Ask a questionAsk a question
 

AnswerFIM 2010 RC1 eval Portal Sync issues

  • Friday, October 30, 2009 8:01 PMMaxim M Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    Hey guys, I am having an issue where I am unable to create syncronization rules within the FIM 2010 portal (Administration >Sync Rules). Currently there are no rules in there, so when I try to create some I get stuck on the second tab (Scope). I am supposed to pick the Metaverse Resource Type, the External System and the External System Resource Type. However, the only option available in either of those fields is the <Please Select an item>.

    Additionally, when I go to administration > Domain Configurations, I see my lab domain listed, but when I try to edit it I can see that the required field Forest Configuration is not populated. I can't search or resolve the current forst in the field.

    Did I miss something obvious during the installation/initial configuration? I followed the install guide step by step, but cant figure out what the issue might be.

    Maxim

Answers

All Replies

  • Monday, November 02, 2009 6:47 PMCapriole Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Could be something wrong with your management agent(s) - the list of external systems is populated from the management agents you have created.
    Maybe try exporting the MAs you have, deleting and re-creating. Or create a dummy text MA and check whether it appears in the external system list...

    HTH.
  • Monday, November 02, 2009 6:49 PMMarkus VilcinskasMSFT, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    What scenario are you working on?

    Cheers,
    Markus
    Markus Vilcinskas, Knowledge Engineer, Microsoft Corporation
  • Monday, November 02, 2009 7:45 PMMaxim M Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     

    I'm trying to stand up a basic FIM installation connecting to a test AD domain OU. I would like to test the user portal features to enable users to join/leave distribution lists, reset their password, etc. Later on I would like to add an (non-trusted) ADAM instance and sync a particular OU from AD to the ADAM instance. Management of ADAM users through the portal would be awesome to have as well.

    I can see that new changes make it through when i run Delta/Full sync, but somehow they never make it to the portal. Is there a guide on how exactly to configure the agents and more specifically on the options relating to the portal?

    Even though I see new changes come through (in the sync statistics) I could've messed up the inital configuration.

    Regards,
    Maxim

  • Monday, November 02, 2009 10:51 PMCapriole Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    You probably want to take a look at "The Introduction to inbound synchronisation" - probably the easiest way to get your AD users provisioned into the portal. http://technet.microsoft.com/en-us/library/ee534911(WS.10).aspx
    Sadly the example doesn't use an AD MA as the source, it has a file MA. If you want to use self service password reset (SSPR) make sure you populate domain and objectsid attributes in FIM, as well as those listed in intro to inbound sync.

    Once you have AD users provisioned into FIM Portal then you can follow this to implement SSPR http://technet.microsoft.com/en-us/library/ee534892(WS.10).aspx

    HTH
     
  • Tuesday, November 03, 2009 1:27 AMMarkus VilcinskasMSFT, ModeratorUsers MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     Answer
    You should follow the steps outlined in the Introduction to Distribution Group Management.
    This would make it easier to assist you in case of a problem.

    Cheers,
    Markus 
    Markus Vilcinskas, Knowledge Engineer, Microsoft Corporation
    • Marked As Answer byMaxim M Wednesday, November 04, 2009 6:38 PM
    •  
  • Wednesday, November 04, 2009 6:36 PMMaxim M Users MedalsUsers MedalsUsers MedalsUsers MedalsUsers Medals
     
    Hey Guys,

    Thanks for the replies ! I am in the process of implementing the scenario described in the Introduction to Distribution Group Management link that Markus linked above to serve as a starting point for my testing. I just passed the point i was having issues with initially so this question can be marked as closed. I will also keep Caporiole's link regarding implementing SSPR as I will require it later on.

    Bottom line was that my Management Agents were not configured correctly. The scenario Markus linked me to helped shed some light on how the configuration should be started.

    Maxim