Bookmark: https://aka.ms/FIM2010Security
↑ Back to top
= Link to the other Wiki pages of this guide.
Purpose & Scope
Purpose
In scope
Out of scope
Document & Naming Conventions
References
FIM vs MIM
Naming conventions
Account types
Generic security principles
Threats
Principle of least privilege (PoLP)
Privilege separation
SoD (Segregation of duties) & Account Isolation
4-eyes principle
Number of accounts vs security risk
Additional reading
Best practices
Best practices for security
Legend
Pre-installation: Backend configuration
Pre-installation: Account creation
Pre-installation: Account lock down
Post-Installation: Set operational admins
Hotfix installation
Pre-installation: Securing the FIM backend infrastructure
SQL Server
IIS5
SharePoint6
Pre-installation: Securing FIM/MIM Components
FIM/MIM general
FIM/MIM Setup
FIM/MIM Service
FIM/MIM SSPR – Registration & Reset portals
Management agents
FIM/MIM Certificate Management
FIM/MIM Reporting (SCSM)
BHOLD
Security during Installation
FIM/MIM setup account – functional account
Post-installation: Securing FIM
FIM/MIM Portal (SharePoint)
Portal Security
Post-installation: Securing FIM Backend
FIM/MIM Default folders
Source code location
Security (General)
FIM/MIM
SharePoint
IIS
Security Best practices
MIM 2016 Product info
Glossary, abbreviations & acronyms
Appendix A: Account overview for FIM basic configuration
Appendix B: Documentation - Compact Check lists
Post-Installation
Appendix C: Security Implementation Sign-off sheet
CISO or authorized security delegate
Sign off
FIM Options implemented
Derogations - Exceptions implemented
Download the entire guide at once, in PDF version from Technet Gallery.
This document has some additional content, which is not available online.
Great thanks to the following people to provide feedback and additional content on the source documentation (see offline document for download)
Due to privacy reasons some reviewers have requested to be kept anonymous, but their help is greatly appreciated!
Return to Table of Contents of the article series.