Friday, November 14, 2014

PowerShell and Scheduled Tasks

I have been setting up some schedule PowerShell scripts through the Task Scheduler; however, I was having a bit of trouble with one of the scripts. 

The script would run perfectly if I ran it manually, but when I ran the task nothing would happen. As you might know this is a bit of a problem because schedule tasks don't not show the console, and won't allow you to see the errors. The Task's log are not very helpful either.

What helped me troubleshoot the problem is this little cmdlet:

Start-transcript -path C:\Temp\Filename.txt

Placing that command at the beginning of your script will create a transcript file. The transcript file will contain everything that would print into the console, and it should look a little like this:


-------------------------------------------------------------

**********************
Windows PowerShell transcript start
Start time: 20141114101902
Username  : DOMAIN\S.AD.Util 
Machine  : HOSTNAME (Microsoft Windows NT 6.3.9600.0) 
**********************
Transcript started, output file is C:\Temp\Transcript_11-14-2014.txt

ModuleType Version    Name                        ExportedCommands     
---------- -------    ----                        ----------------     
Script     1.0        tmp_scev4zye.pet          {Get-DServerSetti...

-------------------------------------------------------------

If there is any errors they will show here, even if they are not stopping errors. Which is great because at one point my script was sending the email and successfully completing, but failing to create the report all together and sending a blank email.

I hope this might help someone out there! 

Wednesday, November 12, 2014

Update: Locked accounts

This post is related to a previous post.

We have recently been receiving several incidents regarding accounts that are getting locked out. Our Service Desk and Desktop team have been unable to find the cause and so they escalated to us. Following the log trail we have found that this devices are normally getting locked out in our CAS server. This was easy enough to be determined by using a Microsoft tool called Lockoutstatus; however, we had been unable to determine exactly what was causing them to get locked out in the CAS server and we would simply inform the user that their account was getting locked out by a smart device using ActiveSync. 

I recently found in this article though that there is a way to figure out what the device exactly is causing the issue by looking at the IIS logs in the CAS Server. The article explains in detail what the log looks like, and what each field means. 

I'll try to provide a bit of a summary, but please visit the full article for more details. 

The logs can be found in the following locations:


  • In Windows Server 2003: C:\WINDOWS\system32\LogFiles
  • In Windows Server 2008: C:\inetpub\logs\LogFiles\W3SVC1
  • In Windows Server 2012: I believe it should be the same but since we don't have a CAS server on a 2012 machine I wasn't able to confirm.

Here is the example provided, and I'll try to break it down as I understood it:

2012-01-10 14:42:26 172.32.22.12 POST /Microsoft-Server-ActiveSync/default.eas User=ratishnair&DeviceId=Appl8xxxxx4S&DeviceType=iPhone&Cmd=FolderSync&Log=PrxFrom:10.123.33.88_Error:BackingOffMailboxServer_ 443 CONTOSO\CAS01$ 10.123.33.88Apple-iPhone3C1/901.405 503 0 0 765


  • 172.32.22.12 : The IP address of where the command was sent to.
  • POST : The type of command that was issued on the Log.
  • /Microsoft-Server-ACtiveSync/ : States that the type of command is ActiveSync.
  • Default.eas : States the ActiveSync policy - this might vary depending on your settings.
  • User= : The username who is running the command.
  • DeviceID= : The ID that was assigned to the ActiveSync Device by the Exchange server when it was first setup. 
  • DeviceType= : The Device Model - We've been using this to point the users to their device having issues.
  • Apple-Iphone3C1/901.405 : The device's firmware version.
  • 503 : This is the error code, which can be any of the ones found below:
    • 200 – Authentication pass
    • 400 – Bad/invalid request
    • 401 and 403 – Unauthorized/server refusing request
    • 404  – File not found
    • 449 – Retry
    • 500 – Server error
    • 503 – Service unavailable
  • 0 0 765 : I'm not 100% sure what this part means; however, the last 3 digits appear to change from log to log. I'm doing further research on this.
Well I hope this might help you troubleshoot this type of issues! I know it will help us a lot, and I am even thinking about allowing the Service Desk read access to this logs, though our Exchange admins aren't too fond of the idea, yet. 

Windows Server 2003 You did it again!

We recently had an outage on some of our VMWare hosts and after the outage was resolved and the hosts came back online we brought up all the VMs back online. Later that day one of my co-workers received a call regarding one of the VMs that was not able to be accessed.

After thoroughly troubleshooting the issue he asked me for some input.


He had done everything anyone would do to troubleshoot an issue with a VM Network:



  • Made sure the IP address and subnet were correct.
  • He double checked the VLAN on the VM host. 
  • He deleted the virtual NIC and added a new one with a different driver
Unfortunately nothing was working. I took over the issue, and I was honestly at a stomp. After redoing everything he had done and a few other things I finally decided to check the Windows EventLog - I probably should have done that sooner. I found an event that said the following:

Event Type: Error

Event Source: IPSEC
Event Category: None
Event ID: 4292
Date:
Time: 
User: N/A
Computer: COMPUTER_NAME
Description:
The IPSec driver has entered Block mode. IPSec will discard all inbound and outbound TCP/IP network traffic that is not permitted by boot-time IPSec Policy exemptions.

After some researching I found the following VMWare article. It turns out this is actually not that an uncommon occurrence on VMs running Windows Server 2003. 

I followed the given instructions and I disabled the IPSec service - even though it wasn't even running - and rebooted the VM. When the system came back online so was the network. 

I hope this might help someone out there! 

Tuesday, August 19, 2014

Web Platform

So for the past few weeks I have put on my learning hat and been learning the ways of the website development. This of course was no easy task, but after many headbangs against my desk I feel like I'm finally making some progress. I was finally able to create a Master page using VS Express 2013 for Web. I got a HTML5/CSS3 Template going, and I believe I can finally start creating pages, backed by C#. 

This is all still a huge learning curve but I gotta say I feel more confident now. So far the resources that I've used to learn this is training on cbtnuggets, I've also used this link here to get a better understanding of CSS http://learnlayout.com/position.html. 

So far what I been learning is very well documenting so I haven't really posted anything, but once I start dabbling into deeper issues I'll try to post some cool stuff. 

Tuesday, August 5, 2014

Stand-alone Application to Web Application

My learning c# project that I had been working is being changed. One of the Architects saw what I had and really liked it and wants me to transform it into a web portal instead of a stand alone application. I agree to this changed, but now I have to learn HTML/CSS/JavaScript and i feel like I'm back on step one.

I hope to get some good knowledge out of this though and I'll keep posting when I find cool things.

Wednesday, July 23, 2014

C# Learning - Creating new AD accounts

I've been coding in PowerShell for 2 years now, and I gotta say switching over to C# is a nightmare! I do like it though, its has been a great fun experience. Once I got past the whole "Hello world" tutorials and learning the syntax it got a lot more fun. I'm not that I'm an expert in any way, but I believe I'm starting to get a hang of what is going on, which makes me happy.

Today as part of my on going project I had to create a function to create AD users through C#, and I'm using System.DirectoryServices class which actually requires that you add each property to the user, but doesn't actually tell you what does properties are, so after some looking around I found a table in this article. It made it a lot simpler than trying to guess the names. Here is the table for those that just want to get a quick look:


LDAP Attribute

Example

CCountry: e.g GB for Great Britain.
CN - Common NameCN=Guy Thomas.  Actually, this LDAP attribute can be made up from givenName joined to SN.
CNMaps to 'Name' in the LDAP provider. Remember CN is a mandatory property.  See also sAMAccountName.
descriptionWhat you see in Active Directory Users and Computers.  Not to be confused with displayName on the Users property sheet.
displayNamedisplayName = Guy Thomas.  If you script this property, be sure you understand which field you are configuring.  DisplayName can be confused with CN or description.

DN - also distinguishedNameDN is simply the most important LDAP attribute.
CN=Jay Jamieson, OU= Newport,DC=cp,DC=com
givenNameFirstname also called Christian name
homeDriveHome Folder : connect.  Tricky to configure
initialsUseful in some cultures.
namename = Guy Thomas.  Exactly the same as CN.
objectCategoryDefines the Active Directory Schema category. For example, objectCategory = Person
objectClassobjectClass = User.  Also used for Computer, organizationalUnit, even container.  Important top level container.
physicalDeliveryOfficeNameOffice! on the user's General property sheet
postOfficeBoxP.O. box.
profilePathRoaming profile path: connect.  Trick to set up
sAMAccountNameThis is a mandatory property, sAMAccountName = guyt.  The old NT 4.0 logon name, must be unique in the domain. 
sAMAccountNameIf you are using an LDAP provider 'Name' automatically maps to sAMAcountName and CN. The default value is same as CN, but can be given a different value.
SNSN = Thomas. This would be referred to as last name or surname.
titleJob title.  For example Manager.
userAccountControlUsed to disable an account.  A value of 514 disables the account, while 512 makes the account ready for logon.
userPrincipalNameuserPrincipalName = guyt@CP.com  Often abbreviated to UPN, and looks like an email address.  Very useful for logging on especially in a large Forest.  Note UPN must be unique in the forest.
wWWHomePageUser's home page.

