Quantcast
Channel: Microsoft Identity Manager forum
Viewing all 7443 articles
Browse latest View live

SAP ECC6 Connectivity Failing with Web Services Connector

$
0
0

I've got the most recent version of the SAP ECC6 Web Services Connector Running In my Environment running in a fresh install of MIM 2016. I downloaded the most recent version of the web services connector and the associated SAP ECC6 sample project. After a fair amount of work getting the proper BPAP's published (instructions didn't match the UI) we got the solution to sync user objects using the built-in user object. I can get user related things to run end-to-end. However,

I also need Roles to sync.  This appears to use BAPI_HELPVALUES_GET.  That BAPI is published, however using the default configuration in the download it fails every time with a Method not allowed message on the SAP side.  The XML payload matches the parameters being described in the .wsconfig file so I expect that there is something wrong with the default parameters in the web services config example.   Has anybody else ACTUALLY gotten these sample files to run correctly to import Role and Group object types?  Were there any modifications required on your end to make it work?


MIM action workflow functionality clarification

$
0
0

Dear All, 

I have a scenario where I have written a action work flow to perform. certain action on a AD user account. but before performing the action, the changes in FIM service database (portal) is supposed to be exported (updated) to the AD via ADMA.

1) how can I achieve the above  scenario.

 2) How can make sure that the ADMA doesn't re import the old data and synchronize this data back to Fim server, whilst the workflow is executing. 

best regards 

Sri

MIM Privileged Access Management API error

$
0
0

Hi,

The MIM Privileged Access Management API is not working. I'm using MIM 2016 with SP1 on Windows server 2012 R2 in Azure. Why o why?

############

Detailed Error Information:
Module    WindowsAuthenticationModule
Notification    AuthenticateRequest
Handler    ExtensionlessUrlHandler-ISAPI-4.0_64bit
Error Code    0x80070021
Config Error    This configuration section cannot be used at this path. This happens when the section is locked at a parent level. Locking is either by default (overrideModeDefault="Deny"), or set explicitly by a location tag with overrideMode="Deny" or the legacy allowOverride="false". 
Config File    \\?\C:\Program Files\Microsoft Forefront Identity Manager\2010\Privileged Access Management REST API\web.config
Requested URL    http://mimservice2.pam.lan:8086/api/pamresources/
Physical Path    C:\Program Files\Microsoft Forefront Identity Manager\2010\Privileged Access Management REST API\api\pamresources\
Logon Method    Not yet determined
Logon User    Not yet determined
 Config Source:
   31:       <authentication>
   32:         <windowsAuthentication enabled="true" useKernelMode="false"/>
   33:       </authentication>

##########


GH

Email notification workflow issue

$
0
0

I've created a simple mail notification workflow. When a "Job Title" attribute is manually changed in the FIM/MIM portal, an email is sent to HR. The new value is then exported to AD, and all is good.

When an administrator makes a change to this attribute in AD, the new value is synchronized and exported to the FIM service, however the workflow is not triggered. How can I make this work? 


Thank you

Martin



Granfeldt PS MA Export question

$
0
0

Hi,

I'm using Mr Granfeldts excellent PS MA but I ran into a small problem.

During export the script is called multiple times depending on the number of objects and the batch-size configured in my Export run profile. The begin and end sections are called every time the script runs but I need a way to find out when the end time is called for the last time. Are there any control variables available that I can check? I could not find any documentation regarding that.

Thanks

Joakim

Session Ended (Error 3002)

$
0
0

I'm trying to rollout Forefront Identity Manager to my company. I have it installed on three servers : SQL, Portal and Web.

Everything is setup and seems to be working correctly, except for one issue.

When I open a browser and navigate to the registration page, I get the first page, click next and immediately get "Session ended. Return to the home page to start again (Error 3002)". If I click to go back to the first page it then works correctly.

Every user trying this after me wont have the same problem.

I then browse to the password reset webpage. Again I get the first page, but after entering my credentials I get the Session Ended page again. Once again if i click to go back to the first page, everything then works, and all other users trying this after me work fine.

It seems to be the very first person to try one of the web pages gets the error, and then everything works. (not just my account, any test account i try first) I'm not sure how long it takes to fail again, as it's not in live environment yet, but when I try it a few days later I'm back to this "first attempt will fail" problem.

Does anyone have any ideas?


FIM Reporting Job fails with timeout

$
0
0

Hi,

We just migrated a FIM to MIM instance.

The initial MIM reporting jobs ran fine, but we brought over the production data and are now getting a timeout error on the incremental reporting job:

"This reporting job has been cancelled because the FIM Service instance handling the job has failed to respond within the pre-configured timeout window."

Anyone know how to find out which FIM Service instance is handling the job? And how to extend the timeout window?

Or any other ideas?

Thank you for any help!

MIM 2016 SP1 Reporting Initial Sync Failing

$
0
0

Hello Everyone,

I am experiencing an issue with the MIM Reporting failing on the Initial Sync. Both times I have experienced the issue has been with the MIM 2016 SP1 install media. SCSM Service manager is on a separate server with SQL and SCSM DW is on a separate server with SQL. I first complete the SCSM 2012 Service Manager and Data Warehouse installation, register the Data Warehouse and confirm the initial MPSync job finishes with all Management Packs imported/associated. Then I run the MIM 2016 SP1 Reporting installation and confirm the MIM Management Packs are all imported/associated and showing up in Reports in the SCSM console. Then I run the FIMPostInstallScriptsForDataWarehouse.ps1 script which completes successfully. When I run theStart-FIMReportingInitialSync.ps1 script and check the Reporting Job in the MIM Portal, it fails immediately and produces the below errors.

Firewall is off between the servers as well. Has anyone seen this issue before and have a solution?

Reporting Job Details: 

ObjectTypeName: Person,

AttributeName: ObjectType,

RequestIdentifier: 00000000-0000-0000-0000-000000000000,

ObjectID: 7fb2b853-24f0-4498-9534-4e10589723c4,

Value: Person,

DataType: String,

MultiValue: False,

Added: True,

SubscriptionDetails: <DataWarehouseClassProperty ClassTypeIdentity="FIMDW.FIMPerson" PropertyIdentity="FIMObjectType" ManagementPackIdentity="Microsoft.Forefront.IdentityManager.Datawarehouse.Base" ManagementPackVersion=”1.0.0.1”/>,

EventTime: 12/05/2016 19:38:27

Event Viewer:(Three errors connected to the issue)

Error
12/5/2016 11:38:17 AM
Microsoft.ResourceManagement.ServiceHealthSource
68 None

"The FIM Reporting ETL job failed while making a call to the System Center Service Manager Management Server SDK service.  This could be caused by a network or service interruption which is preventing communication between the FIM Service and the System Center Service Manager SDK Service, or by an internal error within System Center.

To fix this issue, ensure that there are no firewalls or network connectivity issues which may be preventing communication between these two services. Also ensure that the System Center Management and System Center Data Access services are running on the System Center Service Manager Management Server.

If you encounter this error after running your first ETL job, ensure that you have installed the FIM Reporting support scripts on your Data Warehouse machine.  You can find these scripts in the Service and Portal folder of your FIM media.

For more information about this error, view the most recent reporting job in the FIM Portal and look for any exceptions which may have occurred.
"

Error
9/21/2012 4:19:41 PM
Microsoft.ResourceManagement 3
None

Reporting Job Manager: Reporting job halted due to error.

Error
9/21/2012 4:19:41 PM
Microsoft.ResourceManagement 3
None

ObjectTypeName: Person, AttributeName: ObjectType, RequestIdentifier: 00000000-0000-0000-0000-000000000000, ObjectID: 7fb2b853-24f0-4498-9534-4e10589723c4, Value: Person, DataType: String,

MultiValue: False, Added: True, SubscriptionDetails: <DataWarehouseClassProperty ClassTypeIdentity="FIMDW.FIMPerson" PropertyIdentity="FIMObjectType" ManagementPackIdentity="Microsoft.Forefront.IdentityManager.Datawarehouse.Base" ManagementPackVersion=”1.0.0.1”/>, EventTime: 12/05/2016 19:38:27 ---> System.InvalidOperationException: Cannot find management pack with identity Microsoft.Forefront.IdentityManager.Datawarehouse.Base
   at Microsoft.ResourceManagement.Reporting.DataProvider.DataWarehouseManagementPackManager.GetManagementPack(String managementPackKey)
   at Microsoft.ResourceManagement.Reporting.DataProvider.DataWarehouseObjectGenerator.CreateEnterpriseManagementObject(Guid objectIdentifier, String classType, String managementPackIdentity)
   at Microsoft.ResourceManagement.Reporting.DataProvider.DataWarehouseObjectGenerator.CreateEnterpriseManagementObject(DataWarehouseClassMapping mapping)
   at Microsoft.ResourceManagement.Reporting.DataProvider.DataWarehouseCollection.ProcessEntry(ExportLogEntry entry)
   --- End of inner exception stack trace ---
   at Microsoft.ResourceManagement.Reporting.DataProvider.DataWarehouseCollection.ProcessEntry(ExportLogEntry entry)
   at Microsoft.ResourceManagement.Reporting.DataProvider.DataWarehouseProvider.ProcessBatch(List`1 batch)
   at Microsoft.ResourceManagement.Reporting.ReportingManager.ExecuteBatchOfExtractTransformLoad(IDataManager dataManager)
   at Microsoft.ResourceManagement.Reporting.ReportingManager.ExportData(IDataManager dataManager)
   at Microsoft.ResourceManagement.Reporting.ReportingManager.RefreshSchema()
   at Microsoft.ResourceManagement.Reporting.JobManager.Run()


MIM error on manual Join

$
0
0

I have installed MIM Sync 4.3.2195.0. It was a fresh install and not an upgrade.

When trying to do a manual join I get the following error:

"Could not find any resources appropriate for the specified culture or the neutral culture. Make sure "Microsoft.DirectoryServices.MetadirectoryServices.UI.PropertySheetBase.MMSErrorMessages.resources" was correctly embedded or linked into assembly "PropertySheetBase" at compile time, or that all the satellite assemblies required are loadable and fully signed."

After clicking OK I can see the error details which are as follows:

See the end of this message for details on invoking
just-in-time (JIT) debugging instead of this dialog box.

************** Exception Text **************
System.ArgumentNullException: Value cannot be null.
Parameter name: value
   at System.String.IndexOf(String value, Int32 startIndex, Int32 count, StringComparison comparisonType)
   at System.String.IndexOf(String value, StringComparison comparisonType)
   at Microsoft.DirectoryServices.MetadirectoryServices.UI.WebServices.MMSErrors.AdjustErrorTextForExtensionException(String& sErrorString)
   at Microsoft.DirectoryServices.MetadirectoryServices.UI.AccountJoiner.AccountJoinerControl.Join()
   at System.Windows.Forms.Button.WndProc(Message& m)
   at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)


************** Loaded Assemblies **************
mscorlib
    Assembly Version: 4.0.0.0
    Win32 Version: 4.0.30319.34209 built by: FX452RTMGDR
    CodeBase: file:///C:/Windows/Microsoft.NET/Framework64/v4.0.30319/mscorlib.dll
----------------------------------------
miisclient
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/miisclient.exe
----------------------------------------
PropertySheetBase
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/PropertySheetBase.DLL
----------------------------------------
System.Windows.Forms
    Assembly Version: 4.0.0.0
    Win32 Version: 4.0.30319.34251 built by: FX452RTMGDR
    CodeBase: file:///C:/windows/Microsoft.Net/assembly/GAC_MSIL/System.Windows.Forms/v4.0_4.0.0.0__b77a5c561934e089/System.Windows.Forms.dll
----------------------------------------
System.Drawing
    Assembly Version: 4.0.0.0
    Win32 Version: 4.0.30319.34209 built by: FX452RTMGDR
    CodeBase: file:///C:/windows/Microsoft.Net/assembly/GAC_MSIL/System.Drawing/v4.0_4.0.0.0__b03f5f7f11d50a3a/System.Drawing.dll
----------------------------------------
System
    Assembly Version: 4.0.0.0
    Win32 Version: 4.0.30319.34238 built by: FX452RTMGDR
    CodeBase: file:///C:/windows/Microsoft.Net/assembly/GAC_MSIL/System/v4.0_4.0.0.0__b77a5c561934e089/System.dll
----------------------------------------
UiUtils
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/UiUtils.DLL
----------------------------------------
System.Core
    Assembly Version: 4.0.0.0
    Win32 Version: 4.0.30319.34209 built by: FX452RTMGDR
    CodeBase: file:///C:/windows/Microsoft.Net/assembly/GAC_MSIL/System.Core/v4.0_4.0.0.0__b77a5c561934e089/System.Core.dll
----------------------------------------
System.Xml
    Assembly Version: 4.0.0.0
    Win32 Version: 4.0.30319.34234 built by: FX452RTMGDR
    CodeBase: file:///C:/windows/Microsoft.Net/assembly/GAC_MSIL/System.Xml/v4.0_4.0.0.0__b77a5c561934e089/System.Xml.dll
----------------------------------------
MmsServerRCW
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/MmsServerRCW.DLL
----------------------------------------
System.ServiceProcess
    Assembly Version: 4.0.0.0
    Win32 Version: 4.0.30319.34209 built by: FX452RTMGDR
    CodeBase: file:///C:/windows/Microsoft.Net/assembly/GAC_MSIL/System.ServiceProcess/v4.0_4.0.0.0__b03f5f7f11d50a3a/System.ServiceProcess.dll
----------------------------------------
Operations
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/Operations.DLL
----------------------------------------
GroupListView
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/GroupListView.DLL
----------------------------------------
MaExecution
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/MaExecution.DLL
----------------------------------------
AccountJoiner
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/AccountJoiner.DLL
----------------------------------------
mmsuihlp
    Assembly Version: 0.0.0.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/mmsuihlp.DLL
----------------------------------------
System.Configuration
    Assembly Version: 4.0.0.0
    Win32 Version: 4.0.30319.34209 built by: FX452RTMGDR
    CodeBase: file:///C:/windows/Microsoft.Net/assembly/GAC_MSIL/System.Configuration/v4.0_4.0.0.0__b03f5f7f11d50a3a/System.Configuration.dll
----------------------------------------
ObjectLauncher
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/ObjectLauncher.DLL
----------------------------------------
ObjectViewers
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/ObjectViewers.DLL
----------------------------------------
Preview
    Assembly Version: 4.3.2195.0
    Win32 Version: 4.3.2195.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/Preview.DLL
----------------------------------------

************** JIT Debugging **************
To enable just-in-time (JIT) debugging, the .config file for this
application or computer (machine.config) must have the
jitDebugging value set in the system.windows.forms section.
The application must also be compiled with debugging
enabled.

For example:

<configuration>
    <system.windows.forms jitDebugging="true" />
</configuration>

When JIT debugging is enabled, any unhandled exception
will be sent to the JIT debugger registered on the computer
rather than be handled by this dialog box.


http://www.wapshere.com/missmiis

MIM 2016 SP1 - Error on Manual Join

$
0
0

Hi I receive the following error when trying to complete a manual join in the Sync Service.

"Could not find any resources appropriate for the specified culture or the neutral culture. Make sure "Microsoft.directoryservices.metadirectoryserices.UI.ProperttySheetBase.MMSErrorMessages.resources was correctly embedded or linked into assembly"PropertySheetbase" at compile time, or that all the satellite assemblies required are loadable and fully signed.

Full Error: Value cannot be null. Parameter name: value

See the end of this message for details on invoking 
just-in-time (JIT) debugging instead of this dialog box.

************** Exception Text **************
System.ArgumentNullException: Value cannot be null.
Parameter name: value
   at System.String.IndexOf(String value, Int32 startIndex, Int32 count, StringComparison comparisonType)
   at Microsoft.DirectoryServices.MetadirectoryServices.UI.WebServices.MMSErrors.AdjustErrorTextForExtensionException(String& sErrorString)
   at Microsoft.DirectoryServices.MetadirectoryServices.UI.AccountJoiner.AccountJoinerControl.Join()
   at System.Windows.Forms.Control.OnClick(EventArgs e)
   at System.Windows.Forms.Button.OnClick(EventArgs e)
   at System.Windows.Forms.Button.WndProc(Message& m)
   at System.Windows.Forms.NativeWindow.Callback(IntPtr hWnd, Int32 msg, IntPtr wparam, IntPtr lparam)


************** Loaded Assemblies **************
mscorlib
    Assembly Version: 4.0.0.0
    Win32 Version: 4.6.1055.0 built by: NETFXREL2
    CodeBase: file:///C:/Windows/Microsoft.NET/Framework64/v4.0.30319/mscorlib.dll
----------------------------------------
miisclient
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/miisclient.exe
----------------------------------------
PropertySheetBase
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/PropertySheetBase.DLL
----------------------------------------
System.Windows.Forms
    Assembly Version: 4.0.0.0
    Win32 Version: 4.6.1055.0 built by: NETFXREL2
    CodeBase: file:///C:/Windows/Microsoft.Net/assembly/GAC_MSIL/System.Windows.Forms/v4.0_4.0.0.0__b77a5c561934e089/System.Windows.Forms.dll
----------------------------------------
System
    Assembly Version: 4.0.0.0
    Win32 Version: 4.6.1055.0 built by: NETFXREL2
    CodeBase: file:///C:/Windows/Microsoft.Net/assembly/GAC_MSIL/System/v4.0_4.0.0.0__b77a5c561934e089/System.dll
----------------------------------------
System.Drawing
    Assembly Version: 4.0.0.0
    Win32 Version: 4.6.1055.0 built by: NETFXREL2
    CodeBase: file:///C:/Windows/Microsoft.Net/assembly/GAC_MSIL/System.Drawing/v4.0_4.0.0.0__b03f5f7f11d50a3a/System.Drawing.dll
----------------------------------------
UiUtils
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/UiUtils.DLL
----------------------------------------
System.Core
    Assembly Version: 4.0.0.0
    Win32 Version: 4.6.1055.0 built by: NETFXREL2
    CodeBase: file:///C:/Windows/Microsoft.Net/assembly/GAC_MSIL/System.Core/v4.0_4.0.0.0__b77a5c561934e089/System.Core.dll
----------------------------------------
System.Configuration
    Assembly Version: 4.0.0.0
    Win32 Version: 4.6.1055.0 built by: NETFXREL2
    CodeBase: file:///C:/Windows/Microsoft.Net/assembly/GAC_MSIL/System.Configuration/v4.0_4.0.0.0__b03f5f7f11d50a3a/System.Configuration.dll
----------------------------------------
System.Xml
    Assembly Version: 4.0.0.0
    Win32 Version: 4.6.1055.0 built by: NETFXREL2
    CodeBase: file:///C:/Windows/Microsoft.Net/assembly/GAC_MSIL/System.Xml/v4.0_4.0.0.0__b77a5c561934e089/System.Xml.dll
----------------------------------------
MmsServerRCW
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/MmsServerRCW.DLL
----------------------------------------
System.ServiceProcess
    Assembly Version: 4.0.0.0
    Win32 Version: 4.6.1055.0 built by: NETFXREL2
    CodeBase: file:///C:/Windows/Microsoft.Net/assembly/GAC_MSIL/System.ServiceProcess/v4.0_4.0.0.0__b03f5f7f11d50a3a/System.ServiceProcess.dll
----------------------------------------
Operations
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/Operations.DLL
----------------------------------------
GroupListView
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/GroupListView.DLL
----------------------------------------
MaExecution
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/MaExecution.DLL
----------------------------------------
AccountJoiner
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/AccountJoiner.DLL
----------------------------------------
MvViewer
    Assembly Version: 4.4.1237.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/MvViewer.DLL
----------------------------------------
mmsuihlp
    Assembly Version: 0.0.0.0
    Win32 Version: 4.4.1237.0
    CodeBase: file:///C:/Program%20Files/Microsoft%20Forefront%20Identity%20Manager/2010/Synchronization%20Service/UIShell/mmsuihlp.DLL
----------------------------------------

************** JIT Debugging **************
To enable just-in-time (JIT) debugging, the .config file for this
application or computer (machine.config) must have the
jitDebugging value set in the system.windows.forms section.
The application must also be compiled with debugging
enabled.

For example:

<configuration>
    <system.windows.forms jitDebugging="true" />
</configuration>

When JIT debugging is enabled, any unhandled exception
will be sent to the JIT debugger registered on the computer
rather than be handled by this dialog box.

edit: I have tried two different users and they both do not work.

MIM 2016: Updating Users Profiles

$
0
0

I'll probably get flamed for asking such a stupid question, but I'm honestly stuck on this. All I can say in my defense is that I didn't know anything about Identity Manager a week ago!

OK so I've got everything installed, Sync, Portal and Service. Created MAs for MIM (FIM) and AD DS, and user information is flowing into MIM perfectly.

Now I'm trying to set the portal so users can update their own information, but the only way I can get this to work is by adding an attribute flow into the AD DS MA, and there's not a single guide I can find which says you need to do this. So I think that must be wrong.

I've created an Outbound Sync Rule, MPR and Workflow. In the Outbound Sync Rule I've added the attributes I want users to be able to update. But this doesn't work either. When I run a Full Import and Sync on the MA it still just shows Inbound Synchronization for the statistics.

I've not enabled provisioning, as I'm not really ready to start creating users with the portal just yet. Nor have I enabled "Create resource in external system" for the Outbound Rule as I'm presuming I'm only updating.

Any help very much appreciated :)


Andrew France - http://andrewsprivatecloud.wordpress.com

Extension-DLL-exception when doing a full sync

$
0
0

Basically what I'm trying to do is basically sync AD attributes of users from one forest to a resource forest using FIM. I have created the necessary management agent as well as workflows, sets, MPR and sync rules.

The configuration I made is working on a dev environment but when I try to replicate it to our PROD executing a full sync will give out a lot of error pertaining to extension DLL exception. I have drilled down on a particular user and tried to generate a preview but the error points to the DN.



I did read a article to trim the custom expression that is mapped to the DN but to no avail.

Thanks. 

Task Scheduler not triggering email of huge size

$
0
0

Hi All,

We have developed a PowerShell script that fetches groups from FIM portal expiring in a quarter and trigger email notifications to the group owners. This script works fine when executed in PowerShell console. But when we make this script as part of Windows Task Scheduler, it does not trigger email notification. No errors logged in History tab of the task nor event viewer. We are currently trying with 10K groups which are owned by 10K different owners. The functionality is to send 1 email notification with all 10K recipients in TO list of the email notification.

When I narrow down the filter to fetch fewer groups like ~4K groups in the script and then execute the Task Scheduler it triggers the mail notification.

Any help or clue would be appreciated.

Thanks,



Veena

MIM Service Event Log not created during SP1 installation

$
0
0

I've just done a fresh install of MIM 2016 SP1 Service and Portal. Normally I would expect to find its own event log under "Applications and Services Logs" in Event Viewer - but it's not there. Has this log been discontinued or is this a bug with the SP1 installer?

Carol


http://www.wapshere.com/missmiis

A lot of errors in event viewer on FIM Sync server.

$
0
0

I have thousands of errors in event viewer > applications and services logs > Forefront Identity Manager Synchronization > Operational. They are all very similar. What causes them?

HRESULT: '0x0' Source: 'd:\bt\25920\private\source\miis\server\mgmt\perfmon\prfdata.cpp(654)'  Thread ID: '0x213C' Additional Info: ''

HRESULT: '0x80070002' Source: 'd:\bt\25920\private\source\miis\server\mgmt\perfmon\prfdata.cpp(956)'  Thread ID: '0x213C' Additional Info: ''

HRESULT: '0x80230404' Source: 'd:\bt\25920\private\source\miis\server\sqlstore\csobj.cpp(8254)'  Thread ID: '0xCF4' Additional Info: ''

HRESULT: '0x80070002' Source: 'd:\bt\25920\private\source\miis\server\mgmt\perfmon\optex.cpp(245)'  Thread ID: '0x22AC' Additional Info: ''




Initial password Communication problem

$
0
0

Hello!

I'm trying to automate Initial Password Communication with email.

I have a working process of user provision to AD, but can't do it with this instruction:

http://social.technet.microsoft.com/wiki/contents/articles/2121.fim-how-to-use-workflows-to-automate-the-calculation-and-notification-of-initial-passwords.aspx

This video have the same instruction. One difference is the order of activities in workflow, but I think that this is not a reason.

https://technet.microsoft.com/en-us/video/automate-the-calculation-and-notification-of-initial-passwords-with-fim-2010.aspx

Correctly I understand that:

1. Email is generating when user is provisioned to AD (AD MA Export run profile) ?

2. I don't need a MPR to achieve this goal?

 

 

So, what I have:

1.AD User Outbound Sync rule

2.Workflow parameters

3.Outbound Attribute Flow

4.Action Workflow with 3 activities

5.Password Generation Function

6.Adding target resource to Sync Rule

7.Email Notification

 

Main problem what users are created in AD in disabled state, because of they don't get passwords. When I trying to enable them I get error that users can't be enables, because password doesn't meet password policy.

 

Can anybody say where can be a problem?

Any help very appreciated.

Thanks!

 


1

FIM 2010 R2 to MIM 2016 SP1 upgrade paths

$
0
0

https://docs.microsoft.com/en-us/microsoft-identity-manager/understand-explore/microsoft-identity-manager-2016-sp1-release-notes mentions that I have to upgrade FIM 2010 R2 SP1 to MIM 2016 before upgrading to MIM 2016 SP1, is this only applicable when doing in-place upgrades on the same server? I've searched quite a bit and haven't been able to find out if it's supported to do a MIM2016 SP1 deploy to new windows servers, reusing the FIM R2 SP1 sync & service DB's... I'd like to end up on Windows 2016 servers, but since that is only supported with SP1 I'd like to avoid having to install a separate 2012 server just for the FIM R2->MIM RTM upgrade...

Anyone know what the official word is?

MIM SP1 - direct approval link

$
0
0

Hi,

Using FIM 2010 I have extended approval notification template with link like this:

Request can be seen and approved as well <a href="http://servername/identitymanagement/aspx/Requests/RequestProperties.aspx?id=[//Request/ObjectID]&type=Approval" target="_blank">here</a>

After upgrading to MIM it is still opening approval however when you click approve it doesn't do anything. Is there any new trick to do this with MIM SP1 new UI?

Best regards

Borys


Borys Majewski, Identity Management Solutions Architect (Blog: IDArchitect.NET)

MIM 2016, SQL Server 2016 and "Server and Portal Setup Wizard ended prematurely"

$
0
0

I am testing migrating FIM 2010 R2 / SQL 2012 to MIM 2016 SP1 / SQL 2016.  We set up virtual environment to facilitate this test.  The in-place upgrade of FIM to MIM went relatively smoothly as did porting the FIMSynchronizationService DB from SQL 2012 to SQL 2016 environment.  However, i've gotten suck on updating the the portal to use the DB in SQL 2016.  A 'Change' install of the Service and Portal is failing with the message "Server and Portal Setup Wizard ended prematurely". The install log indicates that

System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.Runtime.InteropServices.COMException (0x800706BA): The RPC server is unavailable.

The  error is basically the same as the one in this article http://www.fimspecialist.com/fim-r2-sp1-fim-service-and-portal-setup-wizard-ended-prematurely/

Unfortunately, the solutions presented there do not resolve my issue. I've also tried uninstalling / re-installing the FIM portal with the same results.  

What's weird is that I can no longer get the FIM portal to install using the DB that was set up on SQL 2012 either.  My FIM virtual environment is set up in a HyperV cluster and is on it's own virtual network.  I wouldn't think any of this would cause problems with the FIM set up but 'RPC server unavailable' error does seem like it's network related. 

Any suggestions on how to resolve this issue or how to further investigate the root cause of 'RPC server is unavailable' would be greatly appreciated.

Thanks

ADFS 3.0 issue while authenticating to third party web application using WS-Federation

$
0
0

I need one help regarding ADFS set up in our project.

  1. We are using Liferay Portal in our application for authenticating the users and SSO using SAML.
  2. We have another requirement to authenticate an application from Liferay. But that new application will not support SSO using SAML token.
  3. Hence we are trying to bring ADFS 3.0 in between Liferay and the third party application
    1. User login to Liferayàclick on third party app iconàGenerate SAML tokenàHit ADFSàConvert to KerberosàAuthenticate application.
  4. Liferay authenticates via AD (A) and third party application sits on another AD (B). Both ADs share same forest and have a trust between them.
  5. We have configured everything but facing an issue while redirecting to application. Below are the details of the error.

Viewing all 7443 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>