How to change FIM service accounts?
Hi,
Is there a way to easily modify the FIM Sync Service & FIM Service service accounts?
We have a case that the user that installed FIM (and now manages FIM) is also the account running the FIM Sync Service & FIM Service service.
Thank you
March 19th, 2011 2:56pm
The following is how I would try it, having full backups of all involved databases. I don't provide any warranty that the items below will work as expected.
For the FIM Service: run the installer in change mode and provide an other user for the FIM Service to run udner
For the FIM Synchronization Service: give the new service account permissions on the SQL db and try changing the identity of the service (in services.msc)
Good luck,
Thomas
http://setspn.blogspot.com
Free Windows Admin Tool Kit Click here and download it now
March 20th, 2011 1:11pm
OK will try tomorrow, thanks
March 20th, 2011 2:08pm
If you back up the license key first (to be sure to be sure), uninstall the sync service and reinstall it, you'll get the chance to change the service account and the wizard will take care of all permissions for you (so long as you the installer has sufficient
rights to the SQL instance to create a database!). The repair on the sync service doesn't allow you to do this ... but there is no problem with the uninstall/reinstall approach, as the wizard will relocate the same db as before and you won't lose any
config or data.Bob Bradley, www.unifysolutions.net (FIMBob?)
Free Windows Admin Tool Kit Click here and download it now
March 20th, 2011 3:25pm
If you back up the license key first (to be sure to be sure), uninstall the sync service and reinstall it, you'll get the chance to change the service account and the wizard will take care of all permissions for you (so long as you the installer has sufficient
rights to the SQL instance to create a database!). The repair on the sync service doesn't allow you to do this ... but there is no problem with the uninstall/reinstall approach, as the wizard will relocate the same db as before and you won't lose any
config or data.Bob Bradley, www.unifysolutions.net (FIMBob?)
March 20th, 2011 3:25pm
The following is how I would try it, having full backups of all involved databases. I don't provide any warranty that the items below will work as expected.
For the FIM Service: run the installer in change mode and provide an other user for the FIM Service to run udner
For the FIM Synchronization Service: give the new service account permissions on the SQL db and try changing the identity of the service (in services.msc)
Good luck,
Thomas
http://setspn.blogspot.com
THe sync service service account SID is also burned into the FIM service side so you would need to update its' corresponding user object in FIM.My Book - Active Directory, 4th Edition
My Blog - www.briandesmond.com
Free Windows Admin Tool Kit Click here and download it now
March 20th, 2011 4:47pm
The following is how I would try it, having full backups of all involved databases. I don't provide any warranty that the items below will work as expected.
For the FIM Service: run the installer in change mode and provide an other user for the FIM Service to run udner
For the FIM Synchronization Service: give the new service account permissions on the SQL db and try changing the identity of the service (in services.msc)
Good luck,
Thomas
http://setspn.blogspot.com
THe sync service service account SID is also burned into the FIM service side so you would need to update its' corresponding user object in FIM.My Book - Active Directory, 4th Edition
My Blog - www.briandesmond.com
March 20th, 2011 4:47pm
Bob,
I agree on the uninstall/reinstall (with a backup of the
encryption key). But what with the scenario where you already updated to update 1. That will get complexer isn't it?
The RTM installer might complain about the updated DB. not sure though.
Kind regards,
Thomashttp://setspn.blogspot.com
Free Windows Admin Tool Kit Click here and download it now
March 20th, 2011 4:49pm
Bob,
I agree on the uninstall/reinstall (with a backup of the
encryption key). But what with the scenario where you already updated to update 1. That will get complexer isn't it?
The RTM installer might complain about the updated DB. not sure though.
Kind regards,
Thomashttp://setspn.blogspot.com
March 20th, 2011 4:49pm
Here is what we eventually did (same results in test lab as production) to fix the FIM 2010 RTM:
reinstalled FIM Sync Service with correct service account (no uninstall) reinstalled FIM Service & Portal with correct service account (no uninstall)
the systems then perform extremely slowly (takes about 15 minutes to load the mmc!)
after applying Update 1 performance and functionality were back to normal
thank you to everyone as usual for your help
PS. Thomas - good question...what if Update 1 is already deployed...will have to test it one day
Free Windows Admin Tool Kit Click here and download it now
March 21st, 2011 9:31am
Thomas - you may want to review this posting:
http://setspn.blogspot.com/2010/11/recovering-or-installing-additional-fim.html
Essentially you can’t install an RTM Service to a RTM + U1 database.
March 23rd, 2011 11:19am