SlideShare a Scribd company logo
SESSION CODE: SEC 318 Paul Conroy Technology Specialist	 Microsoft Fim r2 deep dive (c) 2011 Microsoft. All rights reserved.
WARNING This isn’t an introduction to FIM, for that…. BING – technet implementing forefront identity manger (c) 2011 Microsoft. All rights reserved.
Agenda Web Based User Self Service Password Reset Enhanced Reporting Simplified Reporting and Troubleshooting Tools Enhanced Performance Enhanced MA connectivity (c) 2011 Microsoft. All rights reserved.
Web Based User Self Service Password Reset End user can register and reset from a web browser on a machine that isn’t domain joined ….even if the browser is not Internet Explorer Admin can deploy registration and reset portals on extranet-facing host Admin can configure password reset for external users using the same model as for internal users Upgrade from FIM 2010 SSPR to FIM 2010 R2 without breaking an existing FIMsolution (c) 2011 Microsoft. All rights reserved.
FIM Password Reset ComponentsIllustrative Topology (c) 2011 Microsoft. All rights reserved.
Setup Experience – PW Reset Portals 2 Specify whether host is extranet accessible Choose to install Password Portals 1 4 3 Password Portals visible in IIS Manager Specify AD user account for Portal
Distinguishing Requests from ExtranetHow this works - Registration Security context is determined without reliance upon IP addresses Registration Portal Makes registration request to the FIM Service in the context of the Registration Portal’s AD identity FIM Service Identifies registration requests from the Registration Portal’s identity
Distinguishing Requests from ExtranetHow this works - Reset Reset Portal Makes password reset request to the FIM Service in the context of the Reset Portal’s AD identity FIM Service Identifies reset requests from the reset portal. (c) 2011 Microsoft. All rights reserved.
Authentication and password reset Registration is a process of establishing credentials for alternative authentication Many have a higher bar for authentication from the Internet, than from a domain-joined machine Extensibility for customer-specific needs (c) 2011 Microsoft. All rights reserved.
User Self Service Password Reset demo
Enhanced Reporting ,[object Object],Add historical reporting for FIM-managed objects Includes frequently-requested reports, e.g.: Group membership changes over time Request history Person and group change history Report data store is extensible Can be extended to store history of custom FIM Service objects and attributes Enable customers and ISVs to build custom reports (c) 2011 Microsoft. All rights reserved.
How to Answer these Questions State Events ,[object Object]
What groups does a particular person belong to?
Who is person Y’s manager?
Who joined group A today?
What groups had new members today?
How many new people joined the company today?Current Source: FIM requests via portal Source: FIM database via portal ,[object Object]
How did a group’s membership change over time?
Who approved a group join?
How did a set filter definition change over time?
What groups did person A have access to on November 4th, 2009?
What was a group’s membership last July?Historic Source: FIM Portal and Reporting Source: FIM reporting
Reporting Architecture
Out of Box Reports
Example Membership Change Report: Group Membership Change Samantha removes Colin from the Marketing group Colin changes roles and is added, automatically, to the Finance group  Kim requests to join the Sales group, Darren approves the request User Information ,[object Object]
User Account Name
User Object ID
User DomainGroup Information ,[object Object]
Group Account Name
Group Domain

More Related Content

Similar to Tech Ed 2011 Preso

Help Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GPHelp Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GP
Jeffrey Paulette
 
CoNGNes 2009 - Microsoft BPOS - 22-01-2009 - Final - PPT2K3
CoNGNes 2009 - Microsoft BPOS - 22-01-2009 - Final - PPT2K3CoNGNes 2009 - Microsoft BPOS - 22-01-2009 - Final - PPT2K3
CoNGNes 2009 - Microsoft BPOS - 22-01-2009 - Final - PPT2K3
Peter de Haas
 
Floating on a (Microsoft) Cloud: Data Integration with Microsoft Cloud
Floating on a (Microsoft) Cloud: Data Integration with Microsoft CloudFloating on a (Microsoft) Cloud: Data Integration with Microsoft Cloud
Floating on a (Microsoft) Cloud: Data Integration with Microsoft Cloud
Safe Software
 
Roger l brathwaite_cover_letter_it_2020
Roger l brathwaite_cover_letter_it_2020Roger l brathwaite_cover_letter_it_2020
Roger l brathwaite_cover_letter_it_2020
Accenture
 
informatica mdm training | best informatica mdm Online training - GOT
informatica mdm training | best informatica mdm Online training - GOTinformatica mdm training | best informatica mdm Online training - GOT
informatica mdm training | best informatica mdm Online training - GOT
Global Online Trainings
 
Short Sales Overview of EmpowerID
Short Sales Overview of EmpowerIDShort Sales Overview of EmpowerID
Short Sales Overview of EmpowerID
EmpowerID
 
SharePoint 2010 - IT Platform upgrade and Management
SharePoint 2010 - IT Platform upgrade and ManagementSharePoint 2010 - IT Platform upgrade and Management
SharePoint 2010 - IT Platform upgrade and Management
Chris McNulty
 
Opalis & Service Manager
Opalis & Service ManagerOpalis & Service Manager
Opalis & Service ManagerAmit Gatenyo
 
Oracle RightNow Customer Portal Migration
Oracle RightNow Customer Portal MigrationOracle RightNow Customer Portal Migration
Oracle RightNow Customer Portal Migration
CRMIT
 
The Importance of Integration to Salesforce Success
The Importance of Integration to Salesforce SuccessThe Importance of Integration to Salesforce Success
The Importance of Integration to Salesforce Success
Darren Cunningham
 
Webmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques SocietyWebmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques Societywebhostingguy
 
Webmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques SocietyWebmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques Societywebhostingguy
 
Webmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques SocietyWebmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques Societywebhostingguy
 
8 16-10webinarbpos-101007143808-phpapp02
8 16-10webinarbpos-101007143808-phpapp028 16-10webinarbpos-101007143808-phpapp02
8 16-10webinarbpos-101007143808-phpapp02Liberteks
 
Session #107 - AMSI Hosting Options
Session #107 - AMSI Hosting OptionsSession #107 - AMSI Hosting Options
Session #107 - AMSI Hosting Optionswebhostingguy
 
MGT310 Reduce Support Costs and Improve Business Alignment with Microsoft Sys...
MGT310 Reduce Support Costs and Improve Business Alignment with Microsoft Sys...MGT310 Reduce Support Costs and Improve Business Alignment with Microsoft Sys...
MGT310 Reduce Support Costs and Improve Business Alignment with Microsoft Sys...
Louis Göhl
 
02 David Farrell Keynote V2
02 David Farrell Keynote V202 David Farrell Keynote V2
02 David Farrell Keynote V2Janos Szabo
 
A SharePoint Developers Guide to Project Server
A SharePoint Developers Guide to Project ServerA SharePoint Developers Guide to Project Server
A SharePoint Developers Guide to Project ServerAlexander Burton
 
Eliminate Risks in SOA Implementation & Support
Eliminate Risks in SOA Implementation & SupportEliminate Risks in SOA Implementation & Support
Eliminate Risks in SOA Implementation & Support
SuneraTech
 

Similar to Tech Ed 2011 Preso (20)

Help Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GPHelp Achieve Compliance Objectives with Microsoft Dynamics GP
Help Achieve Compliance Objectives with Microsoft Dynamics GP
 
CoNGNes 2009 - Microsoft BPOS - 22-01-2009 - Final - PPT2K3
CoNGNes 2009 - Microsoft BPOS - 22-01-2009 - Final - PPT2K3CoNGNes 2009 - Microsoft BPOS - 22-01-2009 - Final - PPT2K3
CoNGNes 2009 - Microsoft BPOS - 22-01-2009 - Final - PPT2K3
 
Floating on a (Microsoft) Cloud: Data Integration with Microsoft Cloud
Floating on a (Microsoft) Cloud: Data Integration with Microsoft CloudFloating on a (Microsoft) Cloud: Data Integration with Microsoft Cloud
Floating on a (Microsoft) Cloud: Data Integration with Microsoft Cloud
 
Roger l brathwaite_cover_letter_it_2020
Roger l brathwaite_cover_letