Proposed FIM and Multiforest Office365

  • 2012年2月8日 下午 06:32
     
     

    I need to create a multi forest environment - and sync in to Office365

    can I use the FIM agent to do this

    FIM becomes my authorative source of user provisioning, and will provision a user into whatever forest I chose together with creating the necessary Office365 account 

    • 已編輯 Hodgy0_2 2012年2月8日 下午 06:33
    •  

所有回覆

  • 2012年3月7日 下午 06:05
     
     提議的解答

    Hi

    I dont think this is supported yet.


    Best Regards // Tommy Clarke - Please follow me @ Blog
    and Twitter

  • 2012年3月8日 上午 10:50
     
     

    We run 2 forests with a domain in each. Currently in BPOS we can use Dirsync in each domain/forest to sync users with the BPOS domain. I had read that it was only possible to sync one ad forest with the Office 365 domain so I asked BPOS Support for clrification. This was their answer:

    "About the ability to sync multiple domains with Office 365. It is best to work with a partner on configuring this. However the article below will walk you through setting up multiple federated domains.

    Error when you try to configure a second federated domain in Office 365: "Federation service identifier specified in the AD FS 2.0 server is already in use."
    http://support.microsoft.com/kb/2618887"



  • 2012年3月27日 下午 06:09
     
     提議的解答

    Tommy is correct that multi-forest sync's are not YET supported, but that is coming in the near future (no ETA releasable).

    The only way to perform this NOW is to sync the multiple forests into a joined forest, and then run DirSync from there into BPOS or O365.  The number of domains really doesn't matter, it is the number of forests.  The reason for this is that users are matched with GUID's from on-premises and, since two forests CAN have the same GUID, the conflicting object would get rewritten each time DirSync ran in the competing forest.


    www.insecurityinc.info