Lokesh SG
Windows 10 Domain ID is getting disabled frequently
SSPR and password complexity
Hi,
I am assuming that FIM SSPR utilizes the password complexity settings of the associated AD environment (that FIM is deployed in)?
When resetting a password via SSPR, and a password not complex enough is typed in, does FIM SSPR tell you the password does not meet complexity requirements and offer that you type another password (that matches the complexity requirement)?
Thanks,
SK
PCNS & FIM question
Hi,
When PCNS intercepts the password change on a DC, what format does it send the password to FIM in? is it clear text?
I am asking this because we require to sync AD passwords with a systems where we do not have a Management Agent for (via FIM).
Came across this script, and was wondering if it can be used for password sync & FIM?
http://blog.goverco.com/p/psmapwdmanage.html
Thank you.
SK
FIM to MIM upgrade
Hi,
With MIM now available, I'd like to test an upgrade scenario.
First question though - what are the requirements for MIM? OS? SQL? etc
FIM Sync:
I assume this is a simple in place upgrade of the binaries?
FIM Portal:
I assume we need to remove FIM Portal and Sharepoint 2010 first (as in our case)?
Then deploy Sharepoint 2013 and MIM portal again?
Thanks,
Sk
SSPR client versus FIM/MIM Server version through upgrade process
More or less related to my upgrade question.
Situation to start from:
- FIM 2010 Server Side
- FIM 2010 SSPR on Windows 7
Situation to go to:
- MIM 2016 Server Side
- MIM 2016 SSPR on Windows 7
Now my question: is the MIM 2016 SERVER software backwards compatible? E.g. can FIM 2010 clients connect and perform a SSPR against a MIM 2016 server?
Or is it the other way round? Can a MIM 2016 SSPR client talk to a FIM 2010 server?
I've got quite some clients to upgrade and the first option, server is backwards compatible, would be very very convenient...
SQL server 2012 AlwaysOn Availability Groups support with FIM 2010 R2 Sp1
Forefront Identity Manager 2010. Export EmployeeID to AD
Hello!
I need export attribute EmployeeID from FIM Portal to AD.
When I export EmployeeID to AD (Relationship criteria accountname = samaccountname) - all OK
When I export EmployeeID to AD (Relationship criteria Firstname = givenname and Lastname = sn) - EmployeeId does not export to same user in AD.
Help!
Alex
WindowsUpdate_8020000E" "WindowsUpdate_dt000"
Publishing FIM Password Portals on internet
Hi ,
I need to publish my existing FIM Portal on internet, below is my plan for that:
Current Scenario:
- We have 2 FIM Portal Servers published internally using our internal Hardware load balancer (HLB). We have FIM Sync server and one FIM Portal Admin server.
Proposed plan:
we are going to publish FIM servers using Windows Server 2012 R2's Web Application Proxy (WAP) servers.
We will configure two WAP servers in DMZ network behind our external HLB.
Queries:
1- Does WAP servers are supported in this scenario?
2- Do we require both WAP servers in DMZ to be domain joined?
3- Will this method will work us in publishing Password Register Portal?
http://blogs.msdn.com/b/angeos_blogs/archive/2014/10/01/publishing-forefront-identity-manager-fim-self-service-password-reset-sspr-portals-through-web-application-proxy-wap.aspx
4- Will this method will work for us in publishing password reset portal?
http://blogs.msdn.com/b/angeos_blogs/archive/2014/10/01/publishing-forefront-identity-manager-fim-self-service-password-reset-sspr-portal-through-web-application-proxy-wap.aspx
5- We are going to export and use the same certificate as our current internal servers are using, i think this is fine?
FIM 2010 (NOT R2) to MIM 2016 upgrade
The documentation at https://technet.microsoft.com/en-us/library/mt219041.aspx speaks of a FIM 2010 R2 upgrade to MIM 2016. But I've got a customer who still has a FIM 2010 who is now looking to upgrade to MIM 2016.
The target situation is to have all MIM 2016 software on new servers installed.Will the MIM 2016 installer be able to update the FIM 2010 databases? Or do we need to to a FIM 2010 -> FIM 2010 R2 -> MIM 2016 upgrade?
Could this be a possible strategy:
- Stop FIM 2010 services
- Backup database (duh :) )
- Move database to newer SQL version
- Start setup of MIM Sync/MIM Service
- Point to relocated database and upgrade database
- Have an upgraded environment
FIM pre-requisites for SharePoint 2013 - unable to set compatiblility level as it is a readonly property
I am having a problem setting the compatibility level for SharePoint, prior to installing FIM.
The property is read-only. Is there are registry entry that will complete this?
Here is the environment:
Freshly installed VM with Windows 2012 Std. Server is named: FIMS.
It is domain joined with .Net 3.5 installed.
It also have SQL 2012 Std installed including full-text search.
It has SharePoint 2013 installed...
Configure SQL Server 2012 for SharePoint 2013
http://sharepointpromag.com/sql-server-2012/configure-sql-server-2012-sharepoint-2013
I am stuck at step 1 in the following article to prepare SharePoint for the FIM install.
Installing FIM 2010 R2 on SharePoint Foundation 2013
https://technet.microsoft.com/en-us/library/jj863242(v=ws.10).aspx
Violating any of the above conditions will be caught by the setup prerequisite checks and will block the installation of the portal.
- The SharePoint 2013 site collection runs in 2010 experience mode.
To verify, in the SharePoint 2013 Management command-line shell, enter the following commands and verify that the return value is 14:- $spSite = SpSite("http://www.contoso.com");
- $spSite.CompatibilityLevel
When I run the command it reports the value is read-only. Advice on how to set this via registry or other mean, is much appreciated.
PS C:\> $spSite = SpSite("http://fims")
PS C:\> $spSite.CompatibilityLevel
15
PS C:\> $spSite.CompatibilityLevel = 14
'CompatibilityLevel' is a ReadOnly property.
At line:1 char:1
+ $spSite.CompatibilityLevel = 14
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : InvalidOperation: (:) [], RuntimeException
+ FullyQualifiedErrorId : PropertyAssignmentException
Thank you
FIM Troubleshooting: Error 80230904 occurs when Sync Service Manager tries to create GAL MA and connect to another forest
Hi All,
I am testing GAL sync between 3 forests. With 2 forests, everything is fine. When I try to add the third GAL sync management agent, Synchronization Service Manager fails to connect to the forest and shows error alert with number 80230904.
I suspect the reason of failure is in the new forest which FIM tries to connect. What does this error number mean? Besides showing this number, nothing is recorded in logs. I am failing to find any info on this error.
FIM 2012 R2 SP1 version: 4.1.3646.0, works on Windows 2008 R2 machine, the first and second forests are of level 2012 R2, and the third new one (failing) is of level 2008 R2.
Regards
Dmitry
Bulk Modify Users phone number in FIM portal
Hello,
I'm not sure if somebody asked for this already, i would like to know a detailed instructions in bulk update/modify phone number of users, it could be an MPR or powershell instructions or both. Users are from different departments. If there is an existing
script that i can modify, that would be great. Thank you!
FIM 2010 R2 - Set which contains all group owners
Hi
I have tried to figure out how to create a set which contains all the security group owners. Is that someway possible to do?
I want to show security groups just to group owners so is there is some other way to do that, let me know.
FIM Portal Internal Error
I've configured my portal to have a set of HR users. HR users can access the portal, create users and modify certain attributes of existing Contractors and Staff.
To do this I created some MPRs and search scopes, I login as an HR user, click Users and can successfully create a new user. However, if I search for existing users using the default All Users search scope, or using my All Conteactors and All Staff search scopes, the portal returns:
An internal error occurred and your request cannot be processed. Please contact your system
administrator.
Usual objectSid, Domain, AccountName are in place. Am I missing something simple?
Thanks
stopped-entry-export-error can't provision any accounts to AD
I'm using FIM 2010 R2 (4.1.3419.0) and Exchange 2010, I've recently hit an issue whereby the AD MA stops running due to "Stopped-entry-export-error". My environment was working fine, AD accounts and Exchange mailboxes were being provisioned OK (confirmed working for the past 6 months). I've only come upon this error since we installed around 25 Windows updates on our DC, Exchange server and FIM synchronization server.
There is no associated error in the Synchronization service Application for the user object(s) which cause an error (as you'll see it's blank in the picture). AD MA delta imports and syncs work fine, but exports always fail with different user accounts (so I don't think it's an issue with the accounts being synced). Looking at the Windows logs shows errors as below:
Application log (typical error for a user):
There is an error in Exch2010Extension AfterExportEntryToCd() function when exporting an object with DN CN=jp um
receptionist,OU=staff,OU=Accounts,DC=contoso,DC=local. Type: Microsoft.MetadirectoryServices.ExtensionException Message: **** ERROR **** Property
expression "jp um receptionist" isn't valid. Valid values are: Strings formed with characters from A to Z (uppercase or lowercase), digits from 0 to
9, !, #, $, %, &, ', *, +, -, /, =, ?, ^, _, `, {, |, } or ~. One or more periods may be embedded in an alias, but each period should be preceded and followed by at least one of the other characters. Unicode characters from U+00A1 to U+00FF are also valid in an alias, but they will be mapped to a best-fit US-ASCII string in the e-mail address, which is generated from such an alias. Property Name: Alias **** END ERROR **** Stack Trace: at Exch2010Extension.Exch2010ExtensionClass.AfterExportEntryToCd(Byte[] origAnchor, String origDN, String origDeltaEntryXml, Byte[] newAnchor, String new DN, String failedDeltaEntryXml, String errorMessage)
Application Service Log (Forefront Identity Manager) - Error (happens every 30 minutes, this has been happening for 2 weeks, since the updates were installed):
Microsoft.ResourceManagement.Service: System.InvalidOperationException: Operation is not valid due to the current state of the object.
at Microsoft.ResourceManagement.WebServices.Mail.Exchange.MailChannel.ExchangeMailChannelListener`1.ExchangeMailListener.<OnPollTimerExpired>b__0 (Boolean findUnreadItems) at Microsoft.ResourceManagement.WebServices.Mail.Exchange.MailChannel.ExchangeMailChannelListener`1.ExchangeMailListener.OnPollTimerExpired(Object
state)
Here's the relevant section from my Microsoft.ResourceManagement.Service.exe.config file
<appsettings>
< add key="mailServer" value="https://email.contoso.com/ews/exchange.asmx" />
<add key="isExchange" value="1" />
<add key="SendAsAddress" value="svc-fim@contoso.com" />
<add key="synchronizationServerName" value="SvrFIM01" />
</appsettings>
If I browse to https://email.contoso.com/ews/exchange.asmx I'm PROMPTED for Windows logon credentials (the EWS virtual is configured for anonymous and windows authentication).Upon entering the FIM service account details, the appropriate xml page appears (no certificate warnings or errors are generated). I can logon the FIM service mailbox and send emails.
The error may be down to a PowerShell problem, as I couldn't initiate a remote PowerShell session from my FIM service account to the Exchange server using:
$session=new-pssession -configurationName Microsoft.Exchange -connectionuri https://email.comtoso.com/PowerShell
To get around this, I've added the fim service account to Organization management (it was already a recipient management user) and added it the local administrators group on the FIM server, I then restart the fim synchronization and fim service. The remote Power Shell connection works fine, but the AD MA export still does not.
There are some warnings in the Application logs about not being able to connect to the Exchange web services, however I think these are red herrings as they've been going on for over a year (during which time FIM has been working fine)
https://social.technet.microsoft.com/Forums/forefront/en-US/993a34dd-2c38-431a-8e36-c5be1bb2cf7f/fim-warning-cannot-access-exchange-web-service?forum=ilm2
I would appreciate some help in resolving this as it's currently got me stumped.The only thing I can try is removing the security patches and giving the fim service account administrative and exchange organization management permissions on the server and rebooting all boxes.
Thanks in advance
FIM Synchronization Service hotfix was not successfuly installed
Hi everyone,
I'm experiencing troubles while trying to upgrade FIM Synchronization by installing hot fixes.
My current version is (4.1.3114.0) and I need to go up to new hotfix (4.1.3613.0).
While installing the file (FIMSyncService_x64_KB3011057), I am getting this message :
" Forefront Identity Manager Synchronization Service was not successfully installed. To install Forefront Identity Manager Synchronization Service, run this wizard again."
When I run it again, I get the same message.
I will be grateful if someone can help.
Thanks in advance.
SCSM FIM Management pack not deployed to SCSM DW server
I'm having a problem on my FIM reporting installation, I did everything as noted in the technet documentation and as in missmiis docs, but I never get the MPSyncJob to actually show anything refering to FIM or Forefront.
In the SCSM console, I can see management packs on the administration node, but not in the data warehouse node, is there a catch somewhere or what am I missing? I cannot run the DW scripts on the DW server because it fails everytime saying that management packs aren't deployed....
The actual error message is "Base schema for FIM Datawarehouse has not been deployed. Please wait till this completes."
SQL server 2012 AlwaysOn Availability Groups support with MIM 2016
Microsoft Identity Manager 2016 is now on MSDN/VL available for download
Microsoft Identity Manager 2016, successor of FIM 2010 is now available on MSDN / Volume Licensing sites. It is the "GA" version.
There is also a new site about MIM:
Microsoft Identity Manager at microsoft.com sites.
On-premises identity and access management:
- Synchronize identities between directories, databases and applications
- Self-service password, group and certificate management
- Increase admin security with policies, privileged access and roles
- Thwart identity theft with Microsoft Identity Manager (MIM)
Note that there is "Try now" button on the site, but it is currently redirected to /evalcenter/evaluate-microsoft-advanced-threat-analytics
If you found my post helpful, please give it a Helpful vote. If it answered your question, remember to mark it as an Answer.