none
project server 2013 active directory sync; SecurityInvalidUserUidRef (19083) RRS feed

  • Question

  • i am running "SPProjectActiveDirectoryGroupSync" in project server 2013 and getting following error with timer job at "0%".

    Datasets:

    • SecurityGroupsDataSet
      • Table GroupMembers
        • Row: RES_UID='ffde1fce-bab9-e311-ab93-00505699004d' WSEC_GRP_UID='fa8bbbfa-be8d-e311-816e-00505699001f'
          • Error SecurityInvalidUserUidRef (19083) - column
        • Row: RES_UID='00df1fce-bab9-e311-ab93-00505699004d' WSEC_GRP_UID='fa8bbbfa-be8d-e311-816e-00505699001f'
          • Error SecurityInvalidUserUidRef (19083) - column
        • Row: RES_UID='01df1fce-bab9-e311-ab93-00505699004d' WSEC_GRP_UID='fa8bbbfa-be8d-e311-816e-00505699001f'
          • Error SecurityInvalidUserUidRef (19083) - column
        • Row: RES_UID='02df1fce-bab9-e311-ab93-00505699004d' WSEC_GRP_UID='fa8bbbfa-be8d-e311-816e-00505699001f'
          • Error SecurityInvalidUserUidRef (19083) - column
        • Row: RES_UID='03df1fce-bab9-e311-ab93-00505699004d' WSEC_GRP_UID='fa8bbbfa-be8d-e311-816e-00505699001f'
          • Error SecurityInvalidUserUidRef (19083) - column

    General

    • Queue:
      • GeneralQueueJobFailed (26000) - AdSyncGroup.AdSyncGroupMessage. Details: id='26000' name='GeneralQueueJobFailed' uid='31bbffe4-bab9-e311-ab93-00505699004d' JobUID='f3d7c52d-b6b9-e311-abe0-00505699004b' ComputerName='f8565632-aa21-4c90-a27e-9854cebb33d2' GroupType='AdSyncGroup' MessageType='AdSyncGroupMessage' MessageId='1' Stage='' CorrelationUID='e602839c-0a25-e048-91c7-0d4a77377fd3'. For more details, check the ULS logs on machine f8565632-aa21-4c90-a27e-9854cebb33d2 for entries with JobUID f3d7c52d-b6b9-e311-abe0-00505699004b.

    based on the above message i can find WSEC_GRP_UID='fa8bbbfa-be8d-e311-816e-00505699001f' this is one of the groups we are having issue syncing, but do not find RES_UID='ffde1fce-bab9-e311-ab93-00505699004d' in any of the tables.

    Can any one tell me what does SecurityInvalidUserUidRef (19083) error mean and in which tables would i find this RES_UID?

    Sunday, April 6, 2014 5:12 PM

All replies

  • Use following query to find out Resource name and then remove this resource from Active Directory group before trying resynchronizing again

    Select ResourceName, ResoruceUID from dbo.MSP_epmresoruce where ResourceUID='ffde1fce-bab9-e311-ab93-00505699004d'


    SELECT RES_Name,Res_UID from pub.msp_resources where RES_UID='ffde1fce-bab9-e311-ab93-00505699004d'


    Hrishi Deshpande Senior Consultant

    Monday, April 7, 2014 4:07 PM
    Moderator
  • No results found for both of these queries.  these Res_UID are not found in any of the tables.  Also these ID change on each sync.  A detailed uls for current sync is like this

    b0ry       Medium               PWA:https://projectcentralqa.ampf.com/PWA, ServiceApp:ProjectServerServiceApp, User:i:0#.w|afii\pshah117, PSI: [ProjectServerError] Mismatched Attributes for PSErrorID SecurityInvalidUserUidRef. List of defined attributes: none. List of provided values: RES_UID, ef507066-71be-e311-ab93-00505699004d., LogLevelManager Warning-ulsID:0x62307279 has no entities explicitly specified.     6ef1849c-0a6d-e048-f944-41a68accb7fb

    04/07/2014 12:26:45.59 Microsoft.Office.Project.Server (0x0984)              0x2704  Project Server                   General                                       b0ry       Medium               PWA:https://projectcentralqa.ampf.com/PWA, ServiceApp:ProjectServerServiceApp, User:i:0#.w|afii\pshah117, PSI: [ProjectServerError] Mismatched Attributes for PSErrorID SecurityInvalidUserUidRef. List of defined attributes: none. List of provided values: RES_UID, f0507066-71be-e311-ab93-00505699004d., LogLevelManager Warning-ulsID:0x62307279 has no entities explicitly specified.     6ef1849c-0a6d-e048-f944-41a68accb7fb

    04/07/2014 12:26:45.59 Microsoft.Office.Project.Server (0x0984)              0x2704  Project Server                   General                                       b0ry       Medium               PWA:https://projectcentralqa.ampf.com/PWA, ServiceApp:ProjectServerServiceApp, User:i:0#.w|afii\pshah117, PSI: [ProjectServerError] Mismatched Attributes for PSErrorID SecurityInvalidUserUidRef. List of defined attributes: none. List of provided values: RES_UID, f1507066-71be-e311-ab93-00505699004d., LogLevelManager Warning-ulsID:0x62307279 has no entities explicitly specified.     6ef1849c-0a6d-e048-f944-41a68accb7fb

    04/07/2014 12:26:45.59 Microsoft.Office.Project.Server (0x0984)              0x2704  SharePoint Foundation                 Monitoring                                    nasq      Verbose               Entering monitored scope (Project Server SubDal:FillTypedDataSet -- [pub].MSP_ADMIN_ReadAdSyncSettings(StoredProcedure)). Parent ExecuteGroupsSync          6ef1849c-0a6d-e048-f944-41a68accb7fb

    04/07/2014 12:26:45.59 Microsoft.Office.Project.Server (0x0984)              0x2704  SharePoint Foundation                 Monitoring                                    ac2zs     Verbose               Write Debug Scope start event Project Server SubDal:FillTypedDataSet -- [pub].MSP_ADMIN_ReadAdSyncSettings(StoredProcedure) Id:4263596326388802 Parent ID:4263596326387734                6ef1849c-0a6d-e048-f944-41a68accb7fb

    04/07/2014 12:26:45.60 UMT.CostModule.QueueService.exe (0x1E6C)  0x130C  SharePoint Foundation                 Topology  

     

    Help is highly appreciated.

    Monday, April 7, 2014 5:06 PM
  • There are about 21 groups.

    Actually the message shown is only an xml, so the RES_UID  are not seen in any of the sql tables.  So i turned verbose on logs and the res_uid are found in logs only and also the user name.

    After removing those users from AD group the sync worked fine.

    Issue resolved.

    Tuesday, April 8, 2014 7:44 PM
  • Glad to hear that your issue has been resolved.

    Thanks for the info


    Hrishi Deshpande Senior Consultant

    Tuesday, April 8, 2014 7:46 PM
    Moderator
  • Hi, I have the same issue, and it is really so. But what to do if the user is disabled in AD just for a short period, for example when on vacation or sick? User should be in group to have an access to pwa when account is enabled, but sync totally fails when account is disabled.


    Thursday, May 7, 2015 3:05 AM