We have a curious thing happening with some new users. In this
example: They create their new My Site then go to Shared Documents to
upload a file. When they select Upload, they get a "forbidden 403"
error. If they wait and try later many times they can upload a file.
Has anyone seen this before?
We talked to Microsoft Support yesterday and I'm going to try
escalating the call: Here is how we were troubleshooting the problem:
-----------------------
My Site file upload permission errors (similar to other portal upload
errors we've seen).
Per instructions with our Microsoft rep, we tested with two domain
accounts that had never been used on the portal before.
• MS had us add the new user to the mba portal manually and
give them contributor rights.
• We then selected the My Site, a new My Site was created.
• We tried to upload a document and received a "forbidden, 403"
error.
• We tried with another new test account and received the same
error.
MS wanted to have us test with a newly created Shared Service
Provider and New Portal. This was all done on our production server.
Approximately four attempts to create the SSP failed. We were
finally successful when we stopped and started the "Windows
SharePoint Services Timer" service on MOSS. We used our "farm
account" with all of the following:
• We created a new Shared Service Provider
• We created a new My Site application
• We created a new portal application.
• We assigned the new portal to the new SSP.
• We added our test account users to the site (we didn't import
domain users into this test shared service provider)
• We logged in with the test account, selected My Site,
creating a new My Site.
• We successfully uploaded a document.
At this point our MS support offered two suggestions:
• Since the second Shared Service Provider worked in our test,
MS Support requested that we re-assign our production portal to use
the new Shared Service Provider.
I would not do this. If I did, we would lose all our
audience and search settings. All our targeted portal content would
no longer be targeted and maybe other unknown side effects. If we
did go this route, I would need to configure this exactly as our
current SSP. I would want to do this on a separate server first to
make sure our production site is not adversely affected.
• Change domain accounts for all SharePoint portals, app pools,
shared service provider etc, to use a single account. Then we would
run a series of command line scripts to update the portal to
recognize the new account. "How to change the passwords for service
accounts in SharePoint Server 2007 and in Windows SharePoint Services
3.0"
We will not do this. We built our server with separate
accounts based on recommendations from Microsoft. We have the white
paper to back this up. http://technet2.microsoft.com/Office/en-
us/library/f07768d4-ca37-447a-a056-1a67d93ef5401033.mspx?mfr=true
Final thoughts:
• Even though MS Support had success with our test SSP, Portal
and My Site, we don't know if that site would also exhibit the same
random permission problems like the production site. Additionally,
the two accounts we tested with on the production server that failed
previously, work now. In the words of our own IT professional who
put it plainly:
================================================================
Dear MS Support:
Shortly after we finished our phone conversation with you we went
back to our production portal and all the user accounts we created
for your test were able to download documents. To recap, when we
first created the accounts and tried to upload a document, it
failed. But after a period of time we tried again and then the
accounts could upload a document.
My question is this. If our account is wrong as you say why does it
work after a short period of time? This is the problem we have had
with most people. If they fail to be able to load a document, all
they have to do is wait about 15 minutes or so then when they try
again they can now upload documents fine.
At this point, I'm having a hard time believing if we change the
accounts that are being used by the app pools that all our troubles
will go away. If indeed the accounts are wrong they why would the
accounts be ok after a 15 minute wait?