Chat now with support
Chat with Support

Active Roles 7.5.3 - Solutions Guide

Active Roles Solutions Overview ERFM Solution Configuration Transfer Wizard Solution Active Roles SPML Provider Skype for Business Server Solution
Introducing Skype for Business Server User Management Supported Active Directory topologies User Management policy Master Account Management policy Access Templates for Skype for Business Server Deploying the Solution Managing Skype for Business Server Users
Management Pack for SCOM

Monitoring connection to configuration database

This category includes the event-based processing rules to monitor health of the connection to the configuration database:

  • Connection to database has been lost  Administration Service has lost connection to the configuration database, and is making attempts to re-establish the connection.
  • Connection to database has been restored  Administration Service has restored connection to the configuration database.

The following sub-sections elaborate on each of these processing rules.

Connection to database has been lost - Alert

This rule generates an alert indicating that the Administration Service has lost a connection to the configuration database, and is making attempts to restore the connection. For details, refer to the alert description generated by this rule. Losing the connection to the database does not affect the directory management functions of the Administration Service. All operations related to Active Directory management continue to work as expected.

Until after the connection has been restored, unavailable are the functions of the Administration Service that require access to the database. These include:

  • Collecting data related to change history and user activity
  • Retrieving and updating configuration data
  • Retrieving changes to configuration data made by other Administration Services (both directly and via replication)
  • Retrieving and updating virtual attributes stored in the configuration database
Connection to database has been restored - Alert

This rule generates an alert indicating that the Administration Service has restored the connection to the configuration database. For details, refer to the alert description generated by this rule. Once the connection has been restored, available are all the functions of the Administration Service that require access to the database.

Monitoring of Dynamic Group-related operations

This category includes the event-based processing rules to monitor the background activities of Active Roles related to Dynamic Groups:

  • Rebuilding has been started  Administration Service has been forced to re-calculate (rebuild) the membership list of a Dynamic Group.
  • Failed to add object to Dynamic Group  Administration Service failed to add an object to a Dynamic Group.
  • Failed to remove object from Dynamic Group  Administration Service failed to remove an object from a Dynamic Group.
  • Failed to process membership rule  Administration Service failed to apply a query-based membership rule when updating the membership list of a Dynamic Group.
  • Failed to update membership list  Administration Service failed to update the membership list of a Dynamic Group in accordance with the membership rules.
  • Failed to update membership list of nested group  Administration Service failed to update the membership list of an additional (nested) group generated to accommodate extra members of a Dynamic Group.
  • Failed to update membership rule upon deletion of object  When updating a Dynamic Group, Administration Service failed to delete or update a membership rule of a Dynamic Group upon deletion of an object.
  • Failed to look up object when updating  When updating a Dynamic Group, Administration Service failed to locate an object that is referred to by a certain membership rule. The object may have been deleted.
  • Failed to retrieve information from domain  Administration Service failed to retrieve information about Dynamic Groups from a certain domain.
  • Membership rule domain unavailable  When updating a Dynamic Group, Administration Service failed to apply a membership rule because the rule applies to a domain unavailable on the network.
  • Membership rule failed  When updating a Dynamic Group, Administration Service failed to apply one of the membership rules, which prevented all rules from being applied and stopped changes to the members list of the Dynamic Group.

The following sub-sections elaborate on each of these processing rules.

Dynamic Group - Rebuilding has been started - Alert

This rule generates an alert indicating that an administrator has forced Active Roles to re-calculate (rebuild) the membership list of a Dynamic Group. For details, refer to the alert description generated by this rule.

The administrator could start the rebuilding of a Dynamic Group from the Members tab in the Properties dialog box for that Dynamic Group, in the Active Roles console.

Failed to add object to Dynamic Group - Alert

This rule generates an alert indicating that the Administration Service failed to add an object to a Dynamic Group due to a certain problem. The object is missing from the Dynamic Group until after the problem has been resolved. For details, refer to the alert description generated by this rule.

Try to force rebuilding of the Dynamic Group from the Members tab in the Properties dialog box for that Dynamic Group, in the Active Roles console.

Failed to remove object from Dynamic Group - Alert

This rule generates an alert indicating that the Administration Service failed to remove an object from a Dynamic Group due to a certain problem. The object remains in the Dynamic Group until after the problem has been resolved. For details, refer to the alert description generated by this rule.

Try to force rebuilding of the Dynamic Group from the Members tab in the Properties dialog box for that Dynamic Group, in the Active Roles console.

Dynamic Group - Failed to process membership rule - Alert

This rule generates an alert indicating that the Administration Service failed to apply a query-based membership rule when updating the membership list of a Dynamic Group. The failed rule is not taken into account, so the membership list may be incompliant with the membership rules. For details, refer to the alert description generated by this rule.

Try to force rebuilding of the Dynamic Group from the Members tab in the Properties dialog box for that Dynamic Group, in the Active Roles console. Check membership rules by using the Membership Rules tab in that dialog box.

Dynamic Group - Failed to update membership list - Alert

This rule generates an alert indicating that the Administration Service failed to update the membership list of a Dynamic Group in accordance with the membership rules. The membership list may be incompliant with the membership rules. For details, refer to the alert description generated by this rule.

Try to force rebuilding of the Dynamic Group from the Members tab in the Properties dialog box for that Dynamic Group, in the Active Roles console.

Dynamic Group - Failed to update membership list of nested group - Alert

This rule generates an alert indicating that the Administration Service failed to update the membership list of an additional (nested) group generated to accommodate extra members of a Dynamic Group. The membership list of the nested group may be incompliant with the membership rules. For details, refer to the alert description generated by this rule.

Try to force rebuilding of the Dynamic Group from the Members tab in the Properties dialog box for that Dynamic Group, in the Active Roles console.

Dynamic Group - Failed to update membership rule upon deletion of object - Alert

This rule generates an alert indicating that the Administration Service failed to delete or update a membership rule of a Dynamic Group upon deletion of a certain object. The membership rule could be one of the following:

  • Implicit inclusion or exclusion of that object from the Dynamic Group
  • Query with a filter referring to that object
  • Inclusion or exclusion of the members of the group represented by that object

For details, refer to the alert description generated by this rule.

To resolve these issues, delete or update membership rules by using the Membership Rules tab in the Properties dialog box for that Dynamic Group, in the Active Roles console. Then, force rebuilding of the Dynamic Group from the Members tab in that dialog box.

Dynamic Group - Failed to look up object when updating - Alert

This rule generates an alert indicating that the Administration Service failed to locate an object when updating the membership list of a Dynamic Group in accordance with the membership rules. The object may have been deleted. The object could be referred to by:

  • A membership rule to explicitly include or exclude that object from the Dynamic Group
  • A query-based membership rule (the object may represent the base of a search or be a member of the search result set)
  • A membership rule to include or exclude the members of a certain group (the object may represent the domain of that group)
  • A directory synchronization (DirSync) query (this may be one of the objects returned by that query)

For details, refer to the alert description generated by this rule.

The membership rules referring to that object are inoperative and are not taken into account when updating the Dynamic Group, so the membership list may be incompliant with the membership rules.

To prevent issues with the membership list of the Dynamic Group, check membership rules by using the Membership Rules tab in the Properties dialog box for that Dynamic Group, in the Active Roles console. Then, force rebuilding of the Dynamic Group from the Members tab in that dialog box.

Dynamic Group - Failed to retrieve information from domain - Alert

This rule generates an alert indicating that the Administration Service failed to retrieve information about Dynamic Groups from a certain domain. The Dynamic Groups contained in that domain are inoperative until after the problem has been resolved. For details, refer to the alert description generated by this rule.

Dynamic Group - Membership rule domain unavailable - Alert

This rule generates an alert indicating that Active Roles failed to update the members list of the Dynamic Group in accordance with one of the membership rules. The failed membership rule applies to a domain that is currently unavailable. The membership rule is disregarded, so the members list of the Dynamic Group may be incompliant with the membership rules. For details, refer to the alert description generated by this rule.

Ensure that the domain is available on the network, and then update the Dynamic Group by clicking Rebuild on the Members tab in the Properties dialog box for that group in the Active Roles console or wait for Active Roles to update the Dynamic Group on a schedule.

Dynamic Group - Membership rule failed - Alert

This rule generates an alert indicating that Active Roles failed to update the members list of the Dynamic Group in accordance with one of the membership rules. As one of the membership rules failed, no membership rules are applied until the issue is resolved, so the members list of this Dynamic Group remains unchanged. For details, refer to the alert description generated by this rule.

Try forcing update of the Dynamic Group by clicking Rebuild on the Members tab in the Properties dialog box for that group in the Active Roles console. Check the membership rules on the Membership Rules tab in that dialog box.

Monitoring of Group Family-related operations

This category includes the event-based processing rules to monitor the background activities of Active Roles related to Group Families:

  • Cannot find configuration storage group  Administration Service failed to run a Group Family due to the following problem: The Group Family configuration storage group cannot be found.
  • Failed to retrieve configuration data  Administration Service failed to run a Group Family due to the following problem: Group Family configuration data cannot be retrieved from the Group Family configuration storage group.
  • Incorrect configuration data  Administration Service failed to run a Group Family due to the following problem: Incorrect configuration data was encountered in the Group Family configuration storage group.
  • Failed to retrieve configuration data for controlled group  Administration Service encountered an error when running a Group Family, failed to retrieve configuration data for a controlled group. Changes to the controlled group may not be applied until a subsequent run of the Group Family.
  • Failed to retrieve data from container  Administration Service encountered an error when running a Group Family, failed to search a certain container within the Group Family scope. Until a subsequent run, Group Family does not consider information about objects held in that container.
  • Failed to update configuration data  Administration Service encountered an error when running a Group Family, failed to update data in the Group Family configuration storage group. Information about controlled groups may be incorrect until a subsequent run of the Group Family.
  • Failed to update configuration data for controlled group  Administration Service encountered an error when running a Group Family, failed to update configuration data for a controlled group. The controlled group is not linked with the Group Family until a subsequent run of the Group Family.
  • Cannot find controlled group  Administration Service encountered an error when running a Group Family, failed to find a controlled group. Changes to the controlled group, if any, are not applied until a subsequent run of the Group Family.
  • Failed to create controlled group  Administration Service encountered an error when running a Group Family, failed to create a controlled group. Administration Service will attempt to create that controlled group during a subsequent run of the Group Family.
  • Failed to update membership list of controlled group  Administration Service encountered an error when running a Group Family, failed to update membership data for a controlled group. The membership list of the controlled group may be incorrect until a subsequent run of the Group Family.
  • Failed to create run task  Administration Service failed to create a task to run a Group Family. The Group Family is inoperative until the task is created.
  • Failed to modify run task  Administration Service failed to update a task to run a Group Family. The Group Family runs in accordance with the earlier schedule settings of that task.
  • Failed to delete run task  Administration Service failed to delete a task to run a Group Family. The Group Family continues to run in accordance with the schedule settings of that task.
  • Run task has been started manually  A task to run a Group Family was started manually.
  • Group Family run has been completed  Administration Service has completed a run of a Group Family.
Group Family - Cannot find configuration storage group - Alert

This rule generates an alert indicating that the Administration Service failed to run a Group Family due to the following problem: The Group Family configuration storage group cannot be found. The Administration Service cannot run the Group Family until the problem is resolved.

The configuration storage group may have been either inaccessible or deleted. For details, refer to the alert description generated by this rule.

Group Family - Failed to retrieve configuration data - Alert

This rule generates an alert indicating that the Administration Service encountered the following problem when running a Group Family: Group Family configuration data cannot be retrieved from the configuration storage group. The Administration Service cannot run the Group Family until the problem is resolved. For details, refer to the alert description generated by this rule.

Group Family - Incorrect configuration data - Alert

This rule generates an alert indicating that the Administration Service failed to run a Group Family due to the following problem: Incorrect configuration data was encountered in the Group Family configuration storage group. The configuration storage group may have been corrupted. The run of the Group Family has been canceled. For details, refer to the alert description generated by this rule.

Group Family - Failed to retrieve configuration data for controlled group - Alert

This rule generates an alert indicating that the Administration Service encountered the following problem when running a Group Family: Failed to retrieve configuration data for a certain group that is under the control of the Group Family (controlled group). Changes to the controlled group may not be applied until a subsequent run of the Group Family. For details, refer to the alert description generated by this rule.

Group Family - Failed to retrieve data from container - Alert

This rule generates an alert indicating that the Administration Service encountered the following problem when running a Group Family: Failed to search a certain container within the Group Family scope. The groupings that were calculated during this run of the Group Family may not take into account information about some objects held in that container. For details, refer to the alert description generated by this rule.

During a subsequent run of the Group Family, the Administration Service will attempt to search the entire Group Family scope, including the failed container, in order to re-calculate the Group Family groupings.

Group Family - Failed to update configuration data - Alert

This rule generates an alert indicating that the Administration Service encountered the following problem when running a Group Family: Failed to update configuration data in the Group Family configuration storage group. The Active Roles console may display incorrect information about results of the Group Family run and about groups that are under the control of the Group Family (controlled groups). For details, refer to the alert description generated by this rule.

During a subsequent run of the Group Family, the Administration Service will attempt to update configuration data in the configuration storage group.

Group Family - Failed to update configuration data for controlled group - Alert

This rule generates an alert indicating that the Administration Service encountered the following problem when running a Group Family: Failed to update configuration data for a certain group that is under the control of the Group Family (controlled group). The group is removed from the control of the Group Family. For details, refer to the alert description generated by this rule.

During a subsequent run of the Group Family, the Administration Service will attempt to locate the failed group and put it under the control of the Group Family.

Group Family - Cannot find controlled group - Alert

This rule generates an alert indicating that the Administration Service encountered the following problem when running a Group Family: Cannot find a certain group that is under the control of the Group Family (controlled group). Some changes to the controlled group may not be applied. For details, refer to the alert description generated by this rule.

During a subsequent run of the Group Family, the Administration Service will attempt to locate the controlled group and apply the changes, if any, to that group.

Group Family - Failed to create controlled group - Alert

This rule generates an alert indicating that the Administration Service encountered the following problem when running a Group Family: Failed to create a certain group to be put under the control of the Group Family (controlled group). For details, refer to the alert description generated by this rule.

During a subsequent run of the Group Family, the Administration Service will attempt to create the controlled group and apply the changes, if any, to that group.

Group Family - Failed to update membership list of controlled group - Alert

This rule generates an alert indicating that the Administration Service encountered the following problem when running a Group Family: Failed to update the membership list of a certain group that is under the control of the Group Family (controlled group). Some changes to the membership list of the controlled group may not be applied. For details, refer to the alert description generated by this rule.

During a subsequent run of the Group Family, the Administration Service will attempt to locate the controlled group and apply the changes, if any, to the membership list of that group.

Group Family - Failed to create run task - Alert

This rule generates an alert indicating that the Administration Service failed to create a task to run a Group Family. The Group Family is inoperative until the task is created. For details, refer to the alert description generated by this rule.

Group Family - Failed to modify run task - Alert

This rule generates an alert indicating that the Administration Service failed to update a task to run a Group Family. The Group Family continues to run in accordance with the earlier schedule settings of that task. For details, refer to the alert description generated by this rule.

Try to adjust the schedule settings by using the Schedule tab in the Properties dialog box for the Group Family configuration storage group, in the Active Roles console.

Group Family - Failed to delete run task - Alert

This rule generates an alert indicating that the Administration Service failed to delete a task to run a Group Family while the configuration storage group of that Group Family was successfully deleted. The Group Family continues to run in accordance with the schedule settings of that task, which may cause an error situation. For details, refer to the alert description generated by this rule.

Delete the run task manually. You can do this by switching the Active Roles console into Raw view mode, and then deleting the appropriate task from the Configuration/Server Configuration/Scheduled Tasks/Group Family container.

Group Family - Run task has been started manually - Alert

This rule generates an alert indicating that an administrator has forced Active Roles to run a Group Family. For details, refer to the alert description generated by this rule.

The administrator could start the run task for a Group Family by using the Force Run command on the configuration storage group of that Group Family, in the Active Roles console.

Group Family run has been completed - Alert

This rule generates an alert indicating that the Administration Service has completed the run task for a Group Family. For task results, refer to the alert description generated by this rule.

The alert description also includes the name of the Group Family configuration storage group, so you could use the Properties dialog box for that group in order to examine task results in more detail.

Internal error - Alert

This rule generates an alert when a fatal error occurs at Administration Service run time. Normally, the alert indicates that Administration Service execution stopped.

Related Documents

The document was helpful.

Select Rating

I easily found the information I needed.

Select Rating