<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: The SharePoint PeoplePicker isn&#8217;t showing users from a trusted domain</title>
	<atom:link href="http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/feed/" rel="self" type="application/rss+xml" />
	<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/?utm_source=rss&#038;utm_medium=rss&#038;utm_campaign=the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain</link>
	<description>Technical notes for tricky situations</description>
	<lastBuildDate>Mon, 25 Jul 2011 04:29:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
	<item>
		<title>By: Rob</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-327</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Thu, 11 Nov 2010 16:16:57 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-327</guid>
		<description>Did recreating the site collection work, Gavin?  Glad I was of some help :)</description>
		<content:encoded><![CDATA[<p>Did recreating the site collection work, Gavin?  Glad I was of some help <img src='http://kipper.org.uk/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gavin Pollock</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-324</link>
		<dc:creator>Gavin Pollock</dc:creator>
		<pubDate>Thu, 21 Oct 2010 11:17:41 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-324</guid>
		<description>Rob, thanks so much for all that info. It really helped me clarify my thoughts. I had done the apppassword and all the rest pretty much.

Checked the DNS settings and all, but at the same time the User Profile Sync Connection to the same domain was working with that account and returning user accounts.

Eventually, though I would create a standard web application on another port to see if I still had issues. Went as Farm Admin to the web applications, and the &#039;New&#039; was greyed out. Strange... Logged in as Domain Admin and had the permissions to create the Web App.

So then tried to run the script as Domain Admin rather than Farm Admin, and hey presto the property got created (validated with Get-Property), on both the new web app, and the existing one.

Now the new web app is correctly searching the User Domain, as is the root site collection of the existing web app. However the tenant site collection created under that is giving another error now:

Claims Search call failed. Error Message: Object reference not set to an instance of an object.  Callstack:    at Microsoft.SharePoint.WebControls.PeopleQueryControl.IssueClaimsQuery(String searchPattern, String providerID, String hierarchyNodeID, Int32 pageSize, SPProviderHierarchyTree spgroupTree).

I&#039;m going to try delete the site collection for the tenant and recreate it all as Domain Admin and see if it works then!

Cheers
Gavin</description>
		<content:encoded><![CDATA[<p>Rob, thanks so much for all that info. It really helped me clarify my thoughts. I had done the apppassword and all the rest pretty much.</p>
<p>Checked the DNS settings and all, but at the same time the User Profile Sync Connection to the same domain was working with that account and returning user accounts.</p>
<p>Eventually, though I would create a standard web application on another port to see if I still had issues. Went as Farm Admin to the web applications, and the &#8216;New&#8217; was greyed out. Strange&#8230; Logged in as Domain Admin and had the permissions to create the Web App.</p>
<p>So then tried to run the script as Domain Admin rather than Farm Admin, and hey presto the property got created (validated with Get-Property), on both the new web app, and the existing one.</p>
<p>Now the new web app is correctly searching the User Domain, as is the root site collection of the existing web app. However the tenant site collection created under that is giving another error now:</p>
<p>Claims Search call failed. Error Message: Object reference not set to an instance of an object.  Callstack:    at Microsoft.SharePoint.WebControls.PeopleQueryControl.IssueClaimsQuery(String searchPattern, String providerID, String hierarchyNodeID, Int32 pageSize, SPProviderHierarchyTree spgroupTree).</p>
<p>I&#8217;m going to try delete the site collection for the tenant and recreate it all as Domain Admin and see if it works then!</p>
<p>Cheers<br />
Gavin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-319</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Tue, 19 Oct 2010 10:55:36 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-319</guid>
		<description>I&#039;m more experienced with 2007, rather than 2010, but my understanding is that the same steps are needed to overcome domain trust issues.

You didn&#039;t mentioning running the step:

stsadm –o setapppassword –password MyPassword

If you didn&#039;t first set the encryption key, you can&#039;t store the domain password to access the other domains.  This could cause the failure to store the value highlighted by the use of the getproperty command.

You also don&#039;t mention the nature of the trusts, so it&#039;s difficult to give much advice.  2010 is much more strict than 2007 out of the box - only the local domain will be searched now, unlike 2007.  Of course, there is another potential issue with trust relationships over domains - the ports need to be opened.  Depending on the nature of the &quot;resource&quot; domain, they may well be safeguarded over the network.  Off the top of my head, you need at least 88, 139 and 445 open.  You also need to make sure that DNS is set correctly - if domain resolution on your local domain doesn&#039;t point you to the correct remote domain servers, the resolution won&#039;t work.

Other possibilities include slightly incorrect syntax in your instruction.  First, you need to make sure you are specifiying the specific top level web application, not the server.  If your web application path is http://exampledomain.org/sites/ then specifying 

stsadm -o setproperty -url http://exampledomain.org -pn “peoplepicker-searchadforests” -pv “domain:domainname.co.uk,DOMAIN\ADUserAccess,xxxxx”

won&#039;t work - it has to be the full web application URL.

Next, specifying the domain is rather a pain too.  you need to specify all the domains involved, which will include the local domain, not just the remote user domain.  You need to make sure you specify the AD domain name, which isn&#039;t necessarily the same as the email address or usernames, depending on the config - many use abstract *.local domain names.  putting it together from these examples, you&#039;d need something like:

stsadm –o setapppassword –password MyPassword

followed by:

stsadm -o setproperty -url http://exampledomain.org/sites/ -pn “peoplepicker-searchadforests” -pv “domain:resourcedomain.local;domain:userdomain.local,USERDOMAIN\ADUserAccess,xxxxx”</description>
		<content:encoded><![CDATA[<p>I&#8217;m more experienced with 2007, rather than 2010, but my understanding is that the same steps are needed to overcome domain trust issues.</p>
<p>You didn&#8217;t mentioning running the step:</p>
<p>stsadm –o setapppassword –password MyPassword</p>
<p>If you didn&#8217;t first set the encryption key, you can&#8217;t store the domain password to access the other domains.  This could cause the failure to store the value highlighted by the use of the getproperty command.</p>
<p>You also don&#8217;t mention the nature of the trusts, so it&#8217;s difficult to give much advice.  2010 is much more strict than 2007 out of the box &#8211; only the local domain will be searched now, unlike 2007.  Of course, there is another potential issue with trust relationships over domains &#8211; the ports need to be opened.  Depending on the nature of the &#8220;resource&#8221; domain, they may well be safeguarded over the network.  Off the top of my head, you need at least 88, 139 and 445 open.  You also need to make sure that DNS is set correctly &#8211; if domain resolution on your local domain doesn&#8217;t point you to the correct remote domain servers, the resolution won&#8217;t work.</p>
<p>Other possibilities include slightly incorrect syntax in your instruction.  First, you need to make sure you are specifiying the specific top level web application, not the server.  If your web application path is <a href="http://exampledomain.org/sites/" rel="nofollow">http://exampledomain.org/sites/</a> then specifying </p>
<p>stsadm -o setproperty -url <a href="http://exampledomain.org" rel="nofollow">http://exampledomain.org</a> -pn “peoplepicker-searchadforests” -pv “domain:domainname.co.uk,DOMAIN\ADUserAccess,xxxxx”</p>
<p>won&#8217;t work &#8211; it has to be the full web application URL.</p>
<p>Next, specifying the domain is rather a pain too.  you need to specify all the domains involved, which will include the local domain, not just the remote user domain.  You need to make sure you specify the AD domain name, which isn&#8217;t necessarily the same as the email address or usernames, depending on the config &#8211; many use abstract *.local domain names.  putting it together from these examples, you&#8217;d need something like:</p>
<p>stsadm –o setapppassword –password MyPassword</p>
<p>followed by:</p>
<p>stsadm -o setproperty -url <a href="http://exampledomain.org/sites/" rel="nofollow">http://exampledomain.org/sites/</a> -pn “peoplepicker-searchadforests” -pv “domain:resourcedomain.local;domain:userdomain.local,USERDOMAIN\ADUserAccess,xxxxx”</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gavin Pollock</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-318</link>
		<dc:creator>Gavin Pollock</dc:creator>
		<pubDate>Fri, 15 Oct 2010 15:00:31 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-318</guid>
		<description>Hi there,
We have just setup a multi-tenancy SP 2010 environment, where the User domain is separate from the Resource (Server) domain.

I have setup a hostname based site collection for a test company and everything seems to be working correctly, including the User Profile Application correctly retrieving their profiles from the User domain (when you specify the OU of the company with the Set-SPSiteSubscriptionConfig cmdlet + in conjunction have a Sync Connection setup to retrieve the accounts from the other domain)

But the People picker just isn&#039;t playing ball.
I am running the command:
stsadm -o setproperty -url &quot;http://app01&quot; -pn &quot;peoplepicker-searchadforests&quot; -pv &quot;domain:domainname.co.uk,DOMAIN\ADUserAccess,xxxxx&quot;
as I thought maybe this was required in addition. But then the result of the Get command to check is that the property doesn&#039;t exist:
stsadm.exe -o getproperty -url http://app01 -pn &quot;peoplepicker-searchadforests&quot;


Any ideas!?
Thanks
Gavin</description>
		<content:encoded><![CDATA[<p>Hi there,<br />
We have just setup a multi-tenancy SP 2010 environment, where the User domain is separate from the Resource (Server) domain.</p>
<p>I have setup a hostname based site collection for a test company and everything seems to be working correctly, including the User Profile Application correctly retrieving their profiles from the User domain (when you specify the OU of the company with the Set-SPSiteSubscriptionConfig cmdlet + in conjunction have a Sync Connection setup to retrieve the accounts from the other domain)</p>
<p>But the People picker just isn&#8217;t playing ball.<br />
I am running the command:<br />
stsadm -o setproperty -url &#8220;http://app01&#8243; -pn &#8220;peoplepicker-searchadforests&#8221; -pv &#8220;domain:domainname.co.uk,DOMAIN\ADUserAccess,xxxxx&#8221;<br />
as I thought maybe this was required in addition. But then the result of the Get command to check is that the property doesn&#8217;t exist:<br />
stsadm.exe -o getproperty -url <a href="http://app01" rel="nofollow">http://app01</a> -pn &#8220;peoplepicker-searchadforests&#8221;</p>
<p>Any ideas!?<br />
Thanks<br />
Gavin</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-283</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 22 Jan 2010 20:50:49 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-283</guid>
		<description>Also we have multple domains as well, all are two way and verified no issues.
only one domain has this issue default and another have no issues I can find those accounts.</description>
		<content:encoded><![CDATA[<p>Also we have multple domains as well, all are two way and verified no issues.<br />
only one domain has this issue default and another have no issues I can find those accounts.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-282</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 22 Jan 2010 20:48:57 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-282</guid>
		<description>We have the exact problem accept we have a two way trust and peoplepicker is only finding users inside their own sites.
We have verified that the property is not set it states &quot;NO&quot;
We have run almost in not all STSADM commands available no affect.
Reuilt the SSP&#039;s and all WFE&#039;S No affect.
Some users can sign in but have no access just get read only and some get request access page.
If they get request access page I can then add them.
Very weird scenario and have no clues this issue has been happening now for like 2 months and no body seems to have a clue not even Microsoft</description>
		<content:encoded><![CDATA[<p>We have the exact problem accept we have a two way trust and peoplepicker is only finding users inside their own sites.<br />
We have verified that the property is not set it states &#8220;NO&#8221;<br />
We have run almost in not all STSADM commands available no affect.<br />
Reuilt the SSP&#8217;s and all WFE&#8217;S No affect.<br />
Some users can sign in but have no access just get read only and some get request access page.<br />
If they get request access page I can then add them.<br />
Very weird scenario and have no clues this issue has been happening now for like 2 months and no body seems to have a clue not even Microsoft</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-166</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Mon, 26 Oct 2009 12:40:32 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-166</guid>
		<description>Hi Tom - hopefully the new post on More People Picker Issues will be helpful - http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/</description>
		<content:encoded><![CDATA[<p>Hi Tom &#8211; hopefully the new post on More People Picker Issues will be helpful &#8211; <a href="http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/" rel="nofollow">http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-165</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 23 Oct 2009 19:34:53 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-165</guid>
		<description>Few details first
We have a MOSS 2007 FARM AND 3 DOMAINS all have a two way trust.
We have over 78 sites all of which stopped with no known reason from being able to find users that are in one of the domains we can find the users in the view profiles yet we can no longer find users using peoplepicker for any users from the one domain.
We have tried this command you have provided and they come back with commandline error 
stsadm -o setproperty -pn peoplepicker-searchadforests -pv domain:full domain name,-userlogin domain\username password –url http://webapp url

Any help would be great we have been stumped for over a week,</description>
		<content:encoded><![CDATA[<p>Few details first<br />
We have a MOSS 2007 FARM AND 3 DOMAINS all have a two way trust.<br />
We have over 78 sites all of which stopped with no known reason from being able to find users that are in one of the domains we can find the users in the view profiles yet we can no longer find users using peoplepicker for any users from the one domain.<br />
We have tried this command you have provided and they come back with commandline error<br />
stsadm -o setproperty -pn peoplepicker-searchadforests -pv domain:full domain name,-userlogin domain\username password –url <a href="http://webapp" rel="nofollow">http://webapp</a> url</p>
<p>Any help would be great we have been stumped for over a week,</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Gene</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-151</link>
		<dc:creator>Gene</dc:creator>
		<pubDate>Thu, 23 Jul 2009 02:56:10 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-151</guid>
		<description>Hi,

This is exactly what I am looking for.  I am currently setting up an extranet at my work.  Qustion.  How do you incorporate filter strings to the above example?  For example, I want to return only accounts that are active.

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>This is exactly what I am looking for.  I am currently setting up an extranet at my work.  Qustion.  How do you incorporate filter strings to the above example?  For example, I want to return only accounts that are active.</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chandrika</title>
		<link>http://kipper.org.uk/index.php/2009/05/the-sharepoint-peoplepicker-isnt-showing-users-from-a-trusted-domain/comment-page-1/#comment-79</link>
		<dc:creator>Chandrika</dc:creator>
		<pubDate>Fri, 22 May 2009 05:16:36 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=55#comment-79</guid>
		<description>Hi ,
When i login with external user in to the sharepoint site i am not able to see all AD users but when log in with AD user then i am able to see all the users from the domain in people picker.
we are using ECTS to add External user.

Please help me solve this issue its very critical.

Thanks in advance</description>
		<content:encoded><![CDATA[<p>Hi ,<br />
When i login with external user in to the sharepoint site i am not able to see all AD users but when log in with AD user then i am able to see all the users from the domain in people picker.<br />
we are using ECTS to add External user.</p>
<p>Please help me solve this issue its very critical.</p>
<p>Thanks in advance</p>
]]></content:encoded>
	</item>
</channel>
</rss>

