Showing posts with label sharepoint 2013. Show all posts
Showing posts with label sharepoint 2013. Show all posts

Wednesday, October 22, 2014

Multiple Prompts SharePoint

If you are like me and many other SharePoint admins out there, you have run into this problem.

Scenario One: User launches SharePoint page from inside the domain and they get prompted for credentials.
Scenario Two: User launches SharePoint through VPN and gets prompted for credentials.
Scenario Three: Every resource or new site prompts the user for credentials.
Scenario Four: Extranet SharePoint site continually prompts for credentials.

In this days and age of (SSO) Single Sign On, users expect to log in once and then never be prompted again. Personally I have my Facebook and Google+ connected all over the place so that I can get into just about everything with-out prompting. Unfortunately internal corporate solutions require a little more security. Even more unfortunately SharePoint is extremely sensitive to security configurations, everything from the servers registry to the security on the databases. If you do a quick Google search you will see page after page of possible solutions, and for the most part they are all correct; but. they are correct for different causes. In most cases you are actually being plagued by several issues causing the same problem. So I will do my best to consolidate all of the solutions out there.

Solutions:
1. Internet Security - Ensure that your local security policy, group policy, or basic internet settings have your SharePoint site set in Trusted sites, or Local intranet. This is probably the easiest and least invasive thing you can do.

  • Make sure that you have a couple things configured properly for your local intranet, or trusted sites setting. First, ensure that 'Automatic Logon' is enabled. If your SharePoint URL contains periods then IE automatically assumes that it is on the internet. You can read more on the Technet site

2.Verify that you have correctly configured your alternate access mappings in SharePoint - 2013, 2010

3. Modify your Web.Config

<system.webServer> 
  <security> 
    <requestFiltering allowDoubleEscaping="true"> 
      <verbs allowUnlisted="true"> 
           <add verb="OPTIONS" allowed="false" /> 
          <add verb="PROPFIND" allowed="false" /> 
       </verbs> </requestFiltering> 
     </security> 
</system.webServer>


4. In IIS modify the web application to use NTLM instead of Kerboros

5. Dealing with an Extranet requires a little more configuration to your servers if you wish to avoid credential prompting.
From Technet
"Extranet users that want direct editing:
Use Forms Based Authentication (FBA) with persistent cookies – The only way to maintain direct-edit functionality and also not be prompted by the Office application is to implement a proxy/firewall server by using Forms Based Authentication with persistent cookies such as an Internet Security and Acceleration (ISA) server or a Forefront Threat Management Gateway.
Extranet users and direct editing is not needed:
Disable Client Integration or the OPTIONS/PROPFIND Verbs  -  If the site provides WebDAV functionality through another extension, the provider of that extension should be engaged. For example, to do this with Windows SharePoint Services (WSS), the site should be configured to disable Client Integration, or the OPTIONS and PROPFIND verb should be inhibited. (To inhibit the OPTIONS and PROPFIND verbs on Internet Information Services (IIS) version 6, remove the verbs from the registration line in the web.config file. On IIS 7.0, use the HTTP Verbs tab of the Request Filtering feature to deny the verbs.) Be aware that this approach will open the content in read-only mode because this approach disables direct-edit functionality."

Wednesday, March 20, 2013

SharePoint Site Collection Backups Out of the Box

In this article I am going to show you a very simple way that you can configure your SharePoint Site Collection Backups using Powershell. These Powershell scripts were written for 2013, but should work for 2010 as well.

   There are a couple of different types of backups that you can accomplish by using Powershell; Farm Backups - Full, Farm Backup - Differential, Site Collection Backups, and Configuration Database Backups.
   You can technically accomplish a granular backup of all content, but this isn't really a backup as much as a site copy, and I won't be going into that at this time.

Although I personally run all of these backups, my experience is that the most utilized backup is the Site Collection Backup. So lets go ahead and get started.

The first step of any Powershell script is ensuring that the proper scriptlets are loaded, SharePoint is no exception.

1: To load the SharePoint Scriptlet into your SharePoint Script add the following lines

#Add the SharePoint Snap-in, in case PowerShell wasn't started with the Management Shell
Add-PSSnapin microsoft.sharepoint.powershell -ErrorAction SilentlyContinue


2: The code in this piece of the script will enumerate all site collections within a web-app and then return them to the variable $sites

#Enumerate Sites
$sites=Get-SPWebApplication "Web App URL or Name" |
    Get-SPSite -limit ALL


3: Now that you have your variable of Site Collections, you want to loop through them and back them up. It will also name all of the backup files based on the site collection Title.


#Back-Up Sites
foreach($site in $sites)
{
Backup-SPSite -Identity $site.Url -Path "$backuppath$((Get-SPWeb -Identity $site.Url).Title).bak" -Force -Verbose
Write-Host "Successfully backed up $($site.Url) to $backuppath$((Get-SPWeb -Identity $site.Url).Title).bak"
}

4: The final step of this process it to schedule the backups. This must be done from one of your Web Front Ends (WFE), simpley just launch your task schedule and add your .ps1 file, ensure that the account you are using has full privileges to the site collections.


Here is the script in one piece.
#Add the SharePoint Snap-in, in case PowerShell wasn't started with the Management Shell
Add-PSSnapin microsoft.sharepoint.powershell -ErrorAction SilentlyContinue

#Enumerate Sites
$sites=Get-SPWebApplication "Web App URL or Name" |
    Get-SPSite -limit ALL

#Back-Up Sites
foreach($site in $sites)
{
Backup-SPSite -Identity $site.Url -Path "$backuppath$((Get-SPWeb -Identity $site.Url).Title).bak" -Force -Verbose
Write-Host "Successfully backed up $($site.Url) to $backuppath$((Get-SPWeb -Identity $site.Url).Title).bak"
}

Tuesday, March 19, 2013

New Blogger

So, I have stayed out of the blogging arena for years, but at some point I realized that I had valuable information with no real way to get it out there. Thus the blog! Most likely this blog will be focussed on my SharePoint endeavors, both 2010 and 2013, much of which will probably be powershell related. So if this is something you are interested in, stay tuned, I have some good stuff to share!