Wednesday, January 16, 2013

How security groups work in SharePoint

It’s important to know how SharePoint groups behave when we break the permission inheritance. I’ll take a scenario to explain

Let’s assume I have a site collection with 2 sub sites (Web 1 and Web 2) where I’ve broken the permission inheritance. Then I go to site permission in each web and create groups (Group 1,2,3 and 4) as shown in the diagram below.

image

Following are some observations/conclusions.

1. Security groups are created at root (site collection) level

Although we break the inheritance, if we create a group it’ll be created in the root level. So all 4 groups will be listed in People and Groups in site level. That group collection is referred to as Site Groups.

2. Site Groups collection ≥ Local Web Groups collection

If we go to a web (e.g.: “Web 1”) and navigate to People and Groups we can see only a subset of groups (Group 1 and 2) from site groups (Group 1,2,3,4) . This is because those are the only groups used within that web.

3. A security group is available in web group collection only if that group is referred within that web

The 2nd  observation is in fact due to this. In local group collection of “Web 2” only 2 groups (“Group 1”, “Group 2”) are available because those are the only groups used within that web.

To explain the concept further, I’ll make the scenario broader. Now I’ll create a list in “Web 2” and break the permission inheritance. Then I’ll add “Group 1” to the list (Remember that we created “Group 1” for “Web 1” and was not available in local web group collection of “Web 2”). Updated scenario is given in below image.

image

If you navigate to People and Groups in “Web 2”, you can see “Group 1” also available in the collection of groups. So the conclusion is that if a group is used in somewhere in a web (irrespective of which web we used to create the group in same site collection), it will be available in local web groups collection

Friday, December 14, 2012

Presentation–SharePoint 2010 development with WCF

Recently I did a presentation at Sri Lanka SharePoint forum regarding SharePoint 2010 development with WCF

unnamed (1)

You can download the source code from this link

Monday, December 10, 2012

Patch management in SharePoint

Application of regular security patches and updates is vital for any system. It is same for our SharePoint environment as well. But we should be very careful in patching, as our SharePoint environment can contain mission critical data as well as customization. Data and customization need to be preserved 100% for the patching exercise to be a success.

First we need to understand how Microsoft releases patches for SharePoint.Microsoft provides following types of patches

Hot fixes Released whenever Microsoft encounter vulnerability/issue on SharePoint
Cumulative updates Collection of hot fixes and security updates released every 2 months
Service Packs Collection of fully tested cumulative updates

We can get information on any security update or vulnerability from Microsoft Security Bulletins site. In that site we can search for SharePoint related updates. Once we get the update we need to assess the risk of applying such update.
To assess risks and identify the course of action I use following as the guideline
image
After risk assessment I follow the process given below to apply patches and updates to my production environments
image

Monday, November 19, 2012

Get SharePoint sites created after specific date using PowerShell

Following PowerShell Script will provide sites created after a specific date

  1. $date = [datetime]"10/15/2012"
  2.  
  3. Get-SPWebApplication "http://sp13:8080" | Get-SPSite -Limit All | Get-SPWeb -Limit All | where {$_.Created -lt $date } | select Url, {$_.Created}

Friday, October 12, 2012

Usage of Merge-SPLogFile in SharePoint

We can setup our SharePoint as a multi server farm. Although it is best to distribute workloads among different servers, It can be very painful to debug errors.

Let’s assume we have a SharePoint farm with 3 servers (WFE, App, DB). For an example, let’s say suddenly we get an error while opening a excel document. What do we normally do ?

If the error message is not self-explanatory we will use ULS logs.There are very helpful ULS log readers available. (ULS Viewer is my favourite). First we will log in to WFE and investigate the error using ULS logs and relevant Correlation Id.

image
If the “Excel Services” service application is deployed in App server we might need to get ULS logs from that server as well. If we have tens of servers in our farm we will be in a great trouble. Are we going to remote login each and every server to debug the error?
There is a far better solution. There is a PowerShell cmdlet called Merge-SPLogFile. Using that we can get all log entries from all servers. In the above scenario where we have an issue and we know the correlation id we can use something like below to generate a log file compiled from each server in the farm.

image
Then we can open the CustomLog.log file using ULS Viewer to check all related information from each server.

image
Is this the only usage from Merge-SPLogFile command?
Not really. We can do following using the command. (and there are more use cases as well)
  • Get a summary of all activity compiled from all servers in last hour
Merge-SPLogFile -Path "D:\Logs\FarmMergedLog.log" -Overwrite
  • Get a summary of all activity compiled from all servers for a given log area in last hour(ex.: Search) 
    Merge-SPLogFile -Path "D:\Logs\FarmMergedLog.log" -Overwrite -Area Search
I hope you got some idea about this PowerShell cmdlet.

Wednesday, August 29, 2012

Presentation-SharePoint 2010 Best Practices

In this post I will share the presentation I did at Sri Lanka SharePoint Forum

unnamed

I explained about best practices we can use in different stages of a SharePoint 2010 project, including plan, build and operate.

Tuesday, April 10, 2012

Upload file to SharePoint document library using PowerShell

Following small script will upload file to a given document library in SharePoint

  1. $webUrl = "https://sp13/sites/site"
  2. $docLibName = "SiteLog"
  3. $filePath = "C:\Logs\test.txt"
  4.  
  5. #upload file
  6. $web=Get-SPWeb $webUrl
  7. $file=Get-Item $filePath
  8. $fileStream=([System.IO.FileInfo](Get-Item $file.FullName)).OpenRead()
  9. $folder=$web.GetFolder($docLibName)
  10. $spFile=$folder.Files.Add($folder.Url + “/” + $file.Name, [System.IO.Stream]$fileStream, $true)
  11. $fileStream.Close()