FIM 2010 Portal Account removed, now cannot see portal administration links
Ok.. This is really silly. I have been administering the FIM 2010 Portal (Sync Rules, Sets, Workflows, etc...) using the same account I performed the install and configuration of FIM 2010 Portal. I accidentally deleted the adminstrator account within the portal > Users page (not within AD). Once I did this I could no longer see any of the Administration page links, and was presented with only a standard users Portal console. I figured i would just perform a syncrhonization cycle to get the account back into the portal, and that worked; however the account is still unable to see administration links. The account is still listed within the SharePoint site's Forefront Identity Manager Owner group, and I cannot figure out how to get the administration console configuration visible again. Please help!
June 16th, 2010 6:28am

accounts need to be in Administrators set to be FIM Admin u can try to logon as the sync account and see if u can fix that
Free Windows Admin Tool Kit Click here and download it now
June 16th, 2010 9:14am

I tried that an I get the "Service not available" page. I did figure the Administrator set was the fix; however there has to be a way to get a user into that set without going through the portal.
June 16th, 2010 5:05pm

u might try to use the config migration tool as a generic WS client to do that. u should at least backup the db first messing it up furtherThe FIM Password Reset Blog http://blogs.technet.com/aho/
Free Windows Admin Tool Kit Click here and download it now
June 16th, 2010 6:03pm

Thanks for your reply Anthony. Are you essentially saying export the configuration, edit the (-policyConfig) configuration file and then reimport? $pilot = Export-FIMConfig -uri http://localhost:5725/ResourceManagementService -policyConfig -schemaConfig -portalConfig
June 16th, 2010 6:52pm

i am not sure if that's policy though. Policy refers to Management Policy Rule. You will be interested in the SetsThe FIM Password Reset Blog http://blogs.technet.com/aho/
Free Windows Admin Tool Kit Click here and download it now
June 16th, 2010 11:50pm

Sets would be in the policy export but a non-admin can't update sets and it doesn't appear that the Builtin Sync account has rights to modify sets either. I think the only solution in this case is to export the configuration and roll the db's back to an earlier state. Then you can import the config and get back to where you were; however, you'll want to take care to edit out the Administrator set update otherwise you'll be back to the same point.Brad Turner, ILM MVP - Ensynch, Inc - www.identitychaos.com
June 17th, 2010 2:16am

I have never tried this - so I just wonder... Since the account has been synced back into FIM, is it possible and what happens, when the account was made a static member of the Administrators set again. Has anyone every been in this scenario and tried this? Cheers, Markus Markus Vilcinskas, Knowledge Engineer, Microsoft Corporation
Free Windows Admin Tool Kit Click here and download it now
June 17th, 2010 2:39am

I would have to believe that if the account used to perform the policy export cannot read sets, then "Set" key information will not be contained within the Export and therefore will not overwrite the rollback configuration. I HOPE!
June 18th, 2010 9:53pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics