Sunday, July 17, 2011

Migrate Access 2000 or Later Databases to Public or Private Rollbase Clouds

imageNow that Office 365 has been released to the Web (RTW) for commercial use, there is considerable interest in taking advantage of SharePoint Online’s Access Services to create Web-based data management applications (Access Web Databases) at a monthly cost of US$6 per user. An advantage of this approach is that Access Services supports migration of tables, queries, forms and macros to SharePoint lists, Web pages and workflows. Alternatively, you can move just the Access tables to SharePoint Online and link them to on-premises Access front-ends. Optional local data caching improves data access performance and enables offline data entry. You can learn more about migrating Access 2010 applications to SharePoint Online in my May 2011 Webcast.

imageNote: The current version of Office 365’s Access Services doesn’t support reports. If you need printed reports, Access Hosting offers hosted SharePoint 2010 for up to 10 users at a flat rate of US$99 per month. Access Hosting offers many advantages over SharePoint online, as described here (scroll down.) My Upsizing the Northwind Web Database to an Updated SharePoint 2010 Server Hosted by AccessHosting.com post contains links to my March 2011 Webcast about the topic.

imageRollbase is a cloud application platform, which includes a wizard for importing Access 2000 or later *.mdb and Excel *.xls and *.csv files into Rollbase Objects and Fields to create Rollbase Applications for the Web. Rollbase’s primary claims to fame are its reported capability to import Salesforce and Force.com applications and availability in public and private cloud versions. There’s no indication on the Rollbase site of support for importing Access objects other than tables. Hosted applications are US$15 per month per user.


P.S.: Bruce Kyle reported 200 Sessions Announced for SharePoint Conference 2011 in a 7/17/2011 post to MSDN’s US ISV Evangelism blog:

imageSharePoint Conference 2011 is your only opportunity this year to see over 200 sessions focused on SharePoint 2010 and related technologies both in the cloud and on-premises. All current session content including abstracts and speakers have been posted to www.mssharepointconference.com!

The conference will be held in Anaheim, CA on October 3 – 6.

imageThis year’s conference will have a breadth of both technical and non-technical sessions and will have suitable topics for everyone regardless if you are new to SharePoint 2010 or working on continuing your SharePoint education.

SPC11 will provide you with the training, insight, and networking you need to develop, deploy, govern and get the most from SharePoint. You’ll also hear from Microsoft Engineers, Product Managers, MCMs and MVPs who will discuss topics such as cloud services, best practices and real world project insights.

imageDon’t miss your chance to attend and learn from these sessions by registering now! Conference registration is only $1,199 and seats are selling fast with only 2.5 months until the event!

Pre & Post Conference Training Opportunities

SharePoint Conference announces five ancillary conference training opportunities with limited space! Act fast before space sells out!

To view more information on each session below click on the training title to learn more about the session including abstracts, agendas, speakers, costs and maximum attendance. Register now to reserve your seat!

Sunday, October 2
Thursday, October 6 (2pm-6pm)
Friday, October 7

Saturday, July 9, 2011

Problem Reported with Access Wizards and 64-bit Access 2010 SP1

Stephen Thomas suggested Using 64-bit Access 2010? You may want to wait on [Installing] SP1 in a 7/8/2010 post to the Access blog:

A customer's post on TechNet brought one of my colleague's attention to an error folks are seeing after applying SP1 to 64-bit Access installations and then trying to use a wizard:

The database cannot be opened because the VBA project contained in it cannot be read. ... To open the database and delete the VBA project without creating a backup copy, click OK.

On clicking OK, Access doesn't open the database, offering this error message:

The code contains a syntax error, or a <DB_NAME> function you need is not available. If the syntax is correct, check the Control Wizards subkey or the Libraries key in the <DB_NAME> section of the windows registry to verify that the entries you need are listed and available.

Apparently, the VBE7.DLL file update included in the service pack prevents the opening of .ACCDE files compiled using RTM 64-bit Access. Because wizards are .ACCDE files, they could trigger the error depending on when they were compiled.

The customer who posted reports that uninstalling the service pack restores the functionality, and advises that people with 64-bit Access wait until a solution is provided before applying SP1. TechNet agrees (the mod marked it as an Answer), and so do I.

