# BizTalk Platform Management Tool WinForms tool for controlled Microsoft BizTalk Server 2020 platform operations during maintenance windows. The tool captures runtime snapshots, creates shutdown and restore plans, executes those plans in a safe order, and writes diff reports for validation. ## Current State - Application: C# WinForms - Target framework: .NET Framework 4.6.1 - Solution: `BizTalkPlatformManagementTool.sln` - Project: `src/BizTalkPlatformManagementTool/BizTalkPlatformManagementTool.csproj` - Primary namespace and assembly: `BizTalkPlatformManagementTool` - Legacy PowerShell archive: `archive/powershell/BizTalkPlatformManagementTool.ps1` ## Features - Snapshot before and after downtime as JSON, CSV and HTML - Diff between `before.json` and `after.json` - Controlled shutdown from the current runtime state - Controlled restore from `before.json` - State-aware emergency restore from a preserved `before.json`, including Enterprise SSO startup - WMI-free validation and file selection for preserved recovery snapshots, including 2.1.3 snapshots - Host instance handling for the selected BizTalk server - Dry-run mode enabled by default - WMI access through `root\MicrosoftBizTalkServer` - Startup check for administrator rights - Detailed operation logging in the GUI and daily rolling log files under ProgramData - Automatic operation-log restoration into the grid after an application restart - Thirty-day runtime-log retention with GZip compression for completed daily logs - Process-local ScheduledTask adapter dependency resolution for `scheduler:` receive locations without modifying the GAC - Best-effort plan execution: one isolated WMI failure is recorded while remaining independent steps continue - Idempotent execution that skips artifacts already in the requested target state - Durable per-step result reports even when a shutdown or restore completes only partially - Environment status indicator based on host instance state - Clear and Close actions in the main toolbar - No compile-time dependency on BizTalk ExplorerOM assemblies - Transactional Windows installer/updater with SHA-256 payload validation and rollback - Bounded activation retries plus a verified copy fallback for first installs and atomically backed-up updates when Windows/EDR blocks only the staging rename - Opt-in all-users desktop shortcut whose ACL, WSH, validation or rollback failures remain visible but cannot roll back the core installation - Installer diagnostics with stable phase codes, complete child-process output, exception chains and a ProgramData-to-Temp log fallback - WMI-free runtime self-test plus automated regression test executable ## Safe Usage 1. Start the app with **Run as administrator** on a BizTalk server or a management host with WMI access. 2. Keep **Dry run** enabled. 3. Click **Diagnose** to verify WMI access. 4. Click **Snapshot Before**. 5. Click **Shutdown** and review `shutdown-plan.json`. 6. Disable **Dry run** only when the plan is correct. 7. After maintenance, click **Restore** using the saved `before.json`. 8. Click **Snapshot After** and **Compare**. If a shutdown was interrupted and only the original `before.json` remains, select that file with **State...**, run **Validate State**, keep **Dry run** enabled and click **Emergency Restore**. The recovery plan never overwrites the source snapshot, ensures the `ENTSSO` service is running first, skips already-correct runtime states and continues after isolated step failures. Disable Dry run only after reviewing the timestamped emergency plan. A real run automatically writes a timestamped target/actual diff when the post-operation snapshot succeeds. The environment indicator shows `Started`, `Stopped`, `Partial` or `Unknown` from the most recent snapshot. `Clear` removes the visible status and operation log grids; it does not delete files. **Log Folder** opens the persistent local runtime-log directory. The application requests administrator rights through its UAC manifest and checks them again during startup. Only one GUI instance can run per Windows session. Before a real shutdown or restore, the exact fresh plan is saved and a second dialog shows its executable step count, target server and plan path. Restore is rejected when the snapshot server does not match the selected target (short name and FQDN of the same host are accepted). ## Operation Order Shutdown: - Disable receive locations that were enabled. - Stop orchestrations that were started. - Stop send ports that were started. - Stop host instances that were started on the selected server. Restore: - Start host instances that were previously started. - Restore send ports to Started, Stopped or Bound. - Restore orchestrations where safe. - Restore receive locations last. Orchestrations that were `Bound` are deliberately left unchanged during restore to avoid accidentally making them `Unbound`. ## Outputs - `before.json`, `after.json` - `shutdown-plan.json`, `restore-plan.json` - `shutdown-after.json`, `restore-after.json` - `shutdown-result.json`, `restore-result.json` - Timestamped `emergency-source-before-*`, `emergency-restore-plan-*`, `emergency-restore-result-*`, `emergency-restore-after-*` and `emergency-restore-diff-*` files - `diff.json`, `diff.csv`, `diff.html` - Snapshot sidecars: `*.csv`, `*.hosts.csv`, `*.html` - Runtime logs under `%ProgramData%\BizTalkPlatformManagementTool\Logs` The current day remains a plain `BizTalkPlatformManagementTool-yyyy-MM-dd.log`. Completed daily logs are compressed to `.log.gz`; the current day plus the previous 29 calendar days are retained. Older records are removed on startup. Up to the newest 10,000 retained entries are automatically restored from plain and compressed files into the Operation Log grid after a restart. If ProgramData is unexpectedly unavailable, logging falls back to the executable directory. ## Troubleshooting The Operation Log shows the WMI class, key property, key value and method for real shutdown and restore steps. WMI objects are resolved with a broad `SELECT * FROM ` query and a client-side key filter so names containing special characters do not break the WMI query parser. Execution is deliberately best-effort. A failure such as an adapter-specific validation exception is written as `Failed` in the result report, but later independent plan steps are still attempted. The GUI ends in a failed/operator-review state when any step failed; it never reports a partial execution as an unconditional success. The post-operation snapshot is attempted independently and its own failure is preserved in the same report. For a ScheduledTask receive location, the operation plan retains adapter name and address. Immediately before a real `Enable` or `Disable`, the tool preloads `Microsoft.BizTalk.Scheduler.dll` from the locally installed BizTalk directory and resolves further dependencies from identity-checked BizTalk/ScheduledTask adapter directories. Conventional BizTalk 2020 and `BizTalk ScheduledTask Adapter 7.x` folders plus BizTalk registry paths are discovered automatically. An exceptional installation path can be added to the semicolon-delimited `AdapterAssemblySearchPaths` value in `BizTalkPlatformManagementTool.exe.config`. This is process-local: the tool neither copies DLLs nor changes the GAC. Never point the setting at assemblies from a different BizTalk version. Error records in the grid, execution report and file log include exception type, HRESULT, complete inner-exception chain, available Fusion loader information and stack trace. For the PROD validation and support bundle, follow [ScheduledTask control and runtime logging runbook](docs/PROD-ScheduledTask-und-Laufzeitlogging-2026-08-26.md). Snapshot and plan JSON files are written as UTF-8 without BOM. Loading is tolerant of existing files that contain a UTF-8 BOM or a visible BOM marker from previous encoding conversions. JSON snapshots and plans are written through a same-directory temporary file and atomic replacement. Snapshot comparison keys artifacts by application plus name, preventing collisions between equal artifact names in different applications. CSV fields that could be interpreted as spreadsheet formulas are neutralized. Installer, update and uninstall diagnostics are retained for 90 days under `%ProgramData%\BizTalkPlatformManagementTool\InstallerLogs`. The setup UI can open that directory directly. If the primary log cannot be created, setup reports and uses a `%TEMP%\BizTalkPlatformManagementTool\InstallerLogs` fallback. See [Installation](Installation.md#installer-diagnose) for phase codes and the support checklist. ## Build Open `BizTalkPlatformManagementTool.sln` in Visual Studio on Windows with the .NET Framework 4.6.1 Developer Pack installed, then build the `Release|Any CPU` configuration. The app targets .NET Framework 4.6.1 for compatibility with customer environments that do not have newer .NET Framework developer packs installed. Use `scripts\test-release.cmd` for the build and regression suite and `scripts\package-release.cmd` for the tested installer ZIP, Certutil-compatible Base64 TXT and SHA-256 file. See [Installation](Installation.md) for decoding and update/rollback details. ## Source Documentation All C# types and methods in the application, setup, packager and regression project use XML documentation comments. Method contracts include `param`, `typeparam` and `returns` elements where applicable. Release builds generate one XML documentation file per assembly, so malformed or missing public documentation becomes visible during compilation. Targeted German inline comments explain non-obvious operational decisions such as WMI client-side filtering, shutdown/restore order, atomic file replacement, CSV formula neutralization and installer transaction boundaries. Trivial statements are intentionally not paraphrased in comments; the comments record the reason or safety constraint behind the code. ## Documentation - [Installation](Installation.md) - [Dokumentation](Dokumentation.md) - [Installer stability analysis](docs/Installer-Stabilitaetsanalyse-2026-08-11.md) - [ACC activation incident analysis](docs/ACC-Installer-Aktivierungsfehler-2026-08-11.md) - [PROD activation incident analysis and 2.2.3 fix](docs/PROD-Installer-Aktivierungsfehler-2026-08-24.md) - [Optional all-users desktop shortcut stability](docs/Installer-Optionale-Desktopverknuepfung-2026-08-24.md) - [ACC runtime shutdown incident and recovery fix](docs/ACC-Runtime-Shutdown-Exception-2026-08-19.md) - [PROD ScheduledTask control and runtime logging runbook](docs/PROD-ScheduledTask-und-Laufzeitlogging-2026-08-26.md) - [AI maintainer handoff](AI-README.md) - [References](REFERENCES.md)