Does Provsioning in AD DS require FIMMA?
I have a SQL view from my Student Informations Team and am able to see the data via Metaverse search. My goal is to get the users from the SQL view into FIM and provision them to AD in specicfied OUs. Can you provision direct from a ADMA? Or does it require the FIMMA and/or Portal? TLight Not a FIMster yet! :)
July 22nd, 2011 9:16am

Hi there TLight - It is possible to use the FIM Synchronization Service component, with classic (coded) provisioning rules to transition your data objects from the metadirectory to AD DS OUs via the AD DS MA. The great thing with the FIM Service/Portal is that you can use what's known as declarative provisioning, essentially codeless provisioning rules, to transition your data objects from FIM to AD DS OUs via the AD DS MA. A bonus if you're not familiar with OOP & .Net programming. Does this help? Cheers Tom Houston, HP Enterprise Services - UK Identity Management Practice
Free Windows Admin Tool Kit Click here and download it now
July 22nd, 2011 9:25am

Thank you Thomas. You have confrimed what I thought to be correct! Yes I am not a programmer by a longshot. So this leads me to the FIM portal I have installed, the "console" I am able to see at a "URL: FIMSERVER/IdentityManagement/default.aspx" but there is not any data in it, when I go to add the synchronization rules, the Drop downs are empty?? What actually populates the portal with the data? I all makes since but I just haven't found the right puzzle piece yet! :) I first saw FIM four weeks ago and I have 6 business days left to figure this out! I'm still smiling.... This is what i have so far! From Student Information I am able to generate a preview and I see a success full sync and I can even metaverse search for one of those students ... looks good! Then I can see the 40K+ records in the ADMA as 40K+ Filtered deletions/Objects (discovery) and disconnectors (inbound sync).
July 22nd, 2011 11:38am

The fastest route to get something to work is to walk through these two documents, first: Introduction to Inbound Synchronization Introduction to Outbound Synchronization When you are done with that, you can use this doc: Introduction to Publishing To Active Directory from Two Authoritative Data Sources. Don't - just DON'T :-) - work directly with your 40K+ objects - this makes zero sense. You should build a pilot with a few users, first! Cheers, MarkusMarkus Vilcinskas, Knowledge Engineer, Microsoft Corporation
Free Windows Admin Tool Kit Click here and download it now
July 22nd, 2011 12:17pm

Markus, Thanks for the "Publishing" Document I have not read that one yet. That will be handy for the HR system in a few months. First things first... Students arrive in 6 days and 3 hours or so. :) Yes, I have read and done both the Inbound and Outbound Synch documents. My problem is in the "Create the outbound/inbound synchronization rule" Scope tab... the dropdowns are not populated! I cannot complete the process in the documents due to the lack of these drop downs being empty. The drop downs all say <Please select an item>. I have not been able to get past this step. Which brings me back to the same question... What actually populates the portal with the data? It is almost like the portal isn't talking to FIM service or something. Maybe I have configured it all wrong or installed incorrectly? I don't know how to send a screen shot or I would. Again, thanks to everyone replying to this!! Hope I can return the favor some day! tlight
July 22nd, 2011 1:30pm

There are two routes between sync and the FIM service. One is based on the FIM (imports / exports) and anotherone is based on replication. Your issue is related to the replication path. One thing you can do right away is to check the event log for related entries. You can also try running this script: How to Use PowerShell to Initiate the Internal Synchronization of the Synchronization Configuration Data. Cheers, MarkusMarkus Vilcinskas, Knowledge Engineer, Microsoft Corporation
Free Windows Admin Tool Kit Click here and download it now
July 22nd, 2011 2:01pm

The only thing in the event viewer is the is an entry on the Microsoft.ResourceManagement.Service under Applications and Services:: F I M. Nothing on Replication in applications, or system of the Windows Logs. I also ran your script and no errors. But I still don't have any data on the scope screen? Arrrgh! tlight
July 22nd, 2011 3:08pm

Hey Mark, I have been able to Preview and Commit. I get that individual into AD if I commit them one at a time. However when I try doing the full sync to provision all the users in SQL data from the run profiles it imports , syncs but export shows all Zeros?? only get users if I commit one at a time??? Any Ideas?
Free Windows Admin Tool Kit Click here and download it now
August 27th, 2011 4:06pm

the answer is you have to have sync setup correctly!!! Laughs!
August 27th, 2011 5:18pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics