Unleashing the Ideavirus

Unleashing the Ideavirus 1 http://www.ideavirus.com

Unleashing the Ideavirus

By Seth Godin

Foreword by Malcolm Gladwell

©2000 by Do You Zoom, Inc.

You have permission to post this, email this, print this and pass it along for free to

anyone you like, as long as you make no changes or edits to its contents or digital

format. In fact, I’d love it if you’d make lots and lots of copies. The right to bind this

and sell it as a book, however, is strictly reserved. While we’re at it, I’d like to keep

the movie rights too. Unless you can get Paul Newman to play me.

Ideavirus™ is a trademark of Do You Zoom, Inc. So is ideavirus.com™.

Designed by Red Maxwell

You can find this entire manifesto, along with slides and notes and other good stuff, at

http://www.ideavirus.com.

This version of the manifesto is current until September 17, 2000. After that date, please go

to http://www.ideavirus.com and get an updated version. You can buy this in book form on

September 1, 2000.

This book is dedicated to Alan Webber and Jerry Colonna. Of course.

Unleashing the Ideavirus 2 http://www.ideavirus.com

STEAL THIS IDEA!

Here’s what you can do to spread the word about Unleashing the Ideavirus:

1. Send this file to a friend (it’s sort of big, so ask first).

2. Send them a link to http://www.ideavirus.com so they can download it themselves.

3. Visit http://www.fastcompany.com/ideavirus to read the Fast Company article.

4. Buy a copy of the hardcover book at

http://www.amazon.com/exec/obidos/ASIN/0970309902/permissionmarket.

5. Print out as many copies as you like.

Unleashing the Ideavirus 3 http://www.ideavirus.com

Look for the acknowledgments at the end. This is, after all, a new digital format, and you want to get right to it!

The #1 question people ask me after reading

Permission Marketing:

ÒSo, how do we get attention to ask for

permission in the first place?”

This manifesto is the answer to that question.

Unleashing the Ideavirus 4 http://www.ideavirus.com

Foreword

The notion that an idea can become contagious, in precisely the same way that a virus does,

is at once common-sensical and deeply counter-intuitive. It is common-sensical because all of

us have seen it happen: all of us have had a hit song lodged in our heads, or run out to buy a

book, or become infected with a particular idea without really knowing why. It is counterintuitive,

though, because it doesn’t fit with the marketer’s traditional vision of the world.

Advertisers spent the better part of the 20th century trying to control and measure and

manipulate the spread of information—to count the number of eyes and ears that they could

reach with a single message. But this notion says that the most successful ideas are those that

spread and grow because of the customer’s relationship to other customers—not the

marketer’s to the customer.

For years, this contradiction lay unresolved at the heart of American marketing. No longer.

Seth Godin has set out to apply our intuitive understanding of the contagious power of

information—of what he so aptly calls the ideavirus—to the art of successful

communication. “Unleashing the Ideavirus” is a book of powerful and practical advice for

businesses.

But more than that, it is a subversive book. It says that the marketer is not—and ought not

to be—at the center of successful marketing. The customer should be. Are you ready for that?

Malcolm Gladwell

Author

The Tipping Point

http://www.gladwell.com

Unleashing the Ideavirus 5 http://www.ideavirus.com

Introduction

If you don’t have time to read the whole book, here’s what it says:

Marketing by interrupting people isn’t cost-effective anymore. You

can’t afford to seek out people and send them unwanted marketing

messages, in large groups, and hope that some will send you money.

Instead, the future belongs to marketers who establish a foundation

and process where interested people can market to each other. Ignite

consumer networks and then get out of the way and let them talk.

If you’re looking for mindblowing new ideas, you won’t find them in this, or any other

marketing book. Guerrilla marketing, 1:1 marketing, permission marketing—these ideas are

not really new, but they are thoughtful constructs that let you figure out how to do

marketing better. The fact is, if we built factories as badly as we create advertising campaigns,

the country would be in a shambles. This book will help you better understand the timehonored

marketing tradition of the ideavirus, and help you launch your own.

Questions the book answers:

1.

Why is it foolish to launch a new business with millions of dollars in TV ads?

2.

Are the market leaders in every industry more vulnerable to sudden successes by the

competition than ever before?

3.

Should book publishers issue the paperback edition of a book before the hardcover?

4.

What’s the single most important asset a company can create—and what is the simple

thing that can kill it?

5.

Every ad needs to do one of two things to succeed…yet most ads do neither. What’s the

right strategy?

6.

Does the Net create a dynamic that fundamentally changes the way everything is

marketed?

7.

How can every business…big and small…use ideavirus marketing to succeed?

Unleashing the Ideavirus 6 http://www.ideavirus.com

Foreword……………………………………………………………………………………………………………………….5

Introduction……………………………………………………………………………………………………………………6

SECTION 1: Why Ideas Matter…………………………………………………………………………………… 11

Farms, Factories And Idea Merchants ………………………………………………………………………………….12

Why Are Ideaviruses So Important?…………………………………………………………………………………….21

And Five Things Ideaviruses Have In Common……………………………………………………………………….22

Seven Ways An Ideavirus Can Help You: ……………………………………………………………………………… 23

The Sad Decline of Interruption Marketing ………………………………………………………………………….. 24

We Live In A Winner-Take-Almost-All World………………………………………………………………………….. 25

The Traffic Imperative: Why Sites Fail ……………………………………………………………………………….. 28

We Used To Make Food. We Used To Make Stuff. Now We Make Ideas…………………………………………. 30

People Are More Connected Than They Ever Were Before. We Have Dramatically More Friends Of Friends

And We Can Connect With Them Faster And More Frequently Than Ever……………………………………….31

ThereÕs A Tremendous Hunger To Understand The New And To Remain On The Cutting Edge……………34

While Early Adopters (The Nerds Who Always Want To Know About The Cool New Thing In Their Field)

Have Always Existed, Now WeÕve Got More Nerds Than Ever Before. If YouÕre Reading This, YouÕre A

Nerd!………………………………………………………………………………………………………………………….. 35

Ideas Are More Than Just Essays And Books. Everything From New Technology To New Ways Of Creating

To New Products Are Winning Because Of Intelligent Ideavirus Management By Their Creators………..36

The End Of The Zero Sum Game ………………………………………………………………………………………… 37

SECTION 2: How To Unleash An Ideavirus…………………………………………………………………..39

While It May Appear Accidental, ItÕs Possible To Dramatically Increase The Chances Your Ideavirus Will

Catch On And Spread. ……………………………………………………………………………………………………..40

The Heart Of The Ideavirus: Sneezers ………………………………………………………………………………….41

Sneezers Are So Important, We Need To Subdivide Them………………………………………………………… 42

The Art Of The Promiscuous …………………………………………………………………………………………….. 47

ItÕs More Than Just Word Of Mouth ……………………………………………………………………………………..51

An Ideavirus Adores A Vacuum …………………………………………………………………………………………. 52

Unleashing the Ideavirus 7 http://www.ideavirus.com

Once It Does Spread, An Ideavirus Follows A Lifecycle. Ignore The Lifecycle And The Ideavirus Dies Out.

Feed It Properly And You Can Ride It For A Long Time…………………………………………………………….54

Viral Marketing Is An Ideavirus, But Not All Ideaviruses Are Viral Marketing ……………………………….. 55

What Does It Take To Build And Spread An Ideavirus? ……………………………………………………………. 57

There Are Three Key Levers That Determine How Your Ideavirus Will Spread:………………………………60

Ten Questions Ideavirus Marketers Want Answered ………………………………………………………………. 64

Five Ways To Unleash An Ideavirus ……………………………………………………………………………………. 65

SECTION THREE: The Ideavirus Formula ……………………………………………………………………. 78

Managing Digitally-Augmented Word Of Mouth……………………………………………………………………… 79

Tweak The Formula And Make It Work …………………………………………………………………………………80

Advanced Riffs On The Eight Variables You Can Tweak In Building Your Virus………………………………. 85

Hive …………………………………………………………………………………………………………………………… 88

Velocity………………………………………………………………………………………………………………………. 92

Vector………………………………………………………………………………………………………………………… 94

Medium ………………………………………………………………………………………………………………………. 96

SMOOTHNESS: It Would All Be Easy If We Had Gorgons……………………………………………………………. 98

Persistence …………………………………………………………………………………………………………………100

Amplifier …………………………………………………………………………………………………………………….102

SECTION 4: Case Studies and Riffs…………………………………………………………………………..104

The Vindigo Case Study…………………………………………………………………………………………………..105

Saving The World With An Ideavirus ………………………………………………………………………………….. 107

Moving Private To Public…………………………………………………………………………………………………..111

YouÕre In The Fashion Business! ………………………………………………………………………………………..113

The Money Paradox ………………………………………………………………………………………………………..117

Think Like A Music Executive (Sometimes)…………………………………………………………………………..119

Is That Your Final Answer?……………………………………………………………………………………………….121

A Dozen ideaviruses Worth Thinking About…………………………………………………………………………. 123

Why I Love Bestseller Lists………………………………………………………………………………………………124

How A Parody Of Star Wars Outsold Star Wars …………………………………………………………………….. 127

Unleashing the Ideavirus 8 http://www.ideavirus.com

Wassup? ……………………………………………………………………………………………………………………..129

Judging a book by its cover ……………………………………………………………………………………………..131

Being The Most ……………………………………………………………………………………………………………. 133

In Defense Of World Domination ………………………………………………………………………………………. 135

If YouÕre A Member Of The Academy, You Go To Movies For Free …………………………………………….. 137

How An Ideavirus Can Drive The Stock Market …………………………………………………………………….. 139

Bumper Sticker Marketing……………………………………………………………………………………………….142

No, You Go First! ………………………………………………………………………………………………………….. 143

Digital Media Wants to Be Free…………………………………………………………………………………………145

Van Gogh Lost His Ear To Prove A Point ……………………………………………………………………………..148

Answering InaÕs Question………………………………………………………………………………………………..150

Crossing The Chasm With An Ideavirus ……………………………………………………………………………….152

The Myth Of The Tipping Point ………………………………………………………………………………………….156

The Compounding Effect …………………………………………………………………………………………………158

Bill GatesÕ Biggest Nightmare…………………………………………………………………………………………..160

Hey, Skinny!…………………………………………………………………………………………………………………164

Get Big Fast? The Mistake So Many Companies MakeÉ…………………………………………………………..165

The Heart Of Viral Marketing……………………………………………………………………………………………168

The Great Advertising Paradox………………………………………………………………………………………….171

Permission: The Missing Ingredient…………………………………………………………………………………… 174

How A Virus And Permission Team Up To Find Aliens…………………………………………………………….. 176

The Art of Creating an Ideavirus………………………………………………………………………………………. 177

Is He Really More Evil Than Satan Himself? ………………………………………………………………………… 178

Case Study: Why Digimarc Is Going To Fail…………………………………………………………………………..179

Why Are These Cows Laughing?…………………………………………………………………………………………181

Never Drink Alone …………………………………………………………………………………………………………183

The Power Of Parody ……………………………………………………………………………………………………..185

Bee Stings And The Measles …………………………………………………………………………………………….186

But IsnÕt It Obvious?………………………………………………………………………………………………………187

Unleashing the Ideavirus 9 http://www.ideavirus.com

Your CompanyÕs Worst Enemy ………………………………………………………………………………………….189

Step By Step, Ideavirus Tactics: ……………………………………………………………………………………….192

The Future Of The Ideavirus: What Happens When Everyone Does It? ………………………………………..194

Acknowledgments ………………………………………………………………………………………………..196

Unleashing the Ideavirus 10 http://www.ideavirus.com

SECTION 1: Why Ideas Matter

STEAL THIS IDEA!

Here’s what you can do to spread the word about Unleashing the Ideavirus:

1. Send this file to a friend (it’s sort of big, so ask first).

2. Send them a link to http://www.ideavirus.com so they can download it themselves.

3. Visit http://www.fastcompany.com/ideavirus to read the Fast Company article.

4. Buy a copy of the hardcover book at

http://www.amazon.com/exec/obidos/ASIN/0970309902/permissionmarket.

5. Print out as many copies as you like.

Unleashing the Ideavirus 11 http://www.ideavirus.com

Farms, Factories And Idea Merchants

Imagine for a second that you’re at your business school reunion, trading lies and bragging

about how successful you are and are about to become. Frank the jock talks about the dotcom

company he just started. Suzie the ex-banker is now focusing her energy on rebuilding

Eastern Europe. And then the group looks at you. With a wry look of amusement, you

answer:

“Well, the future—the really big money—is in owning a farm. A small one, maybe 100

acres. I intend to invest in a tractor of course, and expect that in just a few years my husband

and I can cash out and buy ourselves a nice little brownstone in the city.”

Ludicrous, no? While owning a farm may bring tremendous lifestyle benefits, it hasn’t been a

ticket to wealth for, say, 200 years.

What about owning a factory then? Perhaps the road to riches in the new economy would be

to buy yourself a hot-stamping press and start turning out steel widgets. Get the UAW to

organize your small, dedicated staff of craftsmen and you’re on your way to robber-baron

status.

Most of us can agree that the big money went out of owning a factory about thirty years ago.

When you’ve got high fixed costs and you’re competing against other folks who also know

how to produce both quantity and quality, unseemly profits fly right out the window.

Fact is, the first 100 years of our country’s history were about who could build the biggest,

most efficient farm. And the second century focused on the race to build factories. Welcome

to the third century, folks. The third century is about ideas.

Alas, nobody has a clue how to build a farm for ideas, or even a factory for ideas. We

recognize that ideas are driving the economy, ideas are making people rich and most

important, ideas are changing the world. Even though we’re clueless about how to best

organize the production of ideas, one thing is clear: if you can get people to accept and

Unleashing the Ideavirus 12 http://www.ideavirus.com

embrace and adore and cherish your ideas, you win. You win financially, you gain power and

you change the world in which we live.

So how do you win? What do you need to do to change the status quo of whatever industry

you’re in, or, if you’re lucky, to change the world?

If you’re a farmer, you want nothing more than a high price for your soybeans. If you’re a

manufacturer of consumer goods, you want a display at the cash register at Wal-Mart. But

what if you’re an idea merchant?

The holy grail for anyone who trafficks in ideas is this: to unleash an ideavirus.

An idea that just sits there is worthless. But an idea that moves and grows and infects

everyone it touches… that’s an ideavirus.

In the old days, there was a limit on how many people you could feed with the corn from

your farm or the widgets from your factory. But ideas not only replicate easily and well, they

get more powerful and more valuable as you deliver them to more people.

How does an ideavirus manifest itself? Where does it live? What does it look like? It’s useful

to think of ideas of every sort as being similar. I call them manifestos. An idea manifesto is a

powerful, logical “essay” that assembles a bunch of existing ideas and creates a new one.

Sometimes a manifesto is a written essay. But it can be an image, a song, a cool product or

process… the medium doesn’t matter. The message does. By lumping all sorts of

ideas—regardless of format—into the same category (manifestos) it’s much easier to think of

them as versions of the same thing. As long as you can use your manifesto to change the way

people think, talk or act… you can create value.

Definition: MEDIUM In order to move, an idea has to be encapsulated in a medium. It

could be a picture, a phrase, a written article, a movie, even a mathematical formula (e=mc2).

The Medium used for transmitting the ideavirus determines how smooth it is as well as the

velocity of its growth. A medium is not a manifesto—every idea is a manifesto, trying to

make its point, and the medium is the substance that the idea lives in.

Unleashing the Ideavirus 13 http://www.ideavirus.com

Not only is this an essay about ideas and ideaviruses…it’s also a manifesto striving to become

an ideavirus! If this manifesto changes your mind about marketing and ideas, maybe you’ll

share it with a friend. Or two. Or with your entire company. If that happens, this idea will

become an ideavirus, and spread and gain in value.

We live in a world where consumers actively resist marketing. So it’s imperative to stop

marketing at people. The idea is to create an environment where consumers will market to

each other.

Is an ideavirus a form of marketing? Sure it is. And today, marketing is all there is. You don’t

win with better shipping or manufacturing or accounts payable. You win with better

marketing, because marketing is about spreading ideas, and ideas are all you’ve got left to

compete with.

The future belongs to the people who unleash ideaviruses.

What’s an ideavirus? It’s a big idea that runs amok across the target audience. It’s a

fashionable idea that propagates through a section of the population, teaching and changing

and influencing everyone it touches. And in our rapidly/instantly changing world, the art

and science of building, launching and profiting from ideaviruses is the next frontier.

Have you ever heard of Hotmail? Ever used it? If so, it’s not because Hotmail ran a lot of TV

ads (they didn’t). It’s because the manifesto of free email got to you. It turned into an

ideavirus. Someone you know and trust infected you with it. What about a Polaroid

camera… was your first exposure (no pun intended!) in a TV ad, or did you discover it when

a friend showed you how cool the idea of an instant photograph was?

Sometimes it seems like everyone is watching the same TV show as you, or reading the same

book, or talking about the same movie or website. How does that happen? It usually occurs

because the idea spreads on its own, through an accidental ideavirus, not because the

company behind the product spent a ton of money advertising it or a lot of time

Unleashing the Ideavirus 14 http://www.ideavirus.com

orchestrating a virus. And how the idea spreads, and how to make it spread faster—that’s the

idea behind unleashing an ideavirus.

Word of mouth is not new—it’s just different now. There were always ideaviruses—gossip or

ideas or politics that spread like wildfire from person to person. Without running an ad or

buying a billboard, Galileo managed to upset all of Pisa with his ideas. Today, though,

ideaviruses are more important and more powerful than ever. Ideaviruses are easier to launch

and more effective. Ideaviruses are critical because they’re fast, and speed wins and speed

kills—brands and products just don’t have the time to develop the old way. Ideaviruses give

us increasing returns—word of mouth dies out, but ideaviruses get bigger. And finally,

ideaviruses are the currency of the future. While ideaviruses aren’t new, they’re important

because we’re obsessed with the new, and an ideavirus is always about the new.

Remember the slogan, “Only her hairdresser knows for sure?” That was classic brand

marketing, and it flew in the face of word of mouth. It was an ad for a product that was

supposed to be a secret—a secret between you, your hairdresser and Clairol.

A few years later, Herbal Essence took a totally different tack… they tried to encourage you

to tell your friends. But while word of mouth works great among the people who use a

product and their immediate friends—if I love your story or hate your service, I’ll tell a few

friends—it dies out fast. There’s no chance a friend of a friend is going to tell you about my

horrible experience on United Airlines or how much I loved flying on Southwest. Word of

mouth fades out after a few exchanges.

But now, aided by the Net and abetted by the incredible clutter in our universe, ideaviruses

are spreading like wildfire. We’re all obsessed with ideas because ideas, not products, are the

engine of our new economy.

I wore Converse sneakers growing up… so did you. But the shareholders of Converse never

profited from the idea of the shoe—they profited from the manufacture of a decent sneaker.

If two sneakers were for sale, you bought the cheaper one.

Unleashing the Ideavirus 15 http://www.ideavirus.com

It took Converse generations to build a brand and years to amortize a factory and they were

quite happy to extract a modest profit from every pair of sneakers sold, because Converse

knew their factory would be around tomorrow and the day after that. So sneakers, like

everything else, were priced by how much they cost, and sold one pair at a time by earnest

shoe salesmen who cared about things like how well the shoes fit.

Converse could take their time. They were in this for the long haul. Those days are long

gone. Twenty years later, it’s the idea of Air Jordan sneakers, not the shoe, that permits Nike

to sell them for more than $100. It’s the sizzle, not the fit. The idea makes Nike outsized

profits. And Nike knows that idea won’t last long, so they better hurry—they need another

ideavirus, fast.

In the old days, we used to sneer at this and call it a fad. Today, everything from presidential

politics to music to dentistry is driven by fads—and success belongs to marketers who

embrace this fact.

Source: Forrester Research

It took 40 years for radio to have ten million users. By then, an industry had grown that

could profit from the mass audience. It took 15 years for TV to have ten million users. It

Unleashing the Ideavirus 16 http://www.ideavirus.com

only took 3 years for Netscape to get to 10 million, and it took Hotmail and Napster less

than a year. By aggregating mass audiences to themselves (and not having to share them with

an entire industry), companies like Netscape and Hotmail are able to realize huge profits,

seemingly overnight. And they do it by spreading ideaviruses.

Ideas can now be carried in the ether. Because the medium for carrying ideas is fast and

cheap, ideas move faster and cheaper! Whether it’s the image of the new VW Beetle (how

long did it take for the idea of that car to find a place in your brain?) or the words of a new

Stephen King novel (more than 600,000 people read it in the first week it was available

online), the time it takes for an idea to circulate is approaching zero.

Why should we care? Why does it matter that ideas can instantly cross international

boundaries, change discussions about politics, crime and justice or even get us to buy

something? Because the currency of our future is ideas, and the ideavirus mechanism is the

way those ideas propagate. And the science and art of creating ideaviruses and using them for

profit is new and powerful. You don’t have to wait for an ideavirus to happen organically or

accidentally. You can plan for it and optimize for it and make it happen.

Sure, some ideaviruses are organic. They happen and spread through no overt action or

intent on the part of the person who creates them (the Macarena wasn’t an organized plot…

it just happened). Others, though, are the intentional acts of smart entrepreneurs and

politicians who know that launching and nurturing an ideavirus can help them accomplish

their goals.

In the old days, the way we sold a product was through interruption marketing. We’d run

ads, interrupt people with unanticipated, impersonal, irrelevant ads and hope that they’d buy

something. And sometimes, it worked.

The advantage of this branding strategy is that the marketer is in complete and total control.

The disadvantage is that it’s hard and expensive. Every time a catalog clothier (Land’s End,

Eddie Bauer, you name it) wants to sign up a new customer, they need to buy a few hundred

stamps, send out some carefully designed catalogs and hope that one person sends them

money.

Unleashing the Ideavirus 17 http://www.ideavirus.com

What marketers are searching for is a way to circumvent the tyranny of cost-per-thousand

interruptions. They need something that ignites, a way to tap into the invisible currents that

run between and among consumers, and they need to help those currents move in better,

faster, more profitable ways. Instead of always talking to consumers, they have to help

consumers talk to each other.

A beautifully executed commercial on the Super Bowl is an extraordinarily risky bet.

Building a flashy and snazzy website is almost certain to lead to failure. Hiring a celebrity

spokesperson might work on occasion, but more often than not, it won’t break through the

clutter. Whenever advertisers build their business around the strategy of talking directly to

the customer, they become slaves to the math of interruption marketing.

In traditional interruption marketing, the marketer talks directly to as many consumers as possible, with no

intermediary other than the media company. The goal of the consumer is to avoid hearing from the advertiser. The

goal of the marketer is to spend money buying ads that interrupt people who don’t want to be talked to!

Unleashing the Ideavirus 18 http://www.ideavirus.com

In creating an ideavirus, the advertiser creates an environment in which the idea can replicate and spread. It’s the

virus that does the work, not the marketer.

Fortunately, there are already proven techniques you can use to identify, launch and profit

from ideas that can be turned into viruses. There’s a right and a wrong way to create them,

and more important, the care and feeding of your ideavirus can dramatically affect its

potency.

One of the key elements in launching an ideavirus is concentrating the message. If just 1% or

even 15% of a group is excited about your idea, it’s not enough. You only win when you

totally dominate and amaze the group you’ve targeted. That’s why focusing obsessively on a

geographic or demographic or psychographic group is a common trait among successful idea

merchants.

Why are new companies launching on the Net so obsessed with traffic and visitors? Why is a

company like GeoCities sold for more than $2 billion, when it has close to zero revenue and

interesting, but by no means unique, software?

Because infecting large populations with the ideavirus is the first step to building a profitable

business model. The key steps for Internet companies looking to build a virus are:

Unleashing the Ideavirus 19 http://www.ideavirus.com

1.

Create a noteworthy online experience that’s either totally new or makes the user’s life

much better. Or make an offline experience better/faster/cheaper so that switching is

worth the hassle.

2.

Have the idea behind your online experience go viral, bringing you a large chunk of the

group you’re targeting WITHOUT having to spend a fortune advertising the new

service.

3.

Fill the vacuum in the marketplace with YOUR version of the idea, so that competitors

now have a very difficult time of unteaching your virus and starting their own.

4.

Achieve “lock in” by creating larger and larger costs to switching from your service to

someone else’s.

5.

Get permission from users to maintain an ongoing dialogue so you can turn the original

attention into a beneficial experience for users and an ongoing profit stream for you.

6.

Continue creating noteworthy online experiences to further spread new viruses, starting

with your core audience of raving fans.

Unleashing the Ideavirus 20 http://www.ideavirus.com

Why Are Ideaviruses So Important?

1.

We live in a winner-take-almost-all world. (Zipf’s law.)

2.

We used to focus on making food. We used to make stuff. Now we make ideas.

3.

People are more connected than ever. Not only are we more aware that our friends have

friends but we can connect with them faster and more frequently.

4.

There’s a tremendous hunger to understand the new and to remain on the cutting edge.

5.

While early adopters (the nerds who always want to know about the cool new thing in

their field) have always existed, now we’ve got more nerds than ever. If you’re reading this,

you’re a nerd!

6.

The profit from creating and owning an ideavirus is huge.

Unleashing the Ideavirus 21 http://www.ideavirus.com

And Five Things Ideaviruses Have In Common

1.

The most successful ideaviruses sometimes appear to be accidents, but it is possible to

dramatically increase the chances your ideavirus will catch on and spread.

2.

An ideavirus adores a vacuum. (This is a big idea. Read on to see what I mean).

3.

Once an ideavirus spreads, it follows a lifecycle. Ignore the lifecycle and the ideavirus dies

out. Feed it properly and you can extend its useful life and profit from it for a long time.

4.

Ideaviruses are more than just essays and books. Everything from new technology to new

ways of creating new products are winning because of intelligent seeding by their

creators.

5.

Viral marketing is a special case of an ideavirus. Viral marketing is an ideavirus in which

the carrier of the virus IS the product.

Unleashing the Ideavirus 22 http://www.ideavirus.com

Seven Ways An Ideavirus Can Help You:

1.

When everyone in town tells ten friends about your amazing ice cream

shop and a line forms out the door (supercharged word of mouth due to

the virus having dominated the town so completely).

2.

When your company’s new mass storage format catches on and it

becomes the next Zip drive.

3.

When an influential sports writer names your daughter as a high school

All-American basketball player and coaches line up outside the door

with scholarships.

4.

When Steve Jobs commissions the iMac, which spreads the word about

the Mac faster than any advertising ever could, raising market share and

saving your favorite computer company from bankruptcy.

5.

When you write a report for your boss about how your company should

deal with an opportunity in Cuba and it gets passed on, from person to

person, throughout the company, making you a hero and a genius.

6.

When the demo recording you made becomes a bestseller on MP3.com

and you get a call from Sony, who wants to give you a recording

contract.

7.

When you are able to devise a brand-new Internet business plan for a

product that’s useful and also embodies viral marketing…growing from

nothing to a million users in a month and making you rich along the

way.

Unleashing the Ideavirus 23 http://www.ideavirus.com

The Sad Decline of Interruption Marketing

When I first starting writing about Permission Marketing about four years ago, much of

what I said was considered heresy. “What do you mean TV ads are going to decline in

effectiveness?” “How dare you say anything negative about banner ads—of course they

work!” or “Direct mail has never been healthier!”

History, fortunately for me, has borne out my cries of doom and gloom about interruption

marketing. The TV networks are diversifying away from their traditional network TV

business as fast as they can. Banner clickthrough rates are down 85% or more. Ads are

sprouting up on the floors of the supermarket, in the elevator of the Hilton hotel in Chicago

and even in urinals. And everywhere you look, unanticipated, impersonal and irrelevant ads

are getting more expensive and less effective.

There’s a crisis in interruption marketing and it’s going to get much worse. It took more

than thirty pages to build the case against this wasteful, costly ($220 billion a year)

outmoded expense in Permission Marketing, so I’ll only spend a page on it here. If you want

to read the entire jeremiad, send a note to free@permission.com and I’ll send it to you for

free.

Unless you find a more cost-effective way to get your message out, your business is doomed.

You can no longer survive by interrupting strangers with a message they don’t want to hear,

about a product they’ve never heard of, using methods that annoy them. Consumers have

too little time and too much power to stand for this any longer.

Unleashing the Ideavirus 24 http://www.ideavirus.com

We Live In A Winner-Take-Almost-All World

Quick! Name an oil painting hanging in a museum somewhere in the world.

Did you say, “the Mona Lisa”?

As I walk through the Louvre, arguably one of the top ten most packed-with-high-qualitypaintings

museums on the planet, I pass one empty room after another, then come to an

alcove packed with people. Why? Why are these people clawing all over each other in order

to see a painting poorly displayed behind many inches of bullet-proof glass?

The reason the Mona Lisa is the most famous painting in the world is

that something had to be the most famous painting in the world and it

might as well be the Mona Lisa.

Busy people don’t have time to look at every painting. They only have

room in their overcrowded, media-hyped brains for a few paintings.

And when you come right down to it, most people would like to see only the “celebrity”

paintings. And just as there can only be one “My most favorite famous actress” (Julia

Roberts) and one “this site equals the Internet” (Yahoo!), there’s only room for one “most

famous painting in the world” and the safe choice is the Mona Lisa.

There’s a name for this effect. It’s called Zipf’s law, after George Kingsley Zipf (1902-1950),

a philologist and professor at Harvard University. He discovered that the most popular word

in the English language (“the”) is used ten times more than the tenth most popular word,

100 times more than the 100th most popular word and 1,000 times more than the 1,000th

most popular word.

Unleashing the Ideavirus 25 http://www.ideavirus.com

It’s also been discovered that this same effect applies to market share for software, soft drinks,

automobiles, candy bars, and the frequency of hits on pages found on a website. The chart

above shows actual visits to the different pages at Sun’s website.

In almost every field of endeavor, it’s clear that being #1 is a lot better than being #3 or #10.

There isn’t an even distribution of rewards, especially in our networked world.

On the Net, the stakes are even larger. The market capitalization of Priceline, eBay and

Amazon approaches 95% of the total market capitalization of every other consumer ecommerce

stock combined. Clearly, there’s a lot to be gained by winning.

An ideavirus lets you make something like this happen to your idea, to your business, to your

product. While the benefits of being #1 for a public Internet stock or an oil painting are

clear, it’s just as important to small businesses and individuals.

Ideaviruses are faced with a brickwall filter. In electronics, a brickwall filter wipes out certain

frequencies and lets the rest through. There’s no room for second place or extra

effort—either you’re in or you’re out. Ideaviruses are win/lose propositions. Either the

velocity and smoothness are high enough that it becomes a bonafide epidemic, or they’re not

and it dies out. Either your ideavirus works or it doesn’t. Smart propagators know when to

quit if their ideavirus isn’t getting through the filter.

Definition: VELOCITY

The velocity is a measure of how fast the idea spreads from

one party to another. If an idea is going to hit ten people before it gets to me, the multiplier

effect is large indeed—fast steps lead to more people being infected before it dies out.

Unleashing the Ideavirus 26 http://www.ideavirus.com

Definition: SMOOTHNESS SMOOTHNESS

How easy is it for an end user to spread this particular

ideavirus? Can I click one button or mention some magic phrase, or do I have to go through

hoops and risk embarrassment to tell someone about it?

For example, it’s pretty easy to talk about your hairdresser. Someone tells you you’ve got a

great haircut, and you say, “Yeah, I went to Bob at Bumble & Bumble.” On the other hand,

spreading the word about your reflexology therapist is pretty tricky. You’re not sure when to

bring it up, and you really don’t have words to describe it.

The smoothest viruses, like Hotmail, spread themselves. Just the act of using the product

spreads the virus. There’s an obvious relationship between smoothness and catchiness. A

product that’s easy to recommend is often a product that’s easy to get hooked on.

Eric Raymond was a little known programmer when he wrote an essay called “The Cathedral

and the Bazaar.” It was a manifesto—an essay designed to become an ideavirus—arguing

why the open source approach to coding (creating stuff like Linux) made sense. But instead

of having a magazine or a book publisher bring it to market, he posted the essay online, in

text, postscript and audio form. And he gave it away for free.

Within months, tens of thousands of people had read it. Months after that, Raymond

published this essay with some of his other free essays in a book. That book became an

“instant” bestseller. Of course, it wasn’t instant at all. He had laid the foundation long

before, by building an ideavirus.

So, what has creating an ideavirus done for Raymond’s value? Let’s take a crass look at his

financial situation: The virus led to increased demand for his services as a programmer (he

can pick his jobs if he likes), as a consultant, and even as a public speaker. The last I saw, he

had just written an essay about what it was like to make a fortune during an IPO!

Unleashing the Ideavirus 27 http://www.ideavirus.com

The Traffic Imperative: Why Sites Fail

A site without traffic doesn’t exist.

According to Forrester Research, only 20% of 50 leading online retailers expect to turn a

profit this year. Just 18% more expect to be profitable next year. It’s becoming increasingly

obvious that many of these sites will never turn a profit, and that they’re hoping to last long

enough to be acquired or sell their stock.

A recent McKinsey and Co. study found that the vast majority of online retailers are not

only unprofitable, they’re actually losing money on every sale. Without even computing the

cost of advertising and clicks, these sites have discounted their prices so significantly that the

contribution margin from each sale is negative. The average online drugstore, for example,

loses $16.42 on each and every sale, before computing the cost of traffic.

Why? Many of these sites are confusing low prices with an effective customer acquisition

tool. There’s probably no way that’s less effective and more costly than cutting your prices to

the point where you lose money on each sale (for Amazon naysayers—they actually make a

profit of about $5 on the average book order).

Add to this mess the obscene cost of customer acquisition—estimated by the Boston

Consulting Group to be more than $80 a visitor (that’s for visitors, not even customers) for

most online merchants. Now you can see the huge hurdle these sites are going to have to

cross in order to be profitable.

This problem isn’t unique to the online world, of course. When I was enrolled at Tufts

University in 1980, there were two homemade ice cream stores within two miles of campus.

One was Joey’s, which made a terrific product (they used Hydrox cookies instead of Oreos,

by the way, so you could avoid the animal fat if you wanted) and there was never, ever a line.

Unleashing the Ideavirus 28 http://www.ideavirus.com

In the other direction was the now famous Steve’s Ice Cream. His prices were a bit higher

than Joey’s, but his profits were clearly much higher. Why? Because there was always a line at

Steve’s. A long line. Sometimes you’d wait an hour to get an ice cream cone.

What happened? Why did one ice cream shop go viral and the other languished at the edge

of profitability? It certainly wasn’t about advertising, because neither shop did any. The

reason Steve Herrell’s shop did so well is that it was famous for having a line! People brought

folks from out of town to have the experience. Locals came back because they’d convinced

themselves that if the hive liked it enough to wait an hour for an ice cream cone, well, it

must be worth it. Suddenly, it wasn’t about the ice cream. It was about the experience.

Most online merchants, being risk averse copycats afraid to innovate, are guaranteeing that

there will be no ideavirus created around their businesses. By paying millions to AOL and

Yahoo! for “traffic,” they’re investing in exactly the wrong sort of buzz. The

alternative—focusing on people who can promote your site, affiliate programs, unique

promotions and building wow, zing and magic into the site—is just too much work for most

sites.

Unleashing the Ideavirus 29 http://www.ideavirus.com

We Used To Make Food. We Used To Make Stuff. Now We Make Ideas.

Here are some astonishing facts you should think about long and hard on your way to work

tomorrow:

Twenty years ago, the top 100 companies in the Fortune 500 either dug something out of

the ground or turned a natural resource (iron ore or oil) into something you could hold.

Today, fewer than half of the companies on the list do that. The rest make unseemly profits

by trafficking in ideas.

In 1998, there were 30,000 new musical CDs published, including one from the Pope (his,

which I like a lot, features a little rap, a little techno and a lot of worldbeats).

Ninety-nine percent of Yahoo’s market capitalization is due to brand, sizzle, user loyalty and

other “soft” ideas. Only 1% of the company’s value is due to actual unique stuff that you

can’t get anywhere else.

Nathan Mhyrvold, former chief scientist at Microsoft, says a great programmer is worth

10,000 times more than an average one. Why? Because of the quality of her ideas.

The important takeaway is this: Ideas aren’t a sideshow that make our factory a little more

valuable. Our factory is a sideshow that makes our ideas a little more valuable!

Unleashing the Ideavirus 30 http://www.ideavirus.com

People Are More Connected Than They Ever Were Before. We Have

Dramatically More Friends Of Friends And We Can Connect With Them Faster

And More Frequently Than Ever.

Think back. Really far. Ten years ago.

How many people did you have regular telephone contact with ten years ago? Probably ten

or twenty or thirty in your personal life, and maybe 100 at work?

Now, take a look at your email inbox and your ICQ (the most popular instant messenger

program) buddy list. How many people do you hear from every week?

We’re far more connected than we ever were. And now, we’ve got second or third or fourth

order connections. There’s an email in my box from someone who is married to someone I

went to summer camp with twenty years ago who got my email address from a third friend.

Another message is from a former employee, telling me about a doctor who’s about to lose

his license for trying radical medical treatments, and how her mother-in-law will suffer if this

guy can’t practice any longer.

It’s hard for me to imagine either person contacting me if they had to walk across the village

and bang on the door of my hut or pick up the phone and call me. But the moment you

connect to the Internet, you connect, at some level, to all of us. And the connections make

ideas travel. Fast.

What’s the difference between word of mouth and an ideavirus? Two differences. First, word

of mouth tends to spread slower, be more analog. If you like a book, you might tell a friend

or two. And then your friends are unlikely to tell someone else until they read it for

themselves.

Second, word of mouth dies off. Because the numbers are smaller, it doesn’t take many

people who don’t participate in the word of mouth for each generation to be smaller than the

one before it.

Unleashing the Ideavirus 31 http://www.ideavirus.com

Here’s a schematic of typical word of mouth. Notice how few cycles there are, and how it drops off

over time.

Here’s an ideal ideavirus. Note how much more frequently the cycles occur, and how each cycle sees

the virus grow.

With an ideavirus, both principles no longer apply. Ideaviruses spread fast and they spread

far. With word of mouse (word of mouth augmented by the power of online

communication), you can tell 100 friends, or a thousand friends. Because the numbers are

larger and faster, the virus grows instead of slows.

Even before the Net, there were special cases of viruses. In traditional word of mouth in the

book business, someone reads a book and tells a friend. It’s nice, but it’s not usually enough.

The Bridges of Madison County, however, became the bestselling novel of the decade, because

booksellers adopted it and told people. As a bookseller, you’ve got exposure not just to a few

people, but hundreds of people. So the serendipitous word of mouth that helps some books

is replaced by a rapid, virulent alternative.

Unleashing the Ideavirus 32 http://www.ideavirus.com

On the other hand, most Americans have never had a massage from a professional masseuse.

Why? Because in order to understand the power of a massage, you have to get one. We don’t

currently have the word or picture tools to adequately describe the positive benefits of a

massage, and just as important, there isn’t a powerful spokesperson for massage who has

spent the time and energy to develop the ideavirus. There’s no real medium to transmit the

message. So the message travels slowly. So there is no virus around the idea of a massage.

Unleashing the Ideavirus 33 http://www.ideavirus.com

ThereÕs A Tremendous Hunger To Understand The New And To Remain On The

Cutting Edge.

Jed Clampett discovered that finding oil on his property was a sure road to riches. Today, the

road seems to be paved with awareness. If you know what’s news, if you know what’s the

latest, hottest, most impactful new idea, it’s much easier to succeed. You can profit in the

stock market, do better in politics, find breakthroughs in science, or programming or

marketing.

Why does this matter? Because in a society where the new isn’t valued, your social standing

doesn’t increase when you become a nerd. And because ideaviruses are really nothing but

amplified gossip about new stuff, they can’t take root in a culture that doesn’t care about the

new.

Take a look at the Top 40 charts in Billboard magazine. Thirty or forty years ago, a record

could easily stay on the list for six months or more. Today, new records come and go much

faster. Why? Because we are happily saturated in the current hit, and then move on.

Last year, 1,778 business books were published in the U.S. alone. Every one of them got read

by someone, some by an awful lot of people. Why? Because as our world changes faster and

faster and faster, knowing is just as important as having. And that makes the population ready

and eager for the next ideavirus.

As the speed of new ideas entering the community has increased, so has our respect for

people who know. And because it’s valuable, we’re open to both hearing about the new and

telling others about it.

Unleashing the Ideavirus 34 http://www.ideavirus.com

While Early Adopters (The Nerds Who Always Want To Know About The Cool

New Thing In Their Field) Have Always Existed, Now WeÕve Got More Nerds

Than Ever Before. If YouÕre Reading This, YouÕre A Nerd!

The Internet turned us all into nerds. AltaVista isn’t cool any more—google.com is. Don’t

use the Palm, that’s passé. Try this Handspring instead. Suddenly we’re ready, willing and

able to be at the bleeding edge, all the time.

The profit from creating and owning an ideavirus is huge, huger than it ever was before. It

used to be that only a few stereotypical nerds cared about the latest pocket calculator. Today,

you’ll see people talking about their handheld computer on the subway. It used to be that

only a few people knew about the latest Salsa hit out of Mexico or the coolest new chef in

Los Angeles. Today, the roles are totally reversed. Your parents are nerds!

It’s not just that our society is rewarding people who are sensitive enough or smart enough or

cool enough to know about the next new thing. It’s that many of us have crossed over a line

and gone from being the vast majority who waited for something to become

mainstream—we’ve become the early adopters, the folks on the bleeding edge who actually

seek out innovation. The combined circulation of Wired, Fast Company and PC Magazine is

rapidly approaching the total circulation of Sports Illustrated.

Because the population has shifted, the sweet spot has shifted. Companies no longer make

most of their money harvesting money from the laggards who finally get around to buying

something at K-Mart. They make their money the first day, the first week, the first month an

idea is out there.

If something is new and different and exciting and getting buzzed about, we want to know

about it, be part of it. The fashion is now to be in fashion, and ideas are the way we keep up.

Unleashing the Ideavirus 35 http://www.ideavirus.com

Ideas Are More Than Just Essays And Books. Everything From New

Technology To New Ways Of Creating To New Products Are Winning Because

Of Intelligent Ideavirus Management By Their Creators.

A manifesto is a carefully organized series of ideas, designed to get someone to come around

to your point of view. But while one way to make a complicated argument is with a book,

you can just as easily (and sometimes more effectively) send it through a song (Bob Dylan

did this for Hurricane Carter) or with something as elegant as an OXO vegetable peeler.

When you first see the OXO, you instantly understand the idea behind it. You just know it

will work better and cut you less often. If you’ve ever peeled a vegetable, you want an OXO.

The design of the OXO is quite simply a manifesto that says, “There’s a smart, comfortable

way to do this annoying task.” Is the OXO going to get viral? Not across the general

population, of course, but if you hang out with a group of people who have arthritis or love

kitchen stuff, it already has. Just take a look at the glowing reviews of this peeler on

Amazon’s kitchen site.

Unleashing the Ideavirus 36 http://www.ideavirus.com

The End Of The Zero Sum Game

Traditional advertising is a game with winners and losers. If your product gets attention from

the targeted consumer, you win “mindshare” and your customer loses time. When a

consumer is foolish enough to listen to an irrelevant ad, she loses time and doesn’t even gain

useful information. It’s an old economy model in which every transaction has someone

taking something.

Permission marketing and the ideavirus are both very different from this model. These

models create a game in which everyone can win! If there’s a great idea, and it moves through

the hive for free, everyone who touches it wins in several ways.

First, you as the consumer win for recommending it to a friend. This increases your status as

a powerful sneezer (or your compensation as a promiscuous sneezer.) Because you respect

your peers, you’re not suggesting or pitching something that doesn’t make your friends’ lives

better. Violate this respect and your power as a sneezer goes way down.

Definition: SNEEZER Some people are more likely to tell their friends about a great new

idea. These people are at the heart of the ideavirus. Identifying and courting sneezers is a key

success factor for ideamerchants.

Second, the recipient benefits as well. He benefits from the way the idea changes his life, and

he benefits because he now has the ability to sneeze the idea to someone else, thus increasing

his power.

Third, the creator of the idea succeeds because her idea propagates and because she can sell

souvenirs (speeches, consulting, value-added services) to people who are now open and

receptive to her idea.

My friend, Chris Meyer, co-author of Blur, had this to say: “The one thing that distinguishes

effective sneezing campaigns from ineffective ones is RESPECT for the time, attention, and

reputation of the next guy to catch the virus. It’s important to note that the decision to

sneeze is, in general, a distributed one, made by each of us as to whether to clog our friend’s

Unleashing the Ideavirus 37 http://www.ideavirus.com

email or whatever with the virus in question, because our (local, at least) reputation is at

stake.”

This insight goes to the core of why ideaviruses are succeeding and why traditional marketers

don’t immediately grasp this approach (or permission marketing for that matter.) The

distributed nature of the decision is the antithesis of the command-and-control General

Patton approach that marketers have taken previously.

The reason that The Red Herring, The Industry Standard and other magazines are jammed

with ads is not because the ads always work. They don’t. The reason the ads are purchased is

that in exchange for money the marketer gets the illusion that they’re in charge of the

conversation, at least for a few seconds.

Bill Bernbach, the dean of American Advertising, was co-founder of DDB Advertising. He

died twenty years ago, but before he left us, he pointed the way to this “new” way of

marketing:

“You cannot sell a man who isn’t listening; word of mouth is the best

medium of all; and dullness won’t sell your product, but neither will

irrelevant brilliance.”

The answer, of course, is to give people a reason to listen and then create an infrastructure

that will amplify their ability to spread word of mouth. And core to both of those tasks is the

new respect that marketers need to show newly powerful consumers.

Unleashing the Ideavirus 38 http://www.ideavirus.com

SECTION 2: How To Unleash An Ideavirus

STEAL THIS IDEA!

Here’s what you can do to spread the word about Unleashing the Ideavirus:

1. Send this file to a friend (it’s sort of big, so ask first).

2. Send them a link to http://www.ideavirus.com so they can download it themselves.

3. Visit http://www.fastcompany.com/ideavirus to read the Fast Company article.

4. Buy a copy of the hardcover book at

http://www.amazon.com/exec/obidos/ASIN/0970309902/permissionmarket.

5. Print out as many copies as you like.

Unleashing the Ideavirus 39 http://www.ideavirus.com

While It May Appear Accidental, ItÕs Possible To Dramatically Increase The

Chances Your Ideavirus Will Catch On And Spread.

This is the really cool part. Once you understand the fundamental elements behind the

propagation of an ideavirus, you can unleash your own.

Just because ideaviruses have usually spread through unknown means or accidental events

doesn’t mean that there isn’t a science to building and managing them.

You can invest in designing your product to make it virusworthy. Then if you understand

the eight elements of the ideavirus formula, you increase your chances of spreading your

ideavirus with every step along the way.

This can change the way you approach all of your marketing. If launching an ideavirus is the

most powerful thing you can do for a product and service, and there are steps you can take to

increase the likelihood that this will occur, you’ve got to try!

Unleashing the Ideavirus 40 http://www.ideavirus.com

The Heart Of The Ideavirus: Sneezers

SNEEZERS Some people are far more likely to spread an ideavirus than others. Malcolm

Gladwell (author of the brilliant book and ideavirus, The Tipping Point) calls this the Law of

the Few and breaks the key virus spreaders into three groups: Connectors, Mavens and

Salespeople. What’s critical in the analysis is understanding that some folks are dead ends,

while others will enable and amplify your ideavirus.

In his best example, Gladwell talks about the success of Paul Revere in warning us that the

British were coming. It turns out that a second man, William Dawes, went on a similar ride

the same night—but his was a total failure.

Why did Dawes fail where Revere succeeded? It’s because people knew Paul Revere. They

trusted him. He had credibility. And so when he said something, people were willing to

listen and believe. Revere was a sneezer. Dawes, a loner, tried hard but couldn’t get the idea

to become a virus.

Sneezers are at the core of any ideavirus. Sneezers are the ones who when they tell ten or

twenty or 100 people—people believe them.

Unleashing the Ideavirus 41 http://www.ideavirus.com

Sneezers Are So Important, We Need To Subdivide Them

There are two basic kinds of sneezers:

Promiscuous Sneezers

This is your uncle the insurance salesman. These are members of a hive who can be counted

on to try to “sell” their favorite ideavirus to almost anyone, almost any time.

1.

Promiscuous sneezers can be motivated by money or other inducements.

2.

Promiscuous sneezers are rarely held in high esteem as opinion leaders, but if they’re

promiscuous enough, they can be extremely effective.

DEFINITION: HIVE People are not one amorphous mass. We’re self-organized into

groups, or hives that have several things in common: a way to communicate among

ourselves; spoken or unspoken rules and standards; a common history; fashion leaders. Some

examples: Fraternity brothers at a college, orthodox Jews, readers of Fast Company,

Deadheads.

Many of the Net businesses that are now being organized around ideaviruses are targeting

this group (people who are willing to sell to their friends for personal gain). Companies like

Mercata, All Advantage and even Amazon are offering inducements to customers that

compensate them for spreading ideas to their friends and acquaintances in an attempt to

acquire new customers. As the value of creating ideaviruses increases, we’ll see more of this,

and we’ll also see more and more people becoming promiscous sneezers—basically, we’re

paying folks enough to corrupt them into spreading ideas in exchange for cash.

Powerful Sneezers

The hat business is near the end of an eighty-year downward spiral to total irrelevance. Each

year has brought worse news, with one manufacturer after another going out of business, and

most towns left with one (if they’re lucky) haberdasher.

In the midst of all this dismal news, about twenty years ago there was one bright spot.

Harrison Ford. With a bullwhip. Wearing a hat.

Unleashing the Ideavirus 42 http://www.ideavirus.com

Indiana Jones sold more hats for Stetson than any single person since the invention of the

Marlboro Man. Why? Because Ford has the influence to set style, because his appearance in a

movie wearing that hat coaxed millions of men who wanted to be like him into buying a hat.

The paradox of the powerful sneezer is that he can’t be bought. Every time a powerful

sneezer accepts a bribe in exchange for spreading a virus, his power decreases. When Bruce

Springsteen does ads in Japan, or Whoopi Goldberg shills for Flooz, they have less leverage as

powerful sneezers. The public knows that they can be motivated by more than just taste.

In fact, every time a powerful sneezer tries something new and introduces a new idea, she

takes a risk. If her followers reject the virus (for whatever reason), her ability to introduce

future viruses decreases. For this reason, it’s difficult to manipulate powerful sneezers, and

equally difficult to predict what might motivate them to adopt an ideavirus.

Here’s an analogy that demonstrates the difference between promiscuous sneezers and

powerful sneezers, and more important, explains how they might converge:

Anyone can buy an ad in the Pennysaver, or even write and insert a “special advertising

section” in some fancy magazine. The advantage of this kind of presentation, obviously, is

that it gives the marketer complete control over how the message appears and what it says.

Advertising is basically paid sneezing. And because the public realizes that that’s all it is, it

doesn’t have an awful lot of credibility. It still works, but it’s not as effective as real sneezing

from a powerful sneezer.

On the other hand, it’s up to the editor in chief of the New York Times to decide what

articles appear in the paper. No matter how much money a marketer spends (even though

spending a lot might get you noticed by the editorial staff), there’s no guarantee that an

article will appear—and no guarantee that if it does appear, it will say what you want it to

say.

Unleashing the Ideavirus 43 http://www.ideavirus.com

Enter the web. There are plenty of websites where the line between editorial content and

advertising is blurred, where sponsoring a website also gives you the right to say what you

want to say.…

So let’s imagine for a second that the New York Times embraced this shocking idea. That

they said, “Okay marketers, write your own articles! And pay us to run them!” Now there’d

be some ground rules. First, the marketer would specify how much they’d be willing to pay

to have a story featured. For example, a restaurant could decide it might be worth $10,000

for a feature on their new chef to appear in print.

Second, the Times would get final say over what was printed.

Obviously, a wholesale switch from powerful sneezer to promiscuous sneezer would decimate

the circulation base of the Times. If the Times accepted any article, regardless of credibility

and interest, just because the marketer was the highest bidder, it would totally destroy the

paper within a week.

But what if the Times realized that picking only the very best articles that were submitted

(maybe just a few a day) could ensure that people would still be delighted to read the paper?

What if the Times knew that for every 199 badly written restaurant fluff pieces, a great one

would show up? And what if the editor in chief had enough guts to pick just the great articles

and resist pressure to completely sell out?

Journalistic handwringing aside, this is already happening (not at the fabled Times, of

course), and it’s going to happen more. It’s happening on websites. It’s happening on

television (witness the CBS coverage of iWon.com awarding prizes—CBS owns a chunk of

iWon.) And far more interesting than this tortured analogy, it’s already happening with

people’s personal sneezing ethics.

A hundred years ago, there weren’t many opportunities for playwrights, actors and captains

of industry to sell out. Today, Whoopi Goldberg pitches Flooz, William Shatner pitches

Priceline and Gerald Ford is on the board of directors of several companies. In each case, the

celebrity is shifting from role of influential, powerful, can’t-be-bought-I’m-a-style-statesman

Unleashing the Ideavirus 44 http://www.ideavirus.com

to promiscuous sneezer, available for sale. William Shatner had lost his ability to set style

through his actions—he was past his prime as a powerful sneezer. So the segue to paid

sneezer made sense for his career. It would probably be a dumb move for Tom Cruise or Mel

Gibson, though.

After I left Yahoo!, I had many opportunities to serve on boards and do endorsements. I

chose not to. Why? Because I didn’t want to squander the powerful sneezing points I’d

earned by writing my last book. The one ad I did, I did for free. I’m still hearing about it.

Think about your own situation…. Have you ever signed up a friend for MCI’s Friends and

Family program? Or tried to get someone to use your Amazon affiliate links to buy books?

Or join with you to buy something at Mercata.com? In every case, you’re getting paid to

alter your behavior. That makes you more promiscuous and less powerful.

As the Net makes it easier to measure ideaviruses and motivate sneezers, we’re going to see

far more people become Promiscuous Sneezers, but, at the same time, the role of the

powerful sneezer will become ever more important. As available attention becomes ever more

precious, we’re going to be far more likely to listen to someone who’s spreading a virus for

non-personal gain.

Epinions.com is a fascinating model of the intersection between the powerful and the

promiscuous sneezers. Here’s a site where hundreds of thousands of people come to hear the

opinions of thousands of sneezers. Everything is reviewed, from books to dishwashers. And

the reviewers are clearly identified and constantly ranked. Promiscuous sneezers (who get

paid to do the reviews) suddenly become powerful! How? If a lot of people read and like

your reviews, your reviews carry more weight, regardless of your compensation scheme.

“Xyz” has posted more than 1,000 reviews and been read more than 100,000 times. She’s

compensated every time someone reads one of her reviews, so she certainly qualifies as

promiscous. She works hard to get others to read her reviews. But at the same time, she’s

developing a reputation as a powerful sneezer.

Unleashing the Ideavirus 45 http://www.ideavirus.com

Referrals.com is a business based around the idea of paying people to help with job searches.

Instead of just giving some headhunter the names of five friends who might be perfect for a

job (and having the headhunter collect a $30,000 fee if you’re right), referrals.com turns the

idea upside down. With their system, YOU send the job offer along to your friends, and if

they take the job, you get a check for $4,000.

If Referrals.com only attracts promiscuous sneezers, the business will fail. Why? Because the

very best people try hard not to listen to interruptions from promiscuous sneezers. The very

best people know that if someone can be bought, they’re not much more than a walking

billboard, and just as they ignore the billboards on the highway, they’re going to ignore the

most promiscuous sneezers in their midst. (Aside: If you’ve ever been called by a headhunter,

you know just how promiscuous people are willing to be in exchange for cash!)

Referrals.com is working very hard to turn powerful sneezers within very select, high-end

hives into people who, on occasion, are willing to sell out for a $4,000 payoff. These are folks

who might not hassle you just so they can make $5 or $10 in bonuses. But the idea of

becoming a headhunter and making $4,000 in exchange for sending a few emails is too

irresistible to pass up. This idea that even the powerful can become promiscuous for the right

inducement and in the right setting is a key building block to unleashing the ideavirus in an

organized way.

What a paradox. Powerful sneezers become less powerful when you buy them off. But

sometimes, promiscuous sneezers become powerful again when they get particularly

successful at it. It’s a cycle, with people switching off from one to another, always trying to

figure out how to be both promiscuous (read profitable) and powerful.

Unleashing the Ideavirus 46 http://www.ideavirus.com

The Art Of The Promiscuous

How do you attract and keep promiscuous sneezers? There are six key principles:

1. Make big promises

2. Show them how to make it up in volume

3. Describe an attainable path

4. When someone succeeds, tell the rest of them

5. Give the successful ones a way to show the non-sneezers it worked

6. Have a Mary Kay convention

Make big promises

One of the things that drives someone to become a promiscuous sneezer is the opportunity

for a change in lifestyle. Certain rewards, though small, are not as enticing as slightly less

certain rewards that are much larger. Human nature (especially among the optimists) will

give you the benefit of the doubt on the risks, but it won’t cut you any slack on the rewards.

So, I’m much more likely to help you out for a chance to get free dry cleaning for six months

than I am to get a certain reward of $4 off my next dry cleaning bill.

Show them how to make it up in volume

Of course, the promise has to be believable. One of the best ways to do that is to make it

clear to the promiscuous sneezer that the system can be gamed. That if they work the system,

the odds of winning go way up.

If I look at the offer you make and say, “Wait. If I go to ten friends, not just one, then I’m a

lock to win this great prize…” you’ve done it right. I may think I’m scamming you by going

to so many people to adjust the odds in my favor, but actually, I’m doing just what you

wanted me to do—and then some.

Many of the online affiliate programs work this way. These programs offer a commission for

referrals that result in a sale. First designed as a cheap way to get new customers referred from

relevant web sites, they’ve evolved into something far bigger. If you’re at an online pet store,

Unleashing the Ideavirus 47 http://www.ideavirus.com

for example, and you see a link to a book about training dogs, you can click on the link and

buy it from Amazon.com. Amazon then sends the affiliate (the online pet store) a

commission. Small businesspeople have looked at these programs and said “Wait! If I build a

site that does nothing but sell books and Barnes and Noble does all the work, I’ll scam the

system and make a ton of money.” Of course, the online bookstore doesn’t care a wit about

where the customers come from. They’re just happy to have them. In essence, hundreds of

thousands of entrepreneurs are now building businesses dedicated to finding customers for

other merchants.

Describe an attainable path

Alas, trust is in short supply, even among optimistic promiscuous sneezers. Thus you’ve got

to make it clear to potential sneezers that there is in fact a way for them to profit from this

adventure.

This is especially true for offers where you don’t have a lot of time to make your case. By

showing the sneezer how smooth the system is, by making it trivially easy to forward that

email or whisper to that friend, you’re far more likely to get their initial enthusiasm. The first

few sneezes are the most difficult to get an individual to perform.

When someone succeeds, tell the rest of them

This is so important and so overlooked. I’m presuming that you’ve gained permission to talk

with your sneezers on an ongoing basis. So now talk to them! I’m a member of several online

affiliate programs, but not one of them does this. Why not send announcements detailing

how the most effective affiliates are doing? Why not invite me to visit their sites and see them

in action? By making it really clear that some sneezers are happily profiting, you dramatically

increase the chances you’ll get better performance from the rest of your sneezers.

Give the successful ones a way to show the non-sneezers it worked

Mary Kay cosmetics gives its best salespeople a pink Cadillac. This is no accident.

There are plenty of ways to pay off a promiscuous sneezer. Why do it with a pink Cadillac?

Because it is a persistent amplifier of this sneezer’s success. Because it attracts new sneezers to

Unleashing the Ideavirus 48 http://www.ideavirus.com

the fold. Because it’s proof to the rest of your organization and to the world that you can get

rich by selling cosmetics to your friends.

Have a sales convention

Just because it’s a new century doesn’t mean we should abandon the idea of getting together

in real life. Zig Ziglar tells the story of how Mary Kay went to a sales convention when she

was a struggling salesperson. She didn’t even have enough money to eat the meals there…

she brought her own crackers and cheese. But at the final banquet, when the salespeople

queued up to shake the company president’s hand, Mary Kay looked at him and said, “Next

year, I’ll be back as the #1 salesperson.” The president, who could have easily brushed off the

claim, stopped what he was doing, paused for a full thirty seconds, looked her in the eye and

said, “Yes, yes, I believe you will.”

And the rest is sales history. But without the convention, I seriously doubt this would have

occurred. How can you get together with your best promiscuous sneezers?

In addition to these six principles, there are two things you can do to totally and completely

wreck your network of promiscuous sneezers:

1. Change the rules in the middle

2. View the relationship as an expense

Don’t change the rules in the middle

Alladvantage.com is one of the fastest growing websites on the planet. The idea was to create

a multi-level marketing organization where each member would get paid for the ads they saw

and, more importantly, for the ads seen by the people they recruited. This led to a classic

MLM (multi-level marketing) network marketing business, where people made more money

bringing in new salespeople than they did actually using the product.

After growing to more than five million registered users, the company took a look at the

numbers and realized that the path to profitability was going to be hampered by the high

rates they were paying. So, well within the fine print they had published when they first

started, they changed the rates.

Unleashing the Ideavirus 49 http://www.ideavirus.com

All hell broke loose. The very best sneezers started sneezing against the company. The growth

rate hiccupped. Bad news. They’ll survive, and they might even continue their record

growth. But far better to have run the numbers in advance and had a payment schedule they

could live with forever.

Don’t view the relationship as an expense

It’s so easy to move your relationship with promiscuous sneezers from investment to expense.

After all, at the beginning it’s great because these people are dramatically cutting your

acquisition costs and helping you grow. But once you do grow, it’s easy to assume your

growth might be able to continue without the “high cost” of paying your sneezers.

In practice, there are two terrible side effects. The first is that you’ll inevitably try to trim the

benefits you offer your sneezers as well as the effort you put into keeping them happy. Better

to just cancel the program outright than to start disappointing these critical allies (remember,

an unhappy promiscuous sneezer can quickly become an angry powerful sneezer).

Second, you’ll find yourself trying to grow using techniques that you haven’t evolved, tested,

measured or practiced. And more often than not, that means failure.

A better strategy is to put a cap on your new sneezer acquisition efforts at the same time you

love and reward your existing sneezers. During this interregnum period, get really good at

tapping other ways to grow. Only after you’re confident that you’ve got the transition

working should you start to phase out the sneezers who got you there in the first place.

Unleashing the Ideavirus 50 http://www.ideavirus.com

ItÕs More Than Just Word Of Mouth

Marketers have been pursuing word of mouth for years. There are five important principles

that someone unleashing an ideavirus should understand—principles that marketers

pursuing old-fashioned word of mouth didn’t use:

1. An idea merchant understands that creating the virus is the single most important part of

her job. So she’ll spend all her time and money on creating a product and environment that

feeds the virus.

2. An idea merchant understands that by manipulating the key elements of idea

propagation—the velocity, the vector, the smoothness, the persistence and the identification

of sneezers—she can dramatically alter a virus’s success.

Definition: PERSISTENCE Some ideas stick around a long time with each person,

influencing them (and those they sneeze on) for months or years to come. Others have a

much shorter half-life before they fade out.

Definition: VECTOR As an ideavirus moves through a population, it usually follows a

vector. It could be a movement toward a certain geographic or demographic audience, for

example. Sometimes an ideavirus starts in a sub-group and then breaks through that niche

into the public consciousness. Other times, it works its way through a group and then just

stops. Napster vectored straight to college kids. Why? Because they combined the three

things necessary for the virus to catch on: fast connection, spare time and an obsession with

new music.

3. The idea merchant remembers that digital word of mouth is a permanent written record

online, a legacy that will follow the product, for good or for ill, forever.

4. An idea merchant realizes that the primary goal of a product or service is not just to satisfy

the needs of one user. It has to deliver so much wow, be so cool, so neat and so productive

that the user tells five friends. Products market themselves by creating and reinforcing

ideaviruses.

5. An idea merchant knows that the ideavirus follows a lifecycle and decides at which

moment to shift from paying to spread it, to charging the user and profiting from it.

Unleashing the Ideavirus 51 http://www.ideavirus.com

An Ideavirus Adores A Vacuum

It’s very hard to keep two conflicting ideaviruses in your head at the same time

(Communism: evil or benign? Martha Stewart: pro or con? Can’t have both). So if an idea

already inhabits space in your consumer’s brain, your idea can’t peacefully coexist. It usually

has to dislodge a different idea, the incumbent, and that’s always tough.

Given that, the best friend of an ideavirus is a vacuum. When “60 Minutes” ran the story

about runaway acceleration in Audi cars, it was an ideal ideavirus. Why? Because most people

had never driven an Audi. Most people had never interacted with the Audi company. Most

people didn’t have a best friend who loved his Audi. As a result, the virus rushed in, filled the

vacuum and refused to be dislodged.

Audi, of course, did exactly the wrong thing in fighting the virus. They issued a tight-lipped

response and relied on engineering data to PROVE that they were right. Very correct, very

German and totally ineffective. It cost the company billions of dollars in lost sales.

Audi didn’t have to go out and spread the idea that Audi’s were good cars. That would have

been pretty straightforward if they were starting from scratch. Instead, Audi had to undo the

idea that had been spread by “60 Minutes”. And responding “did not” to TV’s “did too” was

a recipe for failure.

Instead, they could have countered the virus by filling in the rest of the vacuum. I would

have advised them to put an Audi 5000 in every major shopping mall in America. Let people

sit in it. Invite them to take the “Audi Sudden Acceleration Test” and see for themselves

what the car was like. By creating a more vivid and forceful alternative to a television hatchet

job, Audi could have unleashed its own countervirus.

At the beginning, the Internet was a vacuum. A Yahoo! or an eBay or an Amazon could walk

in and propagate its ideavirus fast and cheap. Today, though, launching a new search engine

or a new email service is hard indeed. Why? Because the vacuum’s gone.

Unleashing the Ideavirus 52 http://www.ideavirus.com

Take the much-coveted Aeron chair from Herman Miller. The company introduced this

puffy, bouncy desk chair for star executives and invented a market where none had

previously existed. Suddenly, you could spend a lot of money on a chair that actually worked

better, as opposed to just one that made you look bigger when you were busy firing people.

When Internet marketing pioneer Site Specific raised its first round of venture capital, the

principals went out and spent $15,000 on these chairs! This is a chair so remarkable, it was

featured on the front page of the Wall Street Journal.

Now, of course, there are plenty of neat, ergonomic desk chairs. One of Herman Miller’s

biggest competitors is betting the farm on their new Leap chair. Their MBA’s have taken a

hard look at Aeron’s success and market share and decided that they can capture x% of the

market. The problem, of course, is that there’s no longer a vacuum. The problem is that

now, instead of spreading a virus about how you can be more comfortable all day, they have

to spread a much smaller, and less compelling virus about why their chair is a little better

than the chair you’ve already heard of.

There are vacuums in your industry. But not for long….

Unleashing the Ideavirus 53 http://www.ideavirus.com

Once It Does Spread, An Ideavirus Follows A Lifecycle. Ignore The Lifecycle

And The Ideavirus Dies Out. Feed It Properly And You Can Ride It For A Long

Time.

Tom Peters co-wrote In Search of Excellence nearly twenty years ago. Through some smart

marketing moves (not to mention a great virus) the book became an epidemic and turned

into the bestselling business book ever written.

Tom’s career could have followed the arc of almost every other business writer… a big hit

followed by a long decline into obscurity. But instead of ignoring the lifecycle, Tom insisted

on riding it.

And he’s still riding it today. Every few years he unleashes a new ideavirus. He writes

mindblowing articles (like the “Brand Called You” cover piece for Fast Company a few years

ago) and follows up with books and exhausting worldwide speaking tours. When he shows

up in a town to give a speech, perhaps a third of the people there are dyed-in-the-wool Tom

Peters fans. And the rest of the audience? Brought there by the fans, exposed to his virus,

ready to be turned into fans.

By leveraging the base that his first book brought him, Tom has built a career out of

launching new ideaviruses. Sure, none of them were as big as In Search of Excellence, but the

vacuum keeps getting smaller, so the opportunities are smaller.

Other companies and ideas have ridden their first wave and then disappeared. People no

longer clamor to dance the Hustle or to get into Studio 54. They don’t visit the once hot

jennicam website or pay a premium for front row seats at Cats. Why? Because instead of

institutionalizing the process of improving, honing and launching new ideaviruses to replace

the dying ones, the “owners” of these viruses milked them until they died.

Unleashing the Ideavirus 54 http://www.ideavirus.com

Viral Marketing Is An Ideavirus, But Not All Ideaviruses Are Viral Marketing

Viral marketing is a special case of an ideavirus. Viral marketing is an ideavirus in which the

medium of the virus IS the product. It’s an idea where the idea is the amplifier.

DEFINITION: AMPLIFIER A key difference between word of mouth and an ideavirus is

that word of mouth dies out while an ideavirus gets bigger. Why? Because something

amplifies the recommendations to a far larger audience. That could be TV or other forms of

media (a good review in the New York Times that amplifies the message of one reviewer to

many readers) or it could be the web (a site like planetfeedback.com amplifies the message of

a single user).

Steve Jurvetson, the venture capitalist behind Hotmail, coined the term “viral marketing” to

describe the way the service grew. Hotmail offered free email. That alone was a very

compelling two-word business proposition. But the magic of the company was that in every

single email you sent using the service, there was a little ad on the bottom of the note. And

the ad said, “Get Your Private, Free Email from Hotmail at http://www.hotmail.com”.

Every time you sent a note, you spread the virus. The magic of viral marketing is that the

medium carries the message. The more you use Hotmail, the more you spread the virus. But

note: It was also extremely smooth…. The Hotmail site was just a click away from an email,

and it took just a few clicks more to start using it—and sending Hotmail’s built-in ads to

your friends.

Unfortunately, not every product lends itself to viral marketing. Viral marketing requires

that the product you’re using be communications-focused or very public. The new VW

Beetle is an example of viral marketing. Why? Because the more you drive it, the more

people see it. And the more Beetles people see, the more they want one. It’s not audible and

it’s not as smooth as Hotmail, but it is most definitely viral.

Many of the very best Internet ideas are built around some level of viral marketing. Using an

earlier example, Referrals.com pays big money to people who recruit their friends for hot

Unleashing the Ideavirus 55 http://www.ideavirus.com

jobs. Of course, the act of recruiting your friends is also the act of telling them about

Referrals.com.

Try not to get too obsessed with the magic, self-referencing nature of viral marketing

companies. They’re a very special case—for example, it’s hard to imagine how most books

could use viral marketing. Interesting, though, that line-dances like the Hustle and the

Macarena DID use viral marketing. After all, you can’t do the dance unless you teach your

friends how!

Unleashing the Ideavirus 56 http://www.ideavirus.com

What Does It Take To Build And Spread An Ideavirus?

There are two questions you can ask yourself about your idea before you launch

it…questions that will help you determine how likely your idea will become an ideavirus.

Is it worth it?

Nobody spreads an ideavirus as a favor to you. They do it because it’s remarkable, thoughtprovoking,

important, profitable, funny, horrible or beautiful. In today’s winner-take-all

world, there’s no room for a me-too offering, or worse, BORING products and services. If

it’s not compelling, it will never lead to an ideavirus.

Face it. Nobody is going to hand out big rewards ever again for being on time, performing

work of good quality, being useful, finishing a project on budget or being good enough.

That’s expected. That’s a given. The rewards (and the ideavirus) belong to the first, the

fastest, the coolest, the very best.

The biggest mistake companies make is that they chicken out. If your idea doesn’t become a

virus, it’s most likely because it didn’t deserve to become a virus.

If you’re now defining yourself as an idea merchant (hey, it’s either that or lose), then you

must accept the fact that being brave and bold in the creation of ideas is the only reason you

went to work today.

Is it smooth?

After someone’s been exposed to an ideavirus just once, they’re not likely to actually catch it.

We’ve made our brains bulletproof and ideaproof. There’s so much clutter, so much noise,

so many ideas to choose from that the vast majority of them fail to make a dent.

Think about the last time you walked through a bookstore (the home of ideaviruses waiting

to happen). How many books did you stop and look at? Pick up? Turn over? And how many

of those books ended up in your shopping basket? Got read? Led you to tell ten friends?

Precious few, that’s for sure.

Unleashing the Ideavirus 57 http://www.ideavirus.com

Compare this to the Harry Potter phenomenon… the bestselling books of the last few years,

created just because kids told kids. A classic ideavirus, and one that initially grew with no

promotion at all from the publisher.

It’s difficult to get from awareness to the “sale” of an idea, to convert a stranger into a friend

and a friend into a carrier of your ideavirus. An ideavirus succeeds when it pierces our natural

defenses and makes an impact.

In greek mythology, they tell the story of the Medusa. The Medusa was part of the race of

Gorgons—beings with a horrible curse. Anyone who looked in their eyes immediately and

permanently turned to stone.

There are plenty of marketers who wish that their ads or their product had the power of the

Medusa: that every person who saw it would be immediately transfixed, rooted to the spot,

and converted into a customer for life. (Of course, they don’t want their customers to die a

horrible death and be turned into stone, but I couldn’t find a Greek myth in which an evil

goddess turned you into a frequent shopper of Kate Spade purses, getting a second mortgage

just to pay for them.)

Alas, there are precious few Gorgon products and even fewer ad campaigns with Gorgon-like

properties. It’s foolish to expect that one exposure to your message will instantly convert

someone from stranger to raving ideavirus-spreading fan. So plan on a process. Plan on a

method that takes people from where they are to where you want them to go.

And while you’re at it, work on the product. Because a catchier, more compelling, more viral

product makes your job 100 times easier.

These are critical decisions because of the attention deficit marketers are facing. In 1986, the

year I published my first book, there were about 300 other business books published. In

1998, there were 1,778 business books brought to market.

The supermarket sees about 15,000 new products introduced every year. The Levenger

catalog alone features more than 50 different pens and pencils, none of which were available

Unleashing the Ideavirus 58 http://www.ideavirus.com

just a couple years ago. There isn’t a marketplace out there that isn’t more crowded than it

was a decade ago.

In a world where products are screaming for attention, the most precious commodity is

attention. And attention is harder and harder to achieve.

If you already understand the power of permission, your next question might be, “Fine, but

how do we get permission? How do we get the first date… the first interaction where we ask

people if we can start an ongoing dialogue about our products and their needs?”

My answer used to be a rather weak mumble about buying ads. The right answer, however,

is to create an ideavirus. The right answer is to let the market tell itself about your products

and services and give you permission to continue the dialogue without your having to pay for

it each time. The right answer is to create products so dynamic and virusworthy that you

earn the attention.

Unleashing the Ideavirus 59 http://www.ideavirus.com

There Are Three Key Levers That Determine How Your Ideavirus Will Spread:

Where do you start? What are the key elements worth focusing on to turbocharge your idea

and turn it into a virus? There are three things to focus on:

1. How big do you launch?

2. How smooth is it?

3. How can you turn trial into persistence?

1. How many people know about it before the spreading starts?

You can launch big or you can launch small. Vindigo (a viral phenomenon discussed in

detail later) launched their Palm ideavirus with just 100 people. Within weeks, that number

had grown to 3,000, and then quickly to more than 100,000. All without advertising.

However, if you’re entering a vacuum and there’s plenty of competition on the horizon,

launching big (while more expensive) can increase the chances that you’ll succeed.

How to launch big? With traditional interruption advertising. With sponsorships. With free

samples. One of the dumbest things marketers do is put artificial barriers in the way of trial.

For example, it’s obvious that one of the best ways to kill sales of a new car is to charge

people $100 to take a test drive.

But charging for a test drive is just as dumb as a politician charging people to hear a speech,

or a movie studio charging for the coming attractions. When you launch an ideavirus, the

more people who can see it fast, the faster it will spread.

Unleashing the Ideavirus 60 http://www.ideavirus.com

2. The importance of smoothness.

In addition to being persistent and cool, an ideavirus spreads the fastest when it’s smooth.

Persistence matters because the longer people are sneezing about your idea, the more people

they infect. Cool is critical because if it’s not virusworthy, it’s just not going to take off. But

smooth is essential because if you make it easy for the virus to spread, it’s more likely to do

so. In viral marketing (for products like the Polaroid camera and Ofoto.com) the ideal

solution is to build smooth transference tools right into the idea—which can be difficult.

But that doesn’t mean you shouldn’t try. Amazon tried with “Member Get a Member”

promotions, in which they bribe members to tell their friends to buy books from Amazon

(get $5 for your friends and $5 for you!). ZDNet puts a button next to every story they

publish on their website: click here to send this article to a friend. Smooth.

Tupperware built an entire company around the smooth transfer of product enthusiasm

from one friend to another. When you have a Tupperware party you are simultaneously

hanging out with friends, demonstrating products you like, selling them and recruiting other

Unleashing the Ideavirus 61 http://www.ideavirus.com

people to do the same to their friends. By focusing obsessively on how to make it smooth,

you can dramatically increase the velocity of the ideavirus.

3. Turning trial into persistence.

Sooner or later, you’ve got to turn momentary attention into an embrace of your idea, and

then, hopefully, into conversion of the user into a sneezer.

Permission marketing becomes a critical tool in working people through this transition. The

Hare Krishnas have grown their sect by inviting people to eat a vegetarian dinner with them.

Intrigued or just hungry, people give them momentary attention and then permission to talk

to them about this new way of life.

Sometimes people leave, having done nothing but eaten dinner. Sometimes, people listen to

what’s being said and decide to embrace the ideals being discussed. And sometimes, they

become converted and turn into sneezers, volunteering to go out and invite other people over

for dinner the next night.

Note that they didn’t start by walking up to a stranger and proselytizing about their religion.

Instead, they used a gradual technique to sell their idea effectively and turn it into a virus.

Are there religions that are not viruses? Sure, the Shakers were. They didn’t try to convert at

all. That’s why there are no Shakers left.

On the web, this multi-step process is too often overlooked by companies facing short-term

financial pressure (combine this with the legendary short attention span of entrepreneurs and

you can see why this happens). Instead of building a virusworthy cool product or service,

identifying a hive, promoting an idea, and making it smooth and persistent, they just spend a

few million dollars to buy advertising.

The hope, of course, is that somehow by spending enough money on clever ads, they’ll

magically create a critical mass of positive energy that will turn their idea into a virus.

They’re looking for a shortcut, and as a result, leading their companies to doom. Building a

virus takes insight, talent and most of all, patience.

Unleashing the Ideavirus 62 http://www.ideavirus.com

After a consumer is interested enough to visit ZDNet or Google.com or some other neat new

site, what should these sites do to augment the ideavirus? Three things:

1. Get permission to follow up: make it easy for me to learn about why I should embrace this

idea over time. All those ads you ran are a great way to get someone to your site, but it might

cost your site $100 in marketing expenditures to get that one visit from just one consumer. If

you don’t get permission to follow up, the entire $100 is wasted.

2. Make as many supporting manifestos available as possible, in whatever forms necessary, to

turn consumers from skeptics into converts. This can include endorsements, press reviews,

even criticisms and commonly made objections. Think of the Hare Krishnas at dinner. The

more they can expose you to during that hour, the better the odds of spreading the virus.

3. Make it easy for consumers to spread the ideavirus by providing a multitude of tell-afriend

tools, as well as overt rewards for becoming a sneezer.

Unleashing the Ideavirus 63 http://www.ideavirus.com

Ten Questions Ideavirus Marketers Want Answered

1.

Have we chosen a hive we’re capable of dominating?

2.

How likely are the powerful sneezers to adopt our virus?

3.

Do we know who the powerful sneezers are and how to contact them?

4.

What can we do to our product to make it more virusworthy?

5.

Are we rewarding promiscuous sneezers sufficiently to get them on our side?

6.

Have we figured out what we want the sneezers to say? How are we teaching them to say

it?

7.

Even if our product isn’t purely viral by nature, is it possible to add more viral marketing

elements to it (or to our marketing approach)?

8.

Do we know how to get permission from people once they’ve been touched by the virus?

Do we know what to say after we get permission?

9.

How smooth is the transfer of the ideavirus?

10. Is our offering good enough to wow this hive?

11. Do we have the resources and time to dominate this hive before others rush in to fill the

vacuum?

12. Have we built in multiple feedback loops so we can alter the virus as it moves and grows?

13. Have we identified the vector we want the virus to move in, and have we built the tools

and plans to keep it moving in the vector we’d like?

Unleashing the Ideavirus 64 http://www.ideavirus.com

Five Ways To Unleash An Ideavirus

Of the five ways to unleash an ideavirus, the most important element they share is that for

best results you must build this thinking in from the very beginning. If you’ve got an existing

product or service and you’re hoping to build a virus around it, your job will be more

difficult. The ideas behind the lightning fast success stories have all worked because the

ideavirus concept was baked in from the start. That’s one of the reasons more established

companies are having so much trouble competing in the new economy—they’re restricted

because of the standards and systems they built in years ago.

The five techniques, in order of sheer market power, are:

1. Go full viral. The more you use it, the more you market it (whether you want to or not).

In essence, using the product is the same as marketing it.

2. Pay off the promiscuous.

3. Make it smooth for the powerful.

4. Digitally augment word of mouth.

5. Altruism…reward the friends of the promiscuous.

1. Go full viral. This is the holy grail of ideavirus marketing. The beauty of viral marketing is

that if you properly construct the virus, you can grow like a weed and dominate the

market—if you can do it before the competition.

Polaroid and Hotmail are the poster children for viral marketing, but there are a few other

that are worth looking at:

Blue Mountain Arts was a pioneer in creating a virus around the idea of sending electronic

greeting cards. The virus is simple to understand—in order to send a greeting card

Unleashing the Ideavirus 65 http://www.ideavirus.com

successfully, you’ve got to send it to someone. Of course, once someone receives the card, if

they like the idea, they’re just a click away from sending someone else a card!

Even though the cards featured by Blue Mountain Arts could charitably be called “cheesy,”

the virus caught on. People got the idea that it might be fun to send electronic cards to their

friends… and the idea spread. The company started small, with no real advertising. Just a

few people sent the first batch of cards.

But then the magic of viral marketing kicked in. Let’s assume that each person sends cards to

five people. Let’s also assume that those recipients have a 50% chance of being interested

enough in the concept to go to the site and send cards to five of their friends. If we start with

ten people, the generations look like this:

10 people send 50 cards

which means that 25 people get the virus and send 125 cards

which means that 63 people get the virus and send 315 cards

which means that 162 people get the virus and send 810 cards

which means that 405 people get the virus and send 2025 cards…

Now, that may seem like a slow start, but if you assume that each generation takes three days

to occur (I send out ten cards and within three days, five friends show up and do the same

thing), then you’d have 58 million users in 54 days!

Of course, that doesn’t really happen. It’s unlikely you’ll be able to continue to get a 50%

conversion rate. And it’s certain that you’ll soon hit duplication, with individuals starting to

get cards from different people. But the math is nevertheless stunning.

The key number in the equation is the percentage of people who convert. If you lower it

from 50% in the Blue Mountain Arts example to 30%, the number of users drops from 58

million to less than 10,000. Which is why conversion is so critical.

The battle between Hallmark and Blue Mountain in this space is fascinating. Hallmark and

American Greetings, both old-line card companies, were well aware of the potential of the

Unleashing the Ideavirus 66 http://www.ideavirus.com

Internet. But they were also unable to imagine a world in which cards didn’t cost money—so

they made the cards they sold online available for a fee.

As a result, no virus emerged from the Hallmark site. If someone was charmed by a card and

came to the site to send a few, they discovered that they’d have to pay to do that. They didn’t

convert. Conversion fell below the magic number and the virus never ignited.

You can compute the magic number by multiplying the number of cards the average user

sends (in the example above, it’s 5) by the percentage of people who convert (50%). In this

case, the magic number is 2.5, which is how much bigger each generation will be than the

one before. Until the magic number exceeds 1.2 or 1.3, it’s hard for a product to get viral fast

enough to beat the competition.

By focusing on smoothness (it’s only three clicks to send a card and it’s free, so go ahead and

try it), Blue Mountain built an amazing conversion machine. As a result, the site grew and

grew until Excite bought it for nearly a billion dollars worth of stock. Whatever Blue

Mountain’s goal—to make a lot of money, to affect a lot of people or to spread their idea far

and wide—they’ve succeeded.

Hallmark and American Greetings have seen the light, and now they, along with Yahoo! and

others, offer free greeting cards. The challenge that they face is that there’s no longer a

vacuum, so their ideavirus can’t spread as fast, and their magic number is far lower than that

which Blue Mountain Arts enjoyed at its peak (the number must go down as the population

of untouched people approaches zero).

Another example of viral marketing worth looking at is Ofoto. Ofoto is an Internet

alternative to Fotomat. Instead of dropping your film off at the corner, you send your digital

camera files to Ofoto and they send back beautiful prints.

This is a compelling story, but there isn’t enough money in the world to communicate it

through traditional marketing means. Kodak spends $100 million a year in advertising (and

has been advertising for a hundred years). On top of the huge amount of noise out there,

Unleashing the Ideavirus 67 http://www.ideavirus.com

there are just no easy media channels Ofoto can use to spread its message in a cost-effective,

fast way to the target hive: digital photography users.

So Ofoto also launched a digital photo album. This album lets you post your favorite digital

photos online, for free, and invite friends to come see them. Here’s the good part: a digital

photo album with no one looking at it is worthless!

Thus, once you upload your photos, you’ve got to motivate your friends and relatives to stop

by and see the photos. You become Ofoto’s #1 marketing weapon.

Take pictures of your kid’s soccer team. Upload them. Tell everyone on the team where to

find the photos.

Some of the parents will like the photos so much they’ll click a button and buy a print.

Ofoto has a new customer. Interestingly, the content was created by someone else —not the

person who bought the photo. This is an effect that never happens to Kodak.

Even better, some people who see the photos of the soccer team will realize that they too

would like to be able to post pictures for friends. So the torch passes, and Ofoto has added

another photographer to its ever growing stable.

It’s worth noting that the conversion rate for Ofoto is almost certainly going to be lower

than it was for Blue Mountain Arts. First, it’s much less smooth. In order to spread the word

that you’ve posted someone’s picture, you’ve got to find that person and tell them about it,

and then they’ve got to hustle themselves to a computer and go look at it… not as clean as

the all-electronic approach of Blue Mountain.

Second, the virus is less smooth. If I want to buy a print, I’ve got to enter my name and

address, AND I’ve got to pay for it. If I want to upload photos, I’ve got to figure out how to

use my digital camera upload files, or I’ve got to mail in my traditional film to Ofoto for

developing.

Unleashing the Ideavirus 68 http://www.ideavirus.com

Despite these obstacles, Ofoto has a very positive magic number as demonstrated by the fact

that they’ve amassed more than 500,000 users in less than 12 weeks.

The astute reader has probably noticed a critical difference between Hotmail and Blue

Mountain Arts vs. Ofoto.

Hotmail and Blue Mountain Arts are self-referencing ideaviruses. The virus spreads with the

use of the product whether the user wants it to or not. When you first start using Hotmail, the

self-promoting signature line promoting Hotmail is automatically included in every email

you send. You didn’t choose to do that (though you can turn it off), it just goes along

anyway.

In the case of Blue Mountain, the symbiotic relationship between the product and the

marketing is even more obvious. The card is the marketing, so using it is, by definition,

promoting it.

Ofoto, on the other hand, does no such thing. You could quite happily use Ofoto for

developing, sorting and storing your photos and never recommend it to anyone.

Clearly, if the marketing element is benign and totally integrated into your offering, your

magic number is going to be much higher; the symbiosis pays off with big dividends. The

product has 100% efficiency…every user becomes a promoter. The challenge is this: it only

works for a very select group of products and services—probably not yours.

Why have I gone to great lengths to point out that viral marketing is merely a subset of

ideavirus marketing? Because while very few of us will ever be lucky enough to enjoy the full

fruits of a viral marketing campaign, most of us can unleash an ideavirus.

2. Pay off the promiscuous.

Paying powerful sneezers in an effort to make them promiscuous (but have them keep the

power) is an extremely difficult balancing act, but if you can do it successfully, you can turn

it into a billion dollar business.

Unleashing the Ideavirus 69 http://www.ideavirus.com

Some people call it network marketing or multi-level marketing. Others think of it as a paid

celebrity endorsement. But it can be as simple as member-get-a-member for your local health

club.

The basic idea is simple: If your recommendation is going to help my business, I’m happy to

pay you to recommend me.

The implementations vary all over the map. When Nike paid the coach of the Duke

University basketball team millions of dollars (for him, not Duke) to coerce his team

members to switch to Nike shoes, they were turning a formerly powerful sneezer into a

promiscuous one. Why? When people see what the Blue Devils wear, they might decide to

wear the same thing.

On the Net, technology makes it easy to take this model and make it much more personal.

Amazon’s affiliate program, in which Amazon pays users a portion of the book revenue they

generate through referrals, is built around this model.

Go to http://www.permission.com. There, at the bottom of the page, is a link where you can buy a

copy of Permission Marketing. Click on it and it will take you to Barnes & Noble or

Amazon—right to the page on the site that sells Permission Marketing. Both stores give me a

kickback on every sale.

Did I send you to Amazon just because I’m going to get a kickback? Nope. It doesn’t do me

any good to recommend a bookseller where you won’t end up buying the book—I’ll end up

with no kickback and no book sales either. I recommended Amazon because you’re likely to

have one-click shopping already set up, increasing the chances the book will get sold. I also

recommended Barnes & Noble, because their affiliate program is at least as good, and some

of my customers would prefer to shop there. But the kickback still influenced my decision,

and has clearly motivated hundreds of thousands of individuals and businesses to set up links

to their favorite books at Amazon and at Barnes & Noble.

Unleashing the Ideavirus 70 http://www.ideavirus.com

This approach is far less risky than Nike’s. Nike has no idea if the Blue Devils actually sell

shoes. They also have to pay for the endorsement in advance, with no refunds if they’re

wrong.

Amazon and other affiliate marketers, on the other hand, are using the power of the Net to

create a deal with no losers and no downside. You can set up an affiliate link in a few

minutes. For free. If it works, you get paid. If it doesn’t work, you don’t. And it doesn’t cost

Amazon a dime.

Because of this risk model, affiliate programs are flourishing. Be Free, a leading provider of

services to marketers using this approach, calls it Performance Marketing. They currently list

235 websites that are offering affiliate programs.

While it may be interesting to earn a dollar or two on a sale (interesting, that is, if you can

sell thousands a month), some companies are taking a different tack.

Woody Chin, founder of Referrals.com, thinks he’s found a way to change the way people

interact when it comes to job hunts and other sorts of business-to-business commerce.

Instead of paying people a nickel or even a buck, he’s paying people $1,000 to $5,000 each

for that priceless commodity: a referral.

Here’s how job filling works before Referrals.com: Hire a contingency headhunter. Offer to

pay a third of the final salary, but only if you hire someone the headhunter brings along. So

the hunter stands to earn $20,000 or more.

Now, the headhunter hits the phones. She calls everyone she can, and basically begs for leads.

There’s no obvious benefit to the referrer, except for the possible goodwill that occurs when

you find a friend a job.

Woody and Referrals.com are aiming to change that.

With Referrals.com, the hiring manager sends out a description of the job to people she

thinks might know good candidates. These referrers can be people she knows in the industry,

Unleashing the Ideavirus 71 http://www.ideavirus.com

company insiders or super-agents (and anyone can be a super-agent—read on). The key here

is that the referrals are from people whose opinion she values. The description includes a

bounty she is willing to pay for a hire as well as a limit to how deep and how wide a referral

tree she desires.

It’s fascinating to see that Referrals.com is building in a limit to the ideavirus! They don’t

want any given job search to get out of control and start being passed from friend to friend

ad infinitum. Instead, they artificially limit how deep a job search can go into the

community. This limit ensures that employers can focus their searches on a certain hive

without it running amok throughout the entire population. The web has turned what might

have been a multi-level marketing business into a carefully regulated ideavirus.

Anyone who gets involved in referring can sign-up to be a “super-agent.” Once you sign up

as a super-agent, your performance ratings will be available to hiring managers (in recruiting)

looking to find experts to help with their search. And of course, you get first crack at the new

job listings.

Let’s say the company wants a CTO. Let’s say they’re willing to pay $5,000 for a successful

hire. And let’s say they’re only willing to go two levels down the referral tree.

Now, a super-agent can send an email to five people he knows who might be perfect for the

job. If one of them takes the job, the super-agent gets $5,000 just for sending five emails.

But let’s say none of the recipients want the job. But one of them knows someone who does.

Bang. He forwards the mail a second time, and this time it lands on the desk of the perfect

hire. Assuming this guy gets the job, the first super-agent and the second referrer split the

money.

All of a sudden, you’ve monetized word of mouth! Referrals.com could create a class of

thousands of “super-agents” who spend their time doing nothing but finding people through

networking. Essentially, it lets just about anyone become a contingency headhunter. (Now, I

know what you think of contingency headhunters… but the small scale of each person’s tree

makes it unlikely it’ll ever get that bad!)

Unleashing the Ideavirus 72 http://www.ideavirus.com

Of course, it goes deeper than this. If it works for headhunting, maybe it works for finding

new clients for Viant, or for people who are looking to take a cruise. Or what about real

estate? If everyone could become a contingency broker, doesn’t life online get interesting? If

the Internet succeeds when it monetizes previously random analog events (like garage sales at

eBay) then this may just be the killer app for this space.

Does Referrals.com work? I actually have no idea. It’s just launching. We don’t know if the

promiscuous will overwhelm the powerful and pollute the whole system. We don’t know the

velocity of the idea or how long this particular virus will last. But it’s clear that something will

replace the current model of headhunters spamming powerful sneezers and essentially

stealing their rolodex.

Alladvantage.com wanted to take the multi-level marketing approach instead. Each person

they signed up got a commission on the revenue generated by the people those people signed

up. And so on.

They got off to a very hot start, signing up millions of users in a very short period of time.

But now, according to the Wall Street Journal, they’ve discovered that maybe they were

paying these promiscuous sneezers too much to make any money in the end. So Alladvantage

just announced new rules in the way they pay their sneezers.

The result was predictable… their most important sneezers were outraged. When you pay

people to refer on your behalf, you’ve got to expect that they are indeed motivated by

money, and when the money goes, so will your sneezers.

Multi-level marketing has gotten a bad reputation among powerful sneezers. Why? Because

individuals are encouraged to suspend their judgment and embrace the idea that several

generations down the pike, they’ll be rich.

While this is a fine choice for an individual to make, it’s problematic for those who are

friends with this individual. Why? Because the personal interaction is no longer on a level

playing field. Person A uses his friendship with person B to encourage her to buy or use

Unleashing the Ideavirus 73 http://www.ideavirus.com

something that isn’t necessarily in her best interest. If she agrees, then person A sees a

significant return, while person B inevitably sees LESS of a return. If she resists, the

friendship is strained.

If the pyramid is steep enough (if there’s enough money promised at the end of the tunnel),

this sort of approach can work. But it usually leaves scorched earth in its path, and

disappointments in the form of broken friendships or financial promises not reached.

To date, very few companies—online or off—have figured out a way to turn network or

multi-level marketing into a large, sustainable business. Those that have, like Rexall, Amway

and perhaps Alladvantage, now have to work even harder to undo the bad reputation that

this approach has earned.

3. Make it smooth for the powerful.

One of the most elegant ways to take advantage of the new tight networking among

consumers is to identify the powerful members of a hive and make it as easy as possible for

them to tell each other about an ideavirus.

When online content sites first debuted, they were extremely hesitant about sharing their

articles. Some of them went so far as to make it impossible to copy and paste the text in an

article. They were petrified that one person would copy an article and no one else would

come to the site and see the ads.

What they soon learned, however, was that the easier they made it to share, the more likely

people were to tell their friends. And if someone came in to read one article, they were likely

to read more. ZDNet.com was one of the first sites I encountered that used this technique.

In one promotion my former company Yoyodyne did for them, they found that more than

20% of the people exposed to a compelling piece of content actually forwarded it to a friend.

Fast Company magazine—devoted to bootstrapping start-ups—does the same thing. Visit

http://www.fastcompany.com/team/wtaylor.html and you can see a list of the articles that co-

Unleashing the Ideavirus 74 http://www.ideavirus.com

founder Bill Taylor has written for that magazine. They’re all there, unabridged, and you can

read them for free.

But the smooth part of this wannabe ideavirus is the little button on the bottom that says

“Click here to send this page to a friend.” All you have to do is type in their email address

and your email address and—boom—it’s done. If his articles contain ideas that are

virusworthy, the Fast Company site is doing a good job in helping them go viral.

Inside.com, which sells subscriptions to its online media newsletter and website for $200, is

happy to have people send these pricey articles to non-subscribing friends. In fact, there’s a

big “send to a friend” button on the bottom of every article. The reason is obvious. Once

you’ve read one, you might be willing to pay for more. All they need is a few of the ideas

they publish to become viral and suddenly the business of selling subscriptions will get a lot

healthier.

In essence, Inside.com is hoping that its readers will market the site for them, spreading ideas

that might go viral and then bringing in new paying customers as a result.

4. Digitally augment word of mouth.

This is a really interesting way of looking at the fundamental change that’s occurring, and

understanding how word of mouth is different from an ideavirus.

If I was delighted by a movie in the old days, I’d tell a friend or two. My comments would

end up influencing three or four or six people.

There are plenty of books on this topic and marketers have always been enamored by the

potential of word of mouth. Alas, without amplification, it usually peters out.

Today, if I like a movie, I can post my comments on a variety of online movie sites. Or I can

email ten friends (who can each forward the mail to ten friends). Later, when the video

comes out, I can post my review on Amazon, where hundreds or thousands of people might

read it.

Unleashing the Ideavirus 75 http://www.ideavirus.com

Using a service like Epinions.com, I can go online and search out opinions on everything

from BMW motorcycles to summer camps.

What’s neat about digital word of mouth (let’s call it word of mouse) is:

1.

It is extremely persistent. Unlike a comment at the watercooler or over the phone, a

comment in a newsgroup, on Epionions or Amazon lasts forever.

2.

It has much greater velocity. The number of ripples my stone makes when dropped in

the pond of public opinion is far greater online. Why? Because if I tell you I like my car,

it might be months before that sort of car comes up again in conversation. But online,

conversations are happening 24 hours a day, and the “conversation” on any given web

page is precisely about what that page is about. As a result, the number of interactions

multiplies geometrically.

3.

It can have more credibility. At first, the opposite was true. An anonymous stock tip or

other form of online recommendation was totally suspect. The sneezer could be a paid

mole, or worse, someone with horrible taste. But now, thanks to rating systems and the

presence of powerful sneezers, it’s possible to know how congruent your tastes are with

those of the sneezer, so it ends up having a ton of credibility.

Amazon is now rating the reviewers! A visit to

http://www.amazon.com/exec/obidos/tg/cm/member-reviews/-/AFVQZQ8PW0L/102-72353452994554

shows me that Harriet Klausner is the top ranked reviewer on the entire site.

Harriet, a retired librarian, has written more than 500 reviews and has received more than

5,000 votes from other folks who agree with her taste. If Harriet likes a book that you like,

you’re certainly going to give her sneeze some credence in the future.

5. Altruism.

Several years ago, a hot chef in Chicago decided to go out on his own and open his first

restaurant. Realizing how competitive the market was, he did a neat thing. He never opened

it to the public. He refused to accept reservations from strangers.

Unleashing the Ideavirus 76 http://www.ideavirus.com

If you wanted to get into Les Nomades, you had to be a member. And how did you do that?

Well, the first 500 people were given memberships because the chef knew them as regular

customers at his old job, and he personally invited them.

Then he told each member that they were welcome to sponsor other members. All they had

to do was vouch for someone and he’d make them a member too.

So, what’s in it for the member to nominate someone else? Simple. They scored points with

their friends as powerful sneezers because they could “get you in” to the hottest restaurant in

town.

Of course, this wouldn’t have worked if the restaurant hadn’t been spectacular. But it was.

And it was exclusive. But by allowing his members to do his marketing for him, by giving

them an altruistic tool that increased their power as professional sneezers, the chef was able to

get out of the way and let his customers sell for him.

Unleashing the Ideavirus 77 http://www.ideavirus.com

SECTION THREE: The Ideavirus Formula

STEAL THIS IDEA!

Here’s what you can do to spread the word about Unleashing the Ideavirus:

1. Send this file to a friend (it’s sort of big, so ask first).

2. Send them a link to http://www.ideavirus.com so they can download it themselves.

3. Visit http://www.fastcompany.com/ideavirus to read the Fast Company article.

4. Buy a copy of the hardcover book at

http://www.amazon.com/exec/obidos/ASIN/0970309902/permissionmarket.

5. Print out as many copies as you like.

Unleashing the Ideavirus 78 http://www.ideavirus.com

Managing Digitally-Augmented Word Of Mouth

That’s what I would have called this book if it had been published by the Harvard Business

Review. And you probably wouldn’t be reading it now! Words matter. Understanding

exactly what we’re talking about makes it far easier to actually do something about the world

around us. That’s why I take such great pains to invent new words and get us all thinking

about exactly what they mean.

If we bump into each other at some convention and you ask me to talk about your business,

I’ll instantly start using words like hive and sneezer and velocity and smoothness. Why?

Because these shorthand phrases make it easy for us to communicate. By using words that

indicate we both understand the underlying factors that leverage an ideavirus, we’re far

likelier to actually get something done.

The ideavirus formula has eight co-efficients. Each one represents not just a concept, but a

variable that you can tweak to make your product or service more viral, to create the

elements you need to drive your idea into the community.

Unleashing the Ideavirus 79 http://www.ideavirus.com

Tweak The Formula And Make It Work

It may be possible to write down the key elements of building and spreading a virus as a

mathematical formula. No, I don’t think you’ll use it. But understanding the co-efficients

makes it far easier to see what’s important and what’s not. They also help you see the wide

range of factors that can help an idea go viral; focusing on the most highly leveraged factor

for your idea is a first step in launching the virus.

Multiply these five factors:

[reputation benefit to powerful sneezer of recommending virus]

[selfish benefit to promiscuous sneezer of recommending virus]

[smoothness of sharing the virus with a friend]

[power of the amplifier used to spread positive word of mouth]

[frequency of interactions among hive members]

Divided by the sum of these two factors:

[number of times you need to expose someone in this hive in order for the virus to catch]

[number of different sneezers who have to recommend a virus to a given individual for it to

ignite]

And then multiply that by the product of these four factors:

[percentage of infected hive members likely to sneeze]

[number of people the infected sneezer is likely to contact]

[persistence of the virus (how long does a sneezer sneeze?)]

[number of people infected /(divided by) number of people in the hive]

Comments on each component:

[reputation benefit to powerful sneezer of recommending virus]

Powerful sneezers can’t be bought. But don’t forget that they are selfishly motivated. Will

this make me look smart? Will it make someone else happy? Will it make the world a better

place? There are plenty of levers that motivate powerful sneezers to spread the word, and they

are often complicated and subtle. Some of our favorite powerful sneezers: Zagats, Linus

Unleashing the Ideavirus 80 http://www.ideavirus.com

Torvald, Paul Newman, Ruth Reichl, Randall Rothenberg, Andy Hertzfeld, Chuck Close,

Spike Lee, Bill Taylor, Don Peppers, Peter Mayles, Alan Greenspan and Yo-Yo Ma. You may

not know all of these names, and there are plenty of hive-based sneezers I’ve never heard of,

but what they all have in common is that they’re perceived as insightful and altruistic. Once

people think they can be bought off, their power plummets.

[selfish benefit to promiscuous sneezer of recommending virus]

As we saw in the Amazon affiliate example, if you can make the benefit to the individual

both significant and easy to achieve, people will respond to it. Amazon signed up hundreds

of thousands of affiliates with a simple offer (get a percentage kickback on everything you

recommend) and backed it up with a two-minute procedure for qualifying and actually

getting started.

[smoothness of sharing the virus with a friend]

Once I want to tell someone about your idea, how do I do it? If it’s got a dumb, hard-to-say

name, or an embarrassing implication, I’ll probably pass. On the other hand, Hotmail is

smooth indeed, because every time I send email I’m talking about the idea.

The Polaroid camera used this smoothness brilliantly. After all, the only reason to take a

picture is to show it to other people, and if you can make the showing (and the waiting) turn

into a discussion of the idea, so much the better.

The beauty of Vindigo is similar. In order to tell you about Vindigo, I’m going to pull my

Palm out of my pocket and show it to you. But once I show it to you, I’m only one button

away from actually giving it to you. The thing I want to show you is how easy it is to give

you, so the virus self-reinforces.

Ideally, you’ll figure out not only what a sneezer should say to someone when they talk about

your idea, you’ll also make it easy and automatic for them to do so.

[power of the amplifier used to spread positive word of mouth]

The mother of a friend of mine was runner up for Miss America in the early 1960s. I think

she lost to Anita Bryant. Alas, coming in second did very little for her career. Anita, on the

Unleashing the Ideavirus 81 http://www.ideavirus.com

other hand, made her fortune squeezing oranges. Point is that once she conquered that hive

of a few judges, the news was amplified far and wide. And the amplification (as per Zipf’s

law) gave her the foundation to create a career.

A challenge in tailoring your ideavirus is to make sure that when you do conquer an

individual or dominate a hive, the good news is amplified as far as possible, preferably at no

cost to you.

[frequency of interactions among hive members]

Some hives (like teenage girls) interact with each other far more frequently (and with much

more intensity) than others—like senior citizens. By understanding the frequency of hive

interaction and then trying to focus on moments of high interactivity, you can dramatically

increase the velocity of a virus.

Trade shows, for example, bring sneezers together for intense periods of information

exchange. By doing something as simple as handing out hats with your logo on them, you

make it more likely that you’ll reinforce your message during this critical time.

[number of times you need to expose someone in this hive in order for the virus to catch]

Some viruses are smooth indeed. See them once and you understand them. It only took one

exposure to the Macarena to get it. In general, the simpler the idea and the lower the risk, the

more likely someone is to get infected. Most of all, though, this variable is driven by how

viral the idea is to begin with. Meaning: is it cool, wonderful, important, dramatically better

and fun?

[number of different sneezers who have to recommend a virus for it to ignite]

Not all ideas have Medusa qualities. We usually need to hear from external sources before

we’re willing to buy into the new thing, especially for risky ideas. Bestseller lists for books

and other products are terrific, as are the sort of seal-of-approval validations that institutional

sneezers look for. “Hey, if it’s good enough for IBM…” say the more timid prospects.

Unleashing the Ideavirus 82 http://www.ideavirus.com

Bestseller lists are a stand-in for the number of recommendations you need to decide. A

bestseller list says, “There are 24,000 other people who liked this idea.” The reviews on

Amazon are another great example of this. When 50 people post a positive review, it counts

for something.

The alternative, which also works, is actually hearing from sneezers one by one. Some ideas

need only one sneezer to get you try it (like a restaurant) while others might need a hundred

(like switching over to using email or a Palm to run your business).

[percentage of infected hive members likely to sneeze]

Some hives are filled with sneezers. And some ideas make people sneeze more than others.

When John McCain tried to capture his party’s presidential nomination, he discovered an

entire population of people, previously dormant, who were so moved by his candor and

campaign finance message that they started sneezing on his behalf. Not accidentally, many of

these sneezers were in the media, carrying his message far and wide.

Another variable is your ability to increase the likelihood that people who don’t usually

sneeze decide that they’ll make an exception just for you. Focus on the time and place of

your introduction to the hive. Want your employees to spread an important new idea among

themselves? Don’t introduce it at the Friday afternoon beer blast, but rather make it a special

event. Give them the tools they need to spread the word. Reward them for doing so, or make

it clear how the virus will dramatically help your company. It’s not an afterthought—it’s the

core of your marketing campaign.

[number of people the infected sneezer is likely to contact]

This is an especially important metric for promiscuous sneezers. Once you’ve converted

people into spreading your message for their own personal gain, how can you incent them to

spread the word to a LOT of their friends? One way to do this is by offering increasing

returns to the sneezer—the more you bring us, the more we give you (but be careful not to

turn sneezers into spammers, who end up proselytizing strangers and causing a backlash).

Referrals.com aims to do this by turning their best sneezers into super-agents, giving them

better information and more money.

Unleashing the Ideavirus 83 http://www.ideavirus.com

The same reasoning is obviously a factor in choosing which members of the media to

contact. Saul Hansell at the New York Times has far more reach and influence than Jason

Snaggs at the Phoenix Register. Seems obvious, but what most marketers miss is the fact that a

very small number of powerful sneezers can have an impact far outside their perceived

influence. A reporter with the right readers could have far more sway over your virus than

someone with plenty of reach but little influence.

[persistence of the virus (how long does a sneezer sneeze?)]

A short-lived experience that leaves no lasting effects is hard to turn into a virus, especially if

it’s not a social event like pop music (does every generation after ours realize just how bad

their pop tunes are?). Tattoos, on the other hand, are extraordinarily persistent, so even

though they’re not very smooth, they continue to infect people for decades, making up what

they lack in impact with sheer stick-to-it-ness.

[number of people infected /(divided by) number of people in the hive]

This is about measuring hive dominance. If just a small percentage of people in your chosen

hive have been infected, you really have your work cut out for you. While you shouldn’t

compromise the essence of your idea in order to get a wide platform, you should be superwary

that you don’t start with too small a sample of too large a hive. It’s very easy for your

virus to fade before it catches on.

Unleashing the Ideavirus 84 http://www.ideavirus.com

Advanced Riffs On The Eight Variables You Can Tweak In Building Your Virus

In this section, we’ll take a look at each of the eight underlying variables in the ideavirus

formula, and try to get a handle on exactly how you can manipulate them for your product.

No two industries rely on the eight fundamental principles in precisely the same way. But

virtually every ideavirus I’ve ever seen uses some of these principles in an extraordinary way,

and just about every one could be improved if it expanded further into the other areas.

The Eight:

1. Sneezers

2. Hive

3. Velocity

4. Vector

5. Medium

6. Smoothness

7. Persistence

8. Amplifier

Unleashing the Ideavirus 85 http://www.ideavirus.com

Sneezers

As described earlier, there are two kinds of sneezers: Powerful and Promiscuous. While all

eight elements of the formula are critical, this is the area where many brand marketers have

the most control, and thus the most influence.

Choose your sneezers—don’t let them choose you. By focusing obsessively on who you’re

choosing to sneeze on your behalf, you build the foundation for your virus.

Powerful sneezers are certainly the most seductive, in that the right word from the right

sneezer can make all the difference to your virus. If David Letterman visits your diner on

television, or the New Yorker writes a twenty-page rave about your website, or if you win a

MacArthur Fellowship Grant, well, you’ve really made it.

Oprah Winfrey is quite possibly the most successful sneezer of our generation. She has

single-handledly turned more than a dozen books into national bestsellers. She has launched

a magazine that already has more than half a million subscribers. She can influence millions

of the most powerful consumers in America, just by uttering a few sentences.

It’s interesting to see how effectively Oprah and her brandmate Martha Stewart have

successfully monetized their position as powerful sneezers. If they trip and get perceived as

promiscuous sneezers, as sneezers for hire, their effectiveness is quite reduced. But if they can

maintain their position at the same time they sell books and magazines or sheets and towels,

they’ve effectively leveraged their fame.

But few of us are that lucky. Most times, you’re going to have to focus on powerful but less

influential sneezers—individuals or organizations that have something to gain by endorsing

your idea but aren’t so out there that they’re tagged as promiscous sneezers.

Some powerful sneezers are very prominent and thus very hard to reach. The challenge for

most marketers is to find the second tier of sneezer—the approachable, interested sneezer

who can do almost as much for you as Oprah or Martha, but with whom you have a far

greater chance of making an impact.

Unleashing the Ideavirus 86 http://www.ideavirus.com

The story of The Bridges of Madison County is a great example of this. Warner Books, the

publisher, realized that most other publishers were doing very little to market to the

independent bookstores, and that if he could court them and give them something to sell

that made them feel special, it would translate into a bestseller.

Of course, as soon as the legions of independent booksellers succeeded in turning Bridges

into a phenomenon, they were assaulted by dozens of other less imaginative publishers, all

trying to rush in and use the same strategy. Too late. It got cluttered. They got busy. No one

else ever repeated the focused, obvious success of this approach.

Remember, an ideavirus adores a vacuum, and Bridges filled that vacuum. As other book

marketers rushed in, no one was able ever again to persuade a critical mass of booksellers to

support just one book.

Does this mean Warner was doomed never to be able to repeat this process again? Is that all

there is—just one new gimmick after another? No! Instead, Warner needed to gain

permission from this critical sneezer audience and use that permission to promote the next

book and the next through a channel they were clever enough to build.

Unleashing the Ideavirus 87 http://www.ideavirus.com

Hive

Winning with an ideavirus begins with the choice of hive. And this choice is so important,

I’d suggest the following: choose your hive first, then build the idea.

Traditionally, marketers start with a problem, or a factory, and go from there. I’ve got a great

widget, and now I need a way to take it to market. Or, we’ve got this excess plant

capacity—let’s find a way to fill it. But that’s not what works today. Choose your market by

identifying a hive that has a problem and has the right concentration of sneezers, the right

amplified networking, the right high velocity of communication and, most of all, an

appropriate vacuum.

Success will come to marketers who attack small but intimate hives. Yes, Yahoo! and eBay hit

huge home runs, but they’re remarkable precisely because success across such a large hive is

rare indeed. We can learn a more relevant lesson from magazines.

Fast Company is one of the fastest-growing (and most profitable) magazines ever. Why? Well

it certainly helps that it’s a great magazine. It also helps that the Internet created a huge

demand for this sort of advertising space. But the real success came in the hive that the

editors selected.

Turns out there are hundreds of thousands of people in mid-sized to large companies who

are eager to do a great job, but feel frustrated at the slow pace and mind-numbing

bureaucracy they face every day. Until Fast Company, the members of this hive didn’t even

know there were others just like them. They didn’t have a tool they could use to reach their

peers.

Fast Company became the identity, the bible, the badge of honor for this new hive. It gave

them a way to communicate, to learn and to have confidence in themselves. By every

measure, the magazine was virusworthy.

Just about every reader of Fast Company became a powerful sneezer. With no compensation

and very little encouragement, they started signing up co-workers for subscriptions, Xeroxing

Unleashing the Ideavirus 88 http://www.ideavirus.com

page after page of the magazine and passing it around the office. The readers even created a

worldwide network of support groups, meeting in cities on a monthly basis, with no help at

all from the magazine.

Fast Company filled a vacuum. It got viral. It enchanted and connected with a huge legion of

powerful sneezers. All because the editors chose the right hive and created a virusworthy

product.

A few years later, Time Warner launched Real Simple magazine, inspired by the significant

sales of books about simple living. So they launched a magazine dedicated to simplifying our

lives. Obviously, it’s aimed at a very different hive than that of Fast Company. Alas, the

magazine is off to a slow start.

Why?

Because this hive isn’t the right one at the right time. Because there’s a real lack of aggressive

powerful sneezers. Because the hive doesn’t have a built-in forum for communicating with

each other (it’s not office-centric like Fast Company). As a result, the magazine is having a

much harder time going viral.

Choosing your hive

The Zagats Guide to New York City Restaurants is a fascinating document. According to

Zagats, the book is put together by 100,000 reviewers, who ate out an average of four times a

week, spending an average of $40 a person. Do the math. That’s more than $8,000 of mostly

after-tax money spent on eating out every year.

This very special hive of people shares a demographic but is by no means typical of the U.S.

population (which in itself is very different from the world at large). Trying to appeal to

everyone is almost sure to fail, for the simple reason that everyone wants something different!

The reason there isn’t one restaurant in Cincinnati or Indianapolis or Tallahassee that’s as

good as the Union Square Café in New York is not that the population can’t afford the tab.

Unleashing the Ideavirus 89 http://www.ideavirus.com

There’s certainly enough money in those towns to keep the seats filled in several restaurants

of this ilk. It’s simply that the hive that can afford these restaurants don’t have a high velocity

way to get the word out fast enough to keep the restaurateur happy. And it’s not clear that

they’d persist. In other words, eating in a New York-style fancy restaurant probably isn’t the

way these “out-of-town” hives choose to spend their time and money. Same’s thing true for a

New York hive that wouldn’t reward a French restaurant that might do just great in Paris.

All of which is a very fancy way of saying, “If the hive doesn’t want it, you picked the wrong

hive.”

Selecting a hive that respects the core value of your virus is a critical first step in laying the

foundation for promoting the idea. College students want something different from

gardeners, who are quite different from computer geeks. Targeting everyone is a sure path to

failure.

Of course, the real reason you want to pick the right hive is not because their values match

the benefits of your product. It’s because when you pick the right hive (and a small enough

hive) you have a chance of overwhelming it—of pumping so much positive juice into your

digital word of mouth that you really do dominate, that so many sneezers are recommending

you to the rest of the hive that the majority surrenders and the entire hive converts.

Once your idea starts coursing through a hive again and again and again, you’ll have a piling

on effect. People will want to be exposed to your idea just because everyone else in the hive

they respect is talking about it.

The mistake that’s so easy to make is to get greedy as you choose your hive, to say, “this

product is for everyone” or “anyone can benefit from this idea.” Well, there are seven billion

people on the planet, so it’s unlikely your comment is correct; even if it is, there’s little

chance that a virus would spread across a hive that big.

Far better to pick smaller hives and conquer them a few at a time. Far better to identify

consumers when they’re grouped in bunches (at a trade show, say, or geographically) and

then allow the concentrated essence of your virus spread to other hives.

Unleashing the Ideavirus 90 http://www.ideavirus.com

Coors did this with beer years ago. You could only get Coors in Colorado, then you could

only get it west of the Mississippi. By concentrating their marketing dollars, they addressed a

smaller hive. This enabled them to get a larger percentage of the hive to sample the product.

This core group then had a smooth way to spread the word, and it quickly conquered one

state after another.

Without any effort from the Coors people, the virus spread to the East Coast. Coors fielded

thousands of requests from disappointed drinkers who wanted to try this new beer they’d

heard about, but couldn’t.

Coors dominated a hive. Then they went national to try to fulfill the demand created when

their hive spread the word. Unfortunately, the new hive was so large, it turned out to be

difficult to satisfy and dominate.

Compare the powerful, nearly effortless spread of their idea with the challenges they face

today. As a national brand in a stagnant market, growth by any method is hard to come by.

They built their company on a unique virus, but they couldn’t continue to grow their

company the same way.

Unleashing the Ideavirus 91 http://www.ideavirus.com

Velocity

Napster is a worldwide file sharing database that lets Internet users share MP3 files. In

essence, you can listen to the digital record collection of millions of other people. The idea

behind Napster turned into a virus and grew like crazy. Why?

They hit college campuses—a hotbed of communication. A virus can spread across a campus

in a matter of hours. When a dear friend of mine went to Tufts in the late 1970s his

roommate started a rumor that Paul McCartney had died (this was before John Lennon’s

tragic death—they weren’t that callous). Within an hour, they started hearing the rumor

back—from friends of friends of friends who couldn’t precisely remember where or how

they’d heard it.

Napster was spread the same way. How? Because in addition to being on a college campus,

Napster lives on the Internet. So, instead of being word of mouth as in the Paul McCartney

example, it was digitally augmented word of mouth. On college campuses, everyone has

email, and email is both instantaneous and amplified. You can send an email to thirty or

forty friends as easily as you can write to one. So once a powerful sneezer had tried the

software and confirmed that it worked as advertised, the word spread fast.

Why is velocity so important? Remember, filling a vacuum is far easier than going second. If

the velocity of a virus isn’t fast enough, a competitor may leapfrog past you into a new hive

before you can get there, dominating as the “original” in that market.

This happened with beer, in which regional favorites have long survived the introduction of

nationwide refrigerated delivery. It even happened with the college entrance exams, in which

the ACT is favored in the Midwest, years after the SAT became the standard almost

everywhere else in the world. The only reason this happened is that the ACT got to the

Midwest first.

How does the Net change our economy so dramatically? Because it dramatically increases the

velocity of viruses in various hives. Where it used to take weeks or months for a contractor to

Unleashing the Ideavirus 92 http://www.ideavirus.com

talk with suppliers before building an office tower, he can now do it in just a day using the

Net.

This increase in velocity fundamentally changes the dynamic of a virus. Something

newsworthy might have 20 or 30 or 100 cycles of communications before the issue itself

becomes boring. In the days before the Net, if each cycle only touched one or two or three

people, the virus would die before it got old. Today, these cycles allow the virus to mutate

and evolve as it touches millions of people.

Unleashing the Ideavirus 93 http://www.ideavirus.com

Vector

Richard Dawkins, a brilliant evolutionary theorist, had his own word for the phenomenon

I’m calling ideaviruses: memes. He pointed out that a meme was like a living organism,

surviving not in the real world, but in our world of ideas.

Like a real organism, memes could live and die, and more important, they could evolve.

Every time a meme is passed from person to person, it gets touched, changed

and—sometimes—improved.

Once a meme has been passed around enough, it ceases to evolve as quickly and just becomes

a building block for future memes. Pop singers are experts at stringing together memes and

turning them into concise snapshots of our lives. (Paul Simon is a favorite—Graceland,

Kodachrome, the pop charts… you get the idea).

One of the behaviors noticed by Dawkins and practiced by anyone who markets with

ideaviruses is that memes follow a vector. An idea doesn’t spread evenly and nicely through a

population. Instead, people are more likely to send it in one direction instead of another.

At college, there was always someone who knew where the good parties were (and which

ones to avoid). In your town, there’s someone who just seems to have the inside buzz on

which restaurants are hot. On the Internet, some people seem to be on the vector of the

latest email joke, while others—even in the same company or the same cliques—just don’t

seem to get touched as often.

When you create an idea and lay the groundwork for it to become a virus, it pays to study

the vector you’d like it to follow. Why? Because there’s plenty you can do to influence its

vector, and the vector you choose will have a lot to do with who “gets” the virus. The vector

controls the hives through which the idea flows.

If you’re on the Net, for example, the barriers you erect will influence your vector. If your

site needs Shockwave and Flash and a high-bandwidth connection, you’re not likely to vector

straight into the heart of the AOL user universe, regardless of where you start. If your goal is

Unleashing the Ideavirus 94 http://www.ideavirus.com

to create a trading card mania among third graders, launching a series of cards available only

at liquor stores isn’t going to enhance the vector, even if you seed the virus by handing the

cards out at the local elementary school.

But this is about more than simple access. Remember, the goal is to market to people and

then get out of the way. So an email joke (which almost anyone with a job in this country

could access at home, at work or at the library) will still find its vector. How? There are three

factors:

1.

Who it starts with. Often, the way we decide which direction to send an idea is based on

where it came from. It’s hard, for example, to bring home a joke from the office. Instead,

we’re more likely to send it straight back into the quadrant of life from which it came.

2.

Who it resonates with . An idea has to have impact to be worth sharing at all, and we’re

much more likely to share that idea with someone whom we believe it will impact as

well. After all, if we spread ideas that don’t go viral, it hurts our reputation as powerful

sneezers. This encompasses the idea of access… I’m not likely to spread an idea if the

recipient doesn’t have the energy or the technology or the resources to get engaged with

it.

3.

What’s easy. The medium drives the spread of ideas more than you might imagine. If I

have to print something out, put it in an envelope and mail it to someone, that virus is

going to stop right there. That’s why TV and the Internet have proven to be such

powerful media for the spread of viruses—they’re easy.

Unleashing the Ideavirus 95 http://www.ideavirus.com

Medium

Scientists wasted hundreds of years looking for the medium by which light traveled. They

knew it was making it through the vacuum of space, through water and through air, but

without a medium, they couldn’t figure out how it worked.

The medium is probably the most overlooked part of ideavirus planning and construction.

It’s so obvious, we often don’t see it.

In Japan, teenage schoolgirls started and built a craze to billion-dollar proportions. They

continue to line up to use a special kind of photo booth. Here’s how it works: You enter the

photo booth (similar to the old Polaroid ones of our youth), insert a some coins and it takes

your picture.

But, instead of giving you four shots on a strip, it prints out 16 little tiny one-square-inch

images on stickers.

Now, what are you going to do with 16 pictures of yourself on stickers? Obvious—share

them with your friends! As a result, every popular Japanese schoolgirl has an autograph book

loaded with dozens or hundreds of these stickers. Sort of like your high school yearbook

signing ceremony, but on steroids.

A friend of mine, Sam Attenberg, developed and patented this technology in the States. And

while it never became a full-fledged virus in the U.S., it did develop pockets of intense

activity in certain hives. Some machines were turning $70 an hour in sticker business, every

hour on the hour for weeks at a time. In Japan, two companies dominate a multi-billiondollar

industry in Sticker Stations.

So what’s the medium? It’s the person-to-person exchange of stickers. The medium is the key

to the entire virus. Once the first person got the sheet of stickers, the only way she could use

them was by sharing them with 15 friends. But in sharing them, in using the medium

provided, she had to explain where she got them. Boom. Virus spreads.

Unleashing the Ideavirus 96 http://www.ideavirus.com

PayPal.com is another example of an extremely virulent idea that spread because the medium

was so powerful. PayPal.com is an online service that allows customers of eBay—and other

auction site—customers to transfer money online safely and securely. Now, when you pay

for something you buy on eBay, you can just PayPal.com your money to the person.

Here, the medium is the money. People care a lot about money, and since, in this case, it

solves a time-consuming problem (sending checks and waiting for them to clear), it’s

particularly welcome. And, just as we saw in the Sticker Station example, the act of using the

medium causes us to teach others about the idea.

In both cases, a focus on the medium led to the ultimate success of the virus.

Unleashing the Ideavirus 97 http://www.ideavirus.com

SMOOTHNESS: It Would All Be Easy If We Had Gorgons

The goal, of course, is to have an ideavirus so smooth that once someone is exposed to it,

they are instantly hooked. A virus so powerful that all it takes is one guitar lick on the radio,

one phrase in a book review, one glimpse of a website and you completely and totally “get

it.” And not only do you get it, but you want it. Now and forever.

One of the talents of the great Steve Jobs is that he knows how to design Medusa-like

products. While every Macintosh model has had flaws (some more than others), most of

them have had a sexiness and a design sensibility that has turned many consumers into

instant converts. Macintosh owners upgrade far more often than most computer users for

precisely this reason. We have to own that new flat panel display. We must have the new

color of iBook.

Vindigo is Medusa-like in the way the virus spreads so smoothly. It only takes one look at a

friend’s Palm in order to get hooked (and one file beaming to get it forever). The Nextel

phone has that power, and so (for some people) does Britney Spears.

Alas, it’s not going to happen for you. While you can aspire to make your product more

Medusa-like, it’s a mistake to spend all your time wishing for it to happen. The odds are long

indeed, especially if your product is not groundbreaking. The longer it takes someone to get

Unleashing the Ideavirus 98 http://www.ideavirus.com

the basic concept behind your idea, the less Medusa-like it is. But often, that’s a good thing.

Real change, and the profit that goes with it, often comes from unsettling ideas that

significantly alter the way people interact with each other and with your company. And those

ideas aren’t as smooth as some others.

Unleashing the Ideavirus 99 http://www.ideavirus.com

Persistence

In our quest for the quick hit, the easy way to start a business or just to increase our power as

sneezers, there’s a real desire for a shallow virus. A joke. A gimmick. A neat new technology

geegaw that won’t be around tomorrow.

Laser pointers are a fine example. I was in a meeting last month where the presenter used a

laser pointer to highlight various things on his deathly boring Powerpoint slides.

Unfortunately for me, not only was the presentation boring, but he kept aiming the laser at

the TV monitor, which reflected this highly focused electromagnetic radiation right at my

face, hitting me in the eye a few times. I finally got him to turn the thing off, but not

without considerable struggle.

Other than this unfortunate incident, I can’t remember how many years ago it was that I saw

someone actually using one of these pointers.

What happened was that the pointer came out, and for a few early adopters, it felt

marvelous. It touched a Jungian need in us (especially men, I think) to have a magic stick

that could project our thoughts on the wall. Of course, the best place to use one was in a

meeting of other nerds. And all the other nerds noticed the laser pointer and a virus was

spread.

But after we all went out and bought laser pointers, we discovered that they weren’t

particularly useful. After all, how much information could one really have to present that we

needed a high-tech device to point out the good stuff from the bad?

So the lasers ended up in a drawer.

In other words, the virus wasn’t persistent. Those who resisted the initial temptation to rush

out and buy a laser pointer stopped being exposed to them, and the virus died off.

Unleashing the Ideavirus 100 http://www.ideavirus.com

Compare this to the Palm virus. Every day, somebody else marches into your office,

declaring their undying love and devotion to his new pocket wonder. And unlike laser

pointers, people who love them keep using them. They persist.

In Gladwell’s terms, the Palm has now tipped in certain hives. So many people are using it so

often that you’re constantly reminded that unless you get one, you’re a loser. It’s the

persistence of the Palm more than any other viral factor that has led to its success.

Unleashing the Ideavirus 101 http://www.ideavirus.com

Amplifier

Word of mouth by itself isn’t enough. As discussed earlier, unamplified word of mouth dies

off too soon to be much good to the average business. The goal of a marketer creating an

ideavirus is to create a system that allows the positive word of mouth to be amplified (and

the negative to be damped!).

This simple idea is behind the success of Planetfeedback.com. It’s impossible for me to

understand why any business invited by Planetfeedback to participate would hesitate for even

a moment before signing up.

If a consumer has a complaint or a compliment about a company, she can go to

Planetfeedback and turn it into a letter to the company. Then, with a click, she can have a

copy of the email go to the relevant congressmen, media and regulatory agencies. Another

click can send a copy of the letter to the consumer’s ten closest friends and co-workers.

Instant amplification.

Now, if your company is the target of a complaint, which course of action makes sense? You

could either proactively grab the opportunity to stamp out a negative virus, to turn the

complainer from an angry reporter of bad news into a now-satisfied witness to how much

your company cares, or you could ignore them and hope they’ll go away. Of course, they

won’t go away. They—and the people already infected—will continue to amplify the

message.

Planetfeedback is providing a great service to all parties involved. By taking previously

invisible word of mouth and aggregating it, they’re making it far easier for companies to

understand the viruses that are already being spread, and they’re giving them an opportunity

to do something about them. And yes, they are viruses—ideas that are running amok, being

passed from person to person. At the same time, Planetfeedback gives consumers far more

power, and makes it easier for them to get attention.

Unleashing the Ideavirus 102 http://www.ideavirus.com

Of course, you don’t have to sponsor Planetfeedback. Some day they may offer a different

program… or your competitors can pay to talk to your unhappy customers instead of you.

Unleashing the Ideavirus 103 http://www.ideavirus.com

SECTION 4: Case Studies and Riffs

STEAL THIS IDEA!

Here’s what you can do to spread the word about Unleashing the Ideavirus:

1. Send this file to a friend (it’s sort of big, so ask first).

2. Send them a link to http://www.ideavirus.com so they can download it themselves.

3. Visit http://www.fastcompany.com/ideavirus to read the Fast Company article.

4. Buy a copy of the hardcover book at

http://www.amazon.com/exec/obidos/ASIN/0970309902/permissionmarket.

5. Print out as many copies as you like.

Unleashing the Ideavirus 104 http://www.ideavirus.com

The Vindigo Case Study

One of the best examples of a company unleashing an ideavirus is Vindigo. You can find

them at vindigo.com on the web, and you’ll need a Palm (or something compatible) to use

the software.

Vindigo is a directory of restaurants, entertainment venues and stores in major U.S. cities.

You download it to your Palm and carry it with you. Tell it where you’re standing (in the

illustration above, you’re on the corner of Amsterdam and Broadway in New York City), and

it will show you whatever sort of restaurant or fun you’re looking for. Sorted by distance

from where you are. With ratings. For free.

What a killer app! I need to tell everyone. This is why they invented handheld computers!

IT’S SO COOL!

But, while that alone is grounds for this to become an ideavirus, as described it doesn’t seem

particularly smooth. After all, after a sneezer tells you about this cool software, you’ve got to

remember the name (vindaloo? indigo?), go home, type it into your browser, download it,

synchronize it, etc. A disaster. No way it’s going to work.

Which is where the smooth part comes in. You see, right on the bottom, underneath the

buttons for eating, shopping and entertainment, is a button that says “give.”

Unleashing the Ideavirus 105 http://www.ideavirus.com

So, when a sneezer is going on and on and on about how cool this is, you just take out your

Palm, they take out their Palm, press the give button and sixty seconds later the entire product

is now on your Palm!

That’s smooth. It’s about as close to perfect smoothness as you can get.

It goes beyond smooth. It’s persistent. The next time you synchronize your Palm with your

PC, it will automatically upload all the ratings you’ve put into the computer and get you an

updated version. Instantly. Automatically.

The ideavirus has stuck.

Is it working? Well, the folks at Vindigo seeded just 100 sneezers with the original version of

the program. Then they spent virtually nothing on advertising and waited to see if the virus

would spread. It’s now the fastest-growing application on the Palm.

Note that this isn’t viral marketing in the sense that Hotmail is. You can happily use Vindigo

for months without mentioning its existence to a friend. Vindigo works really well, but it

also happens to be optimized for spreading the ideavirus.

Unleashing the Ideavirus 106 http://www.ideavirus.com

Saving The World With An Ideavirus

The Prius is a new car from Toyota. And it’s the only car that’s ever won an award from the

Sierra Club. This is the car that’s supposed to save us from ourselves, to take a whack out of

the greenhouse effect and to conserve our remaining fossil fuels.

How? By using an engine that’s a hybrid of gasoline and electricity. By getting more than 90

miles to the gallon, giving very good performance and emitting close to zero pollution. I

dearly hope it succeeds. THIS CAR IS IMPORTANT!

Unfortunately, because Toyota is a factory-based company that uses ideas (instead of being

an idea company that owns factories) they’ve built the product completely backwards. I’m

confident that someday everybody is going to be driving a car as positive for the world as the

Prius, but it won’t be because of the way this car is marketed.

Let’s start with the name. How can you tell someone about a car you’re excited about if you

don’t know how to pronounce it? Is it pry-us, or is it pree-us? I don’t want to feel stupid, so I

just won’t say the name.

Second, is there a smooth way for me to spread the word? A visit to the Toyota website

doesn’t even show the Prius on the home page, and when I search for it, I get a very nice

page. But where’s the “tell a friend” button? How can I set up a test drive? Is there a place for

me to give my email address so I can give permission to get information on when the car is

going to be available in my neighborhood? Alas, no on all three counts.

What about a community activism component with teenagers going door to door with

petitions, hoping to lobby the local government to buy Prius police cars? Or letter-writing

campaigns that spring up from grassroots environmental organizations around the

country…?

Unleashing the Ideavirus 107 http://www.ideavirus.com

But the biggest mistake Toyota made was the way they designed the car. Unlike the VW

Beetle and the Mazda Miata, the Prius is not a driving billboard for itself. Here’s what it

looks like:

You could have 1,000 of these cars drive by and you’d never, ever notice it. You wouldn’t

notice the styling, you wouldn’t notice the gas mileage or the lack of emissions—and you

certainly wouldn’t aspire to own one just by looking at it.

Is Toyota on a mission from God? Are they acting like zealots, aggressively pushing a car that

will change the world for the better, the most powerful idea to come out of the car industry

since Henry Ford perfected the assembly line? We need passion from our manufacturers.

What a lost opportunity! An idea merchant in search of a virus would take a very different

tack. Instead of trying to make it cheap and boring, they’d realize that the first people to buy

a car like this are people with money to risk on an unproven technology. Realize that the

opinion leaders and nerds who are most susceptible to this idea are also the most likely to

want to drive an exceptional car.

I’d redesign the thing to be stunning. Different. Unique. Maybe a permanent bumper sticker

announcing my current gas mileage on an LCD readout. Or a fleet of far-out colors. The

first 50,000 people who buy this car will be doing it to make a statement. And every person

who does will be making that statement to the 1,000 or 10,000 people who see them driving

it. A virus waiting to happen.

Remember what I said about the VW Beetle? 180° difference.

Unleashing the Ideavirus 108 http://www.ideavirus.com

Toyota forgot to pick a vector for this car. They don’t know exactly who they want to buy it,

so they designed it for everyone. Precisely the opposite strategy of the new VW Bug. But

remember, an ideavirus adores a vacuum, and there is a very big and very empty vacuum just

sitting here, waiting to be plucked. Toyota could have picked any vector they wanted,

leading to any hive they chose, and yet they chose none.

And finally, I wouldn’t let just anyone buy the first models off the line. I’d select the very

best sneezers, the loudmouths, the pillars in their community and do whatever it took to get

these folks to drive a car. James Bond? Julia Roberts in her next film? The mayor of Carmel,

California or the head of Greenpeace?

This is urgent. This isn’t about making another few million bucks from a website. It’s about

infecting the population with a good virus, and doing it before the vacuum fills up with junk

and it’s too noisy to communicate about it.

Unleashing the Ideavirus 109 http://www.ideavirus.com

Is UNLEASHING THE IDEAVIRUS An Ideavirus?

Here is the step by step plan I’m using to turn this manifesto into an ideavirus:

1.

Describe something important and cool and neat and useful and new, and do it in

compelling, clear and exciting words.

2.

Launch the virus to the largest audience of sneezers I can find. In this case, that means

the readership of Fast Company. Do it with graphic splash and panache and impact.

3.

Make it smooth. Post the entire manifesto at http://www.ideavirus.com. Include commentary

from big-name authors, pundits and industry professionals. Include the entire text of not

just the manifesto but the entire book. Make it easy to send the book to a friend. Include

an audio version of the book. Include my powerpoint slides. All for free.

4.

Run ads to create an environment in which sneezers feel comfortable spreading the

manifesto to others.

5.

Maintain the virus as it grows by doing speaking engagements and distributing free

copies of the hard-copy version of the manifesto to appropriate sneezers.

Unleashing the Ideavirus 110 http://www.ideavirus.com

Moving Private To Public

One of the challenges facing oldline companies as the ideavirus becomes more important is

that they’re used to providing private services. Your friends and acquaintances probably have

no idea what brand of PC you have, whether you have gas or oil heat, how often you see the

chiropractor or what your favorite kind of wine is.

Because of the private nature of these relationships, the only way to expand the market for

them is for the marketer to spend more money and interrupt more people with more junk

ads. BUT, if they can figure out how to make them public, if they can figure out how to

launch an ideavirus, the whole equation changes.

Here’s an example: your frequent flyer miles.

American Airlines has made a fortune using frequent flyer miles to induce loyalty, and just as

important, to establish a currency that they sell to other companies.

But none of your friends really knows your frequent flyer habits. You almost never talk about

them unless something exceptional happens that you want to brag about… like buying

tickets for the whole family to fly to France with your miles.

There are a number of things that American Airlines can do to move miles out of the closet

and turn them into an ideavirus. For instance, they could allow people to buy, sell or trade

their miles. Would this lead to more mileage redemptions (a bad thing)? Sure. But it would

also turn miles back into a nationwide fascination.

Far more clever would be to make the following announcement at a convention jammed

with business travelers: “If you can find someone at this convention who has precisely the

same number of miles as you do, we’ll give you both a million miles.” Suddenly, every

person you meet wants to talk to you about your mileage status.

Unleashing the Ideavirus 111 http://www.ideavirus.com

Hakuhodo, one of the largest ad agencies in Japan, used a similar approach and turned it

into a national craze. It seems that sending New Year’s cards is a big deal in Japan…much

bigger than Christmas cards.

Most people buy their cards at the post office—envelope and stamp included. When you

send a card, it comes with a lottery ticket, good for a small prize if the recipient wins (a

bicycle, a radio, etc.).

Hakuhodo runs their promotion on the Net. And the cards are free to send (no stamps, no

fee). But the best part is that if the person you’re writing to wins, you win the same prize. So,

the more you send, the happier your friends are, and of course, the happier you are.

Not only did this promotion go viral, it turned into an epidemic. In 1998, 25% of the

people with Net access in Japan either sent or received one of Hakuhodo’s cards. And

Hakuhodo cashed out by selling ads in each and every one of those cards.

In order to turn these public ideaviruses into useful, long-term assets, the companies that

create them need to gain permission from people to follow up directly. Then, they go back to

private marketing, at a very low cost, with excellent results, until they’re ready to go public

again with another virus.

Of course, going public doesn’t mean you have to run a selfishly oriented promotion. When

I was in college, the gay and lesbian center ran a campus-wide activity called “Wear jeans on

Wednesday if you’re gay.” Suddenly, something that had been a private topic was now the

topic of discussion among everyone. If you weren’t wearing jeans, was that because you were

afraid that people thought you were gay? Is there something wrong with being seen as gay,

whether you were or not?

One simple act turned the notion of sexual preference into an ideavirus and generated

thousands of hours of intense discussions about how society (and how we) viewed the issue.

Unleashing the Ideavirus 112 http://www.ideavirus.com

YouÕre In The Fashion Business!

Without question, the most difficult part of unleashing a manifesto is creating something

that’s virusworthy. And one of the key components of that art is understanding the fashion

moment.

Why do open-toed shoes come and go? Bell-bottoms? Miniskirts?

How is it that every year, multiple clothing designers launch very similar clothes, without

consulting with each other in advance?

Source: Corbis

Why is it that we rarely see people dressed like the two women above? Did these folks wake

up one morning and go out and buy the entire outfit at once, or did it happen gradually?

Why do some Internet businesses (group scheduling, free email, health portals) seem to

appear simultaneously, even though it took them months or years to launch?

Unleashing the Ideavirus 113 http://www.ideavirus.com

The fashion moment occurs when a respected hive member takes a chance and tries out

something new.

One of two things occurs when a hive member shows up with a new “outfit”:

1.

The hive embraces the new. They start wearing a nose ring or get a tatoo or switch from

using a Filofax to using a Palm. When this occurs, the respected member gets MORE

respect, becomes more influential and reinforces his position as a powerful sneezer.

2.

The hive rejects the new. Many times, the person who introduces the new item will be

ignored or ridiculed (this happens more to the less-respected members of the hive, but it

happens to everyone sooner or later). When this happens, the person who tried to

introduce the new fashion loses respect, becomes less influential and is usually less likely

to try again in the near future.

Obviously, respected members are hesitant to lose their positions of influence, hence the

consistency and uniformity among hives.

Some hives are incredibly conservative (go to the Assocation of American Actuaries annual

meeting and you won’t see an awful lot of surprising new innovation), while others are

known for their daring (the trends demonstrated on the New York City nightclub scene

oscillate like the NASDAQ).

Some people—I call them fashion editors—seem to have an innate sense for knowing when a

hive is ready to adopt a new virus. Successful venture capitalists, journalists, chefs, research

and development labs and record label executives are great fashion editors.

Clive Davis at Arista Records was a stellar fashion editor in the music business for

generations. He launched dozens of breakthrough acts… from Aretha Franklin to Whitney

Houston, Carlos Santana to Patti Smith. The only thing they had in common was that they

were just right for their time. A month earlier or a month later and they might never have

succeeded. (Well, maybe Aretha would have succeeded no matter what…)

But no fashion editor is infallible, and if they’re not careful, they fall into one of two traps:

Unleashing the Ideavirus 114 http://www.ideavirus.com

They lose touch with the hive and fall in love with their own taste. Without the feedback loop

the hive provides, they “lose their touch.” Someone who had a seemingly hot hand starts

failing.

Warren Buffet is a brilliant stock market investor with an extraordinary ability to understand

what other people are going to want to invest in. But when Internet mania started to hit the

stock market, Buffet lost his ability to predict what the hive would predict. I think he DID

know, but overruled his sense of what would happen with his own common sense. Buffet left

billions of dollars of profit on the table because he refused to believe that the Internet stock

ideavirus would spread across the hive of investors.

They stop thinking of themselves as fashion editors and start to believe that they are fashion

makers. Rather than acting like someone who has a sense as to what virus will hit the hive

next, they believe that they are respected enough by the hive to FORCE them to accept the

next virus.

Fashion designers are famous for this, as are rock groups, authors and product marketers.

Take a look at New Coke—the biggest flaw in the introduction of this product was that

Coke believed that if they willed the consumer to adopt a new formula, the consumer would

do as they were told. Instead of spreading like a virus from a respected hive member, they

tried to ram the formula for New Coke on the hive. The hive rejected it.

The challenge your business faces is finding or training a fashion editor. Launching products

too early is just as bad as launching them too late—if you miss the timing, you fail to fill the

vacuum with your virus. Miss the timing and the profit belongs to someone with better

timing and better fashion sense than you.

To those dedicated to the idea that your business is a factory, all this must sound like heresy.

After all, if you wanted to go into the fashion business, you’d have gone into the fashion

business! But, like it or not, we’re all in the fashion business.

Unleashing the Ideavirus 115 http://www.ideavirus.com

A few years ago, there was plenty of cherry wood to go around. People weren’t making much

furniture out of it… it wasn’t in style. Then a furniture designer named Thomas Moser

decided that his fashion sense was telling him that cherry wood would make a comeback.

That once people saw how beautiful the wood was, the idea of furnishing your house in this

warm, comfortable wood would spread through his chosen hive.

Moser built an entire company around cherry wood furniture, and bought thousands of acres

of prime cherry in anticipation of demand. Today, Thomas Moser has grown more than

30% a year for the last ten years, with showrooms in New York and overseas selling $5,000

tables and $3,000 chairs. Not because the furniture is great (which it is) but because he

created a fashion that resonated with his hive, because he launched an ideavirus.

Unleashing the Ideavirus 116 http://www.ideavirus.com

The Money Paradox

The sooner you ask for money, the less you’ll make.

The single biggest mistake idea merchants make is that they ask for money too soon. On one

hand, you want to charge early and often, so you don’t waste time on people who are just

looking, and so you can maximize your income before your idea fades. “Take the money and

run” is a cliché for a reason.

But this strategy introduces friction into the system. Many marketers require people to pay

the most when they know the least. For example, why don’t movie studios run a day of free

sneak previews to get the virus started, and then charge more once everyone wants to see the

movie? Today, if you want to taste a new movie, you’ve got to pay $8 for the privilege.

On the Internet, dozens of new businesses have discovered how important this model is. A

company called eFax offers a service that lets you get faxes delivered to your email box. They

launched it as a totally free service. Why? Because it’s scary enough to be one of the first

people to try something as flaky as eliminating your fax machine. And it’s even scarier to pay

money for the privilege as well…

So eFax has a plan: get people hooked on a free system. Build an ideavirus. Then upgrade

people to a paid system that offers all sorts of extras.

1. Fill the vacuum

2. Achieve lock-in

3. Extract revenue

They can fill the vacuum by getting in first and furious and spreading the virus. They can

achieve lock-in by making it hard for people to switch to a competitor (what a hassle to keep

changing your fax number!). And finally, they can extract revenue by offering value-added

services or selling advertising.

In that order!

Unleashing the Ideavirus 117 http://www.ideavirus.com

Will eFax be guaranteed an easy upgrade path to paying customers? I have no idea. Some

businesses (like email) will be stuck at FREE forever, thus making the whole journey hard to

justify. In this case, they could offer free faxes with an eight-hour delay before you get them,

but for $5 a month, you get the faxes instantly. So it’s free for me to try out, free to spread,

but profitable after lock-in is achieved.

The challenge, of course, is to figure out which businesses have a payoff at the end. The

challenge is also to be patient enough to wait, to introduce the friction of charging at just the

right moment.

Watts Wacker catapulted his career by writing The 500 Year Delta. After the book came out,

people started to hand it around, to embrace his ideas. This led to larger audiences and a

dramatic increase in bookings for speaking engagements. In a few months, I’m confident he

made more in speaking fees than he had from royalties on the book. By letting the ideavirus

grow before trying to extract much profit, he was able to make more money in the end.

In very transparent markets like the Internet, the fear is that all ideaviruses will be so

competitive that you’ll never be able to extract money. That’s why the race to fill the vacuum

is so intense. If you can fill the vacuum aggressively and permanently, it is far easier to extract

money.

Unleashing the Ideavirus 118 http://www.ideavirus.com

Think Like A Music Executive (Sometimes)

There are plenty of lessons you can learn about viruses from folks in the music industry

(current behavior notwithstanding, but more on that later).

First, industry executives realize that nobody buys a CD because they like the quality of the

polycarbonate disc. If you don’t like the idea of the music, you’re not going to buy it.

Second, they realize that making money later is way more important than making money

now. They learned this the hard way. Consider radio for a second. Before radio, music sales

were tiny. Why would you buy a song for your Victrola if you’d never heard it before? How

could you know if it was any good?

At first, radio might seem like a threat to the recorded music industry. After all, they play the

ENTIRE song, not just a few notes. And if it’s a hit song, you can hear it night and day on

the radio every few minutes if you’re so inclined.

For a while, the music business fought the idea of radio stations playing songs for little or no

compensation. Then, in the 1950s, they realized how valuable airplay was—so valuable that

a congressional inquiry discovered that music labels were bribing disk jockeys to play their

records.

Fast forward a few decades to MTV. Once again, the music labels balked at supporting

MTV’s insistence that they provide expensively produced music videos—for free! It took a

year or two for them to discover that MTV made hits—that giving away the music for free

turned out to be the best way to sell the music.

Music execs know that you’ll pay nothing to hear a song on the radio, but if you like it,

you’ll gladly pay $15 for the CD. And that if you love the CD, you’re more likely to pay $40

for tickets to the local concert, where you might be converted to a raving sneezer, much more

likely to infect your friends and neighbors with raves about the band, the song, even the

souvenirs!

Unleashing the Ideavirus 119 http://www.ideavirus.com

For some reason, history is repeating itself. Rather than embracing Napster, the software that

lets millions of people listen to each other’s CD collections, music moguls, fronted by the

hard rock band Metallica, are once again complaining about the free distribution model.

Even if the record companies are able to beat Napster in court (a likely outcome) it won’t

matter. There are already dozens of technologies (like gnutella) waiting to take its place, and

each will be harder to stamp out than the one before.

Patience! Instead of hassling Napster, they ought to figure out how to license Napster and

the others, probably in exchange for intensive promotion of their hottest acts. Why not let

me subscribe to my favorite bands, paying for live performances or attending private concerts

or buying T-shirts. I’m certain that if the Grateful Dead were still around, their primary

income source would be souvenirs, followed closely by live concerts. Is that what the record

companies want? Doesn’t matter. It’s what the network is going to deliver, regardless of how

they feel.

Is the CD going to disappear? Absolutely, regardless of what happens to Napster. What will

determine the future of the record business is whether music execs are able to redefine their

jobs around what happens after they ignite a virus over Napster or its successor.

Unleashing the Ideavirus 120 http://www.ideavirus.com

Is That Your Final Answer?

When a sneezer is ready to spread your ideavirus, what should he say?

It sounds like a simple, almost silly question, but it goes to the core of how smooth you can

make your virus. If you give sneezers easy-to-follow, effective instructions, they’re likely to

follow them, because, after all, their goal is to spread the virus.

On “Who Wants to Be a Millionaire?” the producers insist that Regis Philbin repeat the

catchphrase, “Is that your final answer?” almost to distraction. But now it’s become a

powerful, smooth tool for sneezers who want to spread the virus. I must have heard the

phrase fifty times and read it in dozens of newspaper columns before I saw the show for the

first time.

By giving loyal watchers a five-word catchphrase, the producers created (intentionally or not)

a powerful shorthand for referencing the show. Hotmail did the same thing with the sig file

in the free email each person sent. Right there at the bottom of each email, with no

additional work on the part of the sneezer, were specific instructions on how to get Hotmail.

Buffalo Springfield and the Beatles did the same thing with some of their songs. It took just a

few notes—an investment by the listener of seconds, not minutes—for them to expose their

“idea” to a new listener. By working so hard on the first chords of the song, pop music

producers (and Beethoven for that matter) made their products far smoother. It’s easier to

share the song when you can hum the riff.

For most ideas, the web can be a powerful tool to help with this. What might a website for

sneezers look like?

The first touch, the first impression and first visit, must go beautifully. It’s got to be fast.

It should contain exactly what you’ve tested and discovered that most effectively captures the

attention of the first time-visitor. You’re in control in this moment, and you can make it

work or not.

Unleashing the Ideavirus 121 http://www.ideavirus.com

The site should also be filled with tools that make it really easy for a visitor to become a

sneezer. Get out of the way. Give the sneezer something to share. Do like Tom Peters (at

http://www.tompeters.com) and include all your Powerpoint slides. Don’t require registration or

permission at this stage. Let them in, sell them on the idea, then give them the (free) tools to

share.

Unleashing the Ideavirus 122 http://www.ideavirus.com

A Dozen ideaviruses Worth Thinking About

Company Big idea How you spread the virus (the

medium)

Polaroid Instant photography “HEY! Look at this,” you say at

the party.

Tupperware The best food storage devices Get your friends to sell their

friends—multi-level marketing

Fax machine Documents delivered by phone The more you sell to your

business associates, the better

your machine works.

Home Shopping Network Shopping via cable TV “Hey Madge! Look what’s on

Home Shopping,” you say to

your friends on the phone.

Fast Company Journal of the new economy Company of Friends—monthly

meetings of local fans of the

magazine.

CarmineÕs Restaurant Tons of food, tons of garlic Six-person minimum for

reservations—you need to sell

your friends to get in.

Beany Babies Collectible teddy bears If other people start collecting,

your collection increases in

value.

Gamesville Super sticky games on the web Word of mouse—email your

friends and invite them over.

Hotmail Free email Totally viral…every mail you

send promotes it.

Tommy Hilfiger Urban preppy chic Logo virus—the more you wear

the logo, the more people see it.

ÒThe Cathedral and the

BazaarÓ

Open source programming

works

Enabling powerful web sneezers

to spread the word by giving

them a powerful manifesto they

can share.

Vindigo Zagats on my Palm “Give it to me,” and a friend

can beam it over in seconds.

Unleashing the Ideavirus 123 http://www.ideavirus.com

Why I Love Bestseller Lists

One of the critical moments in the spread of an ideavirus is the question the consumer asks

before diving in: “Is it worth my time/money?”

Of course, your recommendation is important to me. Of course, I want to look as good as

you, be as smart as you, have as much fun as you. But I also care desperately about everyone

else’s opinion. After all, none of us is as smart as all of us!

The most common way this popularity is reinforced is that the user will hear about a new

ideavirus from more than one person. Usually, we hear about something first from a

promiscuous sneezer, someone who has some sort of benefit from making the

recommendation, or at the least, someone who’s always recommending stuff. We all know

somebody who eats out every night or listens to every CD or is into whatever bizarre

conspiracy theory has gripped insomniacs this week.

But then, sometimes we hear about the same ideavirus from someone else. And then another

person. Finally, we realize that something is really going on, and we investigate.

In the real world, these reinforcements are usually caused by sightings or physical

interactions. Riding through the New York subway last year, I encountered a kid wearing

what appeared to be a black stocking on his head. But along the hem were the words,

“Tommy Hilfilger.” It seemed like an odd affectation and I let it go.

A week later, I saw four more Hilfiger skull caps. In the week after that, a dozen. If I were in

search of genuine urban chic, I certainly would have bought one at that point, if only to

protect my trademark bald pate from the winter chill.

The same thing happened with the VW Beetle. First there was one in my neighborhood (a

yellow one) and then a few, and then a dozen. With all these reinforcements, I assumed that

it was now a safe thing to consider, and went to the dealer to have a look for myself.

Unleashing the Ideavirus 124 http://www.ideavirus.com

Online, the rules are very different. There is no physical world to bump into. Instead (and

even better for the statistician in each of us), there are actual digital counters and accurate, up

to the minute bestseller lists. No guessing. No inferences. The real scoop.

Amazon.com has a bestseller list more than a million titles long. Visit any title and you can

see where it stands compared to every single other title in the world. Wow. Now we instantly

understand what’s hot and what’s not.

MP3.com has done the same thing with music. As a track gets played more and more often,

it moves up their digital bestseller list. And yes, Zipf’s law works here too—the topmost

tunes are downloaded far often more than those just below them.

We use the same math when we look at the MediaMetrix list of the most visited websites, or

Variety’s tally of the weekly box office numbers (some people saw “Titanic” just because it

seemed that everyone else was). Various organizations also track bestselling cars, bestselling

vodka and highest-paid executives.

One of the best ways to facilitate adoption of your ideavirus is to find a bestseller list that

makes sense and then dominate it. If that’s impossible, figure out how to create your own

bestseller list and popularize that!

This isn’t just conjecture. A breakthrough paper by Stanford Business School professor Kirk

Hanson demonstrated this in a really profound way. His team artificially boosted the

bestseller status of files for download on the web (they downloaded one file over and over

again, increasing the counter of how often it had been downloaded). The result? Heavily

downloaded files get downloaded more often! Nothing was changed but the counter, but

users were more interested in seeing the most popular files. Simple, but true.

Want to launch a new drink using your company’s chi-chi liquer? Why not identify the right

bar, frequented by powerful sneezers in the hive you’re targeting. Then pay the bar to post a

“bestselling drinks list.” Now, bribe enough folks to go in and buy themselves a drink. Soon,

you’ll see your drink climbing the bestselling drinks list, and this alone ought to be enough

to get other—less easily bribed drinkers—to give it a try.

Unleashing the Ideavirus 125 http://www.ideavirus.com

Of course, sampling doesn’t always lead to the spreading of a virus, but without sampling,

you’ve got no chance, do you?

Unleashing the Ideavirus 126 http://www.ideavirus.com

How A Parody Of Star Wars Outsold Star Wars

According to USA Today, a parody called George Lucas In Love is currently outselling the

new Star Wars movie on video on Amazon. How is this possible? How can mighty

Twentieth Century Fox be beat by a nine-minute, $8 handmade film?

Because the parody is an ideavirus. And because the medium of the Net is the perfect place

for the word to spread.

In the old days, if you made a movie, you needed movie theaters across the country to show

it. That’s way outside the reach of an entrepreneur, regardless of how clever his movie is.

Videotape leveled the playing field a bit (Blockbuster can carry hundreds or thousands of

titles) but it’s still very difficult, time-consuming and expensive to force your way into

nationwide distribution.

But Amazon is a different story. Amazon prides itself on carrying just about everything. Since

they don’t have to carry much inventory, Amazon doesn’t take much of a risk by listing a

title. And the entrepreneur can certainly find his tape listed along with the thousands of

others available.

Unleashing the Ideavirus 127 http://www.ideavirus.com

So distribution is the easy part. But how to spread the idea?

Well, the parody fills a vacuum. In this case, the vacuum was “funny and interesting news

about Star Wars.” Certainly, the launch of the videotape was a yawner, the mania about the

film version having largely subsided. Would many people buy the video for their libraries?

No doubt. But it wasn’t news.

But now, here’s an email telling me that someone has seen the funniest little video. It’s

hysterical, my friend says. So I click on over to Amazon (using his affiliate link, I notice—he

may be a powerful sneezer, but he’s also making a profit on this virus). There, I note more

than 100 reviews, all of them positive. I see that it’s a bestseller. I realize that there’s almost

no risk here, certainly worth ten bucks and a few minutes of my time. I buy it.

And after I see it, I’ll tell five friends. This time using my affiliate relationship.

A classic ideavirus. Yes, it would have grown faster if the filmmaker had just put the video

online for free, but he was stuck in the mindset of making money now. Yes, the charge and

the wait for shipping definitely slowed the virus down, but at the same time, it was a nice

balancing act—a slightly slower virus in exchange for tens of thousands of dollars (and

probably a contract for a real movie from a studio).

If it were me, I probably would have posted a low-resolution excerpt of some of the funny

parts online… it’s going to happen anyway, so the filmmaker might as well do it and thus

control what the sneezers say while also increasing the velocity of the virus.

Unleashing the Ideavirus 128 http://www.ideavirus.com

Wassup?

I first heard about the Superfriends parody in an email. Apparently, some clever animator

had taken the soundtrack of the ubiquitous Budweiser commercial and replaced the video

portion with Batman, Superman and Aquaman hamming it up and having a few brews.

Clicking on a link (pretty smooth transition from interest to exposure, you’ll notice), I see

that it’s on a reputable site and happens to be one of the most downloaded files (a bestseller

list!).

Soon, I’m laughing out loud. It really is funny. Of course, I’ve got to tell three friends, so I

do. It’s going viral.

A few weeks later, a site launches another Wassup parody. This one uses the AP photo of

Elian Gonzales as the star. But this time, the virus grows far faster, with more than 100,000

people seeing it in less than 24 hours.

Why did it grow so fast? Because everyone who had seen Superfriends and liked it didn’t

need much coaxing to get infected by this one. By tapping into a virus-friendly base, it took

much less effort for the marketer to get the message to spread.

(Of course, this is a paradox, because the ideavirus loves a vacuum. In this case there wasn’t

a vacuum—the Wassup parody was an old joke. So, in order to make an impact, it had to be

fresh and at least as funny. But once it cleared that hurdle, the rest was taken for granted.)

This time, though, the ending of the cycle was very different. The Associated Press fired off a

letter to the site behind the virus, claiming copyright infringement and not interested at all in

the idea of parody and its protection. So the short movie came down.

Inevitably, if you create a piece of digital media that becomes popular, someone is going to

parody it, or at the very least, use it in a way that you’re not delighted with. If your digital

media becomes that popular, odds are you should embrace it, not fight it. Budweiser, for

Unleashing the Ideavirus 129 http://www.ideavirus.com

example, has wisely let the parody virus spread unfettered. Being parodied online is a

shortcut to burning the Budweiser brand further into our subconscious.

Unleashing the Ideavirus 130 http://www.ideavirus.com

Judging a book by its cover

No question, a great cover can make or break your book. Kurt Andersen wrote one of the

funniest books I’ve ever read (Turn of the Century) but, by all accounts, it didn’t meet sales

expectations. Why? One reason is the cover, which is one of the worst I’ve ever seen in my

life.

Remember, the search for Medusa is usually a hopeless quest. But just as it’s difficult to sell

someone on your ideavirus with just an image, it’s also nearly impossible to suck them

further in if the image is offputting, inconsistent or boring.

Boring is probably the worst offense. Whether your product is a book, a trading card, a car

or even the tag on a bag of tea, boring is the obvious, but wrong, solution.

You’ve worked very hard on the stuff “inside.” You’ve refined, tested, edited and slaved to

make sure that the idea is powerful indeed. And then it comes time to make the

package—the cover. The prevailing wisdom is to create a cover that’s attractive but not

offensive. Something that will attract attention from everyone and offend no one.

This is nonsense, of course. It can’t possibly attract everyone and offend no one. The very

best cover images are like a cold glass of water thrown in your face. They break one or more

rules of graphic design or industry rules of thumb. They play off existing images but change

them in a vital and important way. They’re loud. They attract the eye, but they also hold it.

And most of all, they intrigue us enough that we need to understand what’s inside: we set

ourselves up to be exposed to the virus.

When Yahoo! first launched, the company name and logo broke every rule in the book. But

co-founder Jerry Yang will be the first to tell you that in a world populated with Lycos,

AltaVista, InfoSeek and Architext/Excite, Yahoo! was the easy winner. Easy to spell. Easy to

type. Easy to tell other people about.

And it had personality. It meant something.

Unleashing the Ideavirus 131 http://www.ideavirus.com

Was it risky? I don’t think so. A boring, hard to spell, meaningless name like Lycos was risky.

Unleashing the Ideavirus 132 http://www.ideavirus.com

Being The Most

Turns out there’s been a battle going on for a few years—the battle to make the hottest hot

sauce in the world.

At the beginning, you made a hot sauce by using peppers. Hotter peppers made hotter sauce.

And a sauce made from Scotch Bonnet Peppers (the hottest peppers on Earth) was the

hottest sauce on Earth.

Then, some nutty scientist figured out how to extract just the essence of hotness from Scotch

Bonnet Pepper puree. By using gas chromotagraphy or some other evil technology, he was

able to create a sauce more than 1,000,000 times spicier than your basic pepper.

Why does this matter? Because being the hottest hot sauce ever made is like being the Mona

Lisa. Because if I’ve managed to eat chili with the hottest hot sauce ever made in it, I’m

going to tell my friends. I’m going to spread your hot-sauce virus. If it’s the second or third

hottest, who cares?

There’s always room in any list for the world record holder. The greatest basketball player

who ever lived, or the nastiest restaurant owner, or the fastest computer. It’s noteworthy. It’s

news. It’s worth sharing.

My dad’s hospital crib company dominates the market, making most of the cribs that are

used in hospitals around the world. Their standard models cost $700 to $2,000 each, and

they last forever. How to grow the business? How to get more attention and more sales?

His engineers found a leading hospital, and together they designed the best (and the most

expensive) hospital crib in the world. With all the options, it costs about $7,000. Yet it’s

selling like crazy, from the Philippines to Tuscon. Why? Because it’s worth talking about.

Because it embodies an idea, and it’s an idea worth sharing.

Google.com has plenty of traffic, yet they’ve never spent a nickel on advertising. How?

Because it’s the fastest and most complete search engine ever built. Electronically amplified

Unleashing the Ideavirus 133 http://www.ideavirus.com

voices—from nerds to magazines—are happy to trumpet the idea that there is a faster, better

way to search than using the tried and true favorites.

As you think about a corporate virus or a personal one, consider: What you are the best or

the most at? How can you refine and amplify those traits to create a Wow! product…a

world’s record holder that is worth mentioning?

And by the way, if you’re not facing a vacuum (and most of us aren’t lucky enough to be in

that position) you’ve got to be ten times better than what’s already there, if you’re going to

start your own virus.

Unleashing the Ideavirus 134 http://www.ideavirus.com

In Defense Of World Domination

Targeting isn’t enough. Being a world record holder isn’t enough either. You also need to

dominate your hive.

Having 5,000 loyal, rabid fans of your ideavirus is great. Unless, of course, your audience is

the population of Massachusetts. To dominate Massachusetts you need a lot more fans than

that. Without the power of reinforcement, your virus will peter out. Unless individuals are

hearing from sneezers again and again, your virus will slow and will probably die out over

time.

Imagine, instead, that you have 5,000 fans at Stanford University, which is a hive with a

population of about 15,000. The chances that you’ll be exposed to every other member of

the hive is huge. Why? Because if each one of the 5,000 fans tells just a few other people,

you’re already hitting each person more than once. And if the idea is virusworthy, that’s

probably enough to dominate the entire campus. Even the laggards will surrender when they

see everyone else is doing it (even the accounting department at my old company did the

Macarana at the company Christmas party).

Malcolm Gladwell calls this the tipping pointD—the idea that creating and propagating an

ideavirus is not enough. The biggest win comes the last time your virus doubles in size. The

biggest win comes when you’ve so dominated the hive that the last folks (who are often the

most profitable folks) can’t help but come along. They tip because they hear from so many

respected sneezers that they feel they have no choice but to get on the bandwagon.

This happened with AOL. A few years ago, AOL was paying $300 in marketing costs to get

one new member. All those CDs that showed up in every magazine were expensive, but they

were effective.

But how could AOL justify spending $300 to get a member who had a lifetime value of just

$124? Jan Brandt, the genius behind the campaign, realized that if she could win at this

expensive part of the curve, the game would soon turn in her favor. She knew that once she

Unleashing the Ideavirus 135 http://www.ideavirus.com

got over the hump and dominated the hive of people about to go online, the next generation

of users would come along far cheaper.

She was right. Once AOL established dominance for new users, they established a network of

powerful sneezers. Powerful, because these were folks who until quite recently had been new

users. These once-new, once-lost users had the credibility to spread the word to those just

behind them on the learning curve. They were powerful because they’d been there, and their

personal experience counted for more than any salesperson’s could.

The virus had authority, because every “bestseller” list credited AOL with being far and away

the most popular Internet service provider in the land. Today, someone at Sun City who

until recently had no idea what they were talking about when they said “Internet” could

proudly recommend AOL to the person in the next condo. AOL now spends about $100 in

marketing to get a new member—because their virus tipped.

There’s plenty of interesting action that occurs before the tipping point, though. Viruses

need to spread before they tip, and a smart marketer can be quite happy indeed along the

way.

Dominating the hive is essential in starting the virus in the first place. And most marketers

make the mistake of picking too big a hive to focus on in the first place.

If you go to the Consumer Electronics Show in Las Vegas, you’ll see one of the largest trade

shows in the world, and you’ll also see hundreds of companies spending millions of dollars

trying to dominate the show. All of them fail. Which is why it’s so rare for a virus to be

launched at the CES. It’s just too noisy, and there are no exciting but safe recommendations

for the most powerful sneezers to make.

The smart marketers take a different path. They launch at Demo or Spotlight or Esther

Dyson’s conference—a much smaller venue, but a higher concentration of powerful sneezers.

Here, for about the same money as making a whisper at CES, you can completely dominate

the discussion.

Unleashing the Ideavirus 136 http://www.ideavirus.com

If YouÕre A Member Of The Academy, You Go To Movies For Free

If there’s an association of powerful sneezers, it’s the Academy of Motion Picture Arts and

Sciences. This association of actors, screenwriters and directors has celebrated movies every

year for nearly a century, and every year it seems to get more popular and more influential.

If your movie wins an Oscar, you can count on a blip at the box office, and even better, a

long, profitable life on video. And of course, any actor who wins one has a label that will

enhance his career forever.

So, how much do the studios charge Academy members to go to a movie? That’s right,

nothing. Not only that, but the studios are delighted to deliver the latest movies to an

Academy member’s home, on her choice of VHS or DVD.

Why? Why give the movie away? Well, here it should be pretty obvious. The leverage that

comes from building buzz among Academy members more than pays for the cost of sharing

the movie with them. In fact, the benefits are so obvious that studios like Miramax have been

accused of trying to buy the Oscars by throwing hundreds of thousands of dollars of trade

advertising at Academy members.

Well, if this is so obvious, why bring it up? Because your idea, regardless of marketplace, has

a similar group. Maybe it’s not as easy to find or as easy to reach, but there are powerful

sneezers in the audience for almost every idea. It’s the money paradox, but on a much smaller

scale. Finding these sneezers and giving them a sample of your idea for free is a no-brainer.

Even better, figure out what it costs to deliver it with impact.

I met with a marketing executive from Hong Kong last week. He’s building a company that

is targeting the health care and financial services industries. He’s got a big idea, and if he can

persuade some of the key sneezers in the industry, then most of the other companies are sure

to follow.

Unleashing the Ideavirus 137 http://www.ideavirus.com

The good news is that he was invited to speak at a gathering of 100 top chief information

officers from the financial services industry he’s targeting. The bad news is that he was

planning just to give a speech.

What an opportunity! What a chance to talk to all the key sneezers at once and dominate the

hive. We did the math, and it’s clear that even if he needs to buy each one of the attendees a

BMW to get their attention, it’s worth it.

When you have an opportunity to dominate not just a hive, but the sneezers in the hive, you

need to spare no expense to do so. Don’t just give a speech about how your product works

well. Fly in three satisfied customers to tell their stories in person. Don’t just give a speech

and ask for questions. Sponsor a cocktail party afterward so you can meet individuals and

answer their questions. Don’t just give a speech about how your product is safe and secure.

Give each attendee a first aid kit for their car. By focusing on this key moment, by overinvesting,

you can lay the foundation for a virus to come later.

Unleashing the Ideavirus 138 http://www.ideavirus.com

How An Ideavirus Can Drive The Stock Market

When you think about it, the stock market is nothing but thousands of ideaviruses. (That’s

right, thousands. An ideavirus doesn’t have to dominate our entire culture to be an

ideavirus… some last for just a few days in a very isolated hive, then disappear.) When you

buy a share of stock, you don’t really get anything—just the right to sell that stock to

someone else tomorrow. So… if a positive virus catches on and the demand for the stock

skyrockets, you win.

The market’s respect for ideavirus thinking starts before the company even goes public.

Choosing an investment bank for your IPO is a first step. Firms like Goldman Sachs and

Alex.Brown are powerful sneezers (even though they can easily be bought off with millions of

dollars in investment banking fees by eager companies looking to go public). If one of these

firms aggressively recommends the stock to institutions, the virus starts off on the right foot.

The alternative—marketing the stock through a smaller, less respected (and perhaps cheaper)

investment bank—is almost certain to lead to a lower return.

The next step is pricing the IPO. The current rage is to underprice the stock being offered to

the public, because that will lead to a huge first day appreciation in the stock. It’s not

unusual for an IPO (like Globe.com, Martha Stewart Omnimedia or Street.com) to

dramatically increase in price on the first day of trading.

Why do this? Why leave all those proceeds on the table so that the folks lucky enough to buy

into your IPO make the money instead of your company? The answer is simple, and it has

two parts:

First, by rewarding the powerful sneezers who are lucky enough to buy into your IPO, you

maximize the chance that they’ll participate and will tell their less powerful (but more

numerous friends) about this exciting new investment.

Second, the rapid rise in the first day of trading allows other powerful sneezers (the news

media and brokers you don’t have direct contact with) to talk with excitement and

amazement to the next group of potential investors. In other words, this is cheap marketing.

Unleashing the Ideavirus 139 http://www.ideavirus.com

It’s a way of communicating news (this is a hot stock) to large numbers of people in a

powerful way.

After the stock is public, the company has its work cut out for it. There’s a multi-layered

community of intermediaries between the stock and the people who want to buy it, and the

company must work the hive to find the most powerful sneezers able to spread the word

about the stock.

The first stop is the market analysts who cover the stock. Once again, the marketplace sees

this group as being powerful sneezers (when one analyst recommended Amazon.com, the

price of the stock doubled in just a few days). By courting the analyst community, a

company can find a way to communicate the story they’ve created around the stock.

Don’t underestimate the power of the story. There are almost no other cues available to

persuade someone to spread the word about a stock. You can’t see it or touch it or smell

it—it’s just an intangible right to make money in the future. As a result, the story must be

able to describe the reason why the stock is selling for x today but will be selling for 3x

tomorrow.

Brokers are a fascinating component in the spreading of an ideavirus around a stock.

Remember, they’re not paid unless people trade. Buy and hold is the enemy of most

stockbroker compensation schemes, since they only charge for trades and are paid by

commission. Yet, for many decades, brokers were seen as powerful sneezers, especially if they

helped make you money in the past. In fact, they’ve always been promiscuous sneezers,

motivated (whether in the short term or the long term) by their ultimate financial gain. A

“good” broker is one who realizes that if he postpones financial gain in exchange for helping

his clients make money in the long run he’ll get more and more clients.

All this is changing as the world shifts to trading online, and more important, getting stock

news online. Suddenly, anyone can talk about stocks, anyone can post to a bulletin board,

and anyone can spread a rumor.

Unleashing the Ideavirus 140 http://www.ideavirus.com

As a result, stock ideaviruses spread much more often and much faster. In one case, the

public markets knew about a CEO’s plan to quit before his board of directors did. Because

the individuals who post these notes are anonymous and possess unknown motivations, the

chances that they’ll develop into powerful sneezers is slight. But the sheer number of posts

(more than 100,000 a day on Yahoo!’s bulletin boards alone) means that they have influence.

An astute CFO or CEO can look at the key factors in the creation and spread of a stock

ideavirus and launch a campaign to move the virus with a velocity and vector they’re

comfortable with, and more important, aim it at the appropriate hive.

Note, for example, that some stocks, like Iomega, are the darlings of online stock bulletin

boards. As a direct result, those stocks are far more volatile than the average. Live by the

sword…

Yahoo! has worked hard for years to manage the story about its stock. Gary Valenzuela, the

legendary former CFO at Yahoo!, was obsessed with three things:

1. Become a blue-chip stock, one that institutions would happily own.

2. Become profitable, to distinguish the Yahoo! story from its competitors.

3. Underpromise and overdeliver, always beating the “whisper numbers” that analyst

established for the company’s quarterly earnings.

As a result, Yahoo! stock has consistently and regularly outperformed its competitors. And

due to the success in labeling Yahoo! an Internet blue chip, the stock is much less susceptible

to swings due to rumors.

Was that expensive in the short run? No doubt. When the market was looking for good news

and hype, Yahoo! often refused to deliver. Short term gains were forsaken for building a

story, a story that could become an ideavirus to be delivered by analysts and other powerful

sneezers.

One way to predict the future of a stock, then, is to see beyond the story and understand

whether the company is actively managing the ideavirus, and doing it in a way that will move

it to the right hive.

Unleashing the Ideavirus 141 http://www.ideavirus.com

Bumper Sticker Marketing

Years ago, I was a walking parody of a high-tech yuppie.

I worked as a poorly compensated marketer at a start-up software company in Cambridge,

Massachusetts. I drove a dented old Saab. I used a Macintosh. And on the back of my Saab I

proudly affixed a bumper sticker that read, “I’d rather be driving a Macintosh.”

This is an ancient form of ideavirus marketing, of course. I used my car as an amplifier,

exposing my message to hundreds or thousands of people. But even better, given the

neighborhood I was driving in, I was focusing the message on an appropriate hive, and given

the car I was driving, adding power to my sneezing.

Think about it. If the bumper sticker had been on the back of a junker Chevy, rusting

outside an abandoned farm in Oklahoma, you would have had a very different response to

the message, no?

The neatest thing about this technique is the way Apple converted the private (what sort of

computer do I use) to the public (my proclamation of how happy I was to be a Mac user).

There are countless opportunities for marketers to do precisely the same thing today. And

not just on your bumper. Some marketers ride along with their product—the Ralph Lauren

pony, for example, is advertising on the front of your shirt all day long. Others manage to

make it a more political choice—Marlboro, for example, was one of the ten largest marketers

of imprinted clothing a few years ago.

Picking the medium for your “bumper sticker” is important, but it’s just as important to

determine why someone is going to be willing to stick his neck out to promote your product.

Personal pride is an excellent tactic! If people are willing to sneeze on your behalf because

they’re proud of you, your product and their association with it, you’re in. Now all you’ve

got to do is give them a smooth way to spread the word.

Unleashing the Ideavirus 142 http://www.ideavirus.com

No, You Go First!

The challenge of the new idea is that very few people want to go first. Who was the first to

swim in the Charles River in Cambridge, Massachusetts after years of it being off limits for

health reasons? Who was the first to give their kid the chicken pox vaccine? Which company

chose to be the first to file its taxes electronically?

One of the key reasons to launch an ideavirus is that you can give people a risk-free, cost-free

way to check out the safety of your idea before they commit. And more important, you can

create an aura around your idea—an aura of inevitability, of invincibility. When everyone is

buzzing about a new technique, tactic, service, musical style, club, food—whatever—it’s far

easier to put fear aside and try it.

But just as people are hesitant to be the first to buy a fancy new product, many are hesitant

to try a fancy new idea. There are plenty of people who want nothing to do with a new song

or a new book… they’re happy to wait until it’s been screened, filtered and accepted by the

mainstream.

So, depending on the hive you choose, you need to make it clear to that consumer that your

idea has arrived. That the water’s warm, the air is safe to breathe and your idea is a

comfortable, tried and true one.

One way to do this is with bestseller lists. And with testimonials. And by exposing the digital

word of mouth record to let them see the countless people who have tried it and liked it. Do

it with the specific objective of reminding people that others have taken the risk and happily

survived. If you work at this and do it on purpose, you’ll be amazed at how much water you

can drain from the river—how easy it is to bring the rocks to the surface, how powerful you

can make the message when you expose the connections that led you from person A to

person B. It’s in this sort of active ideavirus marketing that many brands are able to run rings

around the competition.

Even before you do this, offering your idea in trial-sized, bite-sized portions is critical. Many

companies have created neat, effective online products, only to see them fail because they

Unleashing the Ideavirus 143 http://www.ideavirus.com

required consumers to go through a time-consuming download before they could use

them… and if they couldn’t use it, they couldn’t understand why they wanted it! Catch-22:

a product you don’t know if you want to download until you download it.

Give them a version instead that doesn’t require a download and doesn’t work as well—but

still makes their life better. Why? Because now that I’ve sampled it without risking a virus or

taking a lot of time or trying to understand the arcane intricacies of downloading in

Windows, now I’m willing to invest the time to do it.

Unleashing the Ideavirus 144 http://www.ideavirus.com

Digital Media Wants to Be Free

When was the last time you bought some table salt?

Odds are, you didn’t pay very much. Salt is cheap. Why? Because once you own a salt mine

and pay for a salt factory, the cost of making a pound of salt is low indeed. But because

there’s more than one salt mine out there, the competition for getting salt sales is pretty

intense. And given that all salt is pretty much the same, why pay more?

Pricing battles are certainly not unusual in physical goods. In fact, almost every competitive

category of item that’s entirely physical (without an idea attached) uses cost-based pricing. In

other words, it’s a commodity. When those rules are abandoned (as they were with crude oil

during the Arab oil embargo) consumers are shocked and angry.

For a number of reasons, this pricing approach hasn’t really kicked in with intellectual

property. It only costs McKinsey a few hundred bucks to write a report for Chrysler, but

they happily charge a few million dollars for it. One more copy of a Bob Dylan CD only

costs 80 cents to make (less than a vinyl record!) but it sells for twenty times that.

Why?

The biggest reason is that intellectual property is rarely a commodity. There are many kinds

of salt, but there’s only one Bob Dylan. And when you want to listen to Dylan, it’s not clear

that 10,000 Maniacs is an acceptable substitute.

Because intellectual property is unique, it has long resisted a trend toward commodity

pricing at the margin. In fact, the price of most forms of intellectual property has increased.

Barring one big exception:

Stuff that went from being expensive to being free.

The most popular web server software (the programs they use to run most giant websites) is

not sold by Microsoft. And it doesn’t cost $10,000. It’s free.

Unleashing the Ideavirus 145 http://www.ideavirus.com

The most popular web browsers are free.

The cost of listening to a Beethoven concerto went from $30 (at some fancy theater in

London) to $0 after radio was invented.

The cost of watching a movie on network television is zero.

The mathematics of the ideavirus make it too compelling for the creators of viruses to stay

greedy.

The more people know your virus, the more it is worth!

Thus, if charging people for exposure to your virus is going to slow down its spread, give it

away.

Apple just cut the price of WebObjects software from $50,000 a copy to $699. That’s a

98.7% decrease in the price.

Why? Because Apple realized that unless a lot of people use their software, no one will use it.

Take a look at http://www.mp3.com. Pick an obscure music category like Celtic. Go to the end of

the bestseller list: there are 1,168 songs listed. These are not illegal copyright scams, where

the music has been stolen by the artist. These are real songs, posted by the artists or their

labels. The whole song… not part of it.

Why would anyone do this? Give away an entire album of music when Bob Dylan can

charge $16?

Look at it from your point of view. An unknown artist is a commodity. An unknown artist is

the same as a box of salt. If you don’t know why the artist is unique, why pay?

Look at it from the artist’s point of view. The cost of giving away songs is literally zero. Once

you’ve made a record, the cost of one more copy of an MP3 is nothing. And if it helps you

Unleashing the Ideavirus 146 http://www.ideavirus.com

get listened to, if it helps you build your virus, then you’re one step closer to no longer being

a commodity!

In fact, many artists would pay people to listen to their MP3 cuts if they thought it would

help them break through the clutter and get famous. Take a look at the Payola section of

MP3.com. You can do exactly that… pay money to have your song promoted so you can

give it away for free.

Of course, once you’re famous, you can go ahead and charge $16 for your CDs.

Or can you?

Sure, there’s going to be room for collectibles. For live events. For autographed guitars. But

once something is no longer hot and fresh and the latest, rarest thing, why wouldn’t the selfinterested

artist go ahead and give it away free to stoke the ideavirus for the next release? In a

competitive marketplace where there’s transparent information about who’s listening to

what, the Internet becomes radio. And artists know that charging radio stations is dumb.

This same logic applies to books. And to just about any other sort of digital media you can

think of. Unless there’s an extraordinarily unique property of the media being offered, I

maintain that sooner or later it’s going to be free. The Bloomberg machine used by stock

brokers, for example, commanded a huge price premium for years, because the combination

of excellent data and locked-in user interface meant it wasn’t worth switching. But as the

web replicates more and more of the data available, it’s inevitable Bloomberg’s market share

will decrease—and their prices will as well.

The exciting thing is that people who go first, who put their previously expensive digital

media out there for free, will gain the lion’s share of attention and launch bigger and longer

lasting viruses.

So. Who wants to go first? And who wants to go… last?

Unleashing the Ideavirus 147 http://www.ideavirus.com

Van Gogh Lost His Ear To Prove A Point

When Vincent was painting, he often sold his work for just enough money to cover the cost

of paints and canvas. Back then, his ideas and his paintings were one and the same, and

neither was held in very high regard.

Over the last hundred years or so, something has changed. Instead of selling for $200, or

$2,000 or even $20,000, it’s not unusual to read of a $10,000,000 sale of a Van Gogh. Over

time his paintings have increased in value with each sale. But the paintings haven’t changed

at all, have they?

What’s changed is the value of his ideas and the popularity of his ideas—not the ideas

themselves. It’s easy to get a reproduction of a Van Gogh. For a few hundred dollars, you can

even get a painted reproduction that only a trained expert can tell isn’t the original. So why

pay twenty million dollars?

Because you’re buying a souvenir. An expensive souvenir, no doubt, but a souvenir

nonetheless. The original painting is a priceless keepsake that reminds you of the idea

Vincent Van Gogh first unleashed on the world. And unfortunately for Van Gogh and his

heirs, it took far too long for the ideavirus to spread.

Compare this inexorable and dramatic increase in value with the resale value of a newspaper.

Today’s newspaper is “worth” fifty cents to a dollar. The combination of recent news and

events in one handy packet makes it a reasonable purchase. However, yesterday’s paper is

virtually worthless. And if you’ve got a big stack of them, you’re going to have to pay me to

take them away.

Why? What happened? Simple: the newspaper is a vessel for ideas with very short half-lives,

and once the ideas aren’t fresh any more, they’re worthless. Imagine, though, how much you

could sell tomorrow’s paper for—especially if you sold it while the stock market was still

open.

Unleashing the Ideavirus 148 http://www.ideavirus.com

This is a lesson in one way to make your digital media valuable: keep it fresh. It’s getting

harder and harder to do; they used to send Charles Dickens’ serialized novels over here by

boat—news that was three weeks old was considered fresh—but that doesn’t mean you can’t

succeed.

By focusing on souvenirs and speed, creators of digital media can create two effective ways to

profit when we play by the coming new set of rules.

Unleashing the Ideavirus 149 http://www.ideavirus.com

Answering InaÕs Question

So how is a bookstore to make money? Or a publisher? Or an art dealer or a consultant or a

music label?

The biggest objection to ideavirus thinking is that it represents a substantial change from

standard operating procedures. Successful companies are in no hurry to rock the boat…

especially if it represents a significant change in the status quo and a risk to planned-for

revenue and profits.

Mighty Words (an Internet articles publisher) is aggressively targeting traditional book

publishers and re-sellers by creating a new online business that cuts out all the middlemen

and lets authors sell works (preferably 15 to 60 pages) directly to readers. Go to their site and

you can find thousands of articles, priced from $3 to $30 each.

Mighty Words gets half the revenue, the author gets half, the reader gets insight and wisdom

and everybody wins. By creating new markets for mid-length ideas, the company seems to be

filling a niche. Of course, then they can turn their success into dominance by integrating up

the food chain until they disrupt all the competition in the publishing world and profit

mightily.

So you’d think that the concept of ideaviruses would be attractive to this maverick company.

After all, they’re only a few months old.

Not true. It bugs them terribly to give away ideas, because it flies in the face of their brand

new business model. After all, if an author profits most by giving away her work, how does

Mighty Words make money?

If you catch yourself asking this question about a new business model innovation (“How

would we make money?”) you’re headed for trouble. The Internet doesn’t care how you

make money. The Internet isn’t going to wait while you figure out how to react. Instead,

there’s some crazy entrepreneur who’s willing to spend years of his life making you miserable

by wrecking your business model.

Unleashing the Ideavirus 150 http://www.ideavirus.com

Email didn’t ask the fax companies if it was okay with them if a new, instant, permanent,

digital communications tool came along and wrecked the fax business. Matchmaker.com

didn’t hold meetings with the extremely profitable video dating services out there to find out

if it was okay for them to launch. Who cares if Matchmaker.com never makes money? What

matters to the existing businesses is that these new kids on the block have wrecked the

business landscape for the old providers.

Giving digital media away is a reality. Non-dominant players in any industry will always

succeed more by giving away digital content and then profiting later than they will by

holding back to preserve somebody else’s business model.

It was a mistake for the record companies to fight radio and MTV. It’s a mistake for them to

fight Napster. Rather than fighting to patch the leaky bucket, perhaps they could redefine

their roles so they can figure out how to profit from a “free” world.

Unleashing the Ideavirus 151 http://www.ideavirus.com

Crossing The Chasm With An Ideavirus

In his brilliant book, Crossing the Chasm, Geoffrey Moore unleashed a powerful ideavirus

about how new businesses and new ideas get spread. Basically, there’s a chasm in the product

adoption cycle.

The curve used to look like this:

On the left are early adopters, the nerds who love new stuff, who want to get their hands on

anything neat and potentially wonderful. On the right are the laggards, who are still having

trouble getting rid of their steam engine cars.

The meat is obviously in the center. That’s where the vast majority of us live, and where the

combination of big audience and pretty decent pricing is most attractive to a marketer.

In the old days, people believed that you could introduce a product to the early adopters, use

the high profits from those sales to ramp up production and advertising, and then roll the

product out to the masses.

There’s a problem with this view: there’s a gap in the curve. A chasm.

Unleashing the Ideavirus 152 http://www.ideavirus.com

What happened? Turns out people on the right side of the chasm aren’t just lazier or less

intellectually curious than the folks on the left of the chasm. It turns out that people on the

right are fundamentally different from the folks on the left. How?

Pre-chasm people want something cool. Post-chasm people want something that works.

A nerd wants the latest personal digital assistant. An executive wants to keep her

appointments straight.

A cutting-edge IT guy at Allstate wants a device that will use satellite technology to update

claims instantly. The CEO at Nationwide wants something that will reduce costs.

A fashionista wants the latest haute couture outfit from Paris, regardless of how ridiculous it

looks. The party girl wants something that’ll get her a hot date next week.

The foodie wants maple-jalapeño corncakes, layered with crème fraiche and bourbon. The

hungry person just wants something to eat.

As you can see, focusing on the folks who will give you early feedback, be your initial

sneezers, your first customers and probably your start-up’s employees is a one-way ticket to

doom. Their advice will help you make stuff that’s expensive, heavy, hard to use, awkward

Unleashing the Ideavirus 153 http://www.ideavirus.com

and difficult to understand. You’ll be the darling of some well-respected sneezers, and then

you’ll fail. This is why many ideaviruses start with plenty of powerful sneezers but end up

dying.

It happened to Apple with the Newton. It happened to Microsoft with almost every product

they’ve ever launched (Bill Gates is to the far, far left of the chasm—that’s why it takes

Microsoft to version 3 to build something that catches on). It happened to Reebok and to

Stephen Sondheim and to Lou Reed. In every case, they indulged the pre-chasm audience

and lost the big wins on the right. (Of course, in some cases—like Microsoft—sheer staying

power is able to force you over the chasm.)

The challenge in launching an ideavirus is to understand who the pre-chasm sneezers are,

and using them but not letting them use you. In other words, they’re the ones who are most

likely to embrace your new idea and talk about it, but if you don’t get past them to the rest

of the curve, you’re doomed.

Why do Woody Allen movies consistently sell so few tickets? They’re certainly adored by

critics, nominated for awards and attended by a core group of sneezers. The reason is simple:

the virus hits a chasm. There’s a huge gap between the Woody Allen audience and the rest of

the population. Because of this chasm, the word rarely spreads as far and as wide as it could.

The success of his latest movie, “Small Time Crooks,” points to the problem. This movie has

box-office results that rank among the top four he’s ever released for one simple reason.

During the month it was released, it was the only clean family movie available. By focusing

(intentionally or not) on creating a wry, funny movie that was understandable at many levels

and worth bringing your kids to, Woody crossed the chasm. Suddenly, the sneezers were

saying, “This is a great movie for your family,” instead of saying, “this is another great

Woody Allen movie.”

Some viruses are just never going to cross the chasm. Try as they might, the computer nerds

are having no luck at all getting normal people to start using Linux. And the guys who sell

the hottest hot sauce in the world are just not going to find themselves on the table at TGI

Friday’s restaurant.

Unleashing the Ideavirus 154 http://www.ideavirus.com

But that’s okay. It’s okay because these idea merchants understand that the hive they’re

targeting is not everyone. They understand that if they choose the right hive, it’s okay if it’s

small, it’s okay if it’s not everyone. The caveat, of course, is to match your expenses and your

expectations to the size of the hive you’ve chosen. If you spend big on product development

and marketing, figuring that will get you over the chasm, it better.

Unleashing the Ideavirus 155 http://www.ideavirus.com

The Myth Of The Tipping Point

One of the most seductive ideas in Gladwell’s The Tipping Point is that somehow a magic

moment appears when the entire population goes from blissful unawareness of your offering

to total and complete infatuation.

While this certainly appears to happen, it’s not a reality for most companies and most ideas,

and it’s not even a requisite for mindblowing success. There are two related reasons for this.

The first is that it ignores the power of the hive. The chances that you’re going to launch an

ideavirus that consumes the entire population is slim indeed. After all, there are seven billion

people out there, and all of them have very different needs and communication cycles. Even

if you just boil it down to the United States, or to Republicans with Internet access, it’s

pretty clear that large hives very rarely tip about anything.

The second reason is that winning and tipping aren’t the same thing. In order to really win

with an ideavirus, you have to concentrate your message very tightly on a specific hive. But

even then it’s not clear to me that you have to tip to win.

Let’s take a look at eBay, for example. By almost any measure, eBay is a winner. It’s

employees are millionaires and billionaires. Early investors are delighted. Users are happy,

with time spent on the service going up all the time.

But has eBay tipped? Certainly not in terms of awareness among the general population.

When asked to name an online service, only a tiny fraction of the population picks eBay as

their first choice. But it gets even more obvious when you ask people where they go to buy

and sell used junk. The vast majority of people are using classified ads and garage sales, not

eBay.

Yes, the management of eBay is on the cover of Fortune and Business Week at least once a

month, or so it seems. Yes, every meeting at certain high-tech companies includes the

sentence, “But will this allow us to become the eBay of [insert business here].” Within a very

small, very focused, very profitable hive, eBay is a winner. But it didn’t happen because some

Unleashing the Ideavirus 156 http://www.ideavirus.com

magical tipping process took place. It happened because a smart, focused, powerful ideavirus

started and spread across a concentrated hive of investors and pundits, and this led a tiny

company to have a huge stock market valuation.

The reason I point out this myth is that it’s dangerous. Dangerous because it leads idea

merchants to believe that if they just wait long enough, something will happen and make

them tip—like Yahoo! or the Atkins diet or Nike or the Macarena. I don’t buy it. The odds

are with you if you focus on small hives, filled with pre-chasm sneezers, and then obsess with

crossing the chasm as fast as you possibly can. If you tip, that’s a bonus.

Unleashing the Ideavirus 157 http://www.ideavirus.com

The Compounding Effect

One of the factors that makes the tipping point myth seem more real is the power that comes

from multiple sneezers. While one or two recommendations might make for a smooth

transition, there’s no doubt that as the number of powerful sneezers recommending an idea

to you increases, the chances that you’re going to use it dramatically increases.

This is a genuine side effect of the tipping point. As you are surrounded by hive members

who loudly sneeze about a new idea, the greater your chances of at least trying the idea.

Rather than decreasing returns, as we find in advertising, there are actually increasing returns

from an ideavirus. The more people who have it, the more you want it.

Are there iconoclasts who fight every trend? Of course. They wouldn’t be seen in a hip car or

a hip restaurant or listening to a pop tune. But for most individuals, in most hives, the

compounding effect is quite strong.

Thus, one of the most essential tasks an idea merchant can accomplish is to bring all positive

news to the forefront. They make every hive member think that every other hive member is

already converted to the virus, thus creating the self-fulfilling prophecy that leads to success.

Publishing houses do this when they print lots and lots of copies of a book and ship it out to

stores. If there are tons stacked up by the cash register, many people think that this must be

the hot new book, so they buy it. On the basis of this trial, the book shows up on the

bestseller lists soon after being published. This, of course, leads to more people trying it,

because, after all, it’s on the bestseller list. So, without any genuine “word of mouth,” the

book has established a much larger foundation. It won’t get any bigger unless the idea is

virusworthy, but at least the book got a shot.

On Eric Raymond’s page promoting his essay “The Cathedral and the Bazaar,” he lists and

points to critiques of his work. Why? Because bringing these critiques (both positive and

negative) to the forefront is an excellent way to bring the compounding effect into play.

Unleashing the Ideavirus 158 http://www.ideavirus.com

Most marketers focus on getting organic word of mouth going without taking the time to lay

a framework for the compounding effect. Music Direct, on the other hand, goes to great

lengths to leverage powerful sneezers. On their site (www.amusicdirect.com) they list the

recommended recordings of several high-end stereo magazines. Each one is linked directly to

their online ordering service. Thus, you can read a review in Stereophile and know that you’re

only a click away from buying it on their site. Look at a few of the lists and you’ll notice that

the same record shows up more than once. Boom. Even if you weren’t considering buying

that title, the fact that three trusted sneezers have recommended it makes it much more likely

that you’ll consider it.

The folks at Telarc Records learned this lesson early on. Unable to compete with the big

boys at the other classical music labels, they recorded the Cincinnati Orchestra playing

dramatic renditions of songs that only a stereo lover could love. Big cymbals. Cannons. You

get the idea.

Then, they worked hard to get high-end stereo shops to use the CDs they were recording to

demonstrate their equipment. Thousands of consumers who might never have rushed out to

buy another recording of Tchaikovsky’s “1812 Overture” now discovered that Telarc’s

recording was being used anytime they listened to $5,000 speakers or $3,000 amplifiers.

Hey, if you were willing to drop 20 large on a stereo system, certainly it was worth a few

more bucks to have the best CDs to play on it, wasn’t it?

Unleashing the Ideavirus 159 http://www.ideavirus.com

Bill GatesÕ Biggest Nightmare

One of the repeated mantras during the Microsoft anti-trust sideshow was that middleware

threatened the very essence of Microsoft’s cash cow: the Windows OS.

Basically, middleware is software that sits on top of the operating system on your computer

and talks to the Internet or other programs. Once you develop a killer piece of middleware, it

doesn’t matter what operating system you’re running—the middleware works the same. The

first successful example of middleware was the browser, but you can be sure there will be

more.

Today I spoke to a woman named Louise Wannier who developed a piece of software called

enfish. You can find it at http://www.enfish.com.

What if there were a piece of middleware that was designed for people who had an “always

on” connection to the Net. And what if that software let you automatically track your stocks,

your email, your calendar, your instant messages—all the stuff you spend time doing online,

but in an organized way, and all at once?

If you’re like me, that accounts for the vast majority of time you use the computer.

Suddenly, Windows is obsolete.

Sounds like it’s time for Louise to start shopping for a new Porsche, no?

But there are some problems. And all of them are related to the idea she’s created and how to

turn it into an ideavirus.

Problem #1 In order to use enfish, you have to download code. Experience has shown us that

this is a huge amount of friction with which to saddle a new idea. Basically, you can’t enjoy

the software until you go through the pain and suffering of downloading and installing it.

Unleashing the Ideavirus 160 http://www.ideavirus.com

Products like Shockwave and various forms of wallets have shown us that it can cost as much

as $100 in direct to consumer marketing expenditures to get someone to download a piece of

software. In the case of enfish, this is way, way too much.

Solution: Get rid of the download if possible. If not, make it swift and painless.

Problem #2: This is a private experience. Unlike ICQ or Hotmail, which are both based on

communications and are thus pretty viral, enfish saves you time by organizing your life and

your data, and so you’re not naturally inclined to spread the idea. In other words, it doesn’t

do its own sneezing, nor does it reward you for sneezing on its behalf.

Solution: Make it public. Let people post their bookmarks and layouts for their co-workers.

Figure out how to turn it into a communications tool because communications tools are the

most likely to go viral.

Problem #3: It’s not very smooth. It’s awfully difficult to describe what enfish does, because

it’s not simple. It’s biggest strength—that it solves a problem you didn’t know you had—is

also a huge hassle when it comes to marketing the thing. “Free Email” is smooth indeed.

“Automated organizer for always-on Internet knowledge workers that saves you three hours a

day” is not.

Solution: This is the hardest one. Breakthroughs frequently have this problem. Figure out

how to teach the sneezers what to say… even if it means giving them a pre-written email to

forward to friends.

Problem #4: There’s no existing amplifier. There are plenty of sites where people talk about

cars or hobbies or restaurants. Find a hive and you can talk to them. There are magazines

about gardening and starting Internet companies. There are TV shows about cooking and

the weather. But there’s no natural way to amplify a message about the problem that enfish

solves. There are few easily identifiable hives that are just sitting there, waiting to hear from

enfish.

Solution: Use advertising to feature your most satisfied users.

Unleashing the Ideavirus 161 http://www.ideavirus.com

Problem #5: The ideavirus isn’t a natural monopoly. In other words, once they do a great job

of spreading the virus, it’s not clear that enfish’s solution will be the only one to triumph.

One of the amazing things about ICQ, for example, is that the better they did, the better

they did. In other words, there were network effects that created a natural monopoly.

Unfortunately for enfish, there isn’t an obvious reason why an enfish knock-off couldn’t be

as good as enfish.

Solution: The same communication tools that made it go viral will also support its position

as a monopoly.

The good news is that once it catches on, enfish will be extraordinarily persistent. It will sit

on your desk for years, saving you time and making enfish a profit as they go.

The other good news is that because the benefit delivered by enfish is so awesome, once the

virus starts to spread through a hive, it ought to spread with high velocity, and with the

support of the very best kind of powerful sneezers. This is a product that can easily attract

the attention of sneezers on the left side of the chasm (the early adopters) but also offers very

real benefits that will make it fairly smooth to transfer to the right side of the chasm.

So what should enfish do?

My recommendation is that they focus on a single hive: people who trade stocks online.

Why?

Well, the hive is pretty easy to talk to. There are eight or so online brokerage companies who

could all benefit by sneezing about enfish to their best customers. And online traders talk to

each other constantly, meaning that the message can spread through this community with

enormous velocity.

Further, the benefit to online traders is much, much easier to describe, so it’s a lot smoother:

Make more money by trading in a more organized way.

Unleashing the Ideavirus 162 http://www.ideavirus.com

There’s also a vacuum here. Nobody else is offering this value proposition to this audience.

And finally, because online traders tend to be more technically astute, the friction induced by

the download will be less of a barrier.

After infecting the trader hive, will the enfish virus jump to other hives? Perhaps. But in

order to do that, enfish needs to make two significant changes to their product (remember,

the best ideaviruses are integrated right into the product, not tacked on at the end by the

marketing department).

The first change is to create significant benefits to users that derive from enfish’s scale. In

other words, create a network effect so there’s a natural monopoly.

The second change is to create clear and obvious incentives for existing enfish users to

evangelize and bring in new enfish users. These could be simple bribes, but it’s much, much

more effective if the incentives are related to the product—making it work better when you

have more buddies involved.

If they can accomplish these two tricky tasks (so tricky you’ll notice I haven’t even told you

how to do it!), then the odds of the virus jumping from the trader hive to the Net audience

at large increases dramatically.

Unleashing the Ideavirus 163 http://www.ideavirus.com

Hey, Skinny!

One of the most successful books of the last five years has been The Atkins Diet. Dr. Atkins

has sold more than seven million copies of his books…with almost no advertising.

How does a marketing phenomenon like this happen? Conventional marketing wisdom says

that he would need to spend tens or even hundreds of millions of dollars to motivate the one

out of every 40 Americans who has rushed out and bought his book.

The secret to the book’s success is that the diet was virusworthy. Unlike other diets, it really

generates remarkable results in a very short time (let’s leave the health discussion for another

book).

But being virusworthy isn’t enough. It was also smooth. All you had do to tell someone what

diet you were on was say one word, “Atkins.” Because the author became synonymous with

the diet, it was easy to spread.

But the real secret was amplification. Word of mouth could never generate seven million

conversions, not without being amplified.

So what was the amplifier? Your skinnyness! Whenever the diet worked, nosy and proud

friends would ask the dieter, “Hey, skinny! You look great. How’d you do it?” And the dieter

would proudly respond: “Atkins.”

This self-fueling virus saved Atkins millions. And it would never work for transcendental

meditation, St. Johns Wort or reflexology. Nobody is going to notice your inner peace, after

all. Yes, we may be obsessed with the way we look, but it also leads to powerful viruses.

If you doubt the power of this, take a look at all the tattooed kids on the beach.

Unleashing the Ideavirus 164 http://www.ideavirus.com

Get Big Fast? The Mistake So Many Companies MakeÉ

Why was there so much bloodletting among consumer etailers this spring? How did

Boo.com burn through more than a hundred million dollars in start up cash? Why is

Salon.com, arguably one of the most literate sites on the web, floundering?

The answer for almost all these high profile sites is the same: Get Big Fast isn’t always the

right advice.

Remember, an ideavirus adores a vacuum. So many companies, especially those racing to be

the first to fill a vacuum, spend a huge percentage of their funds trying to prime an ideavirus

by buying huge amounts of poorly executed, poor performing interruption advertising.

Big-spending interruption marketers hope the following:

1.

That sheer bulk will make this bad advertising work.

2.

That sheer bulk will scare off the competition.

3.

That an ideavirus will be spawned and they will become instantly and permanently

popular.

4.

That once they are a center of an ideavirus, their truly flawed business model will

magically make sense. Sort of the AOL effect—you can’t be profitable if you’re small and

illogical, but if you’re big and illogical, you can make a fortune from the companies that

pay you because you have a huge market.

They also fear:

1. That someone else will come along and spend more and move faster than them.

2. That if they take their time, the market will realize that their business model is totally

flawed and they won’t be able to get any more funding.

Alas, the pursuit of an ideavirus has confused their analysis. Instead of viewing themselves as

a natural monopoly, as virusworthy, as needing to fill a vacuum, they could have considered

a very different analysis:

Unleashing the Ideavirus 165 http://www.ideavirus.com

1. The ideavirus space for “online merchant” is already filled. It’s filled by Amazon, and to a

lesser, more twisted degree, by eBay and Priceline.

2. Given that the big space is filled, they ought to understand that the virus they’re going to

spread is going to be far smaller and far more quirky. Thus, the win is smaller, but the good

news is that they’ll need far less money to get there.

3. Once you accept the second point, you can realize that growing a virus slowly is actually a

better strategy. Why? Because you get to perfect your business model as you grow, and you

get holistic, organic virus growth, instead of the forced growth a Super Bowl ad brings you.

In other words, you actually get to earn the people who visit your site.

Diamond Organics (www.diamondorganics.com) is following this approach, and it’s

working. Instead of trying to be a category killer and spending tons of money to persuade the

world that their organic vegetable-by-Federal-Express business is a good one, they’re instead

focused on delighting one customer at a time.

By spending little and scaling a lot more slowly, Diamond is able to build serious sneezers,

sneezers who are quite powerful and need little additional inducement to spread the word.

By getting their systems into shape they avoid the pitfalls that struck ToysRUs.com last

Christmas.

But doesn’t this fly in the face of the ideavirus mantra? In many ways it does. It also

challenges the permission marketing idea that once a consumer solves a problem, they’re not

in any hurry to find someone else to solve the same problem, so vendors can achieve lockout.

The problem with implementing the grow-slow strategy is that you might not get the

chance. If you’re a CEO or marketing executive in a new business, you’re subject to the

Catch-22 of rapid business development. You can’t grow (and you can’t get funded) if you

don’t make promises, but those promises might not be able to be kept. And if the promises

aren’t kept (ToysRUs.com failing to ship in time for Christmas) or the promises cost too

much to keep (Boo.com) it doesn’t matter anyway, because you’ll be bust. So most

entrepreneurs make the promises anyway, even though they realize that organic growth is the

better strategy.

Unleashing the Ideavirus 166 http://www.ideavirus.com

So, there has to be a middle ground. And the middle ground that makes the most sense to

me is to not launch a business that can’t sustain an ideavirus. And second, not to force an

ideavirus to happen before the market is ready for it.

My best example is Amazon. My firm belief is that if Jeff Bezos had launched it a year later

or a year earlier, it would never have worked. A year too early and there wouldn’t have been

enough sneezers and the medium wouldn’t have been ready to spread the word. A year too

late and the market would have been so overheated that his promise would have never

broken through the clutter and attracted the attention of sneezers in the first place.

It’s hard for me to imagine how a $50 million marketing campaign is ever appropriate for

any business to launch an ideavirus. If you need to interrupt that many people, you’re doing

something wrong. Sure, you need that much (actually, much more than that) to launch a

brand and to do traditional marketing. But if you’re virusworthy, you generally can do it for

a lot less money than that.

So you need to match the speed of your virus not just with the money you raise but also with

the promises you make to your investors. Yes, Hotmail and Netscape and ICQ and eBay

grew fast, fast, fast. But that doesn’t mean you will. Optimize for the virus and build it into

your company—or expect that it isn’t going to happen.

Unleashing the Ideavirus 167 http://www.ideavirus.com

The Heart Of Viral Marketing

Remember, viral marketing is a special case of the ideavirus where the amplifier for the virus

is built right into the product. And the hot spot for this wonderful self-propagating process is

in communication products.

Let’s take a look at the history of interpersonal business communication over the last 120

years:

Stamps

Telegraph

Telegram

Telephone

Telex

Fax

Conference Calls

Federal Express

Cell Phones

Videoconferencing

Email

The Web

ICQ and Instant Messaging

It’s a pretty extraordinary list. Twenty-five years ago, when I got my first real job, we had no

voice mail, no web pages, no fax machine, no cell phones, no pagers and no email. I

sometimes wonder what we did all day!

So why is there such rapid innovation in this field, when, at the same time, we are still using

precisely the same Qwerty keyboard found on the early typewriters and the same pink “while

you were out” message pads that came with the first phone?

Unleashing the Ideavirus 168 http://www.ideavirus.com

The answer is pretty simple: Each one of these devices creates long-term profits for its

inventor but is spread at a relatively low cost. And the reason it spreads? Because of viral

marketing.

Communication products demand viral marketing because they’re worthless without

someone at the other end. Metcalfe’s law tells us that the value of a network increases with

the square of the number of people using it. So when there are 10 fax machines in the world,

that’s 25 times better than when there were just 2.

Once I buy a communications device, two things happen. First, I become a powerful sneezer,

telling all my friends to buy one so I can send them stuff. And second, provided it’s a tool

that uses an existing channel (like FedEx or Hotmail), every time I send someone a message,

it’s selling the medium.

The story of Post-It notes is so good it ought to be apocryphal but it’s actually true. Nobody

was buying them. 3M was going to cancel the whole program. Then the brand manager of

the product persuaded the secretary of the chairman of 3M to send a case of Post-Its to the

secretaries of the chairmen of the other 499 Fortune 500 companies.

Suddenly, the most powerful sneezers in the most powerful companies in the country were

sending around memos, all containing comments scrawled on Post-Its. It took just a few

months after that for it to become yet another successful business communication device. A

classic ideavirus.

When I was in business school, a classmate spent a year working on a secret project he

wouldn’t tell anyone about. Turns out he was working to launch MCI Mail, the first

commercial email system. It’s a shame he couldn’t tell anyone, because a bunch of us would

have been happy to tell him what we knew, even 20 years ago: An email system isn’t going to

work if there isn’t anyone to send email to!

MCI was charging about $100 to set you up, and another $20 or so a month, plus usage, for

this new service. Big mistake! They inserted friction early in the process, ensuring that people

would never try it, especially so early in the virus’s life.

Unleashing the Ideavirus 169 http://www.ideavirus.com

My idea was that they give MCI Mail, plus a computer to send it with, to 50 people in each

of the top 100 companies in a given industry. FREE. Suddenly, that industry’s leaders would

be communicating with each other fast and frequently. It would change the culture of the

company. The virus would spread. MCI would win.

What’s the lesson? There are two:

3.

If you can somehow convert your idea into a virus that has to do with communication,

it’s much easier to make it go viral. The best sort of communication is an actual

communication tool (like the fax machine or ICQ) but inventing words, new musical

concepts or other ways people communicate goes a long way as well.

4.

Find the powerful sneezers and beg, cajole and bribe them to use your new tool.

Unleashing the Ideavirus 170 http://www.ideavirus.com

The Great Advertising Paradox

Imagine for a second that there was a machine your company could buy. Figure it costs

anywhere from $1 million to $100 million. You’re promised by the salesman that using this

machine can transform your business, dramatically increase sales and profits and turn your

business into a success.

Interested?

What if the salesperson also tells you that companies who don’t buy the machine have a hard

time growing and often languish… and then she points out that one company, Procter &

Gamble, spent more than $2 billion on machines just like this one last year. Interested?

Oh. There’s one caveat. Actually two:

The ongoing output of the machine can’t be measured. You have almost no idea if it’s

working or not—and there’s no guarantee. If it doesn’t work, tough.

Still interested? Well, after those caveats, there’s just one more fact to mention: On average,

the machine only works for about one out of every ten companies that use it. Ninety percent

of the time, the machine fails to work.

By now, you’ve probably figured out that I’m talking about advertising. Mass market

advertising is one of the most puzzling success stories of our economy. Companies spend

billions of dollars to interrupt people with ads they don’t want about products they don’t

need. The ads rarely work. Ads that are created by less than competent ad agencies and

clients almost never work. One day, I’d like to write a book about the worst ads ever run, but

my fear is that it would be too long.

Now, writing off all marketing expenditures because most of the time they don’t work isn’t

the right answer, either. Hence the paradox. You can’t grow without it. But you often can’t

grow with it, either.

Unleashing the Ideavirus 171 http://www.ideavirus.com

So if advertising is such a crap shoot, such a dangerous venture, why do it? Because for the

last 100 years, the single best way to determine whether a company was going to get big or

stay small was to look at its advertising. Time and time again, aggressive companies with

great advertising—regardless of their industry—have managed to make the ads pay and to

grow and become profitable.

So what changed?

A few things. First, the clutter in the marketplace has finally made advertising even less

effective. A threshold has been crossed, and with hundreds of TV channels, thousands of

magazines and literally millions of websites, there’s just too much clutter to reliably interrupt

people. Add to this the “consumerization” of business-to-business sales (with more ads

directed at businesses than ever before) and the explosion of dot-com advertising, and it’s

easy to see that the game is fundamentally different.

So, what should we do about it? Consider the ironic situation that MarchFirst, Inc. finds

itself in. MarchFirst was formed in 2000, the result of a merger between USWeb/CKS,

which does websites and consulting and advertising, and Whittman-Hart, an Internet

consulting firm.

According to the New York Times, MarchFirst wants to launch with a bang, so they’ve

announced a $50,000,000 advertising campaign designed to “cut through the clutter” and to

“get the name out there, to create strong brand awareness,” according to Robert Bernard,

their CEO.

How are they going to do this? By buying full-page ads in newspapers and Internet trade

magazines, by running TV commercials during sporting events, and even running ads in

lifestyle magazines.

Now, be honest. If you’re flipping through a magazine or surfing through channels on TV

and you come across an ad that is based on “the human desire to be first,” will you stop and

pay attention? Will the slogan “a new company for the new economy” make you sit up and

take notice? Will you give up a few minutes of your precious time to read an ad about a

Unleashing the Ideavirus 172 http://www.ideavirus.com

company you’ve never heard of, which solves a problem you probably don’t have? Not

bloody likely.

Surely there’s a better way for this company to spend fifty million dollars. Surely there’s a

more effective way to start a relationship with the 10,000 people who matter to them than

interrupting millions of us over and over and over….

Old-fashioned, hand-crafted, fun-to-make, sorta-fun-to-watch interruption advertising isn’t

going to disappear altogether. But it’s just a matter of time before CEOs and investors start

measuring their ever-increasing ad budgets with the same critical eye they use for every other

insanely expensive investment they make.

Unleashing the Ideavirus 173 http://www.ideavirus.com

Permission: The Missing Ingredient

When Hotmail launched their free email service, they did almost everything right. They

built a product that was worthy of an ideavirus. They made is smooth. They built

amplification right into the product. They approached the right people and started with just

enough push to make the thing take off.

But then they made a huge error.

They forgot to get permission to follow up. They failed to ask their users (the folks who were

infected by the virus) if it was okay to send them an anticipated, personal and relevant email

every week. They didn’t build an asset.

As a result, the Hotmail website has one and only one way to make money. By selling banner

ads. And nobody clicks on banner ads when they’re reading their email. So advertising on the

Hotmail site is super cheap. And probably overpriced.

We’re talking a multi-billion-dollar mistake here. If they had permission to follow up with

20 million people every single week with an email that was filled with useful information and

relevant ads, they could easily sell the slots in this email for a buck a week. That’s a billion

dollars a year in lost revenue, which, using stock market multiples, is a gazillion dollars in

market cap. All because they forgot to ask for permission.

Let’s face it: It’s unlikely that every single idea you come up with is virusworthy. If we’re

going to have to grow our businesses in a reliable, predictable way, it’s unwieldy to have to

depend on an ideavirus catching on every time we want to grow. We still need a way to

communicate with people directly, to do it when we want to, to talk to the marketplace

without a filter.

Advertising used to be the way to do this. But what a waste! What a waste to have to pay a

magazine for an ad to reach a user you already have! You’ve got a pair of Nike sneakers in

your closet. But Nike has to buy an ad to reach you—they don’t have permission or the

ability to talk to you directly.

Unleashing the Ideavirus 174 http://www.ideavirus.com

Same is true with Stevie Wonder. You bought “Innervisions” because you heard it at a

friend’s house, or on the radio, not because you saw an ad. Yet when Stevie comes out with a

new album, his record label has to start all over again, interrupting you using mass media.

Both Stevie and his label waste a huge asset every single time you buy an album. They have

no idea who you are, and worse, they don’t have permission to contact you again.

The challenge of the idea merchant is to turn the virus into an asset. And you turn the virus

into an asset when you ask the user for permission to follow up directly!

This is probably the biggest mistake that ideavirus marketers have made to date. They launch

a virus—a website, a book, a record, a software program, a food—and enjoy the fruits of the

virus while it lasts, but fail to gain a long term asset. And without that asset, they can’t

launch new products or leverage their existing ones without long lag times and the high costs

associated with contacting the users they’ve already converted.

Unleashing the Ideavirus 175 http://www.ideavirus.com

How A Virus And Permission Team Up To Find Aliens

Turns out that the best way to find alien life somewhere in the universe is to listen.

Specifically, to use powerful supercomputers to scan the spectrums for anomalous sounds.

Unfortunately, there isn’t a supercomputer available that’s powerful enough to get the job

done in our lifetime. Which is why the SETI built the largest distributed computer network

in the world. More than 2,000,000 computers are working, in their spare time, to process

these huge chunks of data.

The mechanics of the system are elegant. Whenever your computer has some downtime, a

screensaver pops up, and behind the scenes, your Pentium processor starts cranking through

data that the computer downloads through the web. But what’s really neat is the fact that all

2,000,000 computers in the network signed up without any advertising or financial

inducement.

Instead, the SETI project launched an ideavirus. Word spread among nerds the world over

that they could help find alien intelligence by having their computers participate in the

network. It’s a classic ideavirus, propagated by some powerful sneezers.

The power of the network, though, comes from the fact that they don’t have to relaunch the

thing every week. That it’s incredibly persistent, of course (once you set it up, it stays set up

until you take the initiative to turn it off), but even better, they have permission to

communicate to their users.

This permission is an asset. You can measure it. You can leverage it. You could turn it into

cash if you wanted to.

Let’s take one more look at the sequence:

1. Invent a virusworthy idea.

2. Make it smooth and persistent.

3. Incent powerful sneezers.

4. Get their permission to follow up.

Unleashing the Ideavirus 176 http://www.ideavirus.com

The Art of Creating an Ideavirus

So far, much of what we’ve discussed is science. Mathematical formulas, game theory,

categories of individuals. This is stuff you have to do well to allow your virus to take hold.

And as the understanding of propagating viruses increases, companies will get better and

better at the tactics.

The hard part, though, is building the virus in the first place. The hard part is inventing an

idea that’s so compelling, so ¡Wow! that it spreads through the hive with high velocity,

converting everyone in its path.

How is it that some ideas move so quickly while others just languish? Why did the Apple

Newton fail so badly, while the Palm took off just a few years later?

Caveat: If I knew the answer, I’m not sure I would tell you! To date, no one has come up

with a repeatable formula for creating viruses in a reliable way. There are precious few people

who are serial virus starters.

My hope was that this would be a long chapter, and I could answer your big question about

how. Alas, I don’t know. I know it when I see it, but I fear the rest is art.

Which means you win by trying. And failing. Test, try, fail, measure, evolve, repeat, persist.

It’s old fashioned and hot and dusty and by no means guaranteed to work. Sigh.

Unleashing the Ideavirus 177 http://www.ideavirus.com

Is He Really More Evil Than Satan Himself?

The Google.com search engine is perhaps the most effective and accurate way to search the

web. Why? Because instead of reading every site and trying to understand the content of

every page, Google just reads the links to sites, and selects the pages that plenty of other sites

link to. This way, popular pages rise to the top, and it’s far harder to trick the engine into

pointing to your page by loading up on clever phrases.

Anyway, a few months ago, if you typed, “More Evil Than Satan Himself” into the Google

search engine, the top link it would return was Microsoft.com. Other links that followed

involved mostly Bill Gates.

How did this happen? How was it that enough hackers, nerds and online intelligentsia

building web pages had a strong enough opinion about Bill & Co. that they would go to the

trouble of creating links to Microsoft that used the words like evil and Satan?

Regardless of the dynamics of the virus itself, there’s no question that it’s pervasive, that it

will take years to erase and that it cost Microsoft dearly. By filling the vacuum and creating

an ideavirus of Microsoft as an all-powerful demon, trouncing anyone who came into its

path, the company’s critics brought the Justice Department knocking on its door.

Intel and Cisco have similar market share in the computer space. McDonald’s has similar

impact in the fast food business. There are plenty of companies that could have attracted

attention. But because Microsoft (through its actions—and inaction) spawned a virus, it was

easier for its critics to get the attention of the government. Regardless of your position on the

case, it’s clear that the negative virus (and Microsoft’s actions that reinforced that impression)

affected the judge’s ruling.

Unleashing the Ideavirus 178 http://www.ideavirus.com

Case Study: Why Digimarc Is Going To Fail

Looking at the world through the ideavirus lens makes it easier to prognosticate about a

company’s success or failure. Consider the case of Digimarc.

Digimarc is a fascinating idea. Create a tiny series of dots that can easily be hidden in

magazine ad. Then, if a consumer wants to go to the advertiser’s website, all they have to do

is hold the magazine up to the camera connected to their PC, and Digimarc’s software will

read the dots and automatically take the user to the company’s site.

Charge the advertisers a tiny fee per ad and everyone wins! The magazines win because it

makes their publications more useful. The advertisers win because it creates a direct and

impactful link between the consumer and the ad. And the user wins because she finds special

promotions or discounts on the site… without having to type in a pesky URL.

So why is it going to be an utter failure?

Because there isn’t enough money in the world to turn this into a success, and the shortcut

path of creating an ideavirus isn’t going to happen any time soon either. I know that I’m

going out on a limb here, as this technology has just been featured in Wired and other

magazines and has gotten a lot of press. Still, bear with me….

First, there are few sneezers. The participating magazines have agreed to run full-page ads

promoting the service (if it helps their advertisers, it’s well worth it) but other than that,

who’s going to talk about it?

There are no promiscuous sneezers. No individual is compensated in any way for spreading

the word. There are no powerful sneezers. It’s not such a great, awe-inspiring or even totally

neat thing to do with your computer. There aren’t overwhelming discounts or secret bits of

information, because, after all, if the advertiser was willing to give a discount to a Digimarc

user, he’d probably be willing to give it to everyone, right?

Unleashing the Ideavirus 179 http://www.ideavirus.com

In addition to having a hard time describing why the service might be virusworthy, it’s not

smooth, either. In order to even find out if you like the service, you have to buy a PC camera

($100, plus the hassle of setting it up) as well as download and install a piece of software on

your PC to run the thing.

Once it is set up, it’s not clear if it’s persistent. The incremental benefit of each use of the

service doesn’t appear to go up—you don’t get better and better rewards the more you use it.

So, as the novelty wears off, the likelihood you’ll keep using it and keep sneezing about it is

small indeed.

Finally, they forgot to focus on just one hive. The ads are running in a wide variety of

magazines, targeting a wide variety of users. Because there’s no overwhelming concentration

in just one hive, the odds of the virus popping are small indeed.

So, wise guy, what would you do instead? Well, I’d re-orient the launch from a general massmarket

consumer to a very vertical business-to-business offering. For example, imagine

putting it on the factory floor. Now, instead of a technician having to drop everything and

type in a URL to see a certain page in a manual, he could just hold up the shop manual to

the camera on his already configured PC. Once you can show that it makes an overwhelming

difference in just a few shops, the word can quickly spread across the hive.

If I really wanted to find the consumer market, I’d focus only on the techiest markets (like

the readers of Wired, but I’d create a benefit to promiscuous sneezers within that market.

Rather than creating a flat environment (each ad goes straight to the user), I’d introduce an

email component that rewards the few people who came in at the beginning for emailing

their techno-friendly friends.

My guess is that if Digimarc values the advertising at retail, they’re probably going to spend

$300 for every regular user they get. In order for it to be profitable, my guess is that they

need to get that number down to $3. Problem.

Unleashing the Ideavirus 180 http://www.ideavirus.com

Why Are These Cows Laughing?

If you were in Chicago last summer or lucky enough to walk through Manhattan this June,

you may have noticed a few cows in the street. Actually, hundreds of cows. Big fiberglass

cows—practically life-sized—located on heavily trafficked corners.

The cows cost under $2,000 to make, yet when they’re sold in a charity auction at the end of

the cow invasion, they’ll go for $10,000, $30,000… up to $50,000 a piece.

What happened? How did a $2,000 cow turn into a $50,000 cow?

Well, it helps that the cows are painted by local artists. Some are poignant, some are

whimsical, but they’re all extremely interesting.

However, that doesn’t explain the whole thing. After all, it’s a used cow, having sat out in the

rain and sleet and soot for months. Add to that the fact that the cows are well-designed, but

the artists behind them are by no means famous. In fact, it’s fair to say that in most cases, the

price of the cow will be among the single highest price these artists have ever received at

auction.

A $2,000 cow turns into a $50,000 cow because of amplification. The same cow sitting in a

SOHO gallery wouldn’t be famous. The same cow straight from the artist would just be art,

not a souvenir of a special moment in the history of a city.

Literally hundreds of articles have been written about the cows. But more important, tens of

thousands of conversations have occurred. It’s impossible to walk down the street with a

friend and pass a cow without mentioning it. After all, it’s a cow, just standing there in the

street.

Like all good art, these cows create conversations. But unlike art in an art gallery, these cows

are amplifying the number of conversations. By sitting there. Every day. Calmly. Sort of

like—cows.

Unleashing the Ideavirus 181 http://www.ideavirus.com

As you pass more cows and different cows and provocative cows, your litany of cow lore

increases. Your ability to talk in interesting ways about the cows increases. “Hey, if you think

this cow is cute, wait until you hear about the cow I saw downtown….”

All of which goes to say that street art, performance art, guerrilla marketing performances…

any sort of interruption of our regular routine can lead to a moment of conversation. When

Abby Hoffman and the Yippies dropped dollar bills in the middle of Wall Street during

lunch hour, they generated a virus among the people who were there, which spread to the

media and beyond. By getting people to interact in a way that they weren’t accustomed to,

the Yippies created more impact than they would have if they’d spent five times as much

cash running an ad.

While this sort of interruption of routine is highly amplified, it is by nature not very

persistent. If you keep interrupting the routine, the routine stops being routine and the

interruptions are. If they kept the cows there for years at a time, they’d be boring. If Abby

Hoffman dropped dollar bills every day, people would quickly stop being excited by it.

That’s why the bar for interruption and guerrilla marketers keeps moving. You can’t do what

created buzz yesterday, because there’s no way that’s going to create more buzz today.

Unleashing the Ideavirus 182 http://www.ideavirus.com

Never Drink Alone

Alcohol manufacturers have two spectacular advantages over most marketers. First, there’s a

huge profit margin built in. Second, drinking is a social phenomenon, perfect for spawning

ideaviruses.

Yet, given this natural platform, most distillers are lazy and just buy a huge number of

interruption marketing events—billboards, magazine ads, liquor store displays. They work

sometimes—remember, all vodka is the same, yet people gladly pay double for Absolut.

Most telling of all is the fact that St. Pauli Girl and Becks Light are made on precisely the

same brewery line in Hamburg, yet people will insist that they prefer one over the other.

Despite their successes, though, virtually all of the money spent on liquor advertising is

wasted. Last year, alcohol marketers spent more than a billion dollars advertising their wares,

but you probably can’t even name the top 20 advertisers off the top of your head.

It’s far, far more effective for alcohol manufacturers to focus on advertising to your friends,

not to you, to invest in building viruses that make it more likely that the group will discuss a

brand and eventually order it… or at the very least, admire the person who does.

One of my favorite examples was reportedly created by the brilliant marketer Bob Dorf.

When Dorf was a PR guy, I’m told he was hired by Galliano to turn their obscure liquer into

a nationwide phenomenon. Realizing that there wasn’t enough money in the world to buy

enough “Drink Galliano” billboards, he took a very different tack. He riffed on an invention

by a California bartender named Harvey and decided to popularize the Harvey Wallbanger.

Unleashing the Ideavirus 183 http://www.ideavirus.com

Harvey was a fairly primitive cartoon, a bit better drawn than Kilroy. But he was also a

drink, a drink that coincidentally used a lot of Galliano.

Dorf then set out to teach the newly-counterculture 1970s drinking crowd about this fun

(hey, it was a cartoon) drink. He printed T-shirts, taught bartenders how to mix the drink

and even sent people into popular bars and had them order the drinks (loudly).

The result was an ideavirus. When one fashion-forward powerful sneezer in a group ordered

one, he’d have to stop and explain to everyone else in the group what it was. That group

took the news to the hive, and the virus spread.

The virus wasn’t particularly persistent (from what I’m told, a Harvey Wallbanger wasn’t

that good) but it was extremely smooth. After someone told you about the drink, all you had

to do to get one was say, “I’ll have one too, please.” High velocity, the virus did exactly what

Galliano had asked for… it put the drink on the radar screen.

Unleashing the Ideavirus 184 http://www.ideavirus.com

The Power Of Parody

The sequel to Mission: Impossible had a huge opening this summer. People talked about the

trailer, and more important, told their friends to go see the movie after they’d been.

But how was Warner going to encourage people to see it two or three or four times? How to

get to the hive of media-friendly, time-wasting teenagers just sitting around looking for ways

to spend money? Most important, how could they cost-effectively remind people that MI:2

was out there and worth seeing again?

They decided to unleash an ideavirus that parodied their own movie.

Mission: Imp is a five minute long web film designed to go viral. It features almost famous

Hollywood stars, better than usual production values (for a web virus) and best of all, a “send

to a friend” button.

Unfortunately, it’s not very funny—so while the foundation is there, it’s not as virusworthy

as it might have been if it were made by someone who wasn’t nervous about offending Tom

Cruise. Either way, though, it’s a smart and aggressive way to get out there and start a virus

to keep a product in the public eye.

Unleashing the Ideavirus 185 http://www.ideavirus.com

Bee Stings And The Measles

My friend Kate was on a canoe trip in Algonquin Park and was lucky enough to find an

outhouse on a deserted island. Relishing the chance to relieve herself without having to dig a

hole in the woods, she rushed in and sat down.

Bad news for Kate, there was a beehive inside. Forty stings later, she found herself sitting in

the lake, waiting for the pain to subside. After a long paddle back to base camp, she got

herself to a doctor. The good news is that after a little pain, she was back to normal.

Unfortunately, she’s now extremely sensitive to bee stings, and has to be ever vigilant, lest she

develop an allergic reaction.

Compare that to the childhood ritual of getting the measles. You get the measles, you sit

through a week of annoying itching, and then you’re done. You’re never going to get the

measles again. You’re immune.

In the first case, exposure to an invading poison led the body to become sensitized. In the

second, it led to immunity. Your ideavirus might behave in either way.

Yes, in general, the ideavirus adores a vacuum. It will spread faster and farther when no

similar virus has preceded it. The idea that you can follow a leader to great success might

work in the old economy (like Schick in razors or Burger King in fast food) but it clearly

isn’t a winning strategy in the new one.

But here’s the interesting special case: Sometimes, after being sensitized by one ideavirus, the

market is more susceptible to a new one. The failure of the Newton, for example, made early

adopters and sneezers more aware of the PDA concept, and it paved the way for the Palm to

succeed. The second Thai restaurant in a given town is more likely to turn a profit than the

first one. Michael Jordan wasn’t the first basketball hero by any means, but our desire to have

a hero, as sparked by earlier stars like Wilt Chamberlain and Larry Bird, made it easier for

Michael to walk in and fill a role that had to be filled by someone.

Unleashing the Ideavirus 186 http://www.ideavirus.com

But IsnÕt It Obvious?

One of the big challenges I faced with Permission Marketing and now with Unleashing the

Ideavirus is that a lot of stuff in these books seems pretty obvious. It’s obvious that marketing

to people who want to be marketed to is more effective than interrupting people who hate

you. It’s obvious that word of mouth is more powerful than ads. It’s obvious that the winner

takes all online. It’s obvious….

But precisely because it’s so obvious, it needs to be written about. Defined. Measured.

Because it’s so obvious, it’s easy to fall into a 100-year-old habit and start doing business the

old-fashioned (expensive but easy) way.

After all, if ideavirus marketing is so obvious, why does eToys need to raise $100 million in

venture capital to pay for old-fashioned advertising? Why are the TV networks having their

best year ever in advertising revenues? Why do really smart businesses suddenly turn stupid

when faced with ad opportunities like Planetfeedback.com?

Because to embrace ideavirus marketing techniques you also have to accept a change from

the status quo. And many of the executives who are now in charge made their way to the top

by embracing the status quo, not fighting it.

It’s much easier to raise venture money with a plan that says you’re going to spend $30

million or $60 million dollars on traditional advertising than it is with a plan that says you’ll

only spend $3 million but employ elegant but difficult techniques to get the word out.

It’s much easier to run the marketing department of a Fortune 500 company around the

command-and-control interruption techniques that got the company there in the first place

than it is to allow the customer to be in charge. And it’s far more difficult to devote your

research and development efforts to building ideaviruses than it is to stick with the

traditional incremental improvements.

Even marketers have heroes. Some kids grow up wanting to be like Sandy Koufax or Bart

Starr. But most of us imagined creating the next great TV commercial or building the next

Unleashing the Ideavirus 187 http://www.ideavirus.com

great brand. We envy the folks who built Coke or Nike or Starbucks or Star Wars. But all

these heroes found their success in a different world—in a factory-based, interruptionfocused

marketing environment.

Today, the world is suddenly very different. Almost without exception, every single win on

the consumer side of the Internet has been due to marketing, and the most effective part of

that marketing is about the ideavirus.

Hotmail, Yahoo!, eBay, Amazon, GeoCities, Broadcast.com, Google—all of them succeeded

because an ideavirus was unleashed and spread.

So, yes, the underlying tenets behind the ideavirus are obvious indeed. But executing against

them, fighting the status quo, getting it right—that’s not obvious at all.

Unleashing the Ideavirus 188 http://www.ideavirus.com

Your CompanyÕs Worst Enemy

She might just work in your office. She’s certainly underpaid. And not very well respected.

I’m talking about the folks who staff your customer service department. Admit it—you and

most of the folks in your company would be delighted if you never heard from or about

these guys and what they do. Their job is to make angry customers go away… quietly.

In the old days, this was a pretty easy job. After all, very few people went to all the trouble to

find your mailing address, get an envelope, get a stamp and write a letter. And if you sent the

writer a coupon good for a few bucks, well that was the end of the story.

Today, it’s very different. Planetfeedback (find them at http://www.planetfeedback.com) makes it

easy for angry customers to find you. And they can carbon-copy their congressman or the

FAA or ten friends.

With digitally augmented word of mouth, an angry customer can leave an online record…

one that lasts for centuries! There’s no statute of limitations online.

Take a look at

http://www.deja.com/products/at_a_glance/glance.xp?PCID=11819&PDID=32765. As I write

this, more than 90 people have ranked Flashcom, a provider of DSL services. Flashcom is

ranked as one of the worst providers of DSL service in the country. Actual comments:

Don’t make this mistake

This is a Mickey Mouse operation. Actually, that’s an insult to Mickey Mouse. Their tech

support is incompetent, their customer service is a front, and their technicians are

useless.

