Tuesday, March 27, 2012

Create a alert based Annoucements

Here’s how to use a single announcements list, categorize the announcements by department, and allow alerts to be created per category. This list can also be set up to display only the announcements of the logged in user’s specific department.

  • In your announcements list, create a new column called “Department”, as a text box, choice list, or even a lookup to a separate list of departments.
  • In the list, create a new, filtered view for each different department, like this:
    Click the View drop-down box at the top right of the announcements list, and choose “Create View”, choose Standard View.
    In the Filter section, choose to filter by Department is equal to department name.
    Do a new view for each department.
  • Now that the filtered views exist, alerts can be set up based on them.

Try it out. On the announcements list, click <Actions> and choose <Alert me>. You’ll notice that in the “Send Alerts for These Changes” section, there’s a new option that lets you choose to be alerted on items that exist in a particular view.

Alerts

In this case, it’s a particular department’s announcements. Also, as an administrator, since you have the ability to set up alerts for other people, you can create a new alert based on new items created in the view for each department, and have that alert sent to members of a departmental group in Active Directory.

Publish Date functionality for Announcements

The ideas for this set of articles comes from user questions on Stump the Panel regarding customizations and optimizations to announcements lists on SharePoint sites. I will cover the following customizations:

  • Create a Publish Date feature for announcements
  • Create alerts based on announcement categories
  • Modify the default “Current View” of the announcements Web Parts
  • Create a “More” link to view the details of each announcement

Create a Publish Date functionality for Announcements


Here’s how to create a publish date for each of your announcements, where the announcement will automatically be “published” when the date arrives.

  1. Turn on content approval on your announcements list like this:
    In the list’s settings, go to Versioning settings.
    Change “Require content approval for submitted items?” to Yes
    Date Functionality
  2. Create a new Date and Time column in your announcements list called “Publish Date”, and make it a required column. You can even make it default to today’s date if you’d like.
  3. In SharePoint Designer, create a workflow like this: Open SharePoint Designer, and click <File> and <Open Site>. Paste in the URL of the site where you’d like to create the workflow, and open it. Click <File>, then <New…>, then <Workflow…>
    Date Functionality
  4. Name this workflow “Create Announcement”
  5. Pick your Announcements list from the drop-down list. Only check the box “Automatically start this workflow when a new item is created”.
  6. Add the first condition to “Compare Announcements field”. If the field Publish Date is less than or equal to (then, click on value, and choose the little parameter builder button)
    Date Functionality
    Then, choose Current Date, and click OK.
  7. In the Actions section, choose Set Content Approval Status. Set content approval status to “Approved”, and add comments such as “item automatically approved on publish date”
  8. But, if the announcement is supposed to be published on a future date, we need the workflow to wait. Click to Add ‘Else If’ Conditional Branch. In the new branch’s Action section, choose Pause Until Date. Click on this time, and click the function button to display the data binding menu
    Date Functionality

    With the Source as Current Item, choose Publish Date as the field. Click OK.
    Date Functionality
  9. The second action will be the same as the action on the previous branch.
    Set content approval status to “Approved”, and add comments such as “item automatically approved on publish date”

Here’s what your workflow screen will look like:

Date Functionality

We used “is less than or equal to Today” as the condition (instead of is equal to today) because it’s possible that a user could enter in a past date as the publish date. A condition is not needed in the second branch because it knows that if the condition in the first branch is not met, then otherwise do this.

Thursday, February 2, 2012

SharePoint Security and Permission System Overview

SharePoint Permission and Security Mechanisms

From time to time, our customers ask us about how SharePoint security and permission features work, and how should they be utilized. In this post we try to walk through the basic permission and security features of SharePoint. This post is not intended to be a complete description of every security and permission related feature in SharePoint, but we try to gather all the essential pieces here. We took many screenshots to illustrate what each setting or feature means in practice, enjoy the ride, ;-) !
Additional Resources:

Farm Administrators

Farm Administrators group is a group that is managed centrally via SharePoint Central Administration web-site:

Farm Administrators include by default SharePoint Farm -account, SharePoint installation account and BUILTIN\Administrators group. Farm Administrators have basically “all rights” in SharePoint Farm (or at least they have the ability to get them).
You can give Farm Administration rights to AD groups and AD users:

Additional Resources:

Authentication Providers

With authentication providers you can control how you would like to have your users authenticated in a web application. You can also enable/disable anonymous access and client integration and control client object model permission requirements among others:

Additional Resources:
Web Application Level Permission Policies
With web application level permission policies you can control centrally, with Central Administration, what kind of permission policies you want to apply to all site collections and sites under specific web application. By default SharePoint gives us four predefined policies:

Our recommendation is that you should not edit the default policies, but instead go ahead and create a new policies, if the out of the box policies are not what you are looking for. Policies itself do not grant any permissions unless you attach users or groups to that policy. Policies are just a definitions what the user who has granted the policy can do in the entire web application. With web application policies you can either Grant or Deny the permission.
Here is an example of adding a new web application level permission policy:

Additional Resources:

Web Application Level User Policies

User Policy is the place where the magic happens in a web application level. User policy is basically a AD user or AD group mapping to certain Web Application Level Permission policy. You can even define a Zone in which the policy is applied. For example you can use different policy for users who use the SharePoint sites from your internal network (intranet zone), and different policy for those who access the sites through public internet (internet zone), or just apply to “All Zones”. User policies are especially useful for service accounts and in development/integration environments where you probably recreate site collections often (maybe with TFS autobuild scripts).
Here is a screenshot of applying Manage Content -policy to Content Editors AD group:

Additional Resources:

Web Application Level Anonymous Policy

You can also define web application level anonymous users’ policy through Central Administration -site (but you can only select the policy from a three predefined policies):

Additional Resources:

Web Application Level User Permissions

This is just a checkbox list from where you can manage what kind of permission levels can be used in a web application and site collections (by default all check boxes are checked, and in general we rarely need to modify the selections):

Site Collection Administrators

Site Collection Administrators have full control of a specific SharePoint site collection. You can only use AD users (not AD groups, at least with the UI) as site collection administrators (We don’t actually know why it is like that, do you?). With Central Administration site, you can define two users as site collection administrators, but in site collection settings you can add more site collection administrators. Here is a screenshot of Central Administration site collection administrators settings page:

Additional Resources:

Anonymous Access Permissions

You can control what parts of your site the Anonymous users can access with Anonymous Access Setting:

Anonymous access can further be restricted by enabling View Form Pages Lock Down -feature. Our advice is to enable this feature in every public SharePoint site. More about this feature and some other anonymous access suggestions, please consult the following article:

Site Collection Level Permission Levels

Like in Web Application level permission policies, these are the actual permissions that SharePoint will check when user accesses resources in a SharePoint site. This time we have Grant only abilities (in Web Application Level Permission Policies you could use Grant and Deny). In itself permission levels are only definitions that group the more fine grained permissions together in a more useful entity.
By Default SharePoint has these permission levels defined in site collections (levels can be a little bit different depending on what features have been enabled in a site collection):

You can also define your own permission levels, if predefined levels do not match the requirements. As a general principle, it’s not a good idea to modify predefined permission levels (it will only cause confusion). Own permission levels can be created in similar fashion as web application level permission policies:

Additional Resources:

SharePoint Groups

SharePoint groups are a little bit like AD groups, but these groups are managed in SharePoint instead of Active Directory. SharePoint groups can be used to delegate rights management for the site owners instead of system administrators. Whether this is a good thing or not… well it depends on what you want to archive. SharePoint groups are global to the whole site collection. You cannot specify SharePoint group that exists only in a (sub-)site level. SharePoint groups cannot be used over the site collections. One thing SharePoint groups do support that AD groups do not, is membership requests. You can control SharePoint groups’ permission levels whenever you want to use that group. Basically SharePoint group is just a collection of AD groups and AD users with attached permission level(s). While permission level can change for the group the members are globally defined (site collection wide).
Here is a small clipping of Group creation settings (not all settings are visible, but you get an idea):

SharePoint Groups do no directly give any rights to ad users or ad groups (unless you use some predefined group that already has for example site level permissions attached to it). You have to use that group somewhere. Next we walk through all the places where you can use SharePoint Groups, AD Groups and AD users to actually give the permissions.
Additional Resources:

Site Permissions

Site permissions is where all the permission management begins. More specifically the root site permissions (root site is the top site in a site collection). These are the permissions that all sub-items (sub-sites, libraries and lists, folders and document sets, documents and items) will inherit. That’s why it is important to carefully design the site permissions as the whole site will use these by default (unless the inheritance chain is broken). Our advice is to try to find some general permissions so that you do no need to break inheritance chain too often.
When you grant site permissions you can use AD groups, AD users and SharePoint groups. You can either add users to some of SharePoint groups or grant the permissions directly (aka attach permission level to user or group). I’m not sure why Microsoft recommends granting permissions though SharePoint Groups, because in many cases it makes a little sense. Probably because of in-built functionality that is attached to SharePoint groups or that when using SharePoint groups, you are able to move your site more easily to different domain (for example from development to cloud service, BPOS anyone?). Our advice is that go with SharePoint groups or grant directly, but try not to overuse SharePoint Groups as it only causes confusion in the end.
Here is a screenshot of SharePoint site level permission granting screen (this exact same functionality is also used in other levels described below):

Each sub site can break the permissions inheritance chain and specify their own permissions, just like you specify them in a root site.
Additional Resources:

Library or List Permissions

Library and List permissions can be managed though list settings. Basically the management works exactly the same as with Site permissions. First you break the inheritance chain and then you start to manage individual list’s or library’s permissions. You can grant rights for AD users, AD groups and SharePoint Groups. By default libraries and lists inherit their permissions from parent site.
With lists and libraries you have also some other security related features.
For example you can control Draft Item Security:

You can also control item/document scheduling, enable audience targeting and content approval (with or without workflows):

Additional Resources:

Folder or Document Set Permissions

Like with library and site permissions, folders and document sets can be granted with their own permissions by breaking the permissions inheritance chain.
Document Set and Folder permissions can be accessed from drop-down menu:

Additinal Resources:
  • Consult the links provided in Library or List Permissions

Document or Item Permissions

Last level in SharePoint site structure hierarchy is document or item. Document and item permissions can also be granted just like you did with structures above that (folders, libraries, sites…).
You can access document and item level permission settings page directly from the object you are interested in:

Additinal Resources:
  • Consult the links provided in Library or List Permissions

Miscellaneous Security and Permission Features

Web Part security settings can be configured at web application level:

SharePoint Designer permissions can be controlled with web application level settings:

See also: Managing SharePoint Designer 2010
Browser File Handling and Web Page Security validation can be controlled at web application level:

See Also: Security Validation and Making Posts to Update Data
You can also control blocked file types list (aka restrict of uploading certain file types):

See Also: Manage blocked file types (SharePoint Server 2010)
Self-Service Site Creation that is basically used for my sites is a way to give users a permission to create a new site collections in certain URL namespaces. This can be controlled through Central Administration -web site and the setting is for a web application:

See Also: Turn on or turn off self-service site creation (SharePoint Server 2010)
With SharePoint auditing features you can gather logs and get reports on what the users have been doing on the site collection:

This is a little bit unrelated to security, but as a note, SharePoint has also a two level recycle bin:

See also: Plan to protect content by using recycle bins and versioning (SharePoint Server 2010)

What Was Not Covered in This Article

There is also Windows Rights Managements Services integration in SharePoint… let’s discuss about that in a separate article, or give us a link to some article that discusses SharePoint/RMS integration! We could also talk a little bit about SharePoint managed accounts, but those are more of a infrastructure side. And what about security settings that some of SharePoint services contain? As you can see, SharePoint is a very flexible platform in these kind of things, but this flexibility comes with a price. That price is complexity. Hopefully this article clears some of that.
What we also didn’t discuss that are somewhat related to security are for example:

Whether to use AD Groups or SharePoint Groups as a Main Mechanism to Grant Rights?

Well, Everything starts from Active Directory. If Active Directory is a mess, it should be fixed before designing how to manage rights in SharePoint. If Active Directory is well maintained it also benefits the other applications that integrate to AD (for example normal file sharing and NTFS permissions, or systems like Microsoft CRM).
Use SharePoint groups sparingly. Try to utilize the predefined SharePoint groups that are created in SharePoint sites, if possible. Think twice before defining new Web Application policies or Site Collection Permission Levels, and create new ones only if there isn’t better way around it.

Final Words

Please give us comments and feedback! We will probably come back and update this article in the future.
Popularity: 89% [?]

Thursday, January 26, 2012

Error: The form cannot be rendered. This may be due to a misconfiguration of the Microsoft SharePoint Server State Service. For more information, contact your server administrator.

Error: The form cannot be rendered. This may be due to a misconfiguration of the Microsoft SharePoint Server State Service. For more information, contact your server administrator.

Error:
The form cannot be rendered. This may be due to a misconfiguration of the Microsoft SharePoint Server State Service. For more information, contact your server administrator. 




Reason:
You will get this error while you are trying to view the InfoPath forms in browsers. The reason is, the "State Service" may not be enabled/associated for the current web application.

Solution:
Check all the below possibilities...

(Note: I assume that you already know how to develop a browser compatible InfoPath forms)

1. Go to "Application Management" --> "Manage service applications"
2. Check whether the "State Service" is enabled or not (like the below screenshot). 

















3. If the service is not started or missed, we should configure/start the state service. OK. How to start the service?  proceed with step 4.
4. Go to the "Configuration Wizard" and start the configuration
5. Make sure the "State Service" is enabled. (Eventhough it is selected, run the wizard again.Hmmmm...That is microsoft :) )

6.Wait until you see the below screen (It will take few minutes to complete).













7. Now, check whether the InfoPath forms are rendering properly in the browser or not. If everything is fine, then continue with your work.. Again if you are getting the same error screen, you need to check the "Service Associations" for your current web application (proceed with step 8).

8. In "Central Administration", Go to "Application Management" and select the "Configure service application associations" in "Service Applications" section. 

9. Click on your web application and a pop up windows will be displayed. 






















10. Select the "State Service" Check box and click "OK".  

11. Now you can able to view the InfoPath forms in browser like below. 














Thats it...

Wednesday, January 11, 2012

How to Deploy Solution (WSP) from SharePoint 2010 Central Administration

How to Deploy Solution (WSP) from SharePoint 2010 Central Administration

Hi All,
I'd like to share with you these simple steps to deploy Solution file (WSP) from Central Administration:
1- Add WSP to your farm using the following command:
 stsadm -o addsolution -filename
2- From Central Administration: System Settings
3- Manage Farm Solution
4- Select your WSP file to deploy
5- Deployment Settings
6- WSP deployed
Note: you must run Internet Explorer as

Tuesday, January 10, 2012

SharePoint Farm Installation

Here i am posting step by step installation guides for sharepoint server 2010 ent,

Installing SharePoint 2010 on Windows 2008 Server R2

1 - Introduction
 As the new release of SharePoint 2010 was launched last week, I am updating this post that was written for the beta version, but I let the previous post as an archive at the end of this page.
  - Development benefits (the "why" part of the post)
In order this tutorial do not require any software purchase for a developer that wants to be familiar with the new release of SharePoint 2010:
  1. I chose to take advantage of testing the new version of SharePoint by testing in the same time the Windows 2008 Server R2 OS because Microsoft provides presently an 180 days evaluation version of it.
  2. As you certainly know, SharePoint 2010 requires a 64 bits OS to run.

    Therefore, I have chosen to create the Virtual Machine with VMware because it is to date the only way of making run an 64 bit OS guest on a 32 bits OS host.
    you can actually create a Virtual Machine running Windows 2008 Server R2 64 bits on a 32 bits host by using the free version of VMware:

    VMware player 3.0.


    You can download this software after registration at:

    http://downloads.vmware.com/d/info/desktop_downloads/vmware_player/3_0
As usual I will do my best to supply a step by step tutorial as detailed as possible which demonstrates how to install 2010 SharePoint on Windows server 2008 R2.
  - Environment for this SharePoint 2010 installation:

The environment I propose to mount in this tutorial is a development environment that uses a SharePoint Server 2010 Farm installation on a single computer using several local service accounts in order to be compliant with the least privilege administration policy.

The SharePoint 2010 content databases will run on a SQLServer 2008 Standard Edition Database Engine.
2 Creating the Virtual Machine
 2.1 Download Windows Server 2008 R2 Evaluation
Windows Server 2008 R2 is available in 64-bit (x64) only.

 You have to register to obtain it.
Open VMWare and Select "New Virtual Machine"
The new virtual machine wizard is opening
Choose the option "Installer disc image file "  and browse to refer the previously downloaded image of the Windows 2008 Server R2.
The wizard will detect automatically the OS version and will start easy install.
The wizard will retrieve automatically your user account.
Don't provide any product key you don't need any for this evaluation version, but take time to provide a password because this account will be your Administrator account of your new Virtual Machine and using an Administrator account that has not a password will lead to many problems when configuring your machine  and more trouble when working with SharePoint 2010.
Click OK to the warning message
Choose your Virtual machine name and location.
On this screen let the default values
The Wizard summarize your settings but you can still change some by clicking "Customize Hardware...". Especially the RAM allocated to the Virtual Machine.


When you click "Finish", the installation begins by loading the files.
Then, you have to choose the version of your Operating System.
Do not choose a Web Server version otherwise you will not be able to add an "Application Server" role to the server later.
Choose the Full Installation of the Enterprise Version.


The Easy install will install the OS automatically and in my case it did it in approximately 30 minutes!


Then you can access to your new server. You will see the "Initial Configuration tasks".
After you have completed the installation of Windows Server® 2008 R2, and before you deploy the new server in your enterprise, some configuration is required to identify the computer to other computing resources on your network, secure the computer, enable administrators to perform tasks on the computer, and customize the computer by adding server roles and features.
You can complete these tasks by using commands in the Initial Configuration Tasks window, which opens immediately after the operating system installation is complete.
The Initial Configuration Tasks window opens at each startup, unless the Do not show this window at logon check box is selected.
If you want to open this windows manually run this command:
C:\Windows\System32\Oobe.exe
3 Configuring the server - Standard Configuration Operations
3.1 Hardware Acceleration
In order to accelerate your Virtual Machine you have to perform the following operations :
Right click your desktop and choose "Screen resolution".
Then, click
Troubleshoot tab
Change Settings button
You will access to the "Display Adapter Troubleshooter" dialog.
Set the cursor to the Full position.
3.2 Windows Activating
Go back to the "Initial Configuration tasks" windows and we are going to go through the standard configuration operations easily because the windows lits them.

Be sure the Virtual Machine has an Internet Access.
We have to activate Windows in order to take advantage of the 180 days of the evaluation process.
Click on the "Activate Windows" link.


Do not look for any product key, as said before, you do not need any, just click next.
The activation will be done automatically through Internet. You will notice then the activation number and the number of days remaining on the bottom right corner of the desktop.
3.3 Changing Computer Name
Now, click the "Provide computer name and domain" link,then set your new Virtual machine name.
3.4 Downloading Updates
Click the "Download and install updates link" then turn on automatic updates, and proceed to the latest updates installation.


i

Then restart the Virtual machine.

3.5 Disabling Internet explorer Enhanced Security
To disable Enhanced Security Configuration to specific users by using a computer running Windows Server 2008
  1. Click Start, point to Administrative Tools, and then click Server Manager.
  2. If the User Account Control dialog box appears, confirm that the action it displays is what you want, and then click Continue.
  3. Under Security Summary, click Configure IE ESC.
  4. Under Administrators, click On (Recommended) or Off, depending on your desired configuration.
  5. Under Users, click On (Recommended) or Off, depending on your desired configuration.
  6. Click OK.
  7. Restart Internet Explorer to apply Enhanced Security Configuration.
G


4 Configuring the server - Configuration Operations for SharePoint (MOSS 2007 or SharePoint 2010)
4.1 Adding Server Roles and Roles Services - Application Server - Web Server
On the Initial configuration task windows, click "Add Roles"
The "Add Roles" Wizard is opening.
Check the check box for Application Server.
The wizard opens a modal dialog for the Required Features
Just click the "Add Required Features" button.
You are taken to and intermediate dialog. Click "Next" to go to the "Role Services" dialogs.
Click "Next"
On the "Role Services" dialog, select the followings :
.Net Framework 3.5.1
Web Server (IIS) Support
TCP Port Sharing
HTTP Activation
TCP Activation
Named Pipes Activation
Then Click "Next"
You are taken to an the intermediate page for the Web Server (IIS) Role
Click "Next"
The Select Role Services for Web Server (IIS) Role is displaying, but just let the default options.
Click "Next" to access the confirmation dialog
Then click "Install" and the Roles and Features are being installed
Check the "Installation Result" dialog and close it.

