Detecting changes done by external system
Hello everyone, we are working on a solution to detect if a system administrator on a connected system (connected through a MA in FIM 2010) did a change directly on the system for an object that should be synced with FIM. The idea is that we need all changes to objects (users in this case) to be done in FIM portal and we want to know when we import/sync from an MA if someone did changes on the system itself. looking forward for any hint. ThanksMM
April 22nd, 2010 10:57am

Hi Marie-Ange! I started out a series of articles together with Markus on how to detect Non-Authoritative Accounts but unfortunately I've been to busy to complete it (for which I've got really bad conscience). Currently there are two part under the experts corner that describes how this could be done but they doesn't describe a working solution just an embryo towards it. If you read them you would understand how it could be done but you'll have to work out the details yourself. Detecting Non-Authoritative Accounts – Part 1: Envisioning Detecting Non-Authoritative Accounts – Part 2: Design Also, Markus has written a great guide on the basics for this topic: Understanding Expected State Detection //Henrik Henrik Nilsson, ILM/FIM MVP Blog: http://www.idmcrisis.com Company: Cortego (http://www.cortego.se)
Free Windows Admin Tool Kit Click here and download it now
April 22nd, 2010 11:19am

Thanks Henrik, I will read them and see how to continue from there :)MM
April 22nd, 2010 11:24am

Good article, Henrik. In my test scenario, I am bringing in person objects from AD into FIM portal to manage only a select few attributes on the person object and flow those out again into AD. AD continues to be authoritative for person object for provisioning, deprovisioning and management of attibutes (including co-managing those select few attributes that FIM also manages). This is a likely scenario that will continue for months until the time FIM and HR are the only two authoritative sources. On the select few co-managed attributes, I need to implement ERL/ERE on similar lines as you've outlined in Part 2: Design. Awaiting Part 3, and hopefully will see confluence in your approach and mine ;-) Regards, Anu Anu
Free Windows Admin Tool Kit Click here and download it now
May 3rd, 2010 1:32am

Is part 3 going to be available soon?MM
May 4th, 2010 10:52pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics