Direkt zum Inhalt

Simple validation task is successful...but Simple backup is not

Thread needs solution

What is the purpose of the Simple Validation Task if not to indicate that a Simple Backup (Full) should succeed? The validation succeeds. The actual backup fails. I'm running SBS 2008 with Exchange 2007. Acronis Version 11.5 for SBS (which includes Exchange).

Here are the errors each time I try to perform the Simple Backup:
ProtectCommand: Failed to execute the command.
Additional info:
--------------------
Error code: 41
Module: 307
LineInfo: e6792a5ee190dda7
Fields: $module : agent_protection_addon_vs_32256
Message: ProtectCommand: Failed to execute the command.
--------------------
Error code: 1602
Module: 91
LineInfo: 9d08bc3c61bce3c9
Fields: IsReturnCode : 1, $module : arx_agent_fork_vs_32256
Message: A generic error of Microsoft Exchange Backuper.
--------------------
Error code: 17
Module: 91
LineInfo: 7edade4ed07d5271
Fields: IsReturnCode : 1, $module : arx_agent_fork_vs_32256
Message: Failed to back up the information store.
--------------------
Error code: 2222
Module: 91
LineInfo: 32daa98ec0fe3d3e
Fields: $module : arx_agent_fork_vs_32256
Message: The current user does not have the required privileges.
--------------------
Error code: 2238
Module: 91
LineInfo: 32daa98ec0fe3cff
Fields: IsReturnCode : 1, $module : arx_agent_fork_vs_32256
Message: The current user's privilege 'SeAssignPrimaryTokenPrivilege' is not set.
--------------------

I've used the administrator account. I've use the Acronis account. Same results each time.

Thanks.

1 Users found this helpful

Validation task checks that the archive is not corrupted. Backup task may fail but if archive is good, validation task will succeed.
You may check the solution from here - http://forum.acronis.com/forum/34030#comment-105846

Thanks for the feedback, but the problem remains. It's truly frustrating when I can run a Microsoft Backup without any issues, but after purchasing this Acronis software recently (to make my life easier LOL LOL) I'm having nothing but problems. I've tried umpteen combinations of settings, user rights, etc. Sometimes it works. Most times it doesn't.

Near as I can figure, these errors point to the current problem:
Error code: 2222
Module: 91
LineInfo: 32daa98ec0fe3d3e
Fields: $module : arx_agent_fork_vs_32256
Message: The current user does not have the required privileges.
--------------------
Error code: 2238
Module: 91
LineInfo: 32daa98ec0fe3cff
Fields: IsReturnCode : 1, $module : arx_agent_fork_vs_32256
Message: The current user's privilege 'SeAssignPrimaryTokenPrivilege' is not set.
--------------------

The solution link suggested by Fedor Larin (above) includes these instructions:
--------------------
Browse down to Local Policies -> User Rights Assignment -> and find the following policies:
Adjust memory quotas for a process
Replace a process level token
--------------------

Both of these local security settings are grayed out and do not permit me to add the correct Acronis user.

How is it that Acronis Version 11.5 for SBS is so convoluted? I've been playing with this software for several weeks now and after many backup failures, (and some successes) am astonished at how unstable it appears to be.

I just used the Group Policy Management Editor to edit the local security settings and then attempted yet another backup. Failed with the same errors.

Error code: 2222
Module: 91
LineInfo: 32daa98ec0fe3d3e
Fields: $module : arx_agent_fork_vs_32256
Message: The current user does not have the required privileges.
--------------------
Error code: 2238
Module: 91
LineInfo: 32daa98ec0fe3cff
Fields: IsReturnCode : 1, $module : arx_agent_fork_vs_32256
Message: The current user's privilege 'SeAssignPrimaryTokenPrivilege' is not set.
--------------------

If these settings are grayed out in local policy, they are controlled by domain policy.

It may be required to restart Managed Machine service and/or relogon the currently logged user to have this changes take effect. If it doesn't help, post output of "gpresult /z " command run under that user.

I have same problem

Created On 5/3/2014 at 2:05:33 PM

RSOP data for MCCCOM\administrator on MCSVR : Logging Mode
-----------------------------------------------------------

OS Configuration: Primary Domain Controller
OS Version: 6.1.7601
Site Name: Default-First-Site-Name
Roaming Profile: N/A
Local Profile: C:\Users\Administrator
Connected over a slow link?: No

COMPUTER SETTINGS
------------------
CN=MCSVR,OU=Domain Controllers,DC=mcccom,DC=local
Last time Group Policy was applied: 5/3/2014 at 2:05:12 PM
Group Policy was applied from: MCSVR.mcccom.local
Group Policy slow link threshold: 500 kbps
Domain Name: MCCCOM
Domain Type: Windows 2000

Applied Group Policy Objects
-----------------------------
Default Domain Controllers Policy
Default Domain Policy
Update Services Server Computers Policy
Update Services Common Settings Policy

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Windows SBS CSE Policy
Filtering: Denied (WMI Filter)
WMI Filter: Windows SBS Client

Windows SBS User Policy
Filtering: Denied (Security)

Local Group Policy
Filtering: Not Applied (Empty)

Update Services Client Computers Policy
Filtering: Denied (Security)

SharePoint Psconfig Notification Policy
Filtering: Denied (Security)

The computer is a part of the following security groups
-------------------------------------------------------
BUILTIN\Administrators
Everyone
Certificate Service DCOM Access
BUILTIN\Pre-Windows 2000 Compatible Access
BUILTIN\Users
System Mandatory Level
Windows Authorization Access Group
NT AUTHORITY\NETWORK
NT AUTHORITY\Authenticated Users
This Organization
MCSVR$
Domain Controllers
$H31000-PGE30HE7JLOU
View-Only Organization Management
Exchange Windows Permissions
Exchange Trusted Subsystem
Exchange Servers
NT AUTHORITY\ENTERPRISE DOMAIN CONTROLLERS
Denied RODC Password Replication Group
MCSVR $ Acronis Remote Users
Cert Publishers

Resultant Set Of Policies for Computer
---------------------------------------

Software Installations
----------------------
N/A

Startup Scripts
---------------
N/A

Shutdown Scripts
----------------
N/A

Account Policies
----------------
GPO: Default Domain Policy
Policy: MaxRenewAge
Computer Setting: 7

GPO: Default Domain Policy
Policy: MaximumPasswordAge
Computer Setting: 4294967295

GPO: Default Domain Policy
Policy: MinimumPasswordAge
Computer Setting: 1

GPO: Default Domain Policy
Policy: MaxServiceAge
Computer Setting: 600

GPO: Default Domain Policy
Policy: LockoutBadCount
Computer Setting: N/A

GPO: Default Domain Policy
Policy: MaxClockSkew
Computer Setting: 5

GPO: Default Domain Policy
Policy: MaxTicketAge
Computer Setting: 10

GPO: Default Domain Policy
Policy: PasswordHistorySize
Computer Setting: 24

GPO: Default Domain Policy
Policy: MinimumPasswordLength
Computer Setting: N/A

Audit Policy
------------
N/A

User Rights
-----------
GPO: Default Domain Controllers Policy
Policy: MachineAccountPrivilege
Computer Setting: Authenticated Users

GPO: Default Domain Controllers Policy
Policy: ChangeNotifyPrivilege
Computer Setting: Pre-Windows 2000 Compatible Access
Authenticated Users
NT SERVICE\MSSQL$SBSMONITORING
NT SERVICE\MSSQL$SHAREPOINT
NT SERVICE\MSSQLFDLauncher$SBSMONITORING
NT SERVICE\MSSQLFDLauncher$SHAREPOINT
Administrators
MCCCOM\SQLServerSQLAgentUser$MCSVR$SHAREPOINT
MCCCOM\SQLServerSQLAgentUser$MCSVR$SBSMONITORING
MCCCOM\SQLServer2005MSSQLUser$MCSVR$MICROSOFT##SSEE
NETWORK SERVICE
LOCAL SERVICE
Everyone
MCCCOM\SQLServer2005MSSQLUser$MCSVR$SCANMAIL

GPO: Default Domain Controllers Policy
Policy: IncreaseBasePriorityPrivilege
Computer Setting: Administrators

GPO: Default Domain Controllers Policy
Policy: TakeOwnershipPrivilege
Computer Setting: Administrators

GPO: Default Domain Controllers Policy
Policy: RestorePrivilege
Computer Setting: Server Operators
Backup Operators
Administrators

GPO: Default Domain Controllers Policy
Policy: DebugPrivilege
Computer Setting: Administrators

GPO: Default Domain Controllers Policy
Policy: SystemTimePrivilege
Computer Setting: Server Operators
Administrators
LOCAL SERVICE

GPO: Default Domain Controllers Policy
Policy: SecurityPrivilege
Computer Setting: Administrators
MCCCOM\Exchange Servers

GPO: Default Domain Controllers Policy
Policy: ShutdownPrivilege
Computer Setting: Print Operators
Server Operators
Backup Operators
Administrators

GPO: Default Domain Controllers Policy
Policy: AuditPrivilege
Computer Setting: IIS APPPOOL\hkprintstation.com
IIS APPPOOL\DefaultAppPool
IIS APPPOOL\Classic .NET AppPool
NETWORK SERVICE
LOCAL SERVICE
IIS APPPOOL\hkmcc.biz

GPO: Default Domain Controllers Policy
Policy: InteractiveLogonRight
Computer Setting: Print Operators
Server Operators
Account Operators
Backup Operators
Administrators

GPO: Default Domain Controllers Policy
Policy: CreatePagefilePrivilege
Computer Setting: Administrators

GPO: Default Domain Controllers Policy
Policy: BatchLogonRight
Computer Setting: IIS_IUSRS
Performance Log Users
Backup Operators
Administrators
MCCCOM\SQLServer2005MSSQLUser$MCSVR$MICROSOFT##SSEE
MCCCOM\SQLServer2005MSSQLUser$MCSVR$SCANMAIL

GPO: Default Domain Controllers Policy
Policy: NetworkLogonRight
Computer Setting: Pre-Windows 2000 Compatible Access
ENTERPRISE DOMAIN CONTROLLERS
Authenticated Users
Administrators
Everyone

GPO: Default Domain Controllers Policy
Policy: SystemProfilePrivilege
Computer Setting: NT SERVICE\WdiServiceHost
Administrators

GPO: Default Domain Controllers Policy
Policy: RemoteShutdownPrivilege
Computer Setting: Server Operators
Administrators

GPO: Default Domain Controllers Policy
Policy: BackupPrivilege
Computer Setting: Server Operators
Backup Operators
Administrators

GPO: Default Domain Controllers Policy
Policy: EnableDelegationPrivilege
Computer Setting: Administrators

GPO: Default Domain Controllers Policy
Policy: UndockPrivilege
Computer Setting: Administrators

GPO: Default Domain Controllers Policy
Policy: SystemEnvironmentPrivilege
Computer Setting: MCCCOM\Remoteroot
Administrators

GPO: Default Domain Controllers Policy
Policy: LoadDriverPrivilege
Computer Setting: Print Operators
Administrators

GPO: Default Domain Controllers Policy
Policy: IncreaseQuotaPrivilege
Computer Setting: IIS APPPOOL\hkprintstation.com
MCCCOM\Remoteroot
MCCCOM\spfarm
IIS APPPOOL\DefaultAppPool
IIS APPPOOL\Classic .NET AppPool
NT SERVICE\MSSQL$SBSMONITORING
NT SERVICE\MSSQL$SHAREPOINT
NT SERVICE\MSSQLFDLauncher$SBSMONITORING
NT SERVICE\MSSQLFDLauncher$SHAREPOINT
Administrators
MCCCOM\SQLServerSQLAgentUser$MCSVR$SHAREPOINT
MCCCOM\SQLServerSQLAgentUser$MCSVR$SBSMONITORING
MCCCOM\SQLServer2005MSSQLUser$MCSVR$MICROSOFT##SSEE
NETWORK SERVICE
LOCAL SERVICE
MCCCOM\SQLServer2005MSSQLUser$MCSVR$SCANMAIL
MCCCOM\spwebapp
IIS APPPOOL\hkmcc.biz

GPO: Default Domain Controllers Policy
Policy: ProfileSingleProcessPrivilege
Computer Setting: Administrators

GPO: Default Domain Controllers Policy
Policy: AssignPrimaryTokenPrivilege
Computer Setting: IIS APPPOOL\hkprintstation.com
MCCCOM\Remoteroot
MCCCOM\spfarm
IIS APPPOOL\DefaultAppPool
IIS APPPOOL\Classic .NET AppPool
NT SERVICE\MSSQL$SBSMONITORING
NT SERVICE\MSSQL$SHAREPOINT
NT SERVICE\MSSQLFDLauncher$SBSMONITORING
NT SERVICE\MSSQLFDLauncher$SHAREPOINT
MCCCOM\SQLServerSQLAgentUser$MCSVR$SHAREPOINT
MCCCOM\SQLServerSQLAgentUser$MCSVR$SBSMONITORING
MCCCOM\SQLServer2005MSSQLUser$MCSVR$MICROSOFT##SSEE
NETWORK SERVICE
LOCAL SERVICE
MCCCOM\SQLServer2005MSSQLUser$MCSVR$SCANMAIL
MCCCOM\spwebapp
IIS APPPOOL\hkmcc.biz

Security Options
----------------
GPO: Default Domain Policy
Policy: PasswordComplexity
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ClearTextPassword
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: ForceLogoffWhenHourExpire
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: RequireLogonToChangePassword
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: LSAAnonymousNameLookup
Computer Setting: Not Enabled

GPO: Default Domain Policy
Policy: TicketValidateClient
Computer Setting: Enabled

GPO: Default Domain Controllers Policy
Policy: @wsecedit.dll,-59013
ValueName: MACHINE\System\CurrentControlSet\Services\NTDS\Parameters\LDAPSer
verIntegrity
Computer Setting: 1

GPO: Default Domain Controllers Policy
Policy: @wsecedit.dll,-59043
ValueName: MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters
\RequireSecuritySignature
Computer Setting: 1

GPO: Default Domain Controllers Policy
Policy: @wsecedit.dll,-59044
ValueName: MACHINE\System\CurrentControlSet\Services\LanManServer\Parameters
\EnableSecuritySignature
Computer Setting: 1

GPO: Default Domain Policy
Policy: @wsecedit.dll,-59058
ValueName: MACHINE\System\CurrentControlSet\Control\Lsa\NoLMHash
Computer Setting: 1

GPO: Default Domain Controllers Policy
Policy: @wsecedit.dll,-59018
ValueName: MACHINE\System\CurrentControlSet\Services\Netlogon\Parameters\Req
uireSignOrSeal
Computer Setting: 1

Event Log Settings
------------------
N/A

Restricted Groups
-----------------
N/A

System Services
---------------
N/A

Registry Settings
-----------------
N/A

File System Settings
--------------------
N/A

Public Key Policies
-------------------
N/A

Administrative Templates
------------------------
GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\ElevateNonAdmins
Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\RebootWarningTimeo
utEnabled
Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\AutoInstallMinorUp
dates
Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoRebootWithLo
ggedOnUsers
Value: 0, 0, 0, 0
State: Enabled

GPO: Update Services Server Computers Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\AUOptions
Value: 3, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\DetectionFrequency
Enabled
Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Server Computers Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdate
Value: 0, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\RebootRelaunchTime
outEnabled
Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\RebootRelaunchTime
out
Value: 10, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\DetectionFrequency

Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\RescheduleWaitTime
Enabled
Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\RescheduleWaitTime

Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\NoAutoUpdate
Value: 0, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\RebootWarningTimeo
ut
Value: 5, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\WUServer
Value: 104, 0, 116, 0, 116, 0, 112, 0, 58, 0, 47, 0, 47, 0, 77, 0, 67, 0, 83,
0, 86, 0, 82, 0, 58, 0, 56, 0, 53, 0, 51, 0, 48, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\WUStatusServer
Value: 104, 0, 116, 0, 116, 0, 112, 0, 58, 0, 47, 0, 47, 0, 77, 0, 67, 0, 83,
0, 86, 0, 82, 0, 58, 0, 56, 0, 53, 0, 51, 0, 48, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\UseWUServer
Value: 1, 0, 0, 0
State: Enabled

GPO: Update Services Common Settings Policy
KeyName: SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU\AUOptions
Value: 2, 0, 0, 0
State: Enabled

USER SETTINGS
--------------
CN=Administrator,CN=Users,DC=mcccom,DC=local
Last time Group Policy was applied: 5/3/2014 at 1:33:35 PM
Group Policy was applied from: MCSVR.mcccom.local
Group Policy slow link threshold: 500 kbps
Domain Name: MCCCOM
Domain Type: Windows 2000

Applied Group Policy Objects
-----------------------------
N/A

The following GPOs were not applied because they were filtered out
-------------------------------------------------------------------
Update Services Server Computers Policy
Filtering: Denied (Security)

Windows SBS CSE Policy
Filtering: Denied (WMI Filter)
WMI Filter: Windows SBS Client

Windows SBS User Policy
Filtering: Denied (Security)

Default Domain Policy
Filtering: Not Applied (Empty)

Local Group Policy
Filtering: Not Applied (Empty)

Update Services Common Settings Policy
Filtering: Not Applied (Empty)

Update Services Client Computers Policy
Filtering: Denied (Security)

SharePoint Psconfig Notification Policy
Filtering: Disabled (GPO)

The user is a part of the following security groups
---------------------------------------------------
Domain Users
Everyone
BUILTIN\Administrators
BUILTIN\Users
Certificate Service DCOM Access
BUILTIN\Pre-Windows 2000 Compatible Access
NT AUTHORITY\INTERACTIVE
CONSOLE LOGON
NT AUTHORITY\Authenticated Users
This Organization
LOCAL
Group Policy Creator Owners
Domain Admins
Windows SBS SharePoint_OwnersGroup
Windows SBS Remote Web Access Users
Organization Management
Windows SBS Admin Tools Group
Schema Admins
Enterprise Admins
Denied RODC Password Replication Group
MCSVR $ Acronis Remote Users
WSS_ADMIN_WPG
High Mandatory Level

The user has the following security privileges
----------------------------------------------

Bypass traverse checking
Manage auditing and security log
Back up files and directories
Restore files and directories
Change the system time
Shut down the system
Force shutdown from a remote system
Take ownership of files or other objects
Debug programs
Modify firmware environment values
Profile system performance
Profile single process
Increase scheduling priority
Load and unload device drivers
Create a pagefile
Adjust memory quotas for a process
Remove computer from docking station
Perform volume maintenance tasks
Impersonate a client after authentication
Create global objects
Change the time zone
Create symbolic links
Enable computer and user accounts to be trusted for delegation
Increase a process working set
Add workstations to domain

Resultant Set Of Policies for User
-----------------------------------

Software Installations
----------------------
N/A

Logon Scripts
-------------
N/A

Logoff Scripts
--------------
N/A

Public Key Policies
-------------------
N/A

Administrative Templates
------------------------
N/A

Folder Redirection
------------------
N/A

Internet Explorer Browser User Interface
----------------------------------------
N/A

Internet Explorer Connection
----------------------------
N/A

Internet Explorer URLs
----------------------
N/A

Internet Explorer Security
--------------------------
N/A

Internet Explorer Programs
--------------------------
N/A