Quantcast
Channel: Forum Microsoft Identity Manager
Viewing all 4767 articles
Browse latest View live

Hide Textbox control based on Radiobuttonlist values in MIMPortal RCDC Configuration

$
0
0

I have a radiobuttonList, when I select any of the option like if i sleect Consultant, then the ProposedEndDate Textbox should be Enabled same way for other values. here the values are considered as strings.

any help would be very much helpful for me to goahead.

Hide Textbox control based on Radiobuttonlist values in MIMPortal RCDC Configuration

$
0
0

I have a radiobuttonList, when I select any of the option like if i sleect Consultant, then the ProposedEndDate Textbox should be Enabled same way for other values. here the values are considered as strings.



Programmatic User Registration Error

$
0
0

DEars, 

I am using this: https://docs.microsoft.com/en-us/previous-versions/mim/jj134294(v=ws.10)

I am getting below error:

What could be the solution?

Email motification bug when requesting on behalf of a user

$
0
0

When our help desk staff submits a request on a behalf of another user the default email sent to the approver is misleading in that it looks like it's the help desk person that is requesting the access instead of the true beneficiary.  I believe this is because of the parameter:  //Requestor/DisplayName in the "Default pending approval email template" which resolves to the person submitting the request instead of the beneficiary.  How can I modify the email template so that it reflects the actual beneficiary's name instead of the person requesting the access?

Also, are the email templates and object model documented anywhere?  There might be additional details I'd like to include to include in the approval, rejection and completion e-mails.

Any guidance is appreciated!

Christian


Email notification bug when requesting on behalf of a user

$
0
0

When our help desk staff submits a request on a behalf of another user the default email sent to the approver is misleading in that it looks like it's the help desk person that is requesting the access instead of the true beneficiary.  I believe this is because of the parameter:  //Requestor/DisplayName in the "Default pending approval email template" which resolves to the person submitting the request instead of the beneficiary.  How can I modify the email template so that it reflects the actual beneficiary's name instead of the person requesting the access?

Also, are the email templates and object model documented anywhere?  There might be additional details I'd like to include to include in the approval, rejection and completion e-mails.

Any guidance is appreciated!

Christian



Who will be announced as the next FIM Guru? Read more about January 2019 competition!!

$
0
0


What is TechNet Guru Competition?

Each month the TechNet Wiki council organizes a contest of the best articles posted that month. This is your chance to be announced as MICROSOFT TECHNOLOGY GURU OF THE MONTH!

One winner in each category will be selected each month for glory and adoration by the MSDN/TechNet Ninjas and community as a whole. Winners will be announced in dedicated blog post that will be published in Microsoft Wiki Ninjas blog, a tweet from the Wiki Ninjas Twitter account, links will be published at Microsoft TNWiki group on Facebook, and other acknowledgement from the community will follow.

Some of our biggest community voices and many MVPs have passed through these halls on their way to fame and fortune.

If you have already made a contribution in the forums or gallery or you published a nice blog, then you can simply convert it into a shared wiki article, reference the original post, and register the article for the TechNet Guru Competition. The articles must be written in January 2019 and must be in English. However, the original blog or forum content can be from beforeJanuary 2019.

Come and see who is making waves in all your favorite technologies. Maybe it will be you!


Who can join the Competition?

Anyone who has basic knowledge and the desire to share the knowledge is welcome. Articles can appeal to beginners or discusse advanced topics. All you have to do is to add your article to TechNet Wiki from your own specialty category.


How can you win?

  1. Please copy/Write over your Microsoft technical solutions and revelations to TechNetWiki.
  2. Add a link to your new article on THIS WIKI COMPETITION PAGE (so we know you've contributed)
  3. (Optional but recommended) Add a link to your article at the TechNetWiki group on Facebook. The group is very active and people love to help, you can get feedback and even direct improvements in the article before the contest starts.

Do you have any question or want more information?

Feel free to ask any questions below, or Join us at the official MicrosoftTechNet Wiki groups on facebook. Read More about TechNet Guru Awards.

If you win, people will sing your praises online and your name will be raised as Guru of the Month.


PS: Above top banner came from Vimal Kalathil.



Thanks,
Kamlesh Kumar

If my reply is helpful please mark as Answeror vote as Helpful.

My blog | Twitter | LinkedIn

Side-by-side FIM to MIM upgrade

$
0
0

Hi,

Are the steps detailed in this guide applicable to moving configuration from FIM to MIM?

https://docs.microsoft.com/en-us/previous-versions/mim/ee534906(v%3dws.10)

  1. Back up the pilot and production environments by using the Backup and Restore procedures.

  2. Export the FIM Service schema configuration.

  3. Export the FIM Synchronization Service configuration.

  4. Export the FIM Service policy and FIM Synchronization Service configuration resources.

  5. Install the MIM Synchronization Service and the MIM Service in the production environment.

  6. Enable the maintenance mode in the production environment.

  7. Import the FIM Service schema configuration into the new MIM environment.

  8. Import the FIM Synchronization service configuration into the new MIM environment.

  9. Install the custom DLLs/Custom Activities/etc necessary for custom workflows.

  10. Import the FIM Service policy and FIM Synchronization Service configuration into the new MIM environment.

  11. Disable maintenance mode in the production environment.

I guess installing the new MIM solution using existing databases will not work, as we have some additional elements in our solution like: PowerShell activities and another custom activity library (from Soren Granfeldt). A bit of a catch-22 scenario.

Thank you.

SK




Who will be announced as the next FIM Guru? Read more about January 2019 competition!!

$
0
0


What is TechNet Guru Competition?

Each month the TechNet Wiki council organizes a contest of the best articles posted that month. This is your chance to be announced as MICROSOFT TECHNOLOGY GURU OF THE MONTH!

One winner in each category will be selected each month for glory and adoration by the MSDN/TechNet Ninjas and community as a whole. Winners will be announced in dedicated blog post that will be published in Microsoft Wiki Ninjas blog, a tweet from the Wiki Ninjas Twitter account, links will be published at Microsoft TNWiki group on Facebook, and other acknowledgement from the community will follow.

Some of our biggest community voices and many MVPs have passed through these halls on their way to fame and fortune.

If you have already made a contribution in the forums or gallery or you published a nice blog, then you can simply convert it into a shared wiki article, reference the original post, and register the article for the TechNet Guru Competition. The articles must be written in January 2019 and must be in English. However, the original blog or forum content can be from beforeJanuary 2019.

Come and see who is making waves in all your favorite technologies. Maybe it will be you!


Who can join the Competition?

Anyone who has basic knowledge and the desire to share the knowledge is welcome. Articles can appeal to beginners or discusse advanced topics. All you have to do is to add your article to TechNet Wiki from your own specialty category.


How can you win?

  1. Please copy/Write over your Microsoft technical solutions and revelations to TechNetWiki.
  2. Add a link to your new article on THIS WIKI COMPETITION PAGE (so we know you've contributed)
  3. (Optional but recommended) Add a link to your article at the TechNetWiki group on Facebook. The group is very active and people love to help, you can get feedback and even direct improvements in the article before the contest starts.

Do you have any question or want more information?

Feel free to ask any questions below, or Join us at the official MicrosoftTechNet Wiki groups on facebook. Read More about TechNet Guru Awards.

If you win, people will sing your praises online and your name will be raised as Guru of the Month.


PS: Above top banner came from Vimal Kalathil.



Thanks,
Kamlesh Kumar

If my reply is helpful please mark as Answeror vote as Helpful.

My blog | Twitter | LinkedIn


is it possible to request privileges using MIM PAM Portal?

$
0
0

I cannot see PAM request for normal users? How can I enable that for Normal users without usingPAM SAMPLE portal


Common name for PAM Sample Portal - PAM.contoso.com

$
0
0

Can we use a common name for PAM SAMPLE Portal? 

I tried to use PAM.contoso.com rather using server FQDN:8090 and received the error below:

Oops! Something went wrong. The ajax calls failed, please contact your administrator. Error code:0

Has anyone configured the PAM sample portal using the common name? Could you please share the steps I need to perform to use the common name?

Thanks!

Additional 2016 MIM Portal & MIM Service

$
0
0

Hi Dears,

I did a setup of MIM 2016 Portal & Service on Windows Server 2016 with SharePoint 2016 for SSPR.

I need to know two things:

  • Is it supported to deploy additional MIM 2016 Portal server for SSPR?
  • Where is Microsoft Guide for deploying additional Portal Server? 

I did not find the guide, so Please help on this.

Patches and updates

$
0
0

Hi all,

I am looking for a repository of patches and updates for FIM 2010. I currently have a troublesome installation that I need to update but the updates I need are no longer available. I have pulled down some updates from the Update Catalog but they will not install.

Any suggestions would be appreciated.

The DN must be set before calling CSEntry.CommitNewConnector. Pulling my hair out

$
0
0

This may be my understanding of the product, and any help would be greatly appreciated. I have read everything I can find but still having a hard time understanding what is going on here.

Overview

I am working on a PowerShell MA that exports group info to a rest api. This includes multiple owners and some other custom attributes (like category = type of group based on criteria, approvalType = single owner, multiple owner, manager). I have most of it working and on the home stretch, (I think).

The problem I am facing is on my provision, when I create a new group in ad. I import it then sync the AD MA, I get “The DN must be set before calling CSEntry.CommitNewConnector.”

Info

-The anchor for the MA is a unic sid in the remote system.

-The Join rule is u_objectsid = csObjectID (this is a custom files in the remote system where I want to add the csobjectid on provision.

-Sync rule

               Outbound

               To all metaverse resources of this type

               Scope is group

Scope filter (I have tried a few things here) csObjectid not equal “” (thought was that it would not try to provision until it had this value populated.

Relationship Create resource in external system

Outbound flow ( I have tried a lot of stuff here)

               Initial flow = csObjectID =>DN

-My theory on how this SHOULD work.

  1. The record is imported from ad but no provisioning should happen on my custom MA.
  2. The record gets provision in MIM and get a csObjectID.
  3. On export from mim a provisioning gets triggered for custom MA.
  4. Custom ma export provisions new record in remote system

-what is happening

               AD MA is triggering provisioning on custom MA on sync when no csObjectID is in Metaverse.

I was going to try to change the DN but I want to use a value that does not change, I was going to change it to AD objectGuid but that needs to be converted from binary to string which does not seem to happen on initial import/sync and I get the same result.

Thank you for any help or pointers.

Mike

Integration with AD

$
0
0

Hello.

A current environment has an Oracle Internet Directory (OID) as the authoritative source for identity information. A FIM server responsible for replicating identity information to AD. We are going to migrate AD DS from 2012R2 to new AD DS 2016 and decommission the old DCs. What should we configure to still maintain the same replication from FIM to the new DCs?

Regards

Self Service Password Reset (SSPR) Rich Client Customization

$
0
0

Is it possible to customize any of the strings in the SSPR rich-client install which is part of the windows logon?

I came across this article that talks about customizing the password reset web portal. However, it does not have any information relating to customizing the rich client.

https://docs.microsoft.com/en-us/previous-versions/mim/hh877808(v=ws.10)

I also came across a question posted back in 2013, and the answer from Microsoft rep says it is not possible to customize it.

Is this still the case, now in 2019? Thank you.

https://social.technet.microsoft.com/Forums/en-US/401e9217-52d3-4a63-aed2-af28583334a0/fim-password-reset-client-customization?forum=ilm2



MIM 2016 SP1 Portal GUI unstable

$
0
0

GUI looks unstable (misaligned) for some users (on the same system) but it looks good for some accounts. Can anyone advise the way to fix it? 

2FA For MIM Portals

$
0
0

Hi All,

Just checking if it is possible to integrate MIM Portal, SSPReg, SSPReset Portals with a 3rd Party 2FA System, for additional layer of Authentication. What are the typical requirements.

Also I wish to know what it will take to send Notification for Passwords generated in a MIM WF for user provisioning in AD via SMS as against E-Mail.

Thanks


Akinzo

Delta Sync on Export Only MA's

$
0
0

I have "inherited" a MIM implementation that has some delimited text file MA's in which there are only export attribute flows. The script that runs the sync cycle first does Import / Sync from Active Directory, and before each Export / Delta Import from the text file MA's runs a Delta Sync on those MA's.

My understanding is that this Sync is superfluous since we are not reading anything in from those MA's. Is that correct or could there be a purpose for for the Delta Sync that I'm not aware of?

Multi-Valued Attributes

$
0
0

Hi All!

I am starting with a SQL database that contains SecondarySchoolIDs. It contains a value that is coma separated list of multiple 3 digit numbers. (102,103,104)

In Active Directory I have a multi-valued custom attribute called SchoolCodes. it currently, and correctly, has each SchoolCode as single values in the attribute.

In my Microsoft Identity Manager (MIM) metaverse I have an Attribute called SecondarySchoolIDs that is Multi-valued (and I've tried both Indexed and Non-Indexed)

In my Management Agent I cannot get the SecondarySchoolIDs attribute to allow Multi-valued. "Attribute is multi-valued" checkbox is greyed out.

When I look at my pending export, I see that the SchoolCodes attribute is getting modified by removing all of the single values and putting in 1 coma separated string.

What do I need to do to get the  "Attribute is multi-valued" checkbox in my Management Agent selectable? Or... does MIM even support this?

MIM 2016 unable to start the service after sync install

$
0
0

I am unable to get the sync service to start after installation of sync service. It complains about registry entry but it does have the permission to write the key. The sync system also is just a standard user account. I have it sql 2016 install and sync is db owner to try to narrow down the problem. The sync user has local admin right and rights to run as a service. I am not sure what is going on.

I am using sharepoint 2016 with sp1. I did try to RTM version too. I ran into the same issue.

if i put a domain admin in to run the service it is completed and a key is made. I do not want to do that . It has to be permissions but i can not figure out where.

Viewing all 4767 articles
Browse latest View live




Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>
<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596344.js" async> </script>