Stay tuned for that solution…

Forewarned is forearmed.


Thursday, June 30, 2011

New Substitute for the Access Upsizing Wizard Announced

OneNumbus and Jasco posted Introducing Jasco® 2SQL™ Azure™ about a service for converting Access databases to SQL Azure (and SQL Azure) on 6/30/2011:

image_thumb[2]Help enable your employees to easily access up-to-date information for more effective decision making.

imageJasco 2SQL quickly and securely migrates mission critical data to Microsoft SQL Server or Microsoft Azure, which helps ensure your data can be used more effectively across your organisation and remains accessible to your users.

imageSounds to me like a pricey replacement for the Microsoft Access Upsizing Wizard and Access Data Projects (ADPs). It appears that Microsoft has informally deprecated ADPs, so perhaps 2SQLAzure has a chance of success.

For more details about moving Access tables to SQL Server and SQL Azure, see my Bibliography and Links for My “Linking Access tables to on-premise SQL Server 2008 R2 Express or SQL Azure in the cloud” Webcast of 4/26/2011 post of 4/24/2011.

Wednesday, June 29, 2011

New Office 365 Developer Training Course Includes Updated Access Services Unit

Chris Mayo posted Office 365 is Now Available! to his SharePoint Development in the Cloud blog on 6/28/2011:

imageOffice 365 was released to General Availability today with Steve Ballmer hosting the worldwide launch event in New York City. With this release, Office 365 (including SharePoint Online, Exchange Online, Lync Online and Office 2010 Professional Plus) can now be purchased directly from the Office 365 web site.

imageTo coincide with the launch, I’m happy to announce an updated Office 365 Developer Training Course to help you get started building solutions for the cloud with Office 365. The course includes 8 sessions, over 12 hours of video and 19 labs as both an offline training kit as well as an online training course on MSDN.

The Office 365 Developer Training Course includes the following training units:

  • Developing in the Cloud with Office 365 (Updated)
    • Office 365 provides a communication and collaboration service in the cloud that you can leverage to build custom solutions for SharePoint Online, Exchange Online and Lync Online. In this session, you’ll learn about this new cloud service and the breadth of solutions that can be developed using the same skills, tools and SDKs you use today when building on-premises solutions.
  • Developing for SharePoint Online with Sandbox Solutions (Updated)
    • Sandboxed Solutions are the development paradigm for SharePoint Online. In this session, you’ll learn about sandboxed solutions including how to develop, debug and deploy solutions. You’ll also learn the breadth of solutions that can be developed in the sandbox and strategies for developing common scenarios that are not enabled in the sandbox.
  • Building Workflow Solutions for SharePoint Online (Updated)
    • Building Workflow solutions for SharePoint Online allows you to automate
      collaboration-centric business processes and surface them to your users via SharePoint Online. In this session, you’ll learn the differences between
      declarative and code-based workflows, design a workflow using Visio 2010,
      implement that workflow in SharePoint Designer 2010 and customize the workflow using Visual Studio 2010 and custom actions.
  • Developing SharePoint Online Solutions with the Client Object Model (Updated)
    • The SharePoint Client Object Model provides libraries for programmatically
      accessing SharePoint Online via Silverlight and JavaScript. In this session,
      we’ll go deep into the Client Object Model and show you how to develop solutions using both Silverlight and JavaScript.
  • SharePoint Online Branding (New)
    • Customizing an intranet site with your company's identity and branding can help create a more effective collaboration experience. In this video, you'll learn how SharePoint Online allows users, designers and developers to customize the look and feel of a site. This can range from simple changes like setting a site logo and Theme to completely changing the user experience with custom styles and Master Pages. In this session, you'll learn how to make these customizations to brand your SharePoint Online site.
  • Leveraging Excel and Access Services in SharePoint Online (Updated)
    • imageExcel and Access Services provide powerful features for building SharePoint Online solutions. In this session, you’ll get an inside look at both Excel and Access services and how each can be accessed programmatically when building SharePoint Online solutions. [Emphasis added.]
  • Developing Communication Solutions for Lync Online (Updated)
    • In this session, you learn how to integrate Lync features into your WPF and Silverlight clients much in the same way that Office and SharePoint do, including presence, contact lists and click-to-communicate features. You will also learn how to extend Lync communications to include data and features from your client applications much in the same way that Outlook 2010 does with the "IM" and "Call" features within an email.
  • Developing Messaging Solutions for Exchange Online (Updated)
    • In this session, you'll learn how to integrate Exchange Online mailbox data such as mail, calendar and task items as well as Exchange Online services such as the free-busy service into your applications using an easy to discover and easy to use managed API.

To use this training course as self-paced training, you’ll need to do the following:

  1. Set up a local SharePoint development environment (or download and configure the Information Worker VMs).
  2. Download and install the Office 365 Developer Training Kit onto your development machine.
  3. Sign up for an Office 365 trial to gain access to the service.
  4. Visit the Office 365 Training Course on MSDN to watch the videos and get started with the labs.

Monday, June 20, 2011

Reading Office 365 Beta’s SharePoint Online Lists with the Open Data Protocol (OData)

imageMy earlier Access Web Databases on AccessHosting.com: What is OData and Why Should I Care? post (updated 3/16/2011) described working with multi-tenant SharePoint 2010 Server instances provided by AccessHosters.com. Microsoft is about to release Office 365 as a commercial service (presently scheduled for 6/28/2011), so the details for using OData to manipulate SharePoint Online lists have become apropos.

I delivered on 5/23/2011 a Moving Access Tables to SharePoint 2010 or SharePoint Online Lists Webcast for Que Publishing, which provides detailed instructions for creating Web databases by moving conventional Access *.accdb databases to SharePoint Online lists and, optionally, create Web pages that emulate Access forms and reports. Click here to open the Webcast’s slides, which begin by describing how to move Access tables to an onsite SharePoint 2010 server installation and how to overcome problems with relational features that SharePoint lists don’t support. Slides 30 through 34 describe how to move the tables from Northwind.mdb (the classic version) to a ServiceName.sharepoint.com/TeamSite/Nwind subsite, where ServiceName is the name you chose when you signed up for Office 365 (oakleaf for this example):

image

Opening an OData list of Collections

Log into your site’s default public web site at http://ServiceName.sharepoint.com/, click the Member Login navigation button, type your Microsoft Online username (UserName@ServiceName.onmicrosoft.com) and password if requested, and click OK to enter the default TeamSite in editing mode.

Click the SubsiteName, NWind for this example, and Lists links to display the lists’ names, descriptions, number of items and Last Modified date:

image

To display in OData a list of the SharePoint lists in a subsite, NWind for this example, type http://ServiceName.sharepoint.com/TeamSite/NWind/_vti_bin/listdata.svc in the address bar of IE9 or later:

image

Note: vti is an abbreviation for Vermeer Technologies, Inc., the creators of the FrontPage Web authoring application. Microsoft acquired Vermeer in January 1996 and incorporated FrontPage in the Microsoft Office suite from 1997 to 2003.

The EmployeesTitleOfCourtesy item is a lookup list with Dr., Miss, Mr., Mrs. and .Ms choices. The Attachment and two MasterPage… items are default lists found in all sites.

Display Items in a Collection

To display the list items in a collection, add /CollectionName/ (case-sensitive) to the URL for collections. If the resulting page in IE7+ appears similar to the following, you must turn off feed-reading view:

image

Turn Off Feed-Reading View, if Necessary

To turn off feed-reading view, open the Internet Options dialog, click the Content tab:

image

Click the Feeds and Web Slices section’s Settings button to open the Feed and Web Slice settings dialog and clear all check boxes:

image

Click OK three times to return to IE9+. Close and reopen IE to display the items in a formatted OData feed:

image

Verify Query Throttling

According to the All Site Content page, the OrderDetails table has 2,155 items. To determine if queries are throttled to return a maximum number of items, change the URL’s /CollectionName/ suffix from /EmployeesTitleOfCourtesy/ to /OrderDetails/. Press Ctrl+PgDn to navigate to the last item:

image

Office 365 beta throttles OData queries by delivering a maximum of 1,000 records per query, as indicated by the last item’s ID of 1000 and the <link rel="next" href="http://oakleaf.sharepoint.com/TeamSite/NWind/_vti_bin/listdata.svc/OrderDetails/?$skiptoken=1000" /> element immediately above the </feed> closing tag. Copy the URL with the skiptoken query option into the address bar to return the next 1,000 Order Details items, starting with ID 1001:

image

Paging to the end of the document confirms a $skiptoken=2000 value.

To return a single entry, append the Id value enclosed in parenthesis to the list name, as in http://oakleaf.sharepoint.com/TeamSite/NWind/_vti_bin/listdata.svc/OrderDetails(2001).

Note: SharePoint adds an autoincrementing Id primary key value to all lists generated from Access tables and saves the original primary key value in an __OldID column. This column is the source of the problem I reported in my SharePoint 2010 Lists’ OData Content Created by Access Services is Incompatible with ADO.NET Data Services post of 3/22/2011.

Remote Authentication in SharePoint Online Using Claims-Based Authentication

Third-party OData browsers, such as Fabrice Marguerie’s Sesame Data Browser, enable displaying, querying and, in some cases, updating content delivered by most OData providers. Sesame is a Sliverlight application, which runs from the desktop or in a browser. Sesame offers a built-in set of sample data sets and enables a variety of authentication methods, including Windows Azure, SQL Azure, Azure DataMarket and HTTP Basic.

Here’s a screen capture of browser-based Sesame with a connection specified to Fabrice’s Northwind sample database OData source:

 image

Clicking OK displays members of the tables collection in the left-hand frame. Clicking an entry displays up to its first 15 elements. Hovering over a record selection arrow opens a button to display items in a related table by means of a lookup column, such as orders for AROUT in the following example:

image

Clicking the related table button opens the first 15 or fewer related entries in a linked query window:

 image

The query string is Customers('AROUT')/Orders.

Problems Displaying SharePoint Online Lists in OData Format with the Sesame browser

Attempting to open the OData representation of a SharePoint Online list with Sesame’s Basic authentication (your Office 365 username and password), fails with a .NET Not Found exception. Here’s Fiddler 2.3.4.4 display of the raw HTTP request and response messages involved:

image

Following is a fiddler capture for a successful IE9 browser request for the OData representation of the SharePoint Online Products list:

image

Here’s Fiddler’s Headers view of the successful operation:

image

SharePoint Online doesn’t accept Basic authentication. Instead, it requires a pair of login cookies to enable remote claims-based authentication.

Robert Bogue’s Remote Authentication in SharePoint Online Using Claims-Based Authentication article for the MSDN Library’s “Claims and Security Articles for SharePoint 2011” topic explains how remote claims-based authentication works:

Introduction to Remote Authentication in SharePoint Online Using Claims-Based Authentication

The decision to rely on cloud-based services, such as Microsoft SharePoint Online, is not made lightly and is often hampered by the concern about access to the organization's data for internal needs. In this article, I will address this key concern by providing a framework and sample code for building client applications that can remotely authenticate users against SharePoint Online by using the SharePoint 2010 client-side object model.

Note: Although this article focuses on SharePoint Online, the techniques discussed can be applied to any environment where the remote SharePoint 2010 server uses claims-based authentication.

I will review the SharePoint 2010 authentication methods, provide details for some of the operation of SharePoint 2010 with claims-mode authentication, and describe an approach for developing a set of tools to enable remote authentication to the server for use with the client-side object model.

Brief Overview of SharePoint Authentication

In Office SharePoint Server 2007, there were two authentication types: Windows authentication, which relied upon authentication information being transmitted via HTTP headers, and forms-based authentication. Forms-based authentication used the Microsoft ASP.NET membership and roles engines for managing users and roles (or groups). This was a great improvement in authentication over the 2003 version of the SharePoint technologies, which relied exclusively on Windows authentication. However, it still made it difficult to accomplish many scenarios, such as federated sign-on and single sign-on.

To demonstrate the shortcomings of relying solely on Windows authentication, consider an environment that uses only Windows authentication. In this environment, users whose computers are not joined to the domain, or whose configurations are not set to automatically transmit credentials, are prompted for credentials for each web application they access, and in each program they access it from. So, for example, if there is a SharePoint-based intranet on intranet.contoso.com, and My Sites are located on my.contoso.com, users are prompted twice for credentials. If they open a Microsoft Word document from each site, they are prompted two more times, and two more times for Microsoft Excel. Obviously, this is not the best user experience.

However, if the same network uses forms-based authentication, after users log in to SharePoint, they are not prompted for authentication in other applications such as Word and Excel. But they are prompted for authentication on each of the two web applications.

Federated login systems, such as Windows Live ID, existed, but integrating them into Office SharePoint Server 2007 was difficult. Fundamentally, the forms-based mechanism was designed to authenticate against local users, that is, it was not designed to authenticate identity based on a federated system. SharePoint 2010 addressed this by adding direct support for claims-based authentication. This enables SharePoint 2010 to rely on a third party to authenticate the user, and to provide information about the roles that the user has. …

Robert continues with an “Evolution of Claims-Based Authentication” topic and …

SharePoint Claims Authentication Sequence

Now that you have learned about the advantages of claims-based authentication, we can examine what actually happens when you work with claims-based security in SharePoint. When using classic authentication, you expect that SharePoint will issue an HTTP status code of 401 at the client, indicating the types of HTTP authentication the server supports. However, in claims mode a more complex interaction occurs. The following is a detailed account of the sequence that SharePoint performs when it is configured for both Windows authentication and Windows Live ID through claims.

  1. The user selects a link on the secured site, and the client transmits the request.
  2. The server responds with an HTTP status code of 302, indicating a temporary redirect. The target page is /_layouts/authenticate.aspx, with a query string parameter of Source that contains the server relative source URL that the user initially requested.
  3. The client requests /_layouts/authenticate.aspx.
  4. The server responds with a 302 temporary redirect to /_login/default.aspx with a query string parameter of ReturnUrl that includes the authentication page and its query string.
  5. The client requests the /_login/default.aspx page.
  6. The server responds with a page that prompts the user to select the authentication method. This happens because the server is configured to accept claims from multiple security token services (STSs), including the built-in SharePoint STS and the Windows Live ID STS.
  7. The user selects the appropriate login provider from the drop-down list, and the client posts the response on /_login/default.aspx.
  8. The server responds with a 302 temporary redirect to /_trust/default.aspx with a query string parameter of trust with the trust provider that the user selected, a ReturnUrl parameter that includes the authenticate.aspx page, and an additional query string parameter with the source again. Source is still a part of the ReturnUrl parameter.
  9. The client follows the redirect and gets /_trust/default.aspx.
  10. The server responds with a 302 temporary redirect to the URL of the identity provider. In the case of Windows Live ID, the URL is https://login.live.com/login.srf with a series of parameters that identify the site to Windows Live ID and a wctx parameter that matches the ReturnUrl query string provided previously.
  11. The client and server iterate an exchange of information, based on the operation of Windows Live ID and then the user, eventually ending in a post to /_trust/default.aspx, which was configured in Windows Live ID. This post includes a Security Assertion Markup Language (SAML) token that includes the user's identity and Windows Live ID signature that specifies that the ID is correct.
  12. The server responds with a redirect to /_layouts/authenticate.aspx, as was provided initially as the redirect URL in the ReturnUrl query string parameter. This value comes back from the claims provider as wctx in the form of a form post variable. During the redirect, the /_trust/default.aspx page writes two or more encrypted and encoded authentication cookies that are retransmitted on every request to the website. These cookies consist of one or more FedAuth cookies, and an rtFA cookie. The FedAuth cookies enable federated authorization, and the rtFA cookie enables signing out the user from all SharePoint sites, even if the sign-out process starts from a non-SharePoint site.
  13. The client requests /_layouts/authenticate.aspx with a query string parameter of the source URL.
  14. The server responds with a 302 temporary redirect to the source URL.

Note: If there is only one authentication mechanism for the zone on which the user is accessing the web application, the user is not prompted for which authentication to use (see step 6). Instead, /_login/default.aspx immediately redirects the user to the appropriate authentication provider—in this case, Windows Live ID.

