help understanding
I am not familiar with Forefront Identity Manager at all but I think it will help a problem I am having with my site. We are primarily a Windows site that a Unix ERP system. The Unix ERP system limits our usernames because of a 8 or 9 character limit. Can Forefront Identity Manager help us use out standard username and feed Unix it's limited number of characters for the users? If so, then how difficult is this to setup (just looking for a Yes, you need a Unix admin and some major changes in your environment or not to difficult? Thanks, Eric DycusThanks
May 25th, 2012 8:52am

FIM is definitely worth considering if the following outcome would be desirable: FIM has a default user schema which can be extended to include a custom ERPID string property, which for employees might be defaulted to the unique employee code (if this happens to be 8-9 digits)Every FIM user record is linked 1-1 (joined on sAMAccountName or objectSID) with an AD user account, with attributes synchronized, and every FIM user record is stamped with an ERPIDAn ERP management agent (MA) is used to join and synchronize FIM user records with ERP records linked 1-1 (joined on ERPID)When no ERPID exists for a user, and the criteria are met for the user such that a new ERP user is to be provisioned, that ERP account is created and managed by FIM.The AD user account passwords are synchronized with the ERP account using an ERP MA password extension together with PCNS (password change notification service) installed on each AD DC, and the FIM Sync service configured as the PCNS target (assuming the ERP password can be translated easily to meet the inevitable password policy differences between AD and the ERP system!)FIM policy and workflows are created to manage the entire user "on boarding" (new starters), moves (churns) and "off boarding" (terminations) of users in both AD and ERP, as well as any other non-windows systems secured by a unique username/password. While this sort of implementation is a standard FIM deployment scenario, it is a non-trivial exercise to build, configure and maintain, even with properly qualified technical resource. However a wealth of online expertise is available to get you on your way, starting here, and drawing on the online global FIM community that frequent this forum. You can either enlist the services of a local FIM consultancy, invest in training a team of your own using a resource such as this one, or a qualified MS FIM training partner local to you, or opt for a combination of both.Bob Bradley (FIMBob @ http://thefimteam.com/) ... now using Event Broker 3.0 @ http://www.fimeventbroker.com/ for just-in-time delivery of FIM 2010 policy via the sync engine
Free Windows Admin Tool Kit Click here and download it now
May 25th, 2012 10:16am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics