WMI permissions required for a FIM2010 self-password reset scenario

Reading Time: 2 minutes A recent post from Brad Turner reminded me of something I wanted to blog about since I setup my Forefront Identity Manager (FIM) lab for self-password reset for users. So here it is – WMI permissions … … If you want to enable the self-password reset scenario for users (which is one of scenarios you definitely … Continue reading "WMI permissions required for a FIM2010 self-password reset scenario"

Windows 2008 R2 Recycle Bin support for FIM

Reading Time: < 1 minute Few weeks ago I wrote about FIM 2010 support for Windows 2008 R2 Active Directory environment with Recycle Bin enabled. Basically it wasn't supported configuration at that time. But world is changing … and FIM as well. Few days ago FIM 2010 Update 1 was released  to Windows Update and also Windows Catalog. You can … Continue reading "Windows 2008 R2 Recycle Bin support for FIM"

ILM 2007 and virtualization – small but important change

Reading Time: < 1 minute Small, but important change was introduced in ILM 2007 FP1 FAQ: Wow … this means that something which already had happened at many customers is now officially supported configuration. Good for customers who are running ILM in VM or are thinking about moving to it with ILM. (cc) BikoBikoBiko FAQ mentions Hyper-V explicitly but as … Continue reading "ILM 2007 and virtualization – small but important change"

ILM AD MA, linked attributes and Recycle Bin

Reading Time: 5 minutes Windows 2008 R2 has hit RTM and many of users have already downloaded it from Technet and MSDN to evaluate or even deploy in the network. W2008R2 brings changes in many different aspects of operating system, some are saying that it should not be R2 but brand new OS version. Among other R2 brings changes … Continue reading "ILM AD MA, linked attributes and Recycle Bin"

Reverse engineering attribute flows from server export

Reading Time: 2 minutes ILM (MIIS) allows management agent configuration to be exported in two ways: Management Agent export Server configuration export. Both options produces XML files, however in first case one will get single file which will contain only configuration for single MA. In second case series of XML files will be created, one for each MA and … Continue reading "Reverse engineering attribute flows from server export"

Debugging ILM2

Reading Time: 2 minutes ILM2 has way more moving parts than ILM2007. We have right now portal with end-user UI based on Sharepoint, business logic hidden behind workflows and MPRs and old synchronization engine as it used to be in previous ILM versions This is very simple description, if You want to get whole overview of ILM2 architecture go … Continue reading "Debugging ILM2"

Security ID problem with provisioning mailbox in resource forest

Reading Time: 2 minutes This will be another troubleshooting note, so probably one can notice that some of projects I work on have been delivered or are in the middle of deployment. Well .. this is called life. Something what works in lab not always work in the same perfect way in production environment. (cc) Michael Bonnett Jr Provisioning … Continue reading "Security ID problem with provisioning mailbox in resource forest"

Case of failed-search error

Reading Time: < 1 minute This will be just quick note to present a problem I’ve encountered and quick solution, however I haven’t got time to dig into this issue guts. But I will try to in the feature. Simple scenario: ILM connecting to Active Directory through standard AD Management Agent. Active Directory environment: single forest with multiple domains. ILM … Continue reading "Case of failed-search error"