Enabling FIM Portal Access for a Regular AD User Account
Experts Corner Article To be able to access the FIM portal as a regular user, the following MUST be true: · The user has an AD user account · The attributes “Domain”, “AccountName” and “ObjectSID” must have values populated about that AD user account synched by the FIM Sync Engine · The correct permissions have been configured for the AD user account in the FIM Portal (see more below) To configure the correct permissions in the FIM Portal to allow portal access for regular users, additional configuration checkboxes appear during the installation of the FIM Portal: · Grant Authenticated Users access to the FIM Portal Site (must be checked if you want to allow access to the FIM Portal) · Grant Authenticated Users access to the FIM Password Reset Site (must be checked if you want to allow access to the FIM Password Portal) In addition to this all, you as an administrator need to enable a few MPRs which by default are disabled. I’m talking about the following MPRs: · ”General: Users can read non-administrative configuration resources” · “User management: Users can read attributes of their own” You can check the MPRs in the FIM Portal or use can use this powershell script to do that for you. This is for simple plain FIM Portal access. If you want to allow a user to do more, you need to create and/or enable additional MPRs. Go to the Experts Corner Jorge de Almeida Pinto [MVP-DS / AD DS TechNet Forums Moderator] [Sr. Technical Consultant @ Oxford Computer Group] (http://blogs.dirteam.com/blogs/jorge/default.aspx) (http://www.oxfordcomputergroup.com/)
December 11th, 2009 11:08pm

You can use this script to test your MPR configuration for this scenario.Cheers,MarkusMarkus Vilcinskas, Knowledge Engineer, Microsoft Corporation
Free Windows Admin Tool Kit Click here and download it now
December 12th, 2009 1:07am

You can now use this powershell script to fix missing ObjectSID's - just pass in the account name and domain for the account you wish to fix...Brad Turner, ILM MVP - Ensynch, Inc - www.identitychaos.com
March 29th, 2010 7:54am

To configure the correct permissions in the FIM Portal to allow portal access for regular users, additional configuration checkboxes appear during the installation of the FIM Portal: · Grant Authenticated Users access to the FIM Portal Site (must be checked if you want to allow access to the FIM Portal) · Grant Authenticated Users access to the FIM Password Reset Site (must be checked if you want to allow access to the FIM Password Portal) Can we set this after the installation? I have enabled all the required MPRs, ObjectSID's, Domain and AccountName correctly set. Still a regular user is not able to log in. Getting an error, You do not have permission to access this site. Please contact your help desk or system administrator. > Go to Forefront Identity Manager home page Am I missing something here? Cheers Sachin
Free Windows Admin Tool Kit Click here and download it now
April 23rd, 2010 7:22pm

These settings can be found inside SharePoint itself. As a SharePoint admin, select "Site Actions" in the top right corner and then select "Advanced Permissions". In the permissions for the site itself those checkboxes will grant "NT Authority\Authenticated Users" Read access. /AndreasThis posting is provided "AS IS" with no warranties, and confers no rights. Use of included script samples are subject to the terms specified at http://www.microsoft.com/info/copyright.htm
April 23rd, 2010 7:30pm

Jorge >>The attributes “Domain”, “AccountName” and “ObjectSID” must have values populated about that AD user account synched by the FIM Sync Engine u missed DisplayName
Free Windows Admin Tool Kit Click here and download it now
April 23rd, 2010 9:36pm

Thanks Andreas. I have checked the "Advance Persmission" and they are configured as, 1. Users/Groups Type User Name Permissions NT AUTHORITY\authenticated users Domain Group NT AUTHORITY\authenticated users Read 2. Ran the script provided by Markus to config that the req MPRs are enabled 3. Ran the script provided by Brad to check the ObjectSID. It matches the AD ObjectSID Still getting the same error. Could I be missing any other attributes/settings? Cheers Sachin
April 26th, 2010 1:06pm

I had this problem and if you are following the Syncronize Users from Active Directory Domain Services on the Wiki you need to add a attribute flow on the FIMMA Management Agent for the accountName item in the Person object! This solved the issue for me!James Bulgo Snr ICT Officer Linc Cymru Housing Association
Free Windows Admin Tool Kit Click here and download it now
November 16th, 2010 8:15am

I had this problem and if you are following the Syncronize Users from Active Directory Domain Services on the Wiki you need to add a attribute flow on the FIMMA Management Agent for the accountName item in the Person object! This solved the issue for me!James Bulgo Snr ICT Officer Linc Cymru Housing Association
November 16th, 2010 8:15am

Thanks, James...I had the same issue which was resolved by following your steps.
Free Windows Admin Tool Kit Click here and download it now
December 20th, 2010 12:16pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics