Identity Management

Designing and Implementing RBAC Solutions with FIM 2010 Group Management

After I introduced Brad Turner and turned the time over to him, he showed off some really cool FIM extensions to enable RBAC. He even showed how it fits the NIST RBAC definitions even through level 3. The key design decision was to extend the Set and Group objects. The Set then functions as a role. This allows for both explicit and criteria based membership. A new object type for a Role Membership allows for the user’s membership in a role to expire at an individual time.

Continue reading

FIM Best Practices: Sizing Your FIM Installation

I had a lot of fun presenting this session. Largely based on chapter 5 in volume 1 I showed how to decide on your High availability approach, how that impacts your topology choice, and then how to estimate your scale, load, and complexity points. Then based on those factors figure out how big to make your SQL Server that hosts the FIM service database. In the middle I did enjoy putting in a plug for our Ensynch sponsored green, dishwasher safe water bottles, as I took a drink of my fruit punch Gatorade mix.

Continue reading

Can PXEs Fly? FIM and SCCM Integration (Rob Allen)

I was looking forward to this one, but got called away. I hope to look at the slides soon. http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices

Continue reading

Creating Management Agents with the new EZMA (Andreas Kjellman)

At TEC 2011, Andreas Kjellman of Microsoft, who “owns” the FIM synchronization engine, showed off the upcoming EZMA framework. The problem: The existing eXtensible Management Agent (XMA) does not have a call based import method, we are limited to using GUIDs as the initial anchors, and we don’t have partitions in an XMA. Solution EZMA – which, IMO, will actually be a little harder to do than an XMA but will allow the developer to do much more that will make the FIM admin’s life easier.

Continue reading

Files, FIM, and PowerShell (James Booth)

James Booth former Microsoft Group Program Manager for MIIS (precursor to FIM) presented on using PowerShell to process files in preparation for consumption by FIM. James points out that “In the beginning, it was all files.” These call based MA’s are the new kids on the block, also said that at Microsoft in 2000 the philosophy was “XML is the answer, now what is your question?” James has posted his new commandlets to GitHub https://github.

Continue reading

TEC 2011–FIM Workflows Deep dive

I am already in Las Vegas, prepping to assist my fellow Ensynch coworkers, Joe Zamora, and Rebecca Croft as they lead an awesome value packed pre-conference workshop tomorrow (Sunday) morning at 8 AM to 12 PM (noon). Jerry Camel and Brad Turner will also be around to assist. There are so many good sessions to attend this time here are some of the ones I am looking forward to: Monday morning gets the FIMsters off to a great start with a choice of two great sessions:

Continue reading

Making Sense of the Cloud

National Roadshow Series: 2 High Value Sessions in 1 Business Focused Technology Briefing from Leading Industry Experts at Ensynch and Microsoft It’s time to make sense of the plethora of rhetoric around the term “Cloud.” It’s time to cut through the hype and figure out how to leverage the latest Dynamic Private Cloud and Public Cloud technologies and provide real value to your business. Why Attend? Learn how organizations worldwide are realizing tremendous business value as they begin to migrate portions of their business to securely provide IT as a service through private and public cloud solutions.

Continue reading

Webinar: Cloud’s Silver Lining: Identity Management

Business Insights Webcast: The Cloud’s Silver Lining: Identity Management Join Us for an Informative Webcast on the Value of IDA in the Cloud - Part 2 in a Series of Webcasts from Microsoft FIM MVP David Lundell - Identity Management is a critical component to realizing the true value of the Cloud. Solutions from Microsoft including Forefront Identity Manager (FIM), Active Directory Federation Services (AD FS), and Microsoft Forefront Unified Access Gateway (Forefront UAG) allow you to get the most out of your cloud applications (such as Office 365, BPOS, and other Software a Service (SaaS) solutions); while enabling a seamless transition in managing the identities of your users.

Continue reading

Get FIM Training from Author of FIM Best Practices Volume 1

Come get FIM training from David Lundell, FIM MVP and author of FIM Best Practices Volume 1. Register by emailing FIMTraining@Ensynch.com, providing your contact info, which class and date you want to attend. You will then be contacted to complete the registration. On Feb 8th - Feb 11th in downtown Phoenix (class will start at 8 AM), I will be teaching 50382A Implementing Forefront Identity Manager 2010 and of course adding in lots of valuable information from various FIM implementations that I have performed and supervised.

Continue reading

Law of Unintended Consequences

Any news on certification paths for IDM? Derek A. Hanson - Dec 6, 2010Any news on certification paths for IDM? Hey Derek, No news yet. Just my own speculation but I would expect to see an exam covering several Microsoft Identity Technologies emerging sometime next year.

Continue reading