Friday, August 23, 2013

Home /EMWProf /Quest Migration Manager / Quest CPUU / EMWProf and Windows Credential Manager

Quest CPUU / EMWProf and Windows Credential Manager

I ran into an issue on my current project with Quest Client Profile Update Utility (CPUU).  The CPUU / EMWProf was prompting for user or password or it was failing with MAPI_E_FAILONEPROVIDER error.  The error message or result wasn’t consistent. 

 

clip_image002

The CPUU log shows the utility wasn’t getting the correct source and target user name and password from the INI file.  The utility was trying to open target mailbox using source admin account etc.  I even have specified the target domain domain in the Domaincfg section. 

I was using the latest version of the CPUU utility (5.2).   Clearing the credentials on local machine did not help in my situation.  My solution was to disable the Windows Credential Manger using a GPO (Network access:  Do not allow storage of passwords and credentials – Enabled).  You can GPO details in the following screenshot:

 

clip_image002[5]

 

The following is the error message details from CPUU log file:

 

MAPI error.

Error code: 0x8004011d

Description: MAPI_E_FAILONEPROVIDER

Extended error description:

   Component:         Microsoft Exchange Information Store

   Error description: Microsoft Exchange is not available.  Either there are network problems or the Exchange server is down for maintenance.

   Context:           1318

   Low level:         2147746069

MAPI error.

Error code: 0x8004010f

Description: MAPI_E_NOT_FOUND

SS

Santhosh Sivarajan

Microsoft MVP · Identity & Cybersecurity Architect

Santhosh has 30+ years of hands-on enterprise experience in Identity and Access Management, Microsoft Entra ID, Active Directory, Microsoft 365 and Zero Trust architecture. He is the author of two books on Windows Server and security, and leads consulting, assessments and training at SAG Business Group.

0 comments:

Post a Comment

Popular Posts
Workstation Trust Relationship Issue Issue: You receive the following error message, when you try to login to the domain.  The security database on the server does not have ... ADMT Service Account - Permission and Configuration The ADMT service account needs to have proper permission in source and target domains.  You don’t need to use 2 separate accounts.  You can ... My First Peek into Microsoft Exchange 2010 By Santhosh Sivarajan Before I really dive into Exchange 2010, I thought I would install and play with it first. I took some screen shots and notes during the ins... ObjectSID and Active Directory What is an objectSID in Active Directory? When a new object is created in Active Directory, Domain Controller assigns a unique value used ... AD Group Report - List Group Members in Active Directory–PowerShell Script Updated Script - http://portal.sivarajan.com/2011/10/search-ad-collect-local-admin-group.html Script #1 This script... Add Users to a Group–PowerShell Script Purpose – Add users to a group from an input file – PowerShell V2 Script.  Input file – Input file (Users.csv) contains samAccountName in... User Account Migration and Merging – Part I (ADMT) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM pre-creating user account ... User Account Migration and Merging – Part II (Quest Migration Manager) Part I - User Account Migration and Merging Using ADMT Part II - User Account Migration and Merging Using QMM Pre-creating user account in... Delete Stale or Inactive Computer Accounts from Active Directory Here is an easy way to identify and delete inactive or stale computers in an Active Directory environment.  Using the dsquery command you c... Converting PowerShell (PS1) to EXE / Standalone Application As we know, there many applications available to convert a PowerShell file to a standalone executable file.  Based on my experience, PowerSh...