Quantcast
Channel: File Services and Storage forum
Viewing all 13565 articles
Browse latest View live

Automatically revoking write permissions from a shared folder in Windows Server 2012 R2/10

$
0
0

Hi everybody,

Good day to you!!

I want to share a folder with other window's users (Let's say Server 2012 or Win 10) on my network and want to give them only write permission for a certain period of time (Let's say 4 hours). Is there any way so that the write permission is automatically revoked and user's won't be able to write anything in the shared folder after 4 hours?

Do I need to write a script or is there any straight forward way?

Best,

/ Karim


DFSR replicating between Server 2008R2 standard and Server 2016 standard?

$
0
0

Hi Everyone

Currently all of our file servers are running Server 2008R2. We rely heavily on DFSR to have local copies of the core network shares in the main international offices for performance (c. 1TB each).

I'm now at the point where I have some old hardware to replace and am considering moving to Server 2016 so it can run for the next several years without being touched. The replication hub is in the USA replicating out as far as China.

My Questions are

1) Can Server 2016 happily DFRS replicate with a central replication hub Server running 2008R2?

2) If Yes, can this work with only 2008R2 domain controllers (2008R2 forest functional level running)?

Thanks in advance

Mark

Permissions... Write-only not working.. Must grant Modify access

$
0
0

Hi, all:

I am attempting to give employees write-only access to a share I've created, but for whatever reason, they're unable to write to said folder... However, if I give them modify access, they're able to write to it then.

I created OU folders by project (we're a construction company), and I've got a write and modify AD group for each project. I'd like to give just write-only to some people, and modify (delete/change) access to others. Please let me know if I'm not following something here... Advanced permissions on the shared folder itself has full access, and the permission on the share has read to users (of the "read" or read/write" options)...and I mean the SHARE itself, not the subfolders I'm attempting to add the ACL to.

Thanks,

Aaron



FSRM Notification Variable

$
0
0
I'm currently enabling folder quota managment from the FSRM role on Windows Server 2012 R2.  I have a limit set on the home directories, so the enduser doesn't go over this amount.  I have notifications set for the administrator, which works.  The issue is when I enable notifications for the 85% threshold, the enduser never gets any notification.  I have tested on myself with the same results.  Nearest I can figure is that the username for the login is not the same as the email address.  Our usernames are shorten to 8 characters, which is from the days of old.  Is there a workaround for this issue?

2012r2 DFSR Not reporting for single server

$
0
0

Our environment has several domain controllers, including one that is in a vendor's managed cloud. We just recently removed the last 2008 server and have now updated our domain and forest levels to 2012r2. One of the first things I want to do is move from FRS to DFS. I'm following the blog post at (blogs.technet.microsoft.com/filecab/2008/02/08/sysvol-migration-series-part-1-introduction-to-the-sysvol-migration-process/) for this. I've gotten to the point of running 'dfsrmig /getmigrationstate' repeatedly to make sure all DCs are showing as 'Prepared'. It's been at least 5 hours and all but one of our DCs is done. 

As I'm sure you've guessed, it's the one in our vendors managed cloud. Per their requirements, it has to be behind their firewall and we have to specifically request ports to be opened on an as needed basis. I've looked through all of the technet articles and am fairly sure that we have all of them open between this remote server and two of our DCs (including the PDC). 

For reference, here are the ports that are opened:

25	TCP
42	TCP
67	UDP
137	TCP
137	UDP
138	UDP
139	TCP
636	TCP
2535	udp
3269	TCP
9389	TCP
135	TCP
389	Tcp
389	UDP
3268	TCP
88	TCP
88	UDP
53	TCP
53	UDP
445	TCP
445	UDP
5722	TCP
464	TCP
464	UDP
123	UDP
1024-5000	TCP
1024-5000	UDP
49152-65535	TCP
49152-65535	UDP

I've gone onto the offending server and confirmed the following:

  • C:\windows\sysvol_DFSR exists and is populated
  • I can ping both DCs from this server without issue
  • DFSRDiag /pollad to either of the DCs comes back as 'Operation Succeeded'
  • Sites/Services has replication links created b/t the two DCs and the problem server
  • repadmin /show repl shows successful for all queries
  • DFSDiag /testdcs is successful on the two DCs it can reach, errors out on the others
  • Running repadmin /syncall /AeD fails for the DCs it can't see. Succeeds for most of the tests...
  •    PDC response for 'syncall' is "(network error): -2146893041 (0x8009030f): The message or signature supplied for verification has been altered."
  •    Other DC response for 'syncing partition' is "(network error): -2146893041 (0x8009030f): The message or signature supplied for verification has been altered."

For all intents and purposes, I believe that the replication has taken place, but the server can't report it back to the rest of the domain. 

When I go to ADSIEdit per this solution (social.technet.microsoft.com/Forums/windows/en-US/7730f4e2-c5f2-4c21-bcde-c30c5d25ef9a/migrating-sysvol-to-dfsr-one-server-stuck-when-using-getmigrationstate-but-it-looks-ok-locally?forum=winserverDS) on the PDC, I do not see any folders under 'OU=Domain Controllers\CN=OtherDC'. However, when I look on the problem DC, I do see the folders that should be there.

I've also checked in the DFS management console, but this problem server doesn't show up in there as part of the replication

I did just run 'DFSRMig /getglobalstate' and it shows 'Current DFSR global state: 'Prepared"

My question(s) are: What could be blocking the remote server from reporting its DFSR status to the PDC? Since I can see it replicated and the globalstate is 'Prepared', can I go ahead and move forward with the migration?


DFS Replication Fails - Reports Disk Space Low, but it isn't

$
0
0

I'm new to DFS but have inherited managing my new employer's remote site replication and all the errors it's been having since last year. I've increased the Staging folder sizes, where required, to meet or exceed Top32 on the 14 remote servers and our corporate DFSR hub server. I have also calculated the remote server replicated folder size, Staging quota, and ConflictandDeleted folder sizes so I could adjust the size of the 14 volumes holding the replication folders on our hub server to accommodate the calculated sizes plus 20%.

So far most replication groups have started replicating again with very few, or no, errors. Of course there is always one problem child, and the one I have is driving me nuts. I've had to increase the hub server volume size for remote site"C" a couple additional times to get replication started again and each time it will work for a couple days before throwing the disk space error again.

                            SERVER C            HUB SERVER
                             Size / Free          Size / Free
Physical Disk         1.53 / 1.19 TB    205 / 54 GB
Replicated Folder               130 GB          148 GB
Conflict&Deleted              5 / 0 GB       5 / 2.5 GB
Staging                          35 / 3 GB      35 / 18 GB 

Also, I followed the process outlined in this article Implementing Content Freshness to kickstart the replication of this folder and it seems to have done the job other than the issues with folder size. The hub server is configured as a read-only partner and I don't understand why the replicated folder on the hub server continues to grow larger than the source member of the replication group rather than match the size. 

I greatly appreciate any help/guidance you may provide with resolving this,

Frank


Frank Boyd


How much secure when I store data in regular drive?

$
0
0
Currently I am using my local drive to store data from many sources. EFS is enable in system and other folder drive which I believe secure my data other than password protected folder. Can any one give enough detail about data security in any drive and folder?

WorkFolders - Access denied when File Screening is active

$
0
0

Hey,

We are testing Work Folders and for now everything works alright. We found out that we can apply quota so users will have 10GB space and it works, but we also we want to exclude some file types. We have tried to apply File Screening, but it seems it's not working properly.

server: Windows Server 2012R2
client: Windows 10 Pro 1803

File Screening: for testing - exclude *.exe only.

When passive: users can sync whatever they want
When active: users can't sync exe file, which is good, but also can't sync anything else, in the event viewer, for .txt file:

Event ID: 2114
Source: WorkFolders
Action: (FSP_EVENT_ACTION_UPLOAD)
HResultStr (0x80070005) Access is denied.
Hresult -2147024891

For exe file event looks okay, it just says that this file type is not allowed on this share.

I googled and couldn't find anyone having same problem.

Robocopy from 2008 R2 to 2016 Oddity

$
0
0

I am preparing to migrate one of our file servers from 2008 R2 to 2016, both virtual.  The files appear to copy without an issue to the new server, but when I attempt to access the folder with Windows Explorer, I get an error "You don't currently have permission to access this folder.  Click Continue to permanently get access to this folder."  If I go into Properties and then the Security tab, it tells me "you must have read permissions to view the properties of this object.  Click Advanced to continue."  If I click Advanced, the owner area says "Unable to display current owner." and the permissions tab basically repeats the Read permissions to view properties error but tells me to hit continue.  If I hit Continue, it shows me the security.  I have tried to a few different things but can't seem to get this working and was hoping for some feedback.

The command I am using and running from the 2016 box is.

robocopy "\\2008R2Server\data\Folder" "D:\Data\Folder" /Log:D:\_Migration\Logs\Data.txt /LEV:0 /NP /R:1 /W:10 /E /TEE /MIR /xf *.pst

I have tried adding /COPYALL.  I tried copying files in reverse, meaning going from 2008 R2 to 2016.  All with the same result.  What is interesting is that I copied this script from a previous file server migration I performed but that was 2008R2 to 2012R2. 

Thanks for any assistance.


EDIT : Forgot to state that I am looking to keep the security that was set on the 2008 R2 file server.  I am also using my Domain Admin account that is an administrator on both servers.  I have full control on everything.

Server Manager 2012 not displaying Volumes

$
0
0

I am running server 2012 standard.  When I go to Server Manager --> File and Storage Services --> Volumes server manager does not display the available volumes.  It just says "Loading data" forever.

THis is causing issues with my backups because I am also unable to run a server backup using windows server backup because it never gets to the point where it displays a list of drives to backup (i assume for the same reason that Server Manager is failing to display volumes).

Same story with powershell.  When I run "get-wbvolume -All" it just hangs and never returns anything.

Unfortunately there is not anything being logged in event viewer or any error messages to indicate why... it's just not doing it.

Any help is greatly appreciated.

FSRM - E-Mail Error code: 0x80004002, No such interface supported

$
0
0

Hello all,

Within FSRM i get an error message when sending a report.
When i check the Application-log i get this:

<?xml version="1.0" encoding="utf-8" standalone="yes"?><Events><Event xmlns='http://schemas.microsoft.com/win/2004/08/events/event'><System><Provider Name='SRMSVC'/><EventID Qualifiers='32772'>8201</EventID><Level>2</Level><Task>0</Task><Keywords>0x80000000000000</Keywords><TimeCreated SystemTime='2018-07-06T10:27:13.000000000Z'/><EventRecordID>197772</EventRecordID><Channel>Application</Channel><Computer>COMPUTER.DOMAIN.LOCAL</Computer><Security/></System><EventData><Data>CoCreateInstance for registry supplied class {6C2C1D33-40EA-4941-908C-7DDF0864FFCA} of IID_IFsrmEmailExternal failed</Data><Data></Data><Data>0x80004002, No such interface supported</Data><Data></Data><Binary>2D20436F64653A20454D4C4E54524C4330303030303137372D2043616C6C3A20454D4C4E54524C4330303030303038332D205049443A202030303030323839362D205449443A202030303030373230302D20434D443A2020433A5C57696E646F77735C73797374656D33325C737663686F7374202D6B2073726D7376637320202D20557365723A204E616D653A204E5420415554484F524954595C53595354454D2C205349443A532D312D352D313820</Binary></EventData><RenderingInfo Culture='nl-NL'><Message>File Server Resource Manager Service error: Unexpected COM error CoCreateInstance for registry supplied class {6C2C1D33-40EA-4941-908C-7DDF0864FFCA} of IID_IFsrmEmailExternal failed: .  Error code: 0x80004002, No such interface supported
. </Message><Level>Error</Level><Task></Task><Opcode></Opcode><Channel></Channel><Provider></Provider><Keywords><Keyword>Classic</Keyword></Keywords></RenderingInfo></Event></Events>

With Basicly this error:

File Server Resource Manager Service error: Unexpected COM error CoCreateInstance for registry supplied class {6C2C1D33-40EA-4941-908C-7DDF0864FFCA} of IID_IFsrmEmailExternal failed: .  Error code: 0x80004002, No such interface supported
- Code: EMLNTRLC 177
- Call: EMLNTRLC 83
- PID:2896
- TID:7200
- CMD:C:\Windows\system32\svchost -k srmsvcs
- User:Name: NTAUTHORITY\SYSTEM, SID:S-24


i have tried to re-register som DLL files, without effect.

