Quantcast
Channel: Forum Microsoft Identity Manager
Viewing all 6657 articles
Browse latest View live

Disable "Open ports 5725 and 5726 in firewall"

$
0
0

Hi all,

   I´m installing Forefront Identity Manager Service and Portal Setup. When I arrive to the step about ports in the firewall there are 2 checks disabled and other enabled:

 

Open ports 5725 and 5726 in firewall //disabled

Grant authenticated users access to the FIM Portal site //enabled

Grant authenticated users access to the FIM Pasword Reset site //disabled

What is the reason?. Thanks in advance. BR.

 

 

 


Inbound rule "Forefront Identity Manager Service (Webservice)" is suddenly without any cause disabled. How can it be?

$
0
0

Hi,

I have a strange case where the inbound rule "Forefront Identity Manager Service (Webservice)" is suddenly without any cause disabled.  How can it be?


GH

How to deprovision AD account and keep it in the Metavers?

$
0
0

Hi,

I need to Deprovision AD account and keep them in the Metavers. How do I do that with Extensions? Pleas explain the logic of things:

When / how is the 'Public Function Deprovision(ByVal csentry As CSEntry) As DeprovisionAction Implements IMASynchronization.Deprovision' called? What is triggering it? How?


GH

'Private Sub User_Provisioning(ByVal mventry As MVEntry)' is not starting

$
0
0

Hi,
I'm working on deprovisioning and moving an ADDS account as describe here: http://www.wapshere.com/missmiis/account-deprovisioning-scenarios#Metaverse


The private sub 'Private Sub User_Provisioning(ByVal mventry As MVEntry)' is not starting. I have no better ways of describing it. I placed it under the public sub Provisioning. When I tried to place it in the Provisioning sub I got several #C errors so I stopped right away. Do you have an y Idea why the code is not being called?

 There's no error. No throw. No event in the event viewer.  When running in with Visual Studio in debug mode a break-point is ignored as well.


GH

Minimum FIM password registration quetions in FIM

$
0
0

What is the minimum password secret registration questions that FIM would allow. We are looking to leverage only two simple questions right.

Thanks

FIM password reset error.

$
0
0

Hello All,

Need help!!

I have installed FIM SSPR in our environment and its working fine for all the users. But there is one user who is getting below error while resetting his password using FIM.



Regards,

Suman

SSPR Servcie unavailable

$
0
0

Hello,

We are getting error Http/1.1 Service Unavailable  while using FIM sspr sites.  However, IIS admin service FIm sync and FIm service is running.

Please suggest.

Regards,

Suman

Development and TEST MIM installation on single Active Directory is this possible?

$
0
0
We are planing to do the MIM implementation in our organization and looking for environments to have like Dev and Test. But we have only Active Directory dev. To have dev and test environment do we need to have different active directory for each environment?

MIM Reporting Installation failed

$
0
0

Hi,I tried installing MIM Reporting component, it stopped saying "Installation ended premature".Could anyone help me?

MSI (s) (A8:E8) [07:46:31:973]: Invoking remote custom action. DLL: C:\Windows\Installer\MSI3405.tmp, Entrypoint: EnableReportingLogging
SFXCA: Extracting custom action to temporary directory: C:\Windows\Installer\MSI3405.tmp-\
SFXCA: Binding to CLR version v2.0.50727
Calling custom action Microsoft.IdentityManagement.ServerCustomActions!Microsoft.IdentityManagement.ServerCustomActions.CustomActions.EnableReportingLogging
Exception thrown by custom action:
System.Reflection.TargetInvocationException: Exception has been thrown by the target of an invocation. ---> System.FormatException: Input string was not in a correct format.
   at System.Text.StringBuilder.AppendFormat(IFormatProvider provider, String format, Object args)
   at System.String.Format(IFormatProvider provider, String format, Object args)
   at Microsoft.IdentityManagement.ServerCustomActions.CustomActions.LogOperationException(Session session, String exceptionMessage)
   at Microsoft.IdentityManagement.ServerCustomActions.CustomActions.EnableReportingLogging(Session session)
   --- End of inner exception stack trace ---
   at System.RuntimeMethodHandle._InvokeMethodFast(Object target, Object arguments, SignatureStruct& sig, MethodAttributes methodAttributes, RuntimeTypeHandle typeOwner)
   at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object parameters, CultureInfo culture, Boolean skipVisibilityChecks)
   at System.Reflection.RuntimeMethodInfo.Invoke(Object obj, BindingFlags invokeAttr, Binder binder, Object parameters, CultureInfo culture)
   at Microsoft.Deployment.WindowsInstaller.CustomActionProxy.InvokeCustomAction(Int32 sessionHandle, String entryPoint, IntPtr remotingDelegatePtr)
CustomAction EnableReportingLogging returned actual error code 1603 (note this may not be 100% accurate if translation happened inside sandbox)
Action ended 7:47:10: InstallExecute. Return value 3.
MSI (s) (A8:78) [07:47:10:254]: Note: 1: 2265 2:  3: -2147287035 
MSI (s) (A8:78) [07:47:10:254]: User policy value 'DisableRollback' is 0
MSI (s) (A8:78) [07:47:10:254]: Machine policy value 'DisableRollback' is 0
MSI (s) (A8:78) [07:47:10:270]: Executing op: Header(Signature=1397708873,Version=500,Timestamp=1223572808,LangId=1033,Platform=589824,ScriptType=2,ScriptMajorVersion=21,ScriptMinorVersion=4,ScriptAttributes=1)
MSI (s) (A8:78) [07:47:10:270]: Executing op: DialogInfo(Type=0,Argument=1033)
MSI (s) (A8:78) [07:47:10:270]: Executing op: DialogInfo(Type=1,Argument=Microsoft Identity Manager Service and Portal)
]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434943.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434944.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434945.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434946.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434947.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434948.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434949.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\143494a.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\143494b.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\143494c.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\143494d.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\143494e.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\143494f.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434950.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434951.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434952.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434953.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434954.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434955.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434956.rbf)
MSI (s) (A8:78) [07:47:10:270]: Executing op: RegisterBackupFile(File=C:\Config.Msi\1434957.rbf)
MSI (s) (A8:78) [07Action 7:47:10: Rollback. Rolling back action:
Rollback: EnableReportingLogging

MV attribute set using advanced import flow rule from multiple simultaneous MAs?

$
0
0

I'm trying to set an MV attribute, displayName, using advanced import flows based on multiple MAs.  I understand that I can simply use precedence on the MAs to define the MV attibute but one value that's being used in the computation, obfuscatedPerson, is only available from one of the MAs so that approach will not work.

I can use an advanced export flow rule to take the obfuscatedPerson attribute into account but then I end up with a metaverse view that doesn't correctly represent what's being populated in the connector spaces.

Is there any way to get this to work with an import flow rule?

Cheers,

      Ian Thomas

ECMA for exporting members (Reference type) is not capturing deletes.

$
0
0

Lets take an example of group say X keeping 4 members and 2 are deleted and 1 is added in FIM Portal and finally change is synchronized to ECMA Connector Space as shown below

1) delete ---
2) delete---
3) none---
4) none--
5) add--

when I perform export using ECMA , I do not receive the delete as (ValueModificationType.delete). Rather, I get 3 adds (ValueModificationType.add)   -- 2 for none (not changed in FIM Portal ) and 1 for the added one. I am expecting to see the deletes as well so that i can explicitly delete the members from AD.

I have also tried the possibility of using Capabilities.ExportType = MAExportType.AttributeReplace instead of Capabilities.ExportType = MAExportType.AttributeUpdate;

Any help would be appreciated. Thanks!! Vinay
This is the code fragment I am using correctly.

       
Capabilities.ExportType = MAExportType.AttributeUpdate;

 public PutExportEntriesResults PutExportEntries(IList<CSEntryChange> csentries)
        {

            PutExportEntriesResults Results = new PutExportEntriesResults();

            foreach (CSEntryChange change in csentries)
            {


   foreach (string AttributeName in change.ChangedAttributeNames)
                {
                    if (AttributeName == "member")
                    {
                        
                        if (attributeChange.ModificationType == AttributeModificationType.Replace ||
                            attributeChange.ModificationType == AttributeModificationType.Add)
                        {
                           
                            foreach (ValueChange value in attributeChange.ValueChanges)
                            {
                                string DN = value.Value.ToString();
                                if (value.ModificationType == ValueModificationType.Add)
                                    lstaddMembers.Add(DN);
                                if (value.ModificationType == ValueModificationType.Delete)
                                    lstdelMembers.Add(DN);
                            }

}

Accessing http://:82/identitymanagement always prompts for credential

$
0
0

Followed this documentation for MIM 2016 (https://docs.microsoft.com/en-us/microsoft-identity-manager/deploy-use/install-mim-service-portal), already install everything up to MIM Service and Portal. Was about to lunch the MIM Portal but i cannot continue since it keeps asking me for the credential. Have tried every possible credentials but to no avail.

Thanks in advance for the help.

Problem with radio button on FIM Custom activity UI

$
0
0

Hi,

 

I have developed a new custom activity for FIM and deployed it. In the activity UI, we provide three radio buttons to select different options. The activity UI looks like below:

 

For Option 1 selection, the activity receives the string Option 1 and so on for other options. Based on that value, we run different business logic in the activity. However, I am facing issues when I select Options 2 and 3. When I select Option 2 or 3, it gets selected and the value received in the activity during execution is also proper. However, when I open the workflow to check what Option we have selected, then the UI always displays "Option 1" though it is sending values for Option 2 and 3 as expected during execution.

 

Any idea what can cause this error on the FIM activity UI?

 

Can I sync office 365 Unified groups with AD Connect?

$
0
0
Is AD connect handling group membership the same for office 365 unified groups?

GH

FIM Sync Service "extension-dll-exception" error

$
0
0

Could someone please help me out with this error below:

Recently, when I run a FIM Full Sync and/or Delta Sync, I've started getting this error, and I can't get new users in FIM to feed over to Active Directory, nothing has been changed in the sync ruled mentioned:


FIM SSPR site certifcate change

$
0
0

Hello guys,

Can someone help me in identifying how and from where to change SSPR site certificate hosted on internet.

Regards,

Suman

Multiple Condition in IIF and do nothing if value is false

$
0
0

Hello,

I want change DN of user if two condition is meet.

My condition Company attribute and JobTitle attribute and i want change DN of user is two attribute are meet and want nothing change if conditions doesn't happened.

Please help me that how can i do this?

FIM ECMA Export for attribute change doing nothing

$
0
0

Hey all,

I'm starting to toy around with ECMA based on the 2.0 framework. I more or less copied the sample from:Appendix B: SQL_ECMA2 Source Code

Imports are going just fine. I also wrote a classic rules extension which generates an accountName. That's the value I want to write back to the SQL db. On my synchronization run I can see the export is generated. And on my export I get a success. But in SQL nothing changes. Then on the import I get an "exported change is not reimported error".

I added some debug.writelines. and the thing I found out: the modificationType is the following: csentryChange.AttributeChanges[attribName].ModificationType == AttributeModificationType.Update

The attributeName is AccountName

I would expect to find the value in csentryChange.AttributeChanges[attribName].ValueChanges[0].Value.ToString();

The weird thing is that that ValueChanges[0] is empty... However If I pick ValueChanges[1] it contains the accountName?! So I'm wondering if I did something wrong in my attribute flow config, precedence config, or if the code is flawed? Why is there an "empty" valuechange?

Any thoughts?

Kind regards,

Thomas


http://setspn.blogspot.com

MIM 2016 Portal date format not changing

$
0
0

Hi,

Our MIM Portal date format (e.g. employeeStartDate, search Requests, etc) are all in the US format of M/dd/yyyy.

Changing the underlying operating system's regional settings, the client's regional settings, MIM Portal's Time Zone settings, SPS Foundation's Regional settings has no effect on the MIM Portal date format.

Our MIM 2016 version is 4.3.2195.0.

We require the dates to be in the dd/mm/yyyy format.

Please could someone validate this on their MIM installation, and if possible, provide a work around - or is this a bug?

Thank you,

TZ

FIM 2010 - Portal Groups - Invalid Members

$
0
0

Non-admin users see Invalid Members on some security groups in the portal but Admin-user doesn't see. What is the problem?

What should I check?

Viewing all 6657 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>