<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: More People Picker issues</title>
	<atom:link href="http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/feed/" rel="self" type="application/rss+xml" />
	<link>http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/</link>
	<description>Technical notes for tricky situations</description>
	<lastBuildDate>Tue, 02 Mar 2010 14:28:30 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Rob</title>
		<link>http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/comment-page-1/#comment-289</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Mon, 08 Feb 2010 11:00:10 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=95#comment-289</guid>
		<description>Have you tried manually specifying the domain list in the people picker, with user names and passwords that have access to view the AD? You need to specify these via the command line otherwise it will use the account that the service is running under, and if that doesn&#039;t have access, neither will the people picker.

The mix of users signing in is probably due to a group membership that has been set somewhere.  If you specify authenticated users to have access to a site, they&#039;ll log on.  Incidentally, normally after logging on via a group, you&#039;ll see them showing up in the People Picker index, whether or not the People Picker can see the AD details beforehand.

In the import via the SSP, you specify a domain account in the GUI - the people picker won&#039;t use this.  It runs in the context of the service or usernames and passwords specified via stsadm.</description>
		<content:encoded><![CDATA[<p>Have you tried manually specifying the domain list in the people picker, with user names and passwords that have access to view the AD? You need to specify these via the command line otherwise it will use the account that the service is running under, and if that doesn&#8217;t have access, neither will the people picker.</p>
<p>The mix of users signing in is probably due to a group membership that has been set somewhere.  If you specify authenticated users to have access to a site, they&#8217;ll log on.  Incidentally, normally after logging on via a group, you&#8217;ll see them showing up in the People Picker index, whether or not the People Picker can see the AD details beforehand.</p>
<p>In the import via the SSP, you specify a domain account in the GUI &#8211; the people picker won&#8217;t use this.  It runs in the context of the service or usernames and passwords specified via stsadm.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/comment-page-1/#comment-285</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 22 Jan 2010 21:00:20 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=95#comment-285</guid>
		<description>Oh imports from the affected domain work perfectly still using the domain account given so its not a read right which is what peoplepicker should be doing.</description>
		<content:encoded><![CDATA[<p>Oh imports from the affected domain work perfectly still using the domain account given so its not a read right which is what peoplepicker should be doing.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/comment-page-1/#comment-284</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 22 Jan 2010 20:58:17 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=95#comment-284</guid>
		<description>We have not modified peoplepicker in anyway.
The tool only finds users in the site collections.
We have some users that can sign in and get access request page and then some that can actually sign in and see a page but still cannot be found in peoplepicker.
All trusts are correct.
Peoplepicker commands run
stsadm -o getproperty -url http://sitename -pn peoplepicker-onlysearchwithinsitecollection


stsadm -o setproperty -url http://sitename -pn &quot;peoplepicker-nowindowsaccountsfornonwindowsauthenticationmode&quot; -pv no


We did get the AD commands to work yet we still cannot see users in peoplepicker unless they are already in the site.
This still only affects one domain and most can authenticate we just cannot add them to a site.</description>
		<content:encoded><![CDATA[<p>We have not modified peoplepicker in anyway.<br />
The tool only finds users in the site collections.<br />
We have some users that can sign in and get access request page and then some that can actually sign in and see a page but still cannot be found in peoplepicker.<br />
All trusts are correct.<br />
Peoplepicker commands run<br />
stsadm -o getproperty -url <a href="http://sitename" rel="nofollow">http://sitename</a> -pn peoplepicker-onlysearchwithinsitecollection</p>
<p>stsadm -o setproperty -url <a href="http://sitename" rel="nofollow">http://sitename</a> -pn &#8220;peoplepicker-nowindowsaccountsfornonwindowsauthenticationmode&#8221; -pv no</p>
<p>We did get the AD commands to work yet we still cannot see users in peoplepicker unless they are already in the site.<br />
This still only affects one domain and most can authenticate we just cannot add them to a site.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/comment-page-1/#comment-277</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Fri, 27 Nov 2009 15:00:16 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=95#comment-277</guid>
		<description>I&#039;m not really able to answer your questions with the level of information available, I&#039;m afraid.  The PeoplePicker generally doesn&#039;t look at the profiles imported in the SSP anyway.  It sounds like an attempt to customise the people-picker on the webapp has been set up incorrectly, and thats blocking the response for any user.  Just check the articles on customiseing the PeoplePicker results, and update it with a blank custom query to set it back to default behaviour.  For question 2, do you mean the people picker is returning users from the other domain, or the ssp import is pulling in more users to the user directory than you want?  Those are very different questions.</description>
		<content:encoded><![CDATA[<p>I&#8217;m not really able to answer your questions with the level of information available, I&#8217;m afraid.  The PeoplePicker generally doesn&#8217;t look at the profiles imported in the SSP anyway.  It sounds like an attempt to customise the people-picker on the webapp has been set up incorrectly, and thats blocking the response for any user.  Just check the articles on customiseing the PeoplePicker results, and update it with a blank custom query to set it back to default behaviour.  For question 2, do you mean the people picker is returning users from the other domain, or the ssp import is pulling in more users to the user directory than you want?  Those are very different questions.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tom</title>
		<link>http://kipper.org.uk/index.php/2009/10/more-people-picker-issues/comment-page-1/#comment-243</link>
		<dc:creator>Tom</dc:creator>
		<pubDate>Fri, 20 Nov 2009 20:31:30 +0000</pubDate>
		<guid isPermaLink="false">http://kipper.org.uk/?p=95#comment-243</guid>
		<description>About the issues I posted, we found that some how the link between the sites and the ssp broke down, we have somewhat fixed the problem but we still have one webapp that will not find users that is in the ssp or the specific domain the other sites will find users and works just fine.
Ever seen this issue

Question 2
We also have a domain that we do not want any imports to come from yet we are pulliung them in and it is not specified in the profile import connections How can we keep the one from getting imported.</description>
		<content:encoded><![CDATA[<p>About the issues I posted, we found that some how the link between the sites and the ssp broke down, we have somewhat fixed the problem but we still have one webapp that will not find users that is in the ssp or the specific domain the other sites will find users and works just fine.<br />
Ever seen this issue</p>
<p>Question 2<br />
We also have a domain that we do not want any imports to come from yet we are pulliung them in and it is not specified in the profile import connections How can we keep the one from getting imported.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