Examples of Exchange Specific LDAP attributes

homeMDB Here is where you set the MailStore
legacyExchangeDNLegacy distinguished name for creating Contacts. In the following example,
Guy Thomas is a Contact in the first administrative group of GUYDOMAIN: /o=GUYDOMAIN/ou=first administrative group/cn=Recipients/cn=Guy Thomas
mailAn easy, but important attribute.  A simple SMTP address is all that is required billyn@ourdom.com
mAPIRecipient - FALSEIndicates that a contact is not a domain user.
mailNicknameNormally this is the same value as the sAMAccountName, but could be different if you wished.  Needed for mail enabled contacts.
mDBUseDefaultsAnother straightforward field, just the value to:True
msExchHomeServerNameExchange needs to know which server to deliver the mail.  Example:
/o=YourOrg/ou=First Administrative Group/cn=Configuration/cn=Servers/cn=MailSrv
proxyAddressesAs the name 'proxy' suggests, it is possible for one recipient to have more than one email address.  Note the plural spelling of proxyAddresses.
 targetAddressSMTP:@ e-mail address.  Note that SMTP is case sensitive.  All capitals means the default address.
 showInAddressBookDisplays the contact in the Global Address List.

cCountry or Region
companyCompany or organization name
departmentUseful category to fill in and use for filtering
homephoneHome Phone number, (Lots more phone LDAPs)
l  (Lower case L)L = Location.  City ( Maybe Office
locationImportant, particularly for printers and computers.
managerBoss, manager
mobileMobile Phone number
ObjectClassUsually, User, or Computer
OUOrganizational unit.  See also DN
pwdLastSetForce users to change their passwords at next logon
postalCodeZip or post code
stState, Province or County
streetAddressFirst line of address
telephoneNumberOffice Phone
userAccountControlEnable (512) / disable account (514)

Examples of Obscure LDAP Attributes

dNSHostname
rID
url
uSNCreated, uSNChanged

I removed the Ads because I'm not sure if they would affect his stuff. 

Here is the difference in code from creating users in PowerShell and in C#:

PowerShell * In this particular example I'm taking the values from a CSV, which allows me to create multiple accounts very quickly. 

//This is needed
Import-Module ActiveDirectory

New-ADUser -AccountPassword (ConvertTo-SecureString -AsPlainText "PASSWORDHERE" -Force-Server 'DCHOSTNAME' `
        -Enabled $true `
        -Name $file.username `
        -GivenName $file.name `
        -Surname $file.lastname `
        -Initials $file.middle `
        -DisplayName $file.displayname `
        -SamAccountName $file.username `
        -Office $file.office `
        -Department $file.Department `
        -Company $file.company `
        -StreetAddress $file.Street `
        -City $file.city `
        -State $file.state `
        -PostalCode $file.postalcode `
        -Country $file.country  `
        -Description $file.description `
        -Path $file.path `
        -UserPrincipalName $file.userprincipalname `
        -EmailAddress $file.userprincipalname `
        -OtherAttributes @{'co'="United States"'countryCode'="840"


C# * Please note that I am passing the variables from the "OnClick" function for a button, and also that all the properties name are not provided to you as they are in PowerShell. Final note there is some parameters that have not yet been used as they will be added at a later point when I create the mailbox. 

//These are required
using System.DirectoryServices;
using System.DirectoryServices.ActiveDirectory;

public void createUser(int ticketnumber, string firstname, string middleIn, string lastName, 
string samaccountname, string email, string telephone, string hemisphere, string company, 
string office, string address, string city, string state, string division, string Code, 
string OrganizationalUnit, string country, string department, string title, string displayName, 
string postalCode, string co, string Manager)
        {
            string path = "LDAP://" + OrganizationalUnit;
            int NORMAL_ACCOUNT = 0x200;
            int PWD_NOTREQD = 0x20;
            try
            {
                using (DirectoryEntry ou = new DirectoryEntry(path))
                {
                    DirectoryEntry user = ou.Children.Add("CN=" + samaccountname, "user");
                    user.Properties["SamAccountName"].Add(samaccountname);
                    user.Properties["userPrincipalName"].Add(samaccountname + "@DOMAIN");
                    user.Properties["name"].Add(firstname + " " + lastName);
                    user.Properties["givenName"].Add(firstname);
                    user.Properties["initials"].Add(middleIn);
                    user.Properties["SN"].Add(lastName);
                    user.Properties["telephoneNumber"].Add(telephone);
                    user.Properties["company"].Add(company);
                    user.Properties["physicalDeliveryOfficeName"].Add(office);
                    user.Properties["streetAddress"].Add(address);
                    user.Properties["l"].Add(city);
                    user.Properties["st"].Add(state);
                    user.Properties["co"].Add(country);
                    user.Properties["C"].Add(co);
                    user.Properties["department"].Add(department);
                    user.Properties["title"].Add(title);
                    user.Properties["userAccountControl"].Value = NORMAL_ACCOUNT | PWD_NOTREQD;
                    user.Properties["description"].Add("AC #" + ticketnumber + " JB | Created with JBSoftware");
                    user.Properties["displayName"].Add(displayName);
                    user.Properties["objectCategory"].Add("PERSON");
                    user.Properties["postalCode"].Add(postalCode);
                    user.Properties["manager"].Add(Manager);
                    user.CommitChanges();
                }
            }
            catch (System.DirectoryServices.DirectoryServicesCOMException E)
            {
                MessageBox.Show(E, "ERROR!", MessageBoxButtons.OK, MessageBoxIcon.Error);
                throw;
            }        }


Well I think that is it for the day, I hope that this information might be useful to someone out there!

Edit >
It seems that I forgot a simple o in the Country property. (see in bold)