David's profileDavid Moisan's ITPhotosBlogLists Tools Help
    August 05

    SBS 2003 SP 1/ISA 2004: WMI scripts don't work (Part 1)

    If you just upgraded to SBS 2003 SP1 with ISA 2004 and you use scripts on the SBS machine to monitor and control your client machines or member servers (such as the scripts you find at Technet Script Center), your scripts might not work any longer.
     
    This problem is acute when you use WMI scripts (such as those from the famous Scriptomatic tool) to run against a remote machine and get information from it.  The scripts may give no results, or fail with a 0x800706ba error.
     
    Scripts that you run on a workstation against your SBS machine may fail as well.
     
    After running in circles for a month, I figured it out.  I'll explain how I finally diagnosed this in my next post, but if you have this problem and just want to stop banging your head, here's how to fix it:
     
    On the SBS machine, open up ISA Server Management (if you don't remember where it is, click Start/All Programs/Microsoft ISA Server/ISA Server Managment)
    Find "Firewall Policy" on the left pane and right click it.  Select Edit System Policy.  The System Policy Editor should pop up.
     
    Scroll down to Authentication Services and select it.  In the General tab, note the checkbox marked "Enforce strict RPC compliance".  Note the information balloon that reads:  "When 'Enforce strict RPC compliance' is not selected, additional RPC type protocols, such as DCOM, will be enabled." 
     
    Bingo.
     
    Uncheck "Enforce strict RPC compliance".  Click OK.  Note the bar on the top of the ISA console that prompts you to apply or discard your changes.  Click Apply.  Click OK.
     
    Your WMI scripts should now work.
     
     

    Comments (2)

    Please wait...
    Sorry, the comment you entered is too long. Please shorten it.
    You didn't enter anything. Please try again.
    Sorry, we can't add your comment right now. Please try again later.
    To add a comment, you need permission from your parent. Ask for permission
    Your parent has turned off comments.
    Sorry, we can't delete your comment right now. Please try again later.
    You've exceeded the maximum number of comments that can be left in one day. Please try again in 24 hours.
    Your account has had the ability to leave comments disabled because our systems indicate that you may be spamming other users. If you believe that your account has been disabled in error please contact Windows Live support.
    Complete the security check below to finish leaving your comment.
    The characters you type in the security check must match the characters in the picture or audio.

    To add a comment, sign in with your Windows Live ID (if you use Hotmail, Messenger, or Xbox LIVE, you have a Windows Live ID). Sign in


    Don't have a Windows Live ID? Sign up

    Picture of Anonymous
    mike wrote:
    THANK YOU (insert diety) FOR THIS BLOG!!!
     
    I spent 4 hours today trying to narrow down what was causing this. Eventually (read:3.5 hours later) I found the log entries and searched online for "allow rpc from isa server to trusted servers", and eventually found your posting.
     
    Thanks again,
     
    -Mike
    Jan. 30
    Picture of Anonymous
    Jeff Dettloff wrote:
    Great find! Thanks for blogging this. I was also having difficulting getting this to work properly.
    Dec. 6

    Trackbacks

    The trackback URL for this entry is:
    http://dmoisan.spaces.live.com/blog/cns!95CB015E3E4A702A!121.trak
    Weblogs that reference this entry
    • None