SharePoint Online Authentication Cookies

An important aspect of this process, and the one that makes it difficult but not impossible to use remote authentication for SharePoint Online in client-side applications, is that the FedAuth cookies are written with an HTTPOnly flag. This flag is designed to prevent cross-site scripting (XSS) attacks. In a cross-site scripting attack, a malicious user injects script onto a page that transmits or uses cookies that are available on the current page for some nefarious purpose. The HTTPOnly flag on the cookie prevents Internet Explorer from allowing access to the cookie from client-side script. The Microsoft .NET Framework observes the HTTPOnly flag also, making it impossible to directly retrieve the cookie from the .NET Framework object model.

Note: For SharePoint Online, the FedAuth cookies are written with an HTTPOnly flag. However, for on-premises SharePoint 2010 installations, an administrator could modify the web.config file to render normal cookies without this flag. …

Robert concludes the article with “Using the Client Object Models for Remote Authentication in SharePoint Online” and “Reviewing the SharePoint Online Remote Authentication Sample Code Project.”

Fabrice will need to add a SharePoint authentication option with code similar to that described in the article to enable interacting with OData content from SharePoint Online.

OData References

Following is a table of useful references that provide the details of OData query and data update syntax:

ID

Author

Description

Date

1

Microsoft (MSDN)

[MS-ODATA]: Open Data Protocol (OData) Specification

5/2011

2

Microsoft (MSDN)

Windows Azure Storage Services REST API Reference

2011

3

Robert Bogue for MSDN

Remote Authentication in SharePoint Online Using Claims-Based Authentication

4/2011

4

OData.org

Open Data Protocol Organization Web Site and Blog

6/2011

5

Chris Sells

Open Data Protocol by Example

3/2010

6

Chris Sells

Hello, Data

6/2010

7

SAP

How To... Create Services Using the OData Channel

4/2011

8

Roger Jennings

Access Web Databases on AccessHosting.com: What is OData and Why Should I Care?

3/16/2011

9

Roger Jennings

SharePoint 2010 Lists’ OData Content Created by Access Services is Incompatible with ADO.NET Data Services

3/22/2011

10

Roger Jennings

Reading Office 365 Beta’s SharePoint Online Lists with the Open Data Protocol (OData)

6/20/2011

11

Access Team

Get to Access Services tables with OData

7/20/2010

12

Eric White

Getting Started using the OData REST API to Query a SharePoint List

12/9/2010

13

Eric White

Using the OData Rest API for CRUD Operations on a SharePoint List

12/17/2010

14

Eric White

Consuming External OData Feeds with SharePoint BCS

5/23/2011

15

Jonathan Carter

Open Data for the EnterpriseOpen Data for the Enterprise (TechEd 2010 session)

6/9/2010

16

Alex James

Best Practices: Creating OData Services Using Windows Communication Foundation (WCF) Data Services (TechEd 2010 session)

6/9/2010

Sunday, June 19, 2011

Reading and Updating Office 365 Beta’s SharePoint Online Lists with OData

Updated 6/20/2011: My Reading Office 365 Beta’s SharePoint Online Lists with the Open Data Protocol (OData) post of 6/20/2011 replaces this article due to an incompatibility problem with Windows Live Writer 2011.

image The new post expands on the use of Fabrice Marguerie’s Sesame Data Browser to read and query OData feeds. Sesame won’t open OData content generated by SharePoint Online due to issues with required claims-based federated authentication. The updated post explains these issues.

A later post will provide details about adding, updating, and deleting OData content.

Wednesday, June 15, 2011

Office 365 - Product Insights: Access and Forms Services in SharePoint Online

Ben Tamblyn (@btamblyn) posted Product Insights: Access and Forms Services in SharePoint Online to the Microsoft Office 365 Blogon June 15, 2010:

image Hi, following today’s post we’ll have three more posts the SharePoint Online product insights series. Today we’re going to show you how you can use Access and Forms Services to:

  • simplify routine business processes and;
  • capture information and feedback quickly

Next week is the last week – we’ll focus on Search and how SharePoint Online works together with Project Professional 2010.

In the meantime feel free to add a comment at the bottom of this post on other areas you’d like to see shown over the summer.

Note: See my My SharePoint Online (Office 365) Site for links to my Webcasts and more details about Access Web Databases, Office 365, SharePoint Online and Access Services.