdentity.ManagedAccount = $managedAccount
$c2wts.ProcessIdentity.Update();
$c2wts.ProcessIdentity.Deploy();
$c2wts.ProcessIdentity
# reset to local system
# Should use farm, otherwise in multi server farm you have an array of objects!
$farmServices = Get-SPFarm
$c2wts = $farmServices.Services | Where {$_.TypeName -eq $serviceInstanceType}
$c2wts.ProcessIdentity.CurrentIdentityType=0; #LocalSystem
$c2wts.ProcessIdentity.Update();
$c2wts.ProcessIdentity.Deploy();
$c2wts.ProcessIdentity
Note I use this script to also configure the missing dependency on the Windows Service itself. We can of course start the C2WTS easily as well:
# start c2wts on server(s)
$servers = @("FABSP1", "FABSP2")
foreach ($server in $servers)
{
Get-SPServiceInstance -Server $server | Where {$_.TypeName -eq $serviceInstanceType} | Start-SPServiceInstance
}
Nice and easy. No pointy clicky click click or “Working on it…” needed. The entire end to end configuration in Windows PowerShell takes less than 90 seconds.
s.
by Spence via harbar.net
Office 365 Video: My first impression
I've had the opportunity to look into the possibilities for organizations to use Office 365 Video. Using videos within an organization can be a great way to connect to your employees. This could be a welcome video from the new CEO, a safety regulation video or training material to help new employees get on their way.
Homepage
The Video portal homepage consists of a few key sections. The Spotlight area gives you the possibility to show videos, which have a strong presence on the homepage. The Popular videos section shows videos that are popular within your organization. The last section is the Spotlight channels. Here you can select 3 channels, from which you show the spotlight videos on your homepage.
Office 365 Video portal settings
The popular videos in particular is a great way to see which videos are popular in your organization. The only downside is that an administrator cannot remove or influence the popular video section.
For each video on the homepage you can see the total views and the length of the video.
Personally, I would like to have a little more control over the Office 365 Video homepage. For instance, a channel overview on the left or right side of the screen would be useful to navigate between channels. The possibility to view a video from the homepage could be easier as well, as now you have to click the context action menu (the 3 dots). A pop-up will be shown, starting the video.
Channels
Besides showing videos on your homepage, an administrator has the possibility to create channels. Permissions can be set per channel to allow only certain people (or groups) to view the videos in the channel.
When an administrator creates a channel, a SharePoint Online site collection is created in the background. This is where the video and all metadata will be saved. A copy will be sent to Azure Media services. Microsoft posted this nice video on YouTube explaining how this works behind the scene.
The channel creation process could be more smoothly, as the administrator is required to wait for the site collection to be created, which takes some time. When you close the window while a channel is creating, the channel will still be created, but the channel color you selected won’t be saved. It would be nice if the creation could happen behind the screens, so the administrator doesn’t have to wait for the site collection to be provisioned.
Video
While watching a video, Office 365 Video provides you with several options. You can share the video, see the description of the video, or even comment on the video by using the inline Yammer conversation on the right side of the screen. Below the video is a list of videos that you may also like.
Videos will be processed and displayed in Delve as well. This is a really neat feature that helps employees engage with Office 365 Video without actually navigating to Office 365 Video in the first place, as relevant videos are being showed in Delve.
Conclusion
In conclusion: Office 365 Video is a great initiative that has a lot of potential. At the moment of this writing, I think the service could still be improved by integrating Office 365 Video with other Office 365 services even more. In particular, some of the features that SharePoint online has, could help make Office 365 Video even better. As Office 365 Video is still a relatively new service, I expect Microsoft will make regular improvements that will add business value organizations.
If you are currently testing or using Office 365 Video, make sure to provide feedback to help improve the service. On the top right corner of each page you will find the option to send Feedback to Microsoft.
by Nico Martens via Everyone's Blog Posts - SharePoint Community