Sending mail messages using the same server, smtp adres, recipients etc does work.

what else can i do ?


Bus Enumeration of PCI cards

$
0
0

Hi,

We're using HPE ProLiant DL380 Gen9 servers for our S2D deployment. We have added in 3 HPE 240 HBAs (for a total of 24 drives) in each node and are fully loading the drive bays with 20 HDD disks and 4 SSD for caching. These HBAs are in PCI slots 4, 5, 6 respectively.

We want to marry up physical disk slots with the disk numbers in Windows for ease of identification. We cabled up caddy 1 to HBA in slot 4, caddy 2 to HBA in slot 5 and caddy 3 to HBA in slot 6. This is left-to-right.

We put the SSDs in the last for slots in caddy 3 expecting them to be the last disks in Windows, but it turns out they are 1-4. What's even stranger stranger is that there seems to be no organisation from what HP's Storage Administrator is showing because port 1 on a controller has been given higher disk numbers than port 2. For example slot 1 port 1 on HBA in PCI slot 4 has been given the highest disk number (24) so not even order of ports on the controller/caddy are right!

disk details

$
0
0

Hi experts

i am not sure this question should be asked here.

i have a HPE servers and it has san disks attached. is it possible to know the ldev details of those disks from command line as the storage software which is installed on it is corrupted. the server is windows server 2008 R2

FSRM- Email Notification is not working

$
0
0

Hi All,

I configured hard quota for a folder through FSRM and configured email notification like 85%, did't getting email when quota is breached.

Note: When i am doing test email from configure option, it is working fine and am getting email from FSRM.

Can someone help me on this?

Regards,

Pradip Sisodiya


Pradip Sisodiya

Redirected Folders on DFS Share with Primary Computer - Files are synching on remote server when connecting through RDP session

$
0
0

We have Redirected Folders configured on DFS shares with Primary Computers assigned to each user. Many of these users use RDP sessions into other servers to do some of their work and for some reason offline files are synchronizing on those servers as well as their assigned primary computers. Any idea what could cause this?


User able to access folder without any permission

$
0
0

Hi,

I have a user who is able to access a private folder and I have no idea as to why.

If you select any folder or file and look at their effective permissions there is none.  The folder isn't shared either.

The only users who have access are IT and the MD.  No other user in the company can access this folder just this one user.  I have even put her as Deny for the folder and contents which didn't work.  I am lost as to what to try.

Any help would be greatly appreciated.


Server: Windows 2012 R2 File server
Fully updated

Different share folder permission on two different computers

$
0
0

Hi,


I have scenario 

  1. Active Directory (Windows Server 2016)
  2. File Server (Windows Server 2016)
  3. VM work station (Windows Server 2016)
  4. Laptop (Windows 10 Enterprise LTSB, access via DirectAccess)

I'd like to have write permission to shared folder for user on the laptop and read permission only on the VM work station for the same user.


How do I achieve this goal via GPO?


Restrict user permissions

$
0
0
Hi,


We have Windows server 2012 DCs.


We need to create a shared folder. We want to share this to domain users who use workgroup computers. We want to restrict the user to only see and open the files and folders. We want to restrict them from copying or printing it.


Please let me know the resolution. If this only works with ADRMS, please let me know about the license requirement also.

Non-converged network for SMB traffic

$
0
0

Hi,

I search around for non-converge NIC for SMB traffic but did not find any solution. So here is my question..

I have 2 x Mellanox ConnectX3 Pro Dual Port 10Gbe SFP+.

The plan is to have 2 ports from each card be team in SET for Management and other traffics. The other 2 ports will each use physically for SMB (storage traffic) only. I have SET team for management working now. How do I setup the physical NIC ports for storage traffic? any help, guide will be highly appreciated. Thanks!

Yarra


Yarra G

DFS Referrals + Slow-link mode

$
0
0

Hey,

It's been so long since I looked at this... can someone remind me the difference between a root referral and link referral, and what happens in practice - what a client does with the 2 types of referrals.

Our root referral is 300 seconds (5 minutes) and link referrals are 1800 seconds (30 minutes).

Also, is this a valid configuration for slow-link mode. I want the root to be latency 32000, all links latency 30 with 10Mb throughput, but override public to just latency 120. Or will the * override/conflict with public

Thanks


Viewing all 13565 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>