Article ID: 317872 - Last Review: July 21, 2011 - Revision: 19.0 How to troubleshoot SMS Administrator console connectivity
This article was previously published under Q317872 On This PageINTRODUCTION
If you are using SMS and you try to connect to the site server, you may receive a "Connection Failed" message. Or, the nodes may not be displayed after you are connected. Additionally, errors that are similar to the following may be logged in the AdminUI.log file on the server: Error: Possible UI connection error code is -2147023174 [0x800706ba]
Error: Possible UI connection error code is -2146959355 [0x80080005] Error: Possible UI connection error code is -2147217394 Error: Possible UI connection error code is -2147217389[0x80041013] Failed to execute method GetProviderVersion! Function GetProviderVersion returns empty string of ProviderVersion. Wbem call failed: T_WbemSyncEnumToContainer_Core, return code: -2147217389 We fail to get the ProviderVersion. SiteCode - SiteServerName , Provider Version : Failed to set the connection. error code: -2147217389
Error(ConnectServer):
Possible UI connection error code is -2147024891 Error: Possible UI connection error code is -2147024891 [0x80070005] [994][<date> <time>]:Error(CheckForDisconnect2): Invalid service pointer.
WMI connection has been dropped. : -2147024891 [0x80070005] MORE INFORMATIONHow to grant access to the SMS Administrator consoleIn order to access a local or remote SMS Administrator console, users must be members of the SMS Admins local group. The SMS Admins group is explicitly granted Enable Account and Remote Enable on the Root\SMS namespace. The SMS Admins group provides its members with access to the SMS Provider, through WMI. Add Users to the SMS Admins group when they need to access the SMS Administrator console, but do not have to be Local Administrators. If you want to use a different local group to grant access to the SMS Administrator console, you must also grant that local or domain local group the same WMI permission as the SMS Admins group. To grant access to the SMS Administrator console, follow these steps:
266712
(http://support.microsoft.com/kb/266712/
)
SMS: Security based on global groups fails in Windows 2000 domains
For more information about how to grant additional users access to the SMS Administrator console, click the following article number to view the article in the Microsoft Knowledge Base:
252674
(http://support.microsoft.com/kb/252674/
)
SMS: How to set up a Help Desk administrator
For more information, click the following article numbers to view the articles in the Microsoft Knowledge Base:
201126
(http://support.microsoft.com/kb/201126/
)
Troubleshooting connectivity to the SMS site database
200670
(http://support.microsoft.com/kb/200670/
)
SMS: Customizing the Systems Management Server Administrator console
How to troubleshoot SMS Administrator console connectivityIf you are testing a remote SMS Administrator console, make sure that the latest SMS service pack has been applied to this console. If the service pack has not been applied, an error that is similar to the following may be logged in the AdminUI.log file:CLASS_SMS_ContextMethods,METHOD_GetContextHandle! Failed to set the connection. error code: -2147217407 Run the Setup program from the service pack source to determine whether the SMS Administrator console is the only component that must be upgraded.
Troubleshooting SMS namespace connectivityMake sure that the user can connect to the SMS namespace and the SMS_'sitecode' namespaces. To do this, follow these steps:
How to troubleshoot server connectivityDetermine whether you can connect to the server that the provider is located on. The server is defined in the NamespacePath value that you determined in the "How to troubleshoot SMS namespace connectivity" section. Typically, this server is the same server.
Other security issuesUse the troubleshooting procedures that are described in this section if any one of the following conditions is true:
Verify the Windows Firewall configurationWindows XP SP2 and Windows Server 2003 SP1 include the Windows Firewall feature. If you run the SMS Administrator Console on a Windows XP SP2-based or a Windows Server 2003 SP1-based computer that has the firewall enabled, you must enable the Unsecapp.exe program and TCP port 135 to pass through the Windows Firewall. To do this, follow these steps:
Check DCOM security settingsWarning Do not make these changes unless you cannot resolve this issue by adding the Unsecapp.exe program and TCP port 135 to the exceptions list.Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows You may not resolve this issue by adding these exceptions to Windows Firewall. You may have to set anonymous remote permissions in DCOM for the client computer. To do this on the Windows XP SP2-based computer that is running the SMS Administrator console, follow these steps:
Determine whether the default DCOM permissions have been changedCheck for the DefaultAccessPermission value under the following registry subkey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole Important This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base: 322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows Important Before you delete this value, make sure that you have tried to resolve the issue by following the DCOM troubleshooting steps in in this article. Also, back up the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole registry subkey. To delete the DefaultAccessPermission value, follow these steps:
900960
(http://support.microsoft.com/kb/900960/
)
You cannot perform actions such as search and drag when you use a Windows Server 2003-based computer
Include the Anonymous Logon security group in the Everyone security groupIf the procedures that are previously described do not resolve the permissions issue for the SMS Administrator console, it may be difficult to do the following:
If the EveryoneIncludesAnonymous registry entry is set to REG_DWORD 0x1, the Local Security Authority (LSA) includes the security identifier (SID) of the Everyone security group in the anonymous user's access token. To set the value of the EveryoneIncludesAnonymous registry entry, use either of the following methods. Method 1: Set the EveryoneIncludesAnonymous registry entry by using local security settings
Method 2: Set the EveryoneIncludesAnonymous registry value by using Registry EditorImportant This section, method, or task contains steps that tell you how to modify the registry. However, serious problems might occur if you modify the registry incorrectly. Therefore, make sure that you follow these steps carefully. For added protection, back up the registry before you modify it. Then, you can restore the registry if a problem occurs. For more information about how to back up and restore the registry, click the following article number to view the article in the Microsoft Knowledge Base:322756
(http://support.microsoft.com/kb/322756/
)
How to back up and restore the registry in Windows
278259
(http://support.microsoft.com/kb/278259/
)
Everyone group does not include anonymous security identifier
Additional connectivity testsStart the WMI Control on the site server. Do not start the WMI control on the provider server if this server is different. Click the Logging tab, and then set the logging level to Verbose to increase the logging to the Windows_folder\System32\Wbem\Logs\Wbemcore.log file.Analyze this log on the site server. You see all the WMI traffic that is generated. Look for the query for SMS_Providerlocation that occurred when an SMS Administrator console tried to connect. If this query is present, you can confirm that there is communication between the console and the site server. Test connectivity from the site server back to the requesting SMS Administrator console. Connectivity may not exist in the following scenarios:
Known issues with Microsoft ISA server or Checkpoint VPN softwareIf you cannot expand some nodes on a remote console over a remote connection from a Windows 2003 SP1 computer: Remote Procedure Call-based operations may fail if certain firewall and VPN products deny network requests. These network requests may fail on computers where you apply Windows Server 2003 Service Pack 1 (SP1) to a Windows Server 2003-based computer or your OEM or retail installation media includes SP1 updates. The following products may deny these network requests:
899148
(http://support.microsoft.com/kb/899148/
)
Some firewalls may reject network traffic that originates from Windows Server 2003 Service Pack 1-based computers
This issue may also occur when the following conditions are true:
154596
(http://support.microsoft.com/kb/154596/
)
How to configure RPC dynamic port allocation to work with firewalls
REFERENCES
For more information about how to set WMI Namespace security in Windows XP, click the following article number to view the article in the Microsoft Knowledge Base:
295292
(http://support.microsoft.com/kb/295292/
)
How to set WMI Namespace security in Windows XP
For more information about Systems Management Server WMI terms and concepts, click the following article number to view the article in the Microsoft Knowledge Base:
216738
(http://support.microsoft.com/kb/216738/
)
SMS: WMI terms and concepts
For more information about SMS Administrator connection problems, click the following article numbers to view the articles in the Microsoft Knowledge Base:
314169
(http://support.microsoft.com/kb/314169/
)
SMS: "Connection failed" error message when you run Administrator console on Windows 2000
272937
(http://support.microsoft.com/kb/272937/
)
SMS: Administrator console does not connect to Windows NT 4.0 Site Server
913000
(http://support.microsoft.com/kb/913000/
)
After you install Windows Server 2003 Service Pack 1, you can no longer connect to the SMS site server by using a remote SMS Administrator console
908478
(http://support.microsoft.com/kb/908478/
)
One or more site objects may be missing after you expand a site hierarchy node in a remote System Management Server 2003 Administrator Console
For more information about how to help secure remote WMI connections, visit the following Microsoft Web site:http://msdn2.microsoft.com/en-us/library/aa392291.aspx
(http://msdn2.microsoft.com/en-us/library/aa392291.aspx)
For more information about granular COM permissions, visit the following Microsoft Web site:http://technet2.microsoft.com/WindowsServer/en/library/4c9a2873-2010-4dbb-b9dd-6a7d1e275f0f1033.mspx?mfr=true
(http://technet2.microsoft.com/WindowsServer/en/library/4c9a2873-2010-4dbb-b9dd-6a7d1e275f0f1033.mspx?mfr=true)
For a list of frequently asked questions about site systems, visit the following Microsoft Web site: http://www.microsoft.com/technet/sms/2003/library/techfaq/tfaq02.mspx
(http://www.microsoft.com/technet/sms/2003/library/techfaq/tfaq02.mspx)
APPLIES TO
| Other Resources Other Support Sites
CommunityGet Help NowArticle Translations
|





















Back to the top