FIM 2010 Portal Access
Just installed new FIM test lab and when I go to the FIM portal I am presented with credential challenge. No matter what I enter it fails. I ran the PowerShell script to check the MPR's, and they are both Enabled.
September 30th, 2011 12:29pm

Enabling FIM Portal Access for a Regular AD User Account. Cheers, MarkusMarkus Vilcinskas, Knowledge Engineer, Microsoft Corporation
Free Windows Admin Tool Kit Click here and download it now
September 30th, 2011 4:46pm

Markus' link is the best place to start, especially since you just got it installed. I would only add that if you are accessing the portal from the WSS server itself and you are using a DNS alias, you may experience the behavior you describe due to loopback checking even if FIM is configured to allow you access or you are the FIM administrator. See http://support.microsoft.com/kb/896861 for more information.
September 30th, 2011 8:33pm

MRMO - you mentioned that you have just installed the FIM portal - are there any users in the portal yet? If you have just installed it, try logging on with the user account that was used to install the FIM portal. Open IE, navigate to http://localhost/identitymanagement and when challenged, enter those same credentials. By default, the administrator account in the FIM portal is the same account that was used to install the component.
Free Windows Admin Tool Kit Click here and download it now
October 3rd, 2011 12:49am

You should check Kerberos constrained Delegation and SPN configuration. When promting for user account/password again and again propably the Kerberos authentication fails. Check also the Security and System-Log for failed Logins or unresolved SPNs/Matthias
October 3rd, 2011 3:16am

Yes. when I RDP into the Portal / Sync server (yes both on same server) I can access the Portal as the FIM-Admin. But when I try to access the portal from my own workstation using my non-proveldeged account it prompts me for credentials connecting to the server.
Free Windows Admin Tool Kit Click here and download it now
October 3rd, 2011 10:56pm

This article might help you verify if everything is OK regarding the Kerberos authentication part: FIM 2010: Understanding Kerberos Authentication Setuphttp://setspn.blogspot.com
October 4th, 2011 5:43am

I did a SETSPN -L on the services I'm using for FIM and found that I had a duplicate SPN. So I deleted all of the SPN's that were registered and then thought what the heck let's see if the portal will fire up before I re-create the SPN's, and wala - the portal is now working. I guess I'm not using Kerberose in my sandbox. Thanks for all your help...
Free Windows Admin Tool Kit Click here and download it now
October 4th, 2011 9:11am

you can do change installation of FIM portal and select the checkbox "Grant authenticated Users access to FIM portal site", it will add the right permissions to SharePoint site ... nevertheless if you want manual actions you need to go Site settings -> users and groups -> select from the right "Site Permissions" -> add Users, "NT Authority\Authenticated Users" and give them Read access. that's the SharePoint part, further more you need to import the users into FIM service with ObjectSID
July 25th, 2012 7:27am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics