Remove Group members on the FIM Portal and provide the changes to the AD
Hi I've set up a user and group provisioning from the FIM portal to an active directory. I'm able to create security groups and user accounts on the FIM portal and provide these into my active directory. Providing an user as a member of one of my security groups on the portal works fine and gets synchronized with my active directory but if I try to remove the user as a group member nothing happen's in active directory. can anybody help me?
May 3rd, 2010 8:57pm

I've just got the solution: There is an "Inbound and Outbound" synchronization needed on the group synchronization rule with member=>member as Inbound Attribute Flow.
Free Windows Admin Tool Kit Click here and download it now
May 3rd, 2010 9:28pm

I'm still not able to remove the last user from group members. Any ideas?
May 4th, 2010 12:18pm

Go to the Flow Definition, select Destination and check that "Allow null values to flow to destination" is enabled
Free Windows Admin Tool Kit Click here and download it now
May 31st, 2010 3:08pm

Go to the Flow Definition, select Destination and check that "Allow null values to flow to destination" is enabled I did so but it does not work either.
June 15th, 2010 12:46pm

I'm having the same problem. The last user in the group cannot be deleted either from the portal or from AD. It always gets recreated. Have you found any solution for this problem?
Free Windows Admin Tool Kit Click here and download it now
August 12th, 2010 7:16pm

and I tried the Allow Null checkbox, but that doesn't help
August 12th, 2010 7:24pm

I didn't find a solution for this yet. I've just created a dummy user which is a member of every group. It's not the best "solution" but it works for me.
Free Windows Admin Tool Kit Click here and download it now
August 27th, 2010 4:13pm

We found a solution for this. Instead of having a Delta Import in your run profile after every Export operation on the AD MA, use a DIDS ( Delta Import Delta Synchronization ). This is assuming that you have precedence set on the member attribute of group, to Equal Precedence. You also need to allow null in your sync rules, and also in the attribute flow for the FIM Service MA.
August 27th, 2010 4:52pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics