locked
CRM 2011 New Deployment error (permissions?) RRS feed

  • Question

  • Hi all,

    Trying to set up a new organisation from deployment manager. I get an error which states that 'Name translation: Could not find the name or insufficient right to see name. (Exception from HRESULT: 0x80072116)'. When I go to help, it says I may not have the correct permissions on the PrivUserGroup etc. groups...but I'm a domain admin and can create child objects, read them etc. Has anyone seen this before? The log file displays the following:

    18:28:21|Verbose| Method exit: Microsoft.Crm.Tools.EDW.Framework.EDWTool.PropagateContext
    18:28:21|Verbose| Method entry: Microsoft.Crm.Tools.EDW.Framework.GroupCollection.Constructor()
    18:28:21|Verbose| Method exit: Microsoft.Crm.Tools.EDW.Framework.GroupCollection.Constructor()
    18:28:21|Verbose| Method entry: Microsoft.Crm.Tools.EDW.Framework.GathererCollection.Constructor()
    18:28:21|Verbose| Method exit: Microsoft.Crm.Tools.EDW.Framework.GathererCollection.Constructor()
    18:28:21|Verbose| Built gatherer and sniffer collections.
    18:28:21|Verbose| Cleanup completed.
    18:28:21|Verbose| Calling sniffer collect.
    18:28:21|Verbose| Calling sniffer collect.
    18:28:21|Verbose| Calling sniffer collect.
    18:28:21|Verbose| Collection ran.
    18:28:21|Verbose| Collection completed.
    18:28:21|Verbose| Gatherers ran.
    18:28:21|Verbose| Gathering completed.
    18:28:21|Verbose| Calling sniffer process.
    18:28:21|Verbose| Calling sniffer process.
    18:28:21|Verbose| Calling sniffer process.
    18:28:21|Verbose| Processing ran.
    18:28:21|Verbose| Processing completed.
    18:28:21|   Info| Group Microsoft CRM Organization
    18:28:21|   Info| Check OrgUniqueNameValidator: Success
    18:28:21|   Info| Check OrgFriendlyNameValidator: Success
    18:28:21|   Info| Check BaseCurrencyValidator: Success
    18:28:21|Verbose| Retrieving information from database Provider=SQLOLEDB;Data Source=UKWTSVULM703;Integrated Security=True;Initial Catalog=MSCRM_CONFIG;Connect Timeout=60 ...
    18:28:21|  Error| Check ActiveDirectoryRightsValidator : Failure: Name translation: Could not find the name or insufficient right to see name. (Exception from HRESULT: 0x80072116)

    18:28:21|   Info| Group Microsoft SQL Server™
    18:28:21|   Info| Check CrmSqlDomainValidator: Success
    18:28:21|   Info| Check SqlServerAgentValidator: Success
    18:28:21|   Info| Check SqlInstanceNameValidator: Success
    18:28:22|   Info| SQL Server Version: 10.50.1600.1
    18:28:22|   Info| SQL Server Edition: 3
    18:28:22|   Info| Check SqlServerValidator: Success
    18:28:22|   Info| Check SysAdminValidator: Success
    18:28:22|Verbose| The supported collation 'Latin1_General_CI_AI' matches the language of the database's collation 'Latin1_General_CI_AI'
    18:28:22|   Info| The case sensitivity of the database collation is correct.
    18:28:22|   Info| The database collation is correct.
    18:28:22|   Info| Check SqlCollationValidator: Success

    It appears to follow the MSCRM_CONFIG database access. But again, I'm a domain admin and can access the database just fine by going to SQL Management Studio. Please, any advice is much appreciated, pulling my hair out!

    Thursday, August 22, 2013 5:35 PM

Answers

  • There are two potential issues here.  First of all, you need to be a deployment administrator in deployment manager, this is not an AD group or permission, this is exclusive to deployment manager.  The installing user is one by default and only deployment admins can add deployment admins.  Deployment admins are added in deployment manager itself.

    This could also be a problem with your deployment service account permissions.

    The deployment service account (not your account) controls what happens in deployment manager.  Check that account out, it needs SA on the SQL Server and some other privs (see below).  Its one of several service accounts that would have hopefully been properly created when your CRM implementation was provisioned.

    Deployment Web Service (CRMDeploymentServiceAppPool Application Pool identity)

    • Domain Users membership.
    • That account must be granted the Logon as service permission in the Local Security Policy.
    • Local administrator group membership is required to perform organization database operations (such as create new or import organization) only if the following conditions are true:

      • The Microsoft SQL Server specified for the organization database is on the same computer as the Deployment Web Service server role.
      • The Web Application Server server role is running on the same computer as the Deployment Web Service server role.
    • Local administrator group membership on the computer where the Deployment Web Service is running.
    • Local administrator group membership on the computer where SQL Server is running.
    • Sysadmin permission on the instance of SQL Server to be used for the configuration and organization databases.
    • Folder read and write permission on the Trace and CRMWeb folders, by default located under \Program Files\Microsoft Dynamics CRM\, and user account %AppData% folder on the local computer.
    • Read and write permission to the HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSCRM and HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\MSCRMSandboxService subkeys in the Windows registry.
    • CRM_WPG group membership. This group is used for IIS worker processes. The group is created and the membership is added during Microsoft Dynamics CRM Server Setup.
    • The service account may need an SPN for the URL used to access the website that is associated with it. 


    Jamie Miley

    Check out RBA Today!

    Check out my about.me profile!
    http://mileyja.blogspot.com
    Linked-In Profile
    Follow Me on Twitter!



    Monday, August 26, 2013 9:04 PM
    Moderator