Showing posts with label SharePoint 2013. Show all posts
Showing posts with label SharePoint 2013. Show all posts

Thursday, March 12, 2015

Permission Issues Opening/Editing Office Web Apps Documents SharePoint 2013


Symptoms:

Users provided access to SharePoint through Active Directory (AD) Security Groups may  not be able to edit documents via the browser using Office Web Apps (OWA) without error.

In this scenario, the error from the Word App is: "There's a configuration problem preventing us from getting your document.  If possible, try opening this document in Microsoft Word."

We may find the following information after analyzing the ULS logs from the Office web apps Server and SharePoint Server.

From Office web apps server: (OWA folder in Logs)

w3wp.exe (0x113C) | 0x31C0 | Office Web Apps | WAC Hosting Interaction |
 ajryn | Unexpected | WOPICheckFile,WACSERVER ConfigError [error:The
 SharePoint site appears to have its UPA in an improper sync state.  Please
 contact the SharePoint administrator.  The SharePoint site's WOPI handler
 has determined that the user permissions for this file/folder do not match
 the user permissions when wopiframe.aspx was loaded. |
 WOPICheckFile,WACSERVER | Host Status Code: Unauthorized | Host Error Info:
 SyncUPA, url:https://URLofSite/_vti_bin/wopi.ashx/files/GUID...., host
 correlation:]

w3wp.exe (0x113C) | 0x31C0 | Office Web Apps | WAC Hosting Interaction |
 adhsk | Unexpected | WOPI CheckFile: Catch-All Failure
 [exception:Microsoft.Office.Web.Common.EnvironmentAdapters.ConfigErrorExcept
 ion: The SharePoint site appears to have its UPA in an improper sync state.
 Please contact the SharePoint administrator.  The SharePoint site's WOPI
 handler has determined that the user permissions for this file/folder do not
 match the user permissions when wopiframe.aspx was loaded. |
 WOPICheckFile,WACSERVER | Host Status Code: Unauthorized | Host Error Info:
 SyncUPA

Cause:

http://support.microsoft.com/kb/2908321

This issue can occur if the User Profile Application (UPA) is out of sync.
 If a user profile and the relevant group memberships for the user are not
 synchronized, SharePoint Server 2013 may incorrectly deny access to a given
 resource.

Resolution:
  1. Delete the user from the User Profile database in SharePoint Central Administration
    1. SharePoint Central Administration
    2. Application Management
    3. Manage Service Applications
    4. User Profile Synchronization Service
    5. Manage User Profiles
    6. Search for user
  2. Go to top level site collection with admin privileges
  3. Open the page https://siteurl/_layouts/people.aspx?MembershipGroupId=0 (all users in the site collection)
  4. Find your user, right click the name, and copy shortcut (url to the user's profile page)
  5. Paste the shortcut into the browser address field and append to it (don't press Enter yet): append Force=True (http://servername/_layouts/userdisp.aspx?ID=25&Force=True), press Enter
  6. Click on "Delete User from site collection" link on the toolbar
  7. From Central Administration, start a Full User Profile Synchronization.  Wait until this finishes to continue.
  8. Check that the user now exists in the User Profile database
  9. SharePoint Central Administration
  10. Application Management
  11. Manage Service Applications
  12. User Profile Synchronization Service
  13. Manage User Profiles
  14. Search for user
  15. Add the same user back to the SharePoint group in the Site Collection
  16. Test

Tuesday, December 16, 2014

Farm is unavailable - Registry Error After SP1 or CU

SYMPTOMS:
1.  SharePoint front end or application server is not working (ie .net error msg)
2.  You have an application error something like parameter incorrect server
3.  Errors in Event Log about the server not being part of the farm
4.  Timer jobs in Central Administration are paused for a specific server in the farm

RESOLUTION:
Check the following registry key and change if it contains an incorrect value (Note: it's best to copy value from another server in the same farm if need be)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\Web Server Extensions\15.0\Secure\ConfigDB

Key: dsn
Type: REG_SZ


Incorrect Value:
Connect Timeout=30

Correct Value Format: (Note: You can also copy the correct value from the same registry key of another server in the same farm)
Data Source=YOUR_SQL_SERVER_MACHINE;Initial Catalog=YOUR_SHAREPOINT_CONFIG_DB_NAME;Integrated Security=True;Enlist=False;Pooling=True;Min Pool Size=0;Max Pool Size=100;Connect Timeout=15


No need to restart the server.  It will automatically become a member of the farm again.  But you can restart the server if it gives you a warm fuzzy, it was already "down" anyway.  You will notice in CA that the paused timer jobs will start processing again.