4.1 Adding Desktop Experience Feature
It would be interesting for a development machine to be able to use the Windows Photo Viewer in order to check some screenshots taken during configuration phases, or when wanting to report an issue. To be able to use this feature of Windows server 2008 R2 you have to activate the Desktop Experience feature.
Go back to the  "Initial Configuration tasks" window and click "Add feature", then locate "Desktop Experience" check box and check it.

5 Installing SQL Server 2008
For these operations I let you consult one of my previous post that explains the same for Windows 2003 Server. The operations are exactly the same.
Integrating Reporting Services 2008 with SharePoint 2007 Step 1 - SQL Server 2008 Installation
6 Downloading the Microsoft SharePoint Server 2010 new release
Go to this page to download the Microsoft SharePoint Server 2010. You have to register to access to the download.
Choose the SharePoint Server 2010 Entreprise Client Access License features or SharePoint Server 2010 for Internet Sites, Entreprise, it is the same product, but the Entreprise version will give you all the SharePoint 2010 features.
You will notice that a link is available toward the
SharePoint Server 2010 system requirements

The next section will detail the required things to do in order to be compliant with these requirements.
7 If you have the SharePoint 2010 Beta version installed on this machine
If you have the previous SharePoint 2010 Beta version installed on this machine, uninstall it and uninstall also the Microsoft "Geneva" Framework,
As precised by Micorsoft :
"If you have Microsoft "Geneva" Framework installed, you must uninstall it before you install the Windows Identity Foundation (WIF)."7 Configuring the server - Configuration Operations for SharePoint 2010
8 Installing the manual Prerequistes Softawre
8.1 Downloading and installing SQL Server 2008 SP1
First, we have to update the previously installed SQL Server with the SP1 downlodable at :
Do not forget to choose the x64 package
Here is the package after the download
and the first installation screenshot
8.2 Downloading and installing Cumulative update package 2 for SQL Server 2008 Service Pack 1
Then, we have to install the Cumulative Update package 2 for SQL Server 2008 Service Pack 1. We also could install a later Cummulative Update, except the 3 as Microsoft precises it :
"We do not recommend that you use CU3 or CU4, but instead CU2, CU5, or a later CU than CU5."
Follow the regsitration process. You will be provided an auto extractable package that needs a password and the appropriate password.
Here is the screenshot after all the process
and the first installation screenshot
8.3 Downloading and installing SQL Server 2008 Analysis Services ADODM.NET
For ending with the products related to SQLServer 2008 download and install the SQL Server 2008 Analysis Services ADODM.NET. This is normally installed by the prerequistes installation of SharePoint 2010, but I had issues letting the SharePoint 2010 wizard install it, so I prefer to do it manually.
Here is the direct link to the download:
Here is the screenshot after the download.
And the first screenshot
8.4 QFE for Sharepoint issues - Perf Counter fix & User Impersonation - KB979917
This is a hotfix for 2 Asp .Net issues :

Issue 1
You deploy some partially trusted Web parts on the SharePoint site. These Web parts have more permissions than they should have. This issue may create a security risk on the SharePoint site. For example, these Web parts may generate database requests or HTTP requests unexpectedly. This behavior creates a security risk.
Note:
Partially trusted Web parts are Web parts that are deployed to the Bin directory of a Web application.
Issue 2
The "Requests Queued" performance counter in an ASP.NET performance object functions incorrectly. When you run the SharePoint site, this issue may decrease the performance of the SharePoint site.
I read the following in the Hotfix documentation, so I wonder if we have to really install it or test SharePoint behavior first.
"A supported hotfix is now available from Microsoft. However, it is intended to correct only the problem that is described in this article. Apply it only to systems that are experiencing this specific problem. This hotfix may receive additional testing. Therefore, if you are not severely affected by this problem, we recommend that you wait for the next service pack that contains this hotfix."
Anyway; here is the link to this hotfix :

8.5 hotfix for the token authentication in WCF
This is the version 2 of the kb976462, the famous htofix that led to several discussion on SharePoint blogs. Youn can find it here:

 FIX: A hotfix that provides a method to support the token authentication without transport security or message encryption in WCF is available for the .NET Framework 3.5 SP1 (http://go.microsoft.com/fwlink/?LinkID=166231).

Check its name : Windows6.1-KB976462-v2-x64

Be careful, there is a specific version for Windows server 2008 R2.

By the way, it seems you do not need to install it manually since it should be done by the SharePoint 2010 prerequisites software installation.
9 Microsoft SharePoint Server 2010 Installation
9.1 Installing the SharePoint Prerequisites
Double click the installation package to launch the installation of  Microsoft SharePoint Server 2010
The SharePoint 2010 installation Wizard is opening
Click the "Install Software Prerequisites" in order to update, complete and check the previous preparation described in the previous sections of this post. The Microsoft SharePoint Product and technologies 2010 Preparation Tool is opening
Accept the licence agreement
The prerequisites are being installed 
You should obtain this screen if you followed the operations previously described in this post.
8.2 Installing the SharePoint Files
Back to the SharePoint 2010 Installation wizard, click the "Install SharePoint Server" link. The launched wizard requires the product key.
Then, accept the terms of the licence agreement.
Choose the complete installation
While SharePoint is being installed, notice that a 14 repository is now created where we had the 12 for the 2007 version.
The wpressources repository is created beside the 14.


When the installation of the SharePoint files is finished you are asked to continue with the SharePoint Products Configuration Wizard.
Do not continue with the Wizard but cancel it otherwise you will have an issue due to the current installation described in this post.
In the SharePoint 2010 version, you are not allowed as before to mount a Farm installation on a single machine using local accounts.
If you had continued with the wizard you would have been stopped in the configuration by the following issue:

the specified user Administrator is a local account. Local accounts should only be used in stand alone mode.
Fortunately there is a workaround to succeed in obtaining a Farm environment using local accounts as we used to have in the previous version that I have found in this post:
 I will show it bellow, but first of all, let us create the sevice accounts we need for this.
9.3 Creating several service accounts - about least priviliege administration policy
In the post concerning the Installation of the SharePoint 2010 Beta version, I used a single local account that was local administrator of the machine, but for this installation, I have chosen to use 3 local accounts in order to be compliant with the least priviliege administration policy.
This policy requires service accounts not to be administrator of any server of a farm, and that each service or process runs using a distinct account.
I advice to do it not only for the QA or production environement but also for development environment, and this for two reasons:
  1. First, doing this will help you to debug because the traces of errors in the SharePoint log or in the event wiever sometimes report the name of the involved account and it will be easier to debug an issue if you have a precise information and not always a reference to the unique "Administrator" local account.
  2. Second, using the same system of accounts within the development machines and the QA and production ones can help you to prevent some bugs. Some bugs are due to the fact that the security used for service accounts are different on the development environment and the QA and production ones. So it is better if a bug linked to this security configuration occurs in your development machines than in the QA or worse in the production environement.

For these two reasons, thus, I personally think it is a good practice to have the same service accounts configuration in all your environments even on the development ones.

Regarding the least priviliege administration policy, The minimal SharePoint installation requires us to create 2 more local accounts (we already have "administrator" account for installation):
  1. One is for the process of the IIS Application Pool of the central administration. Assume we call it SPS_Farm
  2. The second will be used for the process of the IIS Application Pool of the first Web Application if it is isolated in its own Application Pool. Assume we call the first Web Application WebApp-80 because it will use the 80 port, let us call this account SPS_WebApp-80.
So let us create these two accounts and configuring them in order password never expires.
9.4 Using SharePoint 2010 Management Shell to create the SharePoint 2010 Configuration databases

Open the SharePoint 2010 Management Shell.
Type the following command
New-SPConfigurationDatabase
run the command by pressing the Carriage Return Key
The Shell willl ask you for:
The database name --> choose any name, for example SharePoint_Config
The database Server name --> type the name of your Virtual Machine in my case VMDEV-012

You will be then prompt for the system account credential. It is now the time to pass the credential of the SPS_FARM service account. Don't forget the machine (domain) name otherwise you will get an exception of the SharePoint shell.
Then you are asked for a passphrase. You can use P@ssw0rd that matches the security policies required.
(This passphrase will be asked when you will add a new server to the SharePoint Farm)

At this step of the installation you can check that two operations has been performed behind the scene.

Two databases has been created in the database server referenced in the shell window. There is at this point no difference with MOSS 2007 instalation.

3 web services has been created in IIS with 3 distinct application pools for each. That is a new feature of SharePoint 2010.

For more information about installing SharePoint 2010 in a production environement while being compliant with the least privilege administration policy, read this excellent post (especially the comments discussing and explaining the workaround about the "SPS_Farm" Database Access Account).

Least Privilege Service Accounts for SharePoint 2010

Here are the official Microsoft documentation links on the topic:



9.4 Running the SharePoint Products Configuration Wizard
This time you can open the SharePoint Products Configuration Wizard.
Let the option "Do not disconnect from this server farm" checked.
Then you will be prompted to chose the Central Administration Site port number. I personally always use 55555 for the configuration of all my development environments in order to type the same Url on all my Virtual Machines.
Let the default NTLM value for the "Authentication provider", Kerberos requires network configuration we cannot perform in the current environment anyway.
The wizard, then, summarize your choices.
Then the 9 main configuration operations are performed.
Finally, the "configuration Successful" dialog summarizes your configuration again and informs you that the central Administration of SharePoint 2010 will be launched when you close it.
When you click "Finish" to close the wizard, the Central Administration Site is opening, and you are prompted for credentials
Then you are asked to sign up to User Experience Improvement Program.
Another page let you choose between configuring your farm yourself or by using a wizard.
When this choice is made, you display for the first time the brand new Welcome Page of SharePoint 2010 Central Administration.

As there is sometimes concern with the SharePoint Services installation with Windows 2008 Server R2, you should check that the services installation has completed successfully.
On SharePoint 2010 Central Administration Home Page under the System Settings section click Manage services on server.
You should see this screen that confirms that SharePoint Services installation has completed successfully.


10 Creating your first site in Microsoft SharePoint Server for Internet Sites Enterprise 2010
10.1 Creating a managed local account for SharePoint 2010
Now we have to perform operations in order the previously created local account SPS_WebApp-80 be referenced as a managed account by SharePoint 2010.
So reopen the SharePoint 2010 shell windows and type the following:

$myWebAppServiceAccount = Get-Credential VMDEV-012\SPS_WebApp-80
You will be prompt for this account credentials:
Then, type the following

New-SPManagedAccount -Credential $myWebAppServiceAccount
The SharePoint 2010 Managemant Shell warns you that the managed account should be use in stand alone environement since it is a local account.
Now, we can create the first SharePoint 2010 Web Application
10.2 Creating your first Web Application for SharePoint 2010
On the default page of the SharePoint 2010 Central Administration, click the "Manage Web Application" link in the "Application Management" section
On the "Manage Web Application" page click the "New" menu entry then click "New Web Application"
I have personally chosen to create it on the default IIS web site, and as a personal usage
named it "Web App - 80"
let the Application pool default settings
named the content database "WSS_Content_WebAppp-80"

You notice then that you have the previously service account available as a SharePoint 2010 managed account to be the account under the which the process of the new Application Pool will run .
You are then prompted the changes are processed
and finally that the SharePoint 2010 Web Application is created.
Click "OK" to close the wizard and to be taken back to the Web Application Management Page where you can see the new SharePoint 2010 Web Application.

Now, if we go to check what have been done behind the scene in ISS we will notice that we can retrieve a trace for our SharePoint 2010 managed local accounts:
And the same in the Services of our machine:
Last, if now you use the SPS_FARM SharePoint 2010 managed local account to sign in to the Central Administration:


You will notice that you are not connected as SPS_Farm, but as System Account.
This account is a Farm administraor account used ONLY to administrate the Farm using the Central Administration Web site. As it is not a local  administrator of the server it cannot be used to run the SharePoint 2010 Configurqtion wizard, neither the obsolete stsadm or psconfig tools, nor the SharePoint 2010 management shell. And there are operations that are no more available from the central administration web site when you are logged in with this account, as "Manage Services on Server".
10.3 Creating your first Site Collection for SharePoint 2010
From the Central Administration Home Page, click on "Create site collections" in order to proceed to the creation of your first SharePoint 2010 Site Collection.
Then, click the "Create site collections" link under the "Site Collections" section. You are taken to the "Create Site Collection" page.
I have personally chosen to create a team site called "SharePoint 2010" team site"


When launching the creation, you are prompted the changes are processed
then prompted on that the site was created successfully.
When clicking on this site link, you can display your first SharePoint 2010 site.

Well done !