Impossible to get a live person through customer service. Sent over 7 emails and have

gotten back one reply. Had to cancel because of this and they charged me an additional

$150 for early termination. Completely bad attitude.

Unleashing the Ideavirus 189 http://www.ideavirus.com

Fraudulent Thieves

Took my $100 deposit (in October!), didn’t deliver a thing, and won’t give it back (they

deny having any record of it). Their “customer care” people use a wide variety of lies to

string you along. STAY AWAY FROM THESE PREDATORS!!!

Now, Flashcom may be running a first-rate organization. But there’s no way to tell that from

these comments. Question: How many expensive full-page ads will the marketing

department have to run to undo the damage that these public posts are going to do to their

brand for years to come?

Compare those reviews to these for Worldspy.com:

Pound for pound the best…

After trying AltaVista, I had about given up on the notion of a “useable” free ISP. I then

stumbled upon WorldSpy… I’ve never gotten a busy signal through WorldSpy and

consistently connect at 52kbps or higher. I’ve never been disconnected and love the

lack of an ad banner blocking my view.

Great so far

Thanks to all for your reviews that helped me find this service. I imagine it is tempting to

keep something like this a secret in order to keep good service for those in the know. I

know I considered that before I wrote this review! But I felt that as I benefited from

others’ recommendations, I owed it to the Deja community to share my experiences. I

have now been using WorldSpy for a few weeks, and have been pleased with it.

Now, we’re not comparing apples to apples here (Worldspy is free) but that only reinforces

the point. The 290 or more people who posted positive reviews are busy telling all their

friends about this service, spreading the positive news. (NB that Worldspy just tanked. An

ideavirus does you no good if you can’t stay in business!)

Unleashing the Ideavirus 190 http://www.ideavirus.com

Finally, take a look at the reviews for Big Planet. They have more than 1,000 reviews, but it

turns out that many of them are posted by Big Planet affiliates, looking to profit from

bringing on new users.

Thus, we see one ISP on the road to failure because it appears that they’ve refused to invest

any time, money or training in the way they treat customers. We see one that has used a very

different business model (free) and combined it with excellent quality and customer service,

and we see a third that’s busy paying promiscuous sneezers to spread the word. What’s your

company doing?

Instead of putting your weakest people into customer service, what would happen if you put

your best there? Instead of asking for reports on how much pain they’re alleviating, why not

let them tell you about how much joy and delight they’re adding to the customer service

experience?

American Express, ordinarily a terrific, data-driven marketer, has gone in almost entirely the

wrong direction on this issue. Every letter and every phone call is designed to reduce costs,

not to increase personal relationship and delight. And with the amplifying power now

available to sneezers, many companies, on the web and off, will either use this as a weapon or

be the victim of it.

Unleashing the Ideavirus 191 http://www.ideavirus.com

Step By Step, Ideavirus Tactics:

• Make it virusworthy.

If it’s not worth talking about, it won’t get talked about.

• Identify the hive.

You won’t get the full benefit of the ideavirus until you dominate your hive.

• Expose the idea.

Expose it to the right people, and do whatever you need to do to get those people

deep into the experience of the idea as quickly as possible. Pay them if necessary,

especially at the beginning. NEVER charge for exposure if you can help it.

• Figure out what you want the sneezers to say.

You’ve got to decide what you want the sneezers to say to the population. If you

don’t decide, either they’ll decide for you and say something less than optimal, or

they won’t even bother to spend the time.

• Give the sneezers the tools they need to spread the virus.

After you’ve got a potential sneezer, make it easy for him to spread the idea. Give

him a way to send your idea to someone else with one click. Let me join your

affiliate program in sixty seconds or less. Reward the people I spread the virus to,

so I don’t feel guilty for spreading it.

• Once the consumer has volunteered his attention, get permission.

The goal of the ideavirus marketer is to use the virus to get attention, then to

build a more reliable, permanent chain of communication so that further

enhancements and new viruses can be launched faster and more effectively, under

your control this time.

• Amaze your audience so that they will reinforce the virus and keep it growing.

Where are the Cabbage Patch Kids? Why do some viruses burn out more quickly

than others? The simplest reason is that marketers get greedy and forget that a

short-term virus is not the end of the process, it’s the beginning. By nurturing the

attention you receive, you can build a self reinforcing virus that lasts and lasts and

benefits all involved.

• Admit that few viruses last forever. Embrace the lifecycle of the virus.

Cats was a terrific success on Broadway. But even great shows don’t last forever.

By understanding that the needs of the virus change over time (and that the

Unleashing the Ideavirus 192 http://www.ideavirus.com

benefits received change as well) the marketer can match expenditures to the

highly leveraged moments.

Unleashing the Ideavirus 193 http://www.ideavirus.com

The Future Of The Ideavirus: What Happens When Everyone Does It?

Interruption marketing (the kind they do on TV) is doomed to fail, because each marketer

who enters the field has more to gain by adding to the clutter than they do by trying to make

the medium work for everyone else. It’s the classic Hudson River pollution problem—once a

big factory is polluting the river, you might as well too.

Permission marketing, on the other hand, is self-limiting. When people have had enough,

they’ll stop giving permission to marketers, and thus there will be no clutter crisis. Sure,

some folks will cheat by spamming or invading privacy or buying and selling names. But

societal pressure and a few key government regulations should stop the cheaters.

But what about the ideavirus? After it dawns on marketers that it’s working, won’t we all be

flooded by offers to make us promiscuous and an incredible flow of free this and free that?

You bet. I think a few things will occur:

1. The race goes to the swift. Just as Frank Zappa and David Bowie supercharged their

careers by getting on CD early, some marketers will fill vacuums and enjoy profits for years

to come. Latecomers will get hurt.

2. The cost of spreading a virus will increase. The bounties to turn people promiscuous will

increase. The benefit to powerful sneezers will increase. When there’s huge demand for

recommendations, marketers will have to pay more to get them.

3. There will be a significant benefit to becoming a powerful sneezer. Everyone will want to

be Esther Dyson or Walter Cronkite, because that sort of genuine credential can be turned

into a profit for years and years. Thus, we’ll see fewer institutional efforts and more

individuals (free agents) who figure out that they can profit mightily by spreading their own

viruses (this manifesto is a living example of that technique).

4. It’s going to be noisy and loud and cluttered as we transition, with a few huge winners and

many satisfied marketers who dominate a hive but don’t necessarily tip. After that, once the

various media settle down, an equilibrium will return and (hopefully) the good stuff will win.

Unleashing the Ideavirus 194 http://www.ideavirus.com

Good luck. Tell me how it goes for you! Sethgodin@ideavirus.com

STEAL THIS IDEA!

Here’s what you can do to spread the word about Unleashing the Ideavirus:

1. Send this file to a friend (it’s sort of big, so ask first).

2. Send them a link to http://www.ideavirus.com so they can download it themselves.

3. Visit http://www.fastcompany.com/ideavirus to read the Fast Company article.

4. Buy a copy of the hardcover book at

http://www.amazon.com/exec/obidos/ASIN/0970309902/permissionmarket.

5. Print out as many copies as you like.

Unleashing the Ideavirus 195 http://www.ideavirus.com

Acknowledgments

First, some professional sneezing (you can find all these links at http://www.ideavirus.com as well):

1. If you ever get the chance to have Red Maxwell design something for you, grab it. He’s an

extraordinary talent, and even better, a brilliant project manager and a great friend. You can

reach Red at red@designfactorynet.com.

2. One of the best ways to start and spread an ideavirus is to have your company write a

book about it. Books are still the most leveraged way to get powerful sneezers to understand

your ideas and spread them. And the partners at Lark Productions—Lisa DiMona, Karen

Watts and Robin Dellabough (robinlark@mindspring.com) are among the best I’ve ever

found at turning ideas into books. In the past twelve months, they’ve handled the words of

Kinko’s, the Dalai Lama (who wrote the foreword for Bo Lozoff’s inspiring new book) and

me. How cool is that?

3. If you haven’t been reading Fast Company, don’t panic. You can catch up on what you’ve

missed at http://www.fastcompany.com. In a world of hype and shallowness, you’ll find very little

of either here.

4. Malcolm Gladwell’s book, The Tipping Point, will radically shift your thinking. That’s a

good thing. Find this and his other writings at http://www.gladwell.com.

5. A lot of people haven’t kept up with Tom Peters since they bought his very first book.

Don’t hesitate! I reread his stuff as often as I can. Find it at http://www.tompeters.com.

6. I also recommend four other great writers and thinkers. Chris Meyer co-wrote Blur

among other things, and despite his protestations, is beginning to share my hairline. Jay

Levinson is the original marketing bigthinker, and you’re selling yourself short if you haven’t

picked up his books lately. And finally, Don Peppers and Martha Rogers who continue to

be way ahead of me and everyone else in how they’re deconstructing and reconstructing the

way we think about marketing.

Unleashing the Ideavirus 196 http://www.ideavirus.com

7. The guys at Peanut Press are terrific. If you’ve got a Palm, point your browser to

http://www.peanutpress.com and go get some books for it. Thanks, Mike!

I’d like also like to thank Susan Greenspan Cohen, Bob Dorf, Louise Wannier, Alison

Heisler and the wonderful people at Fast Company (especially the incredible Alan Webber)

for advice, insight and encouragement as I plowed through this manifesto. And thanks to my

role model and friend Lester Wunderman.

Jerry Colonna, Fred Wilson, Bob Greene, Tom Cohen, Seth Goldstein and their friends,

partners and associates at Flatiron Partners have been generous enough to give me a platform

and a lab to mess with a lot of new thinking. They certainly keep me on my toes, and are

nice enough to sit through my endless slide shows. Fred Wilson and Tom Cohen, though,

deserve extra thanks. Without the two of them, my internet company would have never

thrived, and you wouldn’t be reading this book. Steve Kane and Stu Roseman are, amazingly

enough, about to throw themselves into this maelstrom. Can’t wait.

Thanks to Don Epstein and David Evenchick at the Greater Talent Network in New York

City for believing in me and then being true to their word and keeping me busy.

For the last year, two people have done everything to keep things in perspective for me…

Lisa Gansky and my Dad. Thanks, guys.

Of course, as always, the real joy in my life comes from my wife Helene and our little

entrepreneurs, Alex and Max.

Unleashing the Ideavirus 197 http://www.ideavirus.com

• Deployment guide for Microsoft SharePoint 2013

  1. Prepare the servers
  2. Create the farm
  3. Configure settings, services, solutions, and sites

    Note:

The farm that you create and deploy will undergo significant changes in size, topology, and complexity as you move through the different deployment stages illustrated in the SharePoint 2013 Products Deployment model. This is typical and the expected result of a phased deployment. This is why we recommend that you follow all of the stages described in the “Deployment stages” section of this article.

  • Prepare the servers

In this phase, you get your servers ready to host the product. This includes the supporting servers and the servers that will have SharePoint 2013 installed. The following servers must be configured to support and host a farm:

    Important:

SharePoint 2013 does not support installation on to a domain controller in a production environment. A single label domain (SLD) names or single label forests is also not supported. Because the use of SLD names is not a recommended practice, SharePoint 2013 is not tested in this scenario. Therefore, there may be incompatibility issues when SharePoint 2013 are implemented in a single label domain environment. For more information, see Information about configuring Windows for domains with single-label DNS names and the DNS Namespace Planning Solution Center.

For information about required accounts, see:

In this phase, you install the product and configure each server to support its role in the farm. You also create the configuration database and the SharePoint Central Administration Web site. The following servers are required for a SharePoint 2013 farm:

  • Database server: Unless you plan to use DBA-created databases, the configuration database, content database, and other required databases are created when you run the SharePoint Products Configuration Wizard.
  • Application server: After you prepare the application server, install any additional components that are required to support functions such as Information Rights Management (IRM) and decision support. Install SharePoint 2013 on the server that will host SharePoint Central Administration Web site and then run the SharePoint Products Configuration Wizard to create and configure the farm.
  • Front-end Web server: Install SharePoint 2013 on each Web server, install language packs, and then run the SharePoint Products Configuration Wizard to add the Web servers to the farm.

    Note:

After you add and configure all the front-end Web servers, you can add any additional application servers that are part of your topology design to the farm.

For more information about supported deployment scenarios, see Install SharePoint 2013.

  • Configure settings, services, solutions, and sites

In this phase, you prepare the farm to host your site content by completing the following tasks:

    Note:

Farm configuration steps are not isolated to a specific tier in the server infrastructure.

  1. Verify that the user account that is performing this procedure is a member of either the sysadmin or the serveradmin fixed server role.
  2. On the computer that is running SQL Server, open SQL Server Configuration Manager.
  3. In the navigation pane, expand SQL Server Network Configuration.
  4. Click the corresponding entry for the instance that you are configuring.

    The default instance is listed as Protocols for MSSQLSERVER. Named instances will appear as Protocols for named_instance.

  5. In the main window in the Protocol Name column, right-click TCP/IP, and then click Properties.
  6. Click the IP Addresses tab.

    For every IP address that is assigned to the computer that is running SQL Server, there is a corresponding entry on this tab. By default, SQL Server listens on all IP addresses that are assigned to the computer.

  7. To globally change the port that the default instance is listening on, follow these steps:
  • For each IP address except IPAll, clear all values for both TCP dynamic ports and TCP Port.
  • For IPAll, clear the value for TCP dynamic ports. In the TCP Port field, enter the port that you want the instance of SQL Server to listen on. For example, enter 40000.
  1. To globally change the port that a named instance is listening on, follow these steps:
  • For each IP address including IPAll, clear all values for TCP dynamic ports. A value of 0 for this field indicates that SQL Server uses a dynamic TCP port for the IP address. A blank entry for this value means that SQL Server will not use a dynamic TCP port for the IP address.
  • For each IP address except IPAll, clear all values for TCP Port.
  • For IPAll, clear the value for TCP dynamic ports. In the TCP Port field, enter the port that you want the instance of SQL Server to listen on. For example, enter 40000.
  1. Click OK.

    A message indicates that that the change will not take effect until the SQL Server service is restarted. Click OK.

  2. Close SQL Server Configuration Manager.
  3. Restart the SQL Server service and confirm that the computer that is running SQL Server is listening on the port that you selected.

    You can confirm this by looking in the Event Viewer log after you restart the SQL Server service. Look for an information event similar to the following event:

    Event Type:Information

    Event Source:MSSQL$MSSQLSERVER

    Event Category:(2)

    Event ID:26022

    Date:3/6/2008

    Time:1:46:11 PM

    User:N/A

    Computer:computer_name

    Description:

    Server is listening on [ ‘any’ <ipv4>50000]

  4. Verification: Optionally, include steps that users should perform to verify that the operation was successful.
  1. Verify that the user account that is performing this procedure is a member of either the sysadmin or the serveradmin fixed server role.
  2. In Control Panel, open System and Security.
  3. Click Windows Firewall, and then click Advanced Settings to open the Windows Firewall with Advanced Security dialog box.
  4. In the navigation pane, click Inbound Rules to display the available options in the Actions pane.
  5. Click New Rule to open the New Inbound Rule Wizard.
  6. Use the wizard to complete the steps that are required to allow access to the port that you defined in Configuring a SQL Server instance to listen on a non-default port.

    Note:

You can configure the Internet Protocol security (IPsec) to help secure communication to and from your computer that is running SQL Server by configuring the Windows firewall. You do this by selecting Connection Security Rules in the navigation pane of the Windows Firewall with Advanced Security dialog box.

  1. Verify that the user account that is performing this procedure is a member of either the sysadmin or the serveradmin fixed server role.
  2. Run Setup for SQL Server on the target computer, and install the following client components:
  • Connectivity Components
  • Management Tools
  1. Open SQL Server Configuration Manager.
  2. In the navigation pane, click SQL Native Client Configuration.
  3. In the main window under Items, right-click Aliases, and select New Alias.
  4. In the Alias – New dialog box, in the Alias Name field, enter a name for the alias. For example, enter SharePoint_alias.
  5. In the Port No field, enter the port number for the database instance. For example, enter 40000. Make sure that the protocol is set to TCP/IP.
  6. In the Server field, enter the name of the computer that is running SQL Server.
  7. Click Apply, and then click OK.
  8. Verification: You can test the SQL Server client alias by using SQL Server Management Studio, which is available when you install SQL Server client components.
  9. Open SQL ServerManagement Studio.
  10. When you are prompted to enter a server name, enter the name of the alias that you created, and then click Connect. If the connection is successful, SQL ServerManagement Studio is populated with objects that correspond to the remote database.
  11. To check connectivity to additional database instances from SQL ServerManagement Studio, click Connect, and then click Database Engine.

 

 

  1. Refer to Hardware and software requirements (SharePoint 2013), which lists all the required and optional software for SharePoint 2013. Additionally, this document provides the download location for each prerequisite that is available for download on the Internet.
  2. From the command prompt, navigate to the root of the SharePoint 2013 installation media or folder location.
  3. At the command prompt, type the following command and then press ENTER:

    PrerequisiteInstaller.exe /?

    This displays a list of the command-line options and switches and their corresponding arguments for installing a prerequisite from the command-line.

    Tip:

To copy the contents of the active About window to the Clipboard, press CTRL+C.

  1. Verify that you have an accurate list of the required software. Compare the output from the prerequisite installer to the list of prerequisites in step 1.
  2. Download the prerequisites to a computer that has Internet access.

Next, follow these steps to create a central location that you can use for installing SharePoint 2013 prerequisites on all the farm servers.

To combine prerequisites

  1. Create a shared folder on a computer that can be accessed by the servers on which the prerequisites will be installed.
  2. Copy the files that you downloaded from the Internet to the shared folder.

After you finish creating an available network location for the prerequisites, use the procedure in the following section to install SharePoint 2013 prerequisites on a server.

  1. From the Start menu, open the Command Prompt window using the Run as administrator option.
  2. Navigate to the SharePoint 2013 source directory.
  3. Type the prerequisite program switch and corresponding argument for the program that you want to install, and then press ENTER, for example:

    PrerequisiteInstaller.exe /SQLNCli: “\\o15-sf-admin\SP_prereqs\sqlncli.msi”

    Note:

To install more than one prerequisite, type each switch and argument pair. Be sure to separate each pair by a space, for example:

PrerequisiteInstaller.exe /IDFX: “\\<path>\Windows6.1-KB974405-x64.msu” /sqlncli:”\\<path>\sqlncli.msi” /Sync:”\\<path>\Synchronization.msi”

  1. PrerequisiteInstaller.exe reads the argument file to verify that each switch is valid and that the program identified in the path statement exists.

    Note:

If you specify an argument, PrerequisiteInstaller.exe ignores the arguments file and only processes the command-line argument.

  1. PrerequisiteInstaller.exe scans the local system to determine whether any of the prerequisites are already installed.
  2. PrerequisiteInstaller.exe installs the programs in the argument file and returns one of the following exit codes:
  • 0 – Success
  • 1 Another instance of this application is already running
  • 2 Invalid command line parameter
  • 1001 A pending restart blocks installation
  • 3010 A restart is needed
  1. If a prerequisite requires a restart, a 3010 code is generated and you are prompted to click Finish to restart the system. The behavior of the installer after a 3010 code is different depending on which of the following conditions are true on the computer:

Use the following procedure to create an arguments file.

To create an arguments file

  1. Using a text editor, create a new text document named PrerequisiteInstaller.Arguments.txt. Save this file to the same location as PrerequisiteInstaller.exe. This file will contain the switches and arguments that are used when you run the Microsoft SharePoint Products Preparation Tool.
  2. Using a text editor, edit PrerequisiteInstaller.Arguments.txt and provide file paths to the installation source for each prerequisite switch by using the following syntax:

    /switch: <path>

    Where /switch is a valid switch and <path> is a path of the installation source.

    The following example shows a complete arguments file that uses a file share as a common installation point. Do not include carriage returns in your file.

    /PowerShell:”<path>\WINDOWS6.1-KB2506143-x64.msu” /NETFX:”<path>\dotNetFx45_Full_x86_x64.exe” /IDFX:”<path>\Windows6.1-KB974405-x64.msu” /sqlncli:”<path>\sqlncli.msi” /Sync:”<path>\Synchronization.msi” /AppFabric:”<path>\setup.exe” /IDFX11:”<path>\Microsoft Identity Extensions.msi” /MSIPCClient:”<path>\msipc.msi” /WCFDataServices:”<path>\WcfDataServices.exe” /KB2671763:”<path>\AppFabric1.1-RTM-KB2671763-x64-ENU.exe

  3. After you finish editing PrerequisiteInstaller.Arguments.txt, save your edits, and verify that this file is in the same directory as PrerequisiteInstaller.exe.

Use the following procedure to install the prerequisites.

To install the prerequisites using an arguments file

  1. Run PrerequisiteInstaller.exe at the command prompt to install the prerequisites.

    Caution:

If you are prompted to click Finish to restart the system, do not do so. Instead, click Cancel. For more information, see Known issues you continue with the next step.

  1. Restart the system manually.
  2. At the command prompt type the following command and then press Enter:

    PrerequisiteInstaller.exe

There are two known issues that affect the use of an arguments file:

  • Using line breaks in the arguments file

    If you create an arguments file and use line breaks to put each switch and argument on a separate line, the prerequisite installer fails. The workaround is to enter all the switch and argument pairs on a single line.

  • After a computer restart, the arguments file is not used

    After a restart, PrerequisiteInstaller.exe executes the startup command file, which contains a /continue flag. The /continue flag forces the installer to ignore the arguments file.

    You must prevent a restart by deleting the startup task in this command file by using one of the following options:

    Option 1

  1. Run PrerequisiteInstaller.exe by double-clicking it. The program will display the first screen with the list of prerequisites.
  2. Click Cancel. PrerequisiteInstaller.exe deletes the startup task.

    Option 2

  3. From the Start menu, choose Run and then type regedit to open the registry.
  4. Open the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders.
  5. Check the value for “Common Startup”. This shows the directory where the startup tasks are listed.
  6. Close the registry editor without making any changes.
  7. Navigate to the startup directory, which is usually <systemdir>\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup.
  8. Delete the startup task by deleting “SharePointServerPreparationToolStartup_0FF1CE14-0000-0000-0000-000000000000.cmd”.

 

 

  1. Run the Microsoft SharePoint Products Preparation Tool.
  2. Run Setup, which installs Microsoft SQL Server 2008 R2 SP1 Express Edition and the SharePoint product.
  3. Run the SharePoint Products Configuration Wizard, which installs and configures the configuration database, the content database, and installs the SharePoint Central Administration website. This wizard also creates your first SharePoint site collection.
  4. Configure browser settings.
  5. Perform post-installation steps.

    Important:

To complete the following procedures, you must be a member of the Administrators group on the computer on which you are installing SharePoint 2013.

  • Run the Microsoft SharePoint Products Preparation Tool

Because the prerequisite installer downloads components from the Microsoft Download Center, you must have Internet access on the computer on which you are running the installer. Use the following procedure to install software prerequisites for SharePoint 2013.

To run the Microsoft SharePoint Products Preparation Tool

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. In the folder where you downloaded the SharePoint 2013 software, locate and then run prerequisiteinstaller.exe.
  3. On the Welcome to the Microsoft SharePoint Products Preparation Tool page, click Next.
  4. On the License Terms for software products page, review the terms, select the I accept the terms of the License Agreement(s) check box, and then click Next.
  5. On the Installation Complete page, click Finish.
  6. After you complete the Microsoft SharePoint Products Preparation Tool, you must also install the following:

The following procedure installs Microsoft SQL Server 2008 R2 SP1 Express Edition and the SharePoint product. At the end of Setup, you can choose to start the SharePoint Products Configuration Wizard, which is described later in this section.

To run Setup

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. On the SharePoint Server 2013 or SharePoint Foundation 2013 Start page, click Install SharePoint Server or Install SharePoint Foundation.
  3. On the Enter Your Product Key page, enter your product key, and then click Continue.
  4. On the Read the Microsoft Software License Terms page, review the terms, select the I accept the terms of this agreement check box, and then click Continue.
  5. On the Server Type tab, click Standalone.
  6. When Setup finishes, a dialog box prompts you to complete the configuration of your server. Ensure that the Run the SharePoint Products Configuration Wizard now check box is selected.
  7. Click Close to start the configuration wizard.

    Note:

If Setup fails, check log files in the Temp folder of the user account that you used to run Setup. Ensure that you are logged in using the same user account, and then type %temp% in the location bar in Windows Explorer. If the path in Windows Explorer resolves to a location that ends in a “1” or “2”, you will have to navigate up one level to view the log files. The log file name is SharePoint Server Setup (<time stamp>).

  • Run the SharePoint Products Configuration Wizard

Use the following procedure to install and configure the configuration database and the content database, and install the SharePoint Central Administration website.

To run the SharePoint Products Configuration Wizard

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. If you have closed the SharePoint Products Configuration Wizard, you can access it by clicking Start, point to All Programs, click SharePoint 2013 Products, and then click SharePoint 2013 Products Configuration Wizard. If the User Account Control dialog box appears, click Continue.
  3. On the Welcome to SharePoint Products page, click Next.
  4. In the dialog box that notifies you that some services might have to be restarted during configuration, click Yes.
  5. On the Configuration Successful page, click Finish.

    Note:

If the SharePoint Products Configuration Wizard fails, check the PSCDiagnostics log files, which are located on the drive on which SharePoint 2013 is installed, in the %COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\15\LOGS folder.

  1. On the Template Selection page, select one of the following options, and then click OK:
  • In the Template Selection section, click a predefined template.
  • In the Solutions Gallery section, click Solutions Gallery, and customize your own site template.
  1. On the Set Up Groups for this Site page, specify who should have access to your site, and then either create a new group or use an existing group for these users by doing one of the following:
  • To create a new group, click Create a new group, and then type the name of the group and the members that you want to be part of this group.
  • To use an existing group, click Use an existing group, and then select the user group in the Item list.
  1. Click OK.

    Note:

If you are prompted for your user name and password, you might have to add the SharePoint Central Administration website to the list of trusted sites and configure user authentication settings in Internet Explorer. You might also want to disable the Internet Explorer Enhanced Security settings. If you see a proxy server error message, you might have to configure proxy server settings so that local addresses bypass the proxy server. For more information about how to configure browser and proxy settings, see Configure browser settings.

After you run the SharePoint Products Configuration Wizard, you should confirm that SharePoint 2013 works correctly by configuring additional settings in Internet Explorer.

If you are not using Internet Explorer, you might have to configure additional settings for your browser. For information about supported browsers, see Plan browser support (SharePoint 2013).

To confirm that you have configured browser settings correctly, log on to the server by using an account that has local administrative credentials. Next, connect to the SharePoint Central Administration website. If you are prompted for your user name and password when you connect, perform the following procedures:

  • Add the SharePoint Central Administration website to the list of trusted sites
  • Disable Internet Explorer Enhanced Security settings

If you receive a proxy server error message, perform the following procedure:

  • Configure proxy server settings to bypass the proxy server for local addresses

To add the SharePoint Central Administration website to the list of trusted sites

  1. Verify that the user account that completes this procedure has the following credentials:
  • The user account is a member of the Administrators group on the computer on which you are performing the procedure.
  1. In Internet Explorer, on the Tools menu, click Internet Options.
  2. On the Security tab, in the Select a zone to view or change security settings area, click Trusted Sites, and then click Sites.
  3. Clear the Require server verification (https:) for all sites in this zone check box.
  4. In the Add this web site to the zone box, type the URL to your site, and then click Add.
  5. Click Close to close the Trusted Sites dialog box.
  6. Click OK to close the Internet Options dialog box.

To disable Internet Explorer Enhanced Security settings

  1. Verify that the user account that completes this procedure has the following credentials:
  • The user account is a member of the Administrators group on the computer on which you are performing the procedure.
  1. Click Start, point to All Programs, point to Administrative Tools, and then click Server Manager.
  2. In Server Manager, select the root of Server Manager.
  3. In the Security Information section, click Configure IE ESC.

    The Internet Explorer Enhanced Security Configuration dialog box appears.

  4. In the Administrators section, click Off to disable the Internet Explorer Enhanced Security settings, and then click OK.

To configure proxy server settings to bypass the proxy server for local addresses

  1. Verify that the user account that completes this procedure has the following credentials:
  • The user account is a member of the Administrators group on the computer on which you are performing the procedure.
  1. In Internet Explorer, on the Tools menu, click Internet Options.
  2. On the Connections tab, in the Local Area Network (LAN) settings area, click LAN Settings.
  3. In the Automatic configuration area, clear the Automatically detect settings check box.
  4. In the Proxy Server area, select the Use a proxy server for your LAN check box.
  5. Type the address of the proxy server in the Address box.
  6. Type the port number of the proxy server in the Port box.
  7. Select the Bypass proxy server for local addresses check box.
  8. Click OK to close the Local Area Network (LAN) Settings dialog box.
  9. Click OK to close the Internet Options dialog box.
  1. Run the Microsoft SharePoint Products Preparation Tool, which installs all prerequisites to use SharePoint 2013.
  2. Run Setup, which installs binaries, configures security permissions, and edits registry settings for SharePoint 2013.
  3. Run SharePoint Products Configuration Wizard, which installs and configures the configuration database, installs and configures the content database, and installs the SharePoint Central Administration web site.
  4. Configure browser settings.
  5. Run the Farm Configuration Wizard, which configures the farm, creates the first site collection, and selects the services that you want to use in the farm.
  6. Perform post-installation steps.

    Important:

To complete the following procedures, the account that you use must be a member of the Administrators group on the computer on which you are installing SharePoint 2013. For information about user accounts, see Initial deployment administrative and service accounts in SharePoint 2013.

  • Run the Microsoft SharePoint Products Preparation Tool

Because the prerequisite installer downloads components from the Microsoft Download Center, you must have Internet access on the computer on which you are running the installer. Use the following procedure to install software prerequisites for SharePoint 2013.

To run the Microsoft SharePoint Products Preparation Tool

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. In the folder where you downloaded the SharePoint 2013 software, locate and then run prerequisiteinstaller.exe.
  3. On the Welcome to the Microsoft SharePoint Products Preparation Tool page, click Next.
  4. On the License Terms for software products page, review the terms, select the I accept the terms of the License Agreement(s) check box, and then click Next.
  5. On the Installation Complete page, click Finish.
  6. After you complete the Microsoft SharePoint Products Preparation Tool, you must also install the following:

The following procedure installs binaries, configures security permissions, and edits registry settings for SharePoint 2013. At the end of Setup, you can choose to start the SharePoint Products Configuration Wizard, which is described later in this section.

To run Setup

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. On the SharePoint Server 2013 Start page, click Install SharePoint Server.
  3. On the Enter Your Product Key page, enter your product key, and then click Continue.
  4. On the Read the Microsoft Software License Terms page, review the terms, select the I accept the terms of this agreement check box, and then click Continue.
  5. On the Server Type tab, click Complete.

    The stand-alone option is used to install a single server that has a built-in database.

  6. Optional: To install SharePoint 2013 at a custom location, click the File Location tab, and then either type the location or click Browse to find the location.
  7. Click Install Now.
  8. When Setup finishes, a dialog box prompts you to complete the configuration of your server. Ensure that the Run the SharePoint Products and Technologies Configuration Wizard now check box is selected.
  9. Click Close to start the configuration wizard.

    Note:

If Setup fails, check log files in the Temp folder of the user account you used to run Setup. Ensure that you are logged in using the same user account and then type %temp% in the location bar in Windows Explorer. If the path in Windows Explorer resolves to a location that ends in a “1” or “2”, you have to navigate up one level to view the log files. The log file name is SharePoint Server Setup (<time stamp>).

  • Run the SharePoint Products Configuration Wizard

Use the following procedure to install and configure the configuration database and the content database, and to install the SharePoint Central Administration website.

To run the SharePoint Products Configuration Wizard

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. If you have closed the SharePoint Products Configuration Wizard, you can access it by clicking Start, point to All Programs, click SharePoint 2013 Products, and then click SharePoint 2013 Products Configuration Wizard. If the User Account Control dialog box appears, click Continue.
  3. On the Welcome to SharePoint Products page, click Next.
  4. In the dialog box that notifies you that some services might have to be restarted during configuration, click Yes.
  5. On the Connect to a server farm page, click Create a new server farm, and then click Next.
  6. On the Specify Configuration Database Settings page, do the following:
    1. In the Database server box, type the name of the computer that is running SQL Server.
    2. In the Database name box, type a name for your configuration database or use the default database name. The default name is SharePoint_Config.
    3. In the Username box, type the user name of the server farm account. Ensure that you type the user name in the format DOMAIN\user name.

    Security

The server farm account is used to create and access your configuration database. It also acts as the application pool identity account for the SharePoint Central Administration application pool, and it is the account under which the Microsoft SharePoint Foundation Workflow Timer service runs. The SharePoint Products Configuration Wizard adds this account to the SQL Server Login accounts, the SQL Serverdbcreator server role, and the SQL Serversecurityadmin server role. The user account that you specify as the service account has to be a domain user account. However, it does not have to be a member of any specific security group on your front-end web servers or your database servers. We recommend that you follow the principle of least-privilege and specify a user account that is not a member of the Administrators group on your front-end web servers or your database servers.

  1. In the Password box, type the user password.
  1. Click Next.
  2. On the Specify Farm Security Settings page, type a passphrase, and then click Next.

    Although a passphrase resembles a password, it is usually longer to improve security. It is used to encrypt credentials of accounts that are registered in SharePoint 2013. For example, the SharePoint 2013 system account that you provide when you run the SharePoint Products Configuration Wizard. Ensure that you remember the passphrase, because you must use it every time that you add a server to the farm.

    Ensure that the passphrase meets the following criteria:

  • Contains at least eight characters
  • Contains at least three of the following four character groups:
    • English uppercase characters (from A through Z)
    • English lowercase characters (from a through z)
    • Numerals (from 0 through 9)
    • Nonalphabetic characters (such as !, $, #, %)
  1. On the Configure SharePoint Central Administration Web Application page, do the following:
    1. Either select the Specify port number check box and type the port number that you want the SharePoint Central Administration web application to use, or leave the Specify port number check box cleared if you want to use the default port number.
    2. Click either NTLM or Negotiate (Kerberos).
  2. Click Next.
  3. After you complete the SharePoint Products Configuration Wizard page, review your configuration settings to verify that they are correct, and then click Next.

    Note:

The Advanced Settings option is not available in SharePoint 2013.

  1. On the Configuration Successful page, click Finish. When the wizard closes, setup opens the web browser and connects to Central Administration.

    If the SharePoint Products Configuration Wizard fails, check the PSCDiagnostics log files, which are located on the drive on which SharePoint 2013 is installed, in the %COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\15\LOGS folder.

    If you are prompted for your user name and password, you might have to add the SharePoint Central Administration web site to the list of trusted sites and configure user authentication settings in Internet Explorer. You might also want to disable the Internet Explorer Enhanced Security settings. If you see a proxy server error message, you might have to configure proxy server settings so that local addresses bypass the proxy server. Instructions for configuring proxy server settings are provided in the following section. For more information about how to configure browser and proxy settings, see Configure browser settings.

  • Configure browser settings

After you run the SharePoint Products Configuration Wizard, you should confirm that SharePoint 2013 works correctly by configuring additional settings in Internet Explorer.

If you are not using Internet Explorer, you might have to configure additional settings for your browser. For information about supported browsers, see Plan browser support (SharePoint 2013).

To confirm that you have configured browser settings correctly, log on to the server by using an account that has local administrative credentials. Next, connect to the SharePoint Central Administration web site. If you are prompted for your user name and password when you connect, perform the following procedures:

  • Add the SharePoint Central Administration website to the list of trusted sites
  • Disable Internet Explorer Enhanced Security settings

If you receive a proxy server error message, perform the following procedure:

  • Configure proxy server settings to bypass the proxy server for local addresses

To add the SharePoint Central Administration website to the list of trusted sites

  1. Verify that the user account that completes this procedure has the following credentials:
  • The user account is a member of the Administrators group on the computer on which you are performing the procedure.
  1. In Internet Explorer, on the Tools menu, click Internet Options.
  2. On the Security tab, in the Select a zone to view or change security settings area, click Trusted Sites, and then click Sites.
  3. Clear the Require server verification (https:) for all sites in this zone check box.
  4. In the Add this web site to the zone box, type the URL to your site, and then click Add.
  5. Click Close to close the Trusted Sites dialog box.
  6. Click OK to close the Internet Options dialog box.

To disable Internet Explorer Enhanced Security settings

  1. Verify that the user account that completes this procedure has the following credentials:
  • The user account is a member of the Administrators group on the computer on which you are performing the procedure.
  1. Click Start, point to All Programs, point to Administrative Tools, and then click Server Manager.
  2. In Server Manager, select the root of Server Manager.
  3. In the Security Information section, click Configure IE ESC.

    The Internet Explorer Enhanced Security Configuration dialog box appears.

  4. In the Administrators section, click Off to disable the Internet Explorer Enhanced Security settings, and then click OK.

To configure proxy server settings to bypass the proxy server for local addresses

  1. Verify that the user account that completes this procedure has the following credentials:
  • The user account is a member of the Administrators group on the computer on which you are performing the procedure.
  1. In Internet Explorer, on the Tools menu, click Internet Options.
  2. On the Connections tab, in the Local Area Network (LAN) settings area, click LAN Settings.
  3. In the Automatic configuration area, clear the Automatically detect settings check box.
  4. In the Proxy Server area, select the Use a proxy server for your LAN check box.
  5. Type the address of the proxy server in the Address box.
  6. Type the port number of the proxy server in the Port box.
  7. Select the Bypass proxy server for local addresses check box.
  8. Click OK to close the Local Area Network (LAN) Settings dialog box.
  9. Click OK to close the Internet Options dialog box.
  • Run the Farm Configuration Wizard

You have now completed setup and the initial configuration of SharePoint 2013. You have created the SharePoint Central Administration web site. You can now create your farm and sites, and you can select services by using the Farm Configuration Wizard.

To run the Farm Configuration Wizard

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. On the SharePoint Central Administration home page, on the Quick Launch, click Configuration Wizards, and then click Launch the Farm Configuration Wizard.
  3. On the Help Make SharePoint Better page, click one of the following options, and then click OK:
  • Yes, I am willing to participate (Recommended.)
  • No, I don’t want to participate.
  1. On the Configure your SharePoint farm page, next to Yes, walk me through the configuration of my farm using this wizard, click Start the Wizard.
  2. On the Configure your SharePoint farm page, in the Service Account section, click the service account option that you want to use to configure your services.

    Security

For security reasons, we recommend that you use a different account from the farm administrator account to configure services in the farm.

If you decide to use an existing managed account — that is, an account of which SharePoint 2013 is aware — make sure that you click that option before you continue.

  1. In the Services section, review the services that you want to use in the farm, and then click Next.

    Note:

For more information, see Configure services and service applications in SharePoint 2013. If you are using Office Web Apps, see Office Web Apps (SharePoint 2013).

  1. On the Create Site Collection page, do the following:
    1. In the Title and Description section, in the Title box, type the name of your new site.
    2. Optional: In the Description box, type a description of what the site contains.
    3. In the Web Site Address section, select a URL path for the site.
    4. In the Template Selection section, in the Select a template list, select the template that you want to use for the top-level site in the site collection.

    Note:

To view a template or a description of a template, click any template in the Select a template list.

  1. Click OK.
  2. On the Configure your SharePoint farm page, review the summary of the farm configuration, and then click Finish.
  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. In the folder where you downloaded the SharePoint 2013 software, locate and then run prerequisiteinstaller.exe.
  3. On the Welcome to the Microsoft SharePoint Products Preparation Tool page, click Next.

    Note:

The preparation tool may have to restart the local server to complete the installation of some prerequisites. The installer will continue to run after the server is restarted without manual intervention. However, you will have to log on to the server again.

  1. On the License Terms for software products page, review the terms, select the I accept the terms of the License Agreement(s) check box, and then click Next.
  2. On the Installation Complete page, click Finish.
  3. After you complete the Microsoft SharePoint Products Preparation Tool, you must also install the following:
  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. On the SharePoint 2013 Start page, click Install SharePoint Server.
  3. On the Enter Your Product Key page, enter your product key, and then click Continue.
  4. On the Read the Microsoft Software License Terms page, review the terms, select the I accept the terms of this agreement check box, and then click Continue.
  5. On the Choose the installation you want page, click Server Farm.
  6. On the Server Type tab, click Complete.
  7. On the File Location tab, accept the default location or change the installation path, and then click Install Now.

    Note:

As a best practice, we recommend that you install SharePoint 2013 on a non-system drive.

  1. When the Setup program is finished, a dialog box prompts you to complete the configuration of your server. Clear the Run the SharePoint Products and Technologies Configuration Wizard now check box.

    Note:

For consistency of approach, we recommend that you do not run the configuration wizard until you have installed SharePoint 2013 all application and front-end web servers that will participate in the server farm.

  1. Click Close to finish Setup.
  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. On the server that will host Central Administration (the application server), click Start, point to All Programs, and then click SharePoint 2013 Products, and then click SharePoint 2013 Products Configuration Wizard. If the User Account Control dialog box appears, click Continue.
  3. On the Welcome to SharePoint Products page, click Next.
  4. In the dialog box that notifies you that some services might have to be restarted during configuration, click Yes.
  5. On the Connect to a server farm page, click Create a new server farm, and then click Next.
  6. On the Specify Configuration Database Settings page, do the following:
    1. In the Database server box, type the name of the computer that is running SQL Server.
    2. In the Database name box, type a name for your configuration database, or use the default database name. The default name is SharePoint_Config.
    3. In the Username box, type the user name of the server farm account in DOMAIN\user name format.

    Important:

The server farm account is used to create and access your configuration database. It also acts as the application pool identity account for the SharePoint Central Administration application pool, and it is the account under which the SharePoint Timer service runs. The SharePoint Products Configuration Wizard adds this account to the SQL Server Login accounts, the SQL Serverdbcreator server role, and the SQL Serversecurityadmin server role. The user account that you specify as the service account has to be a domain user account. However, it does not have to be a member of any specific security group on your web servers or your database servers. We recommend that you follow the principle of least-privilege, and specify a user account that is not a member of the Administrators group on your front-end web servers or your database servers.

  1. In the Password box, type the user password.
  1. Click Next.
  2. On the Specify Farm Security Settings page, type a passphrase, and then click Next.

    Although a passphrase resembles a password, it is usually longer to improve security. It is used to encrypt credentials of accounts that are registered in SharePoint 2013. For example, the SharePoint 2013 system account that you provide when you run the SharePoint Products Configuration Wizard. Ensure that you remember the passphrase, because you must use it every time that you add a server to the farm.

    Ensure that the passphrase meets the following criteria:

  • Contains at least eight characters
  • Contains at least three of the following four character groups:
    • English uppercase characters (from A through Z)
    • English lowercase characters (from a through z)
    • Numerals (from 0 through 9)
    • Nonalphabetic characters (such as !, $, #, %)
  1. On the Configure SharePoint Central Administration Web Application page, do the following:
    1. Either select the Specify port number check box and type the port number that you want the SharePoint Central Administration web application to use, or leave the Specify port number check box cleared if you want to use the default port number.

    Note:

If you want to access the SharePoint Central Administration website from a remote computer, make sure that you allow access to the port number that you configure in this step. You do this by configuring the inbound rule for SharePoint Central Administration v4 in Windows Firewall with Advanced Security.

  1. Click either NTLM or Negotiate (Kerberos).
  1. Click Next.
  2. On the Completing the SharePoint Products Configuration Wizard page, click Next.
  3. On the Configuration Successful page, click Finish.

    Note:

If the SharePoint Products Configuration Wizard fails, check the log files on the drive on which SharePoint 2013 is installed, which are located in the %COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\15\LOGS folder.

  1. The Central Administration website will open in a new browser window.

    On the Help Make SharePoint Better page, click one of the following options and then click OK.

    1. Yes, I am willing to participate (Recommended).
    2. No, I don’t wish to participate.
  2. On the Initial Farm Configuration Wizard page, you have the option to use a wizard to configure services or you can decide to configure services manually. For the purpose of this article, we use the manual option. Click Cancel.

    The choice that you make here is a matter of personal preference. The Farm Configuration Wizard will configure some services automatically when you run it. However, if you configure services manually, you have greater flexibility in designing your logical architecture.

    For information about how to use the wizard to configure services, see Configure services and service applications in SharePoint 2013. If you are using Microsoft Office Web Apps, see Office Web Apps overview (Installed on SharePoint 2013).

    Important:

If you are using a DBA-created database, you cannot use the Farm Configuration Wizard, you must use SharePoint Products Configuration Wizard.

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. In the folder where you downloaded the language pack, run setup.exe.
  3. On the Read the Microsoft Software License Terms page, review the terms, select the I accept the terms of this agreement check box, and then click Continue.
  4. The Setup wizard runs and installs the language pack.
  5. Rerun the SharePoint Products Configuration Wizard by using the default settings. If you do not run the SharePoint Products Configuration Wizard after you install a language pack, the language pack will not be installed correctly.

    The SharePoint Products Configuration Wizard runs in the language of the base installation of SharePoint 2013, not in the language of the language pack that you just installed.

To rerun the SharePoint 2013 Configuration Wizard

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. Click Start, point to All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Products Configuration Wizard.
  3. On the Welcome to SharePoint Products page, click Next.
  4. Click Yes in the dialog box that alerts you that some services might have to be restarted during configuration.
  5. On the Modify Server Farm Settings page, click Do not disconnect from this server farm, and then click Next.
  6. If the Modify SharePoint Central Administration Web Administration Settings page appears, do not change any of the default settings, and then click Next.
  7. After you complete the Completing the SharePoint Products and Technologies Configuration Wizard, click Next.
  8. On the Configuration Successful page, click Finish.
  9. After you install a new language pack and rerun the Rerun the SharePoint 2013 Configuration Wizard, you must deactivate and then reactivate any language-specific features before you use the new language pack.

When you install language packs, the language-specific site templates are installed in the %COMMONPROGRAMFILES%\Microsoft Shared\Web server extensions\15\TEMPLATE\LanguageID directory, where LanguageID is the Language ID number for the language that you are installing. For example, the United States English language pack installs to the %COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\15\TEMPLATE\1033 directory. After you install a language pack, site owners and site collection administrators can create sites and site collections based on the language-specific site templates by specifying a language when they are creating a new SharePoint site or site collection.

  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. From the product media or a file share that contains the SharePoint 2013 Products installation files, run Setup.exe.
  3. On the Start page, click the link to install SharePoint 2013.
  4. Review and accept the Microsoft License Terms.
  5. On the Server Type tab, select Complete.

    Note:

You can choose to install only the components that are required for a front-end web server. However, if you perform a complete installation, you have more flexibility to re-purpose the server role in the farm in the future.

  1. Accept the default file location where SharePoint 2013 will be installed or change the installation path in order to suit your requirements.

    Tip:

As a best practice, we recommend that you install SharePoint 2013 on a drive that does not contain the operating system.

  1. When Setup finishes, a dialog box prompts you to run the SharePoint Products Configuration Wizard. You can start the wizard immediately or from the Windows command prompt later.
  1. Verify that the user account that is performing this procedure is the Setup user account. For information about the Setup user account, see Initial deployment administrative and service accounts in SharePoint 2013.
  2. Start the SharePoint 2013 Products Configuration Wizard.
  • For Windows Server 2008 R2:
    • On the new server, click Start, point to All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Products Configuration Wizard.
  • For Windows Server 2012:
    • On the new server, on the Start screen, click SharePoint 2013 Products Configuration Wizard.

      If SharePoint 2013 Products Configuration Wizard is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Products Configuration Wizard.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. On the Welcome to SharePoint Products page, click Next.
  2. On the Connect to a server farm page, click Connect to an existing server farm.
  3. Click Next.
  4. On the Specify Configuration Database settings page, type the name of the instance of SQL Server in the Database server box, and then click Retrieve Database Names.
  5. Select the name of the configuration database in the Database name list, and then click Next.
  6. On the Specify Farm Security Settings page, type the name of the farm passphrase in the Passphrase box, and then click Next.
  7. On the Completing the SharePoint Products Configuration Wizard page, click Next.
  8. On the server that hosts Central Administration, click Manage servers in this farm to verify that the new server is part of the farm.

    Note:

You can also verify a successful server addition or troubleshoot a failed addition by examining the log files. These files are located on the drive on which SharePoint 2013 is installed, in the %COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\15\LOGS folder. For more information, see Monitor health in SharePoint 2013.

  1. On the Servers in Farm page, click the name of the new server. Use the list of available services on the Services on Server page to start the services that you want to run on the new server.
  2. Configure SharePoint 2013 so that the new server can accommodate the role for which it was intended. For more information, see Configure the new server.

To add a new SharePoint 2013 server to the farm by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:Right-click

    • Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command to connect the server to a configuration database:

    Connect-SPConfigurationDatabase -DatabaseServer “<$DatabaseServer>” -DatabaseName “<$RunSettings.ConfigurationDatabaseName>” -Passphrase “<$Passphrase>

    Where:

  • <$DatabaseServer> is the name of the server that hosts the configuration database
  • <$RunSettings.ConfigurationDatabaseName> is the name of the configuration database
  • <$Passphrase> is the passphrase for the farm
  1. At the Windows PowerShell command prompt, type the following command to install the Help File Collections:

    Install-SPHelpCollection -All

  2. At the Windows PowerShell command prompt, type the following command to install the Security Resource for SharePoint 2013:

    Initialize-SPResourceSecurity

  3. At the Windows PowerShell command prompt, type the following command to install the basic services:

    Install-SPService

  4. At the Windows PowerShell command prompt, type the following command to install all the features:

    Install-SPFeature -AllExistingFeatures

  5. At the Windows PowerShell command prompt, type the following command to install application content:

    Install-SPApplicationContent

  6. At the Windows PowerShell command prompt, type the following command to get a list of servers in the farm.

    Get-SPFarm | select Servers

    Note:

You can also verify a successful server addition or troubleshoot a failed addition by examining the log files. These files are located on the drive on which SharePoint 2013 is installed, in the %COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\15\LOGS folder. For more information, see Monitor health in SharePoint 2013.

  1. Configure SharePoint 2013 so that the new server can accommodate the role for which it was intended. For more information, see Configure the new server.
  1. Verify that the user account that completes this procedure has the following credentials:
  • The user account that performs this procedure is a member of the Administrators group on the server.
  1. Stop the services that are running on the server. For information about how to determine which services are running on a specific server and stopping services, see Start or Stop a service (SharePoint 2013).
  2. On the server that you want to remove from the farm, click Start, click Control Panel, and then double-click Programs and Features.
  3. In the list of currently installed programs, click SharePoint 2013, and then click Uninstall.
  4. Click Continue at the confirmation prompt to uninstall the program.
  1. Verify that the user account that completes this procedure has the following credentials:
  • The user account that performs this procedure is a member of the Farm Administrators SharePoint group.
  • The user account that performs this procedure is a member of the Administrators group on the server.
  1. Stop the services that are running on the server. For information about how to determine which services are running on a specific server and stopping services, see Start or Stop a service (SharePoint 2013).
  2. On the SharePoint Central Administration website, in the System Settings section, click Manage servers in this farm.
  3. On the Servers in Farm page, locate the row that contains the name of the server that you want to remove, and then click Remove Server.
  4. In the warning that appears, click OK to remove the server or click Cancel to stop the operation.

    The page updates, and the server that you removed no longer appears in the list of servers.

 

 

  1. Verify that you are a member of the Farm Administrators group or a member of the Administrators group on the local computer.
  2. On the computer that runs SharePoint 2013, log on as a local or domain administrator.
  3. Start Control Panel.
  1. In the Programs area, click Uninstall a program.
  2. In the Uninstall or change a program dialog box, click Microsoft SharePoint Server 2013.
  3. Click Change.
  4. On the Change your installation of Microsoft SharePoint Server 2013 page, click Remove, and then click Continue.

    A confirmation message appears.

  5. Click Yes to remove SharePoint 2013.

    A warning message appears.

  6. Click OK to continue.

    A confirmation message appears.

  7. Click OK.

    You might be prompted to restart the server.

    Note:

If you did not remove the language template packs before you uninstalled and then reinstalled SharePoint 2013, you must run Repair from the SharePoint Products Configuration Wizard for each language template pack on the server. After the repair operation is complete, you must restart the server. Finally, complete the language template pack configuration by running the SharePoint Products Configuration Wizard.

 

 

  1. Verify that the user account that is performing this procedure is a site collection administrator.
  2. Start SharePoint 2013 Central Administration.
  • For Windows Server 2008 R2:
    • Click Start, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Central Administration.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Central Administration.

      If SharePoint 2013 Central Administration is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Central Administration.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. In Central Administration, in the Application Management section, click Manage web applications.
  2. In the Contribute group of the ribbon, click New.
  3. In the Claims Authentication Types section of the Create New Web Application dialog box, select Enable Forms Based Authentication (FBA).
  4. Type a membership provider name in ASP.NET Membership provider name and a role manager name in ASP.NET Role manager name.

    In the example Web.Config files depicted in this article, the membership provider is membership and the role manager is rolemanager.

  5. Configure the other settings for this new web application as needed, and then click OK to create it.
  6. When prompted with the Application Created dialog box, click OK.
  1. Click Start, point to Administrative Tools, and then click Internet Information Services (IIS) Manager.
  2. In the console tree, open the server name, and then Sites.
  3. Right-click the SharePoint Central Administration v4 site, and then click Explore.
  4. In the folder window, double-click the Web.Config file.
  5. In the <Configuration> section, find the <system.web> section and add the following example entry:

    <membership defaultProvider=”AspNetSqlMembershipProvider”>
    <providers>
    <add name=”membership”
    type=”Microsoft.Office.Server.Security.LdapMembershipProvider, Microsoft.Office.Server, Version=15.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c”
    server=”yourserver.com”
    port=”389″
    useSSL=”false”
    userDNAttribute=”distinguishedName”
    userNameAttribute=”sAMAccountName”
    userContainer=”OU=UserAccounts,DC=internal,DC=yourcompany,DC=distinguishedName (of your userContainer)”
    userObjectClass=”person”
    userFilter=”(ObjectClass=person)”
    scope=”Subtree”
    otherRequiredUserAttributes=”sn,givenname,cn” />
    </providers>
    </membership>
    <roleManager enabled=”true” defaultProvider=”AspNetWindowsTokenRoleProvider” >
    <providers>
    <add name=”roleManager”
    type=”Microsoft.Office.Server.Security.LdapRoleProvider, Microsoft.Office.Server, Version=15.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c”
    server=”yourserver.com”
    port=”389″
    useSSL=”false”
    groupContainer=”DC=internal,DC=yourcompany,DC=distinguishedName (of your groupContainer)”
    groupNameAttribute=”cn”
    groupNameAlternateSearchAttribute=”samAccountName”
    groupMemberAttribute=”member”
    userNameAttribute=”sAMAccountName”
    dnAttribute=”distinguishedName”
    groupFilter=”((ObjectClass=group)”
    userFilter=”((ObjectClass=person)”
    scope=”Subtree” />
    </providers>
    </roleManager>

 

In the preceding entry, substitute the following:

  • The name of your membership provider in <add name=”membership”.
  • The fully qualified domain name (FQDN) of your domain controller (your LDAP server) in server=”yourserver.com”.
  • The distinguished name of your user container in userContainer=”OU=UserAccounts,DC=internal,DC=yourcompany,DC=distinguishedName (of your userContainer)”.
  • The name of your role manager in <add name=”roleManager”.
  • The distinguished name of your group container in groupContainer=”DC=internal,DC=yourcompany,DC=distinguishedName (of your groupContainer)”.

After you add this entry, save and close the Web.Config file.

  • Configure the Security Token Service Web.Config file

The following procedure configures the Security Token Service to recognize and use the new forms-based membership provider and role manager.

To configure the Security Token Service Web.Config file

  1. In the console tree of Internet Information Services (IIS) Manager, open the SharePoint Web Services site.
  2. In the console tree, right-click SecurityTokenServiceApplication, and then click Explore.
  3. In the folder window, double-click the Web.Config file.
  4. In the <Configuration> section, create a new <system.web> section and add the following example entry:

    <membership>
    <providers>
    <add name=”membership”
    type=”Microsoft.Office.Server.Security.LdapMembershipProvider, Microsoft.Office.Server, Version=15.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c”
    server=”yourserver.com”
    port=”389″
    useSSL=”false”
    userDNAttribute=”distinguishedName”
    userNameAttribute=”sAMAccountName”
    userContainer=”OU=UserAccounts,DC=internal,DC=yourcompany,DC=com”
    userObjectClass=”person”
    userFilter=”(&amp;(ObjectClass=person))”
    scope=”Subtree”
    otherRequiredUserAttributes=”sn,givenname,cn” />
    </providers>
    </membership>
    <roleManager enabled=”true” >
    <providers>
    <add name=”rolemanager”
    type=”Microsoft.Office.Server.Security.LdapRoleProvider, Microsoft.Office.Server, Version=15.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c”
    server=”yourserver.com”
    port=”389″
    useSSL=”false”
    groupContainer=”DC=internal,DC=yourcompany,DC=com”
    groupNameAttribute=”cn”
    groupNameAlternateSearchAttribute=”samAccountName”
    groupMemberAttribute=”member”
    userNameAttribute=”sAMAccountName”
    dnAttribute=”distinguishedName”
    groupFilter=”(&amp;(ObjectClass=group))”
    userFilter=”(&amp;(ObjectClass=person))”
    scope=”Subtree” />
    </providers>
    </roleManager>

 

In the preceding entry, substitute the following:

  • The name of your membership provider in <add name=”membership”.
  • The FQDN of your domain controller (your LDAP server) in server=”yourserver.com”.
  • The distinguished name of your user container in userContainer=”OU=UserAccounts,DC=internal,DC=yourcompany,DC=com”.
  • The name of your role manager in <add name=”roleManager”.
  • The distinguished name of your group container in groupContainer=”DC=internal,DC=yourcompany,DC=com”.

After you add this entry, save and close the Web.Config file.

  • Configure the new web application Web.Config file

The following procedure configures the new web application to recognize and use the new forms-based membership provider and role manager.

To configure the new web application Web.Config file

  1. In the console tree of Internet Information Services (IIS) Manager, right-click the site that corresponds to the name of the web applications that you just created, and then click Explore.
  2. In the folder window, double-click the Web.Config file.
  3. In the <Configuration> section, find the <system.web> section.
  4. Find the <membership defaultProvider=”i”> section and add the following example entry to the <Providers> section:

    <add name=”membership”
    type=”Microsoft.Office.Server.Security.LdapMembershipProvider, Microsoft.Office.Server, Version=15.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c”
    server=”yourserver.com”
    port=”389″
    useSSL=”false”
    userDNAttribute=”distinguishedName”
    userNameAttribute=”sAMAccountName”
    userContainer=”OU=UserAccounts,DC=internal,DC=yourcompany,DC=com”
    userObjectClass=”person”
    userFilter=”(&amp;(ObjectClass=person))”
    scope=”Subtree”
    otherRequiredUserAttributes=”sn,givenname,cn” />

 

In the preceding entry, substitute the following:

  • The name of your membership provider in <add name=”membership”.
  • The FQDN of your domain controller (your LDAP server) in server=”yourserver.com”.
  • The distinguished name of your user container in userContainer=”OU=UserAccounts,DC=internal,DC=yourcompany,DC=com”.
  1. Find the <roleManager defaultProvider=”c” enabled=”true” cacheRolesInCookie=”false”> section and add the following example entry to the <Providers> section:

<add name=”roleManager”
type=”Microsoft.Office.Server.Security.LdapRoleProvider, Microsoft.Office.Server, Version=15.0.0.0, Culture=neutral, PublicKeyToken=71e9bce111e9429c”
server=”yourserver.com”
port=”389″
useSSL=”false”
groupContainer=”DC=internal,DC=yourcompany,DC=com”
groupNameAttribute=”cn”
groupNameAlternateSearchAttribute=”samAccountName”
groupMemberAttribute=”member”
userNameAttribute=”sAMAccountName”
dnAttribute=”distinguishedName”
groupFilter=”(&amp;(ObjectClass=group))”
userFilter=”(&amp;(ObjectClass=person))”
scope=”Subtree” />

 

In the preceding entry, substitute the following:

  • The name of your role manager in <add name=”roleManager”.
  • The FQDN of your domain controller (your LDAP server) in server=”yourserver.com”.
  • The distinguished name of your group container in groupContainer=”DC=internal,DC=yourcompany,DC=com”.

After you add the preceding entry, save and close the Web.Config file.

    Warning:

Do not overwrite any existing entries in this Web.Config file.

  • Create a new web application that uses forms-based authentication with Windows PowerShell

    Perform the following procedure to create a web application that uses forms-based authentication with Windows PowerShell.

    To create a new web application that uses forms-based authentication with Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • In the SharePoint 2013 environment, on the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • In the SharePoint 2013 environment, on the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. From the Windows PowerShell command prompt, type the following:

    $ap = New-SPAuthenticationProvider -Name <Name> -ASPNETMembershipProvider <Membership Provider Name> -ASPNETRoleProviderName <Role Manager Name>
    $wa = New-SPWebApplication -Name
    <Name> -ApplicationPool <ApplicationPool> -ApplicationPoolAccount <ApplicationPoolAccount> -Url <URL> -Port <Port> -AuthenticationProvider $ap

    Example

    $ap = New-SPAuthenticationProvider -Name “ClaimsForms” -ASPNETMembershipProvider “membership” -ASPNETRoleProviderName “rolemanager”
    $wa = New-SPWebApplication -Name “FBA Web App” -ApplicationPool “Claims App Pool” -ApplicationPoolAccount “internal\appool” -Url http://contoso.com -Port 1234 -AuthenticationProvider $ap

    Note:

The value of the ApplicationPoolAccount parameter must be a managed account on the farm.

  1. After you successfully create the new web application, modify the following Web.Config files:
  1. After you change the Web.Config files, create a SPClaimsPrincipal and a site collection, as shown in the following example:

    $cp = New-SPClaimsPrincipal -Identity “membership:SiteOwner” -IdentityType FormsUser
    $sp = New-SPSite http://servername:port -OwnerAlias $cp.Encode() -Template “STS#0”

    For more information, see New-SPClaimsPrincipal.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • In the SharePoint 2013 environment, on the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • In the SharePoint 2013 environment, on the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. From the Windows PowerShell command prompt, type the following:

    $svc = [Microsoft.SharePoint.Administration.SPWebService]::ContentService
    $svc.MembershipUserKeyType=[Microsoft.SharePoint.Administration.SPMembershipUserKeyType]::ProviderUserKey
    $svc.Update()

 

 

  1. Configure AD FS for a relying party
  2. Configure the claim rule
  3. Export the token signing certificate

Use the procedure in this section to configure a relying party. The relying party defines how the AD FS recognizes the relying party application and issues claims to it.

To configure AD FS for a relying party

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the local computer. For additional information about accounts and group memberships, see Local and Domain Default Groups
  2. On the AD FS server, open the Active Directory Federation Services (AD FS) 2.0 Management console.
  3. In the navigation pane, expand Trust Relationships, and then double-click the Relying Party Trusts folder.
  4. In the right pane, click Add Relying Party Trust.

    This opens the Active Directory Federation Services (AD FS) 2.0 configuration wizard.

  5. On the Welcome to the Add Relying Party Trust Wizard page, click Start.
  6. Select Enter data about the relying party manually, and then click next.
  7. Type a relying party name and then click Next.
  8. Make sure Active Directory Federation Services (AD FS) 2.0 Profile is selected, and then click Next.
  9. Do not use an encryption certificate. Click Next.
  10. Click to select the Enable support for the WS-Federation Passive protocol check box.
  11. In the WS-Federation Passive protocol URL field, type the name of the web application URL, and append /_trust/ (for example, https://WebAppName/_trust/). Click Next.

    Note:

The name of the URL has to use Secure Sockets Layer (SSL).

  1. Type the name of the relying party trust identifier (for example, urn:sharepoint:WebAppName), and then click Add. Click Next. Note that this will be the realm value when you configure a new SPTrustedIdentityTokenIssuer in Phase 3.
  2. Select Permit all users to access this relying party. Click Next.
  3. On the Ready to Add Trust page, there is no action required, click Next.
  4. On the Finish page, click Close. This opens the Rules Editor Management console. Use this console and the next procedure to configure the mapping of claims from your chosen directory source to SharePoint 2013.

Use the procedure in this step to send values of a Lightweight Directory Access Protocol (LDAP) attribute as claims and specify how the attributes will map to the outgoing claim type.

To configure a claim rule

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the local computer. For additional information about accounts and group memberships, see Local and Domain Default Groups
  2. On the Issuance Transform Rules tab, click Add Rule.
  3. On the Select Rule Template page, select Send LDAP Attributes as Claims. Click Next.
  4. On the Configure Rule page, type the name of the claim rule in the Claim rule name field.
  5. From the Attribute Store drop-down list, select Active Directory.
  6. In the Mapping of LDAP attributes to outgoing claim types section, under LDAP Attribute, select SAM-Account-Name.
  7. Under Outgoing Claim Type, select E-Mail Address.
  8. Under LDAP Attribute, select User-Principal-Name.
  9. Under Outgoing Claim Type, select UPN.
  10. Click Finish, and then click OK.

Use the procedure in this section to export the token signing certificate of the AD FS server with which you want to establish a trust relationship, and then copy the certificate to a location that SharePoint 2013 can access.

To export a token signing certificate

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the local computer. For additional information about accounts and group memberships, see Local and Domain Default Groups
  2. On the AD FS server, open the Active Directory Federation Services (AD FS) 2.0 Management console.
  3. In the navigation pane, expand Service, and then click the Certificates folder.
  4. Under Token signing, click the primary token certificate as indicated in the Primary column.
  5. In the right pane, click View Certificate link. This displays the properties of the certificate.
  6. Click the Details tab.
  7. Click Copy to File. This starts the Certificate Export Wizard.
  8. On the Welcome to the Certificate Export Wizard page, click Next.
  9. On the Export Private Key page, click No, do not export the private key, and then click Next.
  10. On the Export File Format page, select DER encoded binary X.509 (.CER), and then click Next.
  11. On the File to Export page, type the name and location of the file that you want to export, and then click Next. For example, enter C:\ADFS.cer.
  12. On the Completing the Certificate Export Wizard page, click Finish.
  1. Exporting multiple parent certificates
  2. Import a token signing certificate by using Windows PowerShell
  3. Define a unique identifier for claims mapping by using Windows PowerShell
  4. Create a new authentication provider

To complete the configuration of the AD FS server, copy the .CER file to the computer that is running AD FS.

The token signing certificate may have one or more parent certificates in its chain. If it does, every certificate in that chain has to be added to the SharePoint 2013 list of trusted root authorities.

To determine whether one or more parent certificates exist, follow these steps.

    Note:

These steps should be repeated until all certificates are exported up to the root authority certificate.

To export multiple parent certificates

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the local computer. For additional information about accounts and group memberships, see Local and Domain Default Groups
  2. Open the Active Directory Federation Services (AD FS) 2.0 Management console.
  3. In the navigation pane, expand Service, and then click the Certificates folder.
  4. Under Token signing, click the primary token certificate as indicated in the Primary column.
  5. In the right pane, click View Certificate link. This displays the properties of the certificate.
  6. Click the Certification tab. This displays any other certificate(s) in the chain.
  7. Click the Details tab.
  8. Click Copy to File. This starts the Certificate Export Wizard.
  9. On the Welcome to the Certificate Export Wizard page, click Next.
  10. On the Export Private Key page, click No, do not export the private key, and then click Next.
  11. On the Export File Format page, select DER encoded binary X.509 (.CER), and then click Next.
  12. On the File to Export page, type the name and location of the file that you want to export, and then click Next. For example, enter C:\adfsParent.cer.
  13. On the Completing the Certificate Export Wizard page, click Finish.

Use this section to import the token signing certificates to the trusted root authority list that resides on the SharePoint Server. This step must be repeated for every token signing certificate in the chain until the root certification authority is reached.

To import a token signing certificate by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • In the SharePoint 2013 environment, on the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • In the SharePoint 2013 environment, on the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. From the Windows PowerShell command prompt, import the parent certificate of the token signing certificate (that is, the root authority certificate), as shown in the following syntax:

    $root = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2(“<PathToParentCert>“)

    New-SPTrustedRootAuthority -Name “Token Signing Cert Parent” -Certificate $root

  2. From the Windows PowerShell command prompt, import the token signing certificate that was copied from the AD FS server, as shown in the following syntax:

    $cert = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2(“<PathToSigningCert>“)

    New-SPTrustedRootAuthority -Name “Token Signing Cert” -Certificate $cert

For additional information about the New-SPTrustedRootAuthority cmdlet, see New-SPTrustedRootAuthority

Use the procedure in this section to define a unique identifier for claims mapping. Typically, this information is in the form of an e-mail address and the administrator of the trusted STS will have to provide this information because only the owner of the STS knows which claim type will be always unique for each user.

To define a unique identifier for claims mapping by using Windows PowerShell

  1. Start the SharePoint 2013 Management Shell.
  1. From the Windows PowerShell command prompt, create an identity claim mapping, as shown in the following syntax:

    $emailClaimMap = New-SPClaimTypeMapping -IncomingClaimType “http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress&#8221; -IncomingClaimTypeDisplayName “EmailAddress” -SameAsIncoming

  2. From the Windows PowerShell command prompt, create the UPN claim mapping as shown in the following syntax:

    $upnClaimMap = New-SPClaimTypeMapping -IncomingClaimType “http://schemas.xmlsoap.org/ws/2005/05/identity/claims/upn&#8221; -IncomingClaimTypeDisplayName “UPN” -SameAsIncoming

For additional information about the New-SPClaimTypeMapping cmdlet, see New-SPClaimTypeMapping

Use the procedure in this section to create a new SPTrustedIdentityTokenIssuer.

To create a new authentication provider by using Windows PowerShell

  1. Start the SharePoint 2013 Management Shell.
  1. From the Windows PowerShell command prompt, create a new authentication provider, as shown in the following syntax.

    Note:

The $realm variable defines the trusted STS that identifies a specific SharePoint farm and the $cert variable is the one that was used from the Import a token signing certificate by using Windows PowerShell section. The SignInUrl parameter is to the AD FS server.

$realm = “urn:sharepoint:<WebAppName>

$signInURL = “https://<YourADFSServerName>/adfs/ls”

$ap = New-SPTrustedIdentityTokenIssuer -Name <ProviderName> -Description <ProviderDescription> -realm $realm -ImportTrustCertificate $cert -ClaimsMappings $emailClaimMap,$upnClaimMap -SignInUrl $signInURL -IdentifierClaim $emailClaimmap.InputClaimType

For additional information about the New-SPTrustedIdentityTokenIssuer cmdlet, see New-SPTrustedIdentityTokenIssuer

  1. Associate an existing web application with the AD FS identity provider
  2. Create a new web application with the AD FS identity provider

To configure an existing web application to use SAML sign-in, the trusted identity provider in the claims authentication type section must be changed.

To configure an existing web application to use the AD FS identity provider

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. In Central Administration, on the home page, click Application Management.
  3. On the Application Management page, in the Web Applications section, click Manage web applications.
  4. Click the appropriate web application.
  5. From the ribbon, click Authentication Providers.
  6. Under Zone, click the name of the zone. For example, Default.
  7. On the Edit Authentication page in the Claims Authentication Types section, select Trusted Identity provider, and then click the name of your SAML provider (<ProviderName> from the New-SPTrustedIdentityTokenIssuer command). Click OK.
  8. Next, you must enable SSL for this web application. You can do this by adding an alternate access mapping for the https:// version of the web applications URL and then configuring the web site in the Internet Information Services (IIS) Manager console for an https binding. For more information about how to set up SSL for IIS, see How to Setup SSL on IIS 7.0.

When creating a new web application to use SAML sign-in, you must configure claims authentication for the AD FS trusted identity provider. See Create claims-based web applications in SharePoint 2013 and do the following:

  • In the Security Configuration section of the New Web Application dialog box, for Use Secure Sockets Layer (SSL), select Yes.

    For information about how to set up SSL for IIS, see How to Setup SSL on IIS 7.0.

  • In the Claims Authentication Types section of the New Web Application dialog box, select Trusted Identity provider, and then click the name of your SAML provider (<ProviderName> from the New-SPTrustedIdentityTokenIssuer command).

 

 

  1. Verify that you are a member of the Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • Securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. In the SharePoint 2013 environment on the farm that is receiving server-to-server requests, start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • In the SharePoint 2013 environment, on the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • In the SharePoint 2013 environment, on the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    New-SPTrustedSecurityTokenIssuer MetadataEndpoint “https://<HostName>/_layouts/15/metadata/json/1&#8221; IsTrustBroker Name “<FriendlyName>”

    Where:

  • <HostName> is the name and port of any SSL-enabled web application of the farm that will be sending server-to-server requests.
  • <FriendlyName> is a friendly name for the sending SharePoint 2013 farm.
  1. Repeat step 3 for all SharePoint 2013 farms that will be sending server-to-server requests.

    Note:

For more information, see New-SPTrustedSecurityTokenIssuer.

The recommended best practice for server-to-server authentication is that each server-to-server application that establishes trust with a SharePoint farm must use a different certificate. In a cross-farm SharePoint topology, if you are required to use the same certificate across the farms, you must also set the name identifier of the SharePoint Security Token Service (STS) to be the same across those farms. The following procedure describes how to synchronize the STS name identifier across two SharePoint farms.

To synchronize the STS name identifier across SharePoint farms

  1. Verify that you are a member of the Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • Securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. In the SharePoint 2013 environment on one of the farms, start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • In the SharePoint 2013 environment, on the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • In the SharePoint 2013 environment, on the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    Get-SPSecurityTokenServiceConfig

  2. In the display of the Get-SPSecurityTokenServiceConfig command, note the value of the NameIdentifier field, which starts with 00000003-0000-0ff1-ce00-000000000000@. This is the name identifier of the SharePoint STS.
  3. To set the name identifier of the SharePoint STS in the other SharePoint farm, use the following Windows PowerShell commands on a server in that farm:

    $config = Get-SPSecurityTokenServiceConfig
    $config.NameIdentifier=<CommonNameIdentifier>
    $config.Update();

    Where <CommonNameIdentifier> is the value of the NameIdentifier field from step 4.

 

 

  1. Verify that you are a member of the Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • In the SharePoint 2013 environment, on the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • In the SharePoint 2013 environment, on the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following commands:

    New-SPTrustedSecurityTokenIssuer MetadataEndpoint “https://<HostName>/metadata/json/1&#8221; IsTrustBroker Name “<FriendlyName>”

    Where:

  • <HostName> is the name or address of the Exchange Server 2013 server.
  • <FriendlyName> is a friendly name for the Exchange Server 2013 server.

To configure permissions on the SharePoint 2013 server

To configure the Exchange Server 2013 server to trust the SharePoint 2013 server

  1. Start the Exchange Management Shell.
  • For Windows Server 2008 R2:
    • In the Exchange Server 2013 environment, on the Start menu, click All Programs, click Microsoft Exchange Server 2013, and then click Exchange Management Shell.
  • For Windows Server 2012:
    • In the Exchange Server 2013 environment, on the Start screen, click Exchange Management Shell.

      If Exchange Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click Exchange Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following commands:

    cd c:\’Program Files’\Microsoft\’Exchange Server’\V15\Scripts
    .\Configure-EnterprisePartnerApplication.ps1 -AuthMetadataUrl https://<HostName>/_layouts/15/metadata/json/1 -ApplicationType SharePoint

    Where:

  • <HostName> is the name and port of any SSL-enabled web application of the SharePoint farm.

Configure server-to-server authentication in SharePoint 2013

 

 

  1. Verify that you are a member of the Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • In the SharePoint 2013 environment, on the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • In the SharePoint 2013 environment, on the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen, right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following commands:

    New-SPTrustedSecurityTokenIssuer MetadataEndpoint “https://<HostName>/metadata/json/1″ IsTrustBroker Name “<FriendlyName>

    Where:

  • <HostName> is name or address of the server that runs Lync Server 2013.
  • <FriendlyName> is a friendly name for the server that runs Lync Server 2013.

To configure the Lync Server 2013 server to trust the SharePoint 2013 server

  1. If you have not already done this, assign a server-to-server authentication certificate to Lync Server 2013. Follow the instructions in Assigning a Server-to-Server Authentication Certificate to Microsoft Lync Server 2013.
  2. Configure the server that runs Lync Server 2013 for a new SharePoint partner application that corresponds to the SharePoint farm. For the instructions in Configuring an On-Premises Partner Application for Microsoft Lync Server 2013, change the metadata URL string in the embedded script from:

 

 

  1. Configure the SharePoint Server 2013 app authentication trust.
  2. Register the app with the Application Management service.
  3. Configure app permissions.

For information about apps for SharePoint, see Overview of apps for SharePoint 2013.

    Note:

Because SharePoint Server 2013 runs as websites in Internet Information Services (IIS), administrators and users depend on the accessibility features that browsers provide. SharePoint Server 2013 supports the accessibility features of supported browsers. For more information, see the following resources:

  • Step 1. Configure the SharePoint Server 2013 app authentication trust

    There are two ways to configure an app authentication trust with SharePoint Server 2013:

    • If you have an Office 365 subscription and the app is also using Windows Azure Access Control Service (ACS) for authentication, you configure the SharePoint farm to trust the ACS instance that corresponds to your Office 365 subscription. ACS then acts as a common authentication broker between the on-premises SharePoint farm and the app and as the online security token service (STS). ACS generates the context tokens when the app requests access to a SharePoint resource.

      In this case, configure SharePoint Server 2013 to trust ACS.

    • If you do not have an Office 365 subscription or if the app does not use ACS for authentication, you must configure a server-to-server trust relationship between the SharePoint farm and the app, known as a high-trust app. A high-trust app generates its own context tokens when it requests access to a SharePoint resource. This must be done for each high-trust app that a SharePoint farm must trust. For example, if multiple apps are running on one server and if they all use different token signing certificates, you must create a separate trust with each one.

      In this case, configure SharePoint Server 2013 to trust the app.

      • Configure SharePoint Server 2013 to trust ACS

    Use the following procedure to configure SharePoint Server 2013 to trust ACS.

    To configure a SharePoint Server 2013 trust relationship with ACS

  1. Verify that you are a member of the Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint Server 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • In the SharePoint 2013 environment, on the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • In the SharePoint 2013 environment, on the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    $New-SPTrustedSecurityTokenIssuer MetadataEndpoint “<Metadata endpoint URL of ACS>IsTrustBroker Name “ACS”

    Where:

  1. Keep the Windows PowerShell command prompt open for the Step 2. Register the app with the Application Management service.
  • Configure SharePoint Server 2013 to trust the app

Use the following procedure to configure SharePoint Server 2013 to trust the app.

To configure a SharePoint Server 2013 trust relationship with a high-trust app

  1. Verify that you are a member of the Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint Server 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. In Central Administration on the SharePoint Server 2013 server in the farm, on the Quick Launch, click System Settings, and then click Manage services on server.
  2. In the list of services on the server, make sure that that User Profile Service is started.
  3. In Central Administration, on the Quick Launch, click Application Management, and then click Manage service applications.
  4. In the list of service applications, make sure that that the App Management Service and User Profile Service Application are started.
  5. Obtain a .CER version of the signing certificate of the high-trust app and store it in a location that can be accessed during the rest of this procedure.
  6. Verify that you are a member of the Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint Server 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Click Start menu, click All Programs, click SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  2. At the Windows PowerShell command prompt, type the following commands:

    $appId = “<AppID>

    $spweb = Get-SPWeb “<AppURL>

    $realm = Get-SPAuthenticationRealm -ServiceContext $spweb.Site

    $certificate = New-Object System.Security.Cryptography.X509Certificates.X509Certificate2(“<CERFilePath>“)

    $fullAppIdentifier = $appId + ‘@’ + $realm

    New-SPTrustedSecurityTokenIssuer -Name “<FriendlyName>” -Certificate $certificate -RegisteredIssuerName $fullAppIdentifier

    Where:

  • <AppID> is the client ID assigned to the high-trust app when it was created.

        Important:

All of the letters in the AppID must be in lowercase.

  • <AppURL> is the URL to the high-trust apps location on the app server.
  • <CERFilePath> is the path of the .CER version of the signing certificate of the high-trust app.
  • <FriendlyName> is a friendly name that identifies the app.
  1. Keep the Windows PowerShell command prompt open for the next procedure.
  1. At the Windows PowerShell command prompt, type the following command:

    $appPrincipal = Register-SPAppPrincipal -NameIdentifier $fullAppIdentifier -Site $spweb -DisplayName “<DisplayName>

    Where:

  • <DisplayName> is the name of the app as displayed in Central Administration.
  1. Keep the Windows PowerShell command prompt open for the next procedure.
  1. Configure AD FS to support claims-based authentication.

    For more information, see AD FS 2.0 – How to change the local authentication type (http://go.microsoft.com/fwlink/p/?LinkId=212513).

  2. Configure SharePoint 2013 to support SAML-based claims authentication using AD FS.

    For more information, see Configure SAML-based claims authentication with AD FS in SharePoint 2013.

  3. Create a web application that uses SAML-based claims authentication.

    For more information, see Create claims-based web applications in SharePoint 2013.

    Note:

These steps will be similar for a third-party STS.

 

 

  1. Install SQL Server 2012 prerequisites on each cluster node.

    For more information, see Prerequisites, Restrictions, and Recommendations for AlwaysOn Availability Groups (SQL Server).

  2. Install SQL Server on each cluster node.

    For more information, see Installation for SQL Server 2012.

  • Enable Named Pipes

Named Pipes is required for an AlwaysOn Availability Group. Use the following procedure to enable Named Pipes for SQL Server.

To enable Named Pipes

  1. Make sure that the logon has the required credentials. To change a network configuration for the database engine, you must be a member of the sysadmin fixed server role.
  2. Log on to the server that will host the primary replica and start SQL Server Management Studio.
  3. Expand SQL Server Network Configuration and then click Protocols for<instance name>.
  4. In the details pane, right-click Named Pipes and then click Enable from the list of available options.
  5. In the console pane, click SQL Server Services.
  6. In the details pane, right-click SQL Server ( <instance name> ) and then click Restart, to stop and restart SQL Server.
  7. Repeat the previous steps to enable Named Pipes for SQL Server on the other cluster nodes.
  • Enable AlwaysOn

After you enable Named Pipes, you must enable AlwaysOn for each of the database servers in the cluster.

    Note:

You can enable AlwaysOn by using SQL Server Management Studio, Transact-SQL, or Windows PowerShell 3.0.

To enable AlwaysOn

  1. Make sure that your logon account has the required permissions to create an availability group. The account must have membership in the db_owner fixed database role and either CREATE AVAILABILITY GROUP server permission, CONTROL AVAILABILITY GROUP permission, ALTER ANY AVAILABILITY GROUP permission, or CONTROL SERVER permission.
  2. Log on to the server that will host the primary replica and start SQL Server Management Studio.
  3. In Object Explorer, select SQL Server Services, right-click SQL Server (<instance name>), where <instance name> is the name of a local server instance for which you want to enable AlwaysOn Availability Groups, and then click Properties.
  4. Select the AlwaysOn High Availability tab.
  5. Select the Enable AlwaysOn Availability Groups check box, and then click OK.
  6. Although the change is saved you must manually restart the SQL Server service (MSSQLSERVER) to commit the change. The manual restart enables you to choose a restart time that is best for your business requirements.
  7. Repeat the previous steps to enable AlwaysOn for SQL Server on the other cluster nodes.

For more information, see Enable and Disable AlwaysOn Availability Groups (SQL Server).

  • Create and configure the availability group

Depending on the SQL Server 2012 environment where you plan to create the Availability Group, you might have to create a temporary database to before you create the Availability Group.

The process that creates an availability group requires you to provide a name for the availability group and then select an eligible user database on the connected server instance as an availability database.

    Note:

To be eligible to be added to an availability group, a database must be a user database. System databases cannot belong to an availability group. For more information, see the “Availability Database Prerequisites and Restrictions” section of Prerequisites, Restrictions, and Recommendations for AlwaysOn Availability Groups (SQL Server) and see Creation and Configuration of Availability Groups (SQL Server).

If there no user databases are on the instance of the connected server, which is the case in our example, you need to create one.

Use the following procedure to create a temporary user database that will be a temporary primary replica for the group.

To create a temporary user database

  1. Make sure that your logon account has the correct permissions for this task. You require one of the following permissions in the master database to create the new database:
  • CREATE DATABASE
  • CREATE ANY DATABASE
  • ALTER ANY DATABASE
  1. Log on to the server that will host the primary replica, which is SP-SRV1 in our example.
  2. Start Management Studio.
  3. In Object Explorer, right-click Databases and then click New Database.
  4. In the New Database dialog box, type the Database name:, which is “TemporaryUserDB” for this example.

    Because this is a temporary database that you delete after you create the availability group, you can use the default settings. Click OK.

    Because the New Availability Group Wizard will not create an availability group unless the user database was backed up, you have to back up the temporary database.

  5. In Object Explorer expand Databases and right-click the temporary database that you just created. Pick Tasks and then choose Back Up.
  6. In the Back Up Database dialog box, click OK to accept all the default settings and create the back up.
  • About replicas and data synchronization

About replicas

Every availability replica is assigned an initial roleeither the primary role or the secondary role, which the availability databases of that replica inherit. The role of a given replica determines whether it hosts read-write databases or read-only databases, the type of failover and whether it uses synchronous commit or asynchronous commit.

The following table shows the information that you have to provide for each replica, either when you first create the availability group, or when you add secondary replicas.

  • Replica configuration requirements

 

Replica information

Description

Server Instance

Displays the name of the instance of the server that will host the availability replica.

Initial Role

Indicates the role that the new replica will first perform: Primary or Secondary.

Automatic Failover (Up to 2)

Indicates the type of failover that the replica uses: automatic or manual.

Synchronous Commit (Up to 3)

Indicates the type of commit that is used for the replica.

Readable Secondary

Indicates whether a secondary replica can be read.

The configuration options are unavailable for read access, read-only, and read-only intent. For more information, see Readable Secondary Replicas (AlwaysOn Availability Groups).

    Important:

Readable secondary replicas are currently not supported for SharePoint 2013 runtime usage.

 

    Note:

When you add replicas to a group, you will also provide the endpoint for each replica and configure backup preferences. For more information, see Specify the Endpoint URL When Adding or Modifying an Availability Replica (SQL Server) and Backup on Secondary Replicas (AlwaysOn Availability Groups).

Data synchronization

As part of the availability group creation process, you have to make an exact copy of the data on the primary replica and install the copy on the secondary replica. This is the initial data synchronization for the Availability Group. For more information, see Select Initial Data Synchronization Page (AlwaysOn Availability Group Wizards).

A network share must exist and must be accessed by all the nodes in the AlwaysOn configuration to do the initial data synchronization between all the cluster nodes that host a replica. For more information, see Network Shares Extension and File Services.

The following restrictions exist when you use the New Availability Group wizard to start data synchronization:

  • If the file paths on the secondary replica location differ from the file paths on the primary location, you have to start data synchronization manually.
  • If any secondary database exists on a secondary replica, you have to manually delete the secondary databases before you start data synchronization in the New Availability Group. However, if you want to use existing secondary databases, exit the New Availability Group wizard and start data synchronization manually.
  • To use the availability group wizard to synchronize data, you have to have a backup share that all the replicas can write to. You can specify the share by browsing to it or by entering its fully qualified universal naming convention (UNC) path name, \\Systemname\ShareName\Path\, in the Specify a shared network location accessible by all replicas box.

For each database in the availability group, the Start Data Synchronization page shows the progress of the following operations:

  • Creating a full database backup of the primary database on the network share.
  • Creating a full database backup of the primary database on the network share.
  • Restoring these backups to the secondary replica location.

    These restore operations both use RESTORE WITH NORECOVERY option and leave the new secondary database in the RESTORING state.

  • Joining the secondary database to the availability group.

    This step puts the secondary database in the ONLINE state and starts data synchronization for this database.

Login replication

SharePoint logins that are created by using the same approach as in previous releases of SQL Server are not replicated in an availability group. This occurs because login information is stored in the MasterDB database, which is not replicated. Although the farm accounts are created when replicas are synchronized, login information is not available after a failover.

If you have already created an availability group and synchronized the primary and secondary replicas, the workaround is to manually copy the logins from the primary replica to the secondary replicas.

SQL Server 2012 introduces the concept of Users with Passwords for Contained Databases. The database itself stores all the database metadata and user information, and a user who is defined in this database does not have to have a corresponding login. The information in this database is replicated by the availability group and is available after a failover. For more information, see Contained Databases.

    Important:

If you create a new SharePoint login to use for an existing availability group, make sure to add the login to the contained database so it is replicated to each server that is hosting a SQL Server instance for the availability group. For example, if you create another application pool for a Web App and give it a new identity (an application pool account that you have not used), then you need to add that account as a login.

  • Create and configure the availability group

Use the following procedure to create an availability group on the primary replica, which is SP-SRV1 in our example.

  • Create the availability group

  1. Make sure that your logon account has the required permissions to create an availability group. This requires membership in the db_owner fixed database role and either CREATE AVAILABILITY GROUP server permission, CONTROL AVAILABILITY GROUP permission, ALTER ANY AVAILABILITY GROUP permission, or CONTROL SERVER permission.
  2. Log on to the server that will host the primary replica and start SQL Server Management Studio.
  3. To start the New Availability Group Wizard, right-click AlwaysOn High Availability and then click New Availability Group Wizard.
  4. Click Next to advance to the Specify Name page. Enter SP-AG1 as the name of the new availability group in the Availability group name: box.

    This name must be: a valid SQL Server identifier, unique on the Windows Server Failover Clustering cluster and unique on the domain.

  5. On the Select Databases page, all user databases that are eligible to become the primary database for the new availability group are listed on the User databases on this instance of SQL Server grid. Select TemporaryUserDB, and then click Next.
  6. On the Specify Replicas page, use the following tabs to configure the replicas for SP-AG1: Replicas, Endpoints, and Backup Preferences.
  7. On the Listener tab, configure an availability group listener for our example.

    An availability group listener is a server name to which clients can connect r to access a database in a primary or secondary replica of an availability group. Availability group listeners direct incoming connections to the primary replica or to a read-only secondary replica. The listener provides fast application failover after an availability group fails over. For more information, see Availability Group Listeners, Client Connectivity, and Application Failover (SQL Server).

    Important:

Intermittent, unusually high latency might occur when you use availability groups that have replicas that are deployed on multiple subnets.

As a best practice, connections to SharePoint availability groups in a multi-subnet environment should configure specifyMultiSubnetFailover=True to avoid issues caused by high network latency. For more information, see Supporting Availability Group Multi-Subnet Failovers.

You cannot directly specify MultiSubnetFailover=True because a SharePoint client cannot directly modify a connection string. You must use Windows PowerShell to set this value on the MultiSubnetFailover database property. The following example shows how to do this.

C# 

$dbs = Get-SPDatabase | ?{$_.MultiSubnetFailover ne $true}
foreach ($db in $dbs)
{
$db.MultiSubnetFailover = $true
$db.Update()
}

  1. Select the desired configuration for each instance in the Selected instances grid, and then click Next.
  2. Click Finish to create the availability group.
  3. The Select Initial Data Synchronization page lets you select a synchronization preference and specify the shared network location that all replicas can access. For our environment accept the default, Full, which performs full database and log backups. Click Next.
  4. The Validation page of the wizard displays the results of six checks before it lets you continue with availability group creation. If all checks pass, click Next to continue. If any tests fail, you cannot continue until you correct the error and then click Re-run Validation to run the validation tests again. When all the tests pass, click Next to continue.
  5. On the Summary page, verify the configuration of the replica that you are adding and then click Finish to save it. To change the configuration, click Previous to return to previous wizard pages.
  • Install and configure SharePoint 2013

At this point in the process, you can install SharePoint 2013 and create the farm. Use the following procedure as a guide to install and configure SharePoint 2013.

    Note:

For detailed installation and configuration instructions, see Prepare for installation of SharePoint 2013 and Install SharePoint 2013.

To install SharePoint 2013

  1. Copy the SharePoint 2013 program files to a local disk on the computer where you plan to install SharePoint products or to a network file share.
  2. Run the Microsoft SharePoint Products Preparation Tool to install all the prerequisites to set up and use SharePoint 2013.
  3. Run Setup to install binaries, configure security permissions, and edit registry settings for SharePoint 2013.
  4. Run the SharePoint Products Configuration Wizard to install and configure the configuration database, install and configure the content database, and install the SharePoint Central Administration website.

    Note:

When you run the configuration wizard, you have to identify the server that will host the SharePoint databases. On the Specify Configuration Database Settings page, in the Database server box, type SP-SRV1 as the name of the computer that is running SQL Server.

To finalize setup of AlwaysOn for a SharePoint 2013 farm, add the SharePoint databases to the availability group and synchronize secondary replicas to the primary replica.

    Important:

Only add the databases that are supported for use with a SQL Server AlwaysOn Availability Group.

On the server that hosts the primary replica, you have to run the Add Databases to Availability Group wizard to add all the SharePoint databases to the availability group. The following procedure is the same as the procedure that we described to create the availability group.

To add SharePoint databases to the availability group

  1. Log on to the server that will host the primary replica and start SQL Server Management Studio.

    The account that that you use must be a member of the Local Administrators group for each server where you install SharePoint 2013

    In addition, the account must have at least one of the following permissions:

  • ALTER AVAILABILITY GROUP permission on the availability group
  • CONTROL AVAILABILITY GROUP permission
  • ALTER ANY AVAILABILITY GROUP permission
  • CONTROL SERVER permission

    To join a database to availability group requires membership in the db_owner fixed database role.

  1. In Object Explorer, browse to, and if it is necessary expand the Availability Groups.
  2. Right-click the example group, SP-AG1, and then click Add Database.
  3. On the Select Databases page, all user databases that are eligible to become the primary database for the new availability group are listed on the User databases on this instance of SQL Server grid. Use the checkboxes to select all the databases that you want to add to the group, and then click Next.
  4. The Select Initial Data Synchronization page lets you select a synchronization preference and specify the shared network location that all replicas can access. For our environment we’ll accept the default, Full, which performs full database and log backups. Click Next.
  5. The Validation page of the wizard displays the results of six checks before it lets you continue with availability group creation. If any tests fail, you cannot continue until you correct the error and then click Re-run Validation to run the validation tests again. When all the tests pass, click Next to continue.
  6. On the Summary page, verify the configuration of the replica that you are adding, and then click Finish to keep it. To change the configuration, click Previous to return to previous wizard pages.

    Important:

Databases that you add to a SharePoint farm are not automatically added to the availability group. You must add them by using the steps described in this article or by using scripts to automate the procedure.

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the front-end web server.
  2. Click Start, point to Administrative Tools, and then click Server Manager.
  3. In Server Manager, click Features.
  4. In Features Summary, click Add Features to open the Add Features Wizard.
  5. On the Select Features page, select SMTP Server.
  6. In the Add Features Wizard dialog box, click Add Required Roll Services, and then click Next.
  7. On the Confirm Installation Selections page, click Install.
  8. On the Installation Results page, ensure that the installation finished successfully, and then click Close.
  • Install IIS 6.0 Management tools

To manage the SMTP service on Windows Server 2008 and Windows Server 2008 R2, you must use Internet Information Services (IIS) 6.0 Manager.

To install IIS 6.0 Manager

  1. Verify that you have the following administrative credentials:
  • You must be a member of the Administrators group on the front-end web server.
  1. Click Start, point to Administrative Tools, and then click Server Manager.
  2. In Server Manager, click Roles.
  3. In Application Server section, click Add Role Services.
  4. On the Select Role Services page, select Management Tools and IIS 6 Management compatibility, and then click Install.
  • Configure the SMTP service

After you install the SMTP service, you configure it to accept email from the mail server for the domain. You can decide to accept relayed email from all servers except those that you specifically exclude. Alternatively, you can block email from all servers except those that you specifically include. You can include servers individually, in groups by subnet, or in groups by domain.

After you configure the service, set it to start automatically.

To configure the SMTP service

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the front-end web server.
  2. Click Start, point to Administrative Tools, and then click Internet Information Services (IIS) 6.0 Manager.
  3. In IIS Manager, expand the server name that contains the SMTP server that you want to configure.
  4. Right-click the SMTP virtual server that you want to configure, and then click Start.
  5. Right-click the SMTP virtual server that you want to configure, and then click Properties.
  6. On the Access tab, in the Access control area, click Authentication.
  7. In the Authentication dialog box, verify that Anonymous access is selected.
  8. Click OK.
  9. On the Access tab, in the Relay restrictions area, click Relay.
  10. To enable relaying from any server, click All except the list below.
  11. To accept relaying from one or more specific servers, follow these steps:
    1. Click Only the list below.
    2. Click Add, and then add servers one at a time by IP address, or in groups by using a subnet or domain.
    3. Click OK to close the Computer dialog box.
  12. Click OK to close the Relay Restrictions dialog box.
  13. Click OK to close the Properties dialog box.

To set the SMTP service to start automatically

  1. Click Start, point to Administrative Tools, and then click Services.
  2. In Services, right-click Simple Mail Transfer Protocol (SMTP), and then select Properties.
  3. In the Simple Mail Transfer Protocol (SMTP) Properties dialog box, on the General tab, in the Startup type list, select Automatic.
  4. Click OK.
  • Configure incoming email in a basic scenario

    You can use the following procedure to configure incoming email in a basic scenario by selecting the Automatic settings mode and using the default settings. After you complete the procedure, users can send email to lists and libraries.

    To configure incoming email in a basic scenario

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the server that is running the SharePoint Central Administration website.
  2. In Central Administration, click System Settings.
  3. On the System Settings page, in the E-Mail and Text Messages (SMS) section, click Configure incoming e-mail settings.
  4. If you want to enable sites on this server to receive email, on the Configure Incoming E-Mail Settings page, in the Enable Incoming E-Mail section, click Yes.
  5. Select the Automatic settings mode.
  6. In the Incoming E-Mail Server Display Address section, in the E-mail server display address box, type a display name for the email server, for example, mail.fabrikam.com.
  7. Use the default settings for all other sections, and then click OK.

After you configure incoming email, users who have Manage Lists permissions can configure emailenabled lists and document libraries.

  • Configure incoming email in an advanced scenario

    You can use the following procedure to configure incoming email in an advanced scenario by selecting the Advanced settings mode and additional options that you want to use for your incoming email environment. After you complete the procedure, users can send email to lists and libraries.

    You can also use the Automatic settings mode in an advanced scenario. In the Automatic settings mode, you can select to receive email that has been routed through a safe-email server application. In the Advanced settings mode, you can instead specify a drop folder. For more information, see Plan incoming email (SharePoint 2013 Preview).

    Several of these steps mention prerequisite procedures that are documented in Prepare your environment for incoming email in an advanced scenario later in this article.

    To configure incoming email in an advanced scenario

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the server that is running the SharePoint Central Administration website.
  2. In Central Administration, click System Settings.
  3. On the System Settings page, in the E-Mail and Text Messages (SMS) section, click Configure incoming e-mail settings.
  4. If you want to enable sites on this server to receive email, on the Configure Incoming E-mail Settings page, in the Enable Incoming E-Mail section, click Yes.
  5. Select the Advanced settings mode.

    You can specify a drop folder instead of using an SMTP server.

    Note:

You can also select the Automatic settings mode and select whether to use Directory Management Service and whether to accept email from all email servers or from several specified email servers. For more information, see Plan incoming email (SharePoint 2013 Preview).

  1. If you want to connect to Directory Management Service, in the Directory Management Service section, click Yes.

    If you select this option, you must first configure Active Directory Domain Services (AD DS). If you use Exchange Server, you must also configure the DNS Manager and add an SMTP connector. For more information, see Configure AD DS to be used with Directory Management Service, Configure DNS Manager, and Add an SMTP connector in Microsoft Exchange Server 2010 later in this article.

    1. In the Active Directory container where new distribution groups and contacts will be created box, type the name of the container in the format OU=ContainerName, DC=domain, DC=com, where ContainerName is the name of the OU in AD DS, domain is the second-level domain, and com is the top-level domain.

    The application pool identity account for Central Administration must be delegated the Create, delete, and manage user accounts task for the container. Access is configured in the properties for the OU in AD DS.

    1. In the SMTP mail server for incoming mail box, type the name of the SMTP mail server. The server name must match the FQDN in the A resource record entry for the mail server in DNS Manager.
    2. To accept messages only from authenticated users, click Yes for Accept messages from authenticated users only. Otherwise, click No.
    3. To enable users to create distribution groups from SharePoint sites, click Yes for Allow creation of distribution groups from SharePoint sites. Otherwise, click No.
    4. Under Distribution group request approval settings, select the actions that will require approval. Actions include the following:
  • Create new distribution group
  • Change distribution group e-mail address
  • Change distribution group title and description
  • Delete distribution group
  1. If you want to use a remote Directory Management Service, select Use remote and complete the remainder of this step. Otherwise, click No and proceed to step 8.

    If you select this option and you are using Exchange Server, you must configure the DNS Manager and add an SMTP connector. For more information, see Configure DNS Manager and Add an SMTP connector in Microsoft Exchange Server 2010 later in this article. The AD DS has most likely already been configured, so you do not need to do this.

    1. In the Directory Management Service URL box, type the URL of the Directory Management Service that you want to use. The URL is typically in the following format: http://server:adminport/_vti_bin/SharePointEmailWS.asmx.
    2. In the SMTP mail server for incoming mail box, type the name of the SMTP mail server. The server name must match the FQDN in the A resource record entry for the mail server in DNS Manager on the domain server.
    3. To accept messages from authenticated users only, click Yes for Accept messages from authenticated users only. Otherwise, click No.
    4. To allow creation of distribution groups from SharePoint sites, click Yes for Allow creation of distribution groups from SharePoint sites. Otherwise, click No.
  2. In the Incoming E-Mail Server Display Address section, in the E-mail server display address box, type a display name for the email server (for example, mail.fabrikam.com). You typically use this option together with the Directory Management Service.

    Tip:

You can specify the email server address that is displayed when users create an incoming email address for a list or group. Use this setting together with Directory Management Service to provide an email server address that is easy to remember.

  1. In the E-Mail Drop Folder section, in the E-mail drop folder box, type the name of the folder from which the Windows SharePoint Services Timer service retrieves incoming email from the SMTP service. This option is available only if you selected Advanced settings mode. If you select this option, ensure that you configure the necessary permissions to the email drop folder. For more information, see Configure permissions to the email drop folder later in this article.

    It is useful to have a dedicated email drop folder if the default email drop folder is full or almost full.

    Ensure that the logon account for the SharePoint Timer service has Modify permissions on the email drop folder. For more information, see To configure email drop folder permissions for the logon account for the SharePoint Timer service later in this article.

  2. In the Safe E-Mail Servers section, select whether you want to accept email from all email servers or from specific email servers.

    This option is available only if you selected Automatic settings mode.

  3. Click OK.

After you configure incoming email, site administrators can configure emailenabled lists and document libraries.

If you selected Directory Management Service, contact addresses that are created for document libraries appear automatically in Active Directory Users and Computers. The addresses are displayed in the OU of AD DS for SharePoint 2013 and must be managed by the administrator of AD DS. The AD DS administrator can add more email addresses for each contact. For more information about AD DS, see Using Active Directory Service in the TechNet Library.

Alternatively, you can configure the computer running Exchange Server by adding a new Exchange Server Global recipient policy. The policy automatically adds external addresses that use the second-level domain name and not the subdomain or host name for SharePoint 2013. For more information about how to manage Exchange Server, see Recipient Configuration Node in the Exchange Server Technical Library.

  1. Verify that the user account that is performing this procedure is a member of the Domain Administrators group or a delegated authority for domain administration on the domain controller that is running DNS Manager.
  2. Click Start, point to Administrative Tools, and then click Active Directory Users and Computers.
  3. In Active Directory Users and Computers, right-click the folder for the second-level domain that contains your server farm, point to New, and then click Organizational Unit.
  4. Type the name of the OU, and then click OK.

    After you create the OU, you must delegate the Create, delete, and manage user accounts right to the container of the OU to manage the user accounts.

To delegate the right to the application pool identity account for Central Administration

  1. Verify that the user account that is performing this procedure is a member of the Domain Administrators group or the Enterprise Administrators group in AD DS, or a delegated authority for domain administration.
  2. In Active Directory Users and Computers, find the OU that you created.
  3. Right-click the OU, and then click Delegate control.
  4. On the Welcome page of the Delegation of Control Wizard, click Next.
  5. On the Users and Groups page, click Add, and then type the name of the application pool identity account that the Central Administration uses.
  6. In the Select Users, Computers, and Groups dialog box, click OK.
  7. On the Users or Groups page of the Delegation of Control Wizard, click Next.
  8. On the Tasks to Delegate page of the Delegation of Control Wizard, select the Create, delete, and manage user accounts check box, and then click Next.
  9. On the last page of the Delegation of Control Wizard, click Finish to exit the wizard.

To create and delete child objects, you must also delegate Create all Child Objects and Delete all Child Objects control of the OU to the application pool identity account for Central Administration. After you complete this procedure, the application pool identity account for Central Administration has Create all Child Objects and Delete all Child Objects control on the OU, and you can enable incoming email.

To delegate Create all Child Objects and Delete all Child Objects control of the OU to the application pool identity account for Central Administration

  1. Verify that the user account that is performing this procedure is a member of the Domain Administrators group or the Enterprise Administrators group in AD DS, or a delegated authority for domain administration.
  2. Right-click the OU, and then click Delegate control.
  3. In the Delegation of Control Wizard, click Next.
  4. Click Add, and then type the name of the application pool identity account for Central Administration.
  5. Click OK.
  6. Click Next.
  7. On the Tasks to Delegate page of the Delegation of Control Wizard, select Create a custom task to delegate, and then click Next.
  8. Click This folder, existing objects in this folder, and creation of new objects in this folder, and then click Next.
  9. In the Permissions section, select Create all Child Objects and Delete all Child Objects.
  10. Click Next.
  11. On the last page of the Delegation of Control Wizard, click Finish to exit the wizard.

Delegating Create all Child Objects and Delete all Child Objects control of the OU to the application pool identity account for Central Administration enables administrators to enable email for a list. After these controls have been delegated, administrators cannot disable email for the list or document library because the Central Administration account tries to delete the contact from the whole OU instead of from the list.

To avoid this problem, you must add Delete Subtree permissions for the application pool identity account for Central Administration. Use the following procedure to add these permissions. After this procedure is complete, you can disable incoming email for a list.

To add Delete Subtree permissions for the application pool identity account for Central Administration

  1. Verify that the user account that is performing this procedure is a member of the Domain Administrators group or the Enterprise Administrators group in AD DS, or a delegated authority for domain administration.
  2. In Active Directory Users and Computers, click the View menu, and then click Advanced Features.
  3. Right-click the OU, and then click Properties.
  4. In the Properties dialog box, click the Security tab, and then click Advanced.
  5. In the Permission Entries area, double-click the application pool identity account for Central Administration.

    If the application pool identity account is listed more than once, select the first one.

  6. In the Permissions area, select Allow, for Delete Subtree.
  7. Click OK to close the Permissions dialog box.
  8. Click OK to close the Properties dialog box.
  9. Click OK to close Active Directory Users and Computers.

After you add these permissions, you must restart Internet Information Services (IIS) for the farm.

For more information, see Active Directory Users, Computers, and Groups in the TechNet Library.

If you are using Exchange Server and are routing email internally in your organization, you must create a host (A) resource record in DNS Manager to associate DNS domain names of computers (or hosts) to their IP addresses. Your organization might already have a configured DNS Manager and an A resource record. If not, then use the following procedure.

To create an A resource record for a subdomain

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the local computer.
  2. In DNS Manager, select the forward lookup zone for the domain that contains the subdomain for SharePoint 2013.
  3. Right-click the zone, and then click New Host (A or AAAA).
  4. In the New Host dialog box, in the Name text box, type the host or subdomain name for SharePoint 2013.
  5. In the Fully qualified domain name (FQDN) text box, type the FQDN for the server that is running SharePoint 2013. This is typically in the format subdomain.domain.com.
  6. Ensure that the domains that are listed under the SMTP server in IIS match the FQDN of the server that receives email. If they do not match, you must create a local domain. For instructions, see To create a local domain later in this article.
  7. In the IP address text box, type the IP address to which you want the FQDN to resolve.
  8. Click Add Host.
  9. In the message that confirms the creation of the host record, click OK.
  10. In the New Host dialog box, click Done.

    The A resource record now appears in DNS Manager.

If you use the E-mail server display address option and if the email address to which you are sending email messages is not the same as your server name, you must create a local domain.

To create a local domain

  1. Click Start, point to Administrative Tools, and then click Internet Information Services (IIS) 6.0 Manager.
  2. In IIS Manager, expand the SMTP server.
  3. Right-click Domains, and on the Action menu, point to New, and then click Domain.
  4. In the New SMTP Domain Wizard dialog box, select Alias, and then click Next.
  5. In the Domain Name area, in the Name box, type the address of the mail that is to be received by this domain.

    This address must be the same as the one that you specified in step 4 in To create an A resource record for a subdomain, and in step 6b in To configure incoming email in an advanced scenario.

  6. Click Finish.
  7. In the message that confirms the creation of the host record, click OK.
  8. Restart the SMTP server so that all email messages that are still in the Queue folder move to the Drop folder. The messages are then sent by the Windows SharePoint Services Timer service to their destination list or library.

    Note:

If you are routing email from outside your organization to an SMTP server, you must use an MX record. For more information, see Add a mail exchanger (MX) resource record to a zone in the Windows Server Technical Library.

An SMTP connector gives you more control over the message flow in your organization. Other reasons to use an SMTP connector are to set delivery restrictions or to specify a specific address space. If you use Exchange Server to route incoming email to SharePoint lists and libraries, you must have an SMTP connector so that all mail that is sent to the SharePoint domain uses the servers that are running the SMTP service.

Use the following procedure to add an SMTP connector in Exchange Server. After you complete the procedure, the SMTP connector ensures that incoming email messages are sent to the correct list and library in the farm.

To add an SMTP connector in Exchange Server

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the server that is running Exchange Server.
  2. In Exchange Management Console, expand the Organization Configuration group, right-click Hub Transport, point to New Send Connector.

    The New Send Connector wizard appears.

  3. On the Introduction page, do the following and then click Next:
    1. In the Name box, type a name for the SMTP connector.
    2. In the Select the intended use for this Send connector box, select the Custom usage type for the connector.
  4. On the Address Space page, click Add, and then click SMTP Address Space.
  5. In the SMTP Address Space dialog box, do the following:
    1. In the Address box, type an email domain for the connector.
    2. In the Cost box, assign an appropriate cost. By default, the cost is 1.
  6. Click OK to return to the Address Space page, and then click Next.
  7. On the Network settings page, select Use domain name system (DNS) “MX” records to route mail automatically, and then click Next.
  8. On the Source Server page, click Next.

    The Source server page only appears on Hub Transport servers. By default, the Hub Transport server that you are currently working on is listed as a source server.

  9. On the New Connector page, review your options and then click New to create the new send connector.
  10. On the Completion page, ensure that the send connector was created, and then click Finish.

    In the Hub Transport pane, you can see that the send connector has been enabled automatically.

For more information, see Create an SMTP Send Connector in the Exchange Server Technical Library.

You can specify a particular email drop folder, which enables SharePoint 2013 to retrieve incoming email from a network share on another server. You can use this option if you do not want to use an SMTP service. However, the drawback of using this option is that SharePoint 2013 cannot detect configuration changes on the remote email server that is delivering email to the drop folder. The result is that SharePoint 2013 cannot retrieve email if the location of the email messages has changed. However, this feature is useful if the default email drop folder is full or almost full.

If you specified an email drop folder, you must ensure that the application pool identity accounts for Central Administration and for the web application have the required permissions to the email drop folder.

  • Configure email drop folder permissions for the application pool identity account for a web application

If your deployment uses different application pool identity accounts for Central Administration and for one or more web applications, each application pool identity account must have permissions to the email drop folder. If the application pool identity account for the web application does not have the required permissions, email will not be delivered to document libraries on that web application.

In most cases, when you configure incoming email and select an email drop folder, permissions are added for the following worker process groups:

  • WSS_Admin_WPG, which includes the application pool identity account for Central Administration and the logon account for the SharePoint Timer service, and has Full Control permissions.
  • WSS_WPG, which includes the application pool accounts for web applications, and has Read & Execute, List Folder Contents, and Read permissions.

In some cases, these groups might not be configured automatically for the email drop folder. For example, if Central Administration is running as the Network Service account, the groups or accounts that are needed for incoming email will not be added when the email drop folder is created. Check to determine whether these groups have been added automatically to the email drop folder. If the groups have not been added automatically, you can add them or add the specific accounts that are required.

To configure email drop folder permissions for the application pool identity account for a web application

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the server that contains the email drop folder.
  2. In Windows Explorer, right-click the drop folder, click Properties, and then click the Security tab.
  3. On the Security tab, under the Group or user names box, click Edit.
  4. In the Permissions for Windows Explorer dialog box, click Add.
  5. In the Select Users, Computers, or Groups dialog box, in the Enter the object names to select box, type the name of the worker process group or application pool identity account for the web application, and then click OK.

    This account is listed on the Identity tab of the Properties dialog box for the application pool in IIS.

  6. In the Permissions for User or Group box, next to Modify, select Allow.
  7. Click OK.
  • Configure email drop folder permissions for the logon account for the SharePoint Timer service

Ensure that the logon account for the Windows SharePoint Services Timer service has Modify permissions on the email drop folder. If the logon account for the service does not have Modify permissions, emailenabled document libraries will receive duplicate email messages.

To configure email drop folder permissions for the logon account for the SharePoint Timer service

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the server that contains the email drop folder.
  2. In Windows Explorer, right-click the drop folder, click Properties, and then click the Security tab.
  3. On the Security tab, under the Group or user names box, click Edit.
  4. In the Permissions for Windows Explorer dialog box, click Add.
  5. In the Select Users, Computers, or Groups dialog box, in the Enter the object names to select box, type the name of the logon account for the SharePoint Timer service, and then click OK.

    This account is listed on the Log On tab of the Properties dialog box for the service in the Services snap-in.

  6. In the Permissions for User or Group box, next to Modify, select Allow.
  7. Click OK.
  1. Click Start, and then click Run.
  2. In the Run dialog box, type Adsiedit.msc, and then click OK.
  3. In the ADSI Edit window, expand ADSI Edit, expand Domain [DomainName], expand DC=DomainName, DC=com, and then expand CN=Users.
  4. Right-click the user name to which you want to add the missing attributes, and then click Properties.
  5. In the Properties dialog box, double-click Internet Encoding on the Attribute Editor tab.
  6. In the Integer Attribute Editor dialog box, type 1310720 in the Value box, and then click OK.
  7. In the Properties dialog box, double-click mAPIRecipient on the Attribute Editor tab.
  8. In the Boolean Attribute Editor dialog box, click False, and then click OK two times.

 

 

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the front-end web server.
  2. Click Start, point to Administrative Tools, and then click Server Manager.
  3. In Server Manager, click Features.
  4. In Features Summary, click Add Features to open the Add Features Wizard.
  5. On the Select Features page, select SMTP Server.
  6. In the Add Features Wizard dialog box, click Add Required Roll Services, and then click Next.
  7. On the Confirm Installation Selections page, click Install.
  8. On the Installation Results page, ensure that the installation is complete, and then click Close.

After you install the SMTP service, you configure it to send email messages from servers in the farm.

You can decide to send relayed email messages to all servers except those that you specifically exclude. Alternatively, you can block messages to all servers except those that you specifically include. You can include servers individually or in groups by subnet or domain.

If you enable anonymous access and relayed email messages, you increase the possibility that the SMTP server will be used to relay unsolicited commercial email messages (spam). It is important to limit this possibility by carefully configuring mail servers to help protect against spam. One way that you can do this is by limiting relayed email messages to a list of specific servers or to a domain, and by preventing relayed email messages from all other servers.

    Note:

To manage the SMTP service on Windows Server 2008, you must use Internet Information Services (IIS) 6.0 Manager. Ensure that you install IIS 6.0 Management tools in Server Manager.

To install IIS 6.0 Management tools

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the front-end web server.
  2. Click Start, point to Administrative Tools, and then click Server Manager.
  3. In Server Manager, click Roles.
  4. In the Application Server section, click Add Role Services.
  5. On the Select Role Services page, select Management Tools and IIS 6 Management compatibility, and then click Install.

To configure the SMTP service

  1. Verify that the user account that is performing this procedure is a member of the Administrators group on the front-end web server.
  2. Click Start, point to Administrative Tools, and then click Internet Information Services (IIS) 6.0 Manager.
  3. In IIS Manager, expand the server name that contains the SMTP server that you want to configure.
  4. Right-click the SMTP virtual server that you want to configure, and then click Start.
  5. Right-click the SMTP virtual server that you want to configure, and then click Properties.
  6. On the Access tab, in the Access control area, click Authentication.
  7. In the Authentication dialog box, verify that Anonymous access is selected.
  8. Click OK.
  9. On the Access tab, in the Relay restrictions area, click Relay.
  10. To enable relayed email messages to any server, click All except the list below.
  11. To accept relayed email messages from one or more specific servers, follow these steps:
    1. Click Only the list below.
    2. Click Add, and then add servers one at a time by IP address, or in groups by using a subnet or domain.
    3. Click OK to close the Computer dialog box.
  12. Click OK to close the Relay Restrictions dialog box.
  13. Click OK to close the Properties dialog box.

Ensure that the SMTP service is running and set to start automatically. To do this, use the following procedure.

To set the SMTP service to start automatically

  1. Click Start, point to Administrative Tools, and then click Services.
  2. In Services, right-click Simple Mail Transfer Protocol (SMTP), and then select Properties.
  3. In the Simple Mail Transfer Protocol (SMTP) Properties dialog box, on the General tab, in the Startup type list, select Automatic.
  4. Click OK.
  • Configure outgoing email for a farm

    You can configure outgoing email for a farm by using the SharePoint Central Administration website. Use the following procedures to configure outgoing email. After you complete the procedures, users can track changes and updates to individual site collections. In addition, site administrators can, for example, receive notices when users request access to a site.

    To configure outgoing email for a farm by using Central Administration

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators group on the server that is running the SharePoint Central Administration website.
  2. In Central Administration, click System Settings.
  3. On the System Settings page, in the E-Mail and Text Messages (SMS) section, click Configure outgoing e-mail settings.
  4. On the Outgoing E-Mail Settings page, in the Mail Settings section, type the SMTP server name for outgoing email (for example, mail.example.com) in the Outbound SMTP server box.
  5. In the From address box, type the email address as you want it to be displayed to email recipients.
  6. In the Reply-to address box, type the email address to which you want email recipients to reply.
  7. In the Character set list, select the character set that is appropriate for your language.
  8. Click OK.
  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators group on the server that is running the SharePoint Central Administration website.
  2. In Central Administration, in the Application Management section, click Manage web applications.
  3. On the Web Applications Management page, select a web application, and then in the General Settings group on the ribbon, click Outgoing E-mail.
  4. On the Web Application Outgoing E-Mail Settings page, in the Mail Settings section, type the name of the SMTP server for outgoing email (for example, mail.fabrikam.com) in the Outbound SMTP server box.
  5. In the From address box, type the email address (for example, the site administrator alias) as you want it to be displayed to email recipients.
  6. In the Reply-to address box, type the email address (for example, a help desk alias) to which you want email recipients to reply.
  7. In the Character set list, click the character set that is appropriate for your language.
  8. Click OK.

 

 

  1. Register a managed account in SharePoint Server 2013 to run the Secure Store application pool.
  2. Start the Secure Store Service on an application server in the farm.
  3. Create a Secure Store Service service application.

To run the application pool, you must have a standard domain account. No specific permissions are required for this account. Once the account has been created in Active Directory, follow these steps to register it with SharePoint Server 2013.

To register a managed account

  1. On the SharePoint Central Administration Web site home page, in the left navigation, click Security.
  2. On the Security page, in the General Security section, click Configure managed accounts.
  3. On the Managed Accounts page, click Register Managed Account.
  4. In the User name box, type the name of the account.
  5. In the Password box, type the password for the Contoso\ExcelAppPool account.
  6. If you want SharePoint Server 2013 to handle changing the password for the account, select the Enable automatic password change box and specify the password change parameters that you want to use.
  7. Click OK.

Once you have configured the registered account, you must start the Secure Store Service on an application server in the farm. Because Secure Store deals with sensitive information, we recommend that you use a separate application server just for the Secure Store Service for better security.

To start the Secure Store Service

  1. On the Central Administration home page, in the System Settings section, click Manage services on server.
  2. Above the Service list, click the Server drop-down list, and then click Change Server.
  3. Select the application server where you want to run the Secure Store Service.
  4. In the Service list, click Start next to Secure Store Service.

Once the service is started, you must create a Secure Store Service service application. Use the following procedure to create the service application.

To create a Secure Store Service service application

  1. On the Central Administration home page, in the Application Management section, click Manage service applications.
  2. On the Manage Service Applications page, click New, and then click Secure Store Service.
  3. In the Service Application Name box, type a name for the service application (for example, Secure Store Service).
  4. In the Database Server box, type the instance of SQL Server where you want to create the Secure Store database.

    Note:

Because the Secure Store database contains sensitive information, we recommend that you deploy the Secure Store database to a different instance of SQL Server from the rest of SharePoint Server 2013.

  1. Select the Create new application pool option and type a name for the application pool in the text box.
  2. Select the Configurable option, and, from the drop-down list, select the account for which you created the managed account earlier.
  3. Click OK.

The Secure Store Service has now been configured. The next step is to generate an encryption key for encrypting the Secure Store database.

  • Work with encryption keys

    Before using the Secure Store Service, you must generate an encryption key. The key is used to encrypt and decrypt the credentials that are stored in the Secure Store Service database.

    • Generate an encryption key

    The first time that you access the Secure Store service application, your only option is to generate a new encryption key. Once the key has been generated, the rest of the Secure Store functionality becomes available.

    To generate a new encryption key

  1. On the Central Administration home page, in the Application Management section, click Manage service applications.
  2. Click the Secure Store service application.
  3. In the Key Management group, click Generate New Key.
  4. On the Generate New Key page, type a pass phrase string in the Pass Phrase box, and type the same string in the Confirm Pass Phrase box. This pass phrase is used to encrypt the Secure Store database.

    Important:

A pass phrase string must be at least eight characters and must have at least three of the following four elements:

  • Uppercase characters
  • Lowercase characters
  • Numerals
  • Any of the following special characters

! ” # $ % & ‘ ( ) * + , – . / : ; < = > ? @ [ \ ] ^ _ ` { | } ~

    Important:

The pass phrase that you enter is not stored. Make sure that you write this down and store it in a safe place. You must have it to refresh the key, such as when you add a new application server to the server farm.

  1. Click OK.

For security precautions or as part of regular maintenance you may decide to generate a new encryption key and force the Secure Store Service to be re-encrypted based on the new key. You can use this same procedure to do this.

    Caution:

You should back up the database of the Secure Store Service application before generating a new key.

Refreshing the encryption key propagates the key to all the application servers in the farm. You may be required to refresh the encryption key if any of the following things are true:

  • You add a new application server to the server farm.
  • You restore a previously backed up Secure Store Service database and have since changed the encryption key.
  • You receive an “Unable to get master key” error message.
  • You have upgraded your farm from SharePoint Server 2010.

To refresh the encryption key

  1. On the Central Administration home page, in the Application Management section, click Manage service applications.
  2. Click the Secure Store service application.
  3. In the Key Management group, click Refresh Key.
  4. In the Pass Phrase box, type the pass phrase that you first used to generate the encryption key.

    This phrase is either the pass phrase that you used when you initialized the Secure Store Service service application or one that you used when you created a new key by using the Generate a New Key command.

  5. Click OK.
  • Store credentials in Secure Store

    Storing credentials in Secure Store is accomplished by using a Secure Store target application. A target application maps the credentials of a user, group, or claim to a set of encrypted credentials stored in the Secure Store database. After a target application is created, you can associate it with an external content type or application model, or use it with a business intelligence service application such as Excel Services or Visio Services to provide access to an external data source. When a SharePoint Server 2013 service application calls the target application, Secure Store confirms that the user making the request is an authorized user of the target application and then retrieves the encrypted credentials. The credentials are then used on the user’s behalf by the SharePoint Server 2013 service application.

    To create a target application, you must do the following:

  1. Create the target application itself, specifying the type of credentials that you want to store in the Secure Store database, the administrators for the target application, and the credential owners.
  2. Specify the credentials that you want to store.

Target applications are configured on the Secure Store Service Application page in Central Administration. Use the following procedure to create a target application.

To create a target application

  1. On the Central Administration home page, in the Application Management section, click Manage service applications.
  2. Click the Secure Store service application.
  3. In the Manage Target Applications group, click New.
  4. In the Target Application ID box, type a text string.

    This is the unique string that you will use externally to identify this target application.

  5. In the Display Name box, type a text string that will be used to display the identifier of the target application in the user interface.
  6. In the Contact Email box, type the e-mail address of the primary contact for this target application.

    This can be any legitimate e-mail address and does not have to be the identity of an administrator of the Secure Store Service application.

  7. When you create a target application of type Individual (see below), you can implement a custom Web page that lets users add individual credentials for the destination data source. This requires custom code to pass the credentials to the target application. If you did this, type the full URL of this page in the Target Application Page URL field. There are three options:
  • Use default page: Any Web sites that use the target application to access external data will have an individual sign-up page that was added automatically. The URL of this page will be http:/<samplesite>/_layouts/SecureStoreSetCredentials.aspx?TargetAppId=<TargetApplicationID>, where <TargetApplicationID> is the string typed in the Target Application ID box. By publicizing the location of this page, you can enable users to add their credentials for the external data source.
  • Use custom page: You provide a custom Web page that lets users provide individual credentials. Type the URL of the custom page in this field.
  • None: There is no sign-up page. Individual credentials are added only by a Secure Store Service administrator who is using the Secure Store Service application.
  1. In the Target Application Type drop-down list, choose the target application type: Group, for group credentials, or Individual, if each user is to be mapped to a unique set of credentials on the external data source.

    Note:

There are two primary types for creating a target application:

  • Group, for mapping all the members of one or more groups to a single set of credentials on the external data source.
  • Individual, for mapping each user to a unique set of credentials on the external data source.
  1. Click Next.
  2. Use the Specify the credential fields for your Secure Store Target Application page to configure the various fields which may be required to provide credentials to the external data source. By default, two fields are listed: Windows User Name and Windows Password.

    To add an additional field for supplying credentials to the external data source, on the Specify the credential fields for your Secure Store Target Application page, click Add Field.

    By default, the type of the new field is Generic. The following field types are available:

  • Field

Description

Generic

Values that do not fit in any of the other categories.

User Name

A user account that identifies the user.

Password

A secret word or phrase.

PIN

A personal identification number.

Key

A parameter that determines the functional output of a cryptographic algorithm or cipher.

Windows User Name

A Windows user account that identifies the user.

Windows Password

A secret word or phrase for a Windows account.

Certificate

A certificate.

Certificate Password

The password for the certificate.

  • To change the type of a new or existing field, click the arrow that appears next to the type of the field, and then select the new type of field.

        Note:

Every field that you add will be required to have data when you set the credentials for this target application.

  • You can change the name that a user sees when interacting with a field. In the Field Name column of the Specify the credential fields for your Secure Store Target Application page, change a field name by selecting the current text and typing new text.
  • When a field is masked, each character that a user types is not displayed but is replaced with a mask character such as the asterisk “*”. To mask a field, click the check box for that field in the Masked column of the page.
  • To delete a field, click the delete icon for that field in the Delete column of the page.

    When you have finished editing the credential fields, click Next.

  1. In the Specify the membership settings page, in the Target Application Administrators Field, list all users who have access to manage the target application settings.
  2. If the target application type is group, in the Members field, list the user groups to map to a set of credentials for this target application.
  3. Click OK to complete configuring the target application.
  • Set credentials for a target application

After creating a target application, an administrator of that target application can set credentials for it. These credentials are used by the calling application to provide access to an external data source. If the target application is of type Individual, you can also enable users to supply their own credentials.

To set credentials for a target application

  1. On the Central Administration home page, in the Application Management section, click Manage service applications.
  2. Click the Secure Store service application.
  3. In the target application list, point at the target application for which you want to set credentials, click the arrow that appears, and then, in the menu, click Set credentials.

    If the target application is of type Group, type the credentials for the external data source. Depending on the information that is required by the external data source, the fields for setting credentials will vary.

    If the target application is of type Individual, type the user name of the individual who will be mapped to this set of credentials on the external data source, and type the credentials for the external data source. Depending on the information that is required by the external data source, the fields for setting credentials will vary.

  4. Click OK.

Once you have set the credentials for the target application, it is ready to be used by a SharePoint Server 2013 service such as Business Connectivity Services or Excel Services.

  • Enable the audit log

    Audit entries for the Secure Store service are stored in the Secure Store Service database. By default, the audit log file is disabled.

    An audit log entry stores information about a Secure Store Service action, such as when it was performed, whether it succeeded, why it failed if it didn’t succeed, the Secure Store Service user who performed it, and optionally the Secure Store Service user on whose behalf it was performed. Therefore, a valid reason to enable an audit log file is to troubleshoot an authentication issue.

     

    To enable the audit log by using Central Administration

  1. On the Central Administration home page, in the Application Management section, click Manage service applications.
  2. Select the Secure Store service application. (That is, select the service application, but do not click the link to go to the Secure Store Service application settings page.)
  3. On the ribbon, click Properties.
  4. From the Enable Audit section, click to select the Audit log enabled box.
  5. To change the number of days that entries will be purged from the audit log file, specify a number in days in the Days Until Purge field. The default value is 30 days.
  6. Click OK.
  1. Create accounts — Certain domain user accounts are required specifically for a Search service application.
  2. Create a Search service application — A Search service application provides enterprise search features and functionality.
  3. Configure the Search service application — Basic configuration of a Search service application includes configuring a default content access account, an email contact, and content sources.
  4. Configure the Search service application topology — You can deploy search components on different servers in the farm. You can also specify which instance of SQL Server is used to host the search-related databases.
  • Step 1: Create accounts that are required for a SharePoint Search service application

    The following table lists the accounts that are required when a Search service application is created.

     

    Account

    Description

    Notes

    Search service

    Windows user credentials for the SharePoint Server Search service, which is a Windows service

    This setting applies to all Search service applications in the farm. You can change this account at any time by clicking Configure service accounts in the Security section on the Central Administration home page.

  • Search Admin Web Service application pool
    • Search Query and Site Settings Web Service application pool
  • Windows user credentials

    For each of these accounts, you can use the same credentials that you specified for the Search service. Or, you can assign different credentials to each account according to the principle of least-privilege administration.

    Default content access

    Windows user credentials for the Search service application to use to access content when crawling

    We recommend that you specify a separate account for the default content access account according to the principle of least-privilege administration.

     

    The accounts that you use for the Search service, the Search Admin Web Service application pool, and the Search Query and Site Settings Web Service application pool must be registered as managed accounts in SharePoint Server 2013 so that they are available when you create the Search service application. Use the following procedure to register each of these accounts as a managed account.

    To register a managed account

  1. On the Central Administration home page, in the Quick Launch, click Security.
  2. On the Security page, in the General Security section, click Configure managed accounts.
  3. On the Managed Accounts page, click Register Managed Account.
  4. On the Register Managed Account page, in the Account Registration section, type the user name and password that you want to use as credentials for the service account.
  5. If you want SharePoint Server 2013 to manage password changes for this account, select the Enable automatic password change check box and configure the parameters for automatic password change.
  6. Click OK.
  • Step 2: Create a SharePoint Search service application

    Each Search service application has a separate content index. You can create multiple Search service applications if you want to have different content indexes for different sets of content. For example, if you want to segregate sensitive content (such as employee benefits information) into a separate content index, you can create a separate Search service application to correspond to that set of content.

    Use the following procedure to create a Search service application.

    To create a Search service application

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators group for the farm for which you want to create the service application.
  2. On the Central Administration home page, in the Application Management section, click Manage service applications.
  3. On the Manage Service Applications page, on the ribbon, click New, and then click Search Service Application.
  4. On the Create New Search Service Application page, do the following:
    1. Accept the default value for Service Application name, or type a new name for the Search service application.
    2. In the Search Service Account list, select the managed account that you registered in the previous procedure to run the Search service.
    3. In the Application Pool for Search Admin Web Service section, do the following:
      1. Select the Create new application pool option, and then specify a name for the application pool in the Application pool name text box.
      2. In the Select a security account for this application pool section, select the Configurable option, and then from the list select the account that you registered to run the application pool for the Search Admin Web Service.
    4. In the Application Pool for Search Query and Site Settings Web Service section, do the following:
      1. Choose the Create new application pool option, and then specify a name for the application pool in the Application pool name text box.
      2. In the Select a security account for this application pool section, select the Configurable option, and then from the list select the account that you registered to run the application pool for the Search Query and Site Settings Web Service.
  5. Click OK.
  • Step 3: Configure the SharePoint Search service application

    You configure a Search service application on the Search Administration page for that service application. Use the following procedure to go to the Search Administration page for a particular Search service application.

    To go to the Search Administration page

  1. Verify that the user account that is performing this procedure is an administrator for the Search service application that you want to configure.
  2. On the home page of the Central Administration website, in the Application Management section, click Manage service applications.
  3. On the Manage Service Applications page, click the Search service application that you want to configure.

On the Search Administration page, configure the settings as described in the following sections:

  • Specify the default content access account
  • Specify the contact email address
  • Create content sources
    • Specify the default content access account

When you create a Search service application, the account that you specify for the Search service is automatically configured as the default content access account. The crawler uses this account to crawl content that does not have an associated crawl rule that specifies a different account. For the default content access account, we recommend that you specify a domain user account that has read access to as much of the content that you want to crawl as possible. You can change the default content access account at any time.

If you have to crawl certain content by using a different account, you can create a crawl rule and specify a different account for crawling. For information about how to create a crawl rule, see Manage crawl rules (SharePoint Server 2013 Preview).

Use the following procedure to specify the default content access account.

 

To specify the default content access account

  1. On the Search Administration page, in the System Status section, click the link in the Default content access account row.
  2. In the Default Content Access Account dialog box, in the Account box, type the account that you created for content access in the form domain\user name.
  3. Type the password for this account in the Password and Confirm Password boxes.
  4. Click OK.
  • Specify the contact email address

The Search service writes the contact email address to the logs of crawled servers. The default contact email address, someone@example.com, is a placeholder. We recommend that you change this to an account that an external administrator can contact when a crawl might be contributing to a problem such as a decrease in performance on a server that the search system is crawling.

Use the following procedure to specify the contact email address.

To specify the contact email address

  1. On the Search Administration page, in the System Status section, click the link for the Contact e-mail address.
  2. In the Search E-mail Setting dialog box, in the E-mail Address box, type the email address that you want to appear in the logs of servers that are crawled by the search system.
  3. Click OK.
  • Create content sources in a SharePoint Search service application

Crawling requires at least one content source. A content source is a set of options that you use to specify the type of content to crawl, the starting URLs to crawl, and when and how deep to crawl. When a Search service application is created, a content source named “Local SharePoint sites” is automatically created and configured for crawling all SharePoint sites in the local server farm. You can create content sources to specify other content to crawl and how the system will crawl that content. For more information, see Add, edit, or delete a content source (SharePoint Server 2013 Preview). However, you do not have to create other content sources if you do not want to crawl content other than the SharePoint sites in the local farm.

If you choose the Standalone installation option when you install SharePoint Server 2013, a full crawl of all SharePoint sites in the farm is automatically performed after installation and an incremental crawl is scheduled to occur every 20 minutes after that. If you choose the Server Farm installation option when you install SharePoint Server 2013, no crawls are automatically scheduled or performed.

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators group.
  2. On the home page of the Central Administration website, in the Application Management section, click Create site collections.
  3. On the Create Site Collection page, do the following:
    1. In the Web Application section, select a web application to contain the new site collection. To use a web application other than the one that is displayed, click the web application that is displayed, and then click Change Web Application.
    2. In the Title and Description section, in the Title box, type the name for the new Search Center site. Optionally, type a description in the Description box.
    3. In the Web Site Address section, for the part of the URL immediately after the web application address, select /sites/, or select a managed path that was previously defined, and then type the final part of the URL.

      Note the address of the new Search Center for future reference.

    4. In the Template Selection section, do the following:
      1. In the Select the experience version drop-down list, select 2013 to create a Search Center site that provides the SharePoint Server 2013 user experience, or select 2010 to create a Search Center site that provides the SharePoint 2010 Products user experience.
      2. In the Select a template subsection, click the Enterprise tab, and then do one of the following:
  • If you are using SharePoint Foundation 2013, select the Basic Search Center template.
  • Otherwise, if you are using SharePoint Server 2013, select the Enterprise Search Center template.
  1. In the Primary Site Collection Administrator section, in the User name box, type the user name of the primary site collection administrator for this site collection in the form domain\user name.
  2. (Optional) In the Secondary Site Collection Administrator section, type the user name of a secondary site collection administrator in the form domain\user name.
  3. In the Quota Template section, select No Quota.

    A Search Center site is not intended to be a data repository. Therefore, you do not have to select a quota template.

  4. Click OK.
  1. On the Top-Level Site Successfully Created page, click the link to the Search Center site that you created.

After you create the Search Center site, you must grant site access to users so that they can perform search queries and view search results. Use the following procedure to grant site access to users.

To grant access to the SharePoint Search Center

  1. Verify that the user account that is performing this procedure is a member of the Owners group on the Search Center site.
  2. In a web browser, go to the Search Center site.
  3. Open the Site menu by clicking the gear icon in the upper-right portion of the page, and then click Site Permissions.
  4. In the Shared with dialog box, click Invite people.
  5. In the Share <SearchCenterName> dialog box, in the Enter users separated with semicolons text box, type the names of the Windows user groups and Windows users to whom you want to grant permissions for submitting queries and viewing search results in the Search Center.

    For example, to grant access to the Search Center to all Windows users, type NT Authority\authenticated users.

  6. Click Show options.
  7. Clear the Send an email invitation check box.
  8. In the Select a group or permission level drop-down list, select <SearchCenterName> Visitors [Read].
  9. Click Share.

 

 

 

  1. Verify that the user account that is performing this procedure is an administrator for the Search service application.
  2. Start SharePoint 2013 Central Administration.
  • For Windows Server 2008 R2:
    • Click Start, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Central Administration.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Central Administration.

      If SharePoint 2013 Central Administration is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Central Administration.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. In Central Administration, in the Application Management section, click Manage service applications.
  2. On the Manage Service Applications page, click the row that contains the User Profile service application, and then in the ribbon, click Administrators.
  3. In the Administrators for User Profile Service Application dialog box, in the To add an account box, type a user account in the form domain\user name.
  4. Click Add.
  5. In the Permissions list, select the Retrieve People Data for Search Crawlers check box.
  6. Click OK.

After you give the account access to crawl the profile store, you must create a crawl rule to specify that you want to use that account when you crawl the profile store. Use the following procedure to create a crawl rule for this purpose.

To create a crawl rule to authenticate to the User Profile service application

  1. Verify that the user account that is performing this procedure is an administrator for the Search service application.
  2. In Central Administration, in the Application Management section, click Manage service applications.
  3. On the Manage Service Applications page, click the Search service application for which you want to create a crawl rule.
  4. On the Search Administration page, in the Quick Launch, in the Crawling section, click Crawl Rules.
  5. On the Manage Crawl Rules page, click New Crawl Rule.
  6. In the Path section, in the Path box, type the start address for the User Profile service application in the form sps3://<hostname>, where <hostname> is the URL for the Web application where you deployed the My Sites site collection.
  7. Click Use regular expression syntax for matching this rule if you want to use regular expression syntax in the path.
  8. In the Crawl Configuration section, select Include all items in this path.
  9. In the Specify Authentication section, select Specify a different content access account.
  10. In the Account box that appears, type the user account to which you gave access to the profile store in the form domain\user name.
  11. Type the password for the account that you specified in the Password and Confirm Password boxes.
  12. Clear the Do not allow Basic Authentication check box only if you want to allow the user account credentials to be sent as plaintext.

    Note:

You should not clear the Do not allow Basic Authentication check box unless you are using SSL to encrypt the website traffic. For more information, see Plan for user authentication methods in SharePoint 2013.

  1. Click OK.

For more information, see Manage crawl rules.

When you configure My Sites, the starting URL to crawl the profile store (sps3://<hostname>) is automatically added to the default content source. We recommend that you remove the URL of the profile store from the default content source and then create a separate content source to crawl only the profile store. This allows you to crawl the profile store on a different schedule from other crawls.

Use the following procedure to remove the URL of the profile store from the default content source.

To remove the profile store URL from the default content source

  1. Verify that the user account that is performing this procedure is an administrator for the Search service application.
  2. In Central Administration, in the Application Management section, click Manage service applications.
  3. On the Manage Service Applications page, click Search Service Application.
  4. On the Search Administration page, in the Quick Launch, in the Crawling section, click Content Sources.
  5. On the Manage Content Sources page, click the link to the default content source (Local SharePoint sites).
  6. In the Start Addresses section, remove the URL for the profile store (sps3://<hostname>, where <hostname> is the URL for the web application where you deployed the My Sites site collection).
  7. Click OK.

    Use the following procedure to create a content source that specifies how to crawl the profile store.

To create a content source that specifies how to crawl the profile store

  1. Verify that the user account that is performing this procedure is an administrator for the Search service application.
  2. In Central Administration, in the Application Management section, click Manage service applications.
  3. On the Manage Service Applications page, click Search Service Application.
  4. On the Search Administration page, in the Quick Launch, in the Crawling section, click Content Sources.
  5. On the Manage Content Sources page, click New Content Source.
  6. On the Add Content Source page, in the Name section, type a name for this content source.
  7. In the Content Source Type section, ensure that SharePoint Sites is selected.
  8. In the Start Addresses section, type the start address in the form sps3://<hostname>, where <hostname> is the URL for the web application where you deployed the My Sites site collection.
  9. In the Crawl Settings section, leave the default value of Crawl everything under the host name for each start address.
  10. In the Crawl Schedules section, do the following:
  • Select Enable Continuous Crawls or Enable Incremental Crawls.

    A continuous crawl automatically provides maximum freshness for the content source without an incremental crawl schedule. For more information, see Manage continuous crawls in SharePoint 2013.

    If you select Enable Incremental Crawls, create an incremental crawl schedule.

  • Optionally create a schedule for full crawls.
  1. If you selected Enable Incremental Crawls, in the Content Source Priority section, select the priority for this content source.

    Note:

The Content Source Priority section does not appear when you specify the content source type as SharePoint Sites and you select Enable Continuous Crawls.

  1. Click OK.
  1. Verify that the user account that is performing this procedure is an administrator for the User Profile service application.
  2. In Central Administration, in the Application Management section, click Manage service applications.
  3. On the Manage Service Applications page, click the User Profile service application.
  4. On the Manage Profile Service page, in the People section, click Manage User Profiles.
  5. On the Manage User Profiles page, in the Find profiles box, type the name of the domain of which the users are members.

    Do not type the fully qualified domain name. For example, if users are members of the Contoso.com domain, type Contoso in the Find profiles box.

  6. Click Find.
  • Add information to My Sites

My Sites keep information in the User Profile service application databases. The User Profile service application stores much of the information that appears in results for people search. People search results become more useful as users add more information to their My Sites.

The first time that a user accesses their My Site, also known as their personal site, a My Site is created for them and a profile is automatically added to the User Profile service application.

To add information to a user’s My Site, log on as a user for whom a user profile was created in the User Profile service application, and then go to that users My Site. In the users My Site, you can provide information about the users expertise and interests. To see how the information that you added affects the people search results that appear, perform a crawl of the profile store, and then search on the user’s name.

  1. Depending on the level at which you want to create the result source, do one of the following:
  • To create a result source for a Search service application:
  • Verify that the user account that performs this procedure is an administrator on the Search service application.
  • In Central Administration, in the Application Management section, click Manage service application.
  • Click the Search service application for which you want to create a result source.
  • On the Search Administration page for the Search service application, on the Quick Launch, in the Queries and Results section, click Result Sources.
  • To create a result source for a site collection:
  • Verify that the user account that performs this procedure is an administrator for the site collection.
  • On the Settings menu for the site collection, click Site Settings.
  • On the Site Settings page, in the Site Collection Administration section, click Search Result Sources.
  • To create a result source for a site:
  • Verify that the user account that performs this procedure is a member of the Owners group for the site.
  • On the Settings menu for the site, click Site Settings.
  • On the Site Settings page, in the Search section, click Result Sources.
  1. On the Manage Result Sources page, click New Result Source.
  2. On the Add Result Source page, in the General Information section, do the following:
    1. In the Name box, type a name for the result source.
    2. In the Description box, type a description of the result source.
  3. In the Protocol section, select one of the following protocols for retrieving search results:
  • Local SharePoint, the default protocol, provides results from the search index for this Search service application.
  • Remote SharePoint provides results from the index of a search service in another farm.
  • OpenSearch provides results from a search engine that uses the OpenSearch 1.0/1.1 protocol.
  • Exchange provides results from Microsoft Exchange Server. Click Use AutoDiscover to have the search system find an Exchange Server endpoint automatically, or type the URL of the Exchange web service to retrieve results from — for example, https://contoso.com/ews/exchange.asmx.

        Note:

Note: The Exchange Web Services Managed API must be installed on the computer on which the search service is running. For more information, see Optional software in Hardware and software requirements for SharePoint 2013.

  1. In the Type section, select SharePoint Search Results to search the whole index, or People Search Results to enable query processing that is specific to people search.
  2. In the Query Transform field, do one of the following:
  • Leave the default query transform (searchTerms) as is. In this case, the query will be unchanged since the previous transform.
  • Type a different query transform in the text box.
  • Use the Query Builder to configure a query transform by doing the following:
  • Click Launch Query Builder.
  • In the Build Your Query dialog box, optionally build the query by specifying filters, sorting, and testing on the tabs as shown in the following tables.
  • On the BASICS tab

Keyword filter

You can use keyword filters to add pre-defined query variables to the query transform. You can select pre-defined query variables from the drop-down list, and then add them to the query by clicking Add keyword filter.

Property filter

You can use property filters to query the content of managed properties that are set to queryable in the search schema.

You can select managed properties from the Property filter drop-down list. Click Add property filter to add the filter to the query.

  • On the SORTING tab

Sort results

In the Sort by menu, you can select a managed property from the list of managed properties that are set as sortable in the search schema, and then select Descending or Ascending. To sort by relevance, that is, to use a ranking model, select Rank. You can click Add sort level to specify a property for a secondary level of sorting for search results.

Ranking Model

If you selected Rank from the Sort by list, you can select the ranking model to use for sorting.

Dynamic ordering

You can click Add dynamic ordering rule to specify additional ranking by adding rules that change the order of results within the result block when certain conditions are satisfied.

  • On the TEST tab

Query text

You can view the final query text, which is based on the original query template, the applicable query rules, and the variable values.

Click Show more to display the options in the following rows of this table.

 

Query template

You can view the query as it is defined in the BASICS tab or in the text box in the Query transform section on the Add Result Source page.

Query template variables

You can test the query template by specifying values for the query variables.

  1. On the Add Result Source page, in the Credentials Information section, select the authentication type that you want for users to connect to the result source.
  1. Perform the appropriate procedures in the following list depending on the level at which the result source was configured.
  • If the result source was created at the Search service application level, do the following:
  • Verify that the user account that performs this procedure is an administrator for the Search service application.
  • In Central Administration, in the Application Management section, click Manage service applications.
  • Click the Search service application for which you want to set the result source as default.
  • On the Search Administration page, in the Queries and Results section, click Result Sources.
  • If the result source is at the site collection level, do the following:
  • Verify that the user account that performs this procedure is an administrator for the site collection administrator.
  • On the Settings menu for the site collection, click Site Settings.
  • On the Site Settings page, in the Site Collection Administration section, click Search Result Sources.
  • If the result source is at the site level, do the following:
  • Verify that the user account that performs this procedure is a member of the Owners group for the site.
  • On the Settings menu for the site, click Site Settings.
  • On the Site Settings page, in the Search section, click Result Sources.
  1. On the Manage Result Sources page, point to the result source that you want to set as default, click the arrow that appears, and then click Set as Default.

 

 

  1. Create a Machine Translation service application.
  2. Configure the Machine Translation Service.
  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group and the Administrators group on the computer that is running Central Administration.
  2. On the Central Administration home page, in the Application Management section, click Manage service applications.
  3. On the ribbon, click New, and then click Machine Translation Service.
  4. In the Create New Machine Translation Service Application pane, in the Name section, type a name for the service application.
  5. In the Application Pool section, do one of the following:
  • Click Use existing application pool, and then select the application pool that you want to use from the drop-down list.
  • Click Create a new application pool, type the name of the new application pool, and then under Select a security account for this application pool do one of the following:
    • Click Predefined to use a predefined security account, and then select the security account from the drop-down list.
    • Click Configurable to specify a new security account to be used for an existing application pool. You can create a new account by clicking the Register new managed account link.

    Important:

The account that is used by the application pool must also have Full Control permissions to the User Profile service application. If you create a new application pool and a new account, make sure that you add the account to the list of accounts that can use the User Profile Service Application, and grant Full Control permissions to the account. For more information, see Restrict or enable access to a service application (SharePoint Server 2010).

  1. In the Partitioned Mode section, select Run in partitioned mode only if you will be providing hosting services for other sites, and the sites using it have site subscriptions.
  2. In the Add to Default Proxy List section, select Add this service application’s proxy to the farm’s default proxy list. If you have multiple Web applications, and want them to use different sets of services, clear this check box.
  3. In the Database section, specify the database server, database name, and authentication method for the new service application as described in the following table. The database is used to hold the work items for the Machine Translation service.
  • Database section properties

Item

Action

Database Server

Type the name of the database server and SQL Server 2012 instance that you want to use in the format ServerName\Instance. You can also use the default entry.

Database Name

Type the name of the database.

    Important:

The database name must be a unique name.

Database Authentication

Select the authentication that you want to use by doing one of the following:

  • If you want to use Windows authentication, leave this option selected. We recommend this option because Windows authentication automatically encrypts the password when it connects to SQL Server.
  • If you want to use SQL authentication, click SQL authentication. In the Account box, type the name of the account that you want the service application to use to authenticate to the SQL Server database, and then type the password in the Password box.

    Note:

In SQL authentication, an unencrypted password is sent to SQL Server. We recommend that you use SQL authentication only if you force protocol encryption to SQL Server or encrypt network traffic by using IPsec.

  1. Click OK.
  2. Start the Machine Translation Service. For more information, see “Starting or stopping a service” in Manage services on the server (SharePoint Server 2010).

To create a Machine Translation service application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    New-SPTranslationServiceApplication -Name “<ServiceApplicationName>” -DatabaseName “<DatabaseName>” -DatabaseServer “<DatabaseServer>” -ApplicationPool “<ApplicationPoolName>” -Default

    Where:

  • <ServiceApplicationName> is name of the new Machine Translation Service application.
  • <DatabaseName> is the name of the database that will host the Machine Translation Service logs. To create a new database, provide a new name.

        Important:

The database name must be a unique name.

  • <DatabaseServer> is the name of the database server that will hold the work items for the Machine Translation Service.
  • <ApplicationPoolName> is the name of an existing application pool in which the new Machine Translation Service should run.

        Important:

The account that is used by the application pool must also have Full Control permissions to the User Profile service application. If you create a new application pool and a new account, make sure that you add the account to the list of accounts that can use the User Profile service application, and grant it Full Control permissions. For more information, see Restrict or enable access to a service application (SharePoint Server 2010).

Example

New-SPTranslationServiceApplication -Name “Machine Translation Service Application” -DatabaseName “MachineTranslationDB” -DatabaseServer “ContosoDBServer” -ApplicationPool “ContosoAppPool” -Default

  1. Start the Machine Translation Service. For more information, see “Starting or stopping a service” in Manage services on the server (SharePoint Server 2010).

For more information, see New-SPTranslationServiceApplication.

  • Configure the Machine Translation Service

    You can configure the Machine Translation Service by using either Central Administration or Windows PowerShell.

        Caution:

    Changing the default settings for the Machine Translation Service can potentially affect server performance. For example, increasing item size limits can result in the translation job taking longer to run, and increasing the number of processes will consume more resources on the server. Be sure to carefully consider any possible server effects before you change these settings.

    To configure the Machine Translation Service by using Central Administration

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators group in SharePoint Server 2013.
  2. On the Central Administration home page, in the Application Management section, click Manage service applications.
  3. On the Manage Service Applications page, click the link that corresponds to the name of the Machine Translation service application.
  4. On the Machine Translation Service page, in the Enabled File Extensions section, clear the check box for any file name extensions that you want to disable. By default, all file name extensions are enabled.
  5. In the Item Size Limits section, do the following:
  • In the Maximum file size for binary files in KB. Microsoft Word documents are binary files box, type the maximum file size (100-524288), in KB, for binary files. The default is 51200. Files that exceed this limit will not be translated.
  • In the Maximum file size for text files in KB. Plain-text, HTML, and XLIFF documents are text files box, type the maximum file size (100-15360), in KB, for text files. The default is 5120. Files that exceed this limit will not be translated.
  • In the Maximum character count for Microsoft Word documents box, type the maximum character count (10000-10000000) for Word documents. The default is 500000.
  1. In the Online Translation Connection section, do one of the following:
  • Click Use default internet settings. This is the default.
  • Click Use the proxy specified, and type a web proxy server and port number.

        Note:

If you change this setting, you must stop and restart the Machine Translation Service after you configure it.

  1. In the Translation Processes section, type the number of translation processes (1-5). The default is 1.

    Note:

If you change this setting, you must stop and restart the Machine Translation Service after you configure it.

  1. In the Translation Throughput section, do the following:
  • In the Frequency with which to start translations (minutes) box, type the frequency with which groups of translations are started, in minutes (1-59). The default is 15.
  • In the Number of translations to start (per translation process) box, type the number of translations (1-1000) per process. This number represents the number of translations started per process every time translations are started. The default is 200.
  1. In the Maximum Translation Attempts section, type the maximum number of times (1-10) a translation is tried before its status is set to Failed. The default is 2.
  2. In the Maximum Synchronous Translation Requests section, type the maximum number of synchronous translation requests (0-300). The default is 10.

    Note:

You can also set this value to 0 so that no synchronous jobs are accepted.

  1. In the Translation Quota section, do the following:
  • In the Maximum number of items which can be queued in a 24-hour period section, do one of the following:
    • Click No limit. This is the default.
    • Click Limit per 24 hours, and then type the maximum number of items (100-1000000) that can be queued in a 24-hour period.
  • In the Maximum number of items which can be queued in a 24-hour period per site subscription section, do one of the following:
    • Click No limit. This is the default.
    • Click Limit per 24 hours, and then type the maximum number of items (100-1000000) that can be queued in a 24-hour period per site subscription.

    Note:

This setting applies only if you will be providing hosting services for other sites, and the sites using it have site subscriptions.

  1. In the Completed Job Expiration Time section, do one of the following:
  • Click Days, and then type the number of days (1-1000) completed jobs are kept in the job history log. The default is 7.
  • Click No expiration.
  1. In the Recycled Threshold section, type the number of documents (1-1000) to be converted before the conversion process is restarted. The default is 100.

    Note:

If you change this setting, you must stop and restart the Machine Translation Service after you configure it.

  1. In the Office 97-2003 Document Scanning section, specify whether to disable security scanning for Office 97-2003 documents. Only enable this setting if you trust the documents that will be converted. The default is No.
  2. Click OK.
  3. If you changed any settings that require you to restart the Machine Translation Service, restart the service now. For more information, see “Starting or stopping a service” in Manage services on the server (SharePoint Server 2010).

To configure the Machine Translation Service by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Set-SPTranslationServiceApplication -Identity “<ServiceApplicationName>” -EnableAllFileExtensions -UseDefaultlnternetSettings -TimerJobFrequency <TimerJobFrequency> -MaximumTranslationAttempts <MaximumTranslationAttempts> -JobExpirationDays <JobExpirationDays> -MaximumSyncTranslationRequests <MaximumSyncTranslationRequests> -RecycleProcessThreshold <RecycleProcessThreshold> -DisableBinaryFileScan <DisableBinaryFileScan>

    Where:

  • <ServiceApplicationName> is name of the Machine Translation service application.
  • <TimerJobFrequency> is the frequency, in minutes (1-59), with which groups of translations are started.
  • <MaximumTranslationAttempts> is the maximum number of times (1-10) a translation is tried before its status is set to Failed.
  • <JobExpirationDays> is the number of days (1-1000) completed jobs are kept in the job history log.
  • <MaximumSyncTranslationRequests> is the maximum number of synchronous translation requests (0-300).
  • <RecycleProcessThreshold> is the number of documents (1-1000) to be converted before the conversion process is restarted.
  • <DisableBinaryFileScan> is either 0 (false) or 1 (true).

    Example

    Set-SPTranslationServiceApplication -Identity “Machine Translation Service Application” -EnableAllFileExtensions -UseDefaultlnternetSettings -TimerJobFrequency 30 -MaximumTranslationAttempts 3 -JobExpirationDays 14 -MaximumSyncTranslationRequests 20 -RecycleProcessThreshold 300 -DisableBinaryFileScan 1

        Note:

Changes to any of the following parameters will require that you restart the Machine Translation Service: KeepAliveTimeout, MaximumTranslationTime, TotalActiveProcesses, RecycleProcessThreshold, WebProxyAddress, MachineTranslationAddress, UseDefaultInternetSettings.

  1. If you changed any settings that require you to restart the Machine Translation Service, restart the service now. For more information, see “Starting or stopping a service” in Manage services on the server (SharePoint Server 2010).

For more information, see Set-SPTranslationServiceApplication.

The Microsoft Translator Hub is an extension of Microsoft Translator, and allows you to build automatic language translation systems that integrate with your website. After you build a custom system, the Test System page on the Projects tab in the Microsoft Translator Hub displays a category ID. You can configure the Machine Translation Service to use the custom translation system by passing the category ID in the MachineTranslationCategory parameter. For more information about the Microsoft Translator Hub, see http://hub.microsofttranslator.com.

  • Additional steps

    If the account that is used by the application pool that was assigned to the Machine Translation service application differs from the one used by the User Profile service application, you must add it to the list of accounts that can use the User Profile service application, and grant it Full Control permissions. For more information, see Restrict or enable access to a service application (SharePoint Server 2010).

     

     

  • Configure Request Manager in SharePoint Server 2013

    Published: October 2, 2012

    Summary: Learn how Request Manager in SharePoint Server 2013 can route and throttle incoming requests to help improve performance and availability.

    Applies to:  SharePoint Server 2013 

    Request Manager is functionality in SharePoint Server 2013 that enables administrators to manage incoming requests and determine how SharePoint Server 2013 routes these requests.

    In this article:

  • Overview

    Request Manager uses configured rules to perform the following tasks when it encounters requests:

    • Deny potentially harmful requests from entering a SharePoint farm.
    • Route good requests to an available server.
    • Manually optimize performance.

    Information that administrators or an automated process provide to Request Manager determine the effectiveness of routed requests.

    To learn about how to use performance data to plan and manage the capacity of a SharePoint Server 2013 environment, see Capacity management and sizing overview for SharePoint Server 2013

  • Scenarios

    The following table describes possible scenarios and resolutions that Request Manager can address.

     

    Area

    Scenario

    Resolution

    Reliability and performance

    Routing new requests to web front end with low performance can increase latency and cause timeouts.

    Request Manager can route to front-end web servers that have better performance, keeping low performance front-end web servers available.

    Requests from users and bots have equal priority.

    Prioritize requests by throttling requests from bots to instead serve requests from end-users).

    Manageability, accountability, and capacity planning

    SharePoint Server fails or generally responds slowly, but its difficult to identify the cause of a failure or slowdown.

    Request Manager can send all requests of a specific type, for example, Search, User Profiles, or Office Web Apps, to specific computers. When a computer is failing or slow, Request Manager can locate the problem.

    All front-end web servers must be able to handle the requests because they could be sent to any front-end web server.

    Request Manager can send multiple or single requests to front-end web servers that are designated to handle them.

    Scaling limits

    Hardware scaling limited by load balancer

    Request Manager can perform application routing and scale out as needed so that a load balancer can quickly balance loads at the network level.

     

  • Setup and Deployment

    Request Manager’s task is to decide two things: a SharePoint farm will accept a request, and if the answer is “yes”, to which front-end web server SharePoint Server will send it. The three major functional components of Request Manager are Request Routing, Request Throttling and Prioritizing, and Request Load Balancing. These components determine how to handle requests. Request Manager manages all requests on a per-web-application basis. Because Request Manager is part of the SharePoint Server 2013 Internet Information Services (IIS) module, it only affects requests that IIS hosts.

    When a new request is received, Request Manager is the first code that runs in a SharePoint farm. Although Request Manager is installed during setup of SharePoint Server on a front-end web server, the Request Management service is not enabled. You can use the Start-SPServiceInstance and Stop-SPServiceInstance cmdlets to start and stop the Request Management service instance respectively or the Manage services on server page on the the SharePoint Central Administration website. You can use the RoutingEnabled or ThrottlingEnabled parameters of the Set-SPRequestManagementSettings Windows PowerShell cmdlet to change properties of Request Manager.

        Note:

    There is no user interface to configure properties of Request Manager. The Windows PowerShell cmdlet is the only way to perform this task.

    Request Manager has two supported deployment modes: Dedicated and Integrated.

    • Dedicated mode

    Figure 1 shows a dedicated mode deployment.

    Figure 1: Dedicated mode

    A set of front-end web servers is dedicated to managing requests exclusively. The front-end web servers that are dedicated to Request Manager are in their own farm that is located between the hardware load balancers (HLBs) and the SharePoint farm. The HLBs send all requests to the Request Manager front-end web servers. Request Manager that runs on these front-end web servers decides to which SharePoint front-end web servers it will send the requests and then routes the requests. Depending on the routing and throttling rules, Request Manager might ignore some requests without sending them to another server. The SharePoint front-end web servers do their normal tasks in processing requests and then send responses back through the front-end web servers that run Request Manager and to the clients.

    Note that all farms are set up as SharePoint farms. All front-end web servers in Figure 1 are SharePoint front-end web servers, each of which can do the same work as any other. The difference between the farms is that the Request Manager front-end web servers have Request Manager enabled.

    Dedicated mode is good for larger-scale deployments when physical computers are readily available. The ability to create a separate farm for Request manager provides two benefits: Request Manager and SharePoint processes do not compete for resources and you can scale out one without having to also scale out the other. This allows you to have more control over the performance of each role.

    • Request Manager and SharePoint processes do not compete for resources.
    • You can scale out each farm separately, which provides more control over the performance of each farm.
      • Integrated mode

    Figure 2 shows an integrated mode deployment.

    Figure 2: Integrated mode

    In an integrated mode deployment, all SharePoint front-end web servers run Request Manager. Hardware load balancers send requests to all front-end web servers. When a front-end web server receives a request, Request Manager decides how to handle it: .

    • Allow it to be processed locally.
    • Route it to a different front-end web server.
    • Deny the request.

    Integrated mode is good for small-scale deployments when many physical computers are not readily available. This mode lets Request Manager and the rest of SharePoint Server to run on all computers. This mode is common for on-premises deployments.

  • Configuration

    Request Manager has two configurable parts: General settings and Decision information. General settings are parameters that make Request Manager ready to use, such as enabling or disabling Request Routing and Request Throttling and Prioritizing. Decision information is all of the information that is used during the routing and throttling processes, such as routing and throttling rules.

        Note:

    You configure Request Manager on a farm and functionality occurs at a web application level.

    • General settings

    By default, request routing and request throttling and prioritizing are enabled. You use the Set-SPRequestManagementSettings cmdlet to change the properties of request routing, request throttling and prioritizing, and select a routing weight scheme.

    The table describes the configuration situation and Windows PowerShell syntax to use.

    • Windows PowerShell examples to enable routing and throttling

     

    Situation

    Windows PowerShell syntax

    Enable routing and throttling for all web applications

    Get-SPWebApplication | Set-SPRequestManagementSettings RoutingEnabled $true ThrottlingEnabled $true

    Enable routing with static weighting for all web applications

    Get-SPWebApplication | Get-SPRequestManagementSettings | Set-SPRequestManagementSettings RoutingEnabled $true ThrottlingEnabled $false RoutingWeightScheme Static

     

    In some situations, multiple front-end web servers will be suitable destinations for a particular request. In this case, by default, SharePoint Server selects one server randomly and uniformly.

    One routing weight scheme is static-weighted routing. In this scheme, static weights are associated with front-end web servers so that Request Manager always favors a higher static weight during the selection process. This scheme is useful to give added weight to more powerful front-end web servers and produce less strain on less powerful ones. Each front-end web server will have a static weight associated with it. The values of the weights are any integer value, where 1 is the default. A value less than 1 represents lower weight, and greater than 1 represents higher weight.

    Another weighting scheme is health-weighted. In health-weighted routing, front-end web servers that have health scores closer to zero will be favored, and fewer requests will be sent to front-end web servers that have a higher health score values. The health weights run from 0 to 10, where 0 is the healthiest and therefore will get the most requests. By default, all front-end web servers are set to healthy, and therefore, will have equal weights. SharePoint’s health score based monitoring system assigns weight to server and send a health score value as a header in the response to a request. Request Manager uses same health score and stores it in local memory.

    • Decision information

    Decision information applies to routing targets, routing rules, and throttling rules.

    • Routing targets

    Request routing determines the routing targets that are available when a routing pool is selected for a request. The scope of routing targets is currently for front-end web servers only, but Request Managers design does not exclude routing to application servers, too. A list of front-end web servers in a farm is automatically maintained by using the configuration database. An administrator who wants to change that list, typically in dedicated mode, has to use the appropriate routing cmdlets to get, add, set, and remove routing targets.

    The following table describes the various routing target tasks and the associated Windows PowerShell syntax to use.

    • Windows PowerShell examples routing target tasks

     

    Task

    Windows PowerShell syntax

    Return a list of routing targets for all available web applications.

    Get-SPWebApplication | Get-SPRequestManagementSettings | Get-SPRoutingMachineInfo Availability Available

    Add a new routing target for a specified web application.

        Note:

    IIS log files will contain all HTTP requests. For additional information about IIS logging, see IIS Logging

    $web=Get-SPWebApplication -Identity <URL of web application>

    $rm=Get-SPRequestManagementSettings -Identity $web

    Add-SPRoutingMachineInfo RequestManagementSettings $rm -Name <MachineName> -Availability Available

    Where

    • <URL of web application> is the URL of the web application to which you’re adding a new routing target.
    • <MachineName>is the name of the server that hosts the web application.

    Edit an existing routing targets availability and static weight for a specified web application

    $web=Get-SPWebApplication -Identity <URL of web application>

    $rm=Get-SPRequestManagementSettings -Identity $web

    $m=Get-SPRoutingMachineInfo -RequestManagementSettings $rm -Name <MachineName>

    Set-SPRoutingMachineInfo -Identity $m -Availability Unavailable

    Where

    • <URL of web application> is the URL of the web application for which you’re editing an existing routing targets availability and static weight.

    Remove a routing target from a specified web application

        Note:

    You cannot remove front-end web servers that are in the farm. Instead, you can use the Availability parameter of the Set-SPRoutingMachineInfo cmdlet to make them unavailable.

    $web=Get-SPWebApplication -Identity <URL of web application>

    $rm=Get-SPRequestManagementSettings -Identity $web

    $m=Get-SPRoutingMachineInfo -RequestManagementSettings $rm -Name <MachineName>

    Remove-SPRoutingMachineInfo -Identity $M

    Where

    • <URL of web application> is the URL of the web application from which you’re removing a routing target.

     

    • Routing and throttling rules

    Request routing and request throttling and prioritizing are decision algorithms that use rules to prescribe many actions. The rules determine how Request Manager handles requests.

    Rules are separated into two categories, routing rules and throttling rules, which are used in request routing and request throttling and prioritizing, respectively. Routing rules match criteria and route to a machine pool. Throttling rules match criteria and throttle based on known health score of a computer.

  • Request Routing

    Request processing is all operations that occur sequentially from the time that Request Manager receives a new request to the time that Request Manager sends a response to the client.

    Request processing is divided into the components:

    • request routing
    • incoming request handler
    • request throttling and prioritizing
    • request load balancing
      • Incoming request handler

    The role of the incoming request handler is to determine whether Request Manager should process a request. If request throttling and prioritizing is disabled and the Request Manager queue is empty, Request Manager directs the request to SharePoint Server that is running on the current front-end web server. If request throttling and prioritizing is enabled, request throttling and prioritizing determines whether the request should be allowed or denied on the current front-end web server.

    The processes steps of the incoming request handler are as follows:

  1. Request is determined if it should be throttled or routed
  2. For routed requests, load balance algorithm is run
  3. Request routed to load balancer endpoint

Request routing and Request throttling and prioritizing only run if it is enabled and is routed once per farm. Request load balancer only runs if a request has been determined as routable. The outgoing request handler only runs if the request has to be sent to a different front-end web server. The role of the outgoing request handler is to send the request to the selected front-end web server, wait for a response, and send the response back to the source.

  • Request routing

The role of request routing is to select a front-end web server to route a request. By using no routing rules that are defined, the routing scheme is as easy as randomly selecting an available front-end web server.

The algorithm of request routing is defined by two parts: request-rule matching and front-end web server selection.

  • Request rule matching

Every rule has one or more match criteria, which consist of three things: match property, match type, and match value.

The following table describes the different types of match properties and match types:

 

Match property

Match type

Hostname

RegEx

URL

Equals

Port number

Starts with

MIME Type

Ends with

 

For example, an administrator would use the following match criteria to match http://contoso requests: Match Property=URL; Match value= http://contoso; Match type=RegEx

  • Front-end web server selection

The front-end web server selection uses all routing rules, whether they match or do not match a given request. Rules that match have machine pools, a request sends load balanced to any machine in any matching rules machine pool. If a request does not match any request, it sends load balanced to any available routing target.

  • Request routing and prioritizing

For routing requests that use the health-based monitoring system, the role of request routing and prioritizing is to reduce the routing pool to computers that have a good health score to process requests. If request routing is enabled, the routing pool is whichever front-end web server is selected. If request routing is disabled, the routing pool only contains the current front-end web server.

Request routing and prioritizing can be divided into two parts: request-rule matching and front-end web server filtering. Request-rule matching happens exactly like in request routing. Front-end web server filtering uses the health threshold parameter from the throttling rules in combination with front-end web server health data to determine whether the front-end web servers in the selected routing pool can process the given request.

The front-end web server filtering process follows these steps:

  1. The routing pool is either the current front-end web server or one or more front-end web servers that request routing selects.
  2. All matching rules are checked to find the smallest health threshold value.
  3. Remove front-end web servers in the routing pool that have health scores greater than or equal to the smallest health threshold value.

For example, request routing is disabled and the current front-end web server has a health score of 7 and a rule Block OneNote without a health threshold (that is, health threshold = 0) is created.

The routing pool is the current front-end web server that has a health threshold equal to zero (0). So, the smallest threshold that the front-end web server can serve is zero. Because the current front-end web server has health score of 7, Request Manager denies and removes the request.

  • Request load balancing

The role of request load balancing is to select a single target to which to send the request. Request load balancing uses the routing weight schemes to select the target. All routing targets begin with a weight of 1. If static weighting is enabled, request load balancing uses the static weights set of each routing target to adjust the weights and the value can be valid integer number. If health weighting is enabled, request load balancing uses health information to add weight to healthier targets and remove weight from less healthy targets.

  1. A user goes to an external list on a SharePoint site. The external list creates a request for data by using the users Windows credentials.
  2. The request is sent to the BDC runtime in the SharePoint farm.
  3. The BDC runtime accesses the external content type for the list (in the BDC Metadata Store) to see how to access the external system and which operations can be performed. By using either the users credentials or the credentials from the Secure Store (as defined in the external content type), the BDC runtime passes the request to a connector that can handle the request, in this case the SQL connector.
  4. The SQL connector accesses the external data source and retrieves the data, and applies any formatting and filtering as specified in the external content type. The data is passed back through the request chain to the list where the user can interact with it.
  5. The user wants to take this data on a portable computer in Outlook so the user can use the Connect to Outlook feature on the external list to take the data offline.
  6. The Click Once installation runs and installs the required BDC model on the client. This lets the BDC Client-Side Runtime access the external data directly.
  7. Outlook then connects to the external data by using the configuration in the BDC model and synchronizes it into an Outlook SharePoint external list, formatted as a contacts list.
  8. The user can then interact with the contact data, and any changes that the user makes can be written back to the external data source either by an on-demand synch or by waiting six hours for the automated synchronization.
  • How to use these procedures and a roadmap of the procedures

    The steps to completely deploy this scenario are presented in smaller procedures. Some of the procedures are on TechNet, some are on Office.com, and some are on MSDN. Each procedure is numbered indicating its position in the overall sequence. At the beginning and end of each procedure, links direct you to the preceding and following steps. The following list contains links to all of the procedures, in proper order, for your reference. You must follow them in sequence to build out the scenario. You can also use these procedures individually to build out your own unique scenarios. When you are assembling individual procedures to build out your own scenarios, be sure to test the entire set of procedures, in order, in a lab setting before you attempt them in production.

  1. Prerequisites for deploying a Business Connectivity Services on-premises solution in SharePoint 2013
  2. Create database logins for a Business Connectivity Services on-premises solution in SharePoint 2013
  3. Start the Business Data Connectivity service for a Business Connectivity Services on-premises solution in SharePoint 2013
  4. Create the Business Data Connectivity service application in SharePoint 2013
  5. Set permissions on the BCS Metadata Store for a Business Connectivity Services on-premises solution in SharePoint 2013
  6. Configure the Secure Store Service for a Business Connectivity Services on-premises solution in SharePoint 2013
  7. Create an external content type for a Business Connectivity Services on-premises solution in SharePoint 2013
  8. Configure permission on an external content type for a Business Connectivity Services on-premises solution in SharePoint 2013
  9. Create an external list for a Business Connectivity Services on-premises solution in SharePoint 2013
  10. Manage user permissions on an external list for a Business Connectivity Services on-premises solution in SharePoint 2013
  11. Connect an external list to Outlook for a Business Connectivity Services on-premises solution in SharePoint 2013
  12. Verify offline access and synchronization of external data in Outlook for a Business Connectivity Services on-premises solution in SharePoint 2013

 

 

  1. From a browser, go to AdventureWorks sample database and download the AdventureWorks2008R2_Data.mdf file.
  2. Install the Adventure Works2008R2 sample database by following the procedures in the Readme for AdventureWorks 2008 R2 Sample Database section of the SQL Server Samples Readme (en-US) page.

    Important:

Link to Step 2Create database logins for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. Start SQL Server Management Studio.
  2. In the Object Explorer, expand the <database server name>, expand Security, and then expand Logins.
  3. Right-click Logins, and then click New Login
  4. In the Login Name box, enter SharePointGroupAccount.
  5. Select SQL Server authentication, and then enter and confirm a password.
  6. In the Default database box, select AdventureWorks2008R2, and then click OK.
  • Create a SQL Server user on the AdventureWorks database

  1. In the Object Explorer, expand Databases, expand AdventureWorks2008R2, expand Security, and then expand Users.
  2. Right-click Users, and then click New User.
  3. Under the Login Name, with the User name box pre-selected, in the first box, enter AdventureWorksUser
  4. In the second box, click Browse, in the Select Login dialog box, click Browse, select the SQL Server account, SharePointGroupAccount, and then click OK twice.
  5. Under Database Role membership, select db_owner.
  6. Click OK.
  7. Close SQL Server Management Studio.

    Important:

Link to Step 3Start the Business Data Connectivity service for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. Open the SharePoint Central Administration website for the server farm that contains your BCS solution.
  2. On the Quick Launch, click System Settings.
  3. On the System Settings page, under Servers, click Manage services on server.
  4. Check the value in the Server field. If the server name shown there is not the server that you want running the Business Data Connectivity Service on, click on the down arrow, click Change Server and select the correct server.
  5. If necessary, next to Business Data Connectivity Service, under the Action column, click Start.

    Note:

If you need to stop the Business Data Connectivity Service after starting it, next to Business Data Connectivity Service in the Action column click Stop.

    Important:

Link to Step 4Create the Business Data Connectivity service application in SharePoint 2013 of the Business Connectivity Services On-Premises deployment procedures

 

  1. Open the SharePoint Central Administration website for your farm with a Farm administrator account. This must be the farm in which you started the Business Data Connectivity Service in the Start the Business Data Connectivity service for a Business Connectivity Services on-premises solution in SharePoint 2013 procedure.
  2. On the Quick start, click, Application Management.
  3. On the Application Management page under Service Applications, click Manage service applications.
  4. If an instance of the Business Data Connectivity Service Application that you will use for this solution is already there, you can skip the rest of this procedure. If not, follow the rest of this procedure to create one.
  5. On the SERVICE APPLICATIONS tab, click New and click Business Data Connectivity Service.
  6. Configure the setting in the Create New Business Data Connectivity Service Application configuration page as follows:
    1. In the Service Application Name box enter the name you want the service to appear as on the Manage Service Applications page. This BCS service application can be used by multiple BCS solutions.
    2. In the Database area, leave the prepopulated values for Database Server, Database Name, and Database authentication, which is Windows authentication (recommended) unless you have specific design needs to change them.
    3. If you have SQL Server database mirroring configured and you want to include the Business Data Connectivity Service database in mirroring, provide the name of the failover database server in the Failover Database Server box.
    4. If you have not already created a new application pool for your service applications, enter a name for a new application pool in the Application pool name box, for example, SharePointServiceApps. You can use this application pool for all your service applications. For more information on planning, creating and configuring service applications, see Manage service applications in SharePoint 2013.
    5. Select the account that you configured in the Prerequisites for deploying a Business Connectivity Services on-premises solution in SharePoint 2013 procedure as the SharePoint products application services account in the Configurable drop down.
  7. Click OK to create the new Business Data Connectivity Service Application and click OK again.
  8. Select the row that the Business Data Connectivity Service Application is in, not the proxy row.
  9. Click Administrators in the Operations area and add any accounts that you want to be able to administer the Business Data Connectivity service application granting them full control. When these individuals open Central Administration they will only be able to administer the Business Data Connectivity service application.

    Important:

Link to Step 5Set permissions on the BCS Metadata Store for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. Open the SharePoint Central Administration website with either a Farm administrator account or an account that has been delegated permissions to administer the Business Data Connectivity Service Applications.
  2. On the Quick Launch, click Application Management.
  3. On the Application Management page, under Service Applications, click Manage service applications.
  4. In the list of services, select the row of the Business Data Connectivity Service Application that you created in Create the Business Data Connectivity service application in SharePoint 2013 and then click Manage and then Set Metadata Store Permissions.
  5. Enter the Farm Administrator account and any other delegate administrators if you have them and then click Add.
  6. For each account or group that you added that is an administrator of the Business Data Connectivity Service Application, select the Edit, Execute, Selectable In Clients, and Set Permissions checkboxes.
  7. Select the Propagate permissions to all BDC Models, External Systems and External Content Types in the BDC Metadata Store. Doing so will overwrite existing permissions checkbox. For more information on setting permissions on the BDC Metadata Store, see Overview of Business Connectivity Services security tasks in SharePoint 2013.
  8. Click OK.

    Note:

Edit is a highly privileged permission that is required to create or modify external content types in the Business Data Connectivity metadata store. Execute permission is required to query the external content type.

    Important:

Link to Step 6Configure the Secure Store Service for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

 

  1. Perform all the steps in Configure the Secure Store Services in SharePoint 2013 Preview with the following parameters.
  2. Open the SharePoint Central Administration website for the server farm that your Secure Store Service is in with an account that has Farm Administrator permissions.
  3. In the Configure the Secure Store Services in SharePoint 2013 Preview article, perform all procedures in the Configure Secure Store section with these parameters
    1. For the Register Managed Account, User name type in the name of the service account that you created in the Prerequisites for deploying a Business Connectivity Services on-premises solution in SharePoint 2013 procedure.
    2. Do not select the Enable automatic password change box.
  4. Perform the To start the Secure Store Service procedure
  5. Perform the To create a Secure Store Service application” procedures using these parameters
    1. In the Service Application Name box enter the name you want the service to appear as on the Manage Service Applications page.
    2. In the Database area, leave the prepopulated values for Database Server, Database Name, and Database authentication, which is Windows authentication (recommended) unless you have specific design needs to change them.
    3. If you have SQL Server database mirroring configured and you want to include the Secure Store Service in mirroring, provide the name of the failover database server in the Failover Database Server box.
    4. For the Configurable dropdown, select the account that you registered as a managed account earlier in this procedure.
  6. Perform the steps in the Work with encryption keys section with these parameters:
    1. Dont perform the procedures in the Refresh the encryption key sub-section
  7. Read the Store credentials in Secure Store section and perform the Create a target application procedure using these parameters.
    1. In the Target Application ID box type in a string for the target application; this is not the display name. For example type in AWTargetAppID.
    2. In the Display Name box, enter the display name you want, for example Adventure Works Target Application ID.
    3. In the Target Application Type dropdown, select Group (which indicates the mapping of many credentials to one credential). In this case, the Target Application Page URL is not needed and automatically selects to None.
    4. On the Create New Secure Store Target Application page, under Field Name, change Windows User Name to SQL User Name, and Windows Password to SQL Password.
    5. Under Field Type change Windows User Name to User Name and change Windows Password to Password.
    6. In the Target Application Administrators add the accounts that you want to be administrators of the Target Application. Note that the Farm Administrator has access by default.
    7. In the Members box, add the names of the users whom you want to allow access to the external data source. For this example use the AdventureWorksBCSUsers security group you created in Prerequisites for deploying a Business Connectivity Services on-premises solution in SharePoint 2013.
  8. Perform the steps in the Set credentials for a target application procedure using these parameters:
    1. In the SQL User Name box, type AdventureWorksUser which is the name SQL Server account you created in Create database logins for a Business Connectivity Services on-premises solution in SharePoint 2013.
    2. In the SQL Password, and Confirm SQL Password boxes type the password for that account, which is actually the password for the SharePointGroupAccount account that you created in Create database logins for a Business Connectivity Services on-premises solution in SharePoint 2013.

    Important:

Link to Step 7Create an external content type for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. Open How to: Create external content types for SQL Server in SharePoint 2013 Preview
  2. Create a new external content type named AWcustomers with a display name of AdventureWorks Customers.
  • Define general and Office behaviors

  1. Set the Office Item Type to Contact. The Office Item Type determines the Outlook behavior you want to attach to the external content type. In this case, this AWCustomer external content type behaves like a native Contact Item in Outlook.
  2. In the Offline Sync for External List checkbox, make sure Enabled is selected, which is the default.

    Note:

If you disable this option, then the SharePoint Connect to Outlook ribbon command is not available for an external list.

  • Create a connection to the external data

  1. Add a connection using SQL Server as the External Data Source Type.
  2. In the Set the Database Server box, enter <The name of the database server> and in the Set the Database Name box, enter AdventureWorks2008R2. Optionally, in the Name box, enter AdventureWorks Sample Database.
  3. Select Connect with Impersonated Custom Identity.
  4. In the Secure Store Application ID box, enter AWTargetAppID.

    Warning:

If you are prompted to enter a user name and password for AWTargetAppID it may be because when you created the SharePointGroupAccount SQL login, you did not uncheck the User must change password at next login option. To fix this, you must change the password via SQL query ALTER LOGIN <LoginName> WITH PASSWORD = <originalpassword>

  • Select a table, view, or routine and Define Operation

  1. In the AdventureWorks Sample Database select the vIndividualCustomer view and right click Create All Operations.

    Note:

Create All Operations is a convenient way to define all basic methods of operations (Create, Read, Read List, Update, and Delete).

    Tip:

Always read carefully the messages in the Errors and Warnings pane. They provide useful information to confirm your actions or troubleshoot any issues.

  • Add columns

  1. In the Parameters Configuration dialog box, by default all columns are selected. To remove unnecessary columns, clear the checkboxes next to the following columns: Suffix and Demographics.
  2. For the BusinessEntityID select the Map to Identifier value.

    Note:

Uncheck the Required box to prevent it from being updated but select the Read Only checkbox, which is needed to retrieve items so you can update other fields.

  • Map Outlook fields and set up the external item picker control

  1. For the FirstName, LastName, EmailAddress, and PhoneNumber fields, do the following:
  2. Click and highlight the field.
  3. Under properties, in the Office property dropdown, select the appropriate matching field: FirstName to First Name (FirstName), LastName to Last Name (LastName), and PhoneNumber to Primary Telephone Phone Number (PrimaryTelephonePhoneNumber), EmailAddress to EmailAddress1 (Email1Address).

    Note:

Unmapped fields, depending on the number, are displayed as extended properties. For two to five fields they are listed as Adjoining meaning that they are appended to the form region at the bottom of an Outlook form’s default page. For six or more fields they are listed as Separate and are added as a new page to an Outlook.

  1. For the following fields, BusinessEntityID, FirstName, LastName, and EmailAddress click and highlight the field, and then under Properties, click Show in Picker.
  • Define filters

  1. Create a Comparison filter named ByRegion, use CountryRegionName for the value.
  2. Under Properties, next to Default Value, enter Canada.
  3. Create Limit filter named AWLimit, use BusinessEntityID for the Filter Field
  4. Set the default value to 200

    Tip:

Click the Errors and Warnings pane and make sure there are no more errors or warnings.

  • Set the Title field for an external list and complete the external content type

  1. Set BusinessEntityID as the Title and save the external content type.

    Important:

Link to Step 8Configure permission on an external content type for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. Open the Central Administration page for your site.
  2. On the Quick Launch, click Application Management.
  3. On the Application Management page, under Service Applications, click Manage service applications.
  4. In the list of services, click your Business Data Connectivity (BDC) Service.
  5. Click AWCustomers.
  6. On the ribbon, click Set Object Permissions.
  7. Enter the user accounts to which you want to grant permissions, and then click Add. For this example, you would add the security group that was created in Prerequisites for deploying a Business Connectivity Services on-premises solution in SharePoint 2013AdventureWorksBCSUsers.
  8. Select the user accounts that you just added, and then select Execute check boxe.
  9. Select the Propagate permissions to all BDC Models, External Systems and External Content Types in the BDC Metadata Store check box to overwrite existing permissions.
  10. Click OK.

The external content type is now available for use in SharePoint and Office products to the appropriate users.

    Important:

Link to Step 9Create an external list for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. Open Create an external list
  2. Create an external list named AdventureWorksCustomers using the AWCustomers external content type.
  • Create a view of an external list

  1. Create a view for the external list AdventureWorksCustomers. For this example use ByRegionData Source Filter.
  2. Make it the default view, and select your own Sort, Filter, and Limit values.

    Important:

Link to Step 10Manage user permissions on an external list for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. On the List tab, in the Settings group, click List Settings.
  2. Under Permissions and Management, click Permissions for this list
  3. Apply permissions to the list as you have planned them.

The following table summarizes the default external list permissions for SharePoint user groups:

 

Name

Permission levels

Excel Services Viewers

View Only

<Site Name> Members

Edit

<Site Name> Owners

Full Control

<Site Name> Visitors

Read

 

    Important:

Link to Step 11Connect an external list to Outlook for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. Open the SharePoint 2013 site that contains the external list. In the ribbon, on the List tab, in the Connect & Export group, click Connect to Outlook.
  2. In the Microsoft Office Customization Installer dialog box, click Install.The installation should take a minute or two.
  3. Once the installation is complete, click Close.
  • Link to

Step 12Verify offline access and synchronization of external data in Outlook for a Business Connectivity Services on-premises solution in SharePoint 2013 of the Business Connectivity Services On-Premises scenario deployment procedures.

 

 

  1. To take Outlook 2013 offline, click Send/Receive, and in the Preferences group, click Work Offline.
  2. Make a change or two to one of the AdventureWorks customers.
  3. To bring Outlook 2013 back online, click Send/Receive, and in the Preferences group, click Work Online.
  4. To synchronize the data, on the navigation pane, right-click the <Team Site Name> AWCustomers external list and then click Sync now

 

 

  1. Ensure that the Exchange Web Service managed API is installed on every front-end server that is running SharePoint Server 2013. For more information about the Exchange Web Service managed API, see Hardware and software requirements (SharePoint 2013 Preview).
  2. Configure a trust relationship between SharePoint Server 2013 and Exchange Server. For information about how to configure the trust relationship, see Configure server-to-server authentication in SharePoint 2013.
  3. If you want content from Lync Server 2013 to be discoverable, configure Lync Server 2013 to archive to Exchange Server 2013. For information about how to configure Lync Server 2013 archiving, see Microsoft Lync Server 2013 Archiving Deployment Guide.
  4. Perform the eDiscovery configuration steps for Exchange. For information about how to configure Exchange Server 2013 for eDiscovery, see Configure Exchange for SharePoint eDiscovery Center.
  1. If content in Exchange Server 2013 must be discoverable, add Exchange Server 2013 as a result source. For information about how to configure a result source, see Configure result sources for search in SharePoint Server 2013.
  2. Ensure that all websites that contain discoverable content are being crawled. For information about how to configure a location to be crawled, see Add, edit, or delete a content source (SharePoint Server 2010).
  3. Ensure that all file shares that contain discoverable content are being crawled. For information about how to configure a location to be crawled, see Add, edit, or delete a content source (SharePoint Server 2010).
  • Grant permissions

    The article Plan for eDiscovery recommends that you create a security group to contain all users of the eDiscovery Center. After you create the security group, grant the security group permissions to access all discoverable content.

        Note:

    The article Plan for eDiscovery explains the different ways of granting permissions to discoverable content. You should have chosen to grant permissions at the web application level or at the site collection level.

  1. If you will grant permissions at the web application level, create a user policy that gives the security group full read permissions for each web application that contains discoverable content. For information about how to create a policy for a web application, see Manage permission policies for a Web application (SharePoint Server 2010).

    Note:

When you change permissions at the web application level, Search re-crawls all of the content in the web application.

  1. If you will grant permissions at the site collection level, make the security group a site collection administrator for each site collection that contains discoverable content. For information about how to add a site collection administrator, see Add or change a site collection administrator.

    Important:

A site collection administrator must add the security group as an additional site collection administrator by using the Site Settings menu. You cannot use Central Administration to make a security group a site collection administrator

  1. Ensure that the security group has permissions to access all file shares and other websites that contain discoverable content.
  2. If you will use a SharePoint eDiscovery Center to discover content in Exchange Server, grant the security group permissions to access Exchange Server mailboxes. For information about how to grant permissions in Exchange, see Configure Exchange for SharePoint eDiscovery Center.
  3. Grant the security group permissions to view the crawl log. For information about how to grant permissions to access the crawl log, see Set-SPEnterpriseSearchCrawlLogReadPermission.
  1. Download EWSManagedAPI.msi from the Microsoft Download Center (http://go.microsoft.com/fwlink/p/?LinkId=258305) and save it to a folder on each WFE server.
  2. Open a command window as administrator and navigate to the folder where you saved EWSManagedAPI.msi.
  3. Run the following command:

    msiexec /i EwsManagedApi.msi addlocal=”ExchangeWebServicesApi_Feature,ExchangeWebServicesApi_Gac”

  4. Reset IIS from the command line by typing IISReset.
  • Establish OAuth Trust and Service Permissions on SharePoint Server 2013

    The next step is to copy the following two scripts. The first should be saved as Set-SiteMailboxConfig.ps1 and the second should be saved as Check-SiteMailboxConfig.ps1.

    Set-SiteMailboxConfig.ps1:

    # .SYNOPSIS
    #
    # Set-SiteMailboxConfig helps configure Site Mailboxes for a SharePoint farm
    #
    # .DESCRIPTION
    #
    # Establishes trust with an Exchange Server, sets Site Mailbox settings and enables Site Mailboxes for a farm.
    #
    # .PARAMETER ExchangeSiteMailboxDomain
    #
    # The FQDN of the Exchange Organization where Site Mailboxes will be created
    #
    # .PARAMETER ExchangeAutodiscoverDomain
    #
    # [Optional] The FQDN of an Exchange Autodiscover Virtual Directory
    #
    # .PARAMETER WebApplicationUrl
    #
    # [Optional] The URL of a specific web application to configure. If not specified all Web Applications will be configured
    #
    # .PARAMETER Force
    #
    # [Optional] Indicate that the script should ignore any configuration issues and enable Site Mailboxes anyway
    #

    Param
    (
    [Parameter(Mandatory=$true)]
    [ValidateNotNullOrEmpty()]
    [string]$ExchangeSiteMailboxDomain,
    [Parameter(Mandatory=$false)]
    [ValidateNotNullOrEmpty()]
    [string]$ExchangeAutodiscoverDomain,
    [Parameter(Mandatory=$false)]
    [ValidateNotNullOrEmpty()]
    [string]$WebApplicationUrl,
    [Parameter(Mandatory=$false)]
    [switch]$Force
    )

    $script:currentDirectory = Split-Path $MyInvocation.MyCommand.Path

    if($WebApplicationUrl -ne $NULL -and $WebApplicationUrl -ne “”)
    {
    $webapps = Get-SPWebApplication $WebApplicationUrl
    }
    else
    {
    $webapps = Get-SPWebApplication
    }

    if($webapps -eq $NULL)
    {
    if($WebApplicationUrl -ne $NULL)
    {
    Write-Warning “No Web Application Found at $($WebApplicationUrl). Please create a web application and re-run Set-SiteMailboxConfig”
    }
    else
    {
    Write-Warning “No Web Applications Found. Please create a web application and re-run Set-SiteMailboxConfig”
    }

    return
    }

    $rootWeb = $NULL

    foreach($webapp in $webapps)
    {
    if($rootWeb -eq $NULL)
    {
    $rootWeb = Get-SPWeb $webApp.Url -EA SilentlyContinue
    }
    }

    if($rootWeb -eq $NULL)
    {
    Write-Warning “Unable to find a root site collection. Please create a root site collection on a web application and re-run Set-SiteMailboxConfig”
    return
    }

    $exchangeServer = $ExchangeAutodiscoverDomain

    if($exchangeServer -eq $NULL -or $exchangeServer -eq “”)
    {
    $exchangeServer = “autodiscover.$($ExchangeSiteMailboxDomain)”
    }

    Write-Host “Establishing Trust with Exchange Server: $($exchangeServer)”

    $metadataEndpoint = “https://$($exchangeServer)/autodiscover/metadata/json/1&#8221;

    $exchange = Get-SPTrustedSecurityTokenIssuer | Where-Object { $_.MetadataEndpoint -eq $metadataEndpoint }

    if($exchange -eq $NULL)
    {
    $exchange = New-SPTrustedSecurityTokenIssuer -Name $exchangeServer -MetadataEndPoint $metadataEndpoint
    }

    if($exchange -eq $NULL)
    {
    Write-Warning “Unable to establish trust with Exchange Server $($exchangeServer). Ensure that $($metadataEndpoint) is accessible.”

    if($ExchangeAutodiscoverDomain -eq $NULL -or $ExchangeAutodiscoverDomain -eq “”)
    {
    Write-Warning “If $($metadataEndpoint) does not exist you may specify an alternate FQDN using ExchangeAutodiscoverDomain.”
    }
    return
    }

    Write-Host “Granting Permissions to Exchange Server: $($exchangeServer)”
    $appPrincipal = Get-SPAppPrincipal -Site $rootWeb.Url -NameIdentifier $exchange.NameId
    Set-SPAppPrincipalPermission -AppPrincipal $appPrincipal -Site $rootWeb -Scope SiteSubscription -Right FullControl -EnableAppOnlyPolicy

    Write-Host
    Write-Host

    Write-Host “Verifying Site Mailbox Configuration”
    $warnings = & $script:currentDirectory\Check-SiteMailboxConfig.ps1 -ReturnWarningState

    if($warnings -and -not $Force)
    {
    Write-Warning “Pre-requisites not satisfied. Stopping Set-SiteMailboxConfig. Use -Force to override”
    return
    }
    elseif($warnings)
    {
    Write-Warning “Pre-requisites not satisfied. -Force used to override”
    }

    foreach($webapp in $webapps)
    {
    Write-Host “Configuring Web Application: $($webapp.Url)”
    Write-Host “Setting Exchange Site Mailbox Domain to $($ExchangeSiteMailboxDomain)”
    $webapp.Properties[“ExchangeTeamMailboxDomain”] = $ExchangeSiteMailboxDomain

    if($ExchangeAutodiscoverDomain -ne $NULL -and $ExchangeAutodiscoverDomain -ne “”)
    {
    Write-Host “Setting Exchange Autodiscover Domain to $($ExchangeAutodiscoverDomain)”
    $webapp.Properties[“ExchangeAutodiscoverDomain”] = $ExchangeAutodiscoverDomain;
    }

    $webapp.Update()
    }

    $feature = Get-SPFeature CollaborationMailboxFarm -Farm -ErrorAction Ignore

    if($feature -eq $NULL)
    {
    Write-Host “Enabling Site Mailboxes for Farm”
    Enable-SPFeature CollaborationMailboxFarm
    }
    else
    {
    Write-Host “Site Mailboxes already enabled for Farm”
    }

    CheckSiteMailboxConfig.ps1:

    Param
    (
    [Parameter(Mandatory=$false)]
    [ValidateNotNullOrEmpty()]
    [switch]$ReturnWarningState
    )

    Add-PSSnapin Microsoft.SharePoint.Powershell

    $anyWarnings = $false

    Write-Host “Step 1: Checking for Exchange Web Services”

    try
    {
    $assm = [System.Reflection.Assembly]::Load(“Microsoft.Exchange.WebServices, Version=15.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35”)
    if($assm.GlobalAssemblyCache)
    {
    Write-Host -Foreground Green “Found Exchange Web Services in Global Assembly Cache”
    Write-Host “Exchange Web Services Version: $([System.Diagnostics.FileVersionInfo]::GetVersionInfo($assm.Location).FileVersion)”
    }
    else
    {
    Write-Warning “Unable to find Exchange Web Services in Global Assembly Cache”
    $anyWarnings = $true
    }
    }
    catch
    {
    Write-Warning “Unable to find Exchange Web Services in Global Assembly Cache”
    $anyWarnings = $true
    }

    Write-Host
    Write-Host

    Write-Host “Step 2: Checking for https web application”

    $webapps = Get-SPWebApplication -EA SilentlyContinue

    $rootWeb = $NULL

    if($webapps -ne $NULL)
    {
    $sslWebAppExists = $false
    foreach($webapp in $webapps)
    {
    if($rootWeb -eq $NULL)
    {
    $rootWeb = Get-SPWeb $webApp.Url -EA SilentlyContinue
    }

    if(-not $webapp.Url.StartsWith(“https://&#8221;))
    {
    Write-Warning “Web Application at $($webapp.Url) does not use HTTPS. Site Mailboxes will not work on this Web Application.”
    }
    else
    {
    $sslWebAppExists = $true
    Write-Host -Foreground Green “Found Web Application at $($webapp.Url) that uses HTTPS”
    }
    }

    if(-not $sslWebAppExists)
    {
    Write-Warning “At least one Web Application must be configured for HTTPS in the default zone.”
    $anyWarnings = $true
    }
    }
    else
    {
    Write-Warning “No Web Applications Found. Please create a web application and re-run Check-SiteMailboxConfig”
    $anyWarnings = $true
    if($ReturnWarningState)
    {
    return $anyWarnings
    }
    return;
    }

    if($rootWeb -eq $NULL)
    {
    Write-Warning “Unable to find any Sites. Please create a root site collection on a web application and re-run Check-SiteMailboxConfig”
    $anyWarnings = $true
    if($ReturnWarningState)
    {
    return $anyWarnings
    }
    return;
    }

    # Get App Permissions Management Objects
    $appPrincipalManager = [Microsoft.SharePoint.SPAppPrincipalManager]::GetManager($rootWeb)
    $appPrincipalPermissionsManager = New-Object -TypeName Microsoft.SharePoint.SPAppPrincipalPermissionsManager -ArgumentList $rootWeb

    Write-Host
    Write-Host
    Write-Host “Step 3: Checking for trusted Exchange Servers”

    $trustedIssuers = Get-SPTrustedSecurityTokenIssuer
    $trustedIssuerHosts = @()

    if($trustedIssuers -ne $NULL)
    {
    $foundTrustedIssuer = $false
    foreach($trustedIssuer in $trustedIssuers)
    {
    if($trustedIssuer.RegisteredIssuerName.StartsWith(“00000002-0000-0ff1-ce00-000000000000@”))
    {
    if($trustedIssuer.IsSelfIssuer)
    {
    $foundTrustedIssuer = $true

    $uri = New-Object -TypeName System.Uri -ArgumentList $trustedIssuer.MetadataEndPoint

    Write-Host -Foreground Green “Found trusted Exchange Server at $($uri.Host)”
    $appPrincipalName = [Microsoft.SharePoint.SPAppPrincipalName]::CreateFromNameIdentifier($trustedIssuer.RegisteredIssuerName)
    $appPrincipal = $appPrincipalManager.LookupAppPrincipal([Microsoft.SharePoint.SPAppPrincipalIdentityProvider]::External, $appPrincipalName);

    if($appPrincipal -ne $NULL)
    {
    $isValidAppPrincipal = $true;

    if($appPrincipalPermissionsManager.GetAppPrincipalSiteSubscriptionContentPermission($appPrincipal) -eq [Microsoft.SharePoint.SPAppPrincipalPermissionKind]::FullControl)
    {
    Write-Host -Foreground Green “Exchange Server at $($uri.Host) has Full Control permissions”

    }
    else
    {
    Write-Warning “Exchange Server at $($uri.Host) does not have Full Control permissions”
    $isValidAppPrincipal = $false;
    $anyWarnings = $true
    }

    if($appPrincipalPermissionsManager.IsAppOnlyPolicyAllowed($appPrincipal))
    {
    Write-Host -Foreground Green “Exchange Server at $($uri.Host) has App Only Permissions”
    }
    else
    {
    Write-Warning “Exchange Server at $($uri.Host) does not have App Only Permissions”
    $isValidAppPrincipal = $false;
    $anyWarnings = $true
    }

    if($isValidAppPrincipal)
    {
    $trustedIssuerHosts += $uri.Host
    }

    }
    else
    {
    Write-Warning “Unable to get App Principal for $($uri.Host). Unable to check permissions for this Exchange Server”
    $anyWarnings = $true
    }
    }
    else
    {
    Write-Warning “Found trusted Exchange Server at $($uri.Host) but it is not a Self Issuer”
    $anyWarnings = $true
    }
    }
    }

    if(-not $foundTrustedIssuer)
    {
    Write-Warning “Unable to find any trusted Exchange Servers”
    $anyWarnings = $true
    }
    }
    else
    {
    Write-Warning “Unable to find any trusted Exchange Servers”
    $anyWarnings = $true
    }

    Write-Host
    Write-Host
    Write-Host “Step 4: Report current Site Mailbox Configuration”

    if($webapps -ne $NULL)
    {
    foreach($webapp in $webapps)
    {
    Write-Host
    Write-Host “Web Application Site Mailbox Configuration: $($webapp.Url)”
    Write-Host “Exchange Site Mailbox Domain: $($webapp.Properties[“ExchangeTeamMailboxDomain”])”

    if($webapp.Properties[“ExchangeAutodiscoverDomain”] -ne $NULL)
    {
    Write-Host “Exchange Autodiscover Domain: $($webapp.Properties[“ExchangeAutodiscoverDomain”])”
    }
    }
    }

    Write-Host
    Write-Host “Trusted Exchange Services: $([String]::Join(“, “, $trustedIssuerHosts))”

    $feature = Get-SPFeature CollaborationMailboxFarm -Farm -ErrorAction Ignore

    if($feature -eq $NULL)
    {
    Write-Host -ForegroundColor Red “Site Mailboxes are NOT enabled for Farm”
    }
    else
    {
    Write-Host -ForegroundColor Green “Site Mailboxes are enabled for Farm”
    }

    if($ReturnWarningState)
    {
    return $anyWarnings
    }

    Save the two .ps1 files to the same folder on a SharePoint 2013 WFE server, as one script calls the other during execution. In a SharePoint PowerShell window (right-click and Run As Administrator to open), navigate to the folder containing the .ps1 files and run the Set-SiteMailboxConfig.ps1 script. This will allow users to retrieve and install the Exchange metadata, giving the Exchange service principal full control permissions to SharePoint site subscription, enable the site mailbox feature in the SharePoint environment and optionally set the Exchange site mailbox target domain, if DNS for the domain has not been configured for AutoDiscover. The Check-SiteMailboxConfig.ps1 is called as part of the Set-SiteMailboxConfig script, and will confirm the configuration has been successful (it can also be run separately).

    The format should be as follows:

    .\Set-SiteMailboxConfig.ps1 <Domain> <Exchange Server> [URL] [FQDN of the Exchange AutoDiscovery virtual directory]

    Where <Domain> will equal the FQDN of the domain your Exchange is in, and <Exchange Server> is the Exchange you intend to connect to. These are required parameters.

    Optional parameters are [URL], which would be a specific URL you may be configuring (typically used in an environment with SSL and non-SSL web applications), while [FQDN of the Exchange AutoDiscovery virtual directory] may need to be configured if DNS AutoDiscovery is not enabled or properly configured.

    Example: .\Set-SiteMailboxConfig.ps1 tailspintoys.com exchange1.tailspintoys.com https://tailspintoys.com https://exchange1.tailspintoys.com/autodiscover/metadata/json/1If while running the script you encounter an error, please refer to the Troubleshooting section below for guidance.

  • Configure Exchange Server 2013 for Site Mailboxes

    The final step is to establish OAuth trust, and service permissions, on the Exchange server.

    • Establish OAuth Trust and Service Permission on Exchange

  1. On your Exchange Server open the Exchange Windows PowerShell window as Administrator and change to the “C:\Program Files\Microsoft\Exchange Server\V15\Scripts” directory.
  2. Run the following command:

    .\Configure-EnterprisePartnerApplication.ps1 -ApplicationType Sharepoint -AuthMetadataUrl https://<SP_FQDN>/_layouts/15/metadata/json/1

    Where <SP_FQDN> is the URL to the SharePoint SSL root site collection you wish to configure.

  • Troubleshooting

    Please review the following if issues are encountered.

    • Table of Error Codes for Reference When Running Configuration Checklist Script

     

    Error Code

    Error

    Notes

    0

    NoError

    Review Prerequisites.

    1

    ExchangeClientNotAvailable

    EWS client was not found on the SharePoint WFE. Run the Check script and ensure the entries are properly in the GAC; you may need to reinstall the EWS client.

    2

    UnsupportedVersion

    EWS client version is incompatible with SharePoint. Run the Check script to ensure the version meets minimum requirements. Alternatively, the Exchange server may be 2010 or earlier.

    3

    InvalidUser

    The TeamMailboxDomain parameter is not a valid FQDN or SMTP address.

    4

    UnauthorizedUser

    The script received a 401 from the Exchange Server, review the Exchange setup steps.

    5

    ServerBusy

    Exchange timed out during AutoDiscovery. It should be intermittent, please retry, but if it is persistent, follow-up with the Exchange Administrator.

    6

    URLNotAvailable

    AutoDiscovery failed to return a URL for ECP/OWA, which means typically that the EWS client version is incompatible with SharePoint. It may also mean Site Mailboxes are not enabled on Exchange, which would require follow-up with the Exchange Administrator.

    7

    OAuthNotSupported

    Unsuccessful in generating an OAuth token on behalf of SharePoint. This is typically caused by claims-based authentication being disabled on the SharePoint web application.

    8

    OAuthException

    An error occurred during the OAuth handshake between SharePoint and Exchange. This is typically caused by server to server configuration issues, such as a realm value mismatch on either side, certificate issues for Exchange or SharePoint, etc. Review certificates and attempt to establish or reestablish trust.

    9

    InvalidAutodiscoverDomain

    The AutoDiscover domain property is not set to a valid FQDN.

    10

    UnknownError

    An unknown error condition has occurred. Run the Check script and confirm that a valid, trusted instance of SharePoint is available, review prerequisites, confirm AutoDiscover has been set-up properly with the Exchange Administrator.

    101

    OAuthNotSupportedOverHttp

    If this error is thrown, your web applications default zone is not set to SSL, and AllowOauthoverHttp is also set to false. Run the Check script to ensure that any web application you intend to host site mailboxes are set with SSL in the default zone, as outlined in the prerequisites.

    102

    AssociatedOwnersGroupNull

    One or both of the default Owners and Members groups for the site have been deleted. Each of these two default groups are required to exist on any site where users install site mailboxes. A site administrator should be able to direct a site owner to recreated these required groups.

    103

    ExchangeTeamMailboxDomainNotSet

    The ExchangeTeamMailboxDomain property has not been set.

    104

    ExchangeAppPrincipalNotFound

    No Exchange app principals were found to be trusted. Typically, this means the New-SPTrustedSecureTokenService step was missed. Run the Check script and ensure that the app principal URL(s) outputted are the correct one(s).

    105

    ExchangeAppPrincipalMissingPermissions

    The Exchange app principal being connected to doesnt have the right permissions on the SharePoint farm. Run the Check script and ensure that the Exchange app principal has the required permissions on the farm.

     

     

     

  • Configure Exchange task synchronization in SharePoint Server 2013

    Published: August 21, 2012

    Summary: Configure Exchange Server 2013 and SharePoint Server 2013 for task synchronization by using the SharePoint Server 2013 Task Synchronization feature.

    Applies to:  SharePoint Server 2013 Enterprise 

    This article describes how to configure Task Synchronization in SharePoint Server 2013 and Exchange Server 2013. Task Synchronization allows users to synchronize SharePoint Server 2013 and Project Server tasks with Exchange Server and have them appear in Outlook 2013.

  • Before you begin

    Before you begin this operation, review the following information about prerequisites:

        Note:

    You may need to import the SSL certificate from the SharePoint Server 2013 web application. This is only necessary if the certificate is not trusted for the API endpoints (such as a Self-SSL Certificate in a lab environment).

    To import the untrusted SSL certificate from SharePoint Server 2013:

    • Open Internet Explorer on the Exchange server and navigate to the SSL SharePoint site https://<SP_FQDN&gt;, where <SP_FQDN> is the URL to the SSL site.
    • Accept to trust the certificate by clicking Continue to website.
    • Click Certificate Error info in Internet Explorer next to the Address bar, and then click View Certificates.
    • Select Install Certificate and then select Place all certificates in the following store.
    • Select the checkbox to show physical stores.
    • Install the certificate to Trusted Root Certification Authorities > Local Computer.
    • In order to perform these procedures, you must be a member of the SharePoint and Exchange Server administrator groups and have an operational Exchange Server with end-user mailboxes.

        Note:

    Because SharePoint 2013 runs as websites in Internet Information Services (IIS), administrators and users depend on the accessibility features that browsers provide. SharePoint 2013 supports the accessibility features of supported browsers. For more information, see the following resources:

  • Configure SharePoint for Task Synchronization in SharePoint Server 2013

    The first step in configuring Task Synchronization is to install the Exchange Server Web Services API on each web front-end server in the SharePoint Server 2013 farm.

    • Install Exchange Web Services API on SharePoint Server

  1. Download EWSManagedAPI.msi from the Microsoft Download Center (http://go.microsoft.com/fwlink/p/?LinkId=258305) and save it to a folder on the application server.
  2. Open a command window as administrator and navigate to the folder where you saved EWSManagedAPI.msi.
  3. Run the following command:

    msiexec /i EwsManagedApi.msi addlocal=”ExchangeWebServicesApi_Feature,ExchangeWebServicesApi_Gac”

  4. Reset IIS from the command line by typing IISReset.
  • Configure Exchange Server 2013 for Task Synchronization

    The next step is to establish OAuth trust and service permission on Exchange Server.

    • Establish OAuth Trust and Service Permission on Exchange

  1. On the Exchange server, open Windows PowerShell and change to the “C:\Program Files\Microsoft\Exchange Server\V15\Scripts” directory.
  2. Run the following script:

    .\Configure-EnterprisePartnerApplication.ps1 -ApplicationType Sharepoint -AuthMetadataUrl https://<SP_FQDN>/_layouts/15/metadata/json/1

    Where <SP_FQDN> is the URL to the root site collection.

 

 

  1. Verify that you have the following administrative credentials:
  • To create a My Site host site collection, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website or a service application administrator for the services related to My Sites. If you are a service application administrator, you must also have permission to create site collections in the web application that you dedicate to host My Sites.
  1. In Central Administration, click Application Management, and then click Create site collections.
  2. On the Create Site Collection page, in the Web Application section, ensure that the selected web application is the web application that you want to host My Sites. If it is not, expand the list, and then click Change Web Application. In the Select Web Application dialog box, select a different web application.
  3. In the Title and Description section, type a title and description for the site collection.
  4. In the Web Site Address section, select the URL where you want this site collection created. Generally, you should use the default path (which is displayed as / in the user interface), which is the root of the web application. For more information about this path, see My Sites architecture in Plan for My Sites (SharePoint 2013 Preview).
  5. In the Template Selection section, in the Select experience version list, select 2013. Then, on the Enterprise tab, click My Site Host.
  6. In the Primary Site Collection Administrator section, and optionally in the Secondary Site Collection Administrator section, type an account in the format domain\username to specify an administrator for the site collection.
  7. Optionally, in the Quota Template section, select a quota template for the My Site host site collection. This quota template does not affect the individual site collections that users create for their My Sites. For more information, see Planning for storage requirements in Plan for My Sites (SharePoint 2013 Preview).
  8. Click OK. Copy this site collection URL for later reference.
  1. Verify that you have the following administrative credentials:
  • To add managed paths, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website.
  1. In Central Administration, click Application Management, and then click Manage Web applications.
  2. On the Web Applications Management page, select the web application that you created to host My Sites.
  3. On the Web Applications tab, in the Manage group, click Managed Paths.
  4. In the Define Managed Paths dialog box, in the Add a New Path section, in the Path box, type the path that you want to append to the URL namespace, and then select Wildcard inclusion. For example, if your web application URL is http://mysites.contoso.com/ and you want users’ individual site collections created under a path named “personal”, type personal in the Path box. Separate My Sites site collections will be created for each user under http://mysites.contoso.com/personal/.
  5. Click Add Path, and then click OK.
  6. Copy this managed path for later reference.
  1. Verify that you have the following administrative credentials:
  • To connect a web application to a service application, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website.
  1. In Central Administration, in the Application Management section, click Manage Web applications.
  2. On the Web Applications Management page, select the web application that you created to host My Sites.
  3. On the Web Applications tab, in the Manage group, click Service Connections.
  4. In the Configure Service Application Associations dialog box, in the Edit the following group of connections list, select default if the default group contains the service applications that you want to connect to the web application.
  • If you choose [Custom], select any service applications to which you want to connect the web application, including the User Profile service application, the managed metadata service application, and the Search service application.
  1. Click OK.
  1. Verify that you have the following administrative credentials:
  • To enable self-service site creation, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website.
  1. In Central Administration, in the Application Management section, click Manage Web applications.
  2. On the Web Applications page, select the web application that you created to host My Sites.
  3. On the Web Applications tab, in the Security group, click Self-Service Site Creation.
  4. In the Self-Service Site Creation Management dialog box, in Site Collections, select On. Optionally, in Quota template to apply, select a quota template.
  5. In Start a Site, choose one of the following options:
    1. Prompt users to create a team site under so users can create team sites from their My Site to use site feeds.
    2. Be hidden from users if you do not want users to create team sites from their My Sites to use site feeds.
  6. Click OK to finish.

Perform these additional steps to configure permissions for users to create team sites from their My Sites to use site feeds.

  1. In the Policy group, click Permission Policy.
  2. On Manage Permission Policy Levels dialog box, click Add Permission Policy Level.
  3. Type a name for the permission policy.
  4. Under Permissions, in Site Permissions, select the Grant option for Create Subsites – Create subsites such as team sites, Meeting Workspace sites, and Document Workspace sites.
  5. Click Save.
  6. In the Policy group, click User Policy.
  7. On Policy for Web Application dialog box, click Add Users.
  8. On Add Users, in Zones select (All Zones), then click Next.
  9. In Choose Users, enter the user names of the users that you want to create team sites from their My Site to use site feeds. If all users can create team sites from their My Site to use site feeds, click the Browse icon. In Select People and Groups, click All Users, then click Everyone. Click Add, and then click OK.
  10. In the Choose Permissions section, select the name of the Permission Policy created previously.
  11. Click Finish, and then click OK.
  1. Verify that you have the following administrative credentials:
  • To configure My Site settings for the User Profile service application, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website or a service application administrator for the User Profile service application.
  1. In Central Administration, in the Application Management section, click Manage service applications.
  2. Click the User Profile service application that you connected to the web application hosting My Sites earlier in this task.
  3. On the Manage Profile Service page, in the My Site Settings section, click Setup My Sites.
  4. On the My Sites Settings page, in the Preferred Search Center section, specify settings for the search center to direct users to when they search for people or documents from their About Me profile page. If you do not have a search center set up yet, you can skip this step and complete it later. For more information, see Search service application in Plan for My Sites (SharePoint 2013 Preview).
  5. In the My Site Host section, type the URL of the My Site host site collection that you created earlier in this task.
  6. Optionally, in the My Site Host URL in Active Directory section, type the URL of the My Site host site collection that is returned to client and mobile phone applications that uses Exchange Auto Discovery. When a user is using a client or mobile phone application, credentials are passed in the form of an email address and password. Exchange Auto Discover then finds other required settings, such as SMTP server name, and sends this to the client or mobile phone application. Client and mobile phone applications use Exchange Auto Discovery to find a user’s SharePoint Server 2013My Site based on the My Site host URL stored in Active Directory Domain Services (AD DS).
  7. In the Personal Site Location section, type the wildcard inclusion managed path you configured earlier in this task. By default, personal is prepopulated in the box. However, if you chose a different path for your wildcard inclusion managed path, replace personal with your path.
  8. In the Site Naming Format section, select a naming format for the My Sites site collections that will be created when users view their My Sites for the first time. For more information about these formats, see My Sites architecture in Plan for My Sites (SharePoint 2013 Preview).
  9. In the Language Options section, specify whether users can select a preferred language for their My Site. The available languages correspond to the language packs installed in the farm. All servers in a farm must have the same language packs. For more information about multilingual sites, see Plan for multilingual sites (SharePoint Server 2010). For more information about language packs, see About language IDs and language packs in Install or uninstall language packs for SharePoint 2013.
  10. In the Read Permission Level section, specify the users or groups that can view other users My Sites when they are created. By default, this includes all authenticated users. However, you can select a more specific group or users depending on the needs of your deployment.
  11. In the Security Trimming Options section, specify how system generated posts are checked for permissions before they are displayed in feeds and on the Tags and Notes page.
  12. In the Newsfeed section, enable system generated posts to the feed on My Sites by selecting Enable activities in My Site newsfeeds. This option is selected by default. This is important in hosted environments where tenants can share the same User Profile service but have different requirements on whether they can enable newsfeeds for their users.

    When upgrading from a SharePoint Server 2010 server farm that uses the newsfeed and tags and notes, you enable these legacy features on your SharePoint Server 2013 server farm by selecting Enable SharePoint 2010 activity migration.

  13. In the E-mail Notifications section, specify an email address to use as the sender email address for My Site email notifications. This account does not have to be a real monitored email address. If you want to receive notifications for newsfeed activities, such as replies to your posts or when someone follows you, select Enable newsfeed email notifications.

    Important:

You must add the IP address of the farm’s outbound SMTP server to the safe list in Exchange Server 2013 to prevent My Site email notifications from being sent to the Junk folder. For more information about safe lists in Exchange Server 2013, see Understanding Connection Filtering in the Exchange Server Technical Library.

  1. In the My Site Cleanup section, specify a new owner of a My Site if the existing My Site user is removed from the profile database. For example, if a user leaves the company and is no longer in the profile database, the users My Site will be deleted together with any content. However, before it is deleted, a new owner can recover any important content. Select Enable access delegation for the My Site cleanup job to first attempt to assign ownership of the My Site to the users manager. If no manager is found, the My Site is assigned to the user specified in Secondary Owner. The new owner has two weeks to retrieve content from the My Site before it is deleted.
  2. In the Privacy Settings section, select Make My Sites Public to make all users’ My Sites public. This option is not selected by default.

    Note:

When a user’s My Site is public, the user’s list of followers, the user’s list of people they are following, and all activities (including new follow notifications, social tagging and rating of content, birthdays, job title changes, workplace anniversary, updating Ask Me About, posting on a note board, and new blog posts) will be public. Any policies set within People and Privacy on the Manage Policies page is overridden.

  1. Click OK.

For more information about additional timer jobs for My Sites, see Planning for jobs and schedules in Plan for My Sites (SharePoint 2013 Preview).

  1. Verify that you have the following administrative credentials:
  • To configure timer jobs, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website.
  1. In Central Administration, click Monitoring, and then click Review job definitions.
  2. On the Job Definitions page, in the View list, select Service. The Service list appears.
  • If the Service list does not display User Profile Service, in Service, click No selection, then click Change Service. On the Select Service page, use the arrows in the upper-right corner to locate User Profile Service, and then click it. The Job Definitions page updates with the User Profile service jobs.
  1. Click the activity feed job for the User Profile service application that you created in Prerequisites earlier in this article. The job name is in the format User_Profile_service_nameActivity Feed Job, where User_Profile_service_name is the name that you specified for your User Profile service application.
  2. On the Edit Timer Job page, in the Recurring Schedule section, select the interval that you want the job to run. Available intervals are Minutes, Hourly, Daily, Weekly, and Monthly. Selecting a shorter interval, such as Minutes or Hourly, ensures that activities appear on users’ My Site newsfeeds more frequently. However, it increases load on the system depending on how many activities are available. Selecting a longer interval, such as Daily, Weekly, or Monthly, reduces the number of times the job runs and processes feeds. However, it also means that users receive less frequent updates to activities in their newsfeeds.
  3. Click Enable.
  4. Optionally, click Run Now to run the job immediately without waiting for the next scheduled interval.
  1. Verify that you have the following administrative credentials:
  • To create a site collection by using the Community Site template, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website or a service application administrator. If you are a service application administrator, you must also have permission to create site collections in the web application in which you create the Community Site.
  1. In Central Administration, click Application Management, and then click Create site collections.
  2. On the Create Site Collection page, in the Web Application section, ensure that the selected web application is the web application in which you want to create the Community Site. If it is not, expand the list, and then click Change Web Application. In the Select Web Application dialog box, select a different web application.
  3. In the Title and Description section, type a title and description for the site collection.
  4. In the Web Site Address section, select the URL where you want this site collection created.
  5. In the Template Selection section, in the Select experience version list, select 2013. Then, on the Collaboration tab, click Community Site.
  6. In the Primary Site Collection Administrator section, and optionally in the Secondary Site Collection Administrator section, type an account in the format domain\username to specify an administrator for the site collection.
  7. Optionally, in the Quota Template section, select a quota template.
  8. Click OK.
  9. Verification: After the site collection is created successfully, click the link to open the Community Site.
  1. Verify that you have the following administrative credentials:
  • To create a site collection by using the Community Portal template, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website or a service application administrator. If you are a service application administrator, you must also have permission to create site collections in the web application in which you create the Community Portal.
  1. In Central Administration, click Application Management, and then click Create site collections.
  2. On the Create Site Collection page, in the Web Application section, ensure that the selected web application is the web application in which you want to create the Community Portal. If it is not, expand the list, and then click Change Web Application. In the Select Web Application dialog box, select a different web application.
  3. In the Title and Description section, type a title and description for the site collection.
  4. In the Web Site Address section, select the URL where you want this site collection created.
  5. In the Template Selection section, in the Select experience version list, select 2013. Then, on the Enterprise tab, click Community Portal.
  6. In the Primary Site Collection Administrator section, and optionally in the Secondary Site Collection Administrator section, type an account in the format domain\username to specify an administrator for the site collection.
  7. Optionally, in the Quota Template section, select a quota template.
  8. Click OK.
  9. Verification: After the site collection is created successfully, click the link to open the Community Portal.
  1. Verify that you have the following administrative credentials:
  • To configure Following settings for the User Profile service application, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website or a service application administrator for the User Profile service application.
  1. In Central Administration, in the Application Management section, in the Service Applications group, click Manage service applications.
  2. In the list of service applications, select the User Profile service application.
  3. In the Operations group, click Manage.
  4. On the Manage Profile Service page, in the My Sites Settings section, click Manage Following.
  5. In the Maximum number of followed people box, type the maximum number of people that a user can follow from the users My Site.
  6. In the Maximum number of followed documents box, type the maximum number of documents that a user can follow from the users My Site.
  7. In the Maximum number of followed sites box, type the maximum number of sites that a user can follow from the users My Site.
  8. Click OK.

 

 

  1. Load last modified time information for recent conversations and activities.
  2. Load recent conversations and activities.

    Note:

In the case of planned maintenance and operations, an administrator can preserve cache data by using the graceful shutdown procedure. For more information, see Perform a graceful shutdown of the Distributed Cache service in Manage the Distributed Cache service in SharePoint Server 2013.

To manage the repopulation process, SharePoint Server 2013 includes the Feed Cache Repopulation Job timer job. When the Feed Cache Repopulation Job timer job runs, it first checks whether the Feed Cache and Last Modified Time Cache are empty. If they are empty, it starts repopulating the last modified time information for recent conversations and activities in the Last Modified Time Cache. After the timer job finishes the Last Modified Time Cache repopulation, the Feed Cache is populated with recent conversations and activities the next time any user accesses a feed in SharePoint Server 2013.

In this article:

  1. Verify that you have the following administrative credentials:
  • To configure timer jobs, you must be a member of the Farm Administrators group on the computer running the SharePoint Central Administration website.
  1. In Central Administration, on the Monitoring page, click Review job definitions.
  2. On the Job Definitions page, in the View list, select All.
  3. Use the arrows at the bottom of the page to locate the feed cache repopulation job for the User Profile service application on your server farm. The job name is in the format User_Profile_service_nameFeed Cache Repopulation Job, where User_Profile_service_name is the name that you specified for the User Profile service application.
  4. On the Edit Timer Job page, in the Recurring Schedule section, select the interval that you want the job to run. Available intervals are Minutes, Hourly, Daily, Weekly, and Monthly. Selecting a shorter interval, such as Minutes or Hourly, ensures that checks for an empty cache is performed more frequently. Selecting a longer interval, such as Daily, Weekly, or Monthly, reduces the number of times the job runs. However, it also means that performing cache repopulation checks are done fewer times. We recommend that this timer job runs on shorter intervals.
  5. Click Enable.
  6. Optionally, click Run Now to run the job immediately without waiting for the next scheduled interval.
  1. In Central Administration, click Application Management.
  2. In Service Applications, click Manage Services on Server.
  3. On the Services on Server page, locate the Distributed Cache service.
  4. If the Distributed Cache service is started and you want to stop the service, under Action, click Stop. If the Distributed Cache service is stopped and you want to start the service, under Action, click Start.

To start the Distributed Cache service by using Windows PowerShell

At the Windows PowerShell command prompt, run the following command:

$instanceName =”SPDistributedCacheService Name=AppFabricCachingService”
$serviceInstance = Get-SPServiceInstance | ? {($_.service.tostring()) -eq $instanceName -and ($_.server.name) -eq $env:computername}
$serviceInstance.Provision()

To stop the Distributed Cache service by using Windows PowerShell

At the Windows PowerShell command prompt, run the following command:

$instanceName =”SPDistributedCacheService Name=AppFabricCachingService”
$serviceInstance = Get-SPServiceInstance | ? {($_.service.tostring()) -eq $instanceName -and ($_.server.name) -eq $env:computername}
$serviceInstance.Unprovision()

  1. Determine the total physical memory on the server. For this example, we will use 16 GB as the total physical memory available on the server.
  2. Reserve 2 GB of memory for other processes and services that are running on the cache host. For example, 16 GB 2 GB = 14 GB. This remaining memory is allocated to the Distributed Cache service.
  3. Take half of the remaining memory, and convert it to MB. For example, 14 GB/2 = 7 GB or 7000 MB. This is the cache size of the Distributed Cache service.
  4. Use the following procedure to update the memory allocation accordingly.
  • Change the memory allocation of the Distributed Cache by using Windows PowerShell

Use this procedure to reconfigure the memory allocation for the Distributed Cache service.

  1. Stop the Distributed Cache service on all cache hosts that are part of the cache cluster. To stop the Distributed Cache service, on all cache hosts, at the Windows PowerShell command prompt, run the following command:

    $instanceName =”SPDistributedCacheService Name=AppFabricCachingService”
    $serviceInstance = Get-SPServiceInstance | ? {($_.service.tostring()) -eq $instanceName -and ($_.server.name) -eq $env:computername}
    $serviceInstance.Unprovision()

  2. Reconfigure the cache size of the Distributed Cache service on the server that is being added or upgraded. On that server only, at the Windows PowerShell command prompt, run the following command:

    Set-CacheHostConfig -Hostname Hostname -cacheport Cacheport -cachesize Cachesize

    Where:

  • Hostname is the FQDN of the application server being reconfigured that runs the Distributed Cache service.
  • Cacheport is equal to the port number of the Distributed Cache (22233).
  • Cachesize is the cache size’s memory allocation assignment in MB. In the previous example, the cache size was calculated at 7000 MB for a server with 16 GB of total physical memory.
  1. Restart the Distributed Cache service. On all servers, at the Windows PowerShell command prompt, run the following command:

    $serviceInstance.Provision()

  1. Create a managed account. For more information, see Configure automatic password change (SharePoint Server 2010).
  2. Set the Managed account as the service account on the AppFabric Caching service. At the Windows PowerShell command prompt, run the following command:

    $farm = Get-SPFarm
    $cacheService = $farm.Services | where {$_.Name -eq “AppFabricCachingService”}
    $accnt = Get-SPManagedAccount -Identity
    domain_name\user_name
    $cacheService.ProcessIdentity.CurrentIdentityType = “SpecificUser”
    $cacheService.ProcessIdentity.ManagedAccount = $accnt
    $cacheService.ProcessIdentity.Update()
    $cacheService.ProcessIdentity.Deploy()

    Where Domain_name\user_name is the domain name and user name of the managed account.

 

 

  1. Verify that you have the following administrative credentials:
  1. In Central Administration, in the Application Management section, click Manage service applications.
  2. In the list of service applications, click User Profile Service Application.
  3. On the Manage Profile Service: User Profile Service Application page, in the People group, click Manage User Permissions.
  4. On the Permissions for User Profile Service Application page, type or select a user or group account, and then click Add.
  5. In the Permissions for box, check the feature or features that you want the user or group to be able to use, and then click OK.

 

 

  1. Verify that the user account that performs this procedure is a site collection administrator on the authoring site collection.
  2. On the top-level site of the authoring site collection, on the Settings menu, click Site Settings.
  3. On the Site Settings page, in the Site Collection Administration section, click Site collection features.
  4. On the Site Collection Features page, next to Cross-Site Collection Publishing, click Activate.
  1. Verify that the user account that performs this procedure is a member of the Owners SharePoint group on the authoring site that contains the catalog.
  2. On the authoring site, on the Settings menu, click Site Settings.
  3. On the Site Settings page, in the Site Administration section, click Term store management.
  4. In the TAXONOMY TERM STORE section, click the term set that you want to make available for tagging.
  5. Click the INTEDED USE tab, and then select Available for Tagging.
  6. Click Save.

When you create catalog content by using SharePoint lists, we recommend that you create site columns for the lists in which you want to maintain your catalog content. This is because managed properties are automatically created for site columns, and you can use these managed properties when defining queries for you catalog content on a publishing site. If you have several lists, we recommend that you create a site content type for each list, and then associate the appropriate site columns to this site content type. If you want to use managed navigation to display catalog content on a publishing site, you also have to create at least one term set as described in Create and manage term sets for tagging content on authoring sites. The tagging term set must be tied to a site column that is a Managed Metadata data type.

For information about how to create site content types and site columns, see the following articles:

If you have large amounts of data in external business systems — for example, an ERP system — consider importing this data into one or more SharePoint lists. SharePoint Server 2013 does not have a solution for importing list content. However, you can develop custom import tools — for example, by using Windows PowerShell. For a set of example Windows PowerShell scripts that you can use to import list content for cross-site publishing, see Import list content to Products list for SharePoint 2013 Preview. The example scripts import content only to a site collection that was created by using the Product Catalog Site Collection template.

Before you share a library or list as a catalog, verify that the Cross-Site Collection Publishing feature is activated for the site collection. If you used the Product Catalog Site Collection template to create the site collection, the Cross-Site Collection Publishing feature is already active. For all other types of site collections, you must activate the Cross-Site Collection Publishing feature before you can continue with the following steps. For more information, see Activate the Cross-Site Collection Publishing feature earlier in this article.

By default, anonymous access is enabled when you share a library or list as a catalog. If you have connected a publishing site to the catalog, and you don’t want anonymous users to be able to view and search content that was added to the search index from this catalog, you should disable anonymous access.

    Important:

In addition to enabling anonymous access for a catalog, you must enable anonymous access for the web application and publishing site so that anonymous users can search and view the content. For more information, see Create claims-based web applications in SharePoint 2013.

To share a library or list as a catalog

  1. Verify that the user account that performs this procedure is a member of the Owners group on the site that contains the library or list that you want to share.
  2. Browse to the library or list that you want to share, and then do one of the following:
  • To share a library, click the LIBRARY tab, and then, on the ribbon, in the Settings group, click Library Settings.
  • To share a list, click the LIST tab, and then, on the ribbon, in the Settings group, click List Settings.
  1. On the Settings page, in the General Settings section, click Catalog Settings.
  2. On the Catalog Settings page, in the Catalog Sharing section, select the Enable this library as a catalog check box.
  3. In the Anonymous Access section, if you want don’t want anonymous users to view and search this content, click Disable anonymous access.
  4. In the Catalog Item URL Fields section, in the Available fields box, select up to five fields that uniquely identify an item in the library or list, and then click Add.

    After you connect a publishing site to this catalog, the fields that you specified as catalog item URL fields appear as part of the friendly URL. (See the example that follows this procedure.)

  5. In the Navigation Hierarchy section, select the column that is associated with the term set that you want to use as a navigation term set for catalog pages. After you connect a publishing site to this library or list to show catalog content, the value of the column that you selected appears as part of the friendly URL (see the example that follows this procedure).

    Note:

You only have to make a selection in this section if you want to use managed navigation to display catalog content on a publishing site.

  1. Click OK.

    Note:

After you share a library or list as a catalog, the content source that contains the catalog must be crawled. You don’t have to start a full crawl. This is because an incremental crawl or a continuous crawl also adds the content to the search index. For more information, see Start, pause, resume, or stop crawls in SharePoint 2013 Preview.

In this example, let’s say that you have a list that contains data for different electronic products. The following items were specified when the list was shared as catalog:

  • Electronic products
    • Audio
    • Car audio
    • MP3
    • Computers
    • Laptops
    • Desktops

Each item in the shared list is associated with a value from this term set in the Item Category Managed Metadata site column. For more information about Managed Metadata columns, see Create a Managed Metadata column.

The following table describes how site columns and their corresponding values in the previous list are combined to create friendly URLs for catalog content when you connect a publishing site collection to this list.

 

Product title

Item Category

Item Number

Friendly URL to an item when the catalog is connected to a publishing site

Proseware 50W Car Radio

Car audio

1010101

<site>/audio/car-audio/1010101

Contoso 4GB Portable MP3 Player M450

MP3

4020102

<site>/audio/mp3/4020102

AdventureWorks Laptop8.9 E0890

Laptops

7030906

<site>/computers/laptops/7030906

WWI Desktop PC2.33 X2330

Desktops

7030906

<site>/computers/desktops/3030802

 

After you create a term set on the authoring site collection, you have to make it available to publishing site collections. You can make a term set available to all site collections or to specific site collections.

To make a term set available to all site collections

  1. Verify that the user account that performs this procedure is a member of the Owners SharePoint group on the authoring site that contains the catalog.
  2. On the authoring site, on the Settings menu, click Site Settings.
  3. On the Site Settings page, in the Site Administration section, click Term store management. If the user that performs this procedure is already a member of the Term Store Administrators group, you can skip to step 7.
  4. In the Term Store Management Tool, verify that Managed Metadata Service is selected.
  5. In the Term Store Administrator section, type one or more user names.
  6. Click Save.
  7. Right-click Managed Metadata Service, and then select New Group.
  8. Type the name of the global term set that you want to create, and then press Enter.
  9. Refresh the page.
  10. Right-click the term set that you want to make available to all site collections, and then click Move Term Set.
  11. In the Term Set Move dialog box, click the global term set that you want to move the term set to, and then click OK.
  12. Refresh the page.

To make a term set available to specific site collections

  1. Verify that the user account that performs this procedure is a member of the Owners SharePoint group on the authoring site that contains the catalog.
  2. On the authoring site, on the Settings menu, click Site Settings.
  3. On the Site Settings page, in the Site Administration section, click Term store management.
  4. In the Term Store Management Tool, click the group that contains all term sets within the site collection.
  5. In the Site Collection Access section, type the URLs of the site collections to which you want to make the term set available for example, http://<site>/sites/products.
  6. Click Save.
  1. Verify that the user account that performs this procedure is a member of the Site collection administrators group on the site that contains the catalog.
  2. Browse to the catalog, and then do one of the following:
  • If you want to perform a full crawl of a catalog in a library, click the LIBRARY tab, and then, on the ribbon, in the Settings group, click Library Settings.
  • If you want to perform a full crawl of a catalog in a list, click the LIST tab, and then, on the ribbon, in the Settings group, click List Settings.
  1. On the Settings page, in the General Settings section, click Advanced settings.
  2. On the Advanced Settings page, in the Reindex List section, click Reindex List, and then click Reindex List to confirm that you want the catalog to be reindexed during the next scheduled crawl.
  3. Click OK.

    Note:

The full reindex of the catalog will be performed during the next scheduled crawl.

 

 

  1. Verify that the user account that completes this procedure is a member of the Owners SharePoint group on the publishing site collection.
  2. On the publishing site collection, on the Settings menu, click Site Settings.
  3. On the Site Settings page, in the Site Administration section, click Manage catalog connections.
  4. On the Manage catalog connections page, click Connect to a catalog. A list of available catalogs appears. Note that only catalogs that have been crawled will appear.
  5. On the line that contains the catalog that you want to connect to, click Connect. You can also search for a specific catalog by typing the catalog name in the search field.
  6. On the Catalog Source Settings page, in the Connection Integration section, do one of the following:
  • To make catalog content available to the publishing site and integrate the catalog tagging term set into the publishing site navigation term set, select Integrate the catalog into my site. When you select this option, use the following steps to specify at which level the term sets should be integrated, specify the URL for the catalog item details page, and select category pages and catalog item pages.
  • To make the catalog content available to the publishing site, select Connect, but do not integrate the catalog. You should select this option if you want to use content from the library to create individual catalog item pages.

    Either option creates a result source for the catalog.

  1. In the Navigation Hierarchy section, specify the term from which the catalog tagging term set should be integrated into the publishing site navigation term set. The catalog navigation column that you previously configured in Share a library or list as a catalog appears by default. The fields in this section are optional. Therefore, if you don’t change the fields in this section, the catalog tagging term set will be integrated from the root term. If you want to integrate the catalog tagging term set from a different term, do the following:
  • Next to the Root term of hierarchy box, click Browse for a valid choice.
  • In the Select: Add Terms dialog box, click the term that corresponds to the level from which you want to integrate the catalog tagging term set, click Select, and then click OK.
  • To integrate the root term that is the parent of the selected term in the publishing site navigation term set, select the Include root term in site navigation check box.

        Note:

All items in the catalog must be tagged with a term from the specified catalog tagging term set. If this is not done, site navigation will not work as intended for all items.

  1. In the Navigation Position section, specify the term in the publishing site navigation term set where the catalog tagging term set should be integrated. Do one of the following:
  • To integrate the catalog tagging term set to the root term of the publishing site navigation term set, click Add to navigation root.
  • To integrate the catalog tagging term set to a term below the root term of the publishing site navigation term set, click Select an alternate location in site navigation, and then do the following:
    • Click Browse for a valid choice to display the publishing site navigation term set.
    • In the Select: Add Terms dialog box, click the term that corresponds to the level from which you want to integrate the catalog tagging term set, click Select, and then click OK.
  1. If you want changes to the catalog tagging term set to be updated on the publishing site, in the Navigation Pinning section, select the Pin terms to site navigation check box. By default, this option is selected. If you clear this check box, changes made to the catalog tagging term set are not reflected on the publishing site navigation.
  2. In the Catalog Item URL Behavior section, specify what you want the URL of the catalog item to do by selecting one of the following options:
  • To point the URL of the catalog item to an item details page, select Make URLs relative to this site. When you select this option, you have to specify a catalog item URL format as described in the next step. This also means that the content that you can display on the item details page has to come from the search index.
  • To have the catalog item URL point to the item in the source catalog, select Make URLs point to source catalog. When you select this option, you do not have to specify a catalog item URL format. Note that when you select this option, anonymous users are not able to access and view the item in the source catalog.
  1. In the Catalog Item URL Format section, select which properties the URL of the item details page should contain by doing one of the following:
  • To use the field that you specified as Primary Key the when you shared the library or list as a catalog as described in Share a library or list as a catalog, select Use the default URL format provided by the catalog source. By default, this option is already selected.

        Note:

All items in the catalog must have values for the specified field. Site navigation will not work as intended for items with missing values.

  • To manually define a format for the URL, select Manually define a URL format, and then type in a URL. You should select this option only if you have created an item details page and the items in your catalog are not tagged with a term from a catalog tagging term set. Type the URL in the following format: /<Folder of item details page>/<Name of item details page>.aspx? <Managed property name>=[Managed property value] for example, /Pages/itemdetails.aspx?TitleProperty=[Title].
  • To construct a custom URL based on catalog properties, select Construct a URL format from catalog properties, and then do the following:
    • In the Available Fields list, select up to five fields, and then click Add.

    Important:

Fields of site column type Number will not create a valid URL. All items in the catalog must have values for the specified fields. Site navigation will not work as intended for items with missing values.

  1. In the Category Page section, do one of the following:
  • To have SharePoint Server 2013 automatically create a new Category page for your catalog content, click Create a new page, and then select a master page. The page will be added to the Pages library with the name Category-<catalog tagging term set name>. The page will not be published automatically.
  • To use a Category page that was already created, select Use an existing page, and then specify the location of the page.
  1. In the Item Page section, do one of the following:
  • To have SharePoint Server 2013 automatically create a new Item page for your catalog content, click Create a new page, and then select a master page. The page will be added to the Pages library with the name CatalogItem-<catalog tagging term set name>. The page will not be published automatically.
  • To use an already created Item page, select Use an existing page, and specify the location of this page.
  1. Click OK.

 

 

  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. Browse to the page where you want to add the Web Part.
  3. Click the Settings menu, and then click Edit page.
  4. In the Web Part Zone where you want to add the Web Part, click Add a Web Part.
  5. In the Categories list, click Content Rollup.
  6. In the Parts list, click Content Search, and then click Add.
  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. Browse to the page that contains the Content Search Web Part that you want to configure.
  3. Click the Settings menu, and then click Edit Page.
  4. In the Web Part, click the Content Search Web Part Menu arrow, and then click Edit Web Part.
  5. In the Web Part tool pane, in the Properties section, in the Search Criteria section, click Change query.
  6. On the BASICS tab, do one of the following:
  • To define your query by using Quick Mode, select options as described in the following table:
  • Quick Mode (default)

Select a query

Select a result source to specify which content should be searched. If you have shared a document library or list as catalog, the catalog result source will be displayed in this drop-down list. By default, this is set to Recently changed items (System).

Restrict results by app

Select an option from the list to restrict results to a specific site, library, list, or URL. By default, this is set to Current site.

Restrict by tag

You can limit results to content that is tagged with a term from a term set.

Select one of the following options:

 

Don’t restrict by any tag

Search results will not be limited based on tags (default).

Restrict by navigation term of current page

Search results will be limited to content that is tagged with the term of the current page. The current tag is displayed as the last part of the friendly URL. This option is only meaningful for sites that use managed navigation.

Restrict by current and child navigation

Search results will be limited to content that is tagged with the term of the current page (displayed as the last part of the friendly URL), and content that is tagged with sub-terms of the current page. This option is only meaningful for sites that use managed navigation.

    Note:

In a cross-site publishing scenario, this selection will only work when the result source selected in the Select a query section is the catalog result source that is created when a publishing site is connected to a catalog.

Restrict on this tag

Search results will be limited to content that is tagged with the tag that you type inside the box.


 

Select a query

Select a result source to specify which content should be searched.

Default result source is Local SharePoint Results (System).

Keyword filter

You can use keyword filters to add query variables to your query. See Query variables in SharePoint Server 2013 for a list of available query variables.

You can select pre-defined query variables from the drop-down list, and then add them to the query by clicking Add keyword filter.

Property filter

You can use property filters to query the content of managed properties that are set to queryable in the search schema.

You can select managed properties from the Property filter drop-down list. Click Add property filter to add the filter to the query.

Query text

Type your query by using Keyword Query Language (KQL), or use the Keyword filter and Property filter lists to build the query.

The keyword query can consist of free-text keywords, property filters, or operators. Use braces to enclose query variables. The query variables will be replaced with an actual value when the query is run.

Keyword queries have a maximum length of 2,048 characters.

  1. The REFINERS tab lists the managed properties that are enabled as refiners in the search schema. You can specify that the search results returned in the Content Search Web Part should be limited to one or more values from the refiners. Click a refiner in the list, and then click Apply to add it to the query.

    Click Show more if you want to define grouping of results. Under Group results, you can specify that the results should be grouped based on one or more managed properties. This is useful when you are displaying several variants for a given item, and want to group them under a single result.

  2. On the SORTING tab, you can specify how search results should be sorted.

    This tab is available only if you use Advanced Mode. If you use Quick Mode, you can define sorting options in the result source.

    In the Sort by drop-down list, select a managed property from the list of managed properties that are set as sortable in the search schema, and then select Descending or Ascending. For example, to sort by relevance (that is, to use a ranking model) select Rank.

    To add more sorting levels, click Add sort level.

    If you selected Rank from the Sort by list, you can select which ranking model to use for sorting in the Ranking Model list.

    Under Dynamic ordering, you can specify additional ranking by adding rules that will change the order of results when certain conditions apply. Click Add dynamic ordering rule, and then specify conditional rules.

  3. On the SETTINGS tab, specify the settings that are listed in the following table.

Query Rules

Select whether to use Query Rules or not.

URL Rewriting

Select if the URL rewrite to the item details page should continue to be relative for each catalog item as defined when you set up the catalog connection. If you select Don’t rewrite URLs, the URLs for catalog items are pointed directly to the library item of the connected catalog.

Loading Behavior

Select when the search results returned by the Content Search Web Part appear on the web page. The default option is Sync option: Issue query from the server. By using this loading behavior, queries are issued from the server, and the search results are included in the page response that is sent back from SharePoint. If you select Async option: Issue query from the browser, the queries will be issued from the end-users browser after the complete page is received. This option may be considered for secondary content on a page for example Recommendations or Popular Items.

Priority

Select the level that best describes the relative importance of content that is displayed by this Web Part in relation to other Search Web Parts. If SharePoint Server 2013 is running under heavy load, the queries will be run according to their priority.

  1. On the TEST tab, you can preview the query that is sent by the Content Search Web Part.

Query text

Shows the final query that will be run by the Content Search Web Part. It is based on the original query template where dynamic variables are substituted with current values. Other changes to the query may have to be made as part of query rules.

Click Show more to display additional information.

Query template

Shows the content of the query template that is applied to the query.

Refined by

Shows the refiners applied to the query as defined on the REFINERS tab.

Grouped by

Shows the managed property on which search results should be grouped as defined on the REFINERS tab.

Applied query rules

Shows which query rules are applied to the query.

The Query template variables section shows the query variables that will be applied to the query, and the values of the variables that apply to the current page. You can type other values to test the effect they will have on the query. Click the Test Query button to preview the search results.

You can also test how the query works for different user segment terms. Click Add user segment term to add terms to be added to the query. Click the Test query button to preview the search results.

  • Query text

Shows the final query that will be run by the Content Search Web Part. It is based on the original query template where dynamic variables are substituted with current values. Other changes to the query may have to be made as part of query rules.

  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. Browse to the page where you want to add the Web Part.
  3. Click the Settings menu, and then click Edit Page.
  4. In the Web Part Zone where you want to add the Web Part, click Add a Web Part.
  5. In the Categories list, select Search.
  6. In the Parts list, select Refinement, and then click Add.
  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. Browse to the page that contains the Refinement Web Part that you want to configure.
  3. Click the Settings menu, and then click Edit Page.
  4. In the Web Part, click the Refinement Web Part Menu arrow, and then click Edit Web Part.
  5. You can configure the Web Part for stand-alone refiners or for refiners for faceted navigation by using the following procedures,
  • To configure the Web Part for stand-alone refiners:
  1. In the Web Part tool pane, in the Properties for Search Refinement section, verify that the Choose Refiners in this Web Part is selected.
  2. Click Choose Refiners…
  3. On the Refinement configuration page, from the Available refiners section, use the buttons to select which refiners should be added to the term set, and also in which order that they should be displayed. If you have specified an alias for a refinable managed property, this alias is displayed in the Configuration for section.
  4. In the Configuration for section, set the configuration for how every refiner appears.

    Note:

If you have a single language site, you can change the refiner display name in the Display name section. For multilingual sites, you have to change the refiner display language as described in Change the refiner display name.

  • To configure the Web Part for refiners for faceted navigation:
  1. In the Web Part tool pane, in the Properties for Search Refinement section, select the option Use the refinement configuration defined in the Managed Navigation term set.
  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. On the Settings menu, click Site Settings.
  3. On the Site Settings page, in the Web Designer Galleries section, click Master pages and page layouts.
  4. On the Master Page Gallery page, click Display Templates.
  5. On the Display Templates page, click Language Files.
  6. On the Language Files page, click the folder that contains the language that you want to change the refiner display name for.
  7. Open the CustomStrings.js file.
  8. Add one line to the file for each managed property that is enabled as a refiner for which you want to change the display name byusing the following syntax:

    “rf_RefinementTitle_ManagedPropertyName”: “Sample Refinement Title for ManagedPropertyName”

    For example, you can add the following line to change the display name for the managed property RefinableInt00 to Price:

    “rf_RefinementTitle_RefinableInt00”: “Price”.

  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. On the Settings menu, click Site Settings.
  3. On the Site Settings page, in the Web Designer Galleries section, click Master pages and page layouts.
  4. On the Master Page Gallery page, click Display Templates.
  5. On the Display Templates page, click Filters.
  6. Open the Filter_Default.html file.
  7. Change the value for ShowCounts to true.
  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. On the Settings menu, click Site Settings.
  3. On the Site Settings page, in the Web Designer Galleries section, click Master pages and page layouts.
  4. On the Master Page Gallery page, click Display Templates.
  5. On the Display Templates page, click Filters.

You can change the display template that is used by each refiner by selecting a display template from a list in the Display template section on the Refinement configuration page. When you add a Filter display template to the master page gallery, it is added to the list.

  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. Browse to the page where you want to add the Web Part.
  3. Click the Settings menu, and then click Edit Page.
  4. In the Web Part Zone where you want to add the Web Part, click Add a Web Part.
  5. In the Categories list, select Search.
  6. In the Parts, select Taxonomy Refinement Panel, and then click Add.
  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. Browse to the page where you have the Taxonomy Refinement Panel Web Part that you want to configure.
  3. On the Settings menu, click Edit Page.
  4. In the Web Part, click the Taxonomy Refinement Panel Web Part Menu arrow, and then click Edit Web Part.
  5. In the Web Part tool pane, in the Properties section, in the Query section, on the Refinement Target menu, select the Web Part you want to associate with the Taxonomy Refinement Panel Web Part.
  6. In the Web Part tool pane, in the Properties section, in the Query section, on the Refiner menu, select the managed property that you have specified for Managed Navigation.
  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. Browse to the page where you want to add the Web Part.
  3. Click the Settings menu, and then click Edit Page.
  4. In the Web Part Zone where you want to add the Web Part, click Add a Web Part.
  5. In the Categories list, click Search-Driven Content.
  6. In the Parts list, click Recommended Items, and then click Add.
  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the publishing site collection.
  2. Browse to the page where you have the Recommended Items Web Part that you want to configure.
  3. On the Settings menu, click Edit Page.
  4. In the Web Part, click the Recommended Items Web Part Menu arrow, and then click Edit Web Part.
  5. In the Web Part tool pane, in the Properties section, in the Search Criteria section, click Change query.
  6. On the BASICS tab, define your query by selecting options described in the following table.
  • Get

    recommended items for

From the drop-down list, select from which value recommendations should be displayed. In a catalog scenario, this will often be A token from a URL. If you select this option, you will also have to select which URL token you want to obtain recommendations for.

For example, let’s say that you want to obtain recommendations for items in your catalog. You have a catalog item page where you display your catalog items, and the item number is part of your friendly URL — for example, www.contoso/audio/mp3/4010101. (4010101 represents the item number.) When you want to obtain recommendations for a token from the URL, you should select {URLToken.1} (4010101) from the second drop-down list.

Restrict results by app

Use this drop-down list to specify a scope for the search results.

Restrict results by content type

Use this drop-down list to limit the search results to a specific content type.

If there are too few recommended items

If you dont have much usage data — for example, if your site is fairly new, or if the items do not have recommendations to display — this Web Part will not display any search results. In order for the Web Part to display recommendations even though not enough user data has cumulated, you can select the option to Select a query to fill in with additional results.

  1. The REFINERS tab lists the managed properties that are set as refiner-enabled in the search schema. You can specify that the search results returned in the Recommended Items Search Web Part should be limited to one or more values from the refiners. Click a refiner in the list, and then click Apply to add it to the query.

    Click Show more if you want to define grouping of results. Under Group results, you can specify that the results should be grouped based on one or more managed properties.

  2. On the SETTINGS tab, specify the following:
  • Query Rules

Select whether to use Query Rules or not.

URL Rewriting

Select if the URL rewrite to the item details page should continue to be relative for each catalog item as defined when you set up the catalog connection. If you select Don’t rewrite URLs, the URLs for your catalog items are pointed directly to the library item of the connected catalog.

Loading Behavior

Select when the search results returned by the Recommended Items Web Part should be displayed on the web page. The default option is Display the page and web party simultaneously. By using this loading behavior, queries are issued from the server, and the search results are included in the page response that is sent back from SharePoint. If you select Display the page and web part independently, the queries will be issued from the end-users browser after the complete page is received. This option may be considered for secondary content on a page — for example, Recommendations or Popular Items

Priority

Select the level that best describes the relative importance of content that is displayed by this Web Part in relation to other Search Web Parts. If SharePoint Server 2013 is running under heavy load, the queries will be run according to their priority.

  1. On the TEST tab, you can preview the query that is sent by the Recommended Items Web Part.
  • Query text

Shows the content of the query template that is applied to the query.

Click Show more to display additional information the query is

  • Refined by

Shows the refiners applied to the query as defined in the REFINERS tab.

Grouped by

Shows the managed property on which search results should be grouped as defined in the REFINERS tab.

Applied query rules

Shows which query rules are applied to the query.

In the Query template variables section, the selections that you made on the BASIC tab are displayed. In addition, you can type additional values for testing as outlined in the following table. Click the Test query button to preview the search results.

  • {RecsURL}*

Shows the token you selected when specifying for which value recommendations should be displayed.

{Scope}*

Shows the scope that you selected for the search results.

{ContentTypeID}*

Shows the content type that you selected for the search results.

You can also test how the query works for different user segment terms. Click Add user segment term for testing to add terms to be added to the query. Click the Test query button to preview the search results.

  • Query text

Shows the final query that will be run by the Recommended Items Web Part. It is based on the original query template where dynamic variables are substituted with current values. Other changes to the query may have be made as part of query rules.

  1. Verify that the user account that performs this procedure has the following credentials:
  • The user account that performs this procedure is a site collection administrator on the publishing site collection.
  1. On the publishing site collection, on the Settings menu, click Site settings.
  2. On the Site Settings page, in the Site Collection Administration section, click Search Schema.
  3. On the Managed Properties page, in the Managed property filter box, type the name of a refinable managed property — for example, RefinableString00 — and then click the arrow.
  4. In the Property Name column, click the refinable managed property that you want to edit.
  5. To specify an alias of the refinable managed property to use when you configure refiners for faceted navigation, on the Edit Managed Property page, type a user-friendly name in the Alias box.
  6. In the Mappings to crawled properties section, click Add a Mapping.
  7. In the Crawled property selection dialog box, find the crawled property that you want to map to the refinable managed property in the list, or search for it by typing the name of the crawled property in the box, and then clicking Find.

    Important:

When you search for a crawled property, you may find two crawled properties that represent the same content. For example, a site column of type text named Color will during crawl discover two crawled properties: ows_Color and ows_q_TEXT_Color. Crawled properties that begin with either ows_r<four letter code>, ows_q<four letter code> or ows_taxId are automatically created crawled properties. When you select a crawled property to map to a refinable managed property, make sure that you don’t map the automatically created crawled property. You should always map the crawled property that begins with ows_.

For information about automatically created crawled properties, see About automatically created managed properties (SharePoint 2013 Preview).

  1. Click OK.
  2. On the Edit Managed Property page, click OK.

    Note:

To configure refiners in Web Parts or in Term Store Management, you must start a full crawl of the content source that contains the refinable managed properties. For more information, see Start, pause, resume, or stop crawls in SharePoint 2013 Preview.

    Important:

All automatically created managed properties use the text data type. Therefore, you should only enable an automatically created managed property as a refiner if the site column used to create the managed property also uses the text data type. For example, if the site column uses an integer or date data type, you must create a new managed property, map the crawled property value to this new managed property, and then enable it as a refiner.

When you select a crawled property to map to a managed property, make sure that you dont map the automatically created crawled property. The name of the automatically created crawled property starts with either ows_r<four letter code>_, ows_q<four letter code>_, or ows_taxId_. The name of the crawled property that you should use in the mapping starts with ows_.

For information about how to create a new managed property, see To add a managed property. For more information about automatically created crawled properties, see About automatically created managed properties (SharePoint 2013 Preview).

To enable a managed property as a refiner

  1. Verify that the user account that performs this procedure is an administrator of the Search service application.
  2. In Central Administration, in the Application Management section, click Manage service applications.
  3. On the Manage Service Applications page, click Search Service Application.
  4. Click the Search service application.
  5. On the Managed Properties page, in the Managed property filter box, type the name of the managed property that you want to enable as refiner, and then click the arrow.
  6. In the Property Name column, click the managed property that you want to edit.
  7. On the Edit Managed Property page, in the Refinable section, select either Yes – active or Yes – latent. If you select Yes – latent, you can switch the refiner to active later without having to do a full crawl.
  8. Click OK.

    Note:

To configure refiners in Web Parts or in Term Store Management, a full crawl of the content source that contains the refinable managed properties must be completed. Administrators of the Search service application can complete a full crawl as described in Start, pause, resume, or stop crawls in SharePoint 2013 Preview. Site collection administrators can initiate a full crawl by specifying that the catalog that contains the refinable managed properties should be reindexed during the next scheduled crawl.

  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the authoring site collection.
  2. On the authoring site collection, on the Settings menu, click Site settings.
  3. On the Site Settings page, in the Site Administration section, click Term store management.
  4. In the TAXONOMY TERM STORE section, click to select the term set that you want to enable for faceted navigation.
  5. Click the INTENDED USE tab, and then select Use this Term Set for Faceted Navigation.
  6. Click Save.

When configuring refiners for faceted navigation, you can add refiners to all terms in a term set or to specific terms in a term set. This procedure is performed on the authoring site collection.

To add refiners to all terms in a term set

  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the authoring site collection.
  2. On the authoring site collection, on the Settings menu, click Site settings.
  3. On the Site Settings page, in the Site Administration section, click Term store management.
  4. In the TAXONOMY TERM STORE section, click the term set that you have enabled for faceted navigation.
  5. Click the FACETED NAVIGATION tab, and then click Customize refiners….
  6. On the Refinement Configuration page, in the Available refiners section, use the buttons to select which refiners should be added to the term set, and also to specify the order in which you want the refiners to appear. If you have specified an alias for a refinable managed property, this alias is displayed in the Configuration section.
  7. In the Configuration for section, specify how you want each refiner to appear.
  8. Click OK to close the Refinement Configuration page, and then click Save.

To add refiners to specific terms in a term set

  1. Verify that the user account that performs this procedure is a member of the Designers SharePoint group on the authoring site collection.
  2. On the authoring site collection, on the Settings menu, click Site settings.
  3. On the Site Settings page, in the Site Administration section, click Term store management.
  4. In the TAXONOMY TERM STORE section, click the term set that you have enabled for faceted navigation, and then click the term to which you want to add term-specific refiners.
  5. Click the FACETED NAVIGATION tab, and then click Stop inheriting….
  6. Click FACETED NAVIGATION tab, and then click Customize refiners….
  7. On the Refinement Configuration page, in the Available refiners section, use the buttons to select which refiners should be added to the term set, and also to specify the order in which you want the refiners to appear. If you have specified an alias for a refinable managed property, this alias is displayed in the Configuration section.
  8. In the Configuration for section, specify how you want each refiner to appear.
  9. Click OK to close the Refinement Configuration page, and then click Save.

For refiners that contain numeric values, you can present the numeric values within different intervals. For example, if you want end-users to be able to refine based on price, it would be useful to specify different price intervals instead of showing all available prices as separate refiners. This procedure is performed in your authoring site collection.

To set intervals for refiner values

  1. Add refiners to a term set as described in Add refiners to a term set in this topic.
  2. On the Refinement Configuration page, in the Selected refiners section, click the refiner that you want to set intervals for.
  3. In the Configuration for section, for Intervals, select Custom, and then type the intervals in the Thresholds box.
  4. Click OK to close the Refinement Configuration page, and then click Save.
  • Additional steps

To show refiners on a page, you must add a Refinement Panel Web Part to the page where you want the refiners to appear. For more information, see Configure Search Web Parts in SharePoint Server 2013.

 

 

  1. Depending on the level at which you want to create the result source, do one of the following:
  • To create a result source for a Search service application:
  • Verify that the user account that performs this procedure is an administrator on the Search service application.
  • In Central Administration, in the Application Management section, click Manage service application.
  • Click the Search service application for which you want to create a result source.
  • On the Search Administration page for the Search service application, on the Quick Launch, in the Queries and Results section, click Result Sources.
  • To create a result source for a site collection:
  • Verify that the user account that performs this procedure is a site collection administrator on the publishing site collection.
  • On the publishing site collection, on the Settings menu, click Site Settings.
  • On the Site Settings page, in the Site Collection Administration section, click Search Result Sources.
  • To create a result source for a site:
  • Verify that the user account that performs this procedure is a member of the Owners group on the publishing site.
  • On the publishing site, on the Settings menu, click Site Settings.
  • On the Site Settings page, in the Search section, click Result Sources.
  1. On the Manage Result Sources page, click New Result Source.
  2. On the Add Result Source page, in the General Information section, do the following:
    1. In the Name box, type a name for the result source.
    2. In the Description box, type a description of the result source.
  3. In the Protocol section, select one of the following protocols for retrieving search results:
  • Local SharePoint, the default protocol, provides results from the search index for this Search service application.
  • Remote SharePoint provides results from the index of a search service in another farm.
  • OpenSearch provides results from a search engine that uses the OpenSearch 1.0/1.1 protocol.
  • Exchange provides results from Microsoft Exchange Server. Click Use AutoDiscover to have the search system find an Exchange Server endpoint automatically, or type the URL of the Exchange web service to retrieve results from — for example, https://contoso.com/ews/exchange.asmx.

        Note:

Note: The Exchange Web Services Managed API must be installed on the computer on which the search service is running. For more information, see Optional software in Hardware and software requirements for SharePoint 2013.

  1. In the Type section, select SharePoint Search Results to search the whole index, or People Search Results to enable query processing that is specific to people search.
  2. In the Query Transform field, do one of the following:
  • Leave the default query transform (searchTerms) as is. In this case, the query will be unchanged since the previous transform.
  • Type a different query transform in the text box.
  • Use the Query Builder to configure a query transform by doing the following:
  • Click Launch Query Builder.
  • In the Build Your Query dialog box, optionally build the query by specifying filters, sorting, and testing on the tabs as shown in the following tables.
  • On the BASICS tab

Keyword filter

You can use keyword filters to add pre-defined query variables to the query transform. You can select pre-defined query variables from the drop-down list, and then add them to the query by clicking Add keyword filter.

For an overview of query variables, see Query variables in SharePoint Server 2013.

Property filter

You can use property filters to query the content of managed properties that are set to queryable in the search schema.

You can select managed properties from the Property filter drop-down list. Click Add property filter to add the filter to the query.

  • On the SORTING tab

Sort results

In the Sort by menu, you can select a managed property from the list of managed properties that are set as sortable in the search schema, and then select Descending or Ascending. To sort by relevance, that is, to use a ranking model, select Rank. You can click Add sort level to specify a property for a secondary level of sorting for search results.

Ranking Model

If you selected Rank from the Sort by list, you can select the ranking model to use for sorting.

Dynamic ordering

You can click Add dynamic ordering rule to specify additional ranking by adding rules that change the order of results within the result block when certain conditions are satisfied.

  • On the TEST tab

Query text

You can view the final query text, which is based on the original query template, the applicable query rules, and the variable values.

Click Show more to display the options in the following rows of this table.

 

Query template

You can view the query as it is defined in the BASICS tab or in the text box in the Query transform section on the Add Result Source page.

Query template variables

You can test the query template by specifying values for the query variables.

  1. On the Add Result Source page, in the Credentials Information section, select the authentication type that you want for users to connect to the result source.
  • Set a result source as default

    You can set any result source as the default result source. Specifying a result source as default can make it easier to edit the query in Search Web Parts. For example, when you add a Content Search Web Part to a page, the Web Part automatically uses the default result source. For more information, see Configure Search Web Parts in SharePoint Server 2013.

    To set a result source as default

  1. Perform the appropriate procedures in the following list depending on the level at which the result source was configured.
  • If the result source was created at the Search service application level, do the following:
  • Verify that the user account that performs this procedure is an administrator for the Search service application.
  • In Central Administration, in the Application Management section, click Manage service applications.
  • Click the Search service application for which you want to set the result source as default.
  • On the Search Administration page, in the Queries and Results section, click Result Sources.
  • If the result source is at the site collection level, do the following:
  • Verify that the user account that performs this procedure is a site collection administrator on the publishing site collection.
  • On the publishing site collection, on the Settings menu, click Site Settings.
  • On the Site Settings page, in the Site Collection Administration section, click Search Result Sources.
  • If the result source is at the site level, do the following:
  • Verify that the user account that performs this procedure is a member of the Owners group on the publishing site.
  • On the publishing site, on the Settings menu, click Site Settings.
  • On the Site Settings page, in the Search section, click Result Sources.
  1. On the Manage Result Sources page, point to the result source that you want to set as default, click the arrow that appears, and then click Set as Default.

 

 

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:


    # To get a site at the root site collection level:
    $Site = Get-SPSite “http://localhost&#8221;

    # To get a site below the root site collection level:
    $Site = Get-SPSite “http://localhost/sites/<SiteName>&#8221;

    # To create a custom usage event type:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $EventGuid = [Guid]::NewGuid()
    $EventName = “<EventTypeName>”
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Guid]::Empty)
    $newEventType = $tenantConfig.RegisterEventType($EventGuid, $EventName, “”)
    $tenantConfig.Update($SSP)

    Where:

  • <SiteName> is the name of the site for which you want to create a custom usage event.
  • <EventTypeName> is the name of the new custom usage event type that you want to create for example, BuyEventType.

    This procedure creates a random GUID for the usage event type. Use this GUID when you add code to record the custom usage event, as described in Record a custom usage event.

        Important:

It can take up to three hours for a custom usage event type to become available in the system. However, to speed up the process, you can alternatively restart the SharePoint Timer Service.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

  • Record a custom usage event

    After you have created a custom usage event type, as described in Create a custom usage event type, you have to add code to the place where the event occurs for example, when a page loads, or when a user clicks a link or a button. This data is then sent to the analytics processing component, where it is recorded and processed.

    If you are using cross-site publishing, where you show catalog content on a publishing site, you must record the usage event on the URL of the indexed item, and override some site settings. For example, if you have a catalog in an authoring site that you have published on a publishing site, when a user interacts with a catalog item on the publishing site, this usage event must be recorded on the item in the authoring site. Furthermore, the code that you add to record the usage event must override the SiteId and the WebId of the publishing site, and be replaced with the SiteId and the WebId of the authoring site.

    To add code to record a custom usage event

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    # To view GUIDs for all usage event types:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $SSP.GetAnalyticsEventTypeDefinitions([Guid]::Empty, 3) | ft

  2. In an HTML editor, open the file where the custom usage event should be logged for example, a display template for a Content Search Web Part, and add the following code:


    window.Log<CustomUsageEventType>ToEventStore = function(url)
    {
    ExecuteOrDelayUntilScriptLoaded(function()
    {
    var spClientContext = SP.ClientContext.get_current();
    var eventGuid = new SP.Guid(“<GUID>”);
    SP.Analytics.AnalyticsUsageEntry.logAnalyticsAppEvent(spClientContext, eventGuid, url);
    spClientContext.executeQueryAsync(null, Function.createDelegate(this, function(sender, e){ alert(“Failed to log event for item: ” + document.URL + ” due to: ” + e.get_message()) }));
    }, “SP.js”);
    }Where:

  • <CustomUsageEventType> is the name of the custom event for example, BuyEventType.
  • <GUID> is the numeric ID of the usage event type for example, 4e605543-63cf-4b5f-aab6-99a10b8fb257.
  1. In an HTML editor, open the file that refers to the custom usage event, and add the following code:

    # The example below shows how a custom usage event type is referred to when a button is clicked:
    <button onclick=”Log<CustomUsageEventType>ToEventStore(‘<URL>’)”></button>

    Where:

  • <CustomUsageEventType> is the name of the custom event type.
  • <URL> is the full URL of the item to which the usage event should be logged for example, http://contoso.com/faq.

To add code to record a custom usage event and override site settings

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    # To view GUIDs for all usage event types:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $SSP.GetAnalyticsEventTypeDefinitions([Guid]::Empty, 3) | ft

  2. In an HTML editor, open the file where the custom usage event should be logged for example, a display template for a Content Search Web Part. The following example shows how to override the current SiteId, WebId and UserId.


    window.Log<CustomUsageEventType>ToEventStore = function(url, siteIdGuid, webIdGuid, spUser)
    {
    ExecuteOrDelayUntilScriptLoaded(function()
    {
    var spClientContext = SP.ClientContext.get_current();
    var eventGuid = new SP.Guid(“<GUID>”);
    SP.Analytics.AnalyticsUsageEntry.logAnalyticsAppEvent2(spClientContext, eventGuid, url, webIdGuid, siteIdGuid, spUser);
    spClientContext.executeQueryAsync(null, Function.createDelegate(this, function(sender, e){ alert(“Failed to log event for item: ” + document.URL + ” due to: ” + e.get_message()) }));
    }, “SP.js”);
    }

    Where:

  • <CustomUsageEventType> is the name of the custom event type for example, BuyEventType.
  • <GUID> is the numeric ID of the usage event type for example, 4e605543-63cf-4b5f-aab6-99a10b8fb257.
  1. In an HTML editor, open the file that refers to the custom usage event type, and add the following code:

    # The example below shows how a custom usage event type is referred to when the “Buy!” button is clicked:
    <button onclick=”Log<CustomUsageEventType>ToEventStore(‘<URL>’, new SP.Guid(‘{<SiteId GUID>}’), new SP.Guid(‘{<WebId guid}>’), ‘<UserName>’)”>Buy!</button>

    Where:

  • <CustomUsageEventType> is the name of the custom event type for example, BuyEventType.
  • <URL> is the URL found in the managed property OriginalPath.
  • <SiteId GUID> is the GUID in the managed property SiteID.
  • <WebId GUID> is the GUID in the managed property WebId.
  • <UserName> can for example, be a cookie ID that is used to identify users on a site that has anonymous users.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    # To view EventTypeId for all usage event types:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $SSP.GetAnalyticsEventTypeDefinitions([Guid]::Empty, 3) | ft

  2. In an HTML editor, open the file where the custom usage event should be logged for example, a display template for a Content Search Web Part, and add the following code:


    window.Log<DefaultUsageEventType>ToEventStore = function(url)
    {
    ExecuteOrDelayUntilScriptLoaded(function()
    {
    var spClientContext = SP.ClientContext.get_current();
    SP.Analytics.AnalyticsUsageEntry.logAnalyticsEvent(spClientContext, <EventTypeId>, url);
    spClientContext.executeQueryAsync(null, Function.createDelegate(this, function(sender, e){ alert(“Failed to log event for item: ” + document.URL + ” due to: ” + e.get_message()) }));
    }, “SP.js”);
    }

    Where:

  • <DefaultUsageEventType> is the name of the default usage event type for example, Views.
  • <EventTypeId> is the numeric ID of the usage event type for example, 1.
  1. In an HTML editor, open the file that refers to the default usage event, and add the following code:

    # The example below shows how a default usage event type is referred to on a page load:
    <body onload=
    Log<DefaultUsageEventType>ToEventStore(‘<URL>’)>

    Where:

  • <DefaultUsageEventType> is the name of the default usage event type for example, Views.
  • <URL> is the full URL of the item to which the usage event should be logged, for example, http://contoso.com/careers
  1. Save the file.

To add code to record a default usage event and override site settings

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    # To view EventTypeId for all usage event types:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $SSP.GetAnalyticsEventTypeDefinitions([Guid]::Empty, 3) | ft

  2. In an HTML editor, open the file where the custom usage event should be logged for example, a display template for a Content Search Web Part. The example below shows how to override the current SiteId, the WebId and the UserId.


    window.Log<DefaultUsageEventType>ToEventStore = function(url, siteIdGuid, webIdGuid, spUser)
    {
    ExecuteOrDelayUntilScriptLoaded(function()
    {
    var spClientContext = SP.ClientContext.get_current();
    SP.Analytics.AnalyticsUsageEntry.logAnalyticsEvent(spClientContext, <EventTypeId>, url, webIdGuid, siteIdGuid, spUser);
    spClientContext.executeQueryAsync(null, Function.createDelegate(this, function(sender, e){ alert(“Failed to log event for item: ” + document.URL + ” due to: ” + e.get_message()) }));
    }, “SP.js”);
    }

    Where:

  • <DefaultUsageEventType> is the name of the default event type for example, Views.
  • <EventTypeId> is the numeric ID of the usage event type for example, 1.
  1. In an HTML editor, open the file that refers to the default usage event type, and add the following code:

    # The example below shows how a default usage event type is referred to on a page load:
    <body onload=
    Log<DefaultUsageEventType>ToEventStore(‘<URL>’, new SP.Guid(‘{<SiteId GUID>}’), new SP.Guid(‘{<WebId GUID>}’), ‘<UserName>’)>

    Where:

  • <DefaultUsageEventType> is the name of the default event type for example, Views.
  • <URL> is the URL in the managed property OriginalPath.
  • <SiteId GUID> is the GUID in the managed property SiteID.
  • <WebId GUID> is the GUID in the managed property WebId.
  • <UserName><UserName> can for example, be a cookie ID that is used to identify users on a site that has anonymous users

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    # To view EventTypeId for all usage event types:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $SSP.GetAnalyticsEventTypeDefinitions([Guid]::Empty, 3) | ft

    # To get a usage event type:
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Guid]::Empty)
    $event = $tenantConfig.EventTypeDefinitions | where-object { $_.EventTypeId -eq <EventTypeId> }

    # To change the importance level of a usage event type:
    $event.RecommendationWeight = <RecommendationWeightNumber>
    $tenantConfig.Update($SSP)

    # To verify the changed importance level for the usage event type:
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Guid]::Empty)
    $event = $tenantConfig.EventTypeDefinitions | where-object { $_.EventTypeId -eq <EventTypeId> }
    $event

    Where:

  • <EventTypeId> is the numeric ID of the usage event type for which you want to change the weight for example, 256.
  • <RecommendationWeightNumber> is the level of importance that you want to apply to the user event type for example, 4.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    # To view EventTypeId for all usage event types:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $SSP.GetAnalyticsEventTypeDefinitions([Guid]::Empty, 3) | ft

    # To get a usage event type:
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Guid]::Empty)
    $event = $tenantConfig.EventTypeDefinitions | where-object { $_.EventTypeId -eq <EventTypeId> }

    # To change the Recent time span for a usage event type:
    $event.RecentPopularityTimeFrame = <TimeFrame>
    $tenantConfig.Update($SSP)

    # To verify the changed Recent time frame for the usage event type:
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Guid]::Empty)
    $event = $tenantConfig.EventTypeDefinitions | where-object { $_.EventTypeId -eq <EventTypeId> }
    $event

    Where:

  • <EventTypeId> is the numeric ID of the usage event type for which you want to change the Recent time frame for example, 256.
  • <TimeFrame> is the new Recent time frame that you want to apply to the user event type for example, 7.

        Note:

The system updates any changes to the Recent time period only after the Usage Analytics Timer Job has run.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    # To view EventTypeId for all usage event types:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $SSP.GetAnalyticsEventTypeDefinitions([Guid]::Empty, 3) | ft

    # To get a usage event type:
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Guid]::Empty)
    $event = $tenantConfig.EventTypeDefinitions | where-object { $_.EventTypeId -eq <EventTypeId> }

    # To enable the logging of anonymous users:
    $event.Options = [Microsoft.Office.Server.Search.Analytics.EventOptions]::AllowAnonymousWrite
    $tenantConfig.Update($SSP)

    # To verify that the logging of anonymous users has been enabled, i.e. that the Options property is set to AllowAnonymousWrite:
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Guid]::Empty)
    $event = $tenantConfig.EventTypeDefinitions | where-object { $_.EventTypeId -eq <EventTypeId> }
    $event

    Where:

  • <EventTypeId> is the numeric ID of the usage event type that you want to enable for the logging of anonymous users for example, 256.

To disable the logging of usage events of anonymous users

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    # To view EventTypeId for all usage event types:
    $SSP = Get-SPEnterpriseSearchServiceApplicationProxy
    $SSP.GetAnalyticsEventTypeDefinitions([Guid]::Empty, 3) | ft

    # To get a usage event type:
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Guid]::Empty)
    $event = $tenantConfig.EventTypeDefinitions | where-object { $_.EventTypeId -eq <EventTypeId> }

    # To disable the logging of anonymous users:
    $event.Options = [Microsoft.Office.Server.Search.Analytics.EventOptions]::None
    $tenantConfig.Update($SSP)

    # To verify that logging of anonymous users has been disabled, i.e. that the Options property is set to None:
    $tenantConfig = $SSP.GetAnalyticsTenantConfiguration([Gui

    Where:

  • <EventTypeId> is the numeric ID of the usage event type that you want to disable for the logging of anonymous users for example, 256.

        Note:

For the default usage event type Views, you cannot disable the logging of anonymous users.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

 

 

  1. Log on to the computer in the SharePoint Server 2013 farm where Workflow Manager was installed.
  2. Open the SharePoint Management Shell as an administrator. This is accomplished by right-clicking the SharePoint 2013 Management Shell and choosing Run as administrator.
  3. Run the Register-SPWorkflowService cmdlet.

    Example:

Register-SPWorkflowService SPSite “http://myserver/mysitecollection&#8221; WorkflowHostUri “http://workflow.example.com:12291&#8221; AllowOAuthHttp

To configure Workflow Manager on a server that is part of the SharePoint 2013 farm and on which communication takes place by using HTTPS

  1. Determine if you need to install Workflow Manager certificates in SharePoint.

    Under some circumstances, you have to obtain and install Workflow Manager certificates. If your installation requires that you obtain and install these certificates, you must complete that step before continuing. To learn whether you need to install certificates, and for instructions, see Installing Workflow Manager certificates in SharePoint Server 2013.

  2. Log into the computer in the SharePoint Server 2013 farm where Workflow Manager was installed.
  3. Open the SharePoint Management Shell as an administrator. This is accomplished by right-clicking the SharePoint 2013 Management Shell and choosing Run as administrator.
  4. Run the Register-SPWorkflowService cmdlet.

    Example:

Register-SPWorkflowService SPSite “https://myserver/mysitecollection&#8221; WorkflowHostUri “https://workflow.example.com:12290&#8221;

To configure Workflow Manager on a server that is NOT part of the SharePoint 2013 farm and on which communication takes place by using HTTP

  1. Log on to each Web Front End (WFE) server in the SharePoint Server 2013 farm.
  2. Install the Workflow Manager Client on each WFE server in the SharePoint farm.

    Before you can run the workflow pairing cmdlet, you must install Workflow Manager Client on each of the WFE servers in the SharePoint farm.

    You can download and install the Workflow Manager Client here: http://go.microsoft.com/fwlink/p/?LinkID=268376

  3. Open the SharePoint Management Shell as an administrator. This is accomplished by right-clicking the SharePoint 2013 Management Shell command and choosing Run as administrator.
  4. Run the Register-SPWorkflowService cmdlet. The cmdlet should be run only once and can be run from any of the WFE servers in the SharePoint farm. Example:

    Register-SPWorkflowService SPSite “http://myserver/mysitecollection&#8221; WorkflowHostUri “http://workflow.example.com:12291&#8221; AllowOAuthHttp

    Important:

You must install the Workflow Manager Client on each Web Front End (WFE) server in the SharePoint farm before you run the pairing cmdlet.

To configure Workflow Manager on a server that is NOT part of the SharePoint 2013 farm and on which communication takes place by using HTTPS

  1. Determine whether you need to install Workflow Manager certificates in SharePoint 2013.

    Under some circumstances, you have to obtain and install Workflow Manager certificates. If your installation requires that you obtain and install these certificates, you must complete that step before continuing. To learn whether you need to install certificates, and for instructions, see Installing Workflow Manager certificates in SharePoint Server 2013.

  2. Log on to each Web Front End (WFE) server in the SharePoint Server 2013 farm.
  3. Install the Workflow Manager Client on each WFE server in the SharePoint farm.

    Before you can run the workflow pairing cmdlet, you must install Workflow Manager Client on each of the WFE servers in the SharePoint farm.

    You can download and install the Workflow Manager Client here: http://go.microsoft.com/fwlink/p/?LinkID=268376

  4. Open the SharePoint Management Shell as an administrator. This is accomplished by right-clicking the SharePoint 2013 Management Shell command and choosing Run as administrator.
  5. Run the Register-SPWorkflowService cmdlet. Example:

    Register-SPWorkflowService SPSite “https://myserver/mysitecollection&#8221; WorkflowHostUri “https://workflow.example.com:12290&#8221;

    Important:

You must install the Workflow Manager Client on each Web Front End (WFE) server in the SharePoint farm before you run the pairing cmdlet.

  • Validate the installation

    Use these steps to validate that you have successfully installed and configured the required components.

    To validate the installation

  1. Add a user to your SharePoint site, and grant the user Site Designer permissions.
  2. Install SharePoint Designer 2013 and create a workflow based on the SharePoint 2013 Workflow platform. For more information, see Creating a workflow by using SharePoint Designer 2013 and the SharePoint 2013 Workflow platform.
  3. Run this workflow from the SharePoint user interface.
  1. If SSL is enabled either on SharePoint Server 2013 (which is not the default) or on Workflow Manager (which is the default), AND
  2. If SharePoint Server 2013 and Workflow Manager do not share a Certificate Authority, AND
  3. If Workflow Manager is configured to generate self-signed certificates (which is the default).

    Note:

Product trial, workflow development, and troubleshooting are easier if SSL is not enabled. However, communication between SharePoint Server 2013 and Workflow Manager is not encrypted if SSL is not enabled. For this reason, SSL should be enabled for production configurations.

To obtain and export certificates from the Workflow Manager server

  1. On a computer that has Workflow Manager installed, choose IIS Manager, Sites. Right-click Workflow Management Site, and then choose Edit Bindings.
  2. Choose the https port, and then choose Edit. Choose the View button in the SSL Certificate section.
  3. To export the issuer certificate, do the following:
    1. In the Certificate window, choose the Certification path tab.
    2. Select root certification path and choose View.
    3. On the Details tab, choose Export Certificate, and take the default options in the export wizard.
    4. Give the exported certificate file a friendly name.

To install certificates on SharePoint Server 2013

  1. Copy the issuer certificate to your SharePoint Server 2013 computer.
  2. Add the certificates to the Windows Certificate store.
  3. For each certificate, do the following:
    1. Double-click the file to open and view the certificate.
    2. On the certificate, choose the Install Certificate button to start the installation wizard.
    3. In the wizard, choose Place all certificates in the following store, and then choose Trusted Root Certification Authorities.
  4. Add the certificates to SharePoint Server by going to the SharePoint Management shell and running the New-SPTrustedRootAuthority cmdlet. Do this for each certificate file.

 

 

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    New-SPWebApplication -Name <Name> -ApplicationPool <ApplicationPool> -AuthenticationMethod <WindowsAuthType> -ApplicationPoolAccount <ApplicationPoolAccount> -Port <Port> -URL <URL>

    Where:

  • <Name> is the name of the new web application.
  • <ApplicationPool> is the name of the application pool.
  • < WindowsAuthType > is either NTLM or Kerberos. Kerberos is recommended.
  • <ApplicationPoolAccount> is the user account that this application pool will run as.
  • <Port> is the port on which the web application will be created in IIS.
  • <URL> is the public URL for the web application.
  • Example

    New-SPWebApplication -Name “Contoso Internet Site” -ApplicationPool “ContosoAppPool” -AuthenticationMethod “Kerberos” -ApplicationPoolAccount (Get-SPManagedAccount “CONTOSO\jdoe”) -Port 80 -URL “https://www.contoso.com&#8221;

For more information, see New-SPWebApplication.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

After this procedure is complete, you can create one or more site collections for this web application. For more information, see Create a site collection.

After you successfully create the web application, when you open the Central Administration page, you see a health rule warning that indicates that one or more web applications is enabled with classic authentication mode. This is a reflection of our recommendation to use claims-based authentication instead of classic mode authentication.

 

 

  1. Verify that you have the following administrative credentials:
  • To create a web application, you must be a member of the Farm Administrators SharePoint group.
  1. Start SharePoint 2013 Central Administration.
  • For Windows Server 2008 R2:
    • Click Start, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Central Administration.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Central Administration.

      If SharePoint 2013 Central Administration is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Central Administration.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. On the Central Administration Home page, click Application Management.
  2. On the Application Management page, in the Web Applications section, click Manage web applications.
  3. In the Contribute group of the ribbon, click New.
  4. On the Create New Web Application page, in the IIS Web Site section, you can configure the settings for your new web application by selecting one of the following two options:
  • Click Use an existing IIS web site, and then select the web site on which to install your new web application.
  • Click Create a new IIS web site, and then type the name of the web site in the Name box.
  • In the Port box, type the port number you want to use to access the web application. If you are using an existing web site, this field contains the current port number.

        Note:

The default port number for HTTP access is 80, and the default port number for HTTPS access is 443.

  • Optional: In the IIS Web Site section, in the Host Header box, type the host name (for example, http://www.contoso.com) that you want to use to access the web application.

        Note:

You do not need to populate this field unless you want to configure two or more IIS web sites that share the same port number on the same server, and DNS has been configured to route requests to the same server.

  • In the Path box, type the path to the IIS web site home directory on the server. If you are creating a new web site, this field contains a suggested path. If you are using an existing web site, this field contains the current path of that web site.
  1. In the Security Configuration section, choose whether or not to Allow Anonymous access and whether or not to Use Secure Sockets Layer (SSL).

    Important:

Secure Sockets Layer (SSL) is a requirement for web applications that are deployed in scenarios that support server-to-server authentication and app authentication. In general, we strongly recommend using SSL for web applications.

  • In the Security Configuration section, click Yes or No for the Allow Anonymous options. If you choose to Yes, visitors can use the computer-specific anonymous access account (that is, IIS_IUSRS) to access the web site.

        Note:

If you want users to be able to access any site content anonymously, you must enable anonymous access for the entire web application zone before you enable anonymous access at the SharePoint site level. Later, site owners can configure anonymous access for their sites. If you do not enable anonymous access at the web application level, site owners cannot enable anonymous access at the site level.

  • In the Security Configuration section, click Yes or No for the Use Secure Sockets Layer (SSL) options. If you choose Yes, you must request and install an SSL certificate to configure SSL. For more information about how to set up SSL, see How to Setup SSL on IIS 7.0.
  1. In the Claims Authentication Types section, select the authentication method that you want to use for the web application.
  • To enable Windows authentication, select Enable Windows Authentication and, in the drop-down menu, select NTLM or Negotiate (Kerberos). We recommend using Negotiate (Kerberos).

    If you do not want to use Integrated Windows authentication, clear Integrated Windows authentication.

        Note:

If you do not select Windows Authentication for at least one zone of this web application, crawling for this web application will be disabled.

  • If you want users’ credentials to be sent over a network in a nonencrypted form, select Basic authentication (credentials are sent in clear text).

        Note:

You can select basic authentication or integrated Windows authentication, or both. If you select both, SharePoint 2013 offers both authentication types to the client web browser. The client web browser then determines which type of authentication to use. If you only select Basic authentication, ensure that SSL is enabled. Otherwise, a malicious user can intercept credentials.

  • To enable forms-based authentication, select Enable Forms Based Authentication (FBA), and then enter the ASP.NET Membership provider name and the ASP.NET Role manager name.

        Note:

If you select this option, ensure that SSL is enabled. Otherwise, a malicious user can intercept credentials.

  • If you have set up Trusted Identity Provider authentication by using Windows PowerShell, the Trusted Identity provider check box is selected.
  1. In the Sign In Page URL section, choose one of the following options to sign into SharePoint 2013:
  • Select Default Sign In Page URL to redirect users to a default sign-in web site for claims-based authentication.
  • Select Custom Sign In page URL and then type the sign-in URL to redirect users to a customized sign-in web site for claims-based authentication.
  1. In the Public URL section, type the URL for the domain name for all sites that users will access in this web application. This URL will be used as the base URL in links that are shown on pages within the web application. The default URL is the current server name and port, and it is automatically updated to reflect the current SSL, host header, and port number settings on the page. If you deploy SharePoint 2013 behind a load balancer or proxy server, then this URL may need to be different than the SSL, host header, and port settings on this page.

    The Zone value is automatically set to Default for a new web application. You can change the zone when you extend a web application.

  2. In the Application Pool section, do one of the following:
  • Click Use existing application pool, and then select the application pool that you want to use from the drop-down menu.
  • Click Create a new application pool, and then type the name of the new application pool, or keep the default name.
  • Click Predefined to use a predefined security account for this application pool, and then select the security account from the drop-down menu.
  • Click Configurable to specify a new security account to be used for an existing application pool.

        Note:

To create a new account, click the Register new managed account link.

  1. In the Database Name and Authentication section, choose the database server, database name, and authentication method for your new web application, as described in the following table.
  • Item

Action

Database Server

Type the name of the database server and SQL Server instance you want to use in the format <SERVERNAME\instance>. You can also use the default entry.

Database Name

Type the name of the database, or use the default entry.

Database Authentication

Select the database authentication to use by doing one of the following:

  • To use Windows authentication, leave this option selected. We recommend this option because Windows authentication automatically encrypts the password when it connects to SQL Server.
  • To use SQL authentication, click SQL authentication. In the Account box, type the name of the account that you want the web application to use to authenticate to the SQL Server database, and then type the password in the Password box.

    Note:

SQL authentication sends the SQL authentication password to SQL Server in an unencrypted format. We recommend that you only use SQL authentication if you force protocol encryption to SQL Server to encrypt your network traffic by using IPsec.

  1. If you use database mirroring, in the Failover Server section, in the Failover Database Server box, type the name of a specific failover database server that you want to associate with a content database
  2. In the Service Application Connections section, select the service application connections that will be available to the web application. In the drop-down menu, click default or [custom]. You use the [custom] option to choose the service application connections that you want to use for the web application.
  3. In the Customer Experience Improvement Program section, click Yes or No.
  4. Click OK to create the new web application.
  • Create a claims-based web application by using Windows PowerShell

    Use the procedure in this section to create a new claims-based SharePoint 2013 web application using Windows PowerShell.

    To create a claims-based web application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • You must read about_Execution_Policies.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 15 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Permissions and Add-SPShellAdmin.

  1. To create a claims-based authentication provider, from the Windows PowerShell command prompt, type the following:

    $ap = New-SPAuthenticationProvider

  2. To create a claims-based web application, from the Windows PowerShell command prompt, type the following:

    New-SPWebApplication -Name <Name>
    -ApplicationPool <ApplicationPool>
    -ApplicationPoolAccount <ApplicationPoolAccount>
    -URL <URL> -Port <Port> -AuthenticationProvider $ap

    Where:

  • <Name> is the name of the new web application that uses claims-based authentication.
  • <ApplicationPool> is the name of the application pool.
  • <ApplicationPoolAccount> is the user account that this application pool will run as.
  • <URL> is the public URL for this web application.
  • <Port> is the port on which the web application will be created in IIS.

        Note:

For more information, see New-SPWebApplication.

The following example creates an https claims-based web application, using the current user credentials and the current machine name:

$waUrl = “https://&#8221; + $env:ComputerName
$siteAdmin = $env:userdomain + “\” + $env:username;
CreateWindowsWebApp -url $waUrl -title “WinClaimsInbound” -site_admin $siteAdmin -app_pool_name “WebAppPool1” -app_pool_account $siteAdmin -use_claims
use_ssl;

    Note:

After you have created the web site, you must configure SSL in IIS for this newly created web site. For more information about how to set up SSL, see How to Setup SSL on IIS 7.0.

If you want your web application to use HTTP, do not use the use_ssl parameter, and use the http scheme for the url parameter.

  • Create a classic-mode web application by using Windows PowerShell

    Use the procedure in this section to create a new classic-mode SharePoint 2013 web application using Windows PowerShell.

    To create a classic-mode web application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • You must read about_Execution_Policies.
  1. From the Windows PowerShell command prompt, type the following:

    New-SPWebApplication Name <Name>
    ApplicationPool <ApplicationPool>
    -AuthenticationMethod <WindowsAuthType>
    ApplicationPoolAccount <ApplicationPoolAccount>
    -Port <Port> -URL <URL>

    Where:

  • <Name> is the name of the new web application that uses classic-mode authentication.
  • <ApplicationPool> is the name of the application pool.
  • <WindowsAuthType> is either NTLM or Kerberos. Kerberos is recommended.
  • <ApplicationPoolAccount> is the user account that this application pool will run as.
  • <Port> is the port on which the web application will be created in IIS.
  • <URL> is the public URL for the web application.

        Note:

For more information, see New-SPWebApplication.

    Note:

After you successfully create the web application, when you open the Central Administration page, you see a health rule warning that indicates that one or more web applications is enabled with classic authentication mode. This is a reflection of our recommendation to use claims-based authentication instead of classic mode authentication.

 

 

  1. Verify that you a member of the Administrators group on the server on which you are configuring IIS.
  2. Click Start, point to Administrative Tools, and then click Internet Information Services (IIS) Manager to start IIS Manager console.
  3. Expand Sites in the console tree, and then click the IIS web site that corresponds to the web application zone on which you want to configure basic authentication.
  4. In Features View, in IIS, double-click Authentication.
  5. In Features View, in Authentication, right-click Basic Authentication, and then click Enable.
  6. Right-click Basic Authentication, and then click Edit.
  7. In the Edit Basic Authentication Settings dialog box, in the Default domain text box, type the appropriate default domain.

    The default domain is the name of a domain against which you want users to be authenticated when they do not provide a domain name.

  8. In the Realm text box, type the appropriate realm, and then click OK.

    The realm is a DNS domain name or an IP address that will use the credentials that are authenticated against your internal Windows domain. Configuring a realm name for basic authentication is optional.

The web site is now configured to use basic authentication.

You can also configure basic authentication when you create a web application in SharePoint Central Administration by selecting Basic authentication (password is sent in clear text) in the Claims Authentication Types section of the Create New Web Application dialog box. For more information, see Create claims-based web applications in SharePoint 2013.

    Security

In the Claims Authentication Types section of the Create New Web Application dialog box, you can select Integrated Windows authentication, Basic authentication (password is sent in clear text), or both. If you select both, SharePoint 2013 will offer both authentication types to the client web browser. The client web browser then determines the type of authentication to use. If you only select Basic authentication (password is sent in clear text), make sure that you enable SSL for this web application.

 

 

  1. Verify that you are a member of the Administrators group on the server on which you are configuring IIS.
  2. Click Start, point to Administrative Tools, and then click Internet Information Services (IIS) Manager to start IIS Manager console.
  3. Expand Sites in the console tree, and then click the IIS web site that corresponds to the web application zone on which you want to configure digest authentication.
  4. In Features View, in IIS, double-click Authentication.
  5. In Features View, in Authentication, right-click Digest Authentication, and then click Enable.
  6. Right-click Digest Authentication, and then click Edit.
  7. In the Edit Digest Authentication Settings dialog box, in the Realm text box, type the appropriate realm, and then click OK.

    The realm is a DNS domain name or an IP address that will use the credentials that have been authenticated against your internal Windows domain. You must configure a realm name for digest authentication.

The web site is now configured to use digest authentication.

 

  1. Verify that the user account that performs this procedure is a local administrator on the domain controller.
  2. Click Start, point to Administrative Tools, and then click DNS.
  3. In DNS Manager, right-click Forward Lookup Zones, and then click New Zone….
  4. In the New Zone Wizard, click Next.
  5. In the Zone Type page, accept the default of Primary zone, and then click Next.
  6. In the Active Directory Zone Replication Scope page, select the appropriate replication method for your environment (the default is To all DNS servers in this domain), and then click Next.
  7. In the Zone Name page, in the Zone name box type the name for your new app domain name (for example, ContosoApps.com), and then click Next.

    The New Zone Wizard shows the new domain name for apps.



  8. On the Dynamic Update page, select the appropriate type of dynamic updates for your environment (the default is Do not allow dynamic updates), and then click Next.
  9. On the Completing the New Zone Wizard page, review the settings, and then click Finish.

For more information about how to create a forward lookup zone, see Add a Forward Lookup Zone.

You have now created a forward lookup zone (and a domain name) to use for apps in your environment.

To create a wildcard Alias (CNAME) record for the new domain name

  1. Verify that the user account that performs this procedure is a local administrator on the domain controller.
  2. In DNS Manager, under Forward Lookup Zones, right-click the new app domain name, and then click New Alias (CNAME).
  3. In the New Resource Record dialog box, in the Alias name (uses parent domain if left blank) box, type *.

    The Fully qualified domain name (FQDN) box displays *. followed by the domain name that you created for apps. For example, *.ContosoApps.com or *.Contoso-Apps.com.

  4. Next to the Fully qualified domain name (FQDN) for target host box, type the FQDN of the server that hosts the SharePoint sites.

    For example, SharePoint.Contoso.com.

    Or:

    1. Next to the Fully qualified domain name (FQDN) for target host box, click Browse and navigate to the Forward Lookup Zone for the domain that hosts the SharePoint sites.

    For example, Contoso.com.

    1. And then navigate to the record that points to the server that hosts the SharePoint site.

    For example, SharePoint.

    New Resource Record dialog box shows the wildcard alias for the app domain and the FQDN of the server that hosts the SharePoint sites.



  5. Click OK.

For more information about how to create a wildcard alias record in DNS Manager, see Add an Alias (CNAME) Resource Record to a Zone.

You can verify the new domain name and alias by pinging them.

To verify the new domain name

  1. Verify that the user account that is performing this procedure is a local administrator on the domain controller.
  2. Click Start, and then click Command Prompt.
  3. At the command prompt, type ping followed by a subdomain of the domain that you created, and then press ENTER.

    For example, ping Apps-12345678ABCDEF.contosoapps.com

    If the ping command returns the correct IP address, then your wildcard for the domain name was configured successfully.

  1. Verify that you are a member of the farm administrators group in Central Administration.
  2. In SharePoint 2013 Central Administration, click System Settings.
  3. On the System Settings page, under Servers, click Manage services on server.
  4. On the Services on Server page, next to App Management Service, click Start.
  5. On the Services on Server page, next to Microsoft SharePoint Foundation Subscription Settings Service, click Start.
  6. Verify that the App Management and Microsoft SharePoint Foundation Subscription Settings services are running. The following illustration shows the Services on Server page where you can verify that the App Management and Subscription Settings services are running.

    Services on Server showing the App Management and Subscription Settings services running.



To configure the Subscription Settings service application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 15 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. First you must establish the application pool, run as account, and database settings for the services. Use a farm account for the SPManagedAccount (which will be used for the application pool runas account).

    At the Windows PowerShell command prompt, type the following commands, and press ENTER after each one to create the application pool:

    $account = Get-SPManagedAccount “<farm account>
    # Gets the name of the Farm administrators account and sets it to the variable $account for later use.

    Where:

  • <farm account> is the name of the Farm administrators account in the SharePoint farm.

    $appPoolSubSvc = New-SPServiceApplicationPool -Name SettingsServiceAppPool -Account $account
    # Creates an application pool for the Subscription Settings service application.
    # Uses the Farm administrators account as the security account for the application pool.
    # Stores the application pool as a variable for later use.

  1. At the Windows PowerShell command prompt, type the following commands, and press ENTER after each one to create the new service application and proxy:

    $appSubSvc = New-SPSubscriptionSettingsServiceApplication ApplicationPool $appPoolSubSvc Name SettingsServiceApp DatabaseName <SettingsServiceDB>
    # Creates the Subscription Settings service application, using the variable to associate it with the application pool that was created earlier.
    # Stores the new service application as a variable for later use.

    Where:

  • <SettingsServiceDB> is the name of the Subscription Settings service database.

    $proxySubSvc = New-SPSubscriptionSettingsServiceApplicationProxy ServiceApplication $appSubSvc
    # Creates a proxy for the Subscription Settings service application.

For more information, see Get-SPManagedAccount, New-SPServiceApplicationPool, New-SPSubscriptionSettingsServiceApplication, New-SPSubscriptionSettingsServiceApplicationProxy.

You can use either Windows PowerShell or Central Administration to create and configure the App Management service application. The following procedures provide the steps for each method.

To configure the App Management service application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 15 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. First you must establish the application pool, run as account, and database settings for the services. Use a farm account for the SPManagedAccount (which will be used for the application pool runas account).

    At the Windows PowerShell command prompt, type the following commands, and press ENTER after each one to create the application pool:

    $account = Get-SPManagedAccount “<farm account>
    # Gets the name of the Farm administrators account and sets it to the variable $account for later use.

    Where:

  • <farm account> is the name of the Farm administrators account in the SharePoint farm.

    $appPoolAppSvc = New-SPServiceApplicationPool -Name AppServiceAppPool -Account $account
    # Creates an application pool for the Application Management service application.
    # Uses the Farm administrators account as the security account for the application pool.
    # Stores the application pool as a variable for later use.

  1. At the Windows PowerShell command prompt, type the following commands, and press ENTER after each one to create the new service application and proxy:

    $appAppSvc = New-SPAppManagementServiceApplication -ApplicationPool $appPoolAppSvc -Name AppServiceApp -DatabaseName <AppServiceDB>
    # Creates the Application Management service application, using the variable to associate it with the application pool that was created earlier.
    # Stores the new service application as a variable for later use.

    Where:

  • <AppServiceDB> is the name of the App Management service database.

    $proxyAppSvc = New-SPAppManagementServiceApplicationProxy -ServiceApplication $appAppSvc
    # Creates a proxy for the Application Management service application.

For more information, see Get-SPManagedAccount, New-SPServiceApplicationPool, New-SPAppManagementServiceApplication and New-SPAppManagementServiceApplicationProxy.

To create the App Management service application in Central Administration

  1. In SharePoint 2013 Central Administration, on the Application Management page, click Manage service applications.
  2. On the ribbon, click New, and then click App Management Service.
  3. In the New App Management Service Application page, in the Service Application Name box, type the name for the service application.
  4. In the Database section, in the Database Server box, type the instance of SQL Server where you want to store the database, or use the default server.
  5. In the Database Name box, type a database name, or use the default name.

    The database name must be unique.

  6. Under Database authentication, select the authentication that you want to use by doing one of the following:
  • If you want to use Windows authentication, leave this option selected. We recommend this option because Windows authentication automatically encrypts the password when it connects to SQL Server.
  • If you want to use SQL authentication, click SQL authentication. In the Account box, type the name of the account that you want the service application to use to authenticate to the SQL Server database, and then type the password in the Password box.

        Note:

In SQL authentication, an unencrypted password is sent to SQL Server. We recommend that you use SQL authentication only if you force protocol encryption to SQL Server or encrypt network traffic by using IPsec.

  1. In the Failover Database Server section, if you want to use a failover database server, specify the server name.
  2. In the Application Pool section, do one of the following:
  • Click Use existing application pool, and then select the application pool that you want to use from the drop-down list.
  • Click Create a new application pool, type the name of the new application pool, and then under Select a security account for this application pool do one of the following:
    • Click Predefined to use a predefined security account, and then select the security account from the drop-down list.
    • Click Configurable to specify a new security account to be used for an existing application pool. You can create a new account by clicking the Register new managed account link.
  1. In the Create App Management Service Application Proxy section, leave the Create App Management Service Application Proxy and add it to the default proxy group check box selected.
  2. Click OK.

    The following illustration shows the App Management service application and proxy that were created.

    Manage Service Applications page showing the App Management service application and proxy.

    Now you must start the service on the server.

  3. In SharePoint 2013 Central Administration, click System Settings.
  4. On the System Settings page, under Servers, click Manage services on server.
  5. On the Services on Server page, next to App Management Service, click Start.
  1. In Central Administration, click Apps.
  2. On the Apps page, click Configure App URLs.
  3. In the App domain box, type the isolated domain that you created for hosting apps.

    For example, ContosoApps.com or Contoso-Apps.com.

  4. In the App prefix box, type a name to use for the URL prefix for apps.

    For example, you could use apps as the prefix so that you would see a URL for each app such as apps-12345678ABCDEF.ContosoApps.com. The following illustration shows the Configure App URLs page after you have filled in the App domain and prefix.

    The Configure App URLs page in Central Administration shows the App domain and App prefix.



  5. Click OK.

Use the following procedure to configure app URLs for multi-tenant hosting environments.

To configure app URLs by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 15 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following commands and press ENTER after each one:

    Set-SPAppDomain <appDomain>

    Set-SPAppSiteSubscriptionName -Name “app” -Confirm:$false

    Where:

  • <appDomain> is the domain name that you created.

For more information, see Set-SPAppSiteSubscriptionName and Set-SPAppDomain.

  • Configure the Internet-facing endpoints feature (Optional)

    The SharePoint Store contains apps for SharePoint intended for use with sites that require Internet-facing endpoints. By default, these apps are not available (greyed out and cannot be purchased) because they are incompatible with most sites. However, if you have a site that uses Internet-facing endpoints, and want to be able to use these apps, you can turn on the Internet-facing endpoints feature to show these apps in the SharePoint Store. You turn this feature on at the web application level in Central Administration.

    To configure Internet-facing endpoints for apps

  1. In Central Administration, click Application Management.
  2. On the Application Management page, click Manage Web applications.
  3. On the Manage Web Applications page, select the web application that you want to change.
  4. On the Ribbon, click Manage Features.
  5. In the feature list, next to Apps that require accessible internet facing endpoints, click Activate.
  6. Click OK.

 

 

  1. Verify that the user account that is performing this procedure is a member of the Farm administrators group.
  2. In Central Administration, on the Apps page, in the App Management section, click Manage App Catalog.

    If no App Catalog exists for the farm, the Web Application page opens, so you can select a web application.

  3. On the Web Application page, select the web application for which you want to create a catalog.
  4. In the App Catalog Site section, select Create a new app catalog site, and then click OK.
  5. On the Create App Catalog page, in the Title box, type a title for the App Catalog site.
  6. In the Description box, type the description for the site.
  7. In the URL box, fill in the URL to use for the site.
  8. In the Primary Site Collection Administrator section, in the User Name box, type the user who will manage the catalog.

    Only one user name can be entered. Security groups are not allowed.

  9. In the End Users section, in the Users/Groups box, type the names of the users or groups that you want to be able to browse the catalog.

    Added users or groups have read access to the App Catalog site. You can add multiple user names and security groups. Users must be added as End Users to be able to browse the App Catalog from their site collections.

  10. In the Select a quota template list box, select the quota template to use for the site.
  11. Click OK.

To use an existing App Catalog site collection for a different web application

  1. Verify that the user account that is performing this procedure is a member of the Farm administrators group.
  2. In Central Administration, on the Apps page, in the App Management section, click Manage App Catalog.
  3. On the Manage App Catalog page, next to Web Application, click the down arrow and click Change Web Application.
  4. In the Select Web Application box, select the web application for which you want to create a catalog.
  5. In the App Catalog section, select Enter a URL for an existing app catalog site.
  6. In the URL box, type the URL to the App Catalog site, and then click OK.

To view an App Catalog site collection from Central Administration

  1. Verify that the user account that is performing this procedure is a member of the Farm administrators group and has Read permission to the App Catalog site.
  2. In Central Administration, on the Apps page, in the App Management section, click Manage App Catalog.
  3. On the Manage App Catalog page, verify that the web application that is selected is the web application you want to manage.

    If you want to switch to a different web application, click the down arrow next to the Web application URL to change to a different web application.

  4. Under Site URL click the link to open the App Catalog for that web application.
  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators group.
  2. In Central Administration, on the Apps page, in the SharePoint and Office Store section, click Configure Store Settings.
  3. On the SharePoint Store Settings page, verify that the selected web application is the web application that you want to configure.

    If you want to switch to a different web application, click the down arrow next to the web application URL to change to a different web application.

  4. To allow or prevent purchases, select an option for Should end users be able to get apps from the SharePoint Store?
  • Select Yes to allow users to purchase apps.
  • Select No to prevent purchases but allow users to request apps.
  1. To allow or prevent apps for Office from the Office Store to be started when a user opens a document in the browser, select an option for Should apps for Office from the store be able to start when documents are opened in the browser?
  • Select Yes to allow apps for Office from the Office Store to start.
  • Select No to prevent apps for Office from the Office Store from starting.
  1. Click OK.

When users request an app for SharePoint from the SharePoint Store, users can request a specific number of licenses and provide a justification for the purchase of the app for SharePoint. Submitted requests are added to the App Requests list in the App Catalog of the web application that contains a users site collection. The app request includes the following fields:

  • Requested by The user name of the person requesting the app for SharePoint.
  • Title The title of the app for SharePoint.
  • Seats and Site License The number of licenses the user requested for that app for SharePoint.
  • Justification The reason why the app for SharePoint would be useful for the organization.
  • Status By default, the status is set to New for new requests. The person who reviews the request can change the status to Pending, Approved, Declined, Withdrawn, Closed as Approved, or Closed as Declined.
  • View App Details A link to the app details page in the SharePoint Store.
  • Approver Comments The person who reviews the request can add comments for the requestor.

To view and manage app requests from the SharePoint Store Settings page

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators group and is a member of the site Owners or Designers group for the App Catalog.
  2. In Central Administration, on the Apps page, in the SharePoint and Office Store section, click Configure Store Settings.
  3. On the SharePoint Store Settings page, verify that the selected web application is the web application that you want to configure.

    If you want to switch to a different web application, click the down arrow next to the web application URL to change to a different web application.

  4. In the App Requests section, click Click here to view app requests.

    The App Requests list in the App Catalog site opens.

  5. Select a request in the list, and then click the Edit button.
  6. Review the details of the request.

    Note:

At this time, the View app details link in the request details opens the SharePoint Store home page, instead of the details page for the app. Search for the app in the SharePoint Store to find more information about the app.

  1. Change the Status to the appropriate value – Approved if you want to user to be able to purchase the app, or Declined if you do not want to allow the purchase.
  2. Add comments in the Approver Comments box, and then click Save.

    To view a request, requestors can go to the Add an App page in their site collection, and then click Your Requests.

To view and manage app requests from the App Catalog site

  1. Verify that the user account that is performing this procedure is a member of the site Owners or Designers group for the App Catalog.
  2. On the App Catalog site, click the App Requests list.
  3. Select a request in the list, and then click the Edit button.
  4. Review the details of the request.

    Note:

At this time, the View app details link in the request details opens the SharePoint Store home page, instead of the details page for the app. Search for the app in the SharePoint Store to find more information about the app.

  1. Change the Status to the appropriate value – Approved if you want to user to be able to purchase the app, or Declined if you do not want to allow the app to be purchased.
  2. Add any comments in the Approver Comments box, and then click Save.

    To view a request, requestors can go to the Add an App page in their site collection, and then click Your Requests.

  1. Verify that the user account that is performing this procedure is a member of the site Owners or Designers group for the App Catalog.
  2. On the App Catalog site, click the Apps for SharePoint list.

    On the Apps for SharePoint page, click new item.

  3. In the Choose a file box, click Browse, and then locate the folder that contains the app that you want to upload.

    Tip:

You can also click Upload files using Windows Explorer instead to drag and drop an app for SharePoint into the App Catalog.

  1. Select the app, and then click Open.
  2. Click OK to upload the app.
  3. In the Item details box, verify the Name, Title, Short Description, Icon URL, and other settings for the app.

    Be sure that the Enabled check box is selected so that users can see the app in their sites.

    You can select the Featured check box to list the app in the Featured content view of the App Catalog.

  4. Click Save.

You can also categorize apps in the App Catalog. To add categories, edit the Category field for the App Catalog list and add the category names you want to use.

You can preview how the app will appear to users.

  1. Verify that the user account that is performing this procedure is a member of the site Owners or Designers group for the App Catalog.
  2. On the App Catalog site, click the Apps for SharePoint list.
  3. On the Apps for SharePoint page, select the app that you want to remove.
  4. In the ribbon, on the Files tab, click Delete Document to remove the app.
  5. In the dialog box, click OK to confirm that you want to send the item to the site Recycle Bin.

    The app is removed.

 

 

  1. Verify that the user account that is performing this procedure is a member of the site Owners group.
  2. On the home page, under Get started with your site, click Add lists, libraries, and other apps.

    If the Get started with your site control does not appear on the home page, click the Settings icon, and click View Site Contents, and then on the Site Contents page, click Add an App.

  3. In the Your Apps list, click the app you want to add.
  4. Follow the instructions to Trust the app (if it is a custom component) or Name the app (if it is a SharePoint component).

    The app for SharePoint is added and appears in the Apps section of your Site Contents list.

To add an app from an App Catalog

  1. Verify that the user account that is performing this procedure is a member of the site Owners group.
  2. On the home page, under Get started with your site, click Add lists, libraries, and other apps.

    If the Get started with your site control does not appear on the home page, click the Settings icon, and click View Site Contents, and then on the Site Contents page, click Add an App.

  3. Click FromName.

    Where Name is the name of your organization’s App Catalog. For example, “From Contoso”.

    Tip:

Apps marked as Featured in the App Catalog will also appear in the main list of Apps.

  1. Click the app you want to add.
  2. In the Grant Permission to an App dialog box, if you trust the app, click Allow Access.

    The app for SharePoint is added and appears in Apps section of your Site Contents list.

To add an app from the SharePoint Store

  1. Verify that the user account that is performing this procedure is a member of the site Owners group.
  2. On the home page, under Get started with your site, click Add lists, libraries, and other apps.

    If the Get started with your site control does not appear on the home page, click the Settings icon, and click View Site Contents, and then on the Site Contents page, click Add an App.

  3. Click SharePoint Store.
  4. Browse the SharePoint Store to find an app that you want.
  5. Click the app you want to add.
  6. Click Details, and then click Buy It.
  7. Follow the steps to log in and purchase the app, if required.
  8. In the Grant Permission to an App dialog box, if you trust the app, click Allow Access.

    The app for SharePoint is added and appears in the Apps section of your Site Contents list.

You can also install an app by using Windows PowerShell. First, you import the app package from the file system, and then install it to the site collection. The following procedure contains a script to perform these steps.

To install an app by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Site Owners group on the site collection to which you want to install the app.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command to import the app and then press ENTER:

    $spapp = Import-SPAppPackage -Path Path to app -Site URL -Source Source
    # Imports the app and sets a variable that you can use to identify the app when you install it in the next step.

    Where:

  • Path to app is the path to the app you want to import on the file system.
  • URL is URL for the site collection to which you want to import the app.
  • Source is one of the following: Marketplace, CorporateCatalog, DeveloperSite, ObjectModel, RemoteObjectModel, or InvalidSource.
  1. At the question Are you sure you want to perform this action?, type Y to import the app.

    The app is imported and information about the app, including the Asset ID, version string, and Product ID is displayed.

  2. At the Windows PowerShell command prompt, type the following command to add the app to a site and then press ENTER:

    Install-SPApp -Web URL -Identity $spapp
    # Installs the app to the subweb you specify.
    # Uses the $spapp variable you set previously to identify that app you want to install.

    Where:

  • URL is URL for the site or subweb to which you want to install the app.

For more information, see Import-SPAppPackage and Install-SPApp.

 

 

  1. Verify that the user account that is performing this procedure is a member of the Site owners group.
  2. On the site, on the Settings menu, click View Site Contents.
  3. In the Apps section, point to the app that you want to remove, click , and then click Remove.
  4. Click OK to confirm that you want to remove the app.

Before you use the following procedure, be sure to get the title for the app that you want to remove.

To remove an app by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Site Owners group on the site collection to which you want to install the app.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 15 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following commands, and press ENTER after each one:

    $instances = Get-SPAppInstance -Web <URL>
    # Gets all apps installed to the subsite you specify.

    $instance = $instances | where {$_.Title -eq ‘<App_Title>‘}
    # Sets the $instance variable to the app with the title you supply.

    Uninstall-SPAppInstance -Identity $instance
    # Uninstalls the app from the subsite.

    Where:

  • <URL> is the path site collection or subsite that contains the app.
  • <App_Title> is the title of the app you want to remove.
  1. At the question Are you sure you want to perform this action?, type Y to uninstall the app.

For more information, see Get-SPAppInstance, Uninstall-SPAppInstance.

 

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. In Central Administration, click General Application Settings.
  3. On the General Application Settings page, in the Apps section, click Monitor Apps.
  4. On the Monitored Apps page, in the Action group of the ribbon, click Add App.

    Note:

If the App Catalog is not already created, or if the App Management Service application and app domain settings are not configured correctly the Add App dialog may create an error.

  1. Select the checkbox for the app that you want to monitor, or type a name in the Search for app name box, and then click the Search icon.
  2. On the search results page, select the app that you want to monitor.

    Note:

Apps that you add to the Monitored Apps list previously are not displayed in the search results.

  1. Click Add App.

    The app now appears in the list of monitored apps.

To remove an app from the monitor apps list

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. On the Monitored Apps page, select the checkbox next to the app that you want to remove.
  3. In the Manage group of the ribbon, click Remove App.
  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. On the Monitored Apps page, click the app that you want to view.

    A new page opens and displays detailed information about the app, such as the following: licensing, errors, installations, and usage.

    Note:

The administrator can also select an app in the monitored apps list and in the App Details group of the ribbon, click View Details.

  1. In the Usage section, click Days, Months, or Years to change the chart to those time frames.

To view the app error details in Monitored Apps

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. On the Monitored Apps page, click the number in the Runtime Errors column for the app you want to view.

    Note:

The administrator can also select an app in the monitored apps list and in the App Details group of the ribbon, click View Errors.

  1. The App Monitoring Details dialog appears with information about each error for that app. You can use the Correlation ID to find the errors in the error log.
  2. Click the URL in the Location column to view more error details for this app.
  3. On the App Monitoring Details page, click the number next to Runtime Errors.
  4. The App Monitoring Details dialog appears and includes a list of all Runtime Errors for this app, the time each error occurred, and the Correlation ID.

    Note:

The app error list can help you determine if you want to remove the app because there are too many errors or if the app is working as it should.

  1. Verify that the user account that is performing this procedure is a member of the site Owners group.
  2. On the Site Contents page, in the quick launch pane, click Apps.

    A new page opens and displays all of the apps that are installed on this site.

  3. On the Apps page click the icon next to the app you want to monitor and then click Details in the callout.

    The App Details page appears for the selected app and the site owner can see the details for licenses, errors Installs and usage.

  4. In the Errors section, click the number next to Install Errors, Runtime Errors, or Upgrade Errors to see the error details.

    For example, click the number next to Runtime Errors and the Runtime Errors dialog appears. This includes a list of all Runtime Errors for this app, the time each error occurred, and the Correlation ID.

    This app error list can help you determine if you want to remove the app because there are too many errors or if the app is working as it should.

    Note:

The app errors that appear in this list have occurred within the previous four days.

  1. In the Usage section, click Days, Months, or Years to change the chart to those time frames.

    The chart displays two bars for each time period that represents the number of times the app has been launched and the number of specific users that use this app each day.

    Note:

If the app uses connections to external data sources through Business Connectivity Services, a graph that shows the number of calls made to the external data sources is also shown. Dates that appear in the Usage and BCS Calls graphs are in Coordinated Universal Time (UTC).

 

 

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group or a license manager.
  2. In Central Administration, click Apps.
  3. On the Apps page, in the Store section, click Manage App Licenses.
  4. On the Manage App Licenses page, click an app for SharePoint in the list to view the license details.

    The Manage App License page shows detailed licensing information. This includes the name of the app, the developer, and current license details.

  5. In the top section, click the drop-down arrow in the dialog box to see purchase details for the selected app for SharePoint.

    The app details include the following information:

  • Number of licenses available for users
  • License type
  • App purchaser name
  1. At the end of the dialog box, a farm administrator can view the app details.
  • Click View in Store to see the app details.
    • In the People with a License (number of licenses available)section, the number of available licenses and a list of the people who currently have licenses for this App are shown.
    • In the License Managers section, all app managers are listed.

To add users to the app license

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. On the Manage App Licenses page, click an app for SharePoint for which you want to add users.
  3. In the People with a License section, click assign people.
  4. In the dialog box that appears below, enter the user name that you want to add and then, click Add User.

    The user name is added to the list at the bottom of this section and the number of available licenses for this app is refreshed for the selected app for SharePoint.

To purchase more app licenses

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. On the Manage App Licenses page, click an app for SharePoint for which you want to purchase more licenses.
  3. In the People with a License section, click buy more licenses.
  4. The SharePoint Store opens with the specific app showing the details with links to purchase additional licenses. Choose the number of Apps you want to purchase and then click OK.

To remove app licenses

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. On the Manage App Licenses page, click an app for SharePoint for which you want to remove licenses.
  3. In the top section, under the app for SharePoint name, at the end of the dialog box, click Remove this License.
  4. Verification: Optionally, include steps that users should perform to verify that the operation was successful.

To recover app licenses

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. On the Manage App Licenses page, click an app for SharePoint for which you want to recover licenses.
  3. In the top section, under the app name, at the end of the dialog box, click Recover License.

    The app for SharePoint details show any changes the administrator has made.

To add a license manager

  1. Verify that the user account that is performing this procedure is a member of the Farm Administrators SharePoint group.
  2. On the Manage App License page, in the License Managers section, click add manager.

    Below the License Managers section, the new App manager appears in the list.

 

 

  1. Create and configure a new farm that is separate from the old farm
  2. Copy the content and services databases to the new farm
  3. Upgrade the data and sites

You can upgrade the content databases in any order and upgrade several databases at the same time to speed up the overall process.

For more information, see Overview of the upgrade process to SharePoint 2013.

  1. A server farm administrator installs SharePoint 2013 to a new farm. The administrator configures farm settings and tests the environment.
  2. A server farm administrator sets the SharePoint 2010 Products farm to read-only so that users can continue to access the old farm while upgrade is in progress on the new farm.

    Figure: Create new farm, set old farm to read-only



  1. With the farm and databases in read-only mode, a server farm administrator backs up the content and service application databases from the SQL Server instance on the SharePoint 2010 Products farm.
  2. The server farm administrator restores a copy of the databases to the SQL Server instance on the SharePoint 2013 farm and sets the databases to read-write on the new farm.

    Figure: Use SQL Server tools to copy databases



  1. A server farm administrator configures the service applications for the new farm. The following service applications have databases that you can upgrade during this process:
  • SharePoint Server 2010 and SharePoint Foundation 2010
    • Business Data Connectivity service application
  • SharePoint Server 2010 only
    • Managed Metadata service application
    • PerformancePoint Services service application
    • Search service application
    • Secure Store Service application
    • User Profile service application
  1. A server farm administrator creates a web application on the SharePoint 2013 farm for each web application on the SharePoint 2010 Products farm.

    Figure: Create web applications for upgrade



  2. A server farm administrator installs all server-side customizations.

    Figure: Copy customizations to the new farm



  3. A server farm administrator then attaches the content databases to the new farm and upgrades the content databases for those web applications.

    Figure: Upgrade the databases by using Windows PowerShell



  4. A server farm administrator confirms that the upgrade is successful.
  1. The My Site host has not been upgraded. My Sites cannot be upgraded yet.
  2. A server farm administrator has upgraded the My Site host. No My Sites have been upgraded.
  3. Some users have upgraded their My Sites.
  4. All My Sites have been upgraded.

    Note:

A server farm administrator can choose to force an upgrade of My Sites without waiting for users to upgrade them. For details and steps, read Upgrade site collections to SharePoint 2013.

Owners of all other site collections can start to upgrade their sites as soon as they see a notification on their site’s home page that the new version is available. The following illustration shows four stages for a site collection during the upgrade process.

Stages in upgrading site collections



  1. The site owner runs the site collection health checks to determine readiness for upgrade. The site owner addresses issues before they continue with the next step.
  2. Optionally, the site owner requests an upgrade evaluation site collection. A timer job runs to create the site collection and the site owner receives an email message when the evaluation site collection is ready. The site owner previews the new user interface. After several days or weeks, the evaluation site collection expires and is deleted by a timer job.

    A server farm administrator can determine the length of time before expiration.

  3. When the site owner is ready, the site owner starts the upgrade process. The site collection health checks are run again automatically. The site owner must address issues before upgrading. If health checks return no issues, the upgrade starts.
  4. When upgrade is complete, the site owner sees the Upgrade Status page that contains the status and a link to the upgrade logs. The site owner reviews the site to make sure that everything works correctly.

    Note:

A server farm administrator can also force specific site collections to be upgraded without waiting for the site owners to upgrade them. For details and steps, read Upgrade site collections to SharePoint 2013.

 

 

  1. Know what is in your environment. Do a full survey first.

    Document the hardware and software in your environment, where server-side customizations are installed and used, and the settings that you need. This helps you plan the trial environment and also helps you recover if upgrade fails. A worksheet is available to record information about your environment. Download the worksheet at SharePoint 2013 Products Preview Upgrade Worksheet.

  2. Make your test environment as similar as possible to your real environment.

    If possible, use the same kind of hardware and use the same settings, the same URLs, and so on to configure it. Minimize the differences between your test environment and your real environment. As you introduce more differences, you are likely to spend time resolving unrelated issues to make sure that they will not occur during the actual upgrade.

  3. Use real data.

    Use copies of your actual databases to run the tests. When you use real data, you can identify trouble areas and also determine upgrade performance. You can also measure how long different upgrade sequences and actions take on different kinds of data. If you cannot test all the data, test a representative subset of the data. Make sure that you find issues with the different kinds and sizes of sites, lists, libraries, and customizations that are present in your environment. If you cannot test all data because of storage concerns, try going over the data in several passes, removing the old trial copies before going on to the next batch.

  4. Run multiple tests.

    A single test can tell you whether you will encounter big problems. Multiple tests will help you find all the issues that you might face and help you estimate a more accurate timeline for the process. By running multiple tests, you can determine the following:

  • The upgrade approaches that will work best for your environment
  • The downtime mitigation techniques that you should plan to use
  • How the process or performance may change after you address the issues that you uncovered in your first tests

    Your final test pass can help you validate whether you have addressed the errors and are ready to upgrade your production environment.

  1. Do not ignore errors or warnings.

    Even though a warning is not an error, a warning could lead to problems in the upgrade process. Resolve errors, but also investigate warnings to make sure that you know the results that a warning might produce.

  2. Test the upgraded environment, not just the upgrade process.

    Check your service applications and run a search crawl and review the log files.

For more information about how to test upgrade, see Use a trial upgrade to SharePoint 2013 to find potential issues and the SharePoint 2013 Products Preview – Test Your Upgrade Process model.

  • Best practices for upgrading to SharePoint 2013

    To guarantee a smooth upgrade from SharePoint 2010 Products to SharePoint 2013, follow these best practices:

  1. Ensure that the environment is fully functioning before you begin to upgrade.

    An upgrade does not solve problems that already exist in your environment. Therefore, make sure that the environment is fully functioning before you start to upgrade. For example, if you are not using web applications, unextend them before you upgrade. If you want to delete a web application in Internet Information Services (IIS), unextend the web application before you delete it. Otherwise, SharePoint 2013 will try to upgrade the web application even though it does not exist, and the upgrade will fail. If you find and solve problems beforehand, you are more likely to meet the estimated upgrade schedule.

  2. Perform a trial upgrade on a test farm first.

    Copy your databases to a test environment and perform a trial upgrade. Examine the results to determine the following:

  1. Plan for capacity.

    Ensure that you have enough disk, processor, and memory capacity to handle upgrade requirements. For more information about system requirements, see System requirements (SharePoint 2013 Preview). For more information about how to plan the disk space that is required for upgrade, see Plan for performance during upgrade to SharePoint 2013.

  2. Clean up before you upgrade

    Issues in your environment can affect the success of upgrade, and unnecessary or very large amounts of data can affect upgrade performance for both databases and site collections. If you don’t need something in your environment, consider removing it before upgrade. If there are issues detected, try to resolve them before you start to upgrade. For more information, see Clean up an environment before an upgrade to SharePoint 2013.

  3. Back up your databases.

    Perform a full backup of your databases before you upgrade. That way, you can try upgrade again if it fails.

  4. Optimize your environment before upgrade.

    Be sure to optimize your SharePoint 2010 Products environment to meet any limits or restrictions, either from your business or governance needs or from the SharePoint 2013 boundaries and limits before upgrade. This will help reduce errors during the upgrade process and prevent broken lists or sites after upgrade. For more information about limits in the product, see SharePoint Server 2010 Capacity Management: Software Boundaries and Limits. For more information about large lists and how to address the lower limit on site collections, see Clean up an environment before an upgrade to SharePoint 2013.

  5. (Optional) Set the original databases to read-only if you want to keep your original environment available while you upgrade.

    If you expect a long outage period while you upgrade, you can set the databases in the original environment to read-only. Users can continue to access the data but cannot change it. For more information, see Attach databases and upgrade to SharePoint 2013.

  6. After upgrade, review the Upgrade Status page and upgrade logs to determine whether you must address issues. Then review the upgraded sites.

    The Upgrade Status page reports on the upgrade progress, and the upgrade logs list any errors or warnings that occurred during the upgrade process. Verify all the sites and test them before you consider the upgrade finished. For more information, see Verify database upgrades in SharePoint 2013 and Review site collections upgraded to SharePoint 2013.

  7. Defer upgrade for site collections until you can get updated customizations to support 2013 mode.

    If you wait until the customizations are available, you can complete the initial upgrade of database and services without significantly affecting use of the existing sites in 2010 mode.

 

  1. Keep the customizations, don’t upgrade the sites   You can continue to run the site in 2010 mode in the upgraded environment. Although you can use this approach to keep the same functionality, you will be unable to take advantage of the features and capabilities that are available in the new version. Use this approach only temporarily – eventually you must address the issue (such as before an upgrade to the next version of the product).
  2. Replace or redo the customizations   If you want to use new functionality, plan to redesign your sites, or are significantly changing the information architecture, the upgrade is your opportunity to start over with new features, a new look, or a new organization. When you replace or redo customizations, you can take advantage of the new capabilities, change your design slightly if you want, or move to a more manageable design.
  3. Discard the customizations   Replace the customizations by using default functionality. You can reset pages to the default site definitions and remove any Web Parts or features that you no longer want to support. In fact, the site collection health-checker checks for unghosted pages and can reset the pages to the default versions. If you decide to discard any customizations, you must fix any issues that result from removing the customizations in the sites that used them. You can use your customizations inventory to determine which sites require this kind of attention before or after upgrade.
  1. If you have an Enterprise version of SQL Server, the Create Upgrade Evaluation Site Collections job timer takes a snapshot of the database and reads the data from the snapshot to a destination database (with the source database being the default target). This doesnt affect the read-only status of the source site throughout the whole process.
  2. For other versions of SQL Server that do not have snapshot capabilities, the Create Upgrade Evaluation Site Collections job timer backs up a site collection and restores it to a new URL. This makes the source site read-only for the whole duration of the process.

The Upgrade Site Collections job collects the list of site collections that were queued for upgrade and then upgrades the queued sites from oldest to newest. The recently added evaluation site is then upgraded (or at least upgrade is tried).

  1. Because of the web application throttle limit, only five sites can start to upgrade for web application 1 – instance 1 on Web server 1.
  2. An additional five sites start to upgrade on web application 1 – instance 2 on Web server 2.
  3. Because of the content database throttle, five sites are sent to the upgrade queue to wait their turn.

You can use the default throttling settings, or you can specify your own values for how many site collections can be upgraded at the same time. Farm administrators can also override throttle settings when they upgrade a site by using Windows PowerShell. Exercise caution when you change these values and make sure that you verify the settings that you want to use in a test environment before you implement them in production. If you increase throttling too much, you could create performance problems in your environment. For example, too many parallel upgrades could affect site rendering. For information about how to change these settings, see Manage site collection upgrades to SharePoint 2013.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2010 Products.
  3. Click SharePoint 2010 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command to return all site collections that are in or have subwebs in the old experience:

    Get-SPSite | ForEach-Object{$_.GetVisualReport()}

  5. At the Windows PowerShell command prompt, type the following command to upgrade those sites to the new experience:

    Get-SPSite | ForEach-Object{$_.VisualUpgradeWebs()}

For more information, see Get-SPSite and Manage visual upgrade (SharePoint Server 2010).

  • Repair data issues

Make sure that you repair all issues in your databases or site content before you upgrade. In particular, check the following items:

  • Check databases for corrupted data

    Clean up your databases to remove any orphaned sites or other corrupted data, such as a corrupted list. Consider defragmenting if you have removed sites or subsites from the database. For more information, see:

  • Check databases for duplicate or orphaned site collections

    Make sure that site collections exist in only one content database. Occasionally, site collections can leave behind duplicate or orphaned references in old content databases if they are moved to new databases, or if a copy of a database was attached to the farm, or if there was an error when a site collection was provisioned. If a site collection is referenced in more than one content database or there is more than one instance of the site collection in a content database, it can cause issues when you upgrade by using the database attach upgrade method. If you upgrade a duplicate version of the site collection first, the site map in your configuration database might end up pointing to that version of the site instead of the current version.

    Before you upgrade, use the Enumallwebs operation in stsadm command-line tool to discover which sites are in which content databases and compare the results. Also, examine each site collection in the results and check whether it is listed as missing in the site map. Being listed as missing indicates that it is an orphaned site. For more information, see Enumallwebs: Stsadm operation. If you find duplicate or orphaned sites, you can use the Remove-SPSite cmdlet in Windows PowerShell to remove the duplicate or orphaned sites from the database.

    For more information, see Remove-SPSite.

  • Check variations

    In publishing environments, check for any variations that must be fixed. For more information, see Variationsfixuptool: Stsadm operation.

  1. Review the Upgrade Status page in the SharePoint Central Administration website.

    For more information about how to check upgrade status, see Verify database upgrades in SharePoint 2013.

  2. Review the following log files:
  • The upgrade error log file and the upgrade log file (which contains more detailed information than the upgrade error log file).
  • ULS or trace log files.

    These files are stored in the %COMMONPROGRAMFILES%\Microsoft Shared\Web Server Extensions\15\LOGS folder and are named Servername_YYYYMMDDMMSS.log.

  • The application event log file.

    This file can be viewed by using the Event Viewer.

    For more information about the upgrade log files, see Verify database upgrades in SharePoint 2013. For more information about the trace log file, see Trace Logs on MSDN.

  • Then, address issues in order

Some issues have more effect than others. For example, a missing server-side file can cause many seemingly unrelated errors at the site level.

Address issues in the following order:

  1. Missing server-side files or customizations, such as features or Web Parts.

    Be sure to install all server-side customizations, such as features, Web Parts, and so on. Be sure to install customizations to the correct location in your new farm. For example, additional style sheets that you must have for SharePoint 2010 Products should be installed in the /14 path, not the new /15 path so that site collections that you have not upgraded can use them. Also, make sure that that you transfer all unique settings from the Web.config files for each web application to the new servers.

  2. Configuration issues in the server farm, web application, or service applications, such as managed paths or service applications that are not started.
  3. Additional issues that you discover on a site-by-site basis, starting with high-profile or very important sites.

As you identify and fix the top-level issues, you can try to run upgrade again to see whether any issues that occurred later in the upgrade process have also been fixed.

  1. Review the upgrade status page for your site collection.

    On the Site Settings page for the site collection, in the Site Collection Administration section, click Site collection upgrade. On the Site Collection Upgrade page, click Review Site Collection Upgrade Status.

  2. Review the site collection upgrade log files. You can review the site collection upgrade logs from the following locations:
  • For site collection administrators: There are also log files for site collection upgrade stored inside the site collection itself, in the Maintenance Logs catalog at (http://<SiteName>/_catalogs/MaintenanceLogs/YYYYMMDD-HHMMSS-SSS.txt , where YYYYMMDD is the date and HHMMSS-SSS is the time (hours in 24-hour clock format, minutes, seconds, and milliseconds).
  • For farm administrators: The site collection upgrade log file and the upgrade error log file are located at %COMMONPROGRAMFILES%\Microsoft Shared\Web server extensions\15\LOGS. The logs are named in the following format: SiteUpgrade-YYYYMMDD-HHMMSS-SSS.log, where YYYYMMDD is the date and HHMMSS-SSS is the time (hours in 24-hour clock format, minutes, seconds, and milliseconds). These file system logs have more information if you want details about issues.
  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt (PS C:\>), type the following command:

    upgrade-spcontentdatabase <Name>

    Where:

  • Name is the database name that you want to upgrade.

    You can also use the -id parameter and provide the database GUID instead of a database name. You can run the following cmdlet to find the GUID for a content database:

    Get-SPContentDatabase -Identity <content_database_name>

    For more information, see Upgrade-SPContentDatabase and Get-SPContentDatabase.

  • Restart upgrade for a site collection

    If upgrade ran into issues during a site collection upgrade, you can restart the upgrade process for the site collection after you have addressed the issue. You can use either the Site Settings page or a Windows PowerShell cmdlet to restart upgrade for a site collection.

    To restart upgrade for a site collection

  1. Verify that the user account that performs this procedure is a site collection administrator.
  2. On the Site Settings page for the site collection, in the Site Collection Administration section, click Site collection upgrade.
  3. On the Site Collection Upgrade page, click Upgrade this Site Collection.

    This option starts to upgrade your site collection. A box opens to verify that you want to start the process.

  4. Click I’m ready to start the actual upgrade.

    Note:

The site collection health checks are run automatically in repair mode before the upgrade starts. The results from the health checks are included in the upgrade log for the site collection. If there is an error, you must address it before you can continue to upgrade.

The upgrade starts, and the Upgrade status page for the site collection is displayed. This page automatically updates while the upgrade is in progress and displays information about the process, such as the following:

  • Errors or warnings
  • When the upgrade started
  • Where you can find the upgrade log file

    After the upgrade is complete, the Upgrade status page is displayed in the new user interface with the message, Upgrade Completed Successfully.

  1. Click Let’s see the new site to go to the home page.

Farm administrators can restart upgrade by using Windows PowerShell.

To restart upgrade for a site collection by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    Upgrade-SPSite <http://site&gt; -VersionUpgrade [-Unthrottled]

    Where:

  • <http://site&gt; is the URL for the site collection.
  • Add the option -Unthrottled option to skip the site collection upgrade queue and start the upgrade immediately.

For more information, see Upgrade-SPSite.

 

 

  1. Run the Microsoft SharePoint Products Preparation Tool to install all required software.
  2. Run Setup to install the product.
  3. Install all language packs that you want in your environment.

    Note:

For more information about how to install available language packs, see Install or uninstall language packs for SharePoint 2013.

  1. Run the SharePoint Products Configuration Wizard to configure your server or servers.

    Important:

Some service applications can be upgraded by using a service application database upgrade. If you want to upgrade these service applications by upgrading the service application databases, do not use the Farm Configuration Wizard to configure these service applications when you set up your new farm.

For step-by-step instructions for these tasks, see Install SharePoint 2013.

Back to top

  1. Verify that the user account that is performing this procedure is a member of the db_owner fixed database role for the databases.
  2. In SQL Server Management Studio, in Object Explorer, connect to an instance of the Database Engine, expand the server, and then expand Databases.
  3. Find the database that you want to configure to be read-only, right-click the database, and then click Properties.
  4. In the Database Properties dialog box, in the Select a page section, click Options.
  5. In the details pane, under Other options, in the State section, next to Database Read-Only, click the arrow, and then select True.

You can use Transact-SQL to configure the READ_ONLY database availability option. For more information about how to use the SET clause of the ALTER DATABASE statement, see Setting Database Options.

Back to top

  1. Verify that the user account that is performing this procedure is a member of the db_owner fixed database role for the databases.
  2. In Management Studio, in Object Explorer, connect to an instance of the Database Engine, expand the server, and then expand Databases.
  3. Right-click the database that you want to back up, point to Tasks, and then click Back Up.

    The Back Up Database dialog box appears.

  4. In the Source area, in the Database box, verify the database name.
  5. In the Backup type box, select Full.
  6. Under Backup component, select Database.
  7. In the Backup set area, in the Name box, either accept the backup set name that is suggested or type a different name for the backup set.
  8. In the Destination area, specify the type of backup destination by selecting Disk or Tape, and then specify a destination. To create a different destination, click Add.
  9. Click OK to start the backup process.

Repeat the previous procedure to back up all the content and appropriate service application databases that SharePoint 2010 Products uses in your environment.

    Important:

Before you can back up the Search service application Administration database, you must stop the Search service on your SharePoint Server 2010 farm. To stop the Search service, on the original farm, on the Start menu, click Administrative Tools, and then click Services. Right-click SharePoint Server Search 14, and then click Stop. Be sure to start the service again after you back up the database.

Back to top

  1. Verify that you have the following memberships:
  • Administrators group on the server on which you are running the command.
  1. Open the Command Prompt window, and then change to the following folder:

    %Program Files%\Microsoft Office Servers\14.0\Synchronization Service\Bin\

  2. To export the key, type the following at the command prompt, and then press ENTER:

    miiskmu.exe

  3. In the Microsoft Identity Integration Server Key Management Utility wizard, verify that Export key set is selected, and then click Next.
  4. In the Account Name box, type the account name for the farm administrator.
  5. In the Password box, type the password for the farm administrator.
  6. In the Domain box, type the domain that contains the farm administrator account, and then click Next.
  7. In the Specify export file name and location box, type or click browse to select the path and file name to use for the exported key, and then click Next.

    The key is exported as a file that has a .BIN file name extension.

  8. Verify the information, and then click Finish.

    A message appears indicating that the key was successfully exported.

  9. Click Close to close the Microsoft Identity Integration Server Key Management Utility.

For more information, see Back up a User Profile Service application (SharePoint Server 2010).

Back to top

  1. Verify that the user account that is performing this procedure is a member of the db_owner fixed database role for the databases.
  2. After you connect to the appropriate instance of the SQL Server 2008 Database Engine, in Object Explorer, expand the server name.
  3. Right-click Databases, and then click Restore Database.

    The Restore Database dialog box appears.

  4. In the Restore Database dialog box, on the General page, type the name of the database to be restored in the To database list.

    Tip:

When you type the name for the restored database, you do not have to use the original name. If you want to change the database name from a name with a long GUID to a shorter, more friendly name, this is an opportunity to make that change. Be sure to also change the database and log file names in the file system (the MDF and LDF files) so that they match.

  1. In the To a point in time text box, keep the default (Most recent possible).
  2. To specify the source and location of the backup sets to restore, click From device, and then use the browse button to select the backup file.
  3. In the Specify Backup dialog box, in the Backup media box, be sure that File is selected.
  4. In the Backup location area, click Add.
  5. In the Locate Backup File dialog box, select the file that you want to restore, click OK, and then, in the Specify Backup dialog box, click OK.
  6. In the Restore Database dialog box, under Select the backup sets to restore grid, select the Restore check box next to the most recent full backup.
  7. In the Restore Database dialog box, on the Options page, under Restore options, select the Overwrite the existing database check box.
  8. Click OK to start the restore process.

Back to top

  1. In SQL Server Management Studio, in Object Explorer, connect to an instance of the Database Engine, expand the server, and then expand Databases.
  2. Select the database that you want to configure to be read-write, right-click the database, and then click Properties.
  3. In the Database Properties dialog box, in the Select a page section, click Options.
  4. In the details pane, under Other options, in the State section, next to Database Read-Only, click the arrow, and then select False.

Back to top

  1. Start the service instances

    The first step is to start service instances for the five service applications that you can upgrade: the Business Data Connectivity service, Managed Metadata Web Service, PerformancePoint Services service, Secure Store service, User Profile service, and Search service. Most of these service instances can be started from Central Administration. However the SharePoint Server Search service instance must be started by using Windows PowerShell.

  2. Create the service applications and upgrade the databases

    After you have started the service instances, the next step is to create the service applications and upgrade the databases. You must use Windows PowerShell to restore the service application databases.

  3. Create proxies for the service applications

    After you have upgraded the service application databases, you create the proxies for the service applications and add them to the default proxy group. You must create proxies for the following service applications:

  • Managed Metadata service application
  • Search service application
  • Secure Store service application
  • PerformancePoint Services service application
  • User Profile service application

    The Business Data Connectivity service application automatically creates a proxy and assigns it to the default proxy group when you create the service application.

  1. Verify that the proxies are in the default group

The following sections provide procedures to complete these steps.

    Note:

The Business Data Connectivity service application is available in both SharePoint Foundation 2013 and SharePoint Server 2013. The other service applications are available only in SharePoint Server 2013. Although SharePoint Foundation 2013 includes search functionality, it is not the same Search service application that is in SharePoint Server 2013 and it cannot be upgraded.

Back to top

  1. Start SharePoint 2013 Central Administration.
  1. In SharePoint 2013 Central Administration, on the Application Management page, in the Service Applications section, click Manage Services on Server.
  2. Next to the Business Data Connectivity service, click Start.
  3. Next to the Managed Metadata Web Service, click Start.
  4. Next to the PerformancePoint Services service, click Start.
  5. Next to the Secure Store Service, click Start.
  6. Next to the User Profile Service, click Start.

The Search service instance must be started by using Windows PowerShell because you cannot start it from Central Administration unless a Search Service application already exists.

To start the Search service instance by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. To start the Search service instance, at the Windows PowerShell command prompt, type the following commands and press ENTER after each one:

    $SearchInst = Get-SPEnterpriseSearchServiceInstance
    # Stores the identity for the Search service instance on this server as a variable
    Start-SPServiceInstance $SearchInst
    # Starts the service instance

For more information, see Get-SPEnterpriseSearchServiceInstance and Start-SPServiceInstance.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. To store the application pool for a particular service application as a variable, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $applicationPool = Get-SPServiceApplicationPool -Identity ‘SharePoint Web Services default

    Where:

  • SharePoint Web Services default is the name of the service application pool that will contain the new service applications.

    This cmdlet sets the service application pool as a variable that you can use again in the cmdlets that follow. If you have multiple application pools and have to use a different application pool for a particular service application, you can repeat this step to get the appropriate application pool before you create the service application.

  1. To upgrade the Secure Store service application, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $sss = New-SPSecureStoreServiceApplication -Name ‘Secure Store‘ -ApplicationPool $applicationPool -DatabaseName ‘SecureStore_Upgrade_DB‘ -AuditingEnabled

    Where:

  • SecureStore is the name that you want to give the new Secure Store service application.
  • SecureStore_Upgrade_DB is the name of the service application database that you want to upgrade.

    This command sets a variable, $sss, that you use when you create the proxy later.

    For more information, see New-SPSecureStoreApplication.

    After you create the Secure Store service application and upgrade the database, you have to refresh the encryption key. For information about how to refresh the encryption key, see Refresh the encryption key.

  1. Type the following command to create a proxy for the Secure Store service application:

    Windows PowerShell 

    New-SPSecureStoreServiceApplicationProxy -Name ProxyName -ServiceApplication $sss -DefaultProxyGroup

    Where:

  • ProxyName is the proxy name that you want to use.
  • $sss is the variable that you set earlier to identify the new Secure Store service application.

        Tip:

If you do not use the variable $sss, then you must use an ID to identify the Secure Store service application instead of a name. If you have to find the ID, you can run the Get-SPServiceApplication cmdlet to return a list of all service application IDs.

  1. Type the following command to restore the passphrase for the Secure Store service application:

    Update-SPSecureStoreApplicationServerKey -Passphrase <Passphrase>

    Where:

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. To store the application pool for a particular service application as a variable, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $applicationPool = Get-SPServiceApplicationPool -Identity ‘SharePoint Web Services default

    Where:

  • SharePoint Web Services default is the name of the service application pool that will contain the new service applications.

    This cmdlet sets the service application pool as a variable that you can use again in the cmdlets that follow. If you have multiple application pools and have to use a different application pool for a particular service application, you can repeat this step to get the appropriate application pool before you create the service application.

  1. To upgrade the Business Data Connectivity service application, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    New-SPBusinessDataCatalogServiceApplication -Name ‘BDC Service‘ -ApplicationPool $applicationPool -DatabaseName ‘BDC_Service_DB

    Where:

  • BDC Service is the name that you want to give the new Business Data Connectivity service application.
  • BDC_Service_DB is name of the service application database that you want to upgrade.

    For more information, see New-SPBusinessDataCatalogServiceApplication.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. To store the application pool for a particular service application as a variable, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $applicationPool = Get-SPServiceApplicationPool -Identity ‘SharePoint Web Services default

    Where:

  • SharePoint Web Services default is the name of the service application pool that will contain the new service applications.

    This cmdlet sets the service application pool as a variable that you can use again in the cmdlets that follow. If you have multiple application pools and have to use a different application pool for a particular service application, you can repeat this step to get the appropriate application pool before you create the service application.

  1. To upgrade the Managed Metadata service application, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $mms = New-SPMetadataServiceApplication -Name ‘Managed Metadata Service Application‘ -ApplicationPool $applicationPool -DatabaseName ‘Managed Metadata Service_DB

    Where:

  • Managed Metadata Service Application is the name that you want to give the new Managed Metadata service application.
  • Managed Metadata Service_DB is name of the service application database that you want to upgrade.

    This command sets a variable, $mms, that you use when you create the proxy later.

    For more information, see New-SPMetadataServiceApplication.

  1. At the Windows PowerShell command prompt, type the following command to create a proxy for the Managed Metadata service application:

    Windows PowerShell 

    New-SPMetadataServiceApplicationProxy -Name ProxyName -ServiceApplication $mmd -DefaultProxyGroup

    Where:

  • ProxyName is the proxy name that you want to use.
  • $mmd is the variable that you set earlier to identify the new Managed Metadata service application.
  • DefaultProxyGroup adds the Managed Metadata service application proxy to the default proxy group for the local farm.

    For more information, see New-SPMetadataServiceApplicationProxy.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. To store the application pool for a particular service application as a variable, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $applicationPool = Get-SPServiceApplicationPool -Identity ‘SharePoint Web Services default

    Where:

  • SharePoint Web Services default is the name of the service application pool that will contain the new service applications.

    This cmdlet sets the service application pool as a variable that you can use again in the cmdlets that follow. If you have multiple application pools and have to use a different application pool for a particular service application, you can repeat this step to get the appropriate application pool before you create the service application.

  1. To upgrade the User Profile service application, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $upa = New-SPProfileServiceApplication -Name ‘User Profile Service Application‘ -ApplicationPool $applicationPool -ProfileDBName ‘User Profile Service Application_ProfileDB‘ -SocialDBName ‘User Profile Service Application_SocialDB
    -ProfileSyncDBName ‘
    User Profile Service Application_SyncDB

    Where:

  • User Profile Service Application is the name that you want to give the new User Profile service application.
  • User Profile Service Application_ProfileDB is name of the User Profile service application Profile database that you want to upgrade.
  • User Profile Service Application_SocialDB is name of the User Profile service application Social database that you want to upgrade.
  • User Profile Service Application_SyncDB is name of the User Profile service application Sync database that you want to upgrade.

    This command sets a variable, $upa, that you use when you create the proxy later.

    For more information, see New-SPProfileServiceApplication.

  1. Type the following command to create a proxy for the User Profile service application:

    Windows PowerShell 

    New-SPProfileServiceApplicationProxy -Name ProxyName -ServiceApplication ServiceApplicationID -DefaultProxyGroup

    Where:

  • ProxyName is the proxy name that you want to use.
  • $upa is the variable that you set earlier to identify the new User Profile service application.
  • ServiceApplicationID is ID of the User Profile service application that you created earlier.

        Tip:

If you do not use the variable $upa, then you must use an ID to identify the User Profile service application instead of a name. If you have to find the ID, you can run the Get-SPServiceApplication cmdlet to return a list of all service application IDs.

After you have created the User Profile Service service application, you must import the Microsoft Identity Integration Server Key (MIIS) encryption key. Import this key to the following directory: <root directory drive>\Program Files\Microsoft Office Servers\15.0\Synchronization Service\Bin.

To import the encryption key for User Profile service application

  1. Verify that you have the following memberships:
  • Administrators group on the server on which you are running the command.
  1. Open the Command Prompt window, and then change to the following folder:

    %Program Files%\Microsoft Office Servers\15.0\Synchronization Service\Bin\

  2. To import the key, type the following at the command prompt, and then press ENTER:

    miiskmu.exe /i Path {0E19E162-827E-4077-82D4-E6ABD531636E}

    Where:

  • Path is the path and file name for the key that you want to import.

    You might also have to enter a user name and password. These are the credentials for the farm administrator.

For more information, see Install a software update (SharePoint Server 2010).

After you have imported the encryption key, you can start the User Profile Synchronization service.

  • Start the User Profile Synchronization service

  1. Start SharePoint 2013 Central Administration.
  • For Windows Server 2008 R2:
    • Click Start, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Central Administration.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Central Administration.

      If SharePoint 2013 Central Administration is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Central Administration.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. In Central Administration, on the System Settings page, under Servers click Manage services on Server.
  2. Next to the User Profile Synchronization Service, click Start.
  3. In the Select the User Profile Application section, select the User Profile service application that you upgraded.
  4. In the Service Account Name and Password section, type the account name and password to use for the User Profile Synchronization service.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. To store the application pool for a particular service application as a variable, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $applicationPool = Get-SPServiceApplicationPool -Identity ‘SharePoint Web Services default

    Where:

  • SharePoint Web Services default is the name of the service application pool that will contain the new service applications.

    This cmdlet sets the service application pool as a variable that you can use again in the cmdlets that follow. If you have multiple application pools and have to use a different application pool for a particular service application, you can repeat this step to get the appropriate application pool before you create the service application.

  1. To upgrade the PerformancePoint Services service application, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $pps = New-SPPerformancePointServiceApplication -Name ‘PerformancePoint Service‘ -ApplicationPool $applicationPool -DatabaseName ‘PerformancePoint Service Application_DB

    Where:

  • PerformancePoint Service is the name that you want to give the new PerformancePoint Services service application.
  • PerformancePoint Service Application_DB is name of the PerformancePoint Services service application database that you want to upgrade.

    This command sets a variable, $pps, that you use when you create the proxy later.

    For more information, see New-SPProfileServiceApplication.

  1. Type the following command to create a proxy for the PerformancePoint Services service application:

    Windows PowerShell 

    New-SPPerformancePointServiceApplicationProxy -Name ProxyName -ServiceApplication ServiceAplicationNameorID -Default

    Where:

  • ProxyName is the proxy name that you want to use.
  • $pps is the variable that you set earlier to identify the new PerformancePoint Services service application.
  • Default adds the PerformancePoint Services service application proxy to the default proxy group for the local farm.

    For more information, see New-SPPerformancePointServiceApplicationProxy.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. To store the application pool for a particular service application as a variable, at the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    $applicationPool = Get-SPServiceApplicationPool -Identity ‘SharePoint Web Services default

    Where:

  • SharePoint Web Services default is the name of the service application pool that will contain the new service applications.

    This cmdlet sets the service application pool as a variable that you can use again in the cmdlets that follow. If you have multiple application pools and have to use a different application pool for a particular service application, you can repeat this step to get the appropriate application pool before you create the service application.

  1. To upgrade the Search service application, at the Windows PowerShell command prompt, type the following command:


    $searchInst = Get-SPEnterpriseSearchServiceInstance -local
    # Gets the Search service instance and sets a variable to use in the next command

    Restore-SPEnterpriseSearchServiceApplication -Name ‘<SearchServiceApplicationName>‘ -applicationpool $applicationPool -databasename ‘<SearchServiceApplicationDBName>‘ -databaseserver <ServerName> -AdminSearchServiceInstance $searchInst

    Where:

  • SearchServiceApplicationName is the name of the Search service application.
  • AppPoolName is the application pool name.
  • SearchServiceApplicationDBName is the name of the Search service application Administration database that you want to upgrade.
  • AdminSearchServiceInstanceID is the ID for the Search Service application instance.

        Note:

A Search service application upgrade might fail because of an issue that occurs during upgrade, such as network or SQL Server latency. If an error message appears during the Search service application upgrade, do the following:

  1. Delete the Search Administration database that you were trying to upgrade.
  2. Using the backup copy that you made of the Search Administration database, repeat the following procedures in this article for the Search service application only:
    1. Restore a backup copy of the database
    2. Set the databases to read-write
  3. Upgrade the Search service application by typing the command again at the Windows PowerShell command prompt.

For more information, see Restore-SPEnterpriseSearchServiceApplication.

You must follow several steps to create the Search service application proxy and add it to the default proxy group. You must complete separate actions to find the ID for the Search service application, create the new proxy, get the proxy ID, and then add the proxy to the default proxy group.

  1. Type the following command to get the ID for the Search service application and store it as a variable:

    Windows PowerShell 

    $ssa = Get-SPEnterpriseSearchServiceApplication

    For more information, see Get-SPEnterpriseSearchServiceApplication.

  2. Type the following command to create a proxy for the Search service application:

    Windows PowerShell 

    New-SPEnterpriseSearchServiceApplicationProxy -Name ProxyName -SearchApplication $ssa

    Where:

  1. Type the following command to get the Search service application proxy ID for the proxy you just created and set it as the variable $ssap:

    Windows PowerShell 

    $ssap = Get-SPEnterpriseSearchServiceApplicationProxy

    For more information, see Get-SPEnterpriseSearchServiceApplicationProxy.

  2. Type the following command to add the Search service application proxy to the default proxy group:

    Windows PowerShell 

    Add-SPServiceApplicationProxyGroupMember member $ssap -identity “ 

    Where:

  • $ssap is the variable that you set earlier to identify the ID for the proxy you just created for the Search service application.
  • You use an empty identity parameter (“ “) to add it to the default group.

    For more information, see Add-SPServiceApplicationProxyGroupMember.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following commands:

    $pg = Get-SPServiceApplicationProxyGroup -Identity “ 
    $pg.Proxies

    Where:

  • $pg is a variable you set to represent the default proxy group.
  • You use an empty identity parameter (“ “) to specify the default proxy group.

    This returns a list of all proxies in the default proxy group, their display names, type names, and IDs.

For more information, see Get-SPServiceApplicationProxyGroup.

Now that the service applications are upgraded, you can start the process to upgrade the content databases. The first step in that process is to create the web applications that are needed for each content database.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    Test-SPContentDatabase -Name DatabaseName -WebApplication URL

    Where:

  • DatabaseName is the name of the database that you want to test.
  • URL is the URL for the web application that will host the sites.

For more information, see Test-SPContentDatabase.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    Mount-SPContentDatabase -Name DatabaseName -DatabaseServer ServerName -WebApplication URL

    Where:

  • DatabaseName is the name of the database that you want to upgrade.
  • ServerName is server on which the database is stored.
  • URL is the URL for the web application that will host the sites.

For more information, see Mount-SPContentDatabase.

    Tip:

To upgrade from SharePoint Foundation 2010 to SharePoint Server 2013, attach the SharePoint Foundation 2010 content databases directly to the SharePoint Server 2013 environment. Just follow the same steps in this article, only use the SharePoint Foundation 2010 databases and a SharePoint Server 2013 farm. The upgrade process will upgrade the version and the product at the same time.

Back to top

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. Start the SharePoint 2013 Management Shell.
  • For Windows Server 2008 R2:
    • On the Start menu, click All Programs, click Microsoft SharePoint 2013 Products, and then click SharePoint 2013 Management Shell.
  • For Windows Server 2012:
    • On the Start screen, click SharePoint 2013 Management Shell.

      If SharePoint 2013 Management Shell is not on the Start screen:

    • Right-click Computer, click All apps, and then click SharePoint 2013 Management Shell.

      For more information about how to interact with Windows Server 2012, see Common Management Tasks and Navigation in Windows Server 2012.

  1. At the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    Get-SPContentDatabase | ft Name, NeedsUpgradeIncludeChildren

This cmdlet returns a table-style list of databases in your farm and indicates whether the database needs an upgrade to SharePoint 2013.

Back to top

  1. Verify that you have the following administrative credentials:
  • To use SharePoint Central Administration, you must be a member of the Farm Administrators group.
  1. On the Central Administration home page, in the Upgrade and Migration section, click Check upgrade status.
  1. Verify that you have the following memberships:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Permissions and Add-SPShellAdmin.

  1. From the Windows PowerShell command prompt, type the following to set the specified user account as an administrator for the site:

    $WebAppName = “http://<yourWebAppUrl>
    $wa = get-SPWebApplication $WebAppName
    $wa.UseClaimsAuthentication = $true
    $wa.Update()

    Where:

  • <yourWebAppUrl> is the URL of the web application.
  1. From the Windows PowerShell command prompt, type the following to configure the policy to enable the user to have full access:

    Windows PowerShell 

    $account = “yourDomain\yourUser”
    $account = (New-SPClaimsPrincipal -identity $account -identitytype 1).ToEncodedString()
    $wa = get-SPWebApplication $WebAppName
    $zp = $wa.ZonePolicies(“Default”)
    $p = $zp.Add($account,”PSPolicy”)
    $fc=$wa.PolicyRoles.GetSpecialRole(“FullControl”)
    $p.PolicyRoleBindings.Add($fc)
    $wa.Update()

    For more information, see Get-SPWebApplication.

  2. From the Windows PowerShell command prompt, type the following to perform user migration:

    $wa.MigrateUsers($true)

  3. After user migration completes, type the following from the Windows PowerShell command prompt to perform provisioning:

    Windows PowerShell 

    $wa.ProvisionGlobally()

    For more information, see New-SPClaimsPrincipal.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

After you complete the previous procedures, you might experience one or more of the following issues:

  • Users who submit valid credentials when accessing the migrated web application might be notified that they do not have permissions. If this occurs, the portalsuperuseraccount property and the portalsuperreaderaccount property of the web application were probably configured prior to migration. If this is the case, update the portalsuperuseraccount property and the portalsuperreaderaccount property to use the new claims-based account name. After migration, you can find the new claims-based account name in the web application policy for the migrated web application.
  • If existing alerts are not invoked after migration, you might have to delete and recreate the alerts.
  • If Search crawl does not function on the web application after migration, make sure that the Search crawl account lists the new converted account name. If the new converted account name is not listed, you must manually create a new policy for the crawl account.

To migrate a claims-based SharePoint 2010 Products web application to SharePoint 2013

  1. In SharePoint 2013, create a claims-based web application. For more information, see Create claims-based web applications in SharePoint 2013.
  2. Attach the two existing SharePoint 2010 Products content databases to the newly created SharePoint 2013 claims-based web application. For more information, see Attach or detach content databases in SharePoint 2013.

    Note:

When you attach the SharePoint 2010 Products content databases to the SharePoint 2013 claims-based web application, the databases will be upgraded to the SharePoint 2013 database format. You have to verify that the content databases work correctly after you attach them.

  • Convert SharePoint 2010 Products classic-mode web applications to SharePoint 2013 claims-based web applications

    In SharePoint 2013, complete the following procedure to convert an existing SharePoint 2010 Products classic-mode web application to a SharePoint 2013 web application that uses claims-based authentication.

    To convert a SharePoint 2010 Products classic-mode web application to a SharePoint 2013 claims-based authentication

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • You must read about_Execution_Policies (http://go.microsoft.com/fwlink/p/?LinkId=193050).
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 15 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Permissions and Add-SPShellAdmin.

  1. In the SharePoint 2013 environment, on the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. Change to the directory where you saved the file.
  5. At the Windows PowerShell command prompt, type the following command:

    New-SPWebApplication name “ClassicAuthApp” Port 100 ApplicationPool
    “ClassicAuthAppPool”
    ApplicationPoolAccount (Get-SPManagedAccount
    <domainname>\<user>“)

    Where:

  • <domainname>\<user> is the domain to which the server belongs and the name of the user account.
  1. Attach the two existing SharePoint 2010 Products content databases to the new SharePoint 2013 classic-mode web application. For more information, see Attach or detach content databases in SharePoint 2013.

    Note:

When you attach the SharePoint 2010 Products content databases to the SharePoint 2013 classic-mode web application, the databases are upgraded to the SharePoint 2013 database format. You have to verify that the content databases work correctly after you have attached them.

  1. From the Windows PowerShell command prompt, type the following:

    Convert-SPWebApplication Identity <yourWebAppUrl>
    To Claims
    -RetainPermissions [ -Force]

    Where:

  • <yourWebAppUrl> is the URL of the web application.

        Note:

Convert-SPWebApplication converts the web application to claims-based authentication. You have to verify that the users can access the web application after you have converted it.

  1. If necessary, attach a third SharePoint 2010 Products content database to the new SharePoint 2013 classic-mode web application, and verify that the content database working correctly after you have attached it.
  2. From the Windows PowerShell command prompt, type the following:

    Convert-SPWebApplication Identity yourWebAppUrl
    To Claims
    -RetainPermissions [ -Force]

Verify that users can access the web application after you have converted it to claims-based authentication.

For more information, see New-SPWebApplication, Get-SPManagedAccount, and Convert-SPWebApplication.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

  • Convert SharePoint 2013 classic-mode web applications to claims-based web applications

    In SharePoint 2013, complete the following procedures to first create a classic-mode Web application, and then convert it to claims-based authentication.

    To create a classic-mode Web application in SharePoint 2013

    • Verify that you have the following memberships:
      • securityadmin fixed server role on the SQL Server instance.
      • db_owner fixed database role on all databases that are to be updated.
      • Administrators group on the server on which you are running Windows PowerShell cmdlets.
      • You must read about_Execution_Policies (http://go.microsoft.com/fwlink/p/?LinkId=193050).
      • Add memberships that are required beyond the minimums above.

        An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 15 Products cmdlets.

            Note:

      If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Permissions and Add-SPShellAdmin.

    • From the Windows PowerShell command prompt, type the following:

      New-SPWebApplication Name <Name>
      ApplicationPool <ApplicationPool>
      -AuthenticationMethod <WindowsAuthType>
      ApplicationPoolAccount <ApplicationPoolAccount>
      -Port <Port> -URL <URL>

      Where:

      • <Name> is the name of the new web application that uses classic-mode authentication.
      • <ApplicationPool> is the name of the application pool.
      • <WindowsAuthType> is either NTLM or Kerberos. Kerberos is recommended.
      • <ApplicationPoolAccount> is the user account that this application pool will run as.
      • <Port> is the port on which the web application will be created in IIS.
      • <URL> is the public URL for the web application.

            Note:

      For more information, see New-SPWebApplication.

          Note:

      After you successfully create the web application, when you open the Central Administration page, you see a health rule warning that indicates that one or more web applications is enabled with classic authentication mode. This is a reflection of our recommendation to use claims-based authentication instead of classic mode authentication.

    To convert a SharePoint 2013 classic-mode web application to claims-based authentication

    • From the Windows PowerShell command prompt, type the following:

      Convert-SPWebApplication -Identity “http:// <servername>:port” -To Claims
      RetainPermissions [-Force]

      Where:

      • <servername> is the name of the server.

    Verify that users can access the web application after you have converted it to claims-based authentication.

    For more information, see New-SPWebApplication, Get-SPManagedAccount, and Convert-SPWebApplication.

        Note:

    We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

  • Migrate SharePoint 2010 Products classic-mode web applications to SharePoint 2013 classic-mode web applications

    In SharePoint 2013, complete the following procedure to create a classic-mode web application, and then migrate an existing SharePoint 2010 Products classic-mode Web application to SharePoint 2013.

    To migrate a SharePoint 2010 Products classic-mode web application to SharePoint 2013

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running Windows PowerShell cmdlets.
  • You must read about_Execution_Policies (http://go.microsoft.com/fwlink/p/?LinkId=193050).
  • Add memberships that are required beyond the minimums above.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 15 Products cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Permissions and Add-SPShellAdmin.

  1. From the Windows PowerShell command prompt, type the following:

    New-SPWebApplication name “ClassicAuthApp” Port 100 ApplicationPool
    “ClassicAuthAppPool”
    ApplicationPoolAccount (Get-SPManagedAccount
    <domainname>\<user>“)

    Where:

  • <domainname>\<user> is the domain to which the server belongs and the name of the user account.
  1. Attach the two existing SharePoint 2010 Products content databases to the new SharePoint 2013 classic-mode web application. Verify that the content databases work correctly after you have attached them. For more information, see Attach or detach content databases in SharePoint 2013.

    Note:

After migration has successfully completed, you might find a user who has not been migrated listed in the ULS log. Determine if the user still exists in your Active Directory domain, and then:

  • If the user does not exist in your Active Directory domain, assign someone else as the site owner and designate the user as deleted in the UserInfo table. To designate a user as deleted, change the tp_deleted value in the UserInfo table for that user to 1.
  • If the user does exist in your Active Directory domain, run the migration procedure again.

For more information, see New-SPWebApplication and Get-SPManagedAccount.

    Note:

We recommend that you use Windows PowerShell when performing command-line administrative tasks. The Stsadm command-line tool has been deprecated, but is included to support compatibility with previous product versions.

 

 

  1. Verify that the user account that performs this procedure is a site collection administrator.
  2. On the Site Settings page for the site collection, in the Site Collection Administration section, click Site collection health checks.
  3. On the Run site collection health checks page, click Start checks.

    A report lists all checked issues and issues that you should resolve.

  4. Resolve all issues, and then click Try it again to verify that you fixed them.
  • Run the site collection pre-upgrade health checks by using Windows PowerShell

    Farm administrators can use the following Windows PowerShell cmdlets to run the site collection health checks and to repair issues: Test-SPSite Repair-SPSite.

    To run the site collection health checks in test mode by using Windows PowerShell

  1. Verify that you have the following memberships:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Test-SPSite -Identity <SiteURL> [-Rule <RuleID>]

    Where:

  • <SiteURL> is URL for the site collection you want to check.
  • <RuleID> is ID for a specific rule that you want to run.

To run the site collection health checks in repair mode by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.
  • Either a site collection administrator or be granted full control (for repair mode) for the web application by policy. For more information about permission policies for web applications, see Manage permission policies for a web application (SharePoint Server 2010).

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Repair-SPSite -Identity <SiteURL> [-Rule <RuleID>]

    Where:

  • <SiteURL> is URL for the site collection you want to repair.
  • <RuleID> is ID for a specific rule that you want to run.
  1. Run the site collection health checks to verify the site is ready to upgrade. For more information, see Run site collection health checks in SharePoint 2013.
  2. Create an upgrade evaluation site to preview the differences between versions. (Optional)
  3. Upgrade the site collection.
  4. Verify that upgrade was successful and the site works as expected. For more information, see Review site collections upgraded to SharePoint 2013.

This article discusses the second and third steps, and includes procedures for performing these tasks from Site Settings. For information about using Windows PowerShell cmdlets to upgrade sites from the command line, see Manage site collection upgrades to SharePoint 2013.

Upgrade step 2: Request evaluation site collection and Step 3: Upgrade the site



For a visual overview of the upgrade process, including site collection upgrade, see Overview of the upgrade process to SharePoint 2013. For more information about how farm administrators can control site collection upgrades, see Manage site collection upgrades to SharePoint 2013. For more conceptual information about site upgrade, including how to plan for upgrade, see Plan for site collection upgrades in SharePoint 2013.

    Important:

If you upgrade from SharePoint Server 2010 to SharePoint Server 2013, there are special considerations for My Sites. (My Sites are not available in SharePoint Foundation 2013.) Make sure that you upgrade the My Site Host site collection before you allow users to access their individual My Sites in SharePoint Server 2013. This makes sure that the server software and database changes are complete so that users can upgrade their individual My Sites successfully.

A user can upgrade his or her My Site by following the steps to upgrade a site collection later in this article, or a farm administrator can upgrade My Sites by using Windows PowerShell.

    Note:

Because SharePoint 2013 runs as websites in Internet Information Services (IIS), administrators and users depend on the accessibility features that browsers provide. SharePoint 2013 supports the accessibility features of supported browsers. For more information, see the following resources:

  1. Verify that the user account that performs this procedure is a site collection administrator.
  2. On the Site Settings page for the site collection, in the Site Collection Administration section, click Site collection upgrade.
  3. On the Step up to SharePoint 2013 page, click Try a demo upgrade.

    This option starts the process of generating an upgrade evaluation site collection.

  4. In the Create Upgrade Evaluation Site Collection box, click Create Upgrade Evaluation Site Collection.

    A box opens and informs you that a demo site request was received.

  5. Click Close to close the box.

    You will receive an e-mail message when the upgrade evaluation is available. The e-mail message will contain a link to the site collection. Review the site and confirm that your site collection will look and behave as expected in the new user interface.

After you have reviewed the upgrade evaluation and made any necessary changes in your original site based on your evaluation, you can upgrade your site collection.

Farm administrators can use Windows PowerShell to request an upgrade evaluation site collection. For more information, see Manage site collection upgrades to SharePoint 2013.

  1. Verify that the user account that performs this procedure is a site collection administrator.
  2. On the Site Settings page for the site collection, in the Site Collection Administration section, click Site collection upgrade.
  3. On the Site Collection Upgrade page, click Upgrade this Site Collection.

    This option starts the process of upgrading your site collection. A box opens to verify that you want to start the process.

  4. Click I’m ready to start the actual upgrade.

    Note:

The site collection health checks are run automatically in repair mode before the upgrade starts. The results from the health checks are included in the upgrade log for the site collection. If there is an error, you must address it before you can continue to upgrade.

The upgrade starts, and the Upgrade status page for the site collection is displayed. This page automatically updates while the upgrade is in progress and displays information about the process, such as the following:

  • Errors or warnings
  • When the upgrade started
  • Where you can find the upgrade log file

    After the upgrade is complete, the Upgrade status page is displayed in the new user interface with the message, Upgrade Completed Successfully.

  1. Click Let’s see the new site to go to the home page.

Farm administrators can use Windows PowerShell to upgrade a site collection. For more information, see Manage site collection upgrades to SharePoint 2013.

  • Verification

    To verify that upgrade has succeeded, check the Upgrade status page for the site collection.

    • View upgrade status in Site Settings

    Site collection administrators can view the Upgrade Status page in Site Settings to verify that upgrade has succeeded for a site collection.

    To view upgrade status in Site Settings

  1. Verify that the user account that performs this procedure is a site collection administrator.
  2. On the Site Settings page for the site collection, in the Site Collection Administration section, click Site collection upgrade.
  3. On the Site Collection Upgrade page, click Review Site Collection Upgrade Status.

    The Upgrade Status page for the site collection is displayed.

Farm administrators can use Windows PowerShell to view site collection upgrade status. For more information, see Manage site collection upgrades to SharePoint 2013.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following commands to view the upgrade notification settings for a web application:

    $wa=Get-SPWebApplication <URL>
    $wa.UpgradeReminderDelay
    $wa.UpgradeMaintenanceLink

    Where:

  • <URL> is URL for the web application that you want to check.

    This command returns the Upgrade reminder delay setting for the specified web application.

  1. At the Windows PowerShell command prompt, type the following command to view the self-service upgrade setting for a site collection:

    $site=Get-SPSite <URL>
    $wa.AllowSelfServiceUpgrade

    Where:

  • <URL> is URL for the site collection that you want to affect.

For more information, see Get-SPWebApplication and Get-SPSite.

To change the upgrade notification and self-service upgrade settings for a web application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command to change the upgrade notification settings for a web application:

    $wa=Get-SPWebApplication <URL>
    $wa.UpgradeReminderDelay=
    <Value>
    $wa.UpgradeMaintenanceLink=’
    <LinkURL>

    Where:

  • <URL> is URL for the web application that you want to affect.
  • <Value> is the numeric value that you want to set for the delay (for example, 10 for 10 days).
  • <LinkURL> is a link where the user can find more information.
  1. At the Windows PowerShell command prompt, type the following command to change the self-service upgrade setting for a site collection:

    $site=Get-SPSite <URL>
    $wa.AllowSelfServiceUpgrade=
    <Value>

    Where:

  • <URL> is URL for the site collection that you want to affect.
  • <Value> is either ‘true’ to allow site collection administrators to upgrade the site, or ‘false’ to not show them the notification and not allow them to upgrade.

For more information, see Get-SPWebApplication and Get-SPSite.

  • Control the compatibility range for site creation modes

    You can control which mode (2010 or 2013, or both) can be used when a user creates a site collection. The CompatibilityRange property on a web application controls the site modes available for a web application. You can view or change the settings for CompatibilityRange by using Windows PowerShell.

    To view the compatibility range for site creation modes for a web application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following commands to view the compatibility range settings for a web application:

    $wa=Get-SPWebApplication <URL>
    # Stores the web application at that URL as a variable
    $wa.CompatibilityRange
    # Returns the CompatibilityRange for the specified web application

    Where:

  • <URL> is URL for the web application that you want to check.

    This command returns the compatibility range for the specified web application. For example:

    MaxCompatibilityLevel MinCompatibilityLevel  DefaultCompatibilityLevel  Singular
    ———————
      ———————  ————————-   ——–
            
           15                    14                   
          15   
      False

  1. At the Windows PowerShell command prompt, type the following commands to view the maximum, minimum, and default settings for a specific range:

    [Microsoft.SharePoint.SPCompatibilityRange]::<RangeName>

    Where:

  • RangeName is one of the following values: OldVersions, NewVersion, AllVersions.

    This command returns the compatibility range for the specified value. For example, for NewVersion:

    MaxCompatibilityLevel MinCompatibilityLevel  DefaultCompatibilityLevel  Singular
    ——————— ———————
      ————————-   ——–
                   15    
                  15                   
          15   
      True

For more information, see Get-SPWebApplication.

To change compatibility range for site creation modes for a web application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command to change the compatibility range settings to a specific range:

    $wa=Get-SPWebApplication <URL>
    # Stores the web application at that URL as a variable
    $wa.CompatibilityRange = [Microsoft.SharePoint.SPCompatibilityRange]::
    <RangeName>
    # Specifies which range to use
    $wa.Update()
    # Updates the CompatibilityRange setting to use only the range you specified
    $wa.CompatibilityRange
    # Returns the new CompatibilityRange for the web application

    Where:

  • <URL> is URL for the web application that you want to change.
  • RangeName is one of the following values: OldVersions, NewVersion, AllVersions.
  1. At the Windows PowerShell command prompt, type the following command to change the values for the CompatibilityRange manually:

    $wa=Get-SPWebApplication <URL>
    # Stores the web application at that URL as a variable
    $range = New-Object Microsoft.SharePoint.SPCompatibilityRange(
    <Integer>,<Integer>)
    # Creates a new compatibility range from
    <Integer> to <Integer>
    $wa.CompatibilityRange = $range
    # Specifies which range to use
    $wa.Update()
    #Updates the CompatibilityRange setting to use only the range you specified with $range
    $wa.CompatibilityRange
    # Returns the new CompatibilityRange for the web application

    Where:

  • <URL> is URL for the web application that you want to change.
  • Integer is a number to use as the minimum or maximum value. For example, (14,15) would set the MinCompatibilityLevel to 14 (2010) and the MaxCompatibilityLevel to 15 (2013). The DefaultCompatibilityLevel is automatically set to the lower of the MaxCompatibilityLevel and the current major version (for example, 15).

    This command sets and then returns the range that you specified. For example:

    MaxCompatibilityLevel  MinCompatibilityLevel  DefaultCompatibilityLevel  Singular
    ———————
       ———————  ————————-   ——–
                    15                     14                   
          15   
      False

For more information, see Get-SPWebApplication.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. To view all site collections in the queue for a content database, at the Windows PowerShell command prompt, type the following command:

    Get-SPSiteUpgradeSessionInfo -ContentDatabase <DatabaseName> -ShowInProgress -ShowCompleted -ShowFailed |ft

    Where:

  • <DatabaseName> is name of the database that you want to check. You can also use the GUID for the database instead of the name.

    For more information, see Get-SPSiteUpgradeSessionInfo.

  1. To see all sites that are currently being upgraded, at the Windows PowerShell command prompt, type the following command:

    Get-SPSiteUpgradeSessionInfo -ContentDatabase <DatabaseName> -ShowInProgress

    Where:

  • <DatabaseName> is name of the database that you want to check. You can also use the GUID for the database instead of the name.

    For more information, see Get-SPSiteUpgradeSessionInfo.

  1. To see whether a particular site is in the queue, at the Windows PowerShell command prompt, type the following command:

    Get-SPSiteUpgradeSessionInfo -Site <http://site&gt;

    Where:

  1. To add a site collection to the upgrade queue, at the Windows PowerShell command prompt, type the following command:

    Upgrade-SPSite <http://site&gt; -VersionUpgrade -QueueOnly

    Where:

  1. To remove a site collection from the upgrade queue, at the Windows PowerShell command prompt, type the following command:

    Remove-SPSiteUpgradeSessionInfo -Identity <URL>

    Where:

  • Control site throttle settings for upgrade to SharePoint 2013

    You can view and change the upgrade throttle settings for a content database and web application by viewing and setting the SPContentDatabase.ConcurrentSiteUpgradeSessionLimit and SPWebApplication.SiteUpgradeThrottleSettings properties. For descriptions of the properties that control throttle levels and the default values, see Plan for site collection upgrades in SharePoint 2013.

    For more information about web application properties, see SPWebApplication Properties. For more information about content database properties, see SPContentDatabase Properties.

    The following procedure provides steps to view upgrade throttling settings for a web application.

    To view the upgrade throttle settings for a web application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    $wa = Get-SPWebApplication <URL>
    $wa.SiteUpgradeThrottleSettings

    Where:

  • <URL> is URL for the web application that you want to check.

    This command returns the set of throttling settings for the specified web application. For example:

    AppPoolConcurrentUpgradeSessionLimit : 5
    UsageStorageLimit : 10
    SubwebCountLimit : 10
    Name :
    TypeName : Microsoft.SharePoint.Administration.SPSiteUpgradeThrottleSettings
    DisplayName :
    Id : ca76dda0-7050-4c6b-a126-05917da39f8a
    Status : Online
    Parent : SPWebApplication Name=SharePoint – 80
    Version : 8222
    Properties : {}
    Farm : SPFarm Name=SharePoint_ConfigUpgradedPersistedProperties : {}

For more information, see Get-SPWebApplication.

You can change the upgrade throttle settings for a web application. The following procedure provides steps to change the upgrade throttling settings for a web application.

To change the upgrade throttle settings for a web application by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    $wa=Get-SPWebApplication <URL>
    $wa.SiteUpgradeThrottleSettings.AppPoolConcurrentUpgradeSessionLimit=
    <Value>
    $wa.SiteUpgradeThrottleSettings.UsageStorageLimit=
    <Value>
    $wa.SiteUpgradeThrottleSettings.SubwebCountLimit=
    <Value>

    Where:

  • <URL> is URL for the web applications that you want to affect.
  • Value is the numeric value that you want to set for that limit (for example, 8).

    This command changes the throttling settings for a web application to the value that you supply.

For more information, see Set-SPWebApplication.

The following procedure provides steps to view upgrade throttling settings for a content database.

To view the throttle settings for a content database by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    $db = Get-SPContentDatabase <DatabaseName>

    # Stores the database name as a variable to use in the next command

    $db.ConcurrentSiteUpgradeSessionLimit
    # Returns the value for the limit for that database

    Where:

  • <DatabaseName> is name of the database that you want to check. You can also use the GUID for the database instead of the name.

    This command returns the set of throttling settings for the specified content database.

For more information, see Get-SPContentDatabase.

You can change the upgrade throttle settings for a content database. The following procedure provides steps to change the upgrade throttling settings for a content database.

To change the throttle settings for a content database by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following commands:

    $db = Set-SPContentDatabase <DatabaseName>
    # Stores the database name as a variable to use in the next command

    $db.ConcurrentSiteUpgradeSessionLimit=<value>
    # Changes the limit to the value you specify.

    Where:

  • <DatabaseName> is name of the database that you want to affect. You can also use the GUID for the database instead of the name.
  • <value> is a numeric value to set the property to, such as 9.

    This command changes the throttling settings for the specified content database to the value that you supply.

For more information, see Set-SPContentDatabase.

  1. Verify that you have the following memberships:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Request-SPUpgradeEvaluationSiteCollection -identity URL to site

    Where:

  • URL to site is the URL to a site collection in 2010 mode.

For more information, see Request-SPUpgradeEvaluationSite.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    Upgrade-SPSite <http://site&gt; -VersionUpgrade [-Unthrottled]

    Where:

  • <http://site&gt; is the URL for the site collection.
  • Add the option -Unthrottled option to skip the site collection upgrade queue and start the upgrade immediately.

This cmdlet upgrades the specific site collection to 2013 mode. For more information, see Upgrade-SPSite.

To upgrade all site collections in a database, use Windows PowerShell. However, because sites can continue to run in 2010 mode in the SharePoint 2013 environment, this is not a necessary procedure for most environments. If you do choose to upgrade all site collections immediately, site collection owners do not have an opportunity to use an upgrade evaluation site to preview the new user interface or change their original site before upgrading. We do not recommend that you upgrade all site collections immediately as part of your initial upgrade. However, you might want to upgrade all site collections after some time has passed and all customizations were verified in 2013 mode.

To upgrade all site collections in a database by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    Get-SPSite -ContentDatabase <DBName> -Limit All | Upgrade-SPSite -VersionUpgrade -QueueOnly

    Where:

  • <DBName> is the name of the content database for which you want to upgrade all site collections.

    The -QueueOnly parameter adds the site collections to the upgrade queue. This allows the timer job to perform parallel upgrades when it is possible and can save time. The sites are upgraded in the order in which they are added to the queue.

This cmdlet upgrades all site collections in the specific content database to 2013 mode.

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Get-SPSiteUpgradeSessionInfo -Site <http://site&gt;

    Where:

  • <http://site&gt; is the URL of the site collection.

    This cmdlet returns the upgrade status for the specified site collection together with information about the upgrade session and a link to the log files for more information. For more information, see Get-SPSiteUpgradeSessionInfo.

  1. Or, you can use the following command to view the information about a specific site collection upgrade:

    $sc = Get-SPSite <http://site&gt;
    # Sets a variable for the site collection
    $sc.CompatibilityLevel
    # Returns the compatibility level for the site collection (either 14 or 15 for 2010 or 2013 mode)
    $sc.UpgradeInfo
    # Returns the upgrade information for the site collection

    Where:

  • <http://site&gt; is the URL of the site collection.

    This command returns the compatibility level and upgrade information (such as a pointer to the log file) for the specified site collection. If the compatibility level is “15,” then it has been upgraded to 2013 mode. For more information, see Get-SPSite.

To view upgrade status for a single database by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Windows PowerShell 

    Get-SPSiteUpgradeSessionInfo ContentDatabase <DatabaseName> -ShowInProgress -ShowCompleted -ShowFailed

    Where:

  • <DatabaseName> is the name of the database that you want to check.

    This cmdlet returns any site collections that have an upgrade in progress, completed, or failed and lists their status, plus a link to the log files for more information. You can use only one parameter to find only in progress, completed, or failed upgrades. For more information, see Get-SPSiteUpgradeSessionInfo.

To view upgrade status for all site collections by using Windows PowerShell

  1. Verify that you have the following memberships:
  • securityadmin fixed server role on the SQL Server instance.
  • db_owner fixed database role on all databases that are to be updated.
  • Administrators group on the server on which you are running the Windows PowerShell cmdlets.

    An administrator can use the Add-SPShellAdmin cmdlet to grant permissions to use SharePoint 2013 cmdlets.

        Note:

If you do not have permissions, contact your Setup administrator or SQL Server administrator to request permissions. For additional information about Windows PowerShell permissions, see Add-SPShellAdmin.

  1. On the Start menu, click All Programs.
  2. Click Microsoft SharePoint 2013 Products.
  3. Click SharePoint 2013 Management Shell.
  4. At the Windows PowerShell command prompt, type the following command:

    Get-SPSite -Limit All

This cmdlet returns the URL for all site collections in the environment and the compatibility level (14 or 15) for each site collection.

UPGRADING FARMS FROM SHAREPOINT 2007 TO SP2010

INTRODUCTION ………………………………………………………………………………………………………….. 4 1.1. Outline ……………………………………………………………………………………………………………………… 4 1.2. Acknowledgements ………………………………………………………………………………………………….. 4 1.3. Updates ……………………………………………………………………………………………………………………. 4 2. UPGRADING FARMS FROM SHAREPOINT 2007 TO SP2010 ……………………………………………….. 5 2.1. The upgrade cycle ……………………………………………………………………………………………………. 5 2.1.1. Learn …………………………………………………………………………………………………………………….. 6 Requirements and prerequisites ………………………………………………………………………………….. 6 Upgrade methods …………………………………………………………………………………………………….. 9 Downtime mitigation processes ………………………………………………………………………………… 16 2.1.2. Prepare ……………………………………………………………………………………………………………….. 19 Document environment …………………………………………………………………………………………… 19 Manage customizations …………………………………………………………………………………………… 19 Choose upgrade strategy ………………………………………………………………………………………… 24 2.1.3. Test ……………………………………………………………………………………………………………………… 24 Build test farms ………………………………………………………………………………………………………… 25 Document and install customizations ………………………………………………………………………… 25 Use real data…………………………………………………………………………………………………………… 25 Evaluate techniques ………………………………………………………………………………………………… 25 Find issues early ……………………………………………………………………………………………………….. 26 2.1.4. Implement …………………………………………………………………………………………………………… 27 Build/upgrade farms ………………………………………………………………………………………………… 27 Deploy customizations ……………………………………………………………………………………………… 27 Minimize downtime ………………………………………………………………………………………………….. 27 Monitor progress ……………………………………………………………………………………………………… 27 2.1.5. Validate ………………………………………………………………………………………………………………. 28 Upgrade event failures …………………………………………………………………………………………….. 28 UI/UX issues ……………………………………………………………………………………………………………… 28 Data issues ……………………………………………………………………………………………………………… 28 2.2. Visual upgrade ………………………………………………………………………………………………………… 28 2.3. No International Domain Name support…………………………………………………………………….. 28 3. UPGRADING SOLUTIONS AND CODE ………………………………………………………………………….. 29 3.1. Recompilation…………………………………………………………………………………………………………. 29 3.2. Upgrading Custom Site Definitions …………………………………………………………………………….. 29 3.2.1. Upgrade definition files …………………………………………………………………………………………. 30 3.3. Upgrading Solutions …………………………………………………………………………………………………. 30 3.4. Versioned Features ………………………………………………………………………………………………….. 31 3.4.1. Declarative feature upgrade ………………………………………………………………………………… 31 3.4.2. Programmatic feature upgrade …………………………………………………………………………….. 32 3.5. Customizations against deprecated/changed UI……………………………………………………….. 32 3.6. Security changes …………………………………………………………………………………………………….. 33 3.6.1. Web Parts …………………………………………………………………………………………………………….. 33 3.6.2. Sandboxed Solutions …………………………………………………………………………………………….. 33 3.7. Large List Throttling …………………………………………………………………………………………………… 34 3.8. Deprecated API’s ……………………………………………………………………………………………………. 35 3.9. Hardcoding issues ……………………………………………………………………………………………………. 35 3.10. Upgrading the look & feel to the new version ………………………………………………………….. 35 3.11. Upgrading projects to Visual Studio 2010 ………………………………………………………………… 36 3.12. Client upgrades ……………………………………………………………………………………………………. 38 4. PLANNING ………………………………………………………………………………………………………………. 38 4.1. Planning prerequisites ………………………………………………………………………………………………. 38 4.2. Planning upgrade model …………………………………………………………………………………………. 39 4.3. Planning new Server Architecture ……………………………………………………………………………… 39 4.4. Test, test, test …………………………………………………………………………………………………………… 40 4.5. Planning operations scheduling ………………………………………………………………………………… 41 4.6. Planning code upgrade approach …………………………………………………………………………… 41 4.7. Planning user adoption…………………………………………………………………………………………….. 42 1. INTRODUCTION 1.1. Outline This document describes guidance for upgrading a SharePoint Products and Technologies 2007 (SP2007) farm to SharePoint Products and Technologies 2010 (SP2010). The various approaches to upgrade will be described and the pros and cons of each approach will be considered. The first part of this document will discuss the process of performing an upgrade from SP2007 to SP2010 to include preparation, methodology and finalization. The second part of this document will focus on the upgrading custom solutions and will discuss some of the various tools and features available to assist in this process. The final part will look at actions that should be started, to prepare a solution for an upgrade. I have tried to encompass both the operations and development angle of the upgrade process in this white paper. This have sometimes forced me to not dig as much into a given subject as I probably would have liked to do, in an attempt to get this document finished.. 1.2. Acknowledgements A few people helped me by reading the initial drafts and suggesting changes: Mike Watson (http://www.sharepointmadscientist.com), Paul Swider (http://www.paulswider.com) and Wictor Wilén (http://wictorwilen.se). I know you guys are busy, so thanks a lot for some great input! In my research for this white paper I have read a lot of blogs and specs, and watched a lot of screen casts on the subject. I have tried to give credit where credit is due, but should I have missed accreditation let me know and I will include it. I will also appreciate any feedback and corrections from the ever growing SharePoint community. Note: This document should be considered a work-in-progress. As very few actual upgrades has been carried out at this point in time (SharePoint 2010 still being in beta) prescriptive guidance is scarce. It is my plan to keep this white paper up to date as best practices become established. 1.3. Updates Date Changed 5/9/2010 Chapter 3.1 – 3.3 updated with more info Added IDN upgrade and BDC upgrade 2. UPGRADING FARMS FROM SHAREPOINT 2007 TO SP2010 Note: There is no upgrade path from the public beta version of SP2010 to the RTM when released. Beta can be used to evaluate the product and to test upgrades, but since it is not a supported product, upgrade is not supported! 2.1. The upgrade cycle When talking upgrade of complex SharePoint solutions, it is important to emphasize that this initially is an iterative approach: Learn •find out all about requirements, prerequisites, documentation, the upgrade process, downtime mitigation, common issues Prepare •document environment thoroughly, upgrade existing documentation, find and manage customizations, choose upgrade strategy, performance test existing hardware Test •build a test farm using real data, evaluate migration techniques, find issues early Implement •upgrade farms, deploy customizations, minimize downtime, monitor progress Validate •upgrade event failures, UI/UX issues, data issues 2.1.1. Learn Requirements and prerequisites Software and hardware The biggest change in architecture from 2007 to SP2010 is, that all servers, including SQL server, must run 64-bit. This is mainly because of scalability issues, the need for large amounts of RAM on the server and to focus support on one version. The minimal requirements for hardware is pt specified to be: Component Minimum requirement Processor 64-bit, four cores RAM 4 GB for developer or evaluation use 8 GB for single server and multiple server farm installation for production use Hard disk 80 GB for system drive For production use, you need additional free disk space for day-to-day operations. Maintain twice as much free space as you have RAM for production environments. For more information, see Capacity management and sizing for SharePoint Server 2010. Table 1: Source TechNet Note: Now TechNet actually has a whole Capacity Management Resource Center for SharePoint 2010 dedicated to capacity planning and performance here http://technet.microsoft.com/enus/ sharepoint/ff601870.aspx In addition to hardware requirements for running SP2010, one must also consider the upgrade process itself and how it may be impacted by hardware as well. For example, the upgrade process may take 4 hours on one set of hardware and 2 hours on another. The speed of the upgrade will be determined in large part by the physical resources available to the SQL server(s). Expect the upgrade to run much faster when the SQL server(s) performing the upgrade has excess processor, memory and physical disk IO capacity. Also, the upgrade process can benefit greatly by scaling out across multiple SQL instances with each instance running one or more upgrade processes. Also be aware that the upgrade itself takes up extra disk space for log files and databases. Also you need to be running Windows Server 2008 R2 or Windows Server 2008 with SP2 on all servers (see this article for upgrade process http://technet.microsoft.com/enus/ library/cc288690.aspx). Furthermore database server must be 64-bit version of either SQL Server 2005 SP3 with cumulative update 3 (CU) or SQL Server 2008 SP1 with cumulative update 2. SharePoint 2007 must have SP2 and latest CU (currently April CU), since a lot of the tools used for upgrading SharePoint is baked into the service packs. Note: The above prerequisite upgrades can be combined, but must not be part of the SharePoint upgrade itself! Read more on hardware and software requirements on TechNet http://technet.microsoft.com/en-us/library/cc262485(office.14).aspx Pre-upgrade check That the tools are already in place also means that you can start planning an upgrade, by running the pre-upgrade checker. The stsadm.exe command PreUpgradeCheck can be used to analyze the existing SP2007 site collections, looking for situations that could cause grief during an upgrade, such as customized (unghosted) artifacts, changes in database schemas, missing features and other potential issues and relevant information like Alternate Access Mappings (AAM) url’s, site definitions used and large lists. It is also important to state, that the tools operations on the databases are read-only! No changes are made on the databases, which makes it a relatively harmless procedure to run, even on your production environment (in comparison with PreScan from 2003-2007 upgrades that would make small alterations to the databases). During execution PreUpgradeCheck will visually display progress in the console. • Green text means everything is fine • Yellow means you will find more information available when digging into the log file with references to KB articles; manual upgrades will also show up here. Below you can see that CAML views are used instead of the new XSLT-based views, this needs to be upgraded manually, also listed are AAM configuration, server and farm info, installed language packs etc. • Red means that there’s an issue that needs attention before an upgrade can be completed successfully. In the example below the upgrade fails to find the xml for an installed feature and also fails on the prerequisites (the server is 32-bit). Figure 1: Pre-Upgrade Check in action (source: http://www.wictorwilen.se) After PreUpgradeCheck has finished, it will generate a report in both XML and HTML format and a log file. The PreUpgradeCheck runs against a rules database that is extendable. You can select what rules to run by specifying the rulefiles parameter followed by a commaseparated list of rule names. You can also see a list of rules being applied by specifying the listrulefiles parameter. Note: For a detailed walk-through of the reports generated see TechNet article http://technet.microsoft.com/en-us/library/cc262231(office.14).aspx and Joel Olsen’s blog http://www.sharepointjoel.com/Lists/Posts/Post.aspx?ID=238 PreUpgradeCheck can be run on both a single server and a whole farm. There are two obvious benefits of this: running it locally will only stress a single Web Frontend (WFE) server, which is good if run on a production environment. Also you can run PreUpgradeCheck on individual WFE and afterwards compare the reports against each other to spot inconsistencies across the frontend servers. PreUpgradeCheck is meant to be run a number of times, not just as a one-off event. Identifying customizations and rehearsing upgrade operation is paramount when we want to achieve a successful upgrade with minimal downtime. For this reason IT should run PreUpgradeCheck on a regular basis as an ongoing process towards the Verson-To-Version (V2V) upgrade. Common issues when upgrading is upgrading language packs to latest version, upgrading custom site definitions to take advantage of new SP2010 functionality (for more information, see http://tinyurl.com/mulfcb), missing features (only guid is stored in the database), large lists (SP2010 uses throttling on large lists, so code may fail! See more in code upgrade section) or orphaned artefacts in configuration or content database. Test-SPContentDatabase To complement PreUpgradeCheck reports, as part of the pre-upgrade testing you should run the SP2010 PowerShell (PS) command Test-SPContentDatabase. This command compares a content database and a web application against each other checking for problems. It can be used against both old 2007 content database and the upgraded SP2010 database. The tool will check for orphans, missing site definitions, features, assemblies etc. In other words it will warn you if it detects any potential problems with matching a specific web application and database, such as creating orphans by adding a database that is already in the farm. Figure 2: Test-SPContentDatabase example output So where Pre-upgrade Check is used to detect issues on the SP2007 environment, Test- SPContentDatabase can be used to for example analyze a SP2010 farm before attaching a content database to it. Upgrade methods Part of the learning process is knowing your options! There’s several ways to upgrade your SharePoint solution and even hybrid variations. Each method has its pros and cons, with concern for downtime, hardware costs etc. In-Place upgrade An in-place upgrade means that the upgrade is done directly on the production server. Since this means closing down the farm for the duration of the upgrade, this approach causes downtime for the solution. On the other hand the approach means that the existing server hardware can be reused (if within specifications and adhering to prerequisites) and that configurations and customizations done on the server is kept. E.g. you don’t need to recreate a complete farm using solutions and manual configuration. Figure 3: In-place upgrade (source TechNet) Doing an in-place upgrade, first install SP2010 on *all* servers in farm -start with the server hosting the Central Administration (CA). Then install language packs. Now run configuration wizard up to point where wizard tells you to configure other servers in farm -start with CA. When wizard is on same step on all servers complete wizard on CA continue on other servers. As an option you can end up running Visual Upgrade (the new SP2010 look for editing sites, with Ribbons etc.). If you have problems during in-place upgrade, the PS command Upgrade-SPContentDatabase can be used to resume an upgrade. Note: More information on In-place upgrade on TechNet: http://technet.microsoft.com/enus/ library/cc303423(office.14).aspx Pros: • customizations are kept • farm-wide settings preserved Cons: • a risky approach since you don’t have a fallback strategy should issues arise • downtime while upgrading (can be mitigated with AAM redirects, see hybrid model below) • all content databases are upgraded in sequence causing more downtime • a power outage or disk space problem during upgrade could leave upgrade in an unsupported state Database attach The database attach approach requires you to create a new farm on new hardware. This farm is then configured, and customizations and artifacts are deployed. Now you backup your old farm, detach it taking it offline and attach it to the new farm (discard temporary content database in new farm). Attaching the new database could be done with either the PowerShell command Mount- SPContentDatabase –name <newdb> -WebApplication <url>, or use stsadm –o addcontentdb –url <url> -databasename <dbname> [-preserveolduserexperience true|false]. The last approach should be preferred if you want control over the UI upgrade (e.g. Ribbons), since it honors the version switch for UI, whereas the PS command forces the new UI (at least until RTM version). This method is also viable for SSP database and upgrade user profile information into the database, but you cannot upgrade search database by using this method. If you have problems during db attach upgrade that you need to address before continuing, the upgrade process is designed so that it can be resumed even in the event of power outage or if you run out of space during the upgrade process: run the PS command Upgrade- SPContentDatabase to resume an upgrade. Note: More information on db attach upgrade on TechNet: http://technet.microsoft.com/enus/ library/cc303436(office.14).aspx Pros: • can upgrade multiple content databases in parallel (less downtime) • you can use this method to consolidate multiple farms into one farm • you can upgrade hardware as well as software • you have an opportunity to clean out the old server and get a “fresh” install Cons: • server and farm settings are not upgraded (mitigation: scripted installs) • the settings of the target farm must exactly match the settings on the source farm • customizations are not upgraded (mitigation: solution deployment, scripted configurations with PowerShell) • copying databases over network takes time (plan this!) • requires direct access to SQL server Figure 4: DB attach upgrade (source: TechNet) Hybrid approach 1: Read-only databases Hybrid approaches gives you the possibility of combining different approaches when upgrading SP2010. One such approach is the R/O databases approach. Basically this is a db attach upgrade but with a downtime mitigation strategy where you continue to provide read-only access to content database during the upgrade. Start by setting up and configuring a new farm, then transfer customizations to new farm and test. Now set content databases to read only (directly in SQL) on original farm while upgrade in progress on new farm (since Sp2 SharePoint will detect that the database is read-only so that the UI respects this). Backup content database from original farm and perform database upgrade on the new farm in parallel. Optionally use AAM for long-running upgrades to redirect requests (see more on this approach later). Map sites from new farm to old farm while upgrade is in progress. Note: You can configure the READ_ONLY database availability option by using Transact-SQL. More about how to use the SET clause of the ALTER DATABASE statement: http://go.microsoft.com/fwlink/?LinkId=148362). Figure 5: Hybrid 1: Read-only database (source TechNet) Pros: • Existing farm can continue to run in read-only mode causing minimal downtime for end users • can upgrade multiple content databases in parallel (less downtime) • you can use this method to consolidate multiple farms into one farm • you can upgrade both software and hardware Cons: • server and farm settings are not upgraded (mitigation: scripted installs) • customizations are not upgraded (mitigation: solution deployment, scripted configurations with PowerShell) • copying databases over network takes time (plan this!) • requires direct access to SQL server Hybrid approach 2: Detach databases Another hybrid approach is a variation over the in-place upgrade: This approach combines the in-place upgrade’s ability to keep configurations and customizations while adding the parallel upgrade approach from db attach positively affecting downtime for the upgrade: Take the original farm off-line, detach content database from original farm, run in place upgrade on original farm servers in parallel, services and configuration databases. Then attach content databases to the original farm and upgrade content. Figure 6: Hybrid: Detach databases (source TechNet) Pros: • customizations are kept • farm-wide settings preserved • save time by upgrading multiple db’s at the same time Cons: • copying databases over network takes time (plan this!) • requires direct access to SQL server Hybrid approach 3: Detach databases (with temporary farm) This approach is very similar to the above hybrid scenario, but it introduces a new small farm that is used temporarily to store the content databases as they are being upgraded: Set up temporary small farm (both WFE and applications running on same hardware) running SP2010 and then take the original farm offline. Detach the content databases from the original farm and run an in-place upgrade on original farm. Now attach content databases to temp farm and upgrade content in parallel. Finally re-attach content databases to the original farm. Figure 7: Hybrid: Detach databases with temporary farm (source: TechNet) Pros: • Same as hybrid 2 approach above + • Reduce downtime since upgrade is carried out in parallel on temp farm Cons: • Same as hybrid 2 approach above + • New hardware needed for temp farm (could be some existing test server) AAM hybrid: detach databases The AAM hybrid should be seen as a last ditch operation, and is only viable for very specific situations, like if you cannot upgrade your farm over a weekend. The reason for this being that it is operationally fairly difficult to set up. It also isn’t perfect; since it has issues with links (different URL’s on new and old farm). Furthermore it gives you double work (e.g. governance of security, double hardware, double maintenance). The upgrade is related to what in the old version was called Gradual Upgrade (no longer supported). Basically db attach is used to upgrade content databases one at the time over a longer period. AAM is then used on the new farm to redirect users that request pages that haven’t yet been upgraded to the old farm (http://WSSold). Over time (could be weeks or even months) all content databases are upgraded one at the time. Compared to Gradual Update the granularity here is entire content databases, not site collections. When the databases are upgraded the old databases could be kept as read-only as a kind of post view upgrade to look at old content to compare with new. Further details available in TechNet White Paper: http://technet.microsoft.com/dadk/ library/ee720448(en-us,office.14).aspx Updating Services Services have been totally reworked in SP2010. There is no longer a Shared Services Provider (SSP) site, but instead you got the possibility to scale out the services to individual servers (through proxies) with individual databases. This flexibility is great in terms of scaling out, but adds complexity to upgrade scenarios. You really need to plan beforehand what services are in use in the farm, and where they should be placed after upgrading to SP2010. Also some services are split up into two separate services, where one is completely new. Depending on the upgrade approach manual work is needed to fully upgrade the service architecture. Another important design change from 2007 to SP2010 is that where some services was specific to Microsoft Office SharePoint Server (MOSS) -some even only in Enterprise edition, they now all reside inside Microsoft SharePoint Foundation (formerly Windows SharePoint Services (WSS)). This should cause solution architects to consider the new possibilities available for the customers’ farm, maybe even change existing solutions to make use of these new possibilities. Important: Even with in-place upgrades, not all configurations are kept after upgrade. These settings, such as timer job configurations, must be collected before upgrade and re-applied post-upgrade. Below is an illustration of SSP architecture before and after an upgrade: If you have a single SSP, all proxies for service applications are added to the default proxy group. The following diagrams show the changes to your farm that are made during in-place upgrade. Services infrastructure before upgrade: Figure 8: SSP before and after upgrade (Source: TechNet) Note: If you have multiple SSP’s, they will be upgraded together and after the upgrade you will have multiple proxy groups! Technical diagrams illustrating services in SP2010: http://technet.microsoft.com/enus/ library/cc263199(office.14).aspx Logical architecture components – Service applications: http://technet.microsoft.com/enus/ library/cc263121(office.14).aspx#section2 User Profiles User Profiles are now split up in two services: • User Profile Service • Managed Metadata Service (new in SP2010) If you run an in-place upgrade, the managed metadata service is automatically enabled and configured. If you upgrade using db attach you will need to enable and configure Managed metadata before upgrading! Persisted properties relating to profiles are also preserved when using in-place upgrades: • MySiteHostURL • SearchCenterURL • EnablePersonalFeaturesforMultipleDeployments • ProfileStoreLanguage • ProfileStoreLanguagePacksApplied • ProfileStoreCollationID • DaysWorthOfEventsToKeep On the other hand a db attach approach will not preserve these properties since they are stored in configuration database. You also will need to enable and configure the Managed Metadata service before you upgrade the User profile service to make taxonomy data part of the upgrade. If you have taxonomy data that needs to be migrated (if you planned meta data before upgrading), use the Move-SPProfileManagedMetadataProperty command in PS. Note: To upgrade and use taxonomy data, the User Profiles Service proxy and Managed Metadata Service proxy must be in the same proxy group. My Sites If you use My Sites, make sure you upgrade the My Site host at the same time as you upgrade the user profiles. Also make sure you upgrade My Sites host as part of the intranet migration process! When you upgrade My Site host it will automatically upgrade to the new look and feel of SP2010, so any customizations on personal and shared My Site pages will be lost! Note: You don’t need to upgrade all the My Sites themselves at the same time as doing the User Profile upgrade, just the host! Search You cannot use db attach to upgrade search data. Instead you should configure search in your new farm before or after the upgrade. If you use in-place upgrade, you should review and adjust search topology after upgrade to suit new recommendations and requirements. Forms Services / InfoPath For db attach approach you need to export XSN files and UDCX files before upgrading and import them into new farm after upgrade: • Export-SPInfoPathAdministrationFiles • Update-SPInfoPathAdminFileUrl to update links if url is different in new farm You cannot use in-place for FormsServices. Excel Services Excel Services is still a local service (it runs service in same farm that consumes it). If you upgrade Excel Services using in-place upgrade: configuration info stored in SSP is automatically moved from SSP db to configuration database. When using the db attach approach, you need to reconfigure Excel Services on the new farm. After upgrade (db attach and in-place), a new unattended service account must be provisioned for Secure Store Service. Business Data Catalog (BDC) When you do an in-place upgrade, data from SSP is moved to a new dedicated database and a new service application is created. BDC is not upgraded in a db attach upgrade process. Old BDC Connections are run using Application Registry Backwards compatible service. The interface for this is kept in the old SSP admin site. New development should not be done in Application Registry Service, as this service is only meant to be used for upgrading BDC from SP2007! Note: If no BDC services were available for the old solution, the SSP site can be deleted after upgrade! Consider moving the BDC profile pages to a new location, as these were hosted in the SSP web application. Single Sign-On (SSO) The SSO service is replaced with Secure Store Service in SP2010. Use the PS cmdlets below to upgrade application definitions: • Upgrade-SPSingleSignOnDatabase • Upgrade-SSOConnectionString • Upgrade-SecureStoreConnectionString • Upgrade-SecureStorePassphrase Notice that passwords are not upgraded, so these will need to be configured post-upgrade. Also you must manually set Secure Store Service the default SSO provider after the upgrade is done. Downtime mitigation processes Usually you would like to minimize downtime during an upgrade. Several parameters affect your downtime: The chosen upgrade model, server performance, size of farm and databases, how well you tested etc. There are different processes that you can use to minimize downtime. Give users read access during upgrade One way is setting the source database to read-only during an upgrade. This will enable end users to access their data without changing it (SharePoint detects the SQL lock on the database and enforce UI trimming accordingly). The users will then only detect downtime when the solution is switched to the new farm. Upgrading in parallel To minimize the time used to run the upgrade use parallel upgrades. You can do parallel database attach (number of parallel upgrades depends on hardware) and create multiple temporary farms to do in-place upgrade and db attach on. Content database attach with AAM redirection is another way to reduce downtime. Avoid surprises – test! More subtle approaches could be to optimize farm before upgrade, to avoid surprises during the production upgrade: make sure you follow recommendations from pre-upgrade checker, split large content databases into smaller ones, test (on real data) –the more you rehearse the upgrade process, and the more “real” the test environment and test data are, the more certain you will be on a successful upgrade. Common issues that is only found through testing includes missing dependencies (features not deployed to new farm, or missing on one or more WFE), UI change (CSS will break if you just upgrade to the new UI without upgrading CSS), lack of space (for example on SQL server, you should expect x2-x3 space –especially depending on # of document versions- increase during an upgrade), there’s almost always some manual post-upgrade configuration that depending on setup needs to be done (for example configuring additional settings on Forms Authentication providers for claims-based web application). Clean up before upgrade It is very hard to predict the amount of time an upgrade will take. Performance will vary on a lot depending on farm metrics: • # site collections • # webs • # lists • # document versions • Document versions size • # documents • # links • Overall DB size To mitigate the above, do general “spring cleaning” on your site collections: delete unused sites, lists and documents. Clean up in number of versions for documents. Split up large content databases. Note: Remember to backup your databases before cleaning up! STSADM.EXE has operations to automate part of this procedure Delete live site collection: stsadm -o DeleteSite -url <URL> [-deleteadaccounts {True | False}] [- gradualdelete] Delete orphaned site collection: stsadm -o DeleteSite -force [-gradualdelete] -siteid <site ID> -databasename <database name> -databaseserver <database server name> Delete live site: stsadm -o DeleteWeb -url <URL> Delete orphaned site: stsadm -o DeleteWeb -force -webid <Web ID> -databasename <database name> – databaseserver <database server name> Since the amount of versions directly affect the time it takes to upgrade, consider manually deleting old document versions, or create a tool to automate this task. Clean up unused templates, features and web parts. Again this is a manual process, but a custom tool could automate the process (for example listing all unused templates and giving you the option to delete them). Repair data issues: stsadm -o DatabaseRepair -url <url> -databasename <database name> [- deletecorruption] stsadm -o ForceDeleteList -url <url> stsadm -o VariationsFixupTool -url <source variation site url> [-scan] [- recurse] [-label] [-fix] [-spawn] [-showrunningjobs] Check and remove locks on site collections (when doing backups): stsadm -o getsitelock -url <url> stsadm -o setsitelock -url <url> -lock {none | noadditions | readonly | noaccess} Revise hardware and server settings Performance also varies based on hardware and software metrics such as (in order of importance): • SQL disk I/O per sec. • SQL DB to disk layout • SQL temp db optimizations (one per cpu) • SQL CPU & memory • WFE CPU & memory • Network bandwidth & latency Revising the hardware and configuring server software before upgrading will help bring down the amount of downtime for an upgrade. 2.1.2. Prepare Document environment If your environment is not documented, this is the time to do this! If it is documented, this is the time to revise your documentation to ensure its up to date! You should document hardware, software, customizations (see more below) and configurations. This will assist you in estimating the scope of the upgrade, and make disaster recovery after a failed upgrade much easier. Manage customizations Probably one of the most common reasons for a failed upgrade is not knowing the extent of customizations on your farm. Are all customizations done using solution deployment? Are manual special case customizations that cannot easily be solved using solution deployment documented? And are these special cases in sync across WFE? Note: An upgrade is an excellent time to enforce government policies. If “rogue” customizations is found this should be followed up with guidance on packaging artifacts in solutions, using features etc. To answer these questions, you have a number of tools to help you, but you will also have to dig in GAC, bin, 12 hive, Solutions store, Add/remove programs, etc. to get an overview of the customizations on the farm. Examples of customizations include custom site/list definitions, themes and changed CSS, master pages, page layouts, content types, custom web parts, custom web controls, event handlers, customized/un-ghosted pages, application pages, custom timer jobs, AAM’s etc. The following section will try to shed some light on how to identify customizations in your farm: Pre-upgrade check First of all run pre-upgrade check tool on both farm and individual servers (running on individual servers and then comparing reports will give you a hint of how similar your WFE are). Note: List of all WSS/MOSS Pre-Upgrade Check KB articles: http://support.microsoft.com/kb/960577 Pre-Upgrade check on TechNet: http://technet.microsoft.com/en-us/library/dd793607.aspx Joel Oleson has a good blog post on the subject http://www.sharepointjoel.com/Lists/Posts/Post.aspx?ID=238 Customized/Unghosted files Pre-upgrade does a good job checking for customizations, but does not detect files customized (unghosted) in SharePoint Designer (SPD). A tool like Gary Lapointes gl-enumunghostedfiles (part of stsadm extensions http://stsadm.blogspot.com/2009/02/downloads.html) can help identifying and reghosting these customizations. Test the content database In SP2010 there’s a new tool available that will help identifying missing customizations: the PS cmdlet Test-SPContentDatabase can detect problems before you attach a content database to a farm. You can see this cmdlet as a compliment to pre-upgrade checker report, plus it works on both SP2010 and 2007 databases, so it is very useful to point at an upgraded database to check if assemblies, site definitions or features are missing or if there are undetected orphans. It also will show metrics for table sizing on a content database, which can be useful for detecting content approaching the software boundaries of the product. Note: Joel Oleson walks through the syntax and uses of Test-SPContentDatabase on his blog: http://www.sharepointjoel.com/Lists/Posts/Post.aspx?ID=288 EnumAllWebs Another tool to determine impact of customizations is stsadm –o enumallwebs. This command can be used to list the ID and sitemap status for all site collections and sub-sites in a specified content database. Especially sitemap status (InSiteMap=”True|False”) is useful, as this tells you if a site collection is orphaned in the content database (this could happen if a content database has been attached to a web application that already contained a site collection with the same URL). An orphan can both be a site only registered in content database, or a site only registered in the configuration database. Such orphans will need to be handled before upgrading the database. Note: Deleting of orphaned sites can be done using stsadm –o deletesite. More info on TechNet and Joel Oleson’s blog http://www.sharepointjoel.com/Lists/Posts/Post.aspx?ID=291 Always remember to backup your content database before deleting any sites or site collections! Deployment Advisor from Quest Deployment Advisor (DA) developed by Quest Software Inc., is a new tool due for release soon: One of the main purposes of this tool is to give Operations a way to get a sanity check on a given SharePoint farm: have the server been configured in compliance with best practices in the field? Does WFE contain unique configurations or customizations? Is the farm ready for an upgrade? Answering these and other questions makes Operations able to assess risks for SharePoint farms in regards to hardware, patches, customizations, security and performance. DA scans the farm against an extendable rules engine that describes best practices for SharePoint within categories such as Performance, SP2010 upgrade, Availability, Search, Security, Supportability and areas such as Antivirus, Farm Configuration, IIS, Network, Server and SQL. In an upgrade scenario, you can use DA to compare WFE servers (one of the ideas behind the tool is for it to be “the WinDiff of SharePoint”) with regards to configuration, customization, patches etc. You can also look at the specific farm with regards to 2010 upgrade issues. Here it will tell you what critical issues that need to be resolved before an upgrade can take place, such as upgrading to a 64-bit architecture on both web servers and SQL servers: You can also examine the SP2010 upgrade readiness for a specific server: One very powerful feature of DA is its ability to compare servers to each other. This mind you is across metrics such as hardware, software, patch-level, files on server, services on server etc. This proves useful both if you want to compare different WFE in the same farm, but also if you want to prepare for an upgrade: Say you create a clean install of SP2007, fully patched and following best practices. Then you compare that to the server you want to upgrade. That gives you the possibility to detect if files like core.js or other “Microsoft owned” files has been customized on the server in question. You can even filter on basically anything (like %.js) to fine tune your comparison. Very neat! Figure 9: Comparing servers in Deployment Advisor showing Core.js is customized In general this comparison against a “best practice server” is also useful if you take over a farm and want to quickly get an overview on the general state of the server by comparing metrics like BuildVersion, patch-level etc. with your “golden” server. Manual inspection A manual inspection of your farm could include • checking in Visual Studio and Solution store if everything is packaged in solutions • any manual editing of web.config (note that this will need to be checked both in relation to differences in web.config on different WFE in the farm, and across environments (devtest, integration test, preprod, prod) • any manual xcopy operations. These manual steps should be documented and if possible mitigated with solution deployment. Places to check for customizations • _layouts, features, sitedefinitions • GAC • add/remove programs (3rd party) • timerjobs, event receivers • http handlers/modules/iis customizations Pre-upgrade check does detect database customizations, but other kind of modifications of Out-Of-The-Box files such as webtemp files, application pages etc. will not be picked up. A way of detecting these customizations is using the above mentioned Depolyment Advisor, Windif (or similar) to detect differences a) from files as they were OOTB (install a clean farm and compare) b) between WFE on the same farm c) between environments Also inspect code, looking for hacks that may cause problems. A good developer would always mark these special cases with some kind of code comment. Since STP files are no longer supported, look for these in your development environment. A way to upgrade STP files to WSP packages is by restoring them on a SP2007 site that is then in-place upgraded. After fixing any visual issues the template can be exported as a WSP package that can then either be used to create new sites from using the UI, or be exported to Visual Studio 2010 and be packaged for deployment. Both the export and import tools has a tendency to import too much, so count on using time cleaning up the solutions before they are ready for deployment. More on this in a later chapter on upgrading code. Other tools for detecting customizations SPDiag version 2 is good for farm insight such as AAM’s or finding deployed solutions using the SnapShot tool. Diagnostics tool is also handy for detecting any discrepancies regarding best practices on configuration of the farm (Part of SharePoint administration Toolkit 4.0 that can be downloaded here http://technet.microsoft.com/en-us/library/cc508987.aspx). WssAnalyzeFeatures. This tool verifies if the feature definition files for all installed features are available on the file system, if the features used on a site collection are installed on the server (download from MSDN Code here http://code.msdn.microsoft.com/WssAnalyzeFeatures). Bamboo SharePoint Analyzer can help you get an overview of your farm topology, installed patches on servers, solutions and features deployed etc. (available here http://community.bamboosolutions.com/media/p/7160.aspx) SharePoint Feature Administration and Clean Up Tool can help locating faulty features in your farm (available from Codeplex http://featureadmin.codeplex.com) Collect customizations When all customizations has been collected, create a list of customizations along with source, environment and action required to move customization (could also be not to move it, e.g. if it’s a SP 2007 specific customization). The list should also contain third party add-ins and assemblies. When collecting customizations try and asses weather this customization is still relevant on the new platform: 1. Keep the customization. Choose if customization can be ported to new platform without issues. 2. Replace or redo customization. Choose if customization has visual or functional issues on the new platform, but you want to keep the customization. 3. Discard customization. Choose this if customization is no longer relevant. The following table illustrates common customizations and recommendation for that customization. Customization type Recommendation Site templates (STP files) STP files are a deprecated feature in SharePoint Server 2010. New site templates in SharePoint Server 2010 are saved as WSP files (solution packages). A site that was provisioned by using a site template will be upgraded, but you will be unable to create new sites based on that template. If you want to be able to create new sites, you can create and deploy a solution package instead. Site definition Migrate sites to a supported, predefined site definition, then apply custom features by using solution deployment. You can also continue to use a custom site definition. You do not have to create a new site definition based on SharePoint Server 2010. However, if you must perform custom upgrade actions for the definition, you might have to create an upgrade definition file for that site definition. For more information, see Upgrade Definition Files (http://go.microsoft.com/fwlink/?LinkId=182339) on MSDN. Feature Evaluate, then redesign or redeploy if necessary. Workflows and server controls Depends on the solution. Contact the vendor to find out whether there is an updated solution. If a workflow is compatible with the new version, redeploy. Event handler Rewrite and redeploy as a feature. Managed paths (inclusions/exclusions) Re-create inclusions for a database attach upgrade. Exclusions are assumed and do not have to be re-created. Themes Because of the extensive changes to the UI, custom themes based on Office SharePoint Server 2007 will not work in SharePoint Server 2010. Use Visual Upgrade to continue to use the sites in the old user experience until you can create and apply a new theme based on SharePoint Server 2010. Toolbar actions Move to the ribbon (Fluent UI). Master pages and CSS files Rework to accommodate the new user experience. JavaScript Test to determine whether any actions are required. In some cases, you might have to adjust the scripts to work with the new page model. Verify that it works on an upgraded site, and in both Visual Upgrade modes. Search provider or security trimmer Test to determine whether any actions are required. Web Parts Test to determine whether any actions are required. You might have to adjust the Web Parts to work with strict XHMTL mode. If a Web Part is located on a page but not in a Web Part Zone (so that it is, basically, HTML code embedded directly in a page), it will not work if you revert the page to the default template. Services Test to determine whether any actions are required. Redesign or adjust code, as needed. Authentication providers Test to determine whether any actions are required. Redeploy the provider on a test farm and ensure that it works correctly with claims authentication. Table 1- Source: TechNet Note: On TechNet you will find a worksheet that will help you document setup and collect customizations: http://go.microsoft.com/fwlink/?LinkId=179928 Choose upgrade strategy When customizations are collected, it is time to plan what upgrade strategy should be chosen, and determine order of operations (what sites goes first? should sites be split up?). Note: Even SharePoint behind the scenes will set recovery model to Simple during an upgrade (applicable for beta 2 in-place upgrade), you should still expect your SQL server to require x2-x3 of its current space –especially if you have a lot of versions on your documents. This is in part caused by the fact that databases aren’t shrinked automatically after an upgrade for time saving reasons. A How-To will come out shortly on TechNet on how to detect databases that need shrinking. The strategy should include means to limit downtime, and document expected downtime, and describe actions for spring cleaning as described earlier. It should also include a rollback strategy and a plan for when an upgrade should be abandoned and recovery of the old farm should start, any hardware upgrades due to new requirements, or space requirements. Note: It’s a good idea to do a performance analysis on your server hardware so you know beforehand if you should upgrade. System requirements for upgrade http://technet.microsoft.com/enus/ library/cc263322(office.14).aspx 2.1.3. Test The importance of testing before, during and after an upgrade cannot be stressed enough! It is imperative for the success of an upgrade that we have a test environment that we trust to be similar to the one we are going to upgrade in production. There are so many things that can go wrong during an upgrade, that without proper testing you could end up with either a long downtime, a site that’s not properly upgraded (missing features) or worse. Build test farms When you build test farms it is important that the metrics of the farm is kept as close to the production farm as possible! Both with regard to hardware, software, configuration, customizations and content they should be kept similar. The more similar your test farm is to the real thing, the higher the probability of everything running smooth during the actual upgrade in production. For hardware for example, the space on the disks plays an important factor: you would like to discover any space related issues during testing rather than having to add more disks during production upgrade. If the test environment is virtual, it should also be kept as close to the real farm as possible. You should for example run SQL server and the farms on different virtual images. If your tests environment isn’t identical you should keep it as similar as possible to the original: if you have multiple servers for a role (like 5 WFE) you should have at least 2 servers with that role in your test setup! Document and install customizations Use the worksheet mentioned above to document and install customizations and configurations. Use real data When you test the upgrade process, keep your content as close to production data as possible. This approach will help you identify trouble areas and determine upgrade performance. For example issues may rise due to large lists that you would not find on test data. Note: You don’t necessarily have to have all content on your upgrade test environment at the same time. Say you have 60 content databases with terabytes of data; it could be hard to convince your IT department to give you that kind of storage for a test farm. Instead test the content databases one at the time –just make sure you tested them all before attempting a real upgrade! Evaluate techniques After choosing the upgrade method you should do a test upgrade. This is just a preliminary test to catch any problems during the upgrade, and to rehearse the actual process. After the upgrade evaluate how things went, improve your techniques and do it again. And again! Evaluating also means troubleshooting problems, hunting for errors and validation of the result. Review log files To review the results of an upgrade, there’s several log files of interest: • pre-upgrade checker log file (in 12/LOGS dir) • psconfig log file (in 14/LOGS dir) • upgrade log file (in 14/LOGS dir) o find most recent log and look for a given correlation id • upgrade error log file (in 14/LOGS dir) If you search for and find the phrase “Upgrade session finished successfully!” the upgrade was went well. If the above entry was not found, search for ERROR and WARNING in upgrade log: • ERROR indicates failures such as failing components and faulty database connections • WARNING indicates issues such as missing features or components. Warnings should not be ignored. They may not break your upgrade process, but warnings should be investigated so you know what the impact will be on your system. Review sites For individual WFE you can also try and run stsadm -o localupgradestatus to find out if sites were skipped. If this is the case, you should restart the upgrade process. The before mentioned PS cmdlet Test-SPContentDatabase can also be used after an upgrade to validate if the content database has issues. Verify that the sites actually work using a browser, do a search crawl of the site and verify the crawl log for issues. Note: Since security scope has changed for deploying custom code in SharePoint, all test reviews should be done with a user with as low privileges as possible Reviewing artifacts A non-exhaustive list of things to check for when validating an upgraded site includes: Web parts • extra or missing web parts • broken web part pages • do they render correct • are any pages still checked out Style and appearance • images display correctly • CSS showing appropriately • themes showing appropriately • js working correctly (check for script errors) Permissions • does the appropriate people and groups still have correct permission level Customized (unghosted) pages • are customizations still in place • should customizations still be there in upgraded farm Find issues early Finding issues early ensures a higher success rate for the upgrade -the earlier we detect the problems the better. If you have multiple environments (as you should!), you can also use finding issues early to not repeat the problems found in test, in the subsequent environments such as integration test, preprod and prod, learning and improving the upgrade along the way. Note: TechNet has a couple of articles regarding testing and trial upgrades http://technet.microsoft.com/en-us/library/ff382642(office.14).aspx 2.1.4. Implement Build/upgrade farms First upgrade all farms to support the prerequisites for upgrade: upgrade to 64-bit, upgrade server OS, upgrade SQL server to supported versions, SP and CU, upgrade SharePoint to supported version, SP and CU. The process of getting the servers in a supported state can be combined, as long as you don’t combine the prerequisite upgrade with the SP2010 upgrade. Also upgrade hardware and build test farms. Depending on the chosen upgrade model, upgrade the services and content databases accordingly. Configure all valid settings, such as timer jobs, as recorded earlier. Prefer scripted configurations over manual ones, to minimize human error and ensure consistency across platforms. This is the case both for OS installations and server installations. Deploy customizations Again depending on upgrade model, it might be necessary to deploy all or at least some customizations. Make sure this is done as solutions whenever possible to ensure a consistent deploy across WFE. Minimize downtime Make sure that the SQL server is up for the job. When upgrading to SP2010 SQL server quickly becomes a bottleneck, so make sure it has plenty of space and horsepower if you want to minimize the time it takes to do an upgrade. Also consider making the content database read-only on the existing environment, while you upgrade a copy of this database in the background. Since SP2 SharePoint will detect that the database is read-only and trims the UI accordingly. This feature was added specifically with upgrade scenarios in mind! If you are doing db-attach upgrade, upgrading content databases in parallel will reduce the time it takes to upgrade. It is also possible to upgrade in parallel to a temporary farm to make the upgrade even faster. Monitor progress Upgrade logs is now split up so that there’s only one upgrade log per session, and a separate log for errors, making it easier to see how the upgrade went. The command line tools for upgrade now have status indicators that will visually show the progress of the upgrade. Also the upgrade status page in Central Administration (CA) tracks the progress and history of upgrades on the upgrade status page. Use the above to ensure upgrade process is on schedule, and be ready to “pull the plug” on the upgrade if you can see you are running out of time for the upgrade and need to recover the old installation. 2.1.5. Validate After upgrade is complete, you need to validate that the upgraded system really works. This means checking logs, checking rendering and checking that the database doesn’t have hidden issues. Upgrade event failures Reviewing the different logs associated with upgrade will give you a good indicator if everything really went fine. Look in the chapter Review log files above for more information. If issues are found, find out how to fix it, and restart or resume the upgrade! UI/UX issues Visually checking the upgraded farm will tell you if some of the functionality developed for the old version of SharePoint needs to be redesigned to look properly or even to work in SP2010. This includes HTML, CSS and JS issues, but could also be XHTML compliance issues. Also pages that fail to upgrade visually might be unghosted/customized in the old farm. You will then have to identify why the page was customized, determine if it is necessary to keep the customization, and then reghost the page in question. Data issues Check for orphaned items or database corruption using stsadm (see earlier chapter on orphaned items). Other data related issues are connectivity issues to data sources. Check that these work where used. 2.2. Visual upgrade By default the old look and feel of SP2007 and WSS3 is retained when doing an upgrade, but the site administrator has the ability to preview and change to the new SP2010 look and feel using the UI. When doing a db attach upgrade using stsadm.exe, setting preserveolduserexperience switch to true|false will enforce the UI accordingly. You could also automate the upgrade by utilizing PowerShell and/or the object model. For example using the SPSite.VisualUpgradeWebs method (consider including this code in a SPLongOperation since it, depending on the size of the site collection, could take a while to finish). In the ONET.XML of a custom site definition the UIVersion attribute in the Project element can be set to 3 or 4 to enforce UI version. 2.3. No International Domain Name support If you are upgrading a web content management site, and is using International Domain Names (IDN), it is worth mentioning that the support for IDN that was there in SP2007 was removed in SP2010! The only reason I have heard for this is, that “Support of internationalized domain names (IDNs) has been deprecated”. Not sure how to interpret that, but the fact is that it no longer works in SP2010, so if you used this in SP2007 you will need to delete all IDN settings in your SP2007 farm before upgrading. Note: See a full list of changes from SP2007 to SP2010 on TechNet http://technet.microsoft.com/enus/ library/ff607742(office.14).aspx 3. UPGRADING SOLUTIONS AND CODE 3.1. Recompilation Existing code that utilizes object model and runs within IIS will continue to work without recompilation (if compiled for AnyCPU or 64-bit). As when upgrading from SPS 2003 to SharePoint 2007 the upgrade process inserts assembly binding redirects from old assemblies to new assemblies (here 12.0.0.0 to 14.0.0.0) making the code automatically redirect to the new SharePoint dll’s. Code that runs outside IIS and utilizes the object model (workflows, feature receivers, timer jobs etc.) will either need recompilation or binding redirects to work with SP2010. Note: In SP2007 for a number of reasons it proved problematic to version assemblies. This often collided with both good development practice, and company rules on development lifecycles. These issues are well documented on the internet (including workarounds to get SPWebConfigModification class to add assembly redirects) so I won’t dig into that here. However the problem does no longer exist in SP2010 because that you now can specify assembly redirects directly in your solution manifest (see more below). It is not an automated process, so you will need to do it manually, but it is a lot easier than it was in SP2007, so developers should definitely consider using AssemblyVersion in code that is expected to have a long lifecycle! 3.2. Upgrading Custom Site Definitions As discussed in earlier chapter regarding visual upgrade, you can decide to keep the visuals as version 3 or you can decide to upgrade the visuals to version 4 adding the new layouts and tools such as the ribbon. This choice also affects how you want to upgrade your Custom Site Definitions (CSD). If you don’t plan on upgrading the visuals to version 4, most CSD should work as is, depending on how much is going on inside the CSD. In other words if you only used a CSD to add a new artifacts or change the basic layout of pages, you might be better off by using a new SP2010 site definition as a basis for re-creating that same functionality in the upgraded farm, or as close as you can get. Then add upgrade logic to your feature (see upgrading features later in this chapter). For more advanced scenarios, a better option would be to upgrade the functionality of the old site definition to match the new site definition. This involves changing the ONET.XML, since this has changed radically in the new version. 3.2.1. Upgrade definition files The purpose of Upgrade Definition Files (UDF) is to transform existing sites customized in the previous version of the product to take advantage of features in the new version. The UDF xml file maps custom lists, files and features from the old custom site definition to the new custom site definition during a schema or version upgrade. Though there are major changes to the product from SP2007 to SP2010, the paradigm shift isn’t as big as from SPS2003 to SP2007, where the feature concept was introduced, making the ONET.XML contain noticeably smaller. Hence the UDF for this version will be less complex, and most of the times not needed at all, depending on what customizations were done in the custom site template. The OOTB upgrade files for SP2010 can be found in 14\CONFIG\UPGRADE and can serve as a guide for upgrading your custom site definitions by selecting the site definition the custom site definition was based on. The custom UDF should be placed in the above mentioned folder and be given a unique name that begins with the name of the site definition (e.g. SPSNEWSCUSTOM_upgrade.xml). Note: For more information on upgrading Custom Site Definitions, check out “Architectural Approaches to Upgrading a Site Definition” http://msdn.microsoft.com/enus/ library/ms437476(v=office.14).aspx, “Upgrade Definition Files” http://msdn.microsoft.com/enus/ library/ms439232(office.14).aspx and “Upgrading a Custom Site Definition” http://msdn.microsoft.com/en-us/library/aa543837(v=office.14).aspx on MSDN. 3.3. Upgrading Solutions There are a few noteworthy changes in Solution packages regarding upgrades. In SP2007 it was tricky to add binding redirects in a consistent manner (SPWebConfigModification) since the runtime element is stored in another xml namespace (it could be done but it was tricky). Now this can be added declaratively as part of the solution manifest: <Solution …> <Assemblies> <Assembly DeploymentTarget=”GlobalAssemblyCache” Location=”MyWebPart.dll”> <BindingRedirects> <BindingRedirect OldVersion=”1.0.0.0” NewVersion=”1.1.0.0” /> </BindingRedirects> … </Assemblies> </Solution> This will add an assembly binding element to the web.config files for the assembly in question, redirecting code that uses the old assembly to point to the new assembly. Solutions can now also have dependencies declared in their manifest files. Three important things to note regarding solution dependencies though: solution dependencies does not automatically secure that dependent solutions are deployed. They just give you an error if you try to activate a solution that is dependent on another solution, and that solution isn’t deployed. Also you cannot have a farm based solution that is dependent on a user solution (Sandboxed solution). Last but not least: you will not receive any errors if you try and retract a solution that another solution is dependent on! 3.4. Versioned Features Upgrading artifacts within features were always a pain-point in SP2007. Upgrade scenarios for features in SP2007 would often mean adding a new dependent feature containing code in a feature call-out trying to change what needed to be changed in the feature. The good news is that upgrading features has received some attention in the new version, so it is now possible to upgrade features both declaratively and programmatically. You can even declare branches for different actions depending on version, or have element manifests being applied at update only. Up until now the version attribute in the Feature.xml manifest served no purpose. This has changed in the new version where the version attribute is used to detect if a given feature instance (SPFeature) needs to be upgraded. This is done by comparing the feature instance version with the feature definition (SPFeatureDefinition) version, hence securing that artifacts are identical whether it was just activated in a new version or upgraded from an old version. The upgrade behavior can both be defined declaratively in the feature.xml and in an event triggered when a feature is upgraded. 3.4.1. Declarative feature upgrade The declarative feature upgrade manifest contains an UpgradeActions element. Here you can declare actions that should only be applied for certain feature version ranges, including adding fields to content types, provision, move or rename files and more. Currently the following elements can be placed inside an UpgradeActions element: • VersionRange • CustomUpgradeAction • ApplyElementManifests • AddContentTypeField • MapFile The optional VersionRange element gives you the opportunity to target feature upgrade to specific version ranges (e.g. between version 1.0.0.0 and version 1.2.0.0). The declarative logic specified inside the VersionRange elements will then only be executed if the version falls inside the version range. This gives you the ability to branch upgrades with different behavior for each version. CustomUpgradeActions contains actions and parameters for custom code that is referenced in the UpgradeActions element (see more below under programmatic feature upgrade). CustomUpgradeActions can both be placed inside the UpgradeActions element and inside the VersionRange element. ApplyElementManifests is what you probably will use a lot when upgrading features: it will include an elements manifest that is only triggered on upgrade. This makes it easy to add new artifacts to an existing feature. The element can be placed under UpgradeActions or VersionRange elements. The optional AddContentTypeField makes it possible to easily add new fields to existing content types. By adding a PushDown=”TRUE” attribute to the element the change is pushed down from the site content types to every list content type. This was really a pain to do both declaratively and in code in SP2007, so that’s a really helpful change in SP2010. MapFile can be used to move or rename files during feature upgrade. 3.4.2. Programmatic feature upgrade The changes are not only declarative. There are several changes to the object model regarding feature upgrades. For once there’s now a FeatureUpgrading event that gets called for each matching VersionRange when a feature is upgraded. You can pass parameters to this event declaratively through the CustomUpgradeAction. New in SP2010 is also the Feature Upgrade Query Object Model. This can be used to query across farm to determine what features are installed and what versions they have, if they need to be upgraded, and then upgrade features accordingly. A QueryFeature method has been added to SPSite, SPContentDatabase, SPWebApplication, SPWebService and SPAdministrationWebApplication classes. These methods can be used to determine what features need upgrading in the relevant scope. Note: More on upgrading features and the feature object model on MSDN http://msdn.microsoft.com/en-us/library/ee535723(office.14).aspx To do the actual upgrade you call the Upgrade method on a deployed feature (SPFeature) and have it update to a new version. Note: The SPFeatureDefinition class already contained a version property. New in SP2010 is that SPFeature also contains a version property. This version does not necessarily correspond to the SPFeatureDefinition version: Upgrading a feature definition does not upgrade the feature instance itself. You will can use the query object model to obtain feature instances that need to be upgraded and programmatically call Upgrade() to upgrade to the new version. Read more on SPFeature version property here http://msdn.microsoft.com/enus/ library/microsoft.sharepoint.spfeature.version(office.14).aspx 3.5. Customizations against deprecated/changed UI Customizations done in Central Administration and SSP Admin UI will also have to be reimplemented. Central Administration has been completely restructured, and SSP has been replaced completely, so configuration links won’t show up as expected. Since the HTML and CSS has changed in the new versions, depending on the layout the customized pages will look different in the new UI, even if the UI was done carefully emulating the existing configuration pages using the same controls! If these links are still needed, they should be moved prior to an upgrade. For application pages consider changing the MasterPageFile attribute with the DynamicMasterPageFile attribute. This will make the application page reference the site master page rather than application.master. 3.6. Security changes 3.6.1. Web Parts As with SP2007 ASP.NET web parts should be preferred. WSS web parts while being phased out are still supported, but there are really no good reasons to use them anymore: Web Part Page Services Components (WPSC) that was part of WSS web parts would allow you to do client-side connections, but the new feature in SP2010 called Client Object Model exceeds anything WPSC would ever allow you to do. Also AJAX (including postbacks) is now natively supported. Other reasons to use SharePoint web part classes include part cache, but this can easily be solved in ASP.NET web parts using runtime cache. Note: More on Managed Client Object Model on MSDN http://msdn.microsoft.com/enus/ library/ee537247(office.14).aspx The Client Object Model is also the reason that new Cross-site scripting (XSS) safeguards have been implemented in SP2010. Properties in web parts that can be changed by contributors, combined with Client Object Model are a XSS risk. This is why custom properties in web parts now require at least Designer level (previously it only took Contributor level). The new XSS safeguards are the RequiresDesignerPermissionAttribute that can be applied to properties in web parts and SafeAgainstScript safe control. Both are designed to limit access to viewing and saving properties in web parts. Note that all web parts are affected by these new security measures (including old SP2007 web parts). This means you should review existing web parts to check if this new restriction breaks functionality, validate the risk of XSS and evaluate if you can risk setting the SafeAgainstScript SafeControl to true (false is default!). Note: XSS Safeguard only affects shared web parts, not Personal or personalized properties. 3.6.2. Sandboxed Solutions Sandboxed solutions are a new concept in SP2010. Sandboxed solutions address a common problem in SP2007: you would have farm administrators would like to keep their servers up and running with good response times, and secure from malicious code. But you would also have developers that were told to develop custom functionality. Testing code before deploying it to a farm is both time consuming and difficult. Even with several test levels such as unit tests, smoke tests, functional test, load test and integration test, you will often not discover problems with the code until it is too late: in your production environment. Sandboxed solutions is a subset of a standard solution: it is limited both in regards of object model and performance to run within a process called User Code Service (SPUCWorkerProcess.exe) that runs within a very limited Code Access Security policy (wss_usercode.config, that should not be edited!) and only on selected servers in the farm. It also uses a limited subset of the SharePoint API (reflected in Visual Studio intellisense). A solution that runs within the sandbox is monitored on an array of metrics such as CPU, queries to database, unhandled exceptions etc. You can set up quota limit that the code needs to stay within. If this quota is exceeded, warnings will go out to Operations and when a limit has been reached, the code is temporarily disabled. You can build custom solution validators that allows only certain types of artifacts (e.g. web parts) or code signed with specific signatures While th is new concept makes a lot of sense, it also means that you need to be aware of this when you upgrade your existing solutions: Code-wize you will need to review your solutions, so that they will still work within the solution sandbox, since sandboxed solutions run against a subset of the API and with a limited CAS policy, a lot of the stuff you did yesterday (like web service calls, or calling code that is not marked with AllowPartiallyTrustedCallers=True) will no longer work! It is possible to make calls to the “real” API, but it requires you to move the code to what’s called a full trust proxy in a separate assembly that goes in the GAC, and call the proxy from the sandbox. You can choose to ignore sandboxed solutions and just upgrade your old 2007 solutions as what is now called Farm Solutions, but all in all the concept of sandboxed solutions will need to be addressed before upgrading a farm. There are good reasons to use the sandbox, including improved security, better monitoring and in the end a more stable and better performing farm, and looking ahead, all new development that fall inside what can be achieved as sandboxed solutions should be developed as such! With regard to architecture, it should be considered to dedicate server(s) to run sandboxed solutions further isolating custom code from the rest of the farm. Note: For more information on SandBoxed solutions check out: http://msdn.microsoft.com/en-us/magazine/ee335711.aspx http://blah.winsmarts.com/2009-12– SharePoint_2010_Sandboxed_Solutions__The_Definitive_Guide.aspx For more information on custom solution validators check out the API: http://msdn.microsoft.com/enus/ library/microsoft.sharepoint.usercode.spsolutionvalidator(office.14).aspx For more information on full trust proxies see the API: http://msdn.microsoft.com/enus/ library/microsoft.sharepoint.usercode.spproxyoperation(office.14).aspx 3.7. Large List Throttling There’s a new performance related feature in SP2010 called Large List Query Throttling: Queries that touch large lists will fail based on predefined thresholds set in CA. There is a good chance that this could cause problems for legacy code, especially if development is being done as an administrative user! Also if development and test environment does not have realistic data volumes, code could fail without this being caught before deployment. For this reason you should start developing against least privileges, and always try to have as realistic data as possible in your environment (for lists it would even make sense to have lists that are a lot larger than in production). Even if you only select a small subset of items from a large list, the API and database still need to do a table scan to select the appropriate items. Hence a small query on a large list will be throttled and throw an exception. This can be resolved by adding an index on the list that matches the field that is used in CAML query to filter the list. It is possible to override the Resource Throttling: SPQueryThrottleOption.Override if Object Model Override is set to Yes in CA and if the user executing the query has Full Read permissions. Note: To avoid Yellow Screen of Death (YSOD) code needs to be changed to log and catch a new exception SPQueryThrottledException. 3.8. Deprecated API’s When you recompile your old SP2007 code for SP2010, you will see warnings for types and methods that have been deprecated in SP2010. Most of these will continue to work without breaking anything in SP2010, but you are encouraged over time to upgrade the code since Microsoft no longer will invest in these API’s. Note: Get a list of deprecated types and methods made obsolete in SP2010 and SP2007 on MSDN: http://code.msdn.microsoft.com/sps2010deprecated Chris Auld mentioned a plug-in for Reflector that would catch obsolete methods and warn against code that could have problems in SP2010, for example in relation to sandboxed solutions. Tool should become available at http://www.syringe.net.nz/blog 3.9. Hardcoding issues If you have hardcoded references to anything residing in the old 12-hive (aka SharePoint root folder: c:\program files\common files\microsoft shared\web server extensions\12) these should be updated to point to the 14 folder instead! 3.10. Upgrading the look & feel to the new version If you choose to go with the new visual upgrade like the Ribbon, developer dashboard etc., you need to manually add these controls to your master pages and page layouts. After upgrading the solution to SP2010, in Site Settings > Site Collection Administration select Visual Upgrade > “Apply the new User Interface to All Sites”. Click Update All Sites. This will change the appearance to the new interface. While the site settings page itself properly will upgrade without issues, but if you are using a custom site definition, you will need to manually replace the old UI controls: Since SharePoint distinguish between v3 (SP2007) and v4 (SP2010) master pages (v3 master pages are filtered out in the standard Master page view), start by creating a new blank v4 master page using SharePoint Designer 2010 (SPD) and replace the content with the content of the v3 master page. • Delete the page editing toolbar (PublishingConsole) tag prefix and associated controls • Delete site action (PublishingSiteAction) tag prefix and associated controls (including the SPSecurityTrimmedControl wrapper control) • Add core.js if not already present as a ScriptLink control • Copy the ribbon DIV html and control (SPRibbon) from v4.master and paste it into the new master at the very top of the body (inside FORM element) • Add register tag prefixes for ribbon (MUISelector) • If you use breadcrumb control, this is contained in ribbon, so remove control and surrounding HTML from master • Copy the developer dashboard control (DeveloperDashboard) from v4.master and insert it into the bottom of the body of the new master Note: Further customizations can be done (such as maintaining the position of the ribbon while scrolling) info on upgrading an existing master page to the SharePoint Foundation master page can be found on MSDN: http://msdn.microsoft.com/en-us/library/ee539981(office.14).aspx 3.11. Upgrading projects to Visual Studio 2010 Part of upgrading your code should be migrating from VS2005/VS2008 to VS2010. There are a bunch of new cool features for SharePoint in the new VS2010, so it is recommendable to upgrade existing projects to the new development platform. Also it will make upgrading existing code easier. If your projects were created using VSeWSS you can download a VS2010 template that will upgrade your projects to VS2010 SharePoint projects. After migration you will need to manually consolidate your artifacts using Feature Designer and Packaging Explorer. Note: The VSeWSS upgrade tool is not officially supported by Microsoft. You can download Visual Studio 2010 (Beta) migration tool for VSeWSS SharePoint projects here: http://www.microsoft.com/downloads/details.aspx?FamilyID=41019A15-8C73-497C-97FB– 502A619A6C46&amp;displaylang=en If you use other tools like STSDEV or WSPbuilder, you can consider a number of different more or less manual approaches: The first approach is a manual approach where you basically build your project structure up manually importing code and artifacts as you go: • First you need to evaluate what your visual studio projects contain. o If you have separated your different logic into tiers for data access, business logic and presentation, there is a good chance that these class library projects can be copied directly into VS2010. o For visual studio projects containing artifacts create an empty SP2010 project. Here you must choose between creating a sandboxed solution or a farm solution –the choice will depend on what customizations are done in the project, since sandboxed solutions put a lot of restrictions on what can be done. Sandboxed solutions should be preferred, but will probably require a lot more effort on refactoring the code to keep within the sandbox boundaries. • Use the new VS2010 feature called Mapped Folders to map the SharePoint root (aka 14- hive) folders you need for your project. Add your existing artifacts into the relevant folders o To take full advantage of VS2010 you can also create some of the artifacts (such as web parts) from scratch using the corresponding template and then copy/paste the code and declarative xml from your existing files. • VS2010 now has a feature called Replaceable Parameters that basically are tokens that are replaced after manifest transformation. The tokens are extendable and include tokens for things like $Sharepoint.Project.AssemblyFullName$ Consider replacing • For artifacts that need to be provisioned to document libraries you create Modules and add your existing content to the modules. • Features can either be created manually or added through the feature Manifest Template (<featurename>.Template.xml). The features added through designer and Manifest Template is merged into a single manifest file for the feature. • Add the artifacts to the Package (Package.package file in project folder) using Package Explorer or Package Designer. • For artifacts currently not supported by VS2010 (for example custom site definitions) add the relevant xml from your existing manifest.xml files to Package.Template.xml that can be found nested under Package folder. Artifacts listed in Package.Template.xml are merged with Package artifacts during packaging into a single solution manifest file. Note: Read more on MSDN about Packaging and Deploying SharePoint Solutions: http://msdn.microsoft.com/en-us/library/ee231544(VS.100).aspx Read more on MSDN about the structure and files in SharePoint project types: http://msdn.microsoft.com/en-us/library/ee476619(VS.100).aspx#projectcomponents To ease this manual process you can instead choose to import SharePoint solution packages (WSP) into VS2010 using the Import SharePoint Solution Package project type. As of now this template works best for simple WSP packages, but hopefully it will become better in the final release: • First create a WSP file containing the artifacts you need to migrate to VS2010. • Create a new Import SharePoint Solution Package project in VS2010 and select WSP file when asked. • If not supported artifacts was contained in the WSP you might get a warning, but don’t count on it. The import still has a lot of beta hiccups, so for example custom site definitions disappear after an import and so does assemblies for CAG. I don’t know if this will be fixed for the final release, but still the tool is still a huge help when you want to convert existing projects. Note: Carsten Keutmann the author of WSPBuilder also has released a beta of WSPBuilder for VS2010. I haven’t had time so far to check this out, but it is available on Codeplex here: http://wspbuilder.codeplex.com/releases/view/30858 The third way of importing a project would be to “roll your own” import tool. VS2010 has specific interfaces defined for creating extensions of various kinds. For example the ISharePointProjectFeature interface for adding items to features and the ISharePointProjectPackage to add items to packages. Note: Since the SharePoint Tools in VS2010 are extendable, we already see a lot of tools by the SharePoint Community. So far most notably Community Kit for SharePoint: Development Tools Edition that contains several enhancements focused on deployment, artifacts and more. CKS:DEV can be found on Codeplex: http://cksdev.codeplex.com/ There are a lot of good reasons to upgrade to VS2010 like F5 debugging, templates for specific tasks, native support for solutions and features, possibility to browse SharePoint sites using Server Explorer. The list goes on! All this makes SharePoint development a much better experience than developing in earlier versions of VS. Note: More info on importing WSP into VS2010 on Channel9: http://channel9.msdn.com/posts/funkyonex/Importing-SharePoint-Solution-Packages-WSP-into– Visual-Studio-2010/ For more info on what’s new in VS2010 with regards to SharePoint development read this TechNet article: http://msdn.microsoft.com/en-us/library/ee290856(VS.100).aspx 3.12. Client upgrades Be aware that Internet Explorer (IE) 6 no longer is supported for authoring, due to its poor interpretation of web standards. As part of an upgrade you should plan for upgrading to a supported browser. Note: Read more on TechNet: Plan browser support http://technet.microsoft.com/enus/ library/cc263526(office.14).aspx 4. PLANNING Now that the basics for upgrading SharePoint 2007 to SP2010 have been laid out both regarding servers and code, it is time to think about what the specific actions should be when doing an upgrade. This chapter only contains general recommendations, as the approach will be dictated by external factors such as if the company that pays for the upgrade is willing to buy new hardware for either a full db attach upgrade or a hybrid approach involving new hardware. Also the physical design of the solution, the size of the content databases, and the amount of customization on the farm will affect the recommended approach, along with demands for downtime. 4.1. Planning prerequisites First thing that should be done is bringing the solution in a supported upgradable position. This includes upgrading any OS used as SharePoint servers from 2003 to 2008 server R2 for all involved servers. Make sure SQL server is running 64-bit with latest SP and CU. For SQL Server this is SP3 with CU3. Optionally consider upgrading to SQL server 2008 SP1 with CU 2 since SQL Server 2005 support lifecycle is terminated in 2011 (http://support.microsoft.com/lifecycle/?p1=2855) another reason for upgrading is improvements from 2005 to 2008 including better compression, better encryption, higher availability through improved patching capabilities, throttling and improved locking mitigating blocking issues, better mirroring, support for Remote BLOB Storage etc. (read here http://blogs.msdn.com/mikewat/archive/2008/08/19/improving-sharepoint-with-sql-server– 2008.aspx and here http://www.sharepointjoel.com/Lists/Posts/Post.aspx?ID=297 for more). Also consider upgrading the OS that SQL server is running on to Windows 2008 Server, since no further service packs is considered for 2003 server (http://www.microsoft.com/windows/lifecycle/servicepacks.mspx). When looking at upgrading the software, also consider upgrading or replacing existing hardware: The upgrade process itself will demand more hard disk space to instantiate a number of new databases, existing databases will grow and log files will take up space as well (transaction model is automatically set to Simple for databases though). 4.2. Planning upgrade model When choosing the appropriate upgrade model, several things will affect your choice: For example consider if the servers are already within specifications or if you can expect acceptable performance by upgrading the hardware (scale up)? If this is the case, this speaks for doing an in-place upgrade. On the contrary, if we already now can see that the existing hardware must be replaced, this will necessitate a db attach upgrade. Another question to be asked are if you have scripted installs. If you don’t have this, this could speak for an in-place upgrade, rather than having to do a manual install, that is prone for human error. Are customizations as a general rule structured and reproducible (read: solutions and features)? If not, this speaks for doing an in-place upgrade to avoid the process of reproducing customizations on a new server. Also ask yourself what is acceptable downtime? If downtime is totally unacceptable, favor solutions that mitigate downtime, such as read-only databases. As described in the chapter on upgrade models, there is also the possibility to choose a hybrid model. For example the read-only databases hybrid approach has a lot speaking for it, with regards to downtime mitigation. In general in-place upgrade is considered risky, since you won’t be able to easily recover from a failed upgrade. If getting new hardware is out of the question for the upgrade, be sure you have a tested disaster recovery plan that will enable you to re-build your SP2007 farm if need be. 4.3. Planning new Server Architecture Since the architecture on SP2010 has changed quite a lot compared to that of SP2007, you also need to take this into consideration when doing an upgrade. Decide how the service architecture should be: Should new server roles be added to the farm by adding new hardware or by combining roles on existing servers? Would the farm architecture benefit from isolating certain services, since this is now possible in SP2010? Default in SP2010 is that all services are disabled. This is good since it indicates that you should consider for each service if it should be enabled. Sandboxed solutions Consider isolating Sandboxed solutions on a separate server (remote mode). Remote mode is more scalable, but requires more administrative involvement. Note: Further information on planning sandboxed solutions, including planning resource usage quotas on TechNet http://technet.microsoft.com/en-us/library/ee721991(office.14).aspx Remote Binary Large Object Storage (RBS) SP2007 used integrated storage architecture for Binary Large Objects (BLOB), meaning that the BLOB was stored in the content database along with the metadata. As content databases grow, so does the time it takes to backup and restore data, hence affecting the Service Level Agreement (SLA) of the farm. In SP2010, it is possible to store BLOB data separate from the content database using RBS. This allows for storing BLOBS on cheaper storage and has faster backup/restore from SQL server since metadata is stored separately from BLOB’s. RBS defines an interface that allows external BLOB storage providers to support it. In the time of writing there are 5 external providers that either already integrate to, or is in the process of writing providers to integrate to RBS: EMC², OpenText, NetApp, AvePoint and CommVault. Note: RBS should not be considered a silver bullet for keeping disaster recovery within SLA, but rather as a specific tool for a specific problem. Also consider that the whole backup/restore picture will be complicated by having to fetch data from several locations. The SQL Filestream RBS provider that SP2010 provides out of the box is supported by both SharePoint and SQL backup and recovery, but support for backup is up to the individual RBS provider. RBS has several advantages over the existing alternative in SP2007, External BLOB Storage (EBS): • It has a managed interface with a provider API • The scope for setting up RBS is per content database, so you can configure one BLOB store provider for one content database and another BLOB store provider for another (in EBS you had farm scope). • As a consequence of the above, you can have many providers with RBS, where EBS only supported one provider • You can configure a RBS maintainer to support retention policies, detect orphans etc. • RBS can be configured through the UI and using PowerShell • You can migrate BLOBS from one store to another using PowerShell Note: Using RBS requires that SP2010 runs on SQL Server 2008 R2. The existing architecture in SP2007, called External BLOB Storage (EBS), is still supported in SP2010, but should be considered deprecated 4.4. Test, test, test As described earlier, upgrading is very much a trial and error discipline. You cannot expect to upgrade a complex farm with lots of content, customizations and configurations perfect the first time. Even if this is possible, you have no way to tell how long the process would take. Practicing the upgrade process documenting the farm and customizations along the way, will give you a much better gut feeling when you do the actual upgrade: You will have a good idea on what to do, since you already have done it plenty of times, you will have a certain degree of knowledge about the outcome of the upgrade, and even if something should go wrong, you have documentation ready to recover your old farm if need be. Using virtual environments to replicate farm setup, where you test for issues after upgrade. If possible consider doing a pilot, where only part of the farm is upgraded and let end users test the site extensively for you with everyday usage. 4.5. Planning operations scheduling Plan upgrade over a weekend. This will give you time to roll back if something breaks in the upgrade process. A simple schedule can help you determine if you are on track or if you should consider rolling back the original site: • Friday 18:00 start backups • Saturday 0:00 start upgrade of content farm/databases • Sunday 12:00 upgrade must be effectively complete, or rollback must begin • Monday 06:00 environment must be up and running Scheduling should also include a plan for operations staff that should be available during the actual upgrade. 4.6. Planning code upgrade approach In parallel with the planning and trial upgrade of the farm, the development team should be looking at what to do with the existing customizations. This could be done as a separate test upgrade, where solutions and features are installed on a test SP2010 environment and tested. Some things to consider regarding existing solutions, features and code: • Should code be migrated as farm solutions, or should an effort be made to convert the solutions to sandboxed solutions? • Should obsolete namespaces, types and methods be addressed? • When upgrading features consider using the new possibilities available (e.g. new fields in Content Types). • Does code access large lists, or could lists grow outside specified throttling metrics? Treat code accordingly, and decide how to handle throttle exceptions. • When reviewing solutions, features and code, think about if the functionality is still relevant -it could either have been replaced by OOTB functionality or the functionality it was addressing could have been removed from the platform (e.g. custom links in SSP). • Code that run outside IIS should be recompiled with new SharePoint assemblies or binding redirects should be defined along with AssemblyVersion. • Considering the wealth of new features in VS2010 for developing and deploying SharePoint code, migrating your projects to VS2010 should have a high priority Note: Download content posters for SP2010 (including 4 posters on upgrade) here: http://blogs.technet.com/tothesharepoint/archive/2009/10/23/3288841.aspx 4.7. Planning user adoption Finally you should plan for your end users. SP2010 is an awesome product, but it is also huge and a lot of the ways things was done in SP2007 has changed in SP2010, especially when enabling visual upgrade. Examples include the Ribbon, new templates for Information Workers, and a new and vastly improved SharePoint Designer to mention a few. Training your site administrators, designers and contributors will prove valuable before doing the actual upgrade ensuring end user adoption from the start. Note: There are a lot of online resources for end user training, a lot of who are free. The below link is an example of free online videos to train end users in SP2010: http://www.point8020.com/SharePointEndUserTraining.aspx

Microsoft Security Intelligence Report vol 12

 

 

Microsoft Security Intelligence Report

 

Volume 12

July through December, 2011

 

Microsoft Security Intelligence Report

footer-right-page.jpg This document is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, AS TO THE INFORMATION IN THIS DOCUMENT.

This document is provided “as-is.” Information and views expressed in this document, including URL and other Internet website references, may change without notice. You bear the risk of using it.

Copyright © 2012 Microsoft Corporation. All rights reserved.

The names of actual companies and products mentioned herein may be the trademarks of their respective owners.

 

footer left page.jpg Authors

Dennis Batchelder

Microsoft Protection Technologies

Shah Bawany

Microsoft Windows Safety Platform

Joe Blackbird

Microsoft Malware Protection Center

Eve Blakemore

Microsoft Trustworthy Computing

Joe Faulhaber

Microsoft Malware Protection Center

Sarmad Fayyaz

Bing

 

David Felstead

Bing

Paul Henry

Wadeware LLC

Nitin Kumar Goel

Microsoft Security Response Center

Jeff Jones

Microsoft Trustworthy Computing

Jimmy Kuo

Microsoft Malware Protection Center

Marc Lauricella

Microsoft Trustworthy Computing

 

Ken Malcolmson

Microsoft Trustworthy Computing

Nam Ng

Microsoft Trustworthy Computing

Mark Oram

Microsoft Trustworthy Computing

Daryl Pecelj

Microsoft IT Information Security and Risk Management

Dave Probert

Microsoft Security Engineering Center

 

Tim Rains

Microsoft Trustworthy Computing

Frank Simorjay

Microsoft Trustworthy Computing

Holly Stewart

Microsoft Malware Protection Center

Matt Thomlinson

Microsoft Trustworthy Computing

Scott Wu

Microsoft Malware Protection Center

Terry Zink

Microsoft Forefront Online Protection for Exchange

 

Contributors

Doug Cavit

Microsoft Trustworthy Computing

Chris Compton

Microsoft Trustworthy Computing

Mike Convertino

Microsoft Trustworthy Computing

Enrique Gonzalez

Microsoft Malware Protection Center

Heather Goudey

Microsoft Malware Protection Center

Roger Grimes

Microsoft IT Information Security and Risk Management

 

Satomi Hayakawa

CSS Japan Security Response Team

Jenn LeMond

Microsoft IT Information Security and Risk Management

Le Li

Microsoft Windows Safety Platform

Jenner Mandel

Microsoft Trustworthy Computing

Hideya Matsuda

CSS Japan Security Response Team

Patrick Nolan

Microsoft Malware Protection Center

Takumi Onodera

Microsoft Premier Field Engineering, Japan

Anthony Penta

Microsoft Windows Safety Platform

Kathy Phillips

Microsoft Legal and Corporate Affairs

Hilda Larina Ragragio

Microsoft Malware Protection Center

Laura A. Robinson

Microsoft IT Information Security and Risk Management

Richard Saunders

Microsoft Trustworthy Computing

 

Jasmine Sesso

Microsoft Malware Protection Center

Adam Shostack

Microsoft Trustworthy Computing

Maarten Van Horenbeeck

Microsoft Trustworthy Computing

Henk van Roest

CSS Security EMEA

Patrik Vicol

Microsoft Malware Protection Center

Steve Wacker

Wadeware LLC

Dan Wolff

Microsoft Malware Protection Center

 

 

footer-right-page.jpg Table of Contents About this report ………………………………………………………………………………………………………………… vi Trustworthy Computing: Security engineering at Microsoft ……………………………………… vii How Conficker continues to propagate 1 Background…………………………………………………………………………………………………………………………… 3 Propagation mechanisms ………………………………………………………………………………………………. 5 Results ……………………………………………………………………………………………………………………………….. 6 Tips to help clean up an environment in which Conficker is present ……………………. 9 Determined Adversaries and Targeted Attacks 11 Introduction ………………………………………………………………………………………………………………………… 13 Determined Adversaries ……………………………………………………………………………………………………. 15 Same old tricks, new era ………………………………………………………………………………………………. 16 The role of the Internet ………………………………………………………………………………………………… 17 Targeted Attacks ………………………………………………………………………………………………………………… 18 Challenges in defending against Targeted Attacks ……………………………………………………… 23 The risk management challenge ………………………………………………………………………………… 23 Prevention ………………………………………………………………………………………………………………………. 24 Detection ………………………………………………………………………………………………………………………… 25 Containment ………………………………………………………………………………………………………………….. 26 Recovery …………………………………………………………………………………………………………………………. 26 Communication and Information Sharing …………………………………………………………………….. 28 footer left page.jpg The Role of Governments ……………………………………………………………………………………………. 28 Conclusion ………………………………………………………………………………………………………………………….. 30 Worldwide threat assessment 33 Vulnerabilities …………………………………………………………………………………………………………………….. 35 Industry-wide vulnerability disclosures …………………………………………………………………….. 35 Vulnerability severity ……………………………………………………………………………………………………. 36 Vulnerability complexity ………………………………………………………………………………………………. 38 Operating system, browser, and application vulnerabilities ………………………………….. 39 Microsoft vulnerability disclosures …………………………………………………………………………….. 40 Guidance: Developing secure software …………………………………………………………………….. 41 Exploits ………………………………………………………………………………………………………………………………… 42 Java Exploits …………………………………………………………………………………………………………………… 44 HTML and JavaScript exploits …………………………………………………………………………………….. 45 Document parser exploits ……………………………………………………………………………………………. 46 Operating system exploits …………………………………………………………………………………………… 48 Adobe Flash Player exploits ………………………………………………………………………………………… 50 Exploit effectiveness with the Enhanced Mitigation Experience Toolkit……………… 52 Malware and potentially unwanted software ……………………………………………………………….. 55 Global infection rates …………………………………………………………………………………………………… 55 Operating system infection rates ……………………………………………………………………………….. 62 Threat categories ………………………………………………………………………………………………………….. 65 Threat categories by location …………………………………………………………………………………. 67 Threat families ……………………………………………………………………………………………………………….. 68 Rogue security software ………………………………………………………………………………………………. 71 Home and enterprise threats ……………………………………………………………………………………… 76 Guidance: Defending against malware ……………………………………………………………………… 80 footer-right-page.jpg Email threats ……………………………………………………………………………………………………………………….. 81 Spam messages blocked ………………………………………………………………………………………………. 81 Spam types …………………………………………………………………………………………………………………….. 84 Guidance: Defending against threats in email …………………………………………………………. 87 Malicious websites …………………………………………………………………………………………………………….. 88 Phishing sites ………………………………………………………………………………………………………………….. 89 Target institutions …………………………………………………………………………………………………….. 91 Global distribution of phishing sites ……………………………………………………………………… 93 Malware hosting sites …………………………………………………………………………………………………… 95 Malware categories ………………………………………………………………………………………………….. 96 Global distribution of malware hosting sites ……………………………………………………….. 98 Drive-by download sites ……………………………………………………………………………………………. 100 Guidance: Protecting users from unsafe websites ………………………………………………… 102 Appendixes 103 Appendix A: Threat naming conventions ……………………………………………………………………. 105 Appendix B: Data sources………………………………………………………………………………………………. 107 Appendix C: Worldwide infection rates ………………………………………………………………………. 109 Glossary …………………………………………………………………………………………………………………………….. 114 Threat families referenced in this report …………………………………………………………………….. 121 footer left page.jpg About this report

The Microsoft® Security Intelligence Report (SIR) focuses on software vulnerabilities, software vulnerability exploits, and malicious and potentially unwanted software. Past reports and related resources are available for download at www.microsoft.com/sir. We hope that readers find the data, insights, and guidance provided in this report useful in helping them protect their organizations, software, and users.

Reporting period

This volume of the Microsoft Security Intelligence Report focuses on the third and fourth quarters of 2011, respectively, with trend data for the last several years presented on a quarterly basis. Because vulnerability disclosures can be highly inconsistent from quarter to quarter and often occur disproportionately at certain times of the year, statistics about vulnerability disclosures are presented on a half- yearly basis, as in previous volumes of the report.

Throughout the report, half-yearly and quarterly time periods are referenced using the nHyy or nQyy formats, where yy indicates the calendar year and n indicates the half or quarter. For example, 2H11 represents the second half of 2011 (July 1 through December 31), and 4Q11 represents the fourth quarter of 2011 (October 1 through December 31). To avoid confusion, please note the reporting period or periods being referenced when considering the statistics in this report.

Conventions

This report uses the Microsoft Malware Protection Center (MMPC) naming standard for families and variants of malware and potentially unwanted software. For information about this standard, see “Microsoft Malware Protection Center Naming Standard” on the MMPC website.

footer-right-page.jpg Trustworthy Computing: Security engineering at Microsoft

Amid the increasing complexity of today’s computing threat landscape and the growing sophistication of criminal attacks, enterprise organizations and governments are more focused than ever on protecting their computing environments so that they and their constituents are safer online. With more than a billion systems using its products and services worldwide, Microsoft collaborates with partners, industry, and governments to help create a safer, more trusted Internet.

Microsoft’s Trustworthy Computing organization focuses on creating and delivering secure, private, and reliable computing experiences based on sound business practices. Most of the intelligence provided in this report comes from Trustworthy Computing security centers—the Microsoft Malware Protection Center (MMPC), Microsoft Security Response Center (MSRC), and Microsoft Security Engineering Center (MSEC)—which deliver in-depth threat intelligence, threat response, and security science. Additional information comes from product groups across Microsoft and from Microsoft IT (MSIT), the group that manages global IT services for Microsoft. The report is designed to give Microsoft customers, partners, and the software industry a well-rounded understanding of the threat landscape so that they will be in a better position to protect themselves and their assets from criminal activity.

 

footer left page.jpg

 

footer-right-page.jpg How Conficker continues to propagate

 

 

footer left page.jpg

footer-right-page.jpg Background

In October 2008, Microsoft® released a security update (MS08-067) that addressed a software vulnerability in some versions of the Windows operating system. At that time, Microsoft recommended that customers install the update as soon as possible and warned that attackers could potentially create a worm that would affect vulnerable computers. Over the next few weeks, hundreds of millions of computers around the world received the MS08-067 update.

In November 2008, the Microsoft Malware Protection Center (MMPC) detected the emergence of the first version of Win32/Conficker, an aggressive and technically complex new family of worms. Win32/Conficker targeted the vulnerability addressed by MS08-067. Although the first version of this new threat did not spread widely, it seriously challenged security responders and others charged with ensuring the safety of the world’s computer systems and data. In late December 2008—a full two months after Microsoft released the security update— a second version of Conficker was detected. This version includes additional attack vectors that help the worm to spread quickly.

Microsoft created and distributed antimalware signatures for the new threats. In addition, Microsoft worked with other members of the international security community to contain much of the damage that was caused by Conficker, and in the process established a potentially groundbreaking template for future cooperative response efforts.

footer left page.jpg 0200,000400,000600,000800,0001,000,0001,200,0001,400,0001,600,0001,800,0002,000,0001Q092Q093Q094Q091Q102Q103Q104Q101Q112Q113Q114Q11Win32/Conficker detections Figure 1. Win32/Conficker detections by Microsoft antimalware products, 1Q09–4Q11

 

This section of the Microsoft Security Intelligence Report, Volume 12 establishes that Conficker remains a threat, provides background information on why it is a serious threat, and what organizations can do to protect themselves. (For more information and deep technical details on Conficker, see the “Win32/Conficker Update” section in Microsoft Security Intelligence Report, Volume 7 (January through June 2009), available at www.microsoft.com/sir.)

At its peak, Conficker infected an estimated seven million computers worldwide, according to the Conficker Working Group. Conficker was immediately recognized as dangerous because it attempts to exploit a vulnerability on Windows XP®-based systems that allows remote code execution when file sharing is enabled (CVE-2008-4250, which Microsoft had addressed in October 2008 with critical update MS08-067). In addition, Conficker disables several important system services and security products, and also downloads arbitrary files. The initial version (labeled Worm:Win32/Conficker.A by the MMPC) was not very successful at propagating, mostly because the MS08-067 security update had already been distributed and widely installed. However, the next variant, Worm:Win32/Conficker.B, uses two new propagation methods—abusing the Autorun feature on Windows XP and Windows Vista®-based computers, and

footer-right-page.jpg guessing administrator passwords on network shares with weak or shared passwords—to quickly propagate through the Internet.

In addition to quick propagation, the newer variants of Conficker use a larger array of attack techniques than most malware families. In addition to a suite of self-defense mechanisms such as blocking access to security-related websites and disabling security software on infected computers, Conficker uses encryption and a method called HTTP rendezvous to protect its payload channel.1

1 See page 96 of Microsoft Security Intelligence Report, Volume 7 (January through June 2009) for more information about this technique.

2 See the entry for Worm:Win32/Conficker.C in the MMPC encyclopedia (www.microsoft.com/security/portal) for the list of weak passwords used by Conficker.

Because of the way Conficker uses multiple attack vectors to maximize its reach, there was a global effort to thwart its use and to determine who would try to make use of it. Worm:Win32/Conficker.E was reported to perform some downloads of the Win32/Waledac spambot and the rogue security software family Win32/FakeSpypro (which identified itself as “SpyProtect 2009”). This variant was programmed to delete itself in May 2009.

Propagation mechanisms

Although the efforts of the Conficker Working Group and associated organizations restricted Conficker’s potential for damage, the MMPC received telemetry reports of the worm infecting or attacking 1.7 million computers in 4Q11, about 100,000 computers more than in 3Q11. A detailed analysis of the MMPC telemetry can help organizations defend against Conficker variants by understanding the relative success rates of the different propagation methods that the worm uses.

Information about the propagation vectors is directly observable through data reported by Microsoft security products running on computers whose administrators or users choose to opt in to data collection. The MMPC used this data to deduce the following information about Conficker’s propagation mechanisms:

. Credential-based attacks. This type of attack uses the credentials of the logged-in user to access local or network resources, or else attacks password- protected resources using a built-in list of common or weak passwords.2 When the worm successfully infects a computer using this type of attack, it

footer left page.jpg creates a scheduled task on the infected computer that attempts to re-infect the computer at regular intervals. Credential-based attacks can therefore be identified through the presence of such a scheduled task. . Autorun feature abuse attempt. Conficker can attempt to spread to a computer by abusing the Autorun feature in Windows, through the use of a malicious autorun.ini file that links to a Conficker executable. Microsoft security software detects and blocks this file, even on computers running versions of Windows that are not at risk from this form of attack. Detection of the malicious autorun.ini file is therefore not an indication of an infected computer, but indicates that an attack has been attempted. . MS08-067 exploitation. It is possible to determine this type of attack because of a detail of the worm’s implementation. After successful exploitation, Conficker calls a Windows API that in turn calls the Microsoft IOfficeAntivirus provider, which detects and blocks the transfer of the worm’s code. The telemetry includes an indicator of whether the worm was active or not, which allows excluding partially removed or broken infection attempts. . Preexisting infection. Microsoft antimalware software also reports details about Conficker infections that were present on the computer before the antimalware software was installed. These pre-existing infections are indicated by the presence of a Windows service created by Conficker.

Results

Figure 2 shows an analysis of three weeks of telemetry data of active Conficker installations or installation attempts.3

3 This data was collected after the February 2011 release (through Windows Update and Microsoft Update) of a security update that addressed the Autorun feature abuse technique used by Conficker, as mentioned earlier. See blogs.technet.com/b/security/archive/2011/06/27/defending-against-autorun-attacks.aspx for more information.

footer-right-page.jpg Figure 2. Propagation methods used by Win32/Conficker variants, by percent of all attempted attacks detected

Worm Variant

Credential- based attack

Preexisting infection

Exploit

Autorun abuse attempt

Worm:Win32/Conficker.A

58%

42%

Worm:Win32/Conficker.B

61%

14%

17%

8%

Worm:Win32/Conficker.C

61%

15%

24%

*

Worm:Win32/Conficker.D

100%

Overall

60%

15%

20%

6%

 

* Autorun files for variants B and C are identical, and accordingly are all grouped with Conficker.B in this chart.

Most of the analyzed incidents (60 percent) involved credential-based attacks, with the remaining 40 percent including all other known propagation methods. The second-greatest number of incidents in the specified timeframe (20 percent) exploited the CVE-2008-4250 vulnerability on computers that had not yet been updated with Security Bulletin MS08-067, despite the fact that the update had been released more than two years before. The third-greatest number of analyzed incidents (15 percent) involved infections that were present on the computer before the installation of the antimalware product that detected and removed the infection. Finally, only 6 percent of incidents that were observed in the specified timeframe involved abuse of the Autorun feature in Windows. The release of an update that hardened the Autorun feature in Windows XP and Windows Vista may have helped achieve this relatively low percentage.

This attack pattern suggests that improving credential policies and practices is one of the most important steps computer administrators can take to effectively combat the spread of Conficker. Domain administrators can use Active Directory® Domain Services (AD DS) to define and enforce Group Policy Objects (GPOs) that require users to create complex passwords.4 If local passwords are used for some resources in an organization, resource owners should be required or encouraged to use strong passwords for them as well.

4 See “Enforcing Strong Password Usage Throughout Your Organization” on Microsoft TechNet for more information and instructions.

When considered from the perspective of the affected operating system, it becomes clearer that credential-based attacks on file shares are the primary mechanism Conficker uses to compromise computers running recent versions of the Windows operating system, as shown in Figure 3.

footer left page.jpg Figure 3. Blocked Conficker infection attempts by operating system

Operating System

Credential-based attack

Exploit

Autorun abuse attempt

Windows 2003

81%

19%

1%

Windows XP

54%

43%

2%

Windows Vista

84%

16%

Windows 7

89%

11%

 

 

Windows 7 was never vulnerable to CVE-2008-4250 exploits, and although Windows Vista was vulnerable, no exploit attempts were observed in the measurement period. Network Inspection System (NIS), a feature of Microsoft Security Essentials and Microsoft Forefront® Threat Management Gateway, blocks exploit attempts on vulnerable computers running Windows Vista and other recent versions of Windows, which prevents the Conficker worm from exploiting the CVE-2008-4250 vulnerability.5 Windows 7 was also far more difficult to attack through Autorun feature abuse, and although autorun abuse attempts were observed and blocked on 11 percent of Windows 7 systems, they would not have been successful because of the restricted Autorun policy on that platform.

5 See go.microsoft.com/fwlink/?LinkId=248183 for more information about the Network Inspection System.

The Conficker worm may or may not have had as great an effect as its creators expected, but it continues to search for new victims. Although installing all relevant security updates and hardening the Autorun feature in Windows can close off several Conficker attack vectors, this analysis of the worm’s attacks shows that using weak passwords for network and local resources can still leave computers at significant risk of infection. To effectively defend against Conficker and similar malware families, responsible computer administrators should develop a multifaceted strategy that includes strong passwords, quick deployment of security updates, and the use of regularly updated, real-time antimalware software.

 

footer-right-page.jpg Figure 4. Blocked Conficker infection attempts on enterprise computers, as detected by Microsoft Forefront Endpoint Protection

Operating System

Credential-based attack

Exploit

Autorun abuse attempt

Windows 2003

91%

9%

Windows 7

100%

Windows Vista

100%

Windows XP

88%

12%

 

 

Figure 5. Blocked Conficker infection attempts on consumer computers, as detected by Microsoft Security Essentials

Operating system

Credential-based attack

Exploit

Autorun abuse attempt

Windows 2003

77%

22%

1%

Windows 7

85%

15%

Windows Vista

77%

23%

Windows XP

46%

51%

3%

 

 

Tips to help clean up an environment in which Conficker is present

Malware such as Conficker can still pose a challenge for IT administrators, despite the fact that it is a well-known threat. Even a conscientious IT department that follows responsible practices for quickly installing security updates, installing and monitoring antimalware and intrusion detection systems, and controlling access to file shares can still encounter outbreaks of a threat such as Conficker.

Malware that uses common network protocols such as Server Message Block (SMB) to replicate can pose a threat to locked-down file shares, because an infected computer that has write privileges to the file share can pass the infection on to it. A common scenario is one in which a file share is disinfected by server- side antimalware software, but is quickly reinfected when an infected client computer connects to it. This potential for repeated reinfection gives malware that leverages open file shares, such as Conficker, staying power in data centers. Identifying the original source of the infection within the organization is therefore essential for eradicating such malware. Finding it can require a bit of agility and creativity on the part of server administrators.

footer left page.jpg Microsoft provides information to help IT administrators deal with Conficker infections at www.microsoft.com/conficker. The following list provides some additional tips that may help advanced users who possess a good understanding of computer security and Windows administration find computers that are infected with Conficker in order to minimize their attack surface.

. Create a “rogue” file share, populate it with various executable files and share the directory for full control to all. However, before sharing the folder, turn on Windows monitoring to identify computers that successfully write to the share.6 The events captured in Windows Event Viewer with share monitoring enabled will capture enough information to identify the original source of the infection. Use this practice on several shares and systems in the environment and monitor as needed. . On infected computers, check the device log; by default, the Windows installation places this log in C:\Windows\inf\setupapi.dev. The log will contain information about devices such as memory sticks or other USB hardware that has been installed on the system and will help find the original source of the infection if this method was used to install Conficker or other malware that propagates through Autorun.7 . The original source of the infection is often determined to be a computer inside the organization’s backup infrastructure. Because of performance and other related factors, many organizations relax security controls for backup systems, which is a big mistake. It is important for the organization’s IT staff to ensure that basic security practices are in place, especially for an environment in which Conficker is problematic. It isn’t uncommon for malware to be stored on backup servers, because the files are usually encrypted and continuously copied back down to clean servers. . Inside the data center, implement a server administrator file share change control process that reviews and approves file share configurations; such an approach will help minimize the attack surface for malware that uses network shares to replicate. Depending on the size of the organization, it could be a daunting task to implement such a process throughout an entire data center, but at a minimum it should be required for servers that have been identified as repeat offenders or other systems that have been deemed critical to the organization’s service.

6 For details on auditing user access, see Microsoft Knowledge Base article 310399 at support.microsoft.com.

7 For more information about the device log, see “Troubleshooting Device Installation with the SetupAPI Log File” at the Microsoft Developer Network website (msdn.microsoft.com).

footer-right-page.jpg Determined Adversaries and Targeted Attacks

 

 

footer left page.jpg

footer-right-page.jpg Introduction

Over the past two decades the internet has become fundamental to the pursuit of day-to-day commercial, personal, and governmental business. However, the ubiquitous nature of the internet as a communications platform has also increased the risk to individuals and organizations from cyberthreats. These threats include website defacement, virus and worm (or malware) outbreaks, and network intrusion attempts. In addition, the global presence of the internet has allowed it to be used as a significant staging ground for espionage activity directed at industrial, political, military, and civil targets.

During the past five years, one specific category of threat has become much more widely discussed. Originally referred to as Advanced Persistent Threats (APT) by the U.S. military — referring to alleged nation-state sponsored attempts to infiltrate military networks and exfiltrate sensitive data — the term APT is today widely used in media and IT security circles to describe any attack that seems to specifically target individual organization, or is thought to be notably technical in nature, regardless of whether the attack was actually either advanced or persistent.

In fact, this type of attack typically involves two separate components — the action(s) and the actor(s) — that may be targeted against governments, military organizations or, increasingly, commercial entities and civil society.

The actions are the attacks themselves, which may be IT-related or not, and are referred to as Targeted Attacks in this paper. These attacks are initiated and conducted by human actors, who are collectively referred to in this paper as Determined Adversaries. These definitions are important because they emphasize the point that the attacks are carried out by human actors who may use any tools or techniques necessary to achieve their goals; these attacks are not merely malicious software or exploits. Using an encompassing term such as APT can mask this reality and create the impression that all such attacks are technically sophisticated and malware-driven, making it harder to plan an effective defensive posture.

For these reasons, this paper uses Targeted Attacks and Determined Adversaries as more specific and meaningful terms to describe this category of attack.

footer left page.jpg . Targeted Attacks. The attackers target individuals or organizations to attack, singly or as a group, specifically because of who they are or what they represent; or to access, exfiltrate, or damage specific high-value assets that they possess. In contrast, most malware attacks are more indiscriminate with the typical goal of spreading malware widely to maximize potential profits. . Determined Adversaries. The attackers are not deterred by early failures and they are likely to attack the same target repeatedly, using different techniques, until they succeed. These attackers will regroup and try again, even after their attacks are uncovered. In many cases the attacks are consciously directed by well-resourced sponsors. This provides the attackers with the resources to adapt to changing defenses or circumstances, and directly supports the persistence of attacks where necessary.

Determined Adversaries and Targeted Attacks may employ combinations of technology and tactics that enable the attacker to remain anonymous and undiscoverable, which is why these methods of attack might appeal to agencies of nation states and other entities who are involved in espionage-related activities.

Hardening the perimeters of computer networks is not a sufficient defensive strategy against these threats. Many computer security experts believe that a well- resourced and determined adversary will usually be successful in attacking systems, even if the target has invested in its defensive posture.8

8 Charney, Scott – Rethinking the Cyber Threat – A Framework and Path Forward www.microsoft.com/download/en/details.aspx?id=747

9 Charney, Scott – Trustworthy Computing Next

aka.ms/nextwp

Rather than the traditional focus on preventing compromise, an effective risk management strategy assumes that Determined Adversaries may successfully breach any outer defenses. The implementation of the risk management strategy therefore balances investment in prevention, detection, containment and recovery.9

Microsoft has a unique perspective on Targeted Attacks, as both a potential target of attacks and a service and solution provider to potential victims. This paper shares Microsoft’s insights into the threat that Determined Adversaries and Targeted Attacks pose, identifies challenges for organizations seeking to combat this threat category and provides a context for other papers that will directly address each of those.

footer-right-page.jpg Determined Adversaries

Since the beginning of history, there have been people willing to steal the possessions of others to satisfy a wide variety of motives. Targeted Attacks are simply the inevitable consequence of the digitization of previously physical processes and assets.

Determined Adversaries who deploy Targeted Attacks tend to be well funded and organizationally sophisticated. Examination of several Targeted Attacks shows that the attackers operate in a team model, to meet the requirements of a threat sponsor. The existence of the threat sponsor is critical in understanding the overall actions of Determined Adversaries. In the case of traditional cybercrime, such as attacks against on-line banking, a technically able attacker can be self- motivated. However, in other cases, such as espionage, the sponsor provides the motivation and resources for the attacker to determinedly collect the information that meets their specific requirements. Because new requirements will emerge, it is logical for the attackers to maintain persistent access to existing or potential future targets.

Detailed information about specific Determined Adversaries is often difficult to obtain. The institutions victimized by Targeted Attacks are often reluctant to share information because of the highly sensitive nature of the networks or assets that they protect.

Many of the early Targeted Attacks focused on military and defense networks,10 which are typically among the more well-defended networks in the world. Consequently, attackers were forced to develop a wide range of technical and non-technical skills to conduct successful attacks.

10 www.businessweek.com/magazine/content/08_16/b4080032218430.htm

Today, many of the actors involved in earlier attacks on military networks have started to put their skills to use by attacking commercial networks in order to meet a sponsor’s economic goals. For this reason, security professionals consider Determined Adversaries to be among the more serious security threats that computer networks currently face.

footer left page.jpg Institutions such as military forces, defense contractors, and critical infrastructure providers have been popular targets for espionage since long before the internet existed, and they remain popular targets for Determined Adversaries. However, in a broad sense almost any institution that possesses information assets that an attacker might value can be a target.

Same old tricks, new era

The operational model often employed for human intelligence gathering will be familiar to readers of espionage novels. In this traditional espionage model, a sponsor organization or “pay master” working on their behalf provides a threat actor in the form of an intelligence officer, and requirements for the information they wish to be collected. The intelligence officer then develops operational intelligence to support the identification and recruitment of a vulnerable individual who is likely to have, or be in a position to facilitate, access to the required information. Since it may be dangerous for the intelligence officer to physically meet with the individual (or agent), they will employ a “dead drop”. This is a physical location through which the intelligence officer can pass requirements to the agent, and through which in turn the agent will pass the collected information. Once the agent is established, they may then go on to recruit other agents.

The model employed by Determined Adversaries in conducting Targeted Attacks has striking similarities to this approach. The sponsor and the threat actor roles, albeit it with a different skill set, are a constant. However, the target is now a vulnerable computer system against which the attacker will employ operational intelligence to achieve compromise. Once the system is compromised, the attacker then employs a “dead drop” in the form of a command-and-control server through which information can be exchanged while protecting the identity of the attacker.

In the traditional espionage scenario, there is significant risk to both the sponsor and the threat actors of being identified. However, the same model implemented by Targeted Attacks is significantly more attractive as there is less risk of the actors being identified, detained and their activities made public.

 

footer-right-page.jpg The role of the Internet

Internet technologies provide a basis upon which to achieve huge efficiencies in communications, storage, data processing and business tractions. Given the ever- increasing use of the internet (2 billion users in 2011 with forecasts of another billion users coming online in the next four years),11 it is no surprise that bad actors are using this near-ubiquitous communications medium for their own ends. With almost all individuals, governments, and organizations connected to one another through the internet, geography is increasingly irrelevant. Low risk attacks can be launched from locations around the world, perhaps originating in countries or regions that do not have regulations or laws governing cybercrime, or lack the resources to effectively enforce such laws.

11 www.mckinsey.com/Features/Sizing_the_internet_economy.aspx

One observation of this trend is the trickle-down effect on attack techniques and technology. Ten years ago, attackers had to build bespoke capabilities to conduct many forms of attack. Today there are kits available in illicit online marketplaces that let prospective attackers achieve the same results with much less effort and expertise. The same trickle-down effect can be observed in the evolution of financially motivated attacks employing techniques that originated with Targeted Attacks. For example, the operational model and techniques employed in the targeting of a company’s payment system to facilitate online banking fraud can be similar to those used in espionage orientated Targeted Attacks.

Understanding this change in threat, and reflecting it in consideration of an organization’s risk profile is now essential. For example, a luxury fashion manufacturer might think that a potential attacker would spend significant resources to acquire military or state secrets, but not to target the company’s product designs. It is worth reiterating that this assumption no longer holds because cybercriminals are using the same attack knowledge and tools that were previously focused exclusively on espionage to support the traditional criminal activity of counterfeiting goods. However, in many cases, organizations are simply not prepared for this shift in the threat environment.

 

footer left page.jpg Targeted Attacks

Although attackers have used computer networks to enable espionage for several decades, the widespread recognition of Targeted Attacks as a distinct class of security threat is a relatively recent development. Attacks of this type became publicly known in the mid-2000s following a number of security incidents that were believed to have been perpetrated by, or on behalf of, national governments or other state actors. More recently, reports of similar attacks waged by non-state actors against commercial and government targets for profit, intelligence gathering, or other reasons have increased.

Although Targeted Attacks may be perceived as an evolution of conventional malware activity to more sophisticated levels, it is more accurate to characterize them as the evolution of conventional espionage techniques to target individuals and non-state organizations to a degree not commonly seen in the past. This holds true even where the motive may be purely financial.

Targeted Attacks are technically opportunistic and technology agnostic; the attacker has the resources to use whatever techniques or technologies work. Although Targeted Attacks are sometimes characterized as highly advanced attacks that exploit previously unknown vulnerabilities in software, the reality is often more mundane.12 Attackers often attempt to leverage the target’s operational weaknesses, such as exploiting long out-of-date software, or unpatched vulnerabilities to gain access to a target. After the target is compromised, the attacker attempts to secure additional footholds within the network by compromising authentication systems, disabling audit capabilities, and even manipulating patch management/deployment servers, in an effort to become stealthier, maintain their position, and better exfiltrate data. Attackers have been observed to expand the scope of such attacks by remotely turning on webcams and telephones in conference rooms to eavesdrop on confidential communications in real time.

12 www.microsoft.com/security/sir/story/default.aspx#!0day

Although purely technical attacks are not unknown, most Targeted Attacks use an element of social engineering to gain access to information and sensitive resources

footer-right-page.jpg more easily than a purely technical approach would allow. The highly targeted nature of these attacks makes it possible for a patient and thorough attacker to successfully trick even a vigilant target. Many such tactics can be considered updated versions of traditional confidence tricks in which an attacker gains the trust of the victim by appealing to basic human emotions and drives, such as curiosity, greed, compassion, and anger. Common tactics can include masquerading as a trusted party or authority figure on the telephone or in instant messenger communications in an effort to obtain the victim’s network credentials, as well as customized and personalized versions of standard phishing attacks that are called spear phishing attacks.

In a typical spear phishing attack, the victim may receive a seemingly legitimate email that includes a malicious attachment or directs the victim to a malicious web page, in an effort to capture logon credentials or to use a browser exploit to download malware to the victim’s computer. Spear phishing web pages often resemble legitimate pages on the victim’s corporate intranet or externally hosted sites designed for legitimate activities, such as reviewing health insurance or employee benefit information. If the victim is accustomed to receiving internal communications about these kinds of sites, it can be difficult to distinguish between links to legitimate external sites and malicious copies.

One spear phishing technique that is often used in Targeted Attacks is the content type attack, in which an attacker sends an employee of the targeted organization an email message with a file attachment that contains an exploit. The attacker can individually tailor the email message to lure the recipient, making content type attacks particularly effective. Microsoft has received content type attack samples from all over the world, written in many different languages, such as the example in the following figure which announces the winner of a competition run by a pharmaceutical company.

Figure 6: Example of a lure message in Japanese

 

The goal of the lure email message is to trick the recipient into opening the malicious file attached to the message, and attackers use a variety of psychological

footer left page.jpg tactics to accomplish this goal. Lures often masquerade as internal communications from superiors or other trusted parties, such as a trusted lawyer or business partner. A popular tactic is to represent the malicious file as containing sensitive information that the recipient might not be entitled to know, such as salary information for all of the employees in the company or department—the temptation presented by such “forbidden fruit” is often too great for recipients to resist. Another tactic is for the attacker to research the prospective recipient in advance, and then create a customized lure that appeals to the recipient’s interests, as shown in the following figure.

Figure 7: An example of a lure tailored to its recipient

 

In this case, the attacker determined that the recipient was someone who worked in finance and who would be especially interested in news about financial markets in Asia. Attackers sometimes send several benign messages before any malicious ones, in an effort to build a trust relationship with the recipient.

File attachments to such messages contain malicious code that attempts to exploit a vulnerability in the application which parses the information, such as a word processor or a document reader, when the file is opened. The exploit itself is typically used to install additional malware on the computer, which performs actions such as stealing or destroying files, or connecting to other network resources. As previously stated, in most cases the malicious code attempts to

footer-right-page.jpg exploit a vulnerability that the software vendor has already addressed, which highlights the importance of keeping all software up to date.13

13 blogs.technet.com/b/security/archive/2011/09/28/targeted-attacks-and-the-need-to-keep-document-parsers- updated.aspx

14 www.microsoft.com/security/portal/Threat/Encyclopedia/Glossary.aspx#t

15 blogs.technet.com/b/security/archive/2011/09/28/targeted-attacks-and-the-need-to-keep-document-parsers- updated.aspx

16 www.microsoft.com/sir

17 Charney, Scott – Rethinking the Cyber Threat – A Framework and Path Forward www.microsoft.com/download/en/details.aspx?id=747

In early Targeted Attacks, the payload, or the actions conducted by the malware, was often performed by a trojan14 that was specially crafted to search for specific files or types of files, and then upload them to servers controlled by the attacker. For example, one trojan used in a Targeted Attack was designed to search for computer-aided design (CAD) files, which often contain sensitive design diagrams. More recently, Targeted Attacks have been observed to use malware that allows the attacker to connect to the controlled computer, and then dynamically issue new commands, often using custom communications protocols designed to hide the traffic from detection by network monitoring software.15

A complicating factor in responding to Targeted Attacks is the difficulty in identifying that activity among the myriad of other cyberthreats that organizations may encounter on a daily basis. According to volume 12 of the Microsoft Security Intelligence Report (SIR),16 more than 700 million pieces of malware were detected on computers around the world in the second half of 2011. Identifying specific Targeted Attacks within this large threat ecosystem can be challenging for several reasons:17

. There are many different malicious actors. . These actors have many different motives. . The attacks can look similar, so the nature of the attack does not always help to identify the actor and the motive. . The internet is a shared and integrated domain, where it is not easy to distinguish well-meaning and malicious network activity.

Attributing a Targeted Attack that has been successfully detected is central to many of these challenges. In some countries, law enforcement, the military, intelligence agencies and the private sector therefore attempt to cooperate in building a picture of the threat environment. Conclusive evidence of the “who” and “why” is often though unavailable when a system is under attack, which can

footer left page.jpg make appropriate national and organizational level responses challenging. For example, the attackers usually demonstrate operational sophistication and sometimes operate in shifts, aligning their operations to the time-zone in which the target organization or individual is located. Some attackers have even observed the same public holidays as their targets, regardless of their own physical location. Without additional information, the use of attack timing to locate the attackers can therefore have limited benefit and may even be used to mislead.

However, while attribution may never be perfect, improved categorization of specific attacks, supported by effective sharing of that information between effected parties, can help inform what an appropriate response might be. Being aware of whether the aim of a specific attack is financial crime or the theft of intellectual property, even if the actors remain unknown, will have a meaningful impact on how an organization defends itself.

footer-right-page.jpg Challenges in defending against Targeted Attacks

For many organizations the risks posed by the existence of Determined Adversaries presents a novel challenge. It is therefore vital for organizations to develop and implement plans that consider the possibility of Targeted Attacks. Every organization would be wise to closely evaluate their existing risk management programs, and make necessary adjustments to help reduce their overall level of vulnerability by making balanced investments in prevention, detection, containment and recovery.

The risk management challenge

Over the past 25 years, IT and information security have become more commoditized and based on a common security model, in which the focus is on infrastructure rather than asset protection. As internet technology has become cheaper and accepted as the industry standard, the emphasis has been on commercial off-the-shelf, easily deployable security mitigations to address generic threats on an enterprise wide basis. Such an approach was largely sufficient for non-military organizations 10 years ago, but during the last five years, the number of Targeted Attacks reported in industry has generally increased. And while the implementation of uniform commoditized security solutions is an important component in addressing opportunistic threats, enhanced risk management practices are more important than ever to ensure the adoption of appropriate mitigation measures to counter the more sophisticated attacks which will focus on specific assets.

However, while risk management is a well understood discipline, the most commonly taken approach has challenges when applied to addressing cyber risks, including Targeted Attacks. Since the threat environment is constantly changing, past successes in managing cyber risks are not reliable indicators of actual security and the sole basis for future planning. Additionally, many organizations have determined which risks should be managed by elevating various concerns to

footer left page.jpg senior management. Managers then considered these concerns and evaluated them relative to each other, before ultimately allocating resources appropriately across the risks. According to Aon’s 2011 Global Risk Management Survey, many organizations still use this method. “Senior management’s intuition and experience remains the primary method used by survey respondents to identify and assess major risks facing their organizations.”18

18 www.aon.com/risk-services/thought-leadership/reports-pubs_2011_grms.jsp

This intuitive approach is bound to fail, because senior management cannot possibly understand and assess the full breadth and depth of today’s cyber risks. It is also the case that, unlike many corporate risk assessments relating to security, the question of probability is a moot point. For most organizations some degree of internal compromise of computer systems is inevitable.

Considerations of the appropriate in-depth approaches to risk management are beyond the scope of this paper. It is though worth noting that regardless of the analysis and assessment models employed, addressing Targeted Attacks does specifically require that digital assets are identified, the potential business impacts of their compromise is understood and that the potential motivations and capabilities of Determined Adversaries are reflected in the deployment of countermeasures.

Prevention

Despite the high likelihood of compromise, prevention continues to be a priority in ensuring effective risk management. Commodity security solutions, such as firewalls and antimalware products, continue to offer wide ranging protection against a variety of generic threats and are essential in ensuring network hygiene.

Research has though shown that poorly configured systems—those that do not have security settings applied correctly, or those that do not have security updates applied in a timely manner—continue to be exploited in attacks. For example, volume 9 of the Microsoft Security Intelligence Report (SIR) contains analysis of a sample set of attacks involving exploitation of vulnerabilities in document parsing software, such as Microsoft Office. This analysis shows that—in the sample set examined—the targeted systems were compromised by exploiting software vulnerabilities after the software vendor had released a security update to address them. In some cases, the security update had been available for more than five years.

footer-right-page.jpg Many organizations develop their own software applications and some of these, particularly when internet facing, can be a vector through which to compromise associated databases and other internal systems. Such organizations should therefore consider adoption and implementation of proactive mitigations, including the use of a software security assurance process, such as the Microsoft Security Development Lifecycle (SDL).19

19 www.microsoft.com/sdl

20 Charney, Scott – Rethinking the Cyber Threat – A Framework and Path Forward www.microsoft.com/download/en/details.aspx?id=747

It is also worth noting that the cumulative effect of effective detection, containment and recovery measures also provide a protective effect. This is because as target organizations increase their own capabilities, the likelihood of the Targeted Attack being successful is reduced. Combined with increased information sharing between organizations this can alter the risk reward equation for the attacker, who may then become more selective as to who is targeted.

Detection

Even well protected environments will be targeted by Determined Adversaries who are technology agnostic and undeterred by traditional defenses.20 However, the deployment of intrusion detection and advanced analytics solutions that observes the real-time health of networks involves more than traditional network monitoring. In addition to security data from intrusion detection systems, organizations can also use information provided by IT assets such as routers, hosts, and proxy servers to evaluate operational and security status. The large amounts of monitoring and audit data generated by these solutions must ultimately be turned into insights that can be used to inform more effective cyber security responses. Such responses may be operational, as discussed later in this section, or they can be more strategic and involve changes in policies, controls, and oversight measures. They can also result in combinations of both, with operational incidents informing longer-term decisions.

Regardless, for this to happen, organizations must have the right data, and analyze that data in context for that data to drive action. Fusing together disparate data from a variety of organizations and systems to create a common operational picture is challenging. And building the analytic capabilities (for example, correlation) to derive valuable insights is even more difficult and is as dependent

footer left page.jpg upon the application of human skills as it is on technology. These skills still scarce and the recruitment of suitably skilled individuals is a significant challenge.

Containment

In many cases, the initial compromise of an environment will not immediately result in the attacker achieving their ultimate goal. Instead they will often need to reconnoiter the environment and compromise multiple additional systems. Effective operational security designs and utilization of native security features can help. For example, if the targeted organization has configured its environment with this potential threat in mind, it is possible to contain the attacker’s activities and thereby buy time to detect, respond to, and mitigate the attack. In most cases, the security features required to contain attacks already exists. Existing environments, however, are often architected to mitigate opportunistic rather than Targeted Attacks. To contain an attack, consideration should therefore be given to architecting domain administration models that limit the availability of administrator credentials and applying available technologies such as IPsec based network encryption to restrict unnecessary interconnectivity on the network.

Recovery

The purpose and challenge of recovery is to mitigate the range of harmful impacts that may result from a successful compromise of critical assets.

Because of this possibility, the best approach is to be prepared with a well- conceived recovery plan, supported by suitably skilled response capability. Where many organizations fail in this regard is due to the separation of business, security, and IT operations groups—these teams must work together to ensure the highest, most effective degree of recovery capability. It is therefore advisable to maintain a “crisis committee” to set business recovery priorities and engage in desktop and other exercises to test the organization’s ability to recover from different attack scenarios.

The exact capabilities required by organizations may differ, and may need to be reinforced with external expertise. In general though, the capabilities required should cover IT operations, investigations, effected business units, legal counsel and communications.

footer-right-page.jpg Maintaining customer confidence immediately following a breach through clear and timely messaging is also extremely important in protecting brands, as well as mitigating the direct impact on customers.

footer left page.jpg Communication and Information Sharing

The challenges to effective risk management in relation to Targeted Attacks have already been stated. The ability for risk management processes to effectively inform the operational needs for protection, detection, containment and recovery is made even more difficult if the necessary information is unavailable. Establishing sources of actionable information, whether through public sources or through specific relationships, is therefore vital.

Communicating openly about what happened to a victim organization can help other similar organizations take appropriate measures to avoid the same fate. However, it is not enough to simply share information. The key to successful information sharing is to be clear about the practical outcome. For example, an organization may share the internet address of a system that is attacking it so that other organizations can block that same address, or an organization may want to share their analysis of an event to see if other organizations have seen similar patterns of attack.

Sharing information about Targeted Attacks is very hard. This is in part because sharing information on these attacks might have consequences for an organization’s brand, regulatory compliance, shareholder concern, and its bottom line. Selective sharing between private organizations is though possible, and has been demonstrated to have a high level of effectiveness and is worth the investment.

The Role of Governments

Besides the protection of their own systems, an important role for governments is to create environments in which their constituents (organizations and individuals) can most effectively protect themselves from Targeted Attacks. The following efforts by governments can help constituents protect themselves:

footer-right-page.jpg . Clearly communicate the realities of the threat environment to citizens, companies and investors so that organizations are more comfortable reporting the key aspects of breaches. This reporting can encourage learning from previous incidents and bolster specific defenses to protect key assets in the future. . Making an organization aware that there is reason to believe they may be the target of a Determined Adversary is a critical first step in protecting their critical assets. Governments may have sources of attribution and expertise in threat assessment that provide valuable insights into the intents, motivations and capabilities of Determined Adversaries. This information, which is distinct from the technical data associated with a specific attack, should be communicated to those organizations considered to be at threat to inform their risk management decisions. . Create a climate that encourages the exchange of technical data (at the unclassified level as much as possible) between public and private organizations to enable meaningful outcomes, with rules and mechanisms that permit both sides to protect sensitive data. This approach represents a shift from past practices that viewed information sharing as an objective itself, as opposed to a tool. It must be a two-way sharing process, in which targeted organizations share details of attacks that take place against them with governments, and governments share intelligence about the current threat environment and potential future threats. To be an effective tool against Targeted Attacks, analysis of security logs, alerts, and other intelligence information needs to take place in near-real time, which will require the establishment of solid public/private partnerships.21 . Some governments believe that their national security is dependent on economic security. They may therefore sponsor, or tacitly condone through inaction, the use of Targeted Attacks for stealing intellectual property to support indigenous industries. This approach is ultimately nearsighted because it inhibits the development of indigenous innovation. Governments therefore have a responsibility to address their philosophical differences and use the tools at their disposal, such as diplomacy and national policy, to establish appropriate international norms of behavior.22

21 Written Testimony of Scott Charney Before the Senate Committee on Homeland Security and Governmental Affairs, February 2012 www.hsgac.senate.gov/download/?id=63aa804a-eb21-45fc-8cb1-014439327fdd

22 Charney, Scott – Rethinking the Cyber Threat – A Framework and Path Forward www.microsoft.com/download/en/details.aspx?&id=747

footer left page.jpg Conclusion

Targeted Attacks carried out by Determined Adversaries are not a new phenomenon; political, military, and even commercial espionage has existed in some form for hundreds of years. Over the past three decades, the global connectivity of the internet, together with the lack of traceability and the ability to remain anonymous online, has opened up new attack vectors.

Successfully combatting such threats requires coordinated action between the public and private sectors, and an increased focus on risk management and incident response in regard to Targeted Attacks. The following summarizes these calls to action:

. Establish a culture that promotes information exchange. Fast, comprehensive information sharing is vital to help address the threat of Targeted Attacks. Such information sharing requires establishing a climate in which victims are sufficiently confident to share details of the attacks against them, and to enable governments to share details of the evolving threat ecosystem from their perspectives. Governments should work toward the creation and harmonization of global laws that protect cyberspace, and enable information sharing (including technical information about the Targeted Attacks and threat assessments about the Determined Adversaries) across international boundaries. How individual countries do this domestically might differ, but the desired outcome is a shared objective. . Make risk management a key strategy for organizations, businesses, and governments seeking to prevent, detect, contain and respond to the threat of Targeted Attacks. A key element of risk management strategies must be the assumption that the organization either will be – or already has been – compromised. Another key is to create action plans that thoroughly analyze what the bad actors will do if they compromise an organization’s high value assets. The goal is effective risk management; risk elimination is not possible. . Make creation and active operation of an analytical security enterprise a priority. Even well protected environments will be targeted by determined adversaries, who are technology agnostic and persistent. The deployment of

footer-right-page.jpg intrusion detection and advanced analytics solutions that observe the real- time health and security condition of networks involves more than traditional network monitoring. In addition to security data from intrusion detection systems, organizations can also use information provided by IT assets such as routers, hosts, and proxy servers to evaluate operational and security status. The large amounts of monitoring and audit data generated by these solutions must ultimately be turned into insights that can be used to inform more effective cyber security responses. . Make establishing a solid incident management and response function a vital activity, at an organizational level and at an international level. Organizations should ensure that they have the capability to react appropriately to an attack when detected, contain the attacker, and then recover from the attack. Response plans should include robust communications plans (internal and external) to help ensure that speculation and assumption do not cause additional damage. Internationally, adequate response capability and capacity needs to be built in to countries around the world. Organizations and governments should establish points of contact that are available 24 hours a day, 7 days a week to help facilitate the response process. It would be prudent for these points of contact to be established before an attack takes place.

 

footer left page.jpg

 

footer-right-page.jpg Worldwide threat assessment

 

footer left page.jpg

footer-right-page.jpg Vulnerabilities

Vulnerabilities are weaknesses in software that enable an attacker to compromise the integrity, availability, or confidentiality of the software or the data that it processes. Some of the worst vulnerabilities allow attackers to exploit the compromised system by causing it to run malicious code without the user’s knowledge.

Industry-wide vulnerability disclosures

A disclosure, as the term is used in the Microsoft Security Intelligence Report, is the revelation of a software vulnerability to the public at large. It does not refer to any type of private disclosure or disclosure to a limited number of people. Disclosures can come from a variety of sources, including the software vendor, security software vendors, independent security researchers, and even malware creators.

The information in this section is compiled from vulnerability disclosure data that is published in the National Vulnerability Database (nvd.nist.gov), the U.S. government repository of standards-based vulnerability management. It represents all disclosures that have a CVE (Common Vulnerabilities and Exposures) identifier.

Figure 8 illustrates the number of vulnerability disclosures across the software industry for each half-year period since 1H09. (See “About this report” on page vi for an explanation of the reporting period nomenclature used in this report.)

footer left page.jpg 05001,0001,5002,0002,5003,0001H092H091H102H101H112H11Industry- wide vulnerability disclosures Figure 8. Industry-wide vulnerability disclosures, 1H09–2H11

 

. Vulnerability disclosures across the industry in 2H11 were down 10.0 percent from 1H11, and down 24.3 percent from 1H09. . This decline continues an overall trend of moderate declines since 2006. This trend is likely because of better development practices and quality control throughout the industry, which results in more secure software and fewer vulnerabilities from major vendors, who are most likely to have their vulnerabilities associated with a distinct CVE identifier. (See Protecting Your Software in the “Managing Risk” section of the Microsoft Security Intelligence Report website for additional details and guidance about secure development practices.)

Vulnerability severity

The Common Vulnerability Scoring System (CVSS) is a standardized, platform- independent scoring system for rating IT vulnerabilities. The CVSS base metric assigns a numeric value between 0 and 10 to vulnerabilities according to severity, with higher scores representing greater severity. (See Vulnerability Severity at the Microsoft Security Intelligence Report website for more information.)

footer-right-page.jpg 02004006008001,0001,2001,4001H092H091H102H101H112H11Industry- wide vulnerability disclosuresMedium(4–6.9) High(7–10) Low(0–3.9) Figure 9. Industry-wide vulnerability disclosures by severity, 1H09–2H11

 

. The overall vulnerability severity trend has been a positive one. All three CVSS severity classifications decreased between 1H11 and 2H11, with the Medium and High-severity classifications continuing a trend of declining disclosures in every period since 2H09. . Medium-severity vulnerabilities again accounted for the largest number of disclosures at 936, a 3.5 percent decrease from 1H11. . High-severity vulnerabilities decreased 31.0 percent from 1H11, continuing a near-constant rate of decline since 1H10. . Low-severity vulnerabilities, which had increased slightly over the past several periods, decreased 13.7 percent from 1H11. . Mitigating the most severe vulnerabilities first is a security best practice. High- severity vulnerabilities that scored 9.9 or greater represent 9.6 percent of all vulnerabilities disclosed in 2H11, as Figure 10 illustrates. This figure was down from 10.6 percent of all vulnerabilities in 1H11.

footer left page.jpg High (9.9 +) 9.6% High (7–9.8) 32.3%Medium (4–6.9) 52.5% Low (0–3.9) 5.6% Figure 10. Industry-wide vulnerability disclosures in 2H11, by severity

 

Vulnerability complexity

Some vulnerabilities are easier to exploit than others, and vulnerability complexity is an important factor to consider in determining the magnitude of the threat that a vulnerability poses. A High-severity vulnerability that can only be exploited under very specific and rare circumstances might require less immediate attention than a lower-severity vulnerability that can be exploited more easily.

The CVSS assigns each vulnerability a complexity ranking of Low, Medium, or High. (See Vulnerability Complexity at the Microsoft Security Intelligence Report website for more information about the CVSS complexity ranking system.) Figure 11 shows complexity trends for vulnerabilities disclosed since 1H09. Note that Low complexity indicates greater risk, just as High severity indicates greater risk in Figure 9.

footer-right-page.jpg 02004006008001,0001,2001,4001H092H091H102H101H112H11Industry- wide vulnerability disclosuresLowComplexityMediumComplexityHighComplexity Figure 11. Industry-wide vulnerability disclosures by access complexity, 1H09–2H11

 

. Low-complexity vulnerabilities—those that are the easiest to exploit— accounted for 55.3 percent of all disclosures in 2H11. A total of 987 Low- complexity vulnerabilities were disclosed in 2H11, an increase from 945 in 1H11 but less than the 1,005 disclosed in 2H10. . Medium-complexity vulnerabilities amounted for 40.4 percent of disclosures in 2H11. Disclosures of Medium-complexity vulnerabilities have decreased significantly over the past year, from 1,121 in 2H10 to 721 in 2H11. . High-complexity vulnerability disclosures declined slightly to 76 in 2H11, a decrease from 118 in 1H11. Disclosures of High-complexity vulnerabilities have been stable or slightly increasing over the past several years, but still only account for 4.3 percent of all vulnerabilities disclosed in 2H11.

Operating system, browser, and application vulnerabilities

Figure 12 shows industry-wide vulnerabilities for operating systems, browsers, and applications since 1H09. (See Operating System, Browser, and Application Vulnerabilities at the Microsoft Security Intelligence Report website for an

footer left page.jpg 05001,0001,5002,0002,5003,0001H092H091H102H101H112H11Industry- wide vulnerability disclosuresApplicationvulnerabilitiesBrowservulnerabilitiesOperating systemvulnerabilities explanation of how operating system, browser, and application vulnerabilities are distinguished.)

Figure 12. Industry-wide operating system, browser, and application vulnerabilities, 1H09–2H11

 

. Disclosures of application vulnerabilities increased 17.8 percent in 2H11, halting a trend of declining disclosures that extends back several periods. In all, applications accounted for 71.2 percent of all vulnerability disclosures in 2H11. . Operating system vulnerability disclosures decreased 34.7 percent in 2H11, and ranked below browser vulnerability disclosures for the first time since at least 2003. . Disclosures of vulnerabilities in web browsers increased 8.6 percent in 2H11, continuing a trend of small increases over each of the last several periods.

Microsoft vulnerability disclosures

Figure 13 charts vulnerability disclosures for Microsoft and non-Microsoft products since 1H09.

footer-right-page.jpg 05001,0001,5002,0002,5001H092H091H102H101H112H11Vulnerability disclosuresNon-MicrosoftMicrosoft Figure 13. Vulnerability disclosures for Microsoft and non-Microsoft products, 1H09–2H11

 

. Vulnerabilities in Microsoft products accounted for 6.4 percent of all vulnerabilities disclosed in 2H11, a decrease from 6.8 percent in 1H11. . Vulnerability disclosures for Microsoft products have generally remained stable over the past three years, though Microsoft’s percentage of all disclosures industry-wide has increased slightly, primarily because of the overall decline in vulnerability disclosures across the industry.

Guidance: Developing secure software

The Security Development Lifecycle (www.microsoft.com/sdl) is a software development methodology that incorporates security and privacy best practices throughout all phases of the development process with the goal of protecting software users. Using such a methodology can help reduce vulnerabilities in the software and help manage vulnerabilities that might be found after deployment. (For more in-depth information about the SDL and other techniques developers can use to secure their software, see Protecting Your Software in the “Managing Risk” section of the Microsoft Security Intelligence Report website.)

footer left page.jpg Exploits

An exploit is malicious code that takes advantage of software vulnerabilities to infect, disrupt, or take control of a computer without the user’s consent and usually without the user’s knowledge. Exploits target vulnerabilities in operating systems, web browsers, applications, or software components that are installed on the computer. In some scenarios, targeted components are add-ons that are pre- installed by the computer manufacturer before the computer is sold. A user may not even use the vulnerable add-on or be aware that it is installed. Some software has no facility for updating itself, so even if the software vendor publishes an update that fixes the vulnerability, the user may not know that the update is available or how to obtain it, and therefore remains vulnerable to attack.

Software vulnerabilities are enumerated and documented in the Common Vulnerabilities and Exposures (CVE) list (cve.mitre.org), a standardized repository of vulnerability information. Here and throughout this report, exploits are labeled with the CVE identifier that pertains to the affected vulnerability, if applicable. In addition, exploits that affect vulnerabilities in Microsoft software are labeled with the Microsoft Security Bulletin number that pertains to the vulnerability, if applicable.23

23 See www.microsoft.com/technet/security/Current.aspx to search and read Microsoft Security Bulletins.

24 In previous volumes of the Microsoft Security Intelligence Report, individual attack counts, rather than unique computers, were often used to report exploit data. Comparison of the exploit figures in this volume with corresponding figures in previous volumes is not appropriate.

Figure 14 shows the prevalence of different types of exploits detected by Microsoft antimalware products each quarter in 2011, by number of unique computers affected.24 (See “Appendix B: Data sources” on page 107 for more information about the products and services that provided data for this report.)

footer-right-page.jpg 0500,0001,000,0001,500,0002,000,0002,500,0003,000,0003,500,0004,000,0004,500,0001Q112Q113Q114Q11Unique computers with detectionsAdobeFlash (SWF) HTML/JavaScriptJavaDocumentsOperatingSystemShellcodeand HeapsprayOther Figure 14. Unique computers reporting exploits each quarter in 2011, by targeted platform or technology

 

. The number of computers reporting exploits delivered through HTML or JavaScript increased steeply in the second half of 2011, due primarily to the emergence of JS/Blacole, a family of exploits used by the so-called “Blackhole” exploit kit to deliver malicious software through infected web pages. Prospective attackers buy or rent the Blacole kit on hacker forums and through other illegitimate outlets. It consists of a collection of malicious web pages that contain exploits for vulnerabilities in versions of Adobe Flash Player, Adobe Reader, Microsoft Data Access Components (MDAC), the Oracle Java Runtime Environment (JRE), and other popular products and components. When the attacker installs the Blacole kit on a malicious or compromised web server, visitors who don’t have the appropriate security updates installed are at risk of infection through a drive-by download attack. (See page 100 for more information about drive-by download attacks.)

For more information about Blacole, see the following entries in the MMPC blog at blogs.technet.com/mmpc:

. Get gamed and rue the day (October 25, 2011) . Disorderly conduct: localized malware impersonates the police (December 19, 2011)

footer left page.jpg 0200,000400,000600,000800,0001,000,0001,200,0001,400,0001,600,0001,800,0001Q112Q113Q114Q11Unique computers with detectionsCVE-2010-0840CVE-2009-3867CVE-2009-3869CVE-2010-0094CVE-2010-0842CVE-2008-5353 . Plenty to complain about with faux BBB spam (January 12, 2012) . Java exploits, formerly the most commonly observed type of exploits, were relegated to second place in 3Q11 and 4Q11 because of the rise in HTML/JavaScript exploits; despite this, the number of computers reporting Java exploit detections remained at a high level during 3Q11 and 4Q11, and actually increased overall from the first half of the year. . Detections of exploits that target vulnerabilities in document readers and editors increased in 4Q11, making them the third most commonly detected type of exploit during the quarter, due primarily to a rise in exploits that target older versions of Adobe Reader.

Java Exploits

Figure 15 shows the prevalence of different Java exploits by quarter.

Figure 15. Unique computers reporting Java exploits each quarter in 2011

 

. As in previous periods, many of the more commonly exploited Java vulnerabilities are several years old, as are the security updates that have been released to address them.

footer-right-page.jpg . The most commonly exploited Java vulnerability throughout 2011 was CVE- 2010-0840, a Java Runtime Environment (JRE) vulnerability first disclosed in March 2010 and addressed with an Oracle security update the same month. The CVE-201-0840 vulnerability is exploited by the JS/Blacole exploit kit andthe trojan downloader family Java/OpenConnection. . CVE-2010-0842, which saw significantly increased exploitation beginning in 4Q11, is also associated with the Blacole kit. . CVE-2008-5353, the third most commonly exploited Java vulnerability in 3Q11 and 4Q11, was first disclosed in December 2008. This vulnerability affects JVM version 5 up to and including update 22, and JVM version 6 up to and including update 10. It allows an unsigned Java applet to gain elevated privileges and potentially have unrestricted access to a host system, outside its “sandbox” environment. Sun Microsystems released a security update that addressed the vulnerability on December 3, 2008. . CVE-2010-0094 was the second most commonly exploited Java vulnerability in 2Q11, but declined to fourth by 4Q11. This vulnerability was first disclosed in December 2009, and affects JRE versions up to and including update 18 of version 6. CVE-2010-0094 allows an unsigned Java applet to gain elevated privileges and potentially have unrestricted access to a host system, outside its sandbox environment. Oracle released a security update that addressed the vulnerability in March 2010.

HTML and JavaScript exploits

Figure 16 shows the prevalence of different types of HTML and JavaScript exploits during each of the four most recent quarters.

footer left page.jpg 0500,0001,000,0001,500,0002,000,0002,500,0003,000,0003,500,0001Q112Q113Q114Q11Unique computers with detectionsJavaScript-multiplecomponentsMaliciousIFrameInternet ExplorerActiveXOther Figure 16. Types of HTML and JavaScript exploits detected and blocked by Microsoft antimalware products each quarter in 2011

 

. The use of malicious JavaScript code designed to exploit one or more web- enabled technologies increased significantly in the second half of 2011, due primarily because of JS/Blacole.A, a malicious script that attempts to load a number of exploits associated with the Blacole exploit kit. . Exploits that involve malicious HTML inline frames (IFrames) increased in the second half of 2011, although detections in 4Q11 were down from 3Q11. These exploits are typically generic detections of inline frames that are embedded in web pages and link to other pages that host malicious web content. These malicious pages use a variety of techniques to exploit vulnerabilities in browsers and plugins; the only commonality is that the exploit can be delivered through an inline frame. The exact exploit delivered and detected by one of these signatures may be changed frequently. . Detections for specific Windows® Internet Explorer® exploits declined slowly throughout 2011. . ActiveX® and other types of browser exploitation remain comparatively low.

footer-right-page.jpg 0100,000200,000300,000400,000500,000600,000700,000800,000900,0001,000,0001Q112Q113Q114Q11Unique computers with detectionsAdobeReaderMicrosoftOfficeJustSystemsIchitaro Document parser exploits

Document parser exploits are exploits that target vulnerabilities in the way a document editing or viewing application processes, or parses, a particular file format. Figure 17 shows the prevalence of different types of document parser exploits during each of the four most recent quarters.

Figure 17. Types of document parser exploits detected and blocked by Microsoft antimalware products each quarter in 2011

 

. Exploits that affect Adobe Reader and Adobe Acrobat accounted for most document format exploits detected throughout the last four quarters. Most of these exploits were detected as variants of the generic exploit family Win32/Pdfjsc. As with many of the exploits discussed in this section, Pdfjsc variants are known to be associated with the JS/Blacole exploit kit. In most cases, the vulnerabilities targeted by these exploits had been addressed with security updates or new product versions several months or years earlier. . Exploits that affect Microsoft Office and Ichitaro, a Japanese-language word processing application published by JustSystems, accounted for a small percentage of exploits detected during the period.

footer left page.jpg 0100,000200,000300,000400,000500,000600,000700,000800,000900,0001Q112Q113Q114Q11Unique computers with detectionsMicrosoftWindowsOtherAndroid Operating system exploits

Although most operating system exploits detected by Microsoft security products are designed to affect the platforms on which the security products run, computer users sometimes download malicious or infected files that affect other operating systems. Figure 18 shows the prevalence of different exploits against operating system vulnerabilities that were detected and removed by Microsoft antimalware products during each of the past four quarters.

Figure 18. Exploits against operating system vulnerabilities detected and blocked by Microsoft antimalware products each quarter in 2011

 

 

. Exploits that target Windows increased throughout 2011, almost entirely because of an increase in detections of exploit attempts that target CVE-2010- 2568, a vulnerability in Windows Shell addressed by Microsoft Security Bulletin MS10-046. See Figure 19 on page 49 for more information about these exploits. Exploits that affect the Android mobile operating system published by Google and the Open Handset Alliance were detected in significant volume throughout 2011. Microsoft security products detect these threats when Android users download infected or malicious programs to their computers before transferring the software to their devices. The increase in

footer-right-page.jpg 0100,000200,000300,000400,000500,000600,000700,0001Q112Q113Q114Q11Unique computers with detectionsCVE-2010-2568 (MS10-046) CVE-2010-1885(MS10-042) OtherUnix/Lotoor Android-based threats has been driven primarily by Unix/Lotoor, a detection for programs that attempt to exploit certain vulnerabilities in order to gain root access to the device. Lotoor is dropped by the trojan family AndroidOS/DroidDream, which often masquerades as a legitimate Android application. Google published a security update in March 2011 that addressed the vulnerability.

For another perspective on these exploits and others, Figure 19 shows trends for the individual exploits most commonly detected and blocked or removed in 2011.

Figure 19. Individual operating system exploits detected and blocked by Microsoft antimalware products each quarter in 2011, by number of unique computers exposed to the exploit

 

. Exploits that target CVE-2010-2568, a vulnerability in Windows Shell, increased significantly throughout 2011, and were responsible for nearly the entire increase in Windows exploit detections seen throughout the year. Microsoft issued Security Bulletin MS10-046 in August 2010 to address the vulnerability.

An attacker exploits CVE-2010-2568 by creating a malformed shortcut file that forces a vulnerable computer to load a malicious file when the shortcut icon is displayed in Windows Explorer. The vulnerability was first discovered being used by the malware family Win32/Stuxnet in mid-2010, and it has

footer left page.jpg 0% 5% 10% 15% 20% 25% 30% 35% 40% JanFebMarAprMayJunJulAugSepOctNovDecPercent of all families found with CVE- 2010- 2568Win32/RamnitWin32/AutorunWin32/SalityWin32/RorpianWin32/Stuxnet since been exploited by a number of other families, many of which predated the disclosure of the vulnerability and were subsequently adapted to attempt to exploit it.

Figure 20. Families commonly found with CVE-2010-2568 in 2011

 

. Exploits targeting CVE-2010-1885, a vulnerability that affects the Windows Help and Support Center in Windows XP and Windows Server 2003, declined to a low level in 1Q11 after dominating for much of 2010, then increased gradually throughout 2011. Microsoft issued Security Bulletin MS10-042 in July 2010 to address the issue.

Adobe Flash Player exploits

Figure 21 shows the prevalence of different Adobe Flash Player exploits by quarter.

footer-right-page.jpg 050,000100,000150,000200,000250,000300,0001Q112Q113Q114Q11Unique computers with detectionsCVE-2010-2884CVE-2011-0611CVE-2007-0071CVE-2010-1297OtherCVE-2011-2110 Figure 21. Adobe Flash Player exploits detected and blocked by Microsoft antimalware products each quarter in 2011, by number of unique computers exposed to the exploit

 

. Exploitation of Adobe Flash Player vulnerabilities increased significantly between 1Q11 and 3Q11, which can be attributed to two zero-day vulnerabilities discovered in the second quarter, CVE-2011-0611 and CVE- 2011-2110. Detections of both exploits decreased in 4Q11, while detections of exploits targeting an older vulnerability, CVE-2010-2884, increased. . CVE-2011-0611 was discovered in April 2011 when it was observed being exploited in the wild, typically in the form of malicious .zip files attached to spam email messages that purported to contain information about the Fukushima Daiichi nuclear disaster in Japan. Adobe released Security Bulletin APSB11-07 on April 15 and Security Bulletin APSB11-08 on April 21 to address the issue. On the same day the security update was released, attacks that targeted the vulnerability skyrocketed and remained high for several days, most of which were detected on computers in Korea. About a month later, a second increase in attacks was observed, affecting multiple locations. After peaking in 3Q11, detections of CVE-2011-0611 exploits declined to negligible levels in the fourth quarter. . CVE-2011-2110 was discovered in June 2011, and Adobe released Security Bulletin APSB11-18 on June 15 to address the issue. As with CVE-2011-0611,

footer left page.jpg attacks that targeted the vulnerability spiked after the security update was released, again with most of the targeted computers located in Korea. CVE- 2011-2110 is also exploited by the JS/Blacole exploit kit, which explains its continued prevalence in 2011. . CVE-2010-2884 was discovered in the wild in September 2010 as a zero-day vulnerability, and Adobe released Security Bulletin APSB10-22 on September 20 to address the issue. As with CVE-2011-0611 and CVE-2011-2110, significant exploitation of the vulnerability began in 2Q11, which suggests that exploit kits may be responsible for the increase.

Exploit effectiveness with the Enhanced Mitigation Experience Toolkit

Recent versions of Windows, including Windows Vista® and Windows 7, include security enhancements that make vulnerabilities significantly harder to exploit than in older releases. Similarly, recent releases of many popular software programs offer security features that make those releases much less vulnerable to successful exploitation. Microsoft recommends using the most recent versions of Windows and applications when practical, to take advantage of the built-in security functionality they offer.25

25 For more information about some of the security features in Windows and other Microsoft products, see “Mitigating Software Vulnerabilities,” available from the Microsoft Download Center.

In some cases, though, individuals and organizations cannot deploy recent software versions for a variety of reasons, or want to take advantage of modern security improvements in advance of a planned upgrade. For these customers, as well as for users of the latest software versions who want to take advantage of additional security improvements, Microsoft offers the Enhanced Mitigation Experience Toolkit (EMET) at no charge from the Microsoft Download Center (www.microsoft.com/download).

EMET provides system administrators with the ability to deploy security mitigation technologies such as Address Space Layout Randomization (ASLR), Data Execution Prevention (DEP), Structured Exception Handler Overwrite Protection (SEHOP), and others to selected installed applications. These technologies function as special protections and obstacles that an exploit author must defeat to exploit software vulnerabilities. These security mitigation technologies do not guarantee that vulnerabilities cannot be exploited. However,

footer-right-page.jpg they make exploitation more difficult. EMET 2.1 is compatible with supported versions of Windows XP, Windows Vista, Windows 7, Windows Server® 2003, Windows Server 2008, and Windows Server 2008 R2.

Figure 22. The Enhanced Mitigation Experience Toolkit (EMET), version 2.1

 

To assess the effectiveness of EMET in addressing a number of commonly exploited vulnerabilities, Microsoft researchers collected a sample of 184 application exploits that had been sent to Microsoft from customers worldwide. All exploits targeted vulnerabilities in popular applications running on one or more versions of Windows. The researchers tested each exploit against Windows XP SP3 in an out-of-the-box configuration, Windows XP SP3 with EMET deployed, and the release-to-manufacturing (RTM) version of Windows 7 in an out-of-the-box configuration. Figure 23 shows the results of these tests.

footer left page.jpg 1812110020406080100120140160180200Windows XP SP3Windows XP SP3 + EMETWindows 7 RTMSuccessful exploits Figure 23. The effectiveness of 184 exploits for popular applications on Windows XP, Windows XP with EMET deployed, and Windows 7

 

. By a large margin, the highest success rates for the exploits tested involved Windows XP without EMET installed. All but three of the 184 exploits tested succeeded on Windows XP in this configuration. . Deploying EMET drastically reduces the effectiveness of exploits on Windows XP. Only 21 of 184 exploits succeeded on Windows XP with EMET deployed. . Ten of the 184 exploits tested succeeded on Windows 7 RTM.

It should be recognized that the results of an exercise such as this one are influenced by the specific exploits being actively used in the wild at the time the exercise is conducted. Nevertheless, the data suggests that system administrators can significantly reduce their attack surface now by upgrading to the latest versions of their operating system and application software by deploying EMET, or both.

 

footer-right-page.jpg Malware and potentially unwanted software

Except where specified, the information in this section was compiled from telemetry data that was generated from more than 600 million computers worldwide and some of the busiest services on the Internet. (See “Appendix B: Data sources” on page 107 for more information about the telemetry used in this report.)

Global infection rates

The telemetry data generated by Microsoft security products from administrators or users who choose to opt in to data collection includes information about the location of the computer, as determined by IP geolocation. This data makes it possible to compare infection rates, patterns, and trends in different locations around the world.26

26 For more information about this process, see the entry “Determining the Geolocation of Systems Infected with Malware” (November 15, 2011) on the Microsoft Security Blog (blogs.technet.com/security).

footer left page.jpg Figure 24. The locations with the most computers reporting detections and removals by Microsoft desktop antimalware products in 2H11

 

Country/Region

3Q11

4Q11

Chg. 3Q to 4Q

1

United States

10,293,718

10,122,222

-1.7% .

2

Brazil

3,969,106

3,810,308

-4.0% .

3

Russia

1,808,380

2,323,182

28.5% .

4

France

2,254,527

2,053,267

-8.9% .

5

Germany

1,477,340

1,926,096

30.4% .

6

China

2,179,211

1,814,082

-16.8% .

7

Korea

1,684,479

1,741,551

3.4% .

8

Turkey

1,359,815

1,591,529

17.0% .

9

United Kingdom

1,669,737

1,568,287

-6.1% .

10

Italy

1,206,092

1,382,590

14.6% .

 

 

. In absolute terms, the locations with the most computers reporting detections tend to be ones with large populations and large numbers of computers. . Detections in Germany increased 30.4 percent from 3Q11 to 4Q11, primarily because of significantly increased detections of Win32/EyeStye, a family of trojans that attempt to steal sensitive data and send it to an attacker. Detection signatures for EyeStye were added to the MSRT in October 2011; within the first 10 days thereafter, more than half of the EyeStye infections detected and removed by the MSRT were in Germany. Germany also saw increased detections of the exploit family JS/Blacole and the generic detection Win32/Keygen. . Detections in Russia increased 28.5 percent from 3Q11 to 4Q11. Families contributing to the increase include Win32/Pameseg, a potentially unwanted software program with a Russian language user interface; Win32/Vundo, a family of trojans that display out-of-context advertisements; and the Blacole exploit family. . Detections in Turkey increased 17.0 percent from 3Q11 to 4Q11, driven by small increases in a number of widespread families, including Keygen, JS/Pornpop, Win32/Sality, and Win32/Autorun. . Detections in Italy increased 14.6 percent from 3Q11 to 4Q11, with increases in EyeStye, Keygen, and Win32/Zbot.

footer-right-page.jpg . Detections in France decreased 8.9 percent from 3Q11 to 4Q11, primarily because of fewer detections of a number of adware and adware-related families, including Win32/ClickPotato, Win32/Hotbar, Win32/Zwangi, Win32/ShopperReports, Win32/OfferBox, and Win32/OpenCandy. . Detections in China decreased 16.8 percent from 3Q11 to 4Q11. This decrease follows a 15.7 percent increase from 2Q11 to 3Q11, driven by a large increase in detections of the adware family Win32/Rugo. Detections of Rugo then dropped in the fourth quarter, explaining much of the overall decrease.

For a different perspective on infection patterns worldwide, Figure 25 shows the infection rates in locations around the world in computers cleaned per mille (CCM), which represents the number of reported computers cleaned for every 1,000 executions of the Microsoft Malicious Software Removal Tool (MSRT). (See the Microsoft Security Intelligence Report website for more information about the CCM metric.)

footer left page.jpg Figure 25. Infection rates by country/region in 3Q11 (top) and 4Q11 (bottom), by CCM

 

 

Detections and removals in individual countries/regions can vary significantly from quarter to quarter. Increases in the number of computers with detections can be caused not only by increased prevalence of malware in that location, but also by improvements in the ability of Microsoft antimalware solutions to detect malware. Large numbers of new antimalware product or tool installations in a location also typically increase the number of computers cleaned in that location.

footer-right-page.jpg 0.05.010.015.020.025.030.035.01Q112Q113Q114Q11Computers cleaned per 1,000 scanned (CCM)PalestinianAuthorityPakistanTurkeyAlbaniaEgyptWorldwide The next three figures illustrate infection rate trends for specific locations around the world, relative to the trends for all locations with at least 100,000 MSRT executions each quarter in 2H11.

Figure 26. Trends for the five locations with the highest infection rates in 4Q11, by CCM (100,000 MSRT executions minimum)

 

footer left page.jpg 0.01.02.03.04.05.06.07.08.09.010.01Q112Q113Q114Q11Computers cleaned per 1,000 scanned (CCM) WorldwideNorwayDenmarkFinlandJapanChina Figure 27. Trends for the five locations with the lowest infection rates in 4Q11, by CCM (100,000 MSRT executions minimum)

 

. The five locations with the highest infection rates in 4Q11 each had a CCM between 22.7 and 32.9, compared to a worldwide 4Q11 CCM of 7.1. Pakistan, the Palestinian territories, and Turkey were also among the five most infected locations in 2Q11, while Albania and Egypt are new to the top five. . Pakistan has seen significant increases in a pair of file infectors, Win32/Ramnit and Win32/Sality. Ramnit detections in Pakistan increased by more than 900 percent between 1Q11 and 4Q11, while detections of Sality more than doubled. . Albania and Egypt also saw an increase in Sality detections, along with increases in a number of worms, notably Win32/Rimecud, Win32/Autorun, Win32/Helompy, and Win32/Conficker. Detections of Win32/Dorkbot also increased significantly in Albania during the second half of the year. . Four of the five locations with the lowest infection rates in 4Q11 were also on the list in 2Q11, with Denmark taking the place of Sweden. All five had 4Q11 infection rates between 1.3 and 2.3, compared to the worldwide average of 7.1.

footer-right-page.jpg 0.010.020.030.040.050.060.070.01Q112Q113Q114Q11Computers cleaned per 1,000 scanned (CCM) QatarTrinidadand TobagoKoreaMexicoTaiwanWorldwide . Historically, Nordic countries such as Denmark, Norway, and Finland have typically had some of the lowest infection rates in the world. Japan also usually experiences a low infection rate. . Although China is one of the locations with the lowest infection rates worldwide as measured by CCM, a number of factors that are unique to China are important to consider when assessing the state of computer security there. The malware ecosystem in China is dominated by a number of Chinese-language threats that are not prevalent anywhere else. The CCM figures are calculated based on telemetry data from the MSRT, which tends to target malware families that are prevalent globally. As a result, many of the more prevalent threats in China are not represented in the data used to calculate CCM. For a more in-depth perspective on the threat landscape in China, see the “Regional Threat Assessment” section of the Microsoft Security Intelligence Report website.

Figure 28. Trends for five locations with significant infection rate improvements in 2H11, by CCM (100,000 MSRT executions minimum per quarter)

 

. Qatar exhibited the most dramatic improvement, from 61.5 in 1Q11 to 13.5 in 4Q11. Qatar as well as Trinidad and Tobago both have relatively few computers overall and are therefore prone to display large statistical variances of this sort from time to time. For Qatar, much of the reduction is the result of

footer left page.jpg steep declines in detections of the worm family Win32/Rimecud, which was responsible for the relatively high CCM in 1Q11. Trinidad and Tobago experienced a general decline in a number of prevalent adware families, including Win32/OpenCandy, Win32/ClickPotato, and Win32/ShopperReports. . Among populous countries and regions, Korea improved the most, going from 30.1 in 1Q11 to 11.1 in 4Q11. Significant decreases in detections of Rimecud, Win32/Frethog, and Win32/Parite were responsible for much of this improvement. . Mexico improved from 16.7 in 1Q11 to 8.8 in 4Q11, with significant declines in detections of OpenCandy, Rimecud, and JS/Pornpop. . Taiwan improved from 17.7 in 1Q11 to 8.2 in 4Q11, with significant declines in detections of Frethog, OpenCandy, Win32/Taterf, and Win32/Agent.

For a more in-depth perspective on the threat landscape in any of these locations, see the “Regional Threat Assessment” section of the Microsoft Security Intelligence Report website.

Operating system infection rates

The features and updates that are available with different versions of the Windows operating system, along with the differences in the way people and organizations use each version, affect the infection rates for the different versions and service packs. Figure 29 shows the infection rate for each currently supported Windows operating system/service pack combination that accounted for at least 0.1 percent of total MSRT executions in 4Q11.

footer-right-page.jpg 8.610.17.34.94.012.09.04.82.90.02.04.06.08.010.012.014.0SP3SP1*SP2RTMSP1Windows XPWindows VistaWindows 7Computers cleaned per 1,000 scanned (CCM) CLIENT3232323232646464644.73.3WindowsServer 2003SP2WindowsServer 2008R2 RTMSERVER3264 Figure 29. Infection rate (CCM) by operating system and service pack in 4Q11

 

“32” = 32-bit edition; “64” = 64-bit edition. SP = Service Pack. RTM = release to manufacturing. Operating systems with at least 0.1 percent of total executions in 4Q11 shown. *Service pack not supported in 4Q11.

. This data is normalized: the infection rate for each version of Windows is calculated by comparing an equal number of computers per version (for example, 1,000 Windows XP SP3 computers to 1,000 Windows 7 RTM computers). . As in previous periods, infection rates for more recently released operating systems and service packs tend to be lower than earlier ones, for both client and server platforms. Windows 7 SP1 and Windows Server 2008 R2, the most recently released Windows client and server versions, respectively, have the lowest infection rates on the chart. The exception is Windows XP SP3, which displayed a lower infection rate than the 32- and 64-bit editions of Windows Vista SP1 and the 64-bit edition of Windows Vista SP2. As the user base of Windows XP continues to decline in favor of newer versions of Windows, malware writers may be refocusing their efforts away from the older platform as well, which could be a factor in this discrepancy. . Infection rates for the 64-bit editions of Windows Vista and Windows 7 have increased since the first half of 2011. For the first time, infection rates for the 64-bit editions of Windows Vista SP1 and SP2 were higher than for the

footer left page.jpg 0.05.010.015.020.025.03Q104Q101Q112Q113Q114Q11Computers cleaned per 1,000 scanned (CCM) WindowsVista SP2WindowsXP SP3WindowsXP SP2WindowsVista SP1Windows7 RTMWindows7 SP1 corresponding 32-bit versions of those platforms in 2H11, and infection rates for both the 32- and 64-bit editions of Windows 7 RTM were almost identical. This data may indicate the increasing acceptance of 64-bit platforms by mainstream users. In the past, 64-bit computing tended to appeal to a more technically savvy audience than the mainstream, and the infection rates for 64-bit platforms were typically much lower than for their 32-bit counterparts, perhaps because 64-bit users tended to follow safer practices and keep their computers more up-to-date than the average user. Over the past several years, 64-bit computing has become more mainstream, and the infection rates for 64-bit platforms have increased at the same time. Malware authors may also be targeting 64-bit platforms more as they become more popular, which could affect infection rates.

Figure 30. Infection rate trends for currently and recently supported 32-bit version of Windows XP, Windows Vista, and Windows 7, 3Q10–4Q11

 

. This chart shows infection rates for supported versions of Windows only. Support for Windows XP SP2 was retired on July 13, 2010. Support for Windows Vista SP1 was retired on July 12, 2011. . Infection rates for all of the supported 32-bit versions of Windows increased slightly during the second half of the year except for Windows XP, for which the infection rate decreased slightly. Microsoft added signatures for a number

footer-right-page.jpg of prevalent malware families to the MSRT in 2H11, including Win32/Tracur (July 2011), Win32/Bamital (September 2011), and Win32/EyeStye (October 2011). Detections of these families increased significantly on all of the supported platforms after MSRT coverage was added, which contributed to the higher infection rates seen in 3Q11 and 4Q11. On Windows XP, however, the increase was offset by decreased detections of families that abuse the Autorun feature in Windows, following the February 2011 release of a security update that changed the way Autorun works on Windows XP and Windows Vista to match its functionality in Windows 7. (For more information about this change, see “Defending Against Autorun Attacks” (June 27, 2011) on the Microsoft Security Blog at blogs.technet.com/security.) . Windows 7 RTM and SP1 have consistently shown lower infection rates than other platforms since their introduction, although increased detections of EyeStye, Bamital, Tracur, and a few other families have contributed to a rise in the infection rate on Windows 7 computers, as with other platforms.

Threat categories

The Microsoft Malware Protection Center (MMPC) classifies individual threats into types based on a number of factors, including how the threat spreads and what it is designed to do. To simplify the presentation of this information and make it easier to understand, the Microsoft Security Intelligence Report groups these types into 10 categories based on similarities in function and purpose.

footer left page.jpg 0% 5% 10% 15% 20% 25% 30% 35% 40% 45% 1Q112Q113Q114Q11Percent of computers reporting detectionsMisc.TrojansPasswordStealers & Monitoring ToolsMisc.Potentially Unwanted SoftwareAdwareWormsExploitsTrojanDownloaders & DroppersVirusesSpywareBackdoors Figure 31. Detections by threat category each quarter in 2011, by percentage of all computers reporting detections

 

Round markers indicate malware categories; square markers indicate potentially unwanted software categories.

. Totals for each time period may exceed 100 percent because some computers report more than one category of threat in each time period. . Adware, the most commonly detected category during the first three quarters, fell to 3rd in 4Q11, continuing a year-long trend of decline. Decreased detections of several highly prevalent adware families, notably Win32/OpenCandy, Win32/ClickPotato, and Win32/ShopperReports, were chiefly responsible for the decline. (See “Threat families” on page 68 for more information.) . Miscellaneous Potentially Unwanted Software rose from 3rd in 1Q11 to 1st in 4Q11, led by the generic detection Win32/Keygen, a tool that generates keys for illegally obtained versions of various software products. . Exploits increased from 8.9 percent of computers with detections in 1Q11 to 15.3 percent in 4Q11, partially because of increased detections of exploits associated with the JS/Blacole exploit kit, a malicious JavaScript that loads a series of other exploits to deliver a payload. If a vulnerable computer browses a compromised website that contains the exploit kit, various malware may be downloaded and run.

footer-right-page.jpg Threat categories by location

There are significant differences in the types of threats that affect users in different parts of the world. The spread of malware and its effectiveness are highly dependent on language and cultural factors, in addition to the methods used for distribution. Some threats are spread using techniques that target people who speak a particular language or who use online services that are local to a specific geographic region. Other threats target vulnerabilities or operating system configurations and applications that are unequally distributed around the globe.

Figure 32 shows the relative prevalence of different categories of malware and potentially unwanted software in several locations around the world in 4Q11.

Figure 32. Threat category prevalence worldwide and in 10 individual locations in 4Q11

Category

World

US

Brazil

Russia

France

Germany

Chiuna

Korea

Turkey

UK

Italy

Adware

37.0%

30.9%

18.5%

5.4%

53.0%

18.8%

9.9%

57.5%

36.6%

32.3%

34.4%

Misc. Potentially Unwanted Software

30.6%

19.6%

36.4%

57.2%

28.4%

23.4%

48.3%

21.1%

33.9%

23.8%

31.2%

Misc. Trojans

28.9%

38.5%

25.3%

39.1%

16.8%

40.8%

29.5%

33.7%

27.8%

34.8%

25.7%

Worms

17.2%

5.7%

22.0%

17.2%

8.6%

7.2%

12.1%

10.4%

34.1%

6.2%

12.7%

Trojan Downloaders & Droppers

14.7%

20.8%

26.1%

14.3%

9.1%

9.4%

12.8%

17.2%

11.9%

13.2%

10.5%

Exploits

10.0%

26.3%

9.7%

17.4%

6.6%

16.7%

13.9%

13.9%

6.6%

23.1%

14.0%

Viruses

6.7%

2.3%

9.3%

6.4%

2.2%

2.0%

8.7%

4.5%

16.6%

5.3%

2.3%

Password Stealers & Monitoring Tools

6.3%

5.2%

20.4%

4.2%

3.8%

8.5%

4.4%

3.8%

6.1%

5.3%

11.0%

Backdoors

5.8%

6.3%

5.0%

4.3%

2.8%

4.3%

6.6%

2.9%

4.6%

4.0%

4.1%

Spyware

0.3%

0.3%

0.1%

0.3%

0.1%

0.2%

1.8%

0.2%

0.1%

0.2%

0.1%

 

Totals for each location may exceed 100 percent because some computers reported threats from more than one category.

footer left page.jpg . Within each row of Figure 32, a darker color indicates that the category is more prevalent in the specified location than in the others, and a lighter color indicates that the category is less prevalent. As in Figure 24 on page 56,the locations in the table are ordered by number of computers reporting detections in 2H11. . The United States and the United Kingdom, two predominantly English- speaking locations that also share a number of other cultural similarities, have similar threat mixes in most categories. . In Russia, the Miscellaneous Potentially Unwanted Software category is especially prevalent, led by Win32/Pameseg and Win32/Keygen. Pameseg is a family of installers that require the user to send a text message to a premium number to successfully install certain programs, some of which are otherwise available for free. Currently, most variants target Russian speakers. . Brazil has long had higher-than-average detections of Password Stealers & Monitoring Tools because of the prevalence of malware that targets customers of Brazilian banks, especially Win32/Bancos and Win32/Banker. . Worms were especially prevalent in Turkey in 4Q11 due to Win32/Helompy, which was detected on more than five times as many computers in Turkey in 4Q11 as in any other individual location. Helompy is a worm that spreads via removable drives and attempts to capture and steal authentication details for a number of different websites or services, including Facebook and Gmail. The worm contacts a remote host to download arbitrary files and to upload stolen details.

See “Appendix C: Worldwide infection rates” on page 109 for more information about malware around the world.

Threat families

Figure 33 lists the top 10 malware and potentially unwanted software families that were detected on computers by Microsoft antimalware products in the second half of 2011.

footer-right-page.jpg 01,000,0002,000,0003,000,0004,000,0005,000,0006,000,0007,000,0008,000,0001Q112Q113Q114Q11Unique computers with detectionsWin32/ShopperReportsWin32/HotbarWin32/OpenCandyWin32/ZwangiWin32/ClickPotatoWin32/Keygen Figure 33. Quarterly trends for the top 10 malware and potentially unwanted software families detected by Microsoft antimalware products in 3Q11 and 4Q11, shaded according to relative prevalence

Family

Most Significant Category

1Q11

2Q11

3Q11

4Q11

Win32/Keygen

Misc. Potentially Unwanted Software

2,299,870

2,680,354

3,424,213

4,187,586

JS/Pornpop

Adware

4,706,968

4,330,510

3,944,489

3,906,625

Win32/Autorun

Worms

3,718,690

3,677,588

3,292,378

3,438,745

Win32/Hotbar

Adware

3,149,677

4,411,501

2,870,465

2,226,173

Win32/Sality

Viruses

1,502,172

1,686,745

1,728,966

1,951,118

Win32/Conficker

Worms

1,859,498

1,790,035

1,614,368

1,704,736

Win32/OpenCandy

Adware

6,797,012

3,652,658

2,166,625

1,676,753

Win32/Zwangi

Misc. Potentially Unwanted Software

2,785,111

2,586,630

2,207,208

1,388,938

Win32/ClickPotato

Adware

4,694,442

2,592,125

2,545,842

1,153,203

Win32/ShopperReports

Adware

3,348,949

2,902,430

1,886,696

662,632

 

 

For a different perspective on some of the changes that have taken place throughout the year, Figure 34 shows the detection trends for a number of families that increased or decreased significantly in 2011.

Figure 34. Detection trends for a number of notable families in 2011

 

footer left page.jpg . Win32/Keygen was the most commonly detected family in 4Q11, and one of only two families in the top 10 with more detections in the fourth quarter of the year than in the first. Keygen is a generic detection for tools that generate keys for illegally obtained versions of various software products. . JS/Pornpop, the second most commonly detected family in 4Q11, is a detection for specially crafted JavaScript-enabled objects that attempt to display pop-under advertisements in users’ web browsers. Initially, JS/Pornpop appeared exclusively on websites that contained adult content; however, it has since been observed to appear on websites that may contain no adult content whatsoever. First detected in August 2010, it grew quickly to become one of the most prevalent families in the world. . Keygen, Win32/Autorun, and Win32/Sality were the only families in the top ten with more detections in 4Q11 than in 3Q11. Sality is a family of polymorphic file infectors that target executable files with the extensions .scr or .exe. Win32/Autorun is a generic detection for worms that spread between mounted volumes using the Autorun feature of Windows. Recent changes to the feature in Windows XP and Windows Vista have made this technique less effective, but attackers continue to distribute malware that attempts to target it. . Detections of Win32/OpenCandy, the most commonly detected family in 1Q11, declined steeply thereafter; it ranked seventh in 4Q11. OpenCandy is an adware program that may be bundled with certain third-party software installation programs, for which detection was first added in February 2011. Some versions of the OpenCandy program send user-specific information without obtaining adequate user consent, and these versions are detected by Microsoft antimalware products. Detections have declined as third-party software developers have increased their use of versions that do not exhibit these behaviors. . Other families that declined in the second half of the year include the adware families Win32/Hotbar, Win32/ClickPotato, and Win32/ShopperReports, and the potentially unwanted software family Win32/Zwangi. Hotbar, ClickPotato, and ShopperReports are three related families that are often found together, and which display targeted advertisements to users based on browsing habits.

footer-right-page.jpg Rogue security software

Rogue security software has become one of the most common methods that attackers use to swindle money from victims. Rogue security software, also known as scareware, is software that appears to be beneficial from a security perspective but provides limited or no security, generates erroneous or misleading alerts, or attempts to lure users into participating in fraudulent transactions. These programs typically mimic the general look and feel of legitimate security software programs and claim to detect a large number of nonexistent threats while urging users to pay for the “full version” of the software to remove the threats. Attackers typically install rogue security software programs through exploits or other malware, or use social engineering to trick users into believing the programs are legitimate and useful. Some versions emulate the appearance of the Windows Security Center or unlawfully use trademarks and icons to misrepresent themselves. (See www.microsoft.com/security/resources/videos.aspx for an informative series of videos designed to educate a general audience about rogue security software.)

Figure 35. False branding used by a number of commonly detected rogue security software programs

 

Figure 36 shows detection trends for the most common rogue security software families detected in 2H11.

footer left page.jpg 0200,000400,000600,000800,0001,000,0001,200,0001,400,0001,600,0001,800,0002,000,0003Q104Q101Q112Q113Q114Q11Unique computers cleanedWin32/FakeSysdefWin32/FakeReanWin32/OnescanWin32/WinwebsecWin32/FakeSpypro Figure 36. Trends for the most common rogue security software families detected in 2H11, by quarter

 

. Detections of Win32/FakeRean decreased significantly after 2Q11, but it remained the most commonly detected rogue security software program during the third and fourth quarters of the year. FakeRean has been distributed with several different names. The user interface and some other details vary to reflect each variant’s individual branding. Current variants of FakeRean choose a name at random, from a number of possibilities determined by the operating system of the affected computer. Signatures for FakeRean were added to the MSRT in August 2009.

footer-right-page.jpg Figure 37. Typical Win32/FakeRean variants on Windows XP and Windows 7

 

For more information about FakeRean, see the following entries in the MMPC blog (blogs.technet.com/mmpc):

. Win32/FakeRean and MSRT (August 11, 2009) . Win32/FakeRean is 33 rogues in 1 (March 9, 2010) . When imitation isn’t a form of flattery (January 29, 2012) . Win32/FakeSysdef, the second most commonly detected rogue security software program in 4Q11, was first detected in late 2010, and signatures for the family were added to the MSRT in August 2011. Unlike most rogue security software families, FakeSysdef does not claim to detect malware infections. Instead, it masquerades as a performance utility that falsely claims to find numerous hardware and software errors such as bad hard disk sectors, disk fragmentation, registry errors, and memory problems. Like other rogue

footer left page.jpg security software families, it claims that the user must purchase additional software to fix the nonexistent problems.

Figure 38. Win32/FakeSysdef pretends to find computer problems and offers to fix them for a fee

 

Like FakeRean, FakeSysdef uses a large number of aliases, which are often tailored to the operating system version it is running on.

For more information about FakeSysdef, see the following entries in the MMPC blog (blogs.technet.com/mmpc):

. FakeSysdef: We can defragment that for you wholesale! / Diary of a scamware (December 1, 2010) . How to defang the Fake Defragmenter (March 19, 2011) . MSRT August ’11: FakeSysdef (August 10, 2011) . Detections of Win32/Onescan increased from the first half of the year to the second. Onescan is a Korean-language rogue security software distributed under a variety of names, brands, and logos. The installer selects the branding

footer-right-page.jpg randomly from a defined set, apparently without regard to the operating system version.

Figure 39. Win32/Onescan, a Korean-language rogue security software program

 

. Detections of Win32/Winwebsec declined significantly in 3Q11, although it remains one of the more widely detected rogue security software programs worldwide. Winwebsec has also been distributed under many names, with the user interface and other details varying to reflect each variant’s individual branding. These different distributions of the trojan use various installation methods, with filenames and system modifications that can differ from one variant to the next. The attackers behind Winwebsec are also believed to be responsible for MacOS_X/FakeMacdef, the highly publicized “Mac Defender” rogue security software program for Apple Mac OS X that first appeared in May 2011. Detections for Winwebsec were added to the MSRT in May 2009.

footer left page.jpg Home and enterprise threats

The usage patterns of home users and enterprise users tend to be very different. Enterprise users typically use computers to perform business functions while connected to a network, and may have limitations placed on their Internet and email usage. Home users are more likely to connect to the Internet directly or through a home router and to use their computers for entertainment purposes, such as playing games, watching videos, shopping, and communicating with friends. These different usage patterns mean that home users tend to be exposed to a different mix of computer threats than enterprise users.

The infection telemetry data produced by Microsoft antimalware products and tools includes information about whether the infected computer belongs to an Active Directory® Domain Services domain. Such domains are used almost exclusively in enterprise environments, and computers that do not belong to a domain are more likely to be used at home or in other non-enterprise contexts. Comparing the threats encountered by domain-joined computers and non- domain computers can provide insights into the different ways attackers target enterprise and home users and which threats are more likely to succeed in each environment.

Figure 40 and Figure 41 list the top 10 families detected on domain-joined and non-domain computers, respectively, in 4Q11.

footer-right-page.jpg 0% 2% 4% 6% 8% 10% 12% 14% 16% 18% 20% JS/PornpopJS/BlacoleJava/CVE-2010- 0840JS/BlacoleWin32/ RealVNCJS/RedirectorWin32/ ZbotWin32/ ConfickerWin32/ AutorunWin32/ DorkbotAdwareExploitsMisc. PotentiallyUnwanted SoftwareMisc. TrojansPasswordStealers & MonitoringToolsWormsPercent of all domain-joined computers cleaned1Q112Q113Q114Q11 Figure 40. Top 10 families detected on domain-joined computers in 4Q11, by percentage of domain-joined computers reporting detections

 

Family

Most Significant Category

1Q11

2Q11

3Q11

4Q11

1

Win32/Conficker

Worms

17.8%

15.8%

14.7%

13.5%

2

Win32/Autorun

Worms

11.7%

11.1%

9.3%

8.5%

3

JS/Blacole

Exploits

2.3%

6.4%

4

Win32/Keygen

Misc. Potentially Unwanted Software

2.9%

3.5%

4.6%

5.0%

5

Win32/Dorkbot

Worms

0.0%

0.6%

2.9%

3.7%

6

Win32/Zbot

Password Stealers & Monitoring Tools

1.8%

1.7%

2.2%

3.6%

7

Win32/RealVNC

Misc. Potentially Unwanted Software

4.5%

4.4%

4.1%

3.4%

8

JS/Redirector

Misc. Trojans

0.9%

0.9%

1.5%

3.3%

9

JS/Pornpop

Adware

4.4%

3.9%

3.5%

3.2%

10

Java/CVE-2010-0840

Exploits

3.3%

3.1%

4.1%

3.2%

 

 

 

footer left page.jpg 0% 2% 4% 6% 8% 10% 12% 14% 16% 18% JS/PornpopWin32/ HotbarWin32/ OpenCandyJS/BlacoleWin32/ KeygenWin32/ ObfuscatorASX/WimadWin32/ SalityWin32/ AutorunWin32/ DorkbotAdwareExploitsMisc. PotentiallyUnwantedSoftwareMisc. TrojansTrojanDown- loaders & DroppersVirusesWormsPercent of All non-domain computers cleaned1Q112Q113Q114Q11 Figure 41. Top 10 families detected on non-domain computers in 4Q11, by percentage of non-domain computers reporting detections

 

Family

Most Significant Category

1Q11

2Q11

3Q11

4Q11

1

Win32/Keygen

Misc. Potentially Unwanted Software

5.1%

5.9%

7.6%

9.0%

2

JS/Pornpop

Adware

10.6%

9.6%

8.8%

8.5%

3

Win32/Autorun

Worms

8.0%

7.8%

7.1%

7.2%

4

JS/Blacole

Exploits

0.0%

0.0%

2.3%

5.3%

5

Win32/Hotbar

Adware

6.9%

9.9%

6.5%

4.8%

6

Win32/Sality

Viruses

3.3%

3.7%

3.8%

4.2%

7

ASX/Wimad

Trojan Downloaders & Droppers

2.2%

1.9%

1.7%

4.0%

8

Win32/Dorkbot

Worms

0.0%

0.5%

2.4%

3.6%

9

Win32/OpenCandy

Adware

15.3%

8.0%

4.8%

3.6%

10

Win32/Obfuscator

Misc. Potentially Unwanted Software

3.2%

4.9%

3.4%

3.4%

 

 

 

. Five families are common to both lists, notably the generic families Win32/Keygen and Win32/Autorun and the exploit family JS/Blacole. . Other families that were prevalent on domain-joined computers during at least one quarter in 2011 included the worm family Win32/Rimecud, the generic detection Win32/Obfuscator, and the adware family

footer-right-page.jpg Win32/OpenCandy. Families that were prevalent on non-domain computers during at least one quarter included the potentially unwanted software family Win32/Zwangi and the adware family Win32/ClickPotato. . The worm family Win32/Dorkbot, ranked fifth on domain-joined computers and eighth on non-domain computers in 4Q11, affected both types of computers about equally during the third and fourth quarters. Dorkbot is an IRC-based botnet family with rootkit capability and password stealing functionality. For more information, see the entry “MSRT March 2012: Breaking bad” (March 13, 2012) on the MMPC blog at blogs.technet.com/mmpc. . Detections of worm family Win32/Conficker, the most commonly detected family on domain-joined computers during each quarter in 2011, declined slowly throughout the year. After being detected on 17.8 percent of domain- joined computers reporting detections in 1Q11, Conficker detections declined in each successive quarter, to a low of 13.5 percent in 4Q11. (See “How Conficker continues to propagate” on page 1 for more information.) Similarly, detections of the generic family Win32/Autorun decreased on domain-joined computers during each quarter in 2011. . Families that were significantly more prevalent on domain-joined computers include Conficker, the botnet family Win32/Zbot, and the potentially unwanted software program Win32/RealVNC. RealVNC is a program that enables a computer to be controlled remotely, similar to Remote Desktop Services. It has a number of legitimate uses, but attackers have also used it to gain control of users’ computers for malicious purposes. . Java/CVE-2010-0840, an exploit that targets a vulnerability in older versions of Oracle Java SE and Java for Business, was the tenth most commonly detected threat on domain-joined computers. See “Java Exploits” on page 44 for more information about this exploit. . Detections on non-domain computers have historically tended to be dominated by adware, but a decline in detections of a number of prevalent adware families has led to a more diverse mix of threat categories during the second half of the year. The adware families ClickPotato and Win32/ShopperReports are among the families that no longer appear on the top-10 list for non-domain computers. . Families that were significantly more prevalent on non-domain computers include the adware families JS/Pornpop and Win32/Hotbar and the generic detection ASX/Wimad. Wimad is a detection for malicious files in the Advanced Stream Redirector (ASX) format used by Windows Media® Player.

footer left page.jpg Guidance: Defending against malware

Effectively protecting users from malware requires an active effort on the part of organizations and individuals. For in-depth guidance, see Protecting Against Malicious and Potentially Unwanted Software in the “Mitigating Risk” section of the Microsoft Security Intelligence Report website.

footer-right-page.jpg Email threats

Most of the email messages sent over the Internet are unwanted. Not only does all this unwanted email tax recipients’ inboxes and the resources of email providers, but it also creates an environment in which emailed malware attacks and phishing attempts can proliferate. Email providers, social networks, and other online communities have made blocking spam, phishing, and other email threats a top priority.

Spam messages blocked

The information in this section of the Microsoft Security Intelligence Report is compiled from telemetry data provided by Microsoft Forefront® Online Protection for Exchange (FOPE), which provides spam, phishing, and malware filtering services for thousands of Microsoft enterprise customers that process tens of billions of messages each month.

footer left page.jpg 0510152025303540Jan-11Feb-11Mar-11Apr-11May-11Jun-11Jul-11Aug-11Sep-11Oct-11Nov-11Dec-11Spam messages blocked (in billions) Figure 42. Messages blocked by FOPE each month in 2011

 

. FOPE blocked 14.0 billion messages in December 2011, less than half of the amount blocked in January. The significant decline in blocked messages seen throughout 2011 is likely attributable to several factors, including the following: . Takedown actions waged against a number of high-volume botnets, including the Rustock botnet in March and the Kelihos botnet in September, seem to have had a significant impact on the ability of spammers to distribute their messages to wide audiences. (For more information about the Rustock takedown, see “Battling the Rustock Threat,” available from the Microsoft Download Center at www.microsoft.com/download.) . As filtering improvements and high-profile takedowns have made it more difficult for spammers to get their messages out, they have adapted their methods in a continual effort to stay one step ahead of spam fighters. Many spammers have shifted from botnet-based delivery to a method some call snowshoe spam, whereby spam is distributed in lower volumes from a wider range of IP addresses in an effort to avoid detection. Snowshoe spam is often sent from IP addresses that the spammers have leased legitimately from commercial Internet service providers (ISPs), and

footer-right-page.jpg can be difficult for automated blocks and filters to distinguish from legitimate bulk email, such as opt-in newsletters and mailing lists.27

65% 70% 75% 80% 85% 90% 95% 100% Jan-11Feb-11Mar-11Apr-11May-11Jun-11Jul-11Aug-11Sep-11Oct-11Nov-11Dec-11Percent of messages receivedEdge blockedContent filteredDelivered0% 27 See blogs.msdn.com/b/tzink/archive/2011/11/22/what-snoeshow-spam-looks-like.aspx for more information about snowshoe spam and related concepts.

FOPE performs spam filtering in two stages. Most spam is blocked by servers at the network edge, which use reputation filtering and other non-content-based rules to block spam or other unwanted messages. Messages that are not blocked at the first stage are scanned using content-based rules, which detect and filter many additional email threats, including attachments that contain malware.

Figure 43. Percentage of incoming messages blocked by FOPE using edge-blocking and content filtering in 2011

 

. Between 76 and 92 percent of incoming messages were blocked at the network edge each month, which means that only 8 to 24 percent of incoming messages had to be subjected to the more resource-intensive content filtering process. . The overall decline in spam blocked between January and December, shown in Figure 42, has disproportionately affected spam blocked at the network edge. Overall, the total volume of content-filtered spam decreased for most of the year, even as the share of content-filtered spam increased relative to edge- blocked spam. This trend reversed in October, as the total volume of content-

footer left page.jpg Pharmacy -Non-sexual46.5% Non-pharmacy Product Ads13.2% 419 Scams10.7% Gambling5.0% Financial4.8% Phishing4.1% Malware3.8% Dating/Sexually Explicit Material3.4% Pharmacy -Sexual3.2% Get Rich Quick2.2% Image Only1.5% Other1.6% filtered spam began to increase, possibly in response to the takedown of the Kelihos botnet in September and to the overall trend in favor of more snowshoe spam.

Spam types

The FOPE content filters recognize several different common types of spam messages. Figure 44 shows the relative prevalence of the spam types that were detected in 2H11.

Figure 44. Inbound messages blocked by FOPE filters in 2H11, by category

 

. Advertisements for pharmaceutical products accounted for almost half of the spam blocked by FOPE content filters in 2H11. The largest total category of spam by a wide margin involved nonsexual pharmaceutical products at 46.5 percent of the total, an increase from 28.0 percent in 1H11. Sexually related pharmaceutical advertisements accounted for 3.2 percent of the total, a decrease from 3.8 percent in 1H11.

footer-right-page.jpg . Advertisements for non-pharmaceutical products accounted for an additional 13.2 percent of messages blocked, a decrease from 17.2 percent in 1H11. . Spam messages associated with advance-fee fraud (so-called “419 scams”) accounted for 10.7 percent of messages blocked, a decrease from 13.2 percent in 1H11. An advance-fee fraud is a common confidence trick in which the sender of a message purports to have a claim on a large sum of money, but is unable to access it directly for some reason, typically involving bureaucratic red tape or political corruption. The sender asks the prospective victim for a temporary loan to be used for bribing officials or for paying fees to get the full sum released. In exchange, the sender promises the target a share of the fortune amounting to a much larger sum than the original loan, but does not deliver.

footer left page.jpg 0% 10% 20% 30% 40% 50% 60% JulyAugustSeptemberOctoberNovemberDecemberPercent of blocked messagesPharmacy- Non-sexual419ScamsNon-pharmacyProduct Ads(Seechart below) 0% 1% 2% 3% 4% 5% 6% 7% 8% JulyAugustSeptemberOctoberNovemberDecemberPercent of blocked messagesMalwareFraudulentDiplomasDating/SexuallyExplicit MaterialPhishingFinancialGamblingPharmacy-SexualStockImageOnlySoftwareGetRich Quick Figure 45. Inbound messages blocked by FOPE content filters each month in 2011, by category

 

 

. Advertisements for non-sexual pharmaceutical products accounted for 46.5 percent of the spam messages blocked by FOPE content filters in 2H11.

footer-right-page.jpg . Together, non-pharmaceutical product advertisements (13.2 percent) and advertisements for non-sexual pharmaceutical products accounted for the majority of the spam messages blocked by FOPE content filters in 2H11. Along with 419 scams (10.7 percent), these categories accounted for more than 70 percent of the spam messages that were blocked during the period. . In an effort to evade content filters, spammers sometimes send messages that consist only of one or more images, with no text in the body of the message. Image-only spam messages decreased to 1.5 percent of the total in 2H11 overall, from 3.1 percent in 1H11 and 8.7 percent in 2010. However, image- only spam increased from 0.8 percent in October to 2.1 percent in November and 2.9 percent in December, suggesting that the recent lull may have been temporary. . Other spam categories that showed significant month-to-month increases in 2H11 included gambling advertisements and financial spam, both of which displayed moderate spikes in November. In both cases, however, the magnitude of the increase was not significantly larger than the month-to- month fluctuations observed throughout the period.

Guidance: Defending against threats in email

In addition to using a filtering service such as FOPE, organizations can take a number of steps to reduce the risks and inconvenience of unwanted email. Such steps include implementing email authentication techniques and observing best practices for sending and receiving email. For in-depth guidance, see Guarding Against Email Threats in the “Managing Risk” section of the Microsoft Security Intelligence Report website.

footer left page.jpg Malicious websites

Attackers often use websites to conduct phishing attacks or distribute malware. Malicious websites typically appear completely legitimate and often provide no outward indicators of their malicious nature, even to experienced computer users. To help protect users from malicious webpages, Microsoft and other browser vendors have developed filters that keep track of sites that host malware and phishing attacks and display prominent warnings when users try to navigate to them.

The information in this section is compiled from a variety of internal and external sources, including telemetry data produced by SmartScreen® Filter (in Windows Internet Explorer 8 and 9), the Phishing Filter (in Internet Explorer 7), from a database of known active phishing and malware hosting sites reported by users of Internet Explorer and other Microsoft products and services, and from malware data provided by Microsoft antimalware technologies. (See “Appendix B: Data sources” on page 107 for more information about the products and services that provided data for this report.)

footer-right-page.jpg Figure 46. SmartScreen Filter in Internet Explorer 8 and 9 blocks reported phishing and malware distribution sites to protect the user

 

Phishing sites

Microsoft gathers information about phishing sites and impressions from phishing impressions generated by users who choose to enable the Phishing Filter or SmartScreen Filter in Internet Explorer. A phishing impression is a single instance of a user attempting to visit a known phishing site with Internet Explorer and being blocked, as illustrated in Figure 47.

footer left page.jpg Figure 47. How Microsoft tracks phishing impressions

 

Figure 48 compares the volume of active phishing sites in the Microsoft URL Reputation Service database each month with the volume of phishing impressions tracked by Internet Explorer.

footer-right-page.jpg 0% 50% 100% 150% 200% MarAprMayJunJulAugSepOctNovDecPercent of monthly averageImpressionsSites Figure 48. Phishing sites and impressions tracked each month from March to December 2011 relative to the monthly average for each

 

. Phishers often engage in discrete campaigns that are intended to drive more traffic to each phishing page, without necessarily increasing the total number of active phishing pages they maintain at the same time. A large spike in impressions was observed in September, when the number of impressions rose to more than twice the monthly average for the period, primarily because of a small number of very effective campaigns targeting social networks. At the same time, the number of active phishing sites tracked did not increase significantly. . Most phishing sites only last a few days, and attackers create new ones to replace older ones as they are taken offline, so the list of known phishing sites is prone to constant change without significantly affecting overall volume. This phenomenon can cause significant fluctuations in the number of active phishing sites being tracked, like the one seen between March and June.

Target institutions

Figure 49 and Figure 50 show the percentage of phishing impressions and active phishing sites, respectively, recorded by Microsoft during each month from August to December 2011 for the most frequently targeted types of institutions.

footer left page.jpg 0% 10% 20% 30% 40% 50% 60% AugustSeptemberOctoberNovemberDecemberPercent of phishing impressionsSocialNetworkingFinancialSitesOnlineServicesGamingE-Commerce 0% 10% 20% 30% 40% 50% 60% 70% 80% AugustSeptemberOctoberNovemberDecemberPercent of phishing sitesSocialNetworkingFinancialSitesOnlineServicesGamingE-Commerce Figure 49. Impressions for each type of phishing site each month from August to December 2011, as reported by SmartScreen Filter

 

Figure 50. Active phishing sites tracked each month from August to December 2011, by type of target

 

footer-right-page.jpg . Impressions by category tend to fluctuate more between successive months than do sites, because of the aforementioned campaign effect, in which phishers sometimes engage in short periods of intense activity designed to drive traffic to a small number of sites. . Phishing sites that targeted financial institutions accounted for an average of 70.4 percent of active phishing sites tracked from August to December 2011, although they accounted for just 34.8 percent of impressions. Financial institutions are relatively inefficient targets for phishers, because the number of possible institutions to target can number in the hundreds or more even within a relatively small population of Internet users. Nevertheless, the potential for direct illicit access to victims’ bank accounts make financial institutions a tempting target for many criminals, and they continue to receive the largest or second-largest number of impressions each month. . By contrast, the number of popular social networking sites is much smaller, so phishers who target social networks can effectively target many more people per site. Social networks accounted for just 6.1 percent of phishing sites between August and December 2011 on average, but garnered 43.7 percent of impressions. Much of this traffic was because of a period of increased phishing activity in September targeting social networks, as mentioned on page 91. . This phenomenon also occurs on a smaller scale with online services and gaming sites. A small number of online services account for most traffic to such sites, so phishing sites that targeted online services garnered 12.0 percent of impressions with just 6.0 percent of sites. Online gaming traffic tends to be spread out among a larger number of sites, so phishing sites that targeted online gaming destinations accounted for 12.5 percent of active sites but gained just 4.1 percent of impressions.

Global distribution of phishing sites

Phishing sites are hosted all over the world on free hosting sites, on compromised web servers, and in numerous other contexts. Performing geographic lookups of IP addresses in the database of reported phishing sites makes it possible to create maps that show the geographic distribution of sites and to analyze patterns.

footer left page.jpg Figure 51. Phishing sites per 1,000 Internet hosts for locations around the world in 3Q11 (top) and 4Q11 (bottom)

 

 

. Locations with smaller populations and fewer Internet hosts tend to have higher concentrations of phishing sites, although in absolute terms most phishing sites are located in large, industrialized countries/regions with large numbers of Internet hosts. . Significant locations with unusually high concentrations of phishing sites include Mongolia, with 5.6 phishing sites per 1,000 hosts in 4Q11; Iran, with 2.4; and Korea, with 0.6.

footer-right-page.jpg Malware hosting sites

SmartScreen Filter in Internet Explorer 8 and 9 helps provide protection against sites that are known to host malware, in addition to phishing sites. SmartScreen Filter uses URL reputation data and Microsoft antimalware technologies to determine whether those sites distribute unsafe content. As with phishing sites, Microsoft keeps track of how many people visit each malware hosting site and uses the information to improve SmartScreen Filter and to better combat malware distribution.

Figure 52. SmartScreen Filter in Internet Explorer 8 (top) and Internet Explorer 9 (bottom) displays a warning when a user attempts to download an unsafe file

 

 

Figure 53 compares the volume of active malware hosting sites in the Microsoft URL Reputation Service database each month with the volume of malware impressions tracked by Internet Explorer.

footer left page.jpg 0% 20% 40% 60% 80% 100% 120% 140% 160% MarAprMayJunJulAugSepOctNovDecPercent of monthly averageImpressionsSites Figure 53. Malware hosting sites and impressions tracked each month from March to December 2011, relative to the monthly average for each

 

. As with phishing, malware hosting impressions and active sites rarely correlate strongly with each other, and months with high numbers of sites and low numbers of impressions (or vice versa) are not uncommon.

Malware categories

Figure 54 and Figure 55 show the types of threats hosted at URLs that were blocked by SmartScreen Filter in 2H11.

footer-right-page.jpg Misc. Trojans43.4% Trojan Downloaders & Droppers28.4% Misc. Potentially Unwanted Software10.5% Exploits6.3% Password Stealers & Monitoring Tools5.5% Backdoors2.5% Worms1.5% Viruses1.2%Other0.8% Figure 54. Categories of malware found at sites blocked by SmartScreen Filter in 2H11, by percent of all malware impressions

 

footer left page.jpg Figure 55. Top families found at sites blocked by SmartScreen Filter in 2H11, by percent of all malware impressions

 

Family

Most Significant Category

Percent of Malware Impressions

1

Win32/Startpage

Misc. Trojans

15.7%

2

Win32/Swisyn

Trojan Downloaders & Droppers

10.4%

3

Win32/Banload

Trojan Downloaders & Droppers

5.8%

4

Win32/Dynamer

Misc. Trojans

5.1%

5

Win32/Obfuscator

Misc. Potentially Unwanted Software

4.5%

6

JS/ShellCode

Exploits

3.9%

7

Win32/Microjoin

Trojan Downloaders & Droppers

2.1%

8

Win32/Malf

Trojan Downloaders & Droppers

2.0%

9

Win32/VB

Worms

1.9%

10

Win32/Sisproc

Misc. Trojans

1.8%

11

Win32/Meredrop

Misc. Trojans

1.8%

12

Win32/Delf

Trojan Downloaders & Droppers

1.6%

13

Win32/Pdfjsc

Exploits

1.4%

14

Win32/Agent

Misc. Trojans

1.4%

15

Win32/BaiduSobar

Misc. Potentially Unwanted Software

1.4%

16

Win32/Bulilit

Trojan Downloaders & Droppers

1.3%

17

Win32/Sirefef

Misc. Trojans

1.3%

 

 

. Most of the families on the list are generic detections for a variety of threats that share certain identifiable characteristics. . Win32/Startpage, the family responsible for the most malware impressions in 2H11, is a generic detection for malware that changes the home page of an affected user’s web browser without consent. . Win32/Swisyn, in second place, is a family of trojans that drops and executes files on an infected computer. These files may be embedded as resource files, and are often bundled with legitimate files in an effort to evade detection.

Global distribution of malware hosting sites

Figure 56 shows the geographic distribution of malware hosting sites reported to Microsoft in 2H11.

footer-right-page.jpg Figure 56. Malware distribution sites per 1,000 Internet hosts for locations around the world in 3Q11 (top) and 4Q11 (bottom)

 

 

. As with phishing sites, locations with smaller populations and fewer Internet hosts tend to have higher concentrations of phishing sites, although in absolute terms most phishing sites are located in large, industrialized countries/regions with large numbers of Internet hosts.

footer left page.jpg Drive-by download sites

A drive-by download site is a website that hosts one or more exploits that target vulnerabilities in web browsers and browser add-ons. Users with vulnerable computers can be infected with malware simply by visiting such a website, even without attempting to download anything.

Search engines such as Bing have taken a number of measures to help protect users from drive-by downloads. Bing analyzes websites for exploits as they are indexed and displays warning messages when listings for drive-by download pages appear in the list of search results. (See Drive-By Download Sites at the Microsoft Security Intelligence Report website for more information about how drive- by downloads work and the steps Bing takes to protect users from them.)

Figure 57 shows the concentration of drive-by download pages in countries and regions throughout the world at the end of 3Q11 and 4Q11, respectively.

footer-right-page.jpg Figure 57. Drive-by download pages indexed by Bing.com at the end of 3Q11 (top) and 4Q11 (bottom), per 1000 URLs in each country/region

 

 

. Each map shows the concentration of drive-by download URLs tracked by Bing in each country or region on a reference date at the end of the associated quarter, expressed as the number of drive-by download URLs per every 1,000 URLs hosted in the country/region. This snapshot approach contrasts with the accumulative approach used to report drive-by downloads in previous volumes of the Microsoft Security Intelligence Report, which accounted for every drive-by URL detected at any point during the relevant period. This new

footer left page.jpg approach is intended to more accurately reflect the short-lived nature of most drive-by URLs; however, comparisons between the data presented here and data presented in previous volumes is not appropriate and should be avoided. . Significant locations with unusually high concentrations of drive-by download URLs in both quarters include Pakistan, with 5.8 drive-by URLs for every 1,000 URLs tracked by Bing at the end of 4Q11; Saudi Arabia, with 3.3; Romania, with 2.7; and Korea, with 2.1.

Guidance: Protecting users from unsafe websites

Organizations can best protect their users from malicious and compromised websites by mandating the use of web browsers with appropriate protection features built in and by promoting safe browsing practices. For in-depth guidance, see the following resources in the “Managing Risk” section of the Microsoft Security Intelligence Report website:

. Promoting Safe Browsing . Protecting Your People

 

footer-right-page.jpg Appendixes

 

 

footer left page.jpg

footer-right-page.jpg Appendix A: Threat naming conventions

The MMPC malware naming standard is derived from the Computer Antivirus Research Organization (CARO) Malware Naming Scheme, originally published in 1991 and revised in 2002. Most security vendors use naming conventions that are based on the CARO scheme, with minor variations, although family and variant names for the same threat can differ between vendors.

A threat name can contain some or all of the components seen in Figure 58.

Figure 58. The Microsoft malware naming convention

 

The type indicates the primary function or intent of the threat. The MMPC assigns each individual threat to one of a few dozen different types based on a number of factors, including how the threat spreads and what it is designed to do. To simplify the presentation of this information and make it easier to understand, the Microsoft Security Intelligence Report groups these types into 10 categories. For example, the TrojanDownloader and TrojanDropper types are combined into a single category, called Trojan Downloaders & Droppers.

The platform indicates the operating environment in which the threat is designed to run and spread. For most of the threats described in this report, the platform is listed as “Win32,” for the Win32 API used by 32-bit and 64-bit versions of Windows desktop and server operating systems. (Not all Win32 threats can run on every version of Windows, however.) Platforms can include programming languages and file formats, in addition to operating systems. For example, threats in the ASX/Wimad family are designed for programs that parse the Advanced Stream Redirector (ASX) file format, regardless of operating system.

footer left page.jpg Groups of closely related threats are organized into families, which are given unique names to distinguish them from others. The family name is usually not related to anything the malware author has chosen to call the threat. Researchers use a variety of techniques to name new families, such as excerpting and modifying strings of alphabetic characters found in the malware file. Security vendors usually try to adopt the name used by the first vendor to positively identify a new family, although sometimes different vendors use completely different names for the same threat, which can happen when two or more vendors discover a new family independently. The MMPC Encyclopedia (www.microsoft.com/mmpc) lists the names used by other major security vendors to identify each threat, when known.

Some malware families include multiple components that perform different tasks and are assigned different types. For example, the Win32/Frethog family includes variants designated PWS:Win32/Frethog.C and TrojanDownloader:Win32/Frethog.C, among others. In the Microsoft Security Intelligence Report, the category listed for a particular family is the one that Microsoft security analysts have determined to be the most significant category for the family (which, in the case of Frethog, is Password Stealers & Monitoring Tools).

Malware creators often release multiple variants for a family, typically in an effort to avoid being detected by security software. Variants are designated by letters, which are assigned in order of discovery—A through Z, then AA through AZ, then BA through BZ, and so on. A variant designation of “gen” indicates that the threat was detected by a generic signature for the family rather than as a specific variant. Any additional characters that appear after the variant provide comments or additional information.

In the Microsoft Security Intelligence Report, a threat name that consists of a platform and family name (for example, “Win32/Taterf”) is a reference to a family. When a longer threat name is given (for example, “Worm:Win32/Taterf.K!dll”), it is a reference to a more specific signature or to an individual variant. To make the report easier to read, family and variant names have occasionally been abbreviated in contexts where confusion is unlikely. Thus, Win32/Taterf would be referred to simply as “Taterf” on subsequent mention in some places, and Worm:Win32/Taterf.K simply as “Taterf.K.”

footer-right-page.jpg Appendix B: Data sources

Data included in the Microsoft Security Intelligence Report is gathered from a wide range of Microsoft products and services. The scale and scope of this telemetry data allows the report to deliver the most comprehensive and detailed perspective on the threat landscape available in the software industry:

. Bing, the search and decision engine from Microsoft, contains technology that performs billions of webpage scans per year to seek out malicious content. After such content is detected, Bing displays warnings to users about it to help prevent infection. . Windows Live Hotmail has hundreds of millions of active email users in more than 30 countries/regions around the world. . Forefront Online Protection for Exchange (FOPE) protects the networks of thousands of enterprise customers worldwide by helping to prevent malware from spreading through email. FOPE scans billions of email messages every year to identify and block spam and malware. . Microsoft Forefront Endpoint Protection is a unified product that provides protection from malware and potentially unwanted software for enterprise desktops, laptops, and server operating systems. It uses the Microsoft Malware Protection Engine and the Microsoft antivirus signature database to provide real-time, scheduled, and on-demand protection. . Windows Defender is a program that is available at no cost to licensed users of Windows that provides real-time protection against pop-ups, slow performance, and security threats caused by spyware and other potentially unwanted software. Windows Defender runs on more than 100 million computers worldwide. . The Malicious Software Removal Tool (MSRT) is a free tool that Microsoft designed to help identify and remove prevalent malware families from customer computers. The MSRT is primarily released as an important update through Windows Update, Microsoft Update, and Automatic Updates. A version of the tool is also available from the Microsoft Download Center. The MSRT was downloaded and executed more than 600 million times each

footer left page.jpg month on average in 2H11. The MSRT is not a replacement for an up-to-date antivirus solution because of its lack of real-time protection and because it uses only the portion of the Microsoft antivirus signature database that enables it to target specifically selected, prevalent malicious software. . Microsoft Security Essentials is a free real-time protection product that combines an antivirus and antispyware scanner with phishing and firewall protection. . The Microsoft Safety Scanner is a free downloadable security tool that provides on-demand scanning and helps remove malware and other malicious software. The Microsoft Safety Scanner is not a replacement for an up-to-date antivirus solution, because it does not offer real-time protection and cannot prevent a computer from becoming infected. . SmartScreen Filter, a feature in Internet Explorer 8 and 9, offers users protection against phishing sites and sites that host malware. Microsoft maintains a database of phishing and malware sites reported by users of Internet Explorer and other Microsoft products and services. When a user attempts to visit a site in the database with the filter enabled, Internet Explorer displays a warning and blocks navigation to the page.

Figure 59. US privacy statements for the Microsoft products and services used in this report

Product or Service

Privacy Statement URL

Bing

privacy.microsoft.com/en-us/bing.mspx

Windows Live Hotmail

privacy.microsoft.com/en-us/fullnotice.mspx

Forefront Online Protection for Exchange

https://admin.messaging.microsoft.com/legal/privacy/en-us.htm

Windows Defender

www.microsoft.com/windows/products/winfamily/ defender/privacypolicy.mspx

Malicious Software Removal Tool

www.microsoft.com/security/pc-security/msrt-privacy.aspx

Forefront Endpoint Protection

www.microsoft.com/download/en/details.aspx?id=23308

Microsoft Security Essentials

windows.microsoft.com/en-US/windows/products/security- essentials/privacy

Microsoft Safety Scanner

www.microsoft.com/security/scanner/en-us/Privacy.aspx

Windows Internet Explorer 9

windows.microsoft.com/en-US/internet-explorer/products/ ie-9/windows-internet-explorer-9-privacy-statement

 

 

footer-right-page.jpg Appendix C: Worldwide infection rates

“Global infection rates,” on page 55, explains how threat patterns differ significantly in different parts of the world. Figure 60 shows the infection rates in locations with at least 100,000 quarterly MSRT executions in 2011, as determined by geolocation of the IP address of the reporting computer. 28 CCM is the number of computers cleaned for every 1,000 executions of MSRT. See the Microsoft Security Intelligence Report website for more information about the CCM metric and how it is calculated.

28 For more information about this process, see the entry “Determining the Geolocation of Systems Infected with Malware” (November 15, 2011) on the Microsoft Security Blog (blogs.technet.com/security).

For a more in-depth perspective on the threat landscape in any of these locations, see the “Regional Threat Assessment” section of the Microsoft Security Intelligence Report website.

Figure 60. Infection rates (CCM) for locations around the world in 2011, by quarter

Country/Region

1Q11

2Q11

3Q11

4Q11

Albania

23.7

25.0

19.3

25.0

Algeria

20.8

16.2

14.2

17.3

Angola

21.4

20.1

18.6

16.1

Argentina

11.4

11.1

8.3

8.3

Armenia

9.2

8.0

6.9

6.8

Australia

5.3

4.6

5.3

4.6

Austria

4.6

3.4

3.9

8.4

Azerbaijan

11.4

10.6

10.3

11.7

Bahamas, The

17.4

14.3

12.0

10.6

Bahrain

16.5

19.2

18.0

15.6

Bangladesh

13.0

13.7

14.9

16.9

Barbados

7.5

6.4

5.4

4.6

 

footer left page.jpg Country/Region

1Q11

2Q11

3Q11

4Q11

Belarus

6.0

6.0

6.3

5.6

Belgium

6.4

5.6

6.1

4.7

Bolivia

13.3

14.3

13.9

13.0

Bosnia and Herzegovina

18.4

16.4

13.4

15.8

Brazil

19.2

18.8

17.2

14.0

Brunei

14.4

12.9

9.6

9.1

Bulgaria

13.9

10.7

8.3

9.0

Cambodia

9.2

12.0

12.4

11.5

Cameroon

15.3

11.3

11.3

12.8

Canada

4.4

5.2

5.8

4.3

Chile

15.4

10.8

7.9

13.9

China

2.4

2.3

1.5

1.0

Colombia

11.8

11.5

8.7

7.8

Costa Rica

11.8

8.9

6.4

5.8

Côte d’Ivoire

15.3

12.7

12.9

13.3

Croatia

14.5

10.9

8.1

10.0

Cyprus

15.1

10.9

9.6

8.0

Czech Republic

5.2

2.9

2.6

2.3

Denmark

2.6

3.0

2.2

2.0

Dominican Republic

18.9

16.7

14.8

14.0

Ecuador

14.2

11.2

9.0

8.6

Egypt

20.9

19.5

17.5

22.7

El Salvador

13.6

10.7

8.1

6.5

Estonia

6.6

4.9

4.8

4.0

Ethiopia

10.2

10.9

9.8

9.2

Finland

1.4

1.3

1.8

1.6

France

6.0

5.0

4.2

3.8

Georgia

22.7

21.6

20.1

21.6

Germany

3.6

3.2

3.3

11.0

Ghana

13.7

11.5

10.5

11.6

Greece

13.0

10.1

9.5

8.5

Guadeloupe

14.8

13.0

9.7

9.1

Guatemala

12.4

10.7

8.8

7.1

 

footer-right-page.jpg Country/Region

1Q11

2Q11

3Q11

4Q11

Haiti

14.6

17.6

Honduras

15.0

12.4

10.2

9.4

Hong Kong SAR

8.9

7.9

5.6

4.4

Hungary

8.7

6.9

5.9

5.1

Iceland

6.8

4.7

4.4

3.7

India

15.2

15.9

15.0

13.8

Indonesia

16.2

18.4

18.7

18.6

Iran

9.1

10.0

10.0

10.6

Iraq

13.1

18.0

20.5

22.0

Ireland

5.9

4.7

4.8

3.8

Israel

15.1

12.1

9.2

9.5

Italy

7.8

6.4

5.2

9.0

Jamaica

16.2

12.5

9.0

9.1

Japan

2.7

2.1

1.9

1.3

Jordan

17.6

18.5

15.3

16.0

Kazakhstan

10.1

8.8

7.9

10.2

Kenya

13.0

11.4

10.5

9.5

Korea

30.1

19.8

12.0

11.1

Kuwait

17.0

15.5

12.8

12.0

Latvia

11.9

9.2

7.0

6.8

Lebanon

15.4

15.8

12.7

12.3

Lithuania

13.5

10.7

7.9

7.7

Luxembourg

4.2

3.2

3.2

3.1

Macao SAR

6.9

5.8

4.6

3.0

Macedonia, FYRO

20.2

14.4

12.5

15.1

Malaysia

13.4

12.0

10.2

9.0

Malta

8.7

6.0

5.6

4.5

Martinique

13.5

10.3

8.4

7.7

Mauritius

12.0

12.1

10.8

9.2

Mexico

16.7

13.5

9.7

8.8

Moldova

7.4

6.7

6.0

6.5

Mongolia

10.7

10.8

9.2

11.2

Morocco

14.4

13.1

12.0

12.3

 

footer left page.jpg Country/Region

1Q11

2Q11

3Q11

4Q11

Mozambique

18.1

14.3

12.6

12.0

Nepal

18.9

23.7

24.0

22.4

Netherlands

4.6

5.3

6.6

13.1

New Zealand

5.7

5.1

4.8

3.8

Nicaragua

11.6

9.2

6.7

5.7

Nigeria

13.1

10.6

9.3

8.5

Norway

2.9

2.5

2.5

2.3

Oman

19.3

18.1

14.4

15.5

Pakistan

27.7

31.1

31.9

32.9

Palestinian Authority

27.5

32.7

27.1

29.9

Panama

15.8

12.8

10.8

9.6

Paraguay

8.9

7.7

6.7

6.3

Peru

16.8

13.7

10.3

10.0

Philippines

11.7

11.0

10.3

9.6

Poland

14.1

11.4

8.7

8.9

Portugal

11.5

9.8

8.9

8.9

Puerto Rico

13.4

10.7

8.0

6.9

Qatar

61.5

34.4

12.1

13.5

Reunion

11.9

11.1

7.9

7.4

Romania

16.5

15.3

14.0

13.8

Russia

6.7

6.0

6.1

7.2

Saudi Arabia

16.4

16.2

14.3

14.1

Senegal

15.1

13.0

10.1

10.4

Serbia

16.0

15.6

13.3

14.4

Singapore

12.6

9.0

6.9

5.7

Slovakia

9.6

6.1

4.2

3.6

Slovenia

9.0

6.3

5.0

4.6

South Africa

13.4

10.6

9.4

8.1

Spain

13.2

11.4

6.9

7.6

Sri Lanka

11.3

12.0

11.3

10.8

Sudan

14.8

16.7

16.6

16.3

Sweden

2.8

2.4

2.7

2.5

Switzerland

3.5

2.8

2.8

2.3

 

footer-right-page.jpg Country/Region

1Q11

2Q11

3Q11

4Q11

Syria

11.2

14.0

15.9

15.9

Taiwan

17.7

16.1

10.4

8.2

Tanzania

17.6

13.6

11.6

10.2

Thailand

18.0

19.6

19.4

17.9

Trinidad and Tobago

17.5

11.9

10.1

8.4

Tunisia

16.0

13.6

11.2

13.2

Turkey

28.2

25.5

22.7

26.6

Uganda

16.9

15.0

12.0

11.6

Ukraine

7.4

6.6

6.3

7.1

United Arab Emirates

18.9

16.7

15.1

16.0

United Kingdom

5.1

5.1

5.5

5.1

United States

5.6

5.6

9.4

5.5

Uruguay

6.1

6.1

5.3

4.0

Venezuela

9.8

8.5

7.5

7.1

Vietnam

12.8

15.8

16.3

16.5

Yemen

20.4

21.7

20.5

 

 

footer left page.jpg Glossary

For additional information about these and other terms, visit the MMPC glossary at www.microsoft.com/security/portal/Threat/Encyclopedia/Glossary.aspx.

419 scam

See advance-fee fraud.

ActiveX control

A software component of Microsoft Windows that can be used to create and distribute small applications through Internet Explorer. ActiveX controls can be developed and used by software to perform functions that would otherwise not be available using typical Internet Explorer capabilities. Because ActiveX controls can be used to perform a wide variety of functions, including downloading and running programs, vulnerabilities discovered in them may be exploited by malware. In addition, cybercriminals may also develop their own ActiveX controls, which can do damage to a computer if a user visits a webpage that contains the malicious ActiveX control.

Address Space Layout Randomization (ASLR)

A security feature in recent versions of Windows that randomizes the memory locations used by system files and other programs, which makes it harder for an attacker to exploit the system by targeting specific memory locations.

advance-fee fraud

A common confidence trick in which the sender of a message purports to have a claim on a large sum of money but is unable to access it directly for some reason, typically involving bureaucratic red tape or political corruption. The sender asks the prospective victim for a temporary loan to be used for bribing officials or for paying fees to get the full sum released. In exchange, the sender promises the target a share of the fortune amounting to a much larger sum than the original loan, but does not deliver. Advance-fee frauds are often called 419 scams, in reference to the article of the Nigerian Criminal Code that addresses fraud.

footer-right-page.jpg adware

A program that displays advertisements. Although some adware can be beneficial by subsidizing a program or service, other adware programs may display advertisements without adequate consent.

ASLR

See Address Space Layout Randomization (ASLR)

backdoor trojan

A type of trojan that provides attackers with remote unauthorized access to and control of infected computers. Bots are a subcategory of backdoor trojans. Also see botnet.

botnet

A set of computers controlled by a “command-and-control” (C&C) computer to execute commands as directed. The C&C computer can issue commands directly (often through Internet Relay Chat [IRC]) or by using a decentralized mechanism, such as peer-to-peer (P2P) networking. Computers in a botnet are often called nodes or zombies.

buffer overflow

An error in an application in which the data written into a buffer exceeds the current capacity of that buffer, thus overwriting adjacent memory. Because memory is overwritten, unreliable program behavior may result and, in certain cases, allow arbitrary code to run.

C&C

Short for command and control. See botnet.

CCM

Short for computers cleaned per mille (thousand). The number of computers cleaned for every 1,000 executions of MSRT. For example, if MSRT has 50,000 executions in a particular location in the first quarter of the year and removes infections from 200 computers, the CCM for that location in the first quarter of the year is 4.0 (200 ÷ 50,000 × 1,000).

clean

To remove malware or potentially unwanted software from an infected computer. A single cleaning can involve multiple disinfections.

footer left page.jpg Data Execution Prevention (DEP)

A security technique designed to prevent buffer overflow attacks. DEP enables the system to mark areas of memory as non-executable, preventing code in those memory locations from running.

definition

A set of signatures that antivirus, antispyware, or antimalware products can use to identify malware. Other vendors may refer to definitions as DAT files, pattern files, identity files, or antivirus databases.

DEP

See Data Execution Prevention (DEP)

disclosure

Revelation of the existence of a vulnerability to a third party.

disinfect

To remove a malware or potentially unwanted software component from a computer or to restore functionality to an infected program. Compare with clean.

downloader/dropper

See trojan downloader/dropper.

exploit

Malicious code that takes advantage of software vulnerabilities to infect a computer or perform other harmful actions.

firewall

A program or device that monitors and regulates traffic between two points, such as a single computer and the network server, or one server to another.

generic

A type of signature that is capable of detecting a variety of malware samples from a specific family, or of a specific type.

IFrame

Short for inline frame. An IFrame is an HTML document that is embedded in another HTML document. Because the IFrame loads another webpage, it can be used by criminals to place malicious HTML content, such as a script that downloads and installs spyware, into non-malicious HTML pages that are hosted by trusted websites.

footer-right-page.jpg in the wild

Said of malware that is currently detected on active computers connected to the Internet, as compared to those confined to internal test networks, malware research laboratories, or malware sample lists.

Internet Relay Chat (IRC)

A distributed real-time Internet chat protocol that is designed for group communication. Many botnets use the IRC protocol for C&C.

keylogger

A program that sends keystrokes or screen shots to an attacker. Also see password stealer (PWS).

malware

Any software that is designed specifically to cause damage to a user’s computer, server, or network. Viruses, worms, and trojans are all types of malware.

malware impression

A single instance of a user attempting to visit a page known to host malware and being blocked by SmartScreen Filter in Internet Explorer 8 or 9. Also see phishing impression.

monitoring tool

Software that monitors activity, usually by capturing keystrokes or screen images. It may also include network sniffing software. Also see password stealer (PWS).

password stealer (PWS)

Malware that is specifically used to transmit personal information, such as user names and passwords. A PWS often works in conjunction with a keylogger. Also see monitoring tool.

payload

The actions conducted by a piece of malware for which it was created. Payloads can include, but are not limited to, downloading files, changing system settings, displaying messages, and logging keystrokes.

peer-to-peer (P2P)

A system of network communication in which individual nodes are able to communicate with each other without the use of a central server.

footer left page.jpg phishing

A method of credential theft that tricks Internet users into revealing personal or financial information online. Phishers use phony websites or deceptive email messages that mimic trusted businesses and brands to steal personally identifiable information (PII), such as user names, passwords, credit card numbers, and identification numbers.

phishing impression

A single instance of a user attempting to visit a known phishing page with Internet Explorer 7, 8, or 9, and being blocked by the Phishing Filter or SmartScreen Filter. Also see malware impression.

polymorphic

A characteristic of malware that can mutate its structure to avoid detection by antimalware programs, without changing its overall algorithm or function.

pop-under

A webpage that opens in a separate window that appears beneath the active browser window. Pop-under windows are commonly used to display advertisements.

potentially unwanted software

A program with potentially unwanted functionality that is brought to the user’s attention for review. This functionality may affect the user’s privacy, security, or computing experience.

remote control software

A program that provides access to a computer from a remote location. Such programs are often installed by the computer owner or administrator and are only a risk if unexpected.

rogue security software

Software that appears to be beneficial from a security perspective but that provides limited or no security capabilities, generates a significant number of erroneous or misleading alerts, or attempts to socially engineer the user into participating in a fraudulent transaction.

rootkit

A program whose main purpose is to perform certain functions that cannot be easily detected or undone by a system administrator, such as hiding itself or other malware.

footer-right-page.jpg SEHOP

See Structured Exception Handler Overwrite Protection (SEHOP).

signature

A set of characteristics that can identify a malware family or variant. Signatures are used by antivirus and antispyware products to determine whether a file is malicious or not. Also see definition.

social engineering

A technique that defeats security precautions by exploiting human vulnerabilities. Social engineering scams can be both online (such as receiving email messages that ask the recipient to click the attachment, which is actually malware) and offline (such as receiving a phone call from someone posing as a representative from one’s credit card company). Regardless of the method selected, the purpose of a social engineering attack remains the same—to get the targeted user to perform an action of the attacker’s choice.

spam

Bulk unsolicited email. Malware authors may use spam to distribute malware, either by attaching the malware to email messages or by sending a message containing a link to the malware. Malware may also harvest email addresses for spamming from compromised machines or may use compromised machines to send spam.

spyware

A program that collects information, such as the websites a user visits, without adequate consent. Installation may be without prominent notice or without the user’s knowledge.

Structured Exception Handler Overwrite Protection (SEHOP)

A security technique designed to prevent exploits from overwriting exception handlers to gain code execution. SEHOP verifies that a thread’s exception handler list is intact before allowing any of the registered exception handlers to be called.

tool

Software that may have legitimate purposes but may also be used by malware authors or attackers.

trojan

A generally self-contained program that does not self-replicate but takes malicious action on the computer.

footer left page.jpg trojan downloader/dropper

A form of trojan that installs other malicious files to a computer that it has infected, either by downloading them from a remote computer or by obtaining them directly from a copy contained in its own code.

virus

Malware that replicates, typically by infecting other files in the computer, to allow the execution of the malware code and its propagation when those files are activated.

vulnerability

A weakness, error, or poor coding technique in a program that may allow an attacker to exploit it for a malicious purpose.

wild

See in the wild.

worm

Malware that spreads by spontaneously sending copies of itself through email or by using other communication mechanisms, such as instant messaging (IM) or peer-to-peer (P2P) applications.

footer-right-page.jpg Threat families referenced in this report

The definitions for the threat families referenced in this report are adapted from the Microsoft Malware Protection Center encyclopedia (www.microsoft.com/security/portal), which contains detailed information about a large number of malware and potentially unwanted software families. See the encyclopedia for more in-depth information and guidance for the families listed here and throughout the report.

Win32/Agent. A generic detection for a number of trojans that may perform different malicious functions. The functionality exhibited by this family is highly variable.

Win32/Autorun. A family of worms that spreads by copying itself to the mapped drives of an infected computer. The mapped drives may include network or removable drives.

Win32/BaiduSobar. A Chinese-language web browser toolbar that delivers pop- up and contextual advertisements, blocks certain other advertisements, and changes the Internet Explorer search page.

Win32/Bamital. A family of malware that intercepts web browser traffic and prevents access to specific security-related websites by modifying the Hosts file. Bamital variants may also modify specific legitimate Windows files in order to execute their payload.

Win32/Bancos. A data-stealing trojan that captures online banking credentials and relays them to the attacker. Most variants target customers of Brazilian banks.

Win32/Banker. A family of data-stealing Trojans that captures banking credentials such as account numbers and passwords from computer users and relays them to the attacker. Most variants target customers of Brazilian banks; some variants target customers of other banks.

footer left page.jpg Win32/Banload. A family of trojans that download other malware. Banload usually downloads Win32/Banker, which steals banking credentials and other sensitive data and sends it back to a remote attacker.

JS/Blacole. An exploit pack, also known as Blackhole, that is installed on a compromised web server by an attacker and includes a number of exploits that target browser software. If a vulnerable computer browses a compromised website containing the exploit pack, various malware may be downloaded and run.

Win32/Bulilit. A trojan that silently downloads and installs other programs without consent. Infection could involve the installation of additional malware or malware components to an affected computer.

Win32/ClickPotato. A program that displays pop-up and notification-style advertisements based on the user’s browsing habits.

Win32/Conficker. A worm that spreads by exploiting a vulnerability addressed by Security Bulletin MS08-067. Some variants also spread via removable drives and by exploiting weak passwords. It disables several important system services and security products, and downloads arbitrary files.

Java/CVE-2010-0840. A detection for a malicious and obfuscated Java class that exploits a vulnerability described in CVE-2010-0840. Oracle Corporation addressed the vulnerability with a security update in March 2010.

Win32/Delf. A detection for various threats written in the Delphi programming language. The behaviors displayed by this malware family are highly variable.

Win32/Dorkbot. A worm that spreads via instant messaging and removable drives. It also contains backdoor functionality that allows unauthorized access and control of the affected computer. Win32/Dorkbot may be distributed from compromised or malicious websites using PDF or browser exploits.

AndroidOS/DroidDream. A malicious program that affects mobile devices running the Android operating system. It may be bundled with clean applications, and is capable of allowing a remote attacker to gain access to the mobile device.

Win32/Dynamer. A generic detection for a variety of threats.

Win32/EyeStye. A trojan that attempts to steal sensitive data using a method known as form grabbing, and sends it to a remote attacker. It may also download and execute arbitary files and use a rootkit component to hide its activities.

footer-right-page.jpg MacOS_X/FakeMacdef. A rogue security software family that affects Apple Mac OS X. It has been distributed under the names MacDefender, MacSecurity, MacProtector, and possibly others.

Win32/FakeRean. A rogue security software family distributed under a variety of randomly generated names, including Win 7 Internet Security 2010, Vista Antivirus Pro, XP Guardian, and many others.

Win32/FakeSpypro. A rogue security software family distributed under the names Antivirus System PRO, Spyware Protect 2009, and others.

Win32/FakeSysdef. A rogue security software family that claims to discover nonexistent hardware defects related to system memory, hard drives, and overall system performance, and charges a fee to fix the supposed problems.

Win32/Frethog. A large family of password-stealing trojans that target confidential data, such as account information, from massively multiplayer online games.

Win32/Helompy. A worm that spreads via removable drives and attempts to capture and steal authentication details for a number of different websites or online services, including Facebook and Gmail.

Win32/Hotbar. Adware that displays a dynamic toolbar and targeted pop-up ads based on its monitoring of web-browsing activity.

Win32/Keygen. A generic detection for tools that generate product keys for illegally obtained versions of various software products.

Unix/Lotoor. A detection for specially crafted Android programs that attempt to exploit vulnerabilities in the Android operating system to gain root privilege.

Win32/Malf. A generic detection for malware that drops additional malicious files.

Win32/Meredrop. A generic detection for trojans that drop and execute multiple forms of malware on a local computer. These trojans are usually packed, and may contain multiple trojans, backdoors, or worms. Dropped malware may connect to remote websites and download additional malicious programs.

Win32/Microjoin. A generic detection for tools that bundle malware files with clean files in an effort to deploy malware without being detected by security software.

footer left page.jpg Win32/Obfuscator. A generic detection for programs that have had their purpose disguised to hinder analysis or detection by antivirus scanners. Such programs commonly employ a combination of methods, including encryption, compression, anti-debugging and anti-emulation techniques.

Win32/OfferBox. A program that displays offers based on the user’s web browsing habits. Some versions may display advertisements in a pop-under window. Win32/OfferBox may be installed without adequate user consent by malware.

Win32/Onescan. A Korean-language rogue security software family distributed under the names One Scan, Siren114, EnPrivacy, PC Trouble, My Vaccine, and many others.

Win32/OpenCandy. An adware program that may be bundled with certain third- party software installation programs. Some versions may send user-specific information, including a unique machine code, operating system information, locale, and certain other information to a remote server without obtaining adequate user consent.

Win32/Pameseg. A fake program installer that requires the user to send SMS messages to a premium number to successfully install certain programs.

Win32/Parite. A family of viruses that infect .exe and .scr executable files on the local file system and on writeable network shares.

Win32/Pdfjsc. A family of specially crafted PDF files that exploit Adobe Acrobat and Adobe Reader vulnerabilities. Such files contain malicious JavaScript that executes when the file is opened.

JS/Pornpop. A generic detection for specially-crafted JavaScript-enabled objects that attempt to display pop-under advertisements, usually with adult content.

Win32/Ramnit. A family of multi-component malware that infects executable files, Microsoft Office files, and HTML files. Win32/Ramnit spreads to removable drives and steals sensitive information such as saved FTP credentials and browser cookies. It may also open a backdoor to await instructions from a remote attacker.

Win32/RealVNC. A management tool that allows a computer to be controlled remotely. It can be installed for legitimate purposes but can also be installed from a remote location by an attacker.

footer-right-page.jpg JS/Redirector. A detection for a class of JavaScript trojans that redirect users to unexpected websites, which may contain drive-by downloads.

Win32/Rimecud. A family of worms with multiple components that spread via fixed and removable drives and via instant messaging. It also contains backdoor functionality that allows unauthorized access to an affected system.

Win32/Rugo. A program that installs silently on the user’s computer and displays advertisements.

Win32/Rustock. A multi-component family of rootkit-enabled backdoor trojans that were first developed around 2006 to aid in the distribution of spam email.

Win32/Sality. A family of polymorphic file infectors that target executable files with the extensions .scr or .exe. They may execute a damaging payload that deletes files with certain extensions and terminates security-related processes and services.

JS/ShellCode. A generic detection for JavaScript-enabled objects that contain exploit code and may exhibit suspicious behavior. Malicious websites and malformed PDF documents may contain JavaScript that attempts to execute code without the affected user’s consent.

Win32/ShopperReports. Adware that displays targeted advertising to affected users while browsing the Internet, based on search terms entered into search engines.

Win32/Sirefef. A rogue security software family distributed under the name Antivirus 2010 and others.

Win32/Sisproc. A generic detection for a group of trojans that have been observed to perform a number of various and common malware behaviors.

Win32/Startpage. A detection for various threats that change the configured start page of the affected user’s web browser, and may also perform other malicious actions.

Win32/Stuxnet. A multi-component family that spreads via removable volumes by exploiting the vulnerability addressed by Microsoft Security Bulletin MS10- 046.

Win32/Swisyn. A trojan that drops and executes arbitrary files on an infected computer. The dropped files may be potentially unwanted or malicious programs.

footer left page.jpg Win32/Taterf. A family of worms that spread through mapped drives to steal login and account details for popular online games.

Win32/Tracur. A trojan that downloads and executes arbitrary files, redirects web search queries to a malicious URL, and may also install other malware.

Win32/VB. A detection for various threats written in the Visual Basic® programming language.

Win32/Vundo. A multiple-component family of programs that deliver pop-up advertisements and may download and execute arbitrary files. Vundo is often installed as a browser helper object (BHO) without a user’s consent.

ASX/Wimad. A detection for malicious Windows Media files that can be used to encourage users to download and execute arbitrary files on an affected machine.

Win32/Winwebsec. A rogue security software family distributed under the names Winweb Security, System Security, and others.

Win32/Zbot. A family of password stealing trojans that also contains backdoor functionality allowing unauthorized access and control of an affected computer.

Win32/Zwangi. A program that runs as a service in the background and modifies web browser settings to visit a particular website.

 

One Microsoft Way

Redmond, WA 98052-6399

microsoft.com/security

 

Real World Branding with SharePoint 2010 Publishing Sites

Real World Branding with SharePoint 2010 Publishing Sites

Published: November 2010

Summary: Learn essential concepts to help you create engaging user interface designs in Microsoft SharePoint Server 2010 publishing sites.

Applies to: Microsoft SharePoint Server 2010

Provided by: Andrew Connell, Critical Path Training LLC1 (SharePoint MVP) | Randy Drisgill, SharePoint9112 (SharePoint MVP)

Contents

Click to get code3 Download code3

Introduction to Real World Branding with SharePoint 2010 Publishing Sites

Microsoft SharePoint Server 2010 publishing sites use Publishing Features to provide capabilities to create engaging web content management (WCM) sites. Frequently used as Internet-facing websites, these sites require the use of custom-designed user interfaces (UIs) to establish an online corporate identity. Creating custom-designed UIs, either on a traditional HTML page or in Microsoft SharePoint Server 2010, is known as website branding. Publishing sites use master pages, page layouts, Web Parts, and cascading style sheets (.css files) to enable designers and developers to create branded websites with designs that can rival those of many current and popular websites today. This article focuses on the mechanics of properly planning and creating a design for an external, Internet-facing website with a publishing site, as shown in Figure 1. The article uses a fictitious travel company, Adventure Works Travel, as an example of a company that wants to create an extensively branded SharePoint site.

Figure 1. Adventure Works Travel site branding

Adventure Works Travel site branding

Gathering Design Requirements for a SharePoint Publishing Site

When you are ready to create a great design for a SharePoint site, you first need to take time to plan the site well. Use a planning phase to gather design requirements for site elements such as master pages and page layouts. By properly understanding what the business objectives are before starting to code, you can avoid difficult and time-consuming rewrites later in the project lifecycle.

Gathering design requirements begins by holding a formal requirements gathering session. Whether the site you are designing will be used by 10 users or 100,000 users, some requirements must be met before the project is considered a success. Depending on how complex the site will be, adjust the level of detail to the requirements that you will gather. For example, large sites (either with many pages or many users) might require more time to gather requirements than a small and simple site would. Involve key business, marketing, and IT stakeholders in requirements gathering to ensure that their ideas are considered and to ensure that all key stakeholders completely approve the project. Requirements gathering can often be difficult for a branding project and sometimes it is delegated to the marketing department or even outsourced to external consultants. Although involving key stakeholders is important, also consider whether involving more people in the decision-making process will increase the time needed to gather requirements and whether it will magnify the overall complexity of the project. For this reason, carefully consider who will provide the most relevant input when considering which stakeholders to include.

The following sections describe some of the more important concepts to understand before starting any SharePoint branding project.

SharePoint Server 2010 Publishing Sites vs. SharePoint Foundation 2010 Sites

After requirements gathering is complete, first decide whether to base the website on Microsoft SharePoint Foundation 2010, or on a server running Microsoft SharePoint Server 2010 with the Publishing Features enabled. Publishing sites are built on SharePoint Foundation, and there are many advantages to building engaging Internet-facing websites with publishing sites. Some of the benefits of creating a brand with SharePoint Server publishing sites and SharePoint Foundation sites include the following:

  • Enables content authors to create webpages with a more robust rich-text editing experience than SharePoint Foundation sites offer.
  • Includes master pages that target publishing sites and that use specific code assemblies that take advantage of publishing Features.
  • Easier control of web navigation from the web UI, and more options are available to the designer.
  • Uses the Web UI to easily change a master page and to apply master pages to all subsites below the current site.
  • Uses page layouts to create templates at the page level. Uses text layouts to accomplish a form of simple page layout. Text layouts are not configurable.
  • Use the $SPUrl token to target HTML assets with URLs that are relative to either the site collection ($SPUrl;~sitecollection/) or site root ($SPUrl:~site/)
noteNote:
For the purposes of this article, a publishing site is a SharePoint Server 2010 web application with a site collection in the top-level (root) directory that has the Publishing Features enabled. For simplicity, Publishing Features are already enabled for the default Publishing templates (Enterprise Wiki and Publishing Portal). This article uses the Enterprise Wiki template for the Adventure Works Travel example.

To learn more about setting up web applications and site collections, see Prescriptive Guidance for SharePoint Server 2007 Web Content Management Sites4.

 

Browsers and Platforms Targeted for SharePoint Publishing Site Designs

Before starting to design and code your site, decide early what browsers and operating system platforms the design will support. Although you should strive to create site designs that render as perfectly as possible in every browser and every operating system, it is often impossible or impractical to even test the design for this level of browser compatibility successfully. Typically, it is good to pick a segment of browsers and operating systems to specifically test against, and code with the intent to support them when branding the site.

One good way to choose a level of browser and operating system support is to consult industry websites that study and provide web traffic analysis. Net Applications Market Share5 lists the top 10 web browsers by total market share for June 2010 as shown in Table 1.

Table 1. Browser versions and total market share

Browser Version Total Percentage of Market Share
Internet Explorer 8 25.18%
Internet Explorer 6 17.16%
Firefox 3.6 15.67%
Internet Explorer 7 12.04%
Firefox 3.5 5.24%
Chrome 4.1 5.16%
Safari 4.0 3.83%
Internet Explorer 8 Compatibility Mode 3.35%
Firefox 3.0 2.65%
Opera 10.x 1.88%

Microsoft designates browsers by the level of support in SharePoint. The levels include:

  • Supported A supported web browser is one that works with SharePoint Server 2010, and all features and functionality work as expected.
  • Supported with known limitations A supported web browser with known limitations is one that works with SharePoint Server 2010, although there are some known limitations. Most features and functionality work, but if there is a feature or functionality that does not work or is disabled by design, documentation on how to resolve these issues is readily available.
  • Not tested A Web browser that is not tested means that its compatibility with SharePoint Server 2010 is untested, and there may be issues with using the particular web browser.

For more information about the levels of browser support in SharePoint, see Plan Browser Support (Office SharePoint Server)6.

noteNote:
Internet Explorer 6.0 is not supported by SharePoint 2010. Although you can create a master page that would display web content properly in Internet Explorer 6.0, it would not be compatible with the authoring experience for SharePoint 2010, which requires a browser that is based on modern standards.

 

The Adventure Works Travel example for this article focuses on an end user browsing experience that is as accurate as possible in Internet Explorer 7, Internet Explorer 8, and Firefox 3, and which ensures that several other modern browsers (including Google Chrome and Apple Safari) also render very well.

Targeted Screen Size for SharePoint Site Designs

Another area for consideration is the screen resolution that the new design should target. Many years ago, monitors supported only a subset of resolutions, such as 640 x 480. As monitor prices have decreased, it is more common to see website visitors browsing in 1920 x 1200 and in higher resolutions. Most web designers consider 1024 x 768 to be the most common screen resolution, followed closely by 1280 x 800. When creating a design that is intended to be displayed in a SharePoint site, remember that SharePoint renders a lot of information at once in the user’s typical screen resolution. The available space for displaying content becomes even smaller when you consider that browser toolbars and scroll bars also consume a percentage of the available display area on the screen.

For the Adventure Works Travel example, the minimum screen resolution is 1024 x 768. The design allows for some padding to accommodate scroll bars. Because of the padding, the site was designed to be no wider than 960 pixels.

Defining the Audience and Success Criteria of SharePoint Site Designs

To help ensure the success of a branding initiative, define some of the more subjective goals of the design. Which audiences will use the site? What tasks does the typical user of the site want or need to complete? How will users want to navigate the site? Are users expecting to do business with a company that has a more traditional image, or are they expecting to do business with a less traditional company? Unlike the software development process, the design process is subjective for every business situation. Design decisions are often disputed between stakeholders until a brand identity is decided upon. Because brand ideas can be difficult to gauge, it is also good to identify the success criteria for a new brand. Success criteria can be as simple as attracting more visitors or as complex as calculating an increase in sales across major demographics. The more quantifiable and measurable the success criteria are, the easier it will be to determine the relative success of the branding effort.

The design of the Adventure Works Travel site caters to a younger set of users that is looking for an edgy look and feel. These users will be comfortable navigating the site with the top and left navigation and with SharePoint Server 2010 search. The users’ primary reason for visiting the site will be to learn about adventure destinations and to book vacations. The brand is that of a travel company that caters to individuals who are looking for a vacation that is more adventurous than just a typical stay at a hotel on the beach.

Planning for SharePoint Branding Tasks

The process of actually coding branding for a SharePoint site involves several steps, such as creating master pages, page layouts, and cascading style sheets (.css files). The planning process for building a SharePoint brand can also include several steps, such as creating black-and-white wireframes, creating full-color website design compositions (or comps), and creating functioning HTML and .css file versions of key pages. The following sections describe these activities as they relate to creating a branded SharePoint UI.

Creating Simple Wireframes of SharePoint Site Design

A wireframe is typically a set of black-and-white block diagrams that visually describe the overall structure of a website and its layout, navigation, functionality and, in some cases, even its content. Because of the subjective nature of web design (or even design in general), it is good to discuss these topics in wireframe form instead of getting mired in colors and photo preferences. When completed correctly, wireframes can provide a guide for developers and designers about the functionality and layout to apply in later stages of the branding process.

There are many ways to create wireframes, from drawing with simple pen and paper to modeling with dedicated software tools such as Microsoft Visio 2010. Using dedicated software tools can be very helpful when you are creating wireframes because you can take advantage of prebuilt stencils that map to specific capabilities of specific applications such as SharePoint. You can find many free templates and stencils that you can use to create wireframes for SharePoint sites.

As you create wireframes, decide what SharePoint functionality is supported by the brand. Some of what SharePoint displays by default is not appropriate for every Internet-facing website. Figure 2 labels the major functional areas of a SharePoint interface, and Table 2 describes these areas.

Figure 2. Major functional areas of a SharePoint interface

Major functional areas of SharePoint interface

Table 2. Major functional areas of a SharePoint interface

Figure Label Functional Area Description of Functionality
A Server ribbon The entire top portion of the UI is part of the ribbon. What is displayed depends on the user’s current context.
B Site Actions The main menu for interacting with SharePoint, used primarily by content authors and administrators.
C Global breadcrumbs control A new implementation of the global breadcrumbs control that was first introduced in Microsoft Office SharePoint Server 2007. When clicked, the icon displays a dynamic HTML that shows a hierarchical view of the site. Use it to navigate up levels of the hierarchy from the current location in the hierarchy.
D Page State Action button The button used to control the page state, and that typically displays a shortcut to edit or save the current page.
E Ribbon contextual tabs Tabs present menus that are specific to the functions of the SharePoint site. What is displayed changes based on what the user is interacting with on the page. Some of the items will not be used on every site.
F Welcome menu This menu shows the welcome message and enables the user to view their profile, to sign out, and to sign in as a different user. If other language packs are installed, the functionality to change the user’s language is also available here. When the user is not logged on, the Welcome menu also shows the Sign In link.
G Developer Dashboard button The button that opens the Developer Dashboard that typically appears at the bottom of the screen. The Developer Dashboard contains statistics about the page rendering and queries. This icon is shown when the Developer Dashboard’s display level is set to OnDemand (other options include On and Off). Administrators can set the Developer Dashboard display level by using Windows PowerShell or by using the SharePoint API.
H Title logo Sometimes referred to as site icon. It typically shows the SharePoint site icon, but can display a user-defined logo instead.
I Breadcrumb This is a breadcrumb-like control that is specific to the v4.master master page. It includes the Site Title and the placeholder for Title in Title Area, which typically contains the Page Title. The Site Title is linked to the top level of the site.
J Social buttons Used for marking items as liked and for adding tags and notes to content.
K Global navigation Sometimes referred to as the Top Link Bar or Top Navigation Bar, it is the primary horizontal navigation mechanism for the site.
L Search area The search box is used to enter terms for performing searches on the site.
M Help button The help button links to the SharePoint 2010 help documents.
N Quick Launch Provides current navigation. Sometimes referred to as the Left Navigation. It is the secondary or vertical navigation mechanism of the pages related to the current location.
O Tree View Provides a Windows Explorer–style representation of the site. Because of its appearance, the tree view is often better suited for intranet sites.
P Recycle Bin Provides a link to the Recycle Bin for the site, which is the area where items are stored when deleted. Typically, this is better suited for intranet sites.
Q All Site Content A link to the All Site Content page. This was the View All Site Content link in Office SharePoint Server 2007. Typically, this is better suited for intranet sites.
R Body area Represents the main content placeholder that includes all of the content that is specific to the page. Required for rendering the content of the page.

When creating wireframes for a SharePoint site, be sure to consider the several types of pages that SharePoint could support. Some examples of the types of pages that can exist in a SharePoint site include the home page, landing pages, search results pages, articles, and wiki pages.

Figure 3 shows the Microsoft Visio 2010 wireframe for the Adventure Works Travel website.

Figure 3. Visio 2010 wireframe for an Adventure Works Travel site

Visio 2010 wireframe for Adventure Works TravelYou can see from the wireframe page that the Adventure Works Travel site supports some SharePoint functionality but not all of it. For example, some elements such as the Help button, Tree View, and Recycle Bin will be omitted from the UI. By making these decisions at the wireframe stage, developers do not have to build unnecessary functionality.

Creating Realistic Design Comps for SharePoint Site Designs

Although creating wireframes can certainly help to support any serious branding effort as you plan a new SharePoint site, you should create a complete design comp or prototype before any coding begins. Unlike wireframes, most web design comps are intended to mimic the appearance and behavior (look and-feel) of an actual website as closely as possible without actually creating any code. Comps include realistic static versions of photos, logos, colors, fonts, form elements, and other design or structural artifacts that might appear on the page. For a SharePoint site, emulating page contents means emulating many of the functional areas of the SharePoint user interface.

Although you can create design comps with any graphics application (or even with a pencil and paper), applications such as Adobe Photoshop or Microsoft Expression Design can make the task much easier. Use these applications to create an easily maintained and reusable design comp for SharePoint sites.

noteNote:
Although this article does not refer to specific features of Adobe Photoshop or Microsoft Expression Design, general concepts and processes are described and similar features may be available in these and similar design applications.

 

The following sections describe capabilities that are common to applications that are used to create design comps.

Using Layers and Layer Groups in Design Applications to Separate Elements

Use layers and layer groups to separate design elements into specific units. Instead of creating design elements in a “flat” file, layers behave as if each new layer is placed on top of the previous layer. Designers can hide, show, manipulate, move, and apply effects such as drop shadows and borders to individual layers without affecting the other design elements. When using a design tool to create a design comp, it is a good idea to make new layers for every element in the design.

Creating Editable Text with Design Applications

Create editable text by using a wide variety of fonts, sizes, and styles. Without this feature, text that is created in basic design programs is static and must be erased before each change. By using a modern design tool, you can resize text, display text in a bold font, color the text, or change its font changed and much more without erasing the previous state.

Creating Web Safe Images with Design Applications

Save images easily in web safe file formats such as .jpg, .gif, and .png. Many design programs can help you create images in a small web-friendly file size without compromising their quality.

Creating Realistic Design Comps with Design Applications

When you are creating design comps, it is tempting to use the power of the design tool to create designs that are highly polished or finished. Be careful not to create a design that is so finished that it looks nicer than a browser can actually render on a SharePoint page. Text is one such limitation. In Adobe Photoshop, each piece of text can use different antialiasing techniques. Antialiasing is a mechanism that reduces distortion of images at lower resolutions. Small text in particular appears much smoother in Photoshop than browsers can replicate. To not set expectations too high, it is a good idea to avoid using anti-aliasing with small text.

In addition to text antialiasing, consider the appearance and behavior of SharePoint. To accurately replicate SharePoint functionality in a design comp, take screen shots of each of the pieces of SharePoint functionality and paste them into the design.

For example, as the Adventure Works Travel design comp is created, various colors and styles are finalized. Stock photos must be acquired, fonts must be selected, and logos must be created. Each element is created in its own layer, and effects such as gradients and borders are created as layer effects to make it easier to make changes later. Capture SharePoint elements such as the Server ribbon or the search box and paste them into the design tool, and finally arrange these elements in an appealing way. Figure 4 shows the final Adventure Works Travel design comp.

Figure 4. Adventure Works design composition

Adventure Works design compositionAs you create the design comp, decide how to replicate the concepts in SharePoint. Figure 5 shows the same design comp with labels applied that highlight each functional area. Table 3 describes the functional areas.

Figure 5. SharePoint functional areas in a design comp

SharePoint functional areas in a design comp

Table 3. Major functional areas in the SharePoint Site design comp

Label Functional Area Description
A The ribbon Includes all of the standard ribbon elements such as the Site Actions menu and Welcome menu.
B Title logo
C Search area
D Global navigation
E Current navigation
F Breadcrumbs Uses the SiteMapPath control.
G Field control
H Field control
I Web Part
J Web Part

Converting the Design Comp into HTML and .CSS Code

Convert the design comp into a functioning HTML page. You can skip this step for simple designs, but for complex designs, completing it enables the designer to work in a familiar environment. The HTML code can be used later to create the master page in a tool such as Microsoft SharePoint Designer 2010. By first creating a functioning HTML version, you can fine-tune the HTML for the master page without having to work around the code that SharePoint adds to the display. When this step is finished, there should be a functionally complete HTML version of the site’s key pages. All cascading style sheet code for the basic layout is complete and all images are sliced from the design comp and saved to individual files.

There are many toolsets available to designers for creating HTML. Tools range from Notepad or another text editor to simply code the HTML, to professional webpage development tools such as Adobe Dreamweaver or Microsoft Expression Web. The following is a list of some of the advantages that a professional webpage development application can offer to designers:

  • Support for HTML and cascading style sheet code completion
  • WYSIWIG (What You See Is What You Get) design views
  • Tools that help with the creation of cross browser webpages

DOCTYPES and SharePoint

When you are creating cross-browser compliant HTML, it is important to understand how HTML DOCTYPE declarations work. A DOCTYPE is a declaration that instructs a browser or validator to use a specific language to interpret the HTML or XML code that it describes. Although it is possible to create HTML—and even master pages—that do not declare a DOCTYPE, without one, browsers can render HTML code in unexpected ways. For example, without a valid DOCTYPE declared, Internet Explorer 8 will render an HTML page in Quirks Mode (which is similar to how Internet Explorer 5.5 would render a page).

There are several DOCTYPE declarations in use currently that can cause a browser to render content in a predictable way. The most popular DOCTYPE declarations are the following:

  • HTML 4.01 Strict Allows all HTML elements but does not allow deprecated elements such as the tag.
  • HTML 4.01 Transitional Allows all HTML elements, including the deprecated elements.
  • XHTML 1.0 Strict Similar to HTML 4.01 Strict, but all tags must be well-formed XML (for example, tags must be closed properly). Any deprecated elements are ignored.
  • XHTML 1.0 Transitional Similar to HTML 4.01 Transitional, but all tags must be well-formed XML. Deprecated elements are allowed (but must also be well-formed XML).

Because SharePoint 2010 uses the XHMTL 1.0 Strict DOCTYPE declaration in its default master pages, use the XHTML 1.0 Strict DOCTYPE when creating HTML that is intended for use in SharePoint 2010.

noteNote:
By default, SharePoint 2010 sites will probably not be 100% valid XHTML 1.0 Strict through any World Wide Web Consortium (W3C) validation checker. Some of the legacy controls are still used in SharePoint 2010. Although the pages will not completely validate, the design experience will be more reliable if XHTML 1.0 Strict is used to code SharePoint HTML. The examples in this article use the XHTML 1.0 Strict DOCTYPE.

 

To create an XHTML 1.0 Strict document in an HTML editor tool, ensure that you create a new blank HTML document that specifies DOCTYPE as XHTML 1.0 Strict. (For more information about the XHTML 1.0 Strict DOCTYPE, see the W3C XHTML 1.0 Strict Specification7.) The blank HTML page that the tool creates will open with the following markup.

<!DOCTYPE html PUBLIC "=//W3C//DTD XHTML 1.0 Strict//EN"" 
http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd><html xmlns=http://www.w3.org/1999/xhtml><head><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><title>Untitled Document</title></head> <body></body></html>

From here, create the rest of the HTML. Be careful to follow the W3C guidelines for creating valid XHTML 1.0 Strict code. For more information about the XHTML 1.0 Strict DOCTYPE, see the W3C XHTML 1.0 Strict Specification7. The rest of this section focuses on specific points related to creating HTML for a SharePoint design. For more information about creating HTML code, see the MSDN HTML and DHTML Overviews and Tutorials.

Designing SharePoint Sites with or without Tables

Another design choice that is often debated is whether the HTML design layout should use tables or whether it should use tags with .css styling. Historically, all HTML layouts were created with tables to allow for a rich UI, but as browsers have evolved, so has the support for cascading style sheet-based layouts. Because HTML tables were originally intended to display tabular information, not to create layouts, they are falling out of favor with web designers.

You should consider that by default SharePoint 2010 contains fewer tables than previous versions, and tables are mostly used in SharePoint 2010 only when displaying tabular data. The Adventure Works Travel HTML code does not use tables and uses cascading style sheets for its entire layout.

HTML and Future Internet Explorer Compatibility with SharePoint

As new versions of Internet Explorer are released, the way HTML is rendered by the browser could change over time. To address the possibility of changes, Microsoft uses the X-UA-Compatible META tag that targets HTML markup to a specific version of Internet Explorer. The default SharePoint 2010 master pages are set to force current and future versions of Internet Explorer to render HTML in Internet Explorer 8 mode like the following markup:

<meta http-equiv="X-UA-Compatibile" content="IE=IE8" />

The Adventure Works Travel HTML includes the META tag to help ensure future Internet Explorer versions will display the SharePoint HTML properly.

For more information about the Internet Explorer Standards Mode, see META Tags and Locking in Future Compatibility8.

Slicing the Design Comp into Web Images

Although creating a design comp is useful for understanding how the webpage should look, use it to create all of the individual images that HTML will load. One great way to break up a large image into individual web images is to use the Slice tool in a design application such as PhotoShop or Expression Blend.

To create web images from a design comp, open the Slice tool from the appropriate menu in your design application. Create rectangular selections around all of the areas that have to be made into web images, and be sure to hide any layers that are unwanted in the final images (such as the mocked-up text that SharePoint creates). Click each slice and select an appropriate web image file format. For slices that should not be turned into images, there should be an option to associate a slice with no image. Typically, .jpg files should be used for photos with many colors, and .gif files or .png files should be used for artwork and text or images that need transparent backgrounds. Files in .png format introduce the ability to include faded levels of transparency, while .gif files have only 100 percent transparent areas.

Creating the Adventure Works Travel HTML

Now that all of the individual web images created, the next step is to code the HTML and .css files for Adventure Works Travel. Adobe Dreamweaver CS3 was used to create an XHTML 1.0 Strict HTML file. The rest of the HTML markup can be found in the associated files that are available for download with this article (see MSDN Sample – Real World SharePoint Branding9 on MSDN Code Gallery).

noteNote:
The HTML in this example does not use tables for layout, but instead frequently uses tags to segment the logical areas of the page. This HTML was checked by using the W3C Markup Validation Service10 and is XHTML 1.0 Strict compliant.

 

 

Creating .css files for Adventure Works Travel

Because .css code is used for all of the layout design, the HTML markup alone will not create an attractive webpage. Find the .css code that was created to style all of the colors, fonts, images and positions for the elements in the HTML in the associated files available for download with this article (see MSDN Sample – Real World SharePoint Branding3 on MSDN Code Gallery). This .css file was linked from the Adventure Works Travel HTML file by way of the following code in the <head> section.

<link rel="stylesheet" href="style.css" type="text/css">

For more information about creating .css code to style an HTML webpage, see MSDN CSS Reference11.

Testing SharePoint Webpage Design in Multiple Browsers

Now that all of the HTML, images, and .css files are created, you can test the webpage to ensure that it looks as similar as possible to the design comp. Figure 6 shows the finished Adventure Works Travel webpage in Internet Explorer.

Figure 6. Completed Adventure Works Travel webpage in Internet Explorer

Completed Adventure Works Travel webpage in IEBefore converting an HTML design into a functional SharePoint site, test the design in as many browsers as possible. In addition to Internet Explorer, by installing Mozilla Firefox, Google Chrome, and Apple’s Safari for Windows, you can test a web design for many different browsing scenarios. Another option for testing in multiple browsers is to use Expression Web Super Preview12. This application is available in Expression Web 3 and is also available as a free download that tests only Internet Explorer versions. The full version can test browsers that are not created by Microsoft, such as Firefox. Both versions can display pages side-by-side by using different rendering engines, and both can enable very intricate inspection of even the smallest differences.

Creating the Brand in SharePoint

Now you will focus on creating a brand in a publishing site. You will learn to work with a starter master page and add custom HTML markup and .css code to create a master page that closely resembles the original Adventure Works Travel HTML page. Finally, you will learn about page layouts, including how to create a page layout for Adventure Works Travel. This section will help you complete the the Adventure Works Travel SharePoint branding.

Building a Custom SharePoint Master Page

When it comes to building a brand for a SharePoint site, the master page is of central importance. Every page in SharePoint uses a master page for laying out the functionality and content that makes up a SharePoint site. One of the keys to creating a well-branded website with SharePoint is creating a good master page. Because you already created a design comp and authored the design in HTML, you can use it to create a custom master page.

Using Content Placeholders in SharePoint

In addition to referencing and using all of the specific SharePoint controls, master pages in SharePoint require a specific set of content placeholders. If these required content placeholders are deleted from a master page, SharePoint displays an error in the browser. Many times the required content placeholders are not used in a particular site design; in these cases it is helpful to have a way to hide the required content placeholders. Remove content placeholders from the rendered page without causing an error by nesting them within a hidden panel control. The following code shows a content placeholder placed in a hidden panel.

<asp:Panel visible="false" runat=server>
  <asp:ContentPlaceholder ID=PlaceHolderNavSpacer"> runat="server" />
</asp:Panel>

For more information about how content placeholders are used in the SharePoint default master page see The Default Content Placeholders on Default.Master in a Windows SharePoint Services 3.0 Site13.

The SharePoint Starter Master Page

Because SharePoint requires many specific content placeholders, creating a custom master page from scratch can be challenging. Although any of the default master pages can serve as the starting point for a new custom master page, they contain a lot of branding code that must be deleted before starting. A better approach is to begin with a starter master page, a preconfigured master page skeleton that includes only the functionality that is absolutely required to create a functioning page in SharePoint. For a list of the content placeholders used in a SharePoint Server 2010 master page, see Upgrading an Existing Master Page to the SharePoint Foundation Master Page14.

The downloads for this article include a well-commented starter master page designed for use with an Internet-facing publishing site. For the most part, this is a traditional starter master page for SharePoint, but it uses a few publishing-specific elements, most notably the navigation controls. The starter master page should work with most of the default SharePoint 2010 pages including Application pages (such as Site Settings), lists, and documents.

Each section of the starter master page has comments that label which functional area of SharePoint is represented. The following sections describe some of the key aspects of working with master pages in SharePoint 2010, specifically as they relate to the starter master.

Working with the SharePoint Ribbon

The starter master page is set up much like the default master pages so that it has the ribbon “stuck” to the top of the visible page. With the Ribbon Positioning System enabled, SharePoint manages the page scrolling and enables large pages to scroll and still show the ribbon at the top of the browser window at all times. To accomplish this, page scrolling is turned off in .css code and on the tag, and the main body content (everything that is below the ribbon) is placed inside two specific tags, as follows.

<div id="s4-workspace"> <div id=s4-bodyContainer"> . . . </div> </div>

SharePoint looks for these tags and adds scrolling to only that area and not the ribbon. Because of how the Ribbon Positioning System manages the scrolling and placement of the ribbon, it may be necessary to turn it off and use a more traditional scrolling method when working with very complex .css layouts. To learn more about how the Ribbon Positioning System works, or how to change it to use a more traditional scrolling method, see Customizing Ribbon Positioning in SharePoint 2010 Master Pages15.

Handling Fixed Width SharePoint Webpage Designs

Part of the Ribbon Positioning System in SharePoint 2010 involves setting the page width and height automatically based on how large the browser window is. The default SharePoint branding uses the full browser width for its layout; custom branding that uses a fixed width (often centered in the middle of the page) must have a special .css class named s4-nosetwidth applied to the Workspace element. The starter master page is set to use this instance of the s4-nosetwidth class; it should be removed for designs that must take up the full width of the browser.

Working with .css Code in SharePoint Webpage Design

One of the key aspects of branding in SharePoint is the cascading nature of the style sheets in .css files. If two .css rules have the same specificity, the .css rule that is loaded last is the style that is applied to an element. For more information about this concept, see the W3C’s Assigning Property Values, Cascading, and Inheritance16.

Microsoft has taken full advantage of the cascade and uses it as the primary means of overriding default styles with custom styles. The bulk of the .css style that is loaded by default in SharePoint comes from the Corev4.css file and several other related .css files that are loaded on the fly by SharePoint 2010 as particular pages need them. Corev4 and the other default .css files are loaded from the [..]\14\TEMPLATE\LAYOUTS\1033\STYLES folder, which is located in the SharePoint root folder where most of the SharePoint installation files can be found.

For a list of all of the styles loaded default in SharePoint 2010, see Cascading Style Sheets Class Usage in SharePoint Foundation17.

A primary branding task is to override the default styles with custom .css that will restyle the SharePoint functionality to match the overall website branding. In SharePoint 2010, Microsoft added the After property to allow custom .css to always come after specific .css files such as the default CoreV4.css file. The following code shows the After property being used to load a custom cascading style sheet.

<SharePoint:CssRegistration name="/Style Library/sitename/style.css" After="corev4.css" runat="server"/>
noteNote:
The After property requires a more complete path to load a .css file after other custom .css files. For example, to load another .css file after the custom style.css file, use the following code.

<SharePoint:CssRegistration name="/Style Library/sitename/morestyles.css" After="/Style Library/sitename/style.css" runat="server"/>

 

The CssRegistration in the starter master page is set to look for the custom .css in the Style Library of the publishing site under the SiteName subfolder. You should replace the SiteName folder referenced in the starter master page with the name of an actual site.

noteNote:
When making references to web files such as a custom style sheet, SharePoint Server 2010 provides the $SPUrl token for making site collection root-relative URLs or site root relative-URLs. The style sheet reference in the starter master page could be written to use this functionality, as follows: <SharePoint:CssRegistration name”<% $SPUrl:-sitecollection/Style Library/sitename/style.css %>” After=”corev4.css” runat=”server”/>

The benefit of using this method can be seen when branding is deployed to a site collection that is not located at the web application root. Using a URL that is relative to the site collection ensures that styles are loaded from the site collection’s own Style Library and not from the root site collection’s Style Library. The disadvantage of using this method is that Design View cannot display some assets when referenced this way. For simplicity, this article does not use the $SPURL variable in its URLs.

 

Considering Impact of Branding on SharePoint Dialog Boxes

One powerful new feature in SharePoint 2010 is the dialog framework. Many menu pages are loaded in modal dialog boxes that appear over the main page content. This affects branding because by default all custom branding including logos, headers, navigation, and footers all appear inside of dialog boxes. To prevent branding elements from displaying in dialog boxes, SharePoint 2010 provides a cascading style sheet class called s4-notdlg. When this class is applied to an element, SharePoint 2010 automatically hides that element from dialog boxes. This class I used throughout the starter master page to hide branding from dialog boxes.Figure 7 shows custom branding being applied to a dialog box.

Figure 7. Custom branding in a dialog box

Custom branding in a dialog box

Handling the Name.dll ActiveX Control

When displaying Internet-facing publishing sites, Internet Explorer browsers display an annoying message when they do not have the SharePoint 2010 server added to their trusted sites list. This message asks the user to add the Name.dll ActiveX Control.

Typically, this control is not used by anonymous users of SharePoint and the request to load it can be quite alienating to users who are not familiar with SharePoint. You can turn off the message on the General Settings page of the Manage Web Applications section of Central Administration. Set Enable Person Name smart tag and Online Status for members to No.

You can suppress the message by adding ECMAScript (JavaScript, JScript) code to the master page. The starter master page includes the following JavaScript code, which will hide the message.

<script type="text/javascript"> 
function ProcessImn(){}
function ProcessImnMarkers () {}
</script>

For more information about presence, see Presence in SharePoint 201018.

Handling Legacy Browsers

In most cases, because Internet Explorer 6 is not a supported browser for SharePoint 2010, Microsoft recommends warning Internet Explorer 6 users that their experience may be degraded. Microsoft provides a WarnOnUnsupportedBrowsers control that can be used in master pages to warn users about unsupported browsers, as shown in the following example.

<SharePoint:WarnOnUnsupportedBrowsers runat="server"/>

The starter master page uses the WarnOnUnsupportedBrowsers control near the bottom of the code; to turn off the alert, remove that control from the master page.

Creating a Master Page with SharePoint Designer

After the code for a starter master page is ready, add the master page to SharePoint. Microsoft SharePoint Designer 2010 is well-suited for this task.

To add the starter master page to SharePoint by using SharePoint Designer 2010

  1. Open a SharePoint Server 2010 publishing site in Microsoft SharePoint Designer 2010.
  2. In the Site Objects panel, click Master Pages. This is the master page gallery where all master pages and page layouts are created.
  3. On the ribbon, click Blank Master Page, and then name it AdventureWorks.master.
  4. Click the file named AdventureWorks.master, and on the ribbon, click Edit File. SharePoint opens the new master page with its default content.
  5. Select all of the content, and then press Delete to remove it. Next, copy the contents of StarterPublishing.master (available with the article downloads) and paste it into AdventureWorks.master.
  6. To save the changes, click Save in SharePoint Designer 2010.
  7. On the Site Objects menu, click Master Pages, right-click AdventureWorks.master, and then click Check In. On the Check In menu, select Publish a major version, and then click OK.
  8. Because there is an approval workflow applied to the master page gallery, a warning appears that says “This document requires content approval. Do you want to view or modify its approval status”. Click Yes.
  9. The SharePoint web interface opens in a browser. If you are challenged to authenticate, log on with your user name and password.
  10. The Master Page Gallery opens with a view grouped by Approval Status. Click to the right of AdventureWorks.master, and then click Approve/Reject.
  11. For Approval Status, select Approved, and then click OK.
    noteNote:
    To add master pages to SharePoint, check them in as major versions, and publish and approve them before users other than the one who has the file checked out in order to enable users to access a site that has had the master page applied to it. The same is true for any changes to the master page: other users will see updates only if the changes are checked-in as a major version, published, and approved.

     

When working with SharePoint files in SharePoint Designer 2010, be aware that SharePoint puts them in a customized state, which can impact site maintenance. The final section of this article describes the process for deploying branding files to SharePoint in an uncustomized state. Because of customization, it is best to work on branding files in SharePoint Designer only in a development environment, instead of working on final versions of files on a production server running SharePoint. For more information about creating uncustomized files in SharePoint, see Understanding and Creating Customized and Uncustomized Files in Windows SharePoint Services 3.019. Although this article addresses the previous version of SharePoint, all the concepts and code still apply to SharePoint 2010.

Applying a Master Page

With the master page checked in and approved, the next step is to apply the master page to the SharePoint site.

To apply the master page to the SharePoint site

  1. Click Site Actions, click Site Settings, and in the Look and Feel section, click Master page.
  2. For Site Master Page and System Master Page, select AdventureWorks.master, and then click Reset all subsites to inherit the Site Master Page setting.
  3. Ensure that the Alternate CSS URL is set to Use Microsoft SharePoint Foundation default styles. Click OK.

By applying the master page to both the Site Master Page and the System Master Page, all publishing pages and the application pages will be styled with the custom branding. This is a new feature in SharePoint 2010; by default, in Office SharePoint Server 2007 custom master pages did not apply to Application pages such as the Site Settings menus. One potential disadvantage to applying a highly stylized master page such as Adventure Works Travel as the System Master Page is that more testing is required to ensure that all settings pages and lists render the correct custom branding. The decision to apply a custom master page to the System Master Page is purely a business decision.

noteNote:
Custom master pages that are applied to application pages sometimes have specific user interface needs. For example, in Site Settings, the Users and Permissions menus must have the PlaceHolderLeftNavBar content placeholder visible in the custom master page to show people and groups. Also, sometimes if elements such as required content placeholders are missing, the Application pages do not display an error. Instead, they revert back to displaying the standard v4.master page.

 

With the starter master page applied, the site’s look and feel is blank and ready to have a brand applied to it. The starter master page is certainly not very attractive, but that will be addressed in the following sections.

Figure 8. Starter master page applied to a publishing site

Starter master page applied to a publishing site

Adding .css and Image Files to SharePoint

The branding for Adventure Works Travel requires .css files and images to work properly. They were all created for the HTML mockup earlier and are included with the downloadable code associated with MSDN Sample – Real World SharePoint Branding3.

To add branding files to the Style Library

  1. From the Site Objects menu, click All Files. From the All Files list in the main window, click Style Library.
  2. On the ribbon, click Folder to create a new folder, and name it AdventureWorks.
  3. Click the new AdventureWorks folder, and then drag all of the images, favicon.ico, and style.css from the HTML Branding folder in the MSDN Sample – Real World SharePoint Branding3article downloads.
  4. Select all of the files that were added to the Style Library, right-click, and then select Check In.
  5. On the Check In menu, click Publish a major version, and then click OK. Because the Style Library does not have an approval workflow applied to it, approving the files will not be necessary.

Building the Master Page with HTML

After all of the branding files are added to the SharePoint site, the next step is to start adding in code from the HTML design to the starter master page. While adding the HTML, this is also a good time to start moving areas of the starter master around in the overall layout and make any other site specific changes. Verify that Adventure Works.master is open in SharePoint Designer 2010 and that it is checked out for editing. To check out the file, click Master Pages on the Site Objects menu. In the main window, if there is no green check mark next to AdventureWorks.master, right-click the file, and then click Check Out.

For the Adventure Works Travel site, this process begins with the section of the starter master page. Three areas of the section have text for Site Name that can be changed to Adventure Works, including the PlaceHolderPageTitle, SPShortcutIcon, and CssRegistration placeholders.

<title runat="server"><asp:ContentPlaceHolder id="PlaceHolderPageTitle" runat="server">Adventure Works</asp:ContentPlaceHolder></title>
<SharePoint:SPShortcutIcon runat="server" IconUrl="/Style Library/AdventureWorks/favicon.ico"/>
<SharePoint:CssRegistration name="/Style Library/AdventureWorks/style.css" After="corev4.css" runat="server"/>

Adventure Works has its own custom style sheet, so the inline .css code that is included in the section of the starter master page can be moved to the path Style Library/AdventureWorks/style.css.

noteNote:
You can ignore the entire ribbon section of the code. Unless there are unique circumstances, most master pages can use the default ribbon code.

 

Next, copy and paste everything from the original HTML design between the <form> and </form> tags into the master page after the <div id="MSO_ContentDiv" runat="server"> tag. The next sections describe which areas of SharePoint functionality will be moved up from the lower parts of the starter master page into the pasted HTML code.

noteNote:
Some of information below may be tricky to follow, so it may be helpful to open the final version of the Adventure Works master page, which is available with the article downloads, and follow along.

 

To build the master page with HTML

  1. Adventure Works is a public-facing Internet site, and the decision was made to hide the ribbon for anonymous users and instead show a simple User Login link. When users are authenticated, the User Login link disappears and the full ribbon is displayed at the top. The code is not included by default in the starter master page. An <asp:Loginview> tag is used to show different HTML code for anonymous users and logged in users. The new custom <div> tag contains that code.
    <div class="customTopLeft"> <asp:LoginView id="LoginView1" runat="server"> <AnonymousTemplate> <div class="customLogin"<a href="/_layouts/authenticate.aspx">User Login</a></div> <style type="text/css" body #s4-ribbonrow { display: none; } </style> </AnonymousTemplate> <LoggedInTemplate> <style type="text/css"> .customLogin { display: none; } </style> </LoggedInTemplate> <asp:LoginView> </div>
  2. Because the customTop <DIV> tag should not show in the dialog boxes in SharePoint Server 2010, the s4-notdlg .css class must be added.
    <div class="customTop s4-notdlg">
  3. The static search HTML is replaced with the PlaceHolderSearchArea placeholder and the SmallSearchInputBox delegate control.
    <div class="customSearch"> <asp:ContentPlaceHolder id="PlaceHolderSearchArea" runat="server"> <SharePoint:DelegateControl runat="server" ControlId="SmallSearchInputBox" Version="4"/> </asp:ContentPlaceHolder> </div>
  4. The customHeader <DIV> tag should not show in the dialog boxes in SharePoint 2010, so the s4-notdlg .css class must be added.
  5. The static link back to home (<a class="customLogo" href="#"><img src="logo.png" alt="Back to Home" title="Back to Home" /></a>), is replaced with a custom logo (<div class="customLogo">) tag and the SharePoint link button <SharePoint:SPLinkButton> and <SharePoint:SiteLogoImage> tag from the starter master page are moved into it. Also, the LogoImageUrl tag is changed from sitename to AdventureWorks. These changes are shown in the following markup.
    <div class="customLogo"> <SharePoint:SPLinkButton runat="server" NavigateUrl="~sitecollection/"> <SharePoint:SiteLogoImage LogoImageUrl="/Style Library/AdventureWorks/logo.png" AlternateText="Back to Home" ToolTip="Back to Home" runat="server"/> </SharePoint:SPLinkButton> </div>

     

  6. The static navigation is replaced with the SharePoint Global Navigation control and the corresponding data source. You can also remove the .css classes for menu and horizontal orientation from <div class="menu horizontal customTopNavHolder"> because SharePoint will now handle this .css code.
    <div class="customTopNavHolder"> <PublishingNavigation:PortalSiteMapDataSource ID="topSiteMap" runat="server" EnableViewState="false" SiteMapProvider="GlobalNavigation" StartFromCurrentNode="true" StartingNodeOffset="0" ShowStartingNode="false" TrimNonCurrentTypes="Heading"/> <SharePoint:AspMenu ID="TopNavigationMenuV4" Runat="server" EnableViewState="false" DataSourceID="topSiteMap" AccessKey="<%$Resources:wss,navigation_accesskey%>" UseSimpleRendering="true" UseSeparateCss="false" Orientation="Horizontal" StaticDisplayLevels="1" MaximumDynamicDisplayLevels="1" SkipLinkText="" CssClass="s4-tn"> </SharePoint:AspMenu> </div>
  7. The default SharePoint 2010 status bar <DIV> tags are added between the customHeader closing </DIV> tag and the customMain <DIV> tag. This is shown in the following markup.
    </div> <div class="s4-notdlg"> <div id="s4-statusbarcontainer"> <div id="pageStatusBar" class="s4-status-s1"></div> </div> </div> <div class="customMain">
  8. Next, the left navigation will be added. But because the Adventure Works branding has uniquely styled navigation, it is a good idea to show only the branded navigation when an Adventure Works publishing page is created, not on all of the application pages or anywhere else. Use only the content placeholder for PlaceHolderLeftNavBar and remove any of its usual contents, such as the AspMenu and data source placeholders. Removing these placeholders enables the Adventure Works page layout to override the content placeholder with branded navigation, and any other page that needs left navigation can also override it with its own navigation. For pages that do not include left navigation, set up the placeholder to hide the left panel entirely so that there is no empty space on the left side of the interface. Also, notice that the containing <DIV> ID tag and the Class get combined with the customMainLeft class from the HTML mockup. This combination allows the default SharePoint .css files to apply to the left navigation and any custom branding for Adventure Works.
    <div id="s4-leftpanel" class="customMainLeft s4-notdlg"> <asp:ContentPlaceHolder id="PlaceHolderLeftNavBar" runat="server"> <style type="text/css"> #s4-leftpanel { display: none; } .customMainRight { width: inherit; padding-left: 10px; } </style> </asp:ContentPlaceHolder> </div>
  9. In the HTML for the mockup, there is a Trip Planner that appears below the left navigation. In SharePoint 2010, this is a good place for a Web Part zone. You add Web Part zones from page layouts, not from master pages. So to add a Web Part zone, add the PlaceHolderLeftActions content placeholder below the PlaceHolderLeftNavBar content placeholder. The Adventure Works page layout will override the PlaceHolderLeftActions content placeholder, and any page that does not override this placeholder will not display anything in this area of the master page.
    <asp:ContentPlaceHolder id="PlaceHolderLeftActions" runat ="server"/>
  10. The customMainRight <DIV> tag is where much of the page content is. Add the s4-ca class so that SharePoint can control the area with its own cascading style sheet.
    <div class="s4ca customMainRight">
  11. Next, place the breadcrumbs, page title, and page description in their own <DIV> section with the s4-notdlg .css class applied so that they can be hidden for dialog boxes. For the page title and description, this is as simple as adding the PlaceHolderPageTitleInTitleArea and PlaceHolderPageDescription content placeholders. The breadcrumbs involve a bit more work because the default breadcrumb menu for SharePoint 2010 is the pop-up menu on the top left side of the page. This pop-up menu works well for intranet sites, but is not an element that would normally appear on public-facing Internet sites for anonymous users. To duplicate the functionality of a more traditional breadcrumb, use the SiteMapPath class: <asp:SiteMapPath runat="server" />.
    <div class="customMainContent"> <div class="s4-notdlg"> <div class="customBreadcrumbs"> <asp:SiteMapPath runat="server"/> </div> <h1 class="customPageTitle"><asp:ContentPlaceHolder id="PlaceHolderPageTitleInTitleArea" runat="server" /></h1> <asp:ContentPlaceHolder id="PlaceHolderPageDescription" runat="server" /> </div>
  12. The remaining content from the HTML mockup that is in the customMainContent section is handled by the PlaceHolderMain content placeholder and is ultimately supplied by the page layout. This code includes the subtitle, the page content, and the Top Activities (which will be a Web Part). Simply remove all of this section and replace it with the placeholder, as shown in the following example.
    <asp:ContentPlaceHolder id="PlaceHolderPageDescription" runat="server" /> </div> <asp:ContentPlaceHolder id="PlaceHolderMain" runat="server"/> </div> </div>
  13. Because the customFooter <DIV> section should not appear in dialog boxes in SharePoint 2010, add the s4-notdlg .css class.<div class="customFooter s4-notdlg">.
  14. Move up the Developer Dashboard code from the starter master page code and place it right after the customFooter closing </DIV> tag.
    </div> <div id="DeveloperDashboard" class="ms-developerdashboard"> <SharePoint:DeveloperDashboard runat="server"/> </div>
  15. Remove any of the remaining starter master page code that is located after the Developer Dashboard closing </DIV> tag and before the three closing </DIV> tags and the PlaceholderFormDigest placeholder.

At this point, the Adventure Works Travel master page is complete. You should check in the master page, publish it as a major version, and approve it so that users can see the changes. Although the master page is finished at this point, the site still does not look like the final design. The site requires the addition of much more custom .css code to the style.css file before the look is complete.

Building Out .css Rules for the SharePoint Site Design

When all of the .css files and images were added to the Style Library, they included the style.css file, which included all of the styles that created the look and feel of the HTML design. For the cascading style sheets to work with the additional SharePoint functionality, several changes need to be made to the .css code. This section begins with areas of the HTML design’s .css code that must be updated, and then concludes with a large chunk of .css code that is used to style the SharePoint functional elements.

noteNote:
Working with .css code in SharePoint can be very challenging because of the sheer volume of .css rules that are applied. With over 5,000 lines of .css code in use at any one time, designers and developers often turn to tools to help them work with .css files in SharePoint. Two such tools are the Internet Explorer 8 Developer Tools20 and the Firebug FireFox plug-in21. Both can be used to inspect and manipulate .css code that is being applied to a webpage (including SharePoint pages). One key feature that is common to both tools is the ability to point to areas of the page and get a better understanding of all of the .css code that is applied to that area, and see which rules are being overridden by the .css cascade.

 

To update the .css code for SharePoint Site Design

  1. Add a color to the a:hover style to ensure that the link hover colors match the rest of the links in SharePoint.
    a:hover {
     color: #0077b4;
     text-decoration: underline;
  2. Add automatic scrolling (overflow:auto) to the main content area.
    noteNote:
    The branding elements will be used throughout SharePoint—including in application pages and in lists—so it can be helpful to add automatic scrolling to the main content area. Adding automatic scrolling enables very wide pages to scroll inside of the branding instead displaying outside of the branding and showing up over the background.

     

    .customMain {
     width: 100%;
     background-color: white;
     min-height: 400px;
     padding:8px 20px;
     width:937px;
     overflow:auto;
    }
  3. Adjust the width of the .customMainRight class. The width for .customMainRight is 760 pixels by default. If left navigation is hidden, the master page or page layout will adjust the width to expand to fill the entire middle area.
    .customMainRight { 
     width:760px;
     padding-bottom:15px;
     float: left;
    }
  4. Remove several existing styles from the HTML mockup for areas that will have specific SharePoint styles added later, including styles for the search, navigation, top navigation, and left navigation. You can remove each of the following classes and all corresponding .css code.
    .menu ul
    .menu ul, .menu li
    .horizontal li
    .customSearch input
    .customSearchGo
    .customSearchGo:hover
    .customTopNavHolder li
    .customTopNavHolder li:hover
    .customTopNavHolder li a
    .customLeftNavHolder li
  5. Add several styles to brand the search area, including hiding the default search button, adding a branded button with a hover, and adding styles for the search box.
    /* search button hider */
    .customSearch .ms-sbgo img {
     display: none;
    }
    
    /* fancy search button */
    .customSearch .ms-sbgo a {
     display: block;
     height:17px;
     width:32px;
     background:transparent url('but_go.gif') no-repeat scroll left top;
     margin: 0px;
     padding: 0px;
     position: relative;
     top: 0px; 
    }
    
    /* search button hover */
    .customSearch .ms-sbgo a:hover {
     background-image: url('but_go_on.gif');
    }
    
    /* search box style */
    .customSearch input.ms-sbplain {
     font-size:1em;
     height:15px;
     margin-right: 5px;
     background-image: none;
     color: #999999;
    }
  6. Add several styles to handle the various top navigation elements, including hiding the default arrows, the item style and hover state, the dynamic flyout holder, and the flyout item and hover state.
    /* arrow for flyouts */
    .menu-horizontal a.dynamic-children span.additional-background,
    .menu-horizontal span.dynamic-children span.additional-background {
     padding-right:0px;
     background-image:none;
    }
    
    /* item style */
    .s4-tn li.static > .menu-item {
     white-space:nowrap;
     border:0px none transparent;
     padding:12px 10px 5px;
     display:inline-block;
     vertical-align:middle;
     color:white;
     font-family:arial,helvetica,sans-serif;
     font-size: 105%;
     font-weight: bold;
     background-image:url('dottedline.gif');
     background-position:right top;
     background-repeat:no-repeat;
     background-color:transparent;
    }
    
    /* item style hover */
    .s4-tn li.static > a:hover {
     color: white; 
     text-decoration: none;
     background-image:url('nav_hover.gif');
     background-position:right top;
     background-repeat: repeat-x;
    }
    
    /* flyout holder */
    .s4-tn ul.dynamic {
     background-color:#1e4b68;
     border:0px none;
    }
    
    /* flyout item */
    .s4-tn li.dynamic > .menu-item {
     display:block;
     white-space:nowrap;
     font-weight:normal;
     background-color: #1E4B68;
     background-repeat: repeat-x;
     padding:4px 8px 4px 10px;
     font-family:arial,helvetica,sans-serif;
     border-top: 0px;
     color: #ffffff;
    }
    
    /* flyout item hover */
    .s4-tn li.dynamic > a:hover {
     font-weight:normal;
     text-decoration:none;
     background-color: #b5d8ee;
     color: #222222;
    }
  7. The left navigation has style applied to only the items in the navigation, not the design. Because the left navigation in Adventure Works Travel will not show flyouts, there are no styles added for those states.
    /* left nav item style */
    .customLeftNavHolder li > .menu-item {
     background-image:url('arrow.gif');
     background-position:left center;
     background-repeat:no-repeat;
     border-bottom:1px solid #ECF0EF;
     padding:4px 0 4px 14px;
    }
  8. The Web Parts in the left column need special styling so that their titles include the branding elements, and to reduce some white space and padding.
    /* Web Part title for left column */
    .customLeftWPHolder .ms-WPTitle {
     color:inherit;
     padding:0px;
     font-family: Arial,sans-serif;
     font-weight: bold;
     font-size: 1.2em;
     margin-bottom: 0;
     text-transform: uppercase;
     background-image:url('ticket_bg.gif');
     background-position:left top;
     background-repeat:no-repeat;
     height:30px;
     line-height:34px;
     padding-left:4px;
    }
    
    /* Web Part padding for left column */
    .customLeftWPHolder .ms-wpContentDivSpace {
     padding: 0px;
    }
    
    /* Remove some white space from Web Parts in left column */
    .customLeftWPHolder .ms-WPHeader .ms-wpTdSpace {
     display:none;
    }
    
    /* remove border from bottom of Web Parts in left column */
    .customLeftWPHolder .ms-WPHeader td {
     border-bottom: none;
    }
  9. After all of the HTML design styles, several SharePoint-specific .css styles are added. Each of the style rules in this section begins with comments that describe its specific usage. The first few were the styles that were included inline in the starter master page.
    /* hide body scrolling (SharePoint will handle) */ 
    body { 
    height:100%; 
    overflow:hidden; 
    width:100%; 
    } 
    /* Pop-out breadcrumb menu needs background color for Firefox */ 
    .s4-breadcrumb-menu { 
    background:#F2F2F2; 
    } 
    /* If you want to change the left navigation width, change this and the margin-left in .s4-ca */ 
    body #s4-leftpanel { 
    padding-right:20px; 
    } 
    /* body area */ 
    .s4-ca { 
    margin-left:auto; 
    } 
    /* Fix scrolling on list pages */ 
    #s4-bodyContainer { 
    position: relative; 
    } 
    /* Fix the font on some built-in menus */ 
    .propertysheet, .ms-authoringcontrols { 
    font-family: Verdana,Arial,sans-serif;; 
    line-height: normal; 
    } 
    /* Nicer border between top bar and page */ 
    .ms-cui-topBar2 { 
    border-bottom: 1px solid #666666; 
    } 
    /* Hide the hover state for the ribbon links */ 
    #s4-ribbonrow a:hover { 
    text-decoration: none; 
    } 
    /* Fix ribbon line height */ 
    #s4-ribbonrow { 
    line-height: normal; 
    } 
    /* Make site settings links look normal */ 
    .ms-linksection-level1 ul li a { 
    font-weight:normal; 
    } 
    /* Hide the left margin when dialog is up */ 
    .ms-dialog .customCentered, .ms-dialog .customMain, .ms-dialog .customMainRight { 
    margin-left:0 !important; 
    margin-right:0 !important; 
    min-height:0 !important; 
    min-width:0 !important; 
    width:auto !important; 
    height:auto !important; 
    background-color: white !important; 
    background-image: none !important; 
    padding: 0px !important; 
    overflow:inherit; 
    } 
    /* Dialog bg */ 
    .ms-dialog body { 
    background-color: white; 
    background-image: none; 
    } 
    /* Fix dialog padding */ 
    .ms-dialog .s4-wpcell-plain { 
    padding: 4px; 
    }

After the last style rules are added to style.css, the .css code for the Adventure Works Travel branding is complete. Check in and publish the style.css file as a major version so that end users can see the changes. Figure 9 shows the much improved SharePoint branding.

Figure 9. Almost completed SharePoint branding job

Almost completed SharePoint branding job

noteNote:
The content part of the page still does not look like the design mockup. This area will be branded with a custom page layout.

 

Creating a Custom Page Layout

Use page layouts as a type of page template in publishing sites to give designers and developers a way to create different types of page designs that will live inside of the master page design. In addition to overriding the content placeholders from the master page, page layouts also define all of the editable content areas of the page with field controls, Web Parts, and Web Part zones. To learn more about the differences between field controls and Web Parts, see Understanding Field Controls and Web Parts in SharePoint Server 2007 Publishing Sites22. Although this article targets Office SharePoint Server 2007, the concepts and capabilities still apply to SharePoint 2010.

Every page layout in SharePoint is created from one specific SharePoint content type. A content type defines all of the site columns that can be used to store data for the page. These site columns make up the available field controls that can be used in the page layout. For simplicity, the Adventure Works Travel page layout will use the existing default Welcome Page content type. This content type has enough site columns to create an Adventure Works Travel page and the existing home page layout can be swapped out easily with the new page layout.

To create the Adventure Works travel page layout

  1. On the Site Objects menu, click Page Layouts.
  2. On the ribbon, click New Page Layout.
  3. In the New page layout window, do the following:
    • For Content Type Group, select Page Layout Content Types.
    • For Content Type Name, select Welcome Page.
    • For URL Name, type AW_Layout.aspx.
    • For Title, type Adventure Works Page.
  4. Click OK.

SharePoint Designer opens the new page layout with the PlaceHolderPageTitle and PlaceHolderMain content placeholders already created.

<asp:Content ContentPlaceholderID="PlaceHolderPageTitle" runat="server"> <SharePointWebControls:FieldValue id="PageTitle" FieldName="Title" runat="server"/> </asp:Content> <asp:Content ContentPlaceholderID="PlaceHolderMain" runat="server">
</asp:Content>

Editing a Page Layout with SharePoint Designer

Next, you will edit the Adventure Works Travel page layout by adding field controls and Web Part zones. You can add these elements easily from specific task panes in SharePoint Designer.

noteNote:
Page layouts must be edited using Advanced Mode in SharePoint Designer 2010. If you attempt to edit a page layout in Normal Mode, all of the content will be highlighted in yellow to indicate that it is not editable. New page layouts are opened automatically in Advanced Mode; when opening existing page layouts, on the ribbon, point to Edit File, and then click Edit File in Advanced Mode.

 

Field Controls

Use the Toolbox pane in SharePoint Designer to add field controls to a page layout. Simply drag the field controls you want to use from the Toolbox pane to the content control that will contain them.

Web Part Zones

To add a Web Part zone to a content control, select the content control in SharePoint Designer by using the Design View or Split View, and then on the ribbon, click Web Part Zone. Adding a Web Part Zone creates an empty Web Part zone that can be given a more useful title to help content authors identify it when editing the page.

Finishing the Adventure Works Travel Page Layout

Finish the page layout for Adventure Works Travel by adding controls, inline styles, and other elements to it.

To finish the Adventure Works Travel Page Layout

  1. Add the PlaceHolderAdditionalPageHead content control and some inline styles to control the width of the left and right areas of the page.
    <asp:Content ContentPlaceholderID="PlaceHolderLeftActions" runat="server"> <div class="customLeftWPHolder"> <WebPartPages:WebPartZone id="LeftZone" runat="server" title="Left Zone"><ZoneTemplate></ZoneTemplate></WebPartPages:WebPartZone>
     </div>
    </asp:Content>
  2. Add the PlaceHolderPageTitle content control to the page layout and add the text Adventure Works – before the PageTitle field control. These actions insert the text before the page title and place all of it into the HTML page title.
    <asp:Content ContentPlaceholderID="PlaceHolderPageTitle" runat="server"> Adventure Works - <SharePointWebControls:FieldValue id="PageTitle" FieldName="Title" runat="server"/>
    </asp:Content>
  3. Add the PlaceHolderPageTitleInTitleArea content control with the TitleField field control inside of it. These controls add the page title before the page content.
    <asp:Content ContentPlaceholderID="PlaceHolderPageTitleInTitleArea" runat="server"> <SharePointWebControls:TextField runat="server" id="TitleField" FieldName="Title"/>
    </asp:Content>
  4. Add the PlaceHolderLeftNavBar to the page to add the Related Links title from the HTML mockup, followed by the left navigation AspMenu and data source that was removed from the starter master page. These additions cause the branded left navigation to appear for pages created from this page layout.
    <asp:Content ContentPlaceholderID="PlaceHolderLeftNavBar" runat="server"> <div class="customTicketTitle"> <h1>RELATED LINKS</h1> </div> <PublishingNavigation:PortalSiteMapDataSource ID="SiteMapDS" runat="server" EnableViewState="false" SiteMapProvider="CurrentNavigation" StartFromCurrentNode="true" StartingNodeOffset="0" ShowStartingNode="false" TrimNonCurrentTypes="Heading"/> <SharePointWebControls:AspMenu ID="CurrentNav" runat="server" EnableViewState="false" DataSourceID="SiteMapDS" UseSeparateCSS="false" UseSimpleRendering="true" Orientation="Vertical" StaticDisplayLevels="1" MaximumDynamicDisplayLevels="0" CssClass="customLeftNavHolder" SkipLinkText="<%$Resources:cms,masterpages_skiplinktext%>"/>
    </asp:Content>
  5. The PlaceHolderMain content placeholder starts with the <WebPartPages:SPProxyWebPartManager /> control, which is added automatically by SharePoint Designer when Web Part zones are being used in a page layout. Next, the Comments field control is added to enable content authors to edit the subtitle of the page. Then, the PublishingPageContent field control is added. This control contains the main publishing HTML content of the page.
    <asp:Content ContentPlaceholderID="PlaceHolderMain" runat="server"> <WebPartPages:SPProxyWebPartManager runat="server" id="ProxyWebPartManager"></WebPartPages:SPProxyWebPartManager> <div class="customSubTitle"> <SharePointWebControls:NoteField FieldName="Comments" InputFieldLabel="SubTitle" DisplaySize="50" runat="server"></SharePointWebControls:NoteField> </div> <PublishingWebControls:RichHtmlField FieldName="PublishingPageContent" runat="server"/>
    </asp:Content>

This is all of the code that is needed to create the Adventure Works Travel page layout. Before content authors can create pages based on this page layout, the page layout must be checked in, published as a major version, and approved.

Changing the Page Layout of a Page

With the custom page layout completed, you can create new pages that are based on it. This is certainly useful for filling the site with new content, but there is still one step that must be completed to make the home page look like the initial design comp. Because the home page is using a default page layout, you need to replace the home page with the custom Adventure Works Travel page layout.

noteNote:
The site template that is used to create the publishing site determines which page layouts are available to select. Depending on which page layout you used to create your publishing site, you may need to change the available page layouts before your new page layout will be available to select. To change the available page layouts, click Site Actions, point to Site Settings, point to Look and Feel, and click Page layouts and site templates. This settings page has an option for Page Layouts from which the available page layouts can be selected. The easiest way to try out a several page layouts, including the new custom page layout, is to select Pages in this site can use any layout, and then click OK.

 

To switch from the home page to the new page layout

  1. Click Site Actions, and then click Edit Page.
  2. On the ribbon, click Page, and the click Page Layout. In the drop-down list under the Welcome Page group, select Adventure Works Page.
  3. The page refreshes and the new page layout is applied to the page, as shown in Figure 10.

Figure 10. Adventure Works Travel home page in edit mode

Adventure Works Travel home page in edit modeFrom here, the page can be edited to include any content, including the subtitle, page content, and any Web Parts. In SharePoint Server 2010, Web Parts do not have to be added to Web Part zones; they can also be added to rich HTML content areas in publishing pages and wiki pages. Figure 11 shows the final page with all of the content from the HTML mockup added.

Figure 11. Adventure Works Travel home page with all content added in edit mode

Adventure Works Travel home page with all contentAfter all of the changes are finalized, just click the small Save icon at the top left of the ribbon or click Page, and then click Save & Close. If the publishing workflow is activated for the pages library, the page must be published and approved before end users will be able to see the new content.

Packaging and Deploying SharePoint Branding

At this point, the Adventure Works Travel site branding is created and applied to an existing SharePoint publishing site. Although creating and applying branding in this way works well for testing demonstration purposes, the next step finalizes the branding work by packaging the branding files (including images, .css files, JavaScript and markup in both the master pages and page layouts) in a way that the branding files can be added to other environments. The final package enables site designers to easily distribute the branding files. The following are a few ways to complete this step.

Branding Deployment Options

To deploy custom branding files, the first option is to simply use the site collection backup and restore. This option is not ideal in an Internet-facing scenario because all of the files will remain as customized files. For more information about the differences and implications of customized and uncustomized files in SharePoint, see Understanding and Creating Customized and Uncustomized Files in Windows SharePoint Services 3.019. When branding files are deployed and managed as customized files, site rebranding campaigns can get complicated. Therefore, an uncustomized branding and management process is preferred, especially for highly trafficked sites and those filled with a significant amount of content.

When deploying uncustomized branding files, publishing site implementers can pick from among a few different options when deciding where to deploy the files. The following are the three most popular and common options:

  • Deploy branding files to the site’s top-level folder.
  • Deploy branding files to the sites _layouts directory.
  • Deploy branding files to the site collection’s content database.

Each of these options has distinct advantages and disadvantages, all addressed in the MSDN article Implementing a Brand in a SharePoint Server 2007 Publishing Site23. The remainder of this article assumes that the last option, deploying branding files to the site collection’s content database, will be used. Deploying branding files to the site collection’s content database makes the maintenance and potential future rebranding campaigns much easier to carry out. All the files will be deployed to the site collection’s master page gallery and Style Library, both found in the root site of all SharePoint publishing site collections.

To deploy branding files to the site collection’s content database, you must provision files into the site collection’s content database–specifically to the Master Page Gallery and Style Library, by using the SharePoint Feature framework. The Feature framework contains a way to create customized and uncustomized instances of files in the SharePoint content database. The source files, including images, .css files, JavaScript libraries, master pages, and page layouts, are deployed as part of the Feature and stay on the file system. When the Feature is activated, it provisions an uncustomized instance of source files to the specified location.

Deploying branding files to the site collection’s content database is usually handled by developers and administrators as it involves putting files on the file system and creating Features and SharePoint solution packages (.wsp files).

SharePoint Brand Packaging and Deployment Process Overview

The packaging and deployment approach selected and demonstrated in the remainder of this article allows each individual responsible for their own area of expertise to focus only on that area. This makes for a much cleaner and smoother process of implementing and deploying a new brand for a publishing site. For example, up to this point this article has addressed two of the three components in building a custom SharePoint brand:

  • Create the brand with SharePoint in mind by taking into account considerations such as the Welcome menu and Site Actions controls.
  • Implement the brand in SharePoint by using master pages and page layouts, by overriding the SharePoint default .css code, and by adding certain JavaScript code to work around some issues that are unique to Internet-facing sites.

These two components are the responsibility of the person who has the role of site and branding designer. The third component is usually served by the role of the site developer who creates the SharePoint Feature and WSP that is used to deploy and provision the files to the site collection. The designer needs to turn the branded publishing site over to the developer for packaging. The site developer pulls the files out of the site collection and adds them to a new Feature, then includes that Feature in a solution package (.wsp file), deploys the .wsp file, and tests the branding files by activating the Feature. If the site designer and developer work in different environments, as is the case when the branding is outsourced, the easiest approach is for the designer to back up the site collection by using Windows PowerShell, send the backup file to the developer, and ask the developer to restore the site collection into a new SharePoint web application.

noteNote:
The remainder of this article assumes that the reader has created two web applications: http://test.adventure-works.com and http://test1.adventure-works.com. The http://test.adventure-works.com web application should be empty, containing no site collections. The http://test1.adventure-works.com web application should contain a single site collection at the root that is based on the Publishing Portal template.

 

Transferring the Branded Site Collection from Designer to Developer

If both the designer and developer work in the same shared environment, there is no need to back up to transfer the site collection from one environment to another. However, if the branding work was outsourced to an outside vendor such as an agency, the developers need an easy way to get a copy of the implemented brand. This is quite easy.

The designers of the site can back up the site collection and send the backup file to the developers. The backup can even be sent through email because it is likely that the site collection is not very big and does not contain any content. Back up the site with Windows PowerShell, as shown in the following example.

PS C:\> $siteCollection = Get-SPSite | Where-Object {$_.Url -eq [URL USED WHEN CREATING AND TESTING THE BRAND]}
PS C:\> Backup-SPSite -Identity $siteCollection -Path "C:\AdventureWorksBranded.dat"

Deliver the c:\AdventureWorksBranded.dat file to the developers. The developers can restore the site into their environment. Microsoft recommends restoring backed-up site collections to the root of a new SharePoint web application that has no other site collections. Restoring backups in this way ensures that there are no possible files in other sites that may be accidentally referenced. To restore the site collection into the http://test.adventure-works.com site, use Windows PowerShell again, as shown in the following code.

PS C:\> Restore-SPSite "http://test.adventure-works.com" -Path "C:\AdventureWorksBranded.dat"

Windows PowerShell prompts you to confirm that you want to restore the site.

When using the backup/restore method to move a site collection from one environment to another, there is one more step that most developers will want to apply. Because the two environments are likely from different domains, the primary site collection administrator is no longer a valid account in the restored environment. Quickly change this in Central Administration by selecting the Site Collection Administrators link on the Application Management page. Select the site collection to which the backed-up site was restored, and change the primary site collection administrator to the account that will be used to log on to and extract files from the site.

Developers now have a local copy of the branded publishing site.

Creating a Visual Studio Project to Hold and Package the Branding File Feature

Now that developers have a local copy of the branded publishing site, the next step is to create the Visual Studio 2010 project that will contain the Feature and that will be used to create the solution package. In Microsoft Visual Studio 2010, Microsoft introduced robust SharePoint development tools to make this task straightforward and easy. The SharePoint development tools in Visual Studio 2010 are included in the Visual Studio 2010 installation.

To extract branding files from the branded sample publishing site collection and add them to the Visual Studio project

  1. Create a new SharePoint 2010 project in Visual Studio 2010 by using the Empty SharePoint Project template, making sure you select the .NET Framework 3.5 as the target framework version.
  2. When prompted by Visual Studio 2010 in the SharePoint Customization Wizard, pass in the site collection URL (http://test1.adventure-works.com) to test the project against, and specify it as a Farm solution.
  3. Add the containers for the files to the Visual Studio project.
  4. Copy the files from the publishing site to the Visual Studio project.
  5. Modify the project file to include all of the added files.
  6. Add the Style Library files.
  7. Add the files in the Master Page Gallery.

Add the Style Library files.

Adding Style Library Files to Visual Studio

Copy the files from the publishing site’s Style Library into the project. Open the Style Library in the browser, switch to Explorer view, and copy-and-paste the files into Visual Studio.

To add files from the SharePoint Style Library to Visual Studio

  1. Set up the Visual Studio project container, or module, for the files in the Style Library. Right-click the project name, click Add, then click New Item.
  2. In the Add New Item dialog box, select Module from the SharePoint/2010 category and name it StyleLibraryModule.
  3. In Solution Explorer, delete the sample.txt file from the StyleLibraryModule, because it is simply a placeholder file.

To copy files from the Style Library into the project

  1. In the browser, open http://test.adventure-works.com.
  2. On the Site Actions menu, click Manage Site Content and Structure.
  3. In the left folder view, hover over the Style Library and use the Edit Control Block (ECB) menu to select Open link in new window.
  4. Double-click the AdventureWorks node in the Style Library, and then on the ribbon, click Library on the Library Tools menu. From the Connect & Export group, open the project with Windows Explorer.
  5. Copy all of the files in the AdventureWorks node in Windows Explorer and paste them to the StyleLibraryModule in the Visual Studio project.

 

<Module Name="StyleLibraryModule" Url="/Style Library/AdventureWorks" RootWebOnly="TRUE">

Now, each file that will be provisioned into the Style Library must be added to the Module element as a child File element. Each entry should specify the name of the file and the Type of file to be provisioned. The two Type options are Ghostable and GhostableInLibrary. Both provision an uncustomized instance into the site collection, but because these files must be registered as content within the Style Library, set the type to GhostableInLibrary. In addition, the Url attribute of each File element must be updated so that the files are placed in the location specified by the Module element. To update the Url attribute, remove the subfolder specified in the Url attribute by updating the Module element to the following markup.

<?xml version="1.0" encoding="utf-8"?> <Elements xmlns="http://schemas.microsoft.com/sharepoint/"> <Module Name="StyleLibraryModule" Url="Style Library/AdventureWorks" RootWebOnly="TRUE"> <File Path="StyleLibraryModule\bg.gif" Url="bg.gif" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\but_go.gif" Url="but_go.gif" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\but_go_on.gif" Url="but_go_on.gif" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\dottedline.gif" Url="dottedline.gif" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\favicon.ico" Url="favicon.ico" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\footer_bg.png" Url="footer_bg.png" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\glory.jpg" Url="glory.jpg" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\logo.png" Url="logo.png" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\microsoft_logo.gif" Url="microsoft_logo.gif" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\nav_hover.gif" Url="nav_hover.gif" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\style.css" Url="style.css" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\ticket_bg.gif" Url="ticket_bg.gif" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\wp_topactivities.jpg" Url="wp_topactivities.jpg" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\wp_tripplanner.jpg" Url="wp_tripplanner.jpg" Type="GhostableInLibrary" /> <File Path="StyleLibraryModule\arrow.gif" Url="arrow.gif" Type="GhostableInLibrary" /> </Module> </Elements>

Next, add files in the master page gallery.

Adding Files to the Master Page Gallery

The other files required for deploying the Adventure Works Travel custom brand are in the master page gallery. There are two files in this gallery that need to be moved:

  • AdventureWorks.master, which is the custom master page that is used to implement the brand.
  • AW_layout.aspx, which is the page layout that is based on the default Welcome Page content type used for the site home page.

To add files from the SharePoint Master Page Gallery to Visual Studio

  1. Set up the Visual Studio project container, or module, for the files in the Style Library. Right-click the project name, click Add, then choose New Item.
  2. In the Add New Item dialog box, select Module from the SharePoint/2010 category, and then name it MasterPageGalleryModule.
  3. In Solution Explorer, delete the sample.txt file from the MasterPageGalleryModule, because it is simply a placeholder file.

Now files can be retrieved from the site collection and added to the Visual Studio project.

To download the master page and page layout

  1. In the browser, open http://test.adventure-works.com.
  2. On the Site Actions menu, click Site Settings. In the Galleries section, select Master pages and page layouts.
  3. Download copies of the two files AdventureWorks.master and AW_layout.aspx. To do this, select the item and on its drop-down menu, point to Send To, and then click Download a Copy. Save both files to your desktop.
  4. Using Windows Explorer, copy both files to the StyleLibraryModule in the Visual Studio project.
  5. To provision the three files into the master page gallery, modify the Elements.xml file in the path MasterPageGalleryModule\Elements.xml.
    <?xml version="1.0" encoding="utf-8"?> <Elements Id="94022f3a-580a-4745-9d9c-42c21f79fdfe" xmlns="http://schemas.microsoft.com/sharepoint/"> <Module Name="MasterPageGalleryModule" Url="_catalogs/masterpage" RootWebOnly="TRUE"> </Module> </Elements>
  6. Add the following markup after the opening <Module> tag to provision the master page.
    noteNote:
    Provisioning master pages requires the module to specify additional fields, such as which content type to associate with the master page file when it is provisioned.

     

    <File Url="AdventureWorks.master" Path="MasterPageGalleryModule\AdventureWorks.master" Type="GhostableInLibrary"> <Property Name="ContentType" Value="$Resources:cmscore,contenttype_masterpage_name;" /> <Property Name="Title" Value="Adventure Works Travel Custom Branding" /> </File>
  7. Add the page layout. As with the master page, you must set additional properties. However, the page layout uses a different content type than the master page and also needs to specify the content type that the page layout is associated with by using the PublishingAssociatedContentType attribute.
  8. Add the following markup after the master page’s <File /> tag.
    <File Url="AW_layout.aspx" Path="MasterPageGalleryModule\AW_layout.aspx" Type="GhostableInLibrary"> <Property Name="ContentType" Value="$Resources:cmscore,contenttype_pagelayout_name;" /> <Property Name="PublishingAssociatedContentType" Value=";#Welcome Page;#0x010100C568DB52D9D0A14D9B2FDCC96666E9F2007948130EC3DB064584E219954237AF390064DEA0F50FC8C147B0B6EA0636C4A7D4;#" /> <Property Name="Title" Value="Adventure Works Travel Branded Welcome Page" /> </File>

At this point, the Visual Studio project is complete and contains all of the files that should be provisioned to the Master Page Gallery and Style Library.

Packaging, Deploying, and Testing the Branding Feature

Verify that the Feature automatically created by the SharePoint development tools in Microsoft Visual Studio 2010 is configured correctly. In Solution Explorer in vsstudio2010short, double-click the AdventureWorksBranding\Features\Feature1\Feature1.feature file to open the Feature designer. Notice that the Scope is currently set to Web. Change the Scope to Site because this Feature must appear on the Manage Site Collection Features page. Also notice that the two items in the Feature are the two modules you created.

Now that the Visual Studio project is complete, you can package, deploy, and test the new branding Feature. Test the branding Feature by creating a clean Publishing Portal site collection at the root of a new web application. The reason to create a new web application and Publishing Portal site collection is to eliminate the chance that any of the files are referencing files in the restored site collection (such as images or .css files). For the following test, the Publishing Portal template was used to create a new web application, http://test1.adventure-works.com, with a new site collection created at the root of the web application.

To test the new branding feature

  1. In Visual Studio 2010, press F5 to compile, package, deploy, and activate the feature.
  2. Navigate to http://test1.adventure-works.com, point to Site Actions, point to Site Settings, and then click Modify All Site Settings.
  3. Switch the master page by selecting Master page in the Look and Feel group and set the Site Master Page to AdventureWorks.master.
  4. Go back to the home page of the site and verify that the new branding is being used. Just like before, the page will look a bit strange because it is not using the page layout that the branding Feature deployed.
  5. Update the page so that it is using the correct page layout by navigating to the Site Actions menu and clicking Edit Page.
  6. Use the ribbon to switch the page layout: point to Page, and from the Page Actions group, choose Page Layout, and then select the Adventure Works Travel Branded page layout from the Welcome Page section.
  7. To deploy the branding in other environments, look in the \bin\debug folder of the Visual Studio project for the *.wsp file. This is the solution package file that contains the Feature that provisioned all of the branding files into the publishing site collection.

Conclusion

This article explains the entire process of branding a Microsoft SharePoint Server 2010 publishing site with a custom design. First, the article steps the site designer through the process for developing a brand for a new SharePoint publishing site, including examining issues that are unique to publishing sites and the SharePoint-specific controls. Next, the article describes how to convert the design comps from prototypes into a real implementation of a branded publishing site that uses master pages, page layouts, CSS, and images. Finally, the article describes how to take the branded publishing site and convert it to a Feature that makes the brand easier to maintain in the future. This is done by using the SharePoint development tools in Visual Studio 2010 and creating a new project that provisions all of the files involved in a custom brand.

Additional Resources

Change History

Date Description
November 2010 Initial publication
Links Table

Virtualized High Availability and Disaster Recovery Solutions Microsoft Hyper-V on the IBM System Storage™ DS5000, IBM System x™ Servers, & IBM BladeCenter Highlights

Virtualized High Availability and Disaster Recovery Solutions Microsoft Hyper-V on the IBM System Storage™ DS5000, IBM System x™ Servers, & IBM BladeCenter Highlights

 

 

Windows Server 2008 and Hyper-V with MSCS failover cluster support provides efficient high availability

 

 

Quick migration of Hyper-V guest machines between IBM HS21XM

 

Blades with automatic fail-over

 

 

Optimized disaster recovery with the flexibility of virtualization and efficiency of the IBM BladeCenter, System x 3850 M2 and the DS5000 modular storage system

 

 

Reliable replication of data between sites with the IBM DS5000 and Remote Volume Mirroring

 

IBM DS5000

 

 

A robust, yet easy to manage & configure HA/DR

 

scenario

 

Today’s virtualization solutions help customers reduce datacenter complexity and management costs, providing dynamic and flexible configurations across multiple resources. Companies of all sizes are interested in energy and space efficiency, centralized management, and flexible disaster recovery options to reduce their total cost of ownership. High availability and disaster recovery are two key areas virtualization can offer significant flexibility and cost savings. By leveraging IBM servers and storage with Microsoft Hyper-V and Windows Server 2008, organizations are equipped to streamline their IT infrastructure for maximum efficiency.

 

The Solution – Implementing Hyper-V for high availability and disaster-recovery scenarios, using the IBM System Storage DS5000, System x3850 M2, and BladeCenter servers with Hyper-V. This reference architecture outlines one possible solution for intra-site high availability and inter-site disaster recovery scenarios. The configuration includes simulation of 2 geographically dispersed sites, with local site HA provided by 2 MSCS failover clustered HS21XM Blade servers hosting multiple Hyper-V virtual machines. The DR simulation consists of Remote Volume Mirror LUN replication between the two sites, with the capability of bringing the Hyper-V virtual machines online at the second site if the main datacenter goes down or is otherwise unavailable. Remote Volume Mirroring is a premium feature of the IBM System Storage DS5000. Data replication and control is handled by the array controllers over replication links with little or no impact on host applications. Advanced features such as ordered-writes and consistency group support help ensure that complex application LUN layouts and database integrity are preserved. Figure 1 below shows the FC SAN logical design:

 

Figure 1)

 

FC solution design for RVM.

 

Hyper-V virtual servers run as cluster resources, and automatically fail over if one host node is unavailable. These virtual machines can also be quickly migrated between the cluster nodes, pausing running applications and resuming automatically once online. In a DR event, replicated LUNS and guest are manually activated and brought online. Figure 2 below highlights the logical view of the solution:

 

Figure 2)

 

Hyper-V logical HA/DR solution view

Each of the two blades at the primary site host multiple Hyper-v guest machines (VM1, VM2, and VM3). The secondary site also runs Hyper-V guests (VM4, VM5, and VM6). In the event of a failure of one of the computer nodes at the primary site, the guests are automatically migrated to the surviving node. The primary site remains online. Guest LUNs on the primary site are replicated via RVM to the secondary site. Figure 3 below shows a localized server failure:

 

Figure 3)

 

Localized server failure.

In the event of a local site failure, if the entire BladeCenter or DS5000 goes offline within the primary site, Hyper-V guest machines are restarted on the System x3850 M2 at the secondary site. Replicated data will be in a crash-consistent state, and application recovery methods (i.e. log replay) are activated. In a manual fail over (i.e. for maintenance), this would not need to occur. Once the LUN’s are enabled read/write & mapped to the relocated Hyper-V guests, the applications are restarted and service resumes. Figure 4 below shows a complete site failure example.

 

Figure 4) Primary site failure.© 2008 IBM CorporationIBM Systems and Technology GroupLogical ViewDS5000 DS5000 System x 3850 M2Primary SiteSecondary SiteVM 1VM 2VM 3VM 1VM 2VM 3Hyper-VRemote Volume Mirror -RVMVM 4VM 5VM 6VM 4VM 5VM 6HS21HS21SwitchSwitchHyper-VHyper-VMS Cluster ServerSite failure! Primary site goes offline.Hyper-V guests restarted at secondary site.

In the event of an outage at the secondary site, as shown in Figure 5 below, the reciprocal process to the primary site failure would occur, and Hyper-V guests would be manually restarted at the primary site.

 

Figure 5) Secondary site failure.© 2008 IBM CorporationIBM Systems and Technology GroupLogical ViewHS21HS21DS5000 SwitchSwitchDS5000 System x 3850 M2Primary SiteSecondary SiteHyper-VHyper-VMS Cluster ServerVM 1VM 2VM 3VM 1VM 2VM 3Hyper-VRemote Volume Mirror -RVMVM 4VM 5VM 6VM 4VM 5VM 6Site failure! Secondary site goes offline.Hyper-v guests restarted at primary site.

Since Hyper-V uses the familiar MMC 3.0 framework, Windows administrators can manage the virtualized, clustered environment in a familiar environment. Furthermore, the DS5000 Storage Manager GUI is easy to configure & manage even in complex HA/DR scenarios such as RVM. Figure 6 below shows a clustered Hyper-V MMC:

 

Figure 6)

 

FCM MMC panel. Microsoft’s Hyper-V, included with Windows Server 2008, provides software infrastructure and management tools that you can use to create and manage a virtualized server computing environment for consolidated and scalable data centers.

Key features of Hyper-V include:

•64-bit native hypervisor-based virtualization

•Ability to run 32-bit and 64-bit virtual machines concurrently

•Large virtual machine memory support and Virtual LAN support

•Virtual machine snapshots, to capture the state of a running virtual machine so you can revert the virtual machine to a previous state quickly & easily.

 

Runs on all roles including Server Core, of Windows Server 2008

•Hyper-V leverages Microsoft Cluster Services for failover cluster support

•Microsoft Management Console (MMC) 3.0 interface

 

The NEW IBM System Storage DS5000

 

sets new standards for performance, scalability, reliability, availability, and flexibility for midrange storage systems. As IBM’s most powerful midrange storage system, the DS5000 is the ideal platform for a virtualized environment that can keep pace with your business growth. Organizations can buy only the capacity needed initially, and can then dynamically upgrade and reconfigure additional capacity & features later to meet changing business requirements, all without any system downtime. The DS5000 delivers class-leading performance and is equally adept at supporting transactional-applications, such as databases and OLTP, throughput-intensive applications, such as HPC and rich media, and concurrent workloads, well-suited for consolidation and virtualization. With its relentless performance and architected to provide the highest reliability and availability, the DS5000 storage system is comfortable supporting the most demanding service level agreements (SLAs). And when requirements change, the DS5000 can easily be reconfigured “on-the-fly” to add or replace host interfaces, increase performance, grow capacity, or add cache – ensuring it keeps pace with your growing company. DS5000 key features:

 

Flexible host interface options are 8 Gb/s Fibre Channel and 10 Gb/s iSCSI ready

•Sixteen 4 Gb/s Fibre Channel drive interfaces for support up to 256 drives in initial release, with future support for 448 FC/SATA drives, using EXP5000/EXP810 drive expansion units.

•Up to 16 GB of dedicated data cache (8 GB per controller) in initial release, with future support for 32 GB. Dedicated cache mirroring channels and persistent cache backup in the event of a power outage

•Support for RAID 6, 5, 3, 10, 1, 0

•Two performance levels (base and high) with ability to field-upgrade

– Base model is DS5100 – High model is DS5300

•Remote Volume Mirroring and FlashCopy premium features for Volume Shadow Copy (VSS) supported backups and flexible DR scenarios

•Break-through performance levels over 5X greater than the DS4800

System x3850 M2 and x3950 M2 key features:

•True 2–to–16-socket scalability up to 64 cores

•Revolutionary Intel Xeon dual-core and quad-core MP

7300 Series processors

•Up to 1TB of registered DIMM memory for better workload

density and up to 20–30% less power consumption than competitors’ fully buffered DIMM technology*

•IBM Memory ProteXion™with redundant bit-steering offers twice the memory resilience of the competition

•4th generation snoop filter 4 times larger than the competition’s best

•IBM Predictive Failure Analysis

 

®, not just on hard drives and memory but, unlike competitors, also on processors, power supplies, fans, and voltage regulator modules

•40% lower memory latency than the nearest competition

•More flexible memory configurations than competitors, at significantly lower costs

The IBM System x3850 M2 and x3950 M2 servers provide an uncomplicated, cost-effective and highly flexible solution. With the ability to scale while maintaining balanced performance between processors, memory and I/O, these servers can easily accommodate business expansion and the resulting need for additional application space.

 

BladeCenter key features: The IBM BladeCenter H delivers high performance, extreme reliability, and ultimate flexibility to even the most demanding IT environments. In 9 U of rack space, the BladeCenter H chassis can contain up to 14 blade servers, 10 switch modules, and four power supplies to provide the necessary I/O network switching, power, cooling, and control panel information to support the individual servers. The chassis supports up to four traditional fabrics using networking switches, storage switches, or pass-through devices. The chassis also supports up to four high-speed fabrics for support of protocols like 4X InfiniBand or 10 Gigabit Ethernet. The built-in media tray includes light path diagnostics, two front USB inputs, and an optical drive.

•Dense, space-saving 9U chassis

•Up to 14 blades in a chassis

•IBM Cool Blue

 

® technology

•Energy-efficient design

•IBM Open Fabric

•Powerful solutions management

•High-availability midplane

•Hot-swappable, redundant management, switch, power supply

and blower modules

•New high-speed switch module support

•New high-speed bridge module bays

•Advanced server management

•IBM Remote Deployment Manager

•Light path diagnostics self-diagnosis panel

•Predictive Failure Analysis

•9.5 mm UltraSlim DVD

•3-year customer replaceable unit and onsite limited warranty

Emulex LightPulse

 

 

® IBM Qualified 43W6859 (LP1105-BCX) and 42D0494 (LPe12002) Fibre Channel host bus adapters (HBAs) provide streamlined installation and management, outstanding scalability and industry-leading virtualization support well-suited for small-to-large enterprises and Microsoft Windows Server 2008 and Hyper-V storage area network (SAN) environments. With powerful management tools and broad System x and BladeCenter support, the LightPulse family of IBM-branded 4Gb/s and 8Gb/s HBAs (IBM Server Proven Validation) delivers high performance for a broad range of applications and environments. Emulex HBA key features:

 

•xceptional performance and full-duplex data throughput

•omprehensive virtualization capabilities with support for N-Port ID Virtualization (NPIV)

•implified installation and configuration using AutoPilot Installer

 

®


Administration via HBAnyware

 

® integrated with IBM Director Conclusion – Putting it all together – Microsoft’s Hyper-V ushers in a new era of application virtualization affordably to the masses, offering new opportunities for increased resource utilization, ease of management, and improved ROI. IBM has worked closely with Microsoft to ensure our products are optimized for Hyper-V deployments. Together with the new System Storage DS5000, the ability for companies of all sizes to implement a highly-available and disaster-tolerant computing environment has never been easier.

A full solution whitepaper will be available on the IBM ISV Solution website by Q408: http://www-03.ibm.com/systems/storage/solutions/isv/index.html#microsoft

Copyright © 2008 by International Business Machines Corporation. This document could include technical inaccuracies or typographical errors. IBM may make changes, improvements or alterations to the products, programs and services described in this document, including termination of such products, programs and services, at any time and without notice. Any statements regarding IBM’s future direction and intent are subject to change or withdrawal without notice, and represent goals and objectives only. The information contained in this document is current as of the initial date of publication only, and IBM shall have no responsibility to update such information. Performance data for IBM and non-IBM products and services contained in this document was derived under specific operating and environmental conditions. The actual results obtained by any party implementing and such products or services will depend on a large number of factors specific to such party’s operating environment and may vary significantly. IBM makes no representation that these results can be expected or obtained in any implementation of any such products or services. THE INFORMATION IN THIS DOCUMENT IS PROVIDED “AS-IS” WITHOUT ANY WARRANTY, EITHER EXPRESS OR IMPLIED. IBM EXPRESSLY DISCLAIMS ANY WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE OR INFRINGEMENT. References in this document to IBM products, programs, or services does not imply that IBM intends to make such products, programs or services available in all countries in which IBM operates or does business. Any reference to an IBM program or product in this document is not intended to state or imply that only that program or product may be used. Any functionally equivalent program or product, that does not infringe IBM’s intellectually property rights, may be used instead. It is the user’s responsibility to evaluate and verify the operation of any non-IBM product, program or service. The provision of the information contained herein is not intended to, and does not grant any right or license under any IBM patents or copyrights. Inquiries regarding patent or copyright licenses should be made, in writing, to: IBM Director of Licensing IBM Corporation North Castle Drive Armonk, NY 10504-1785 U.S.A. IBM, the IBM logo, System x, and System Storage are trademarks or registered trademarks of International Business Machines Corporation in the United States, other countries or both. Microsoft and Windows are trademarks of Microsoft Corporation in the United States, other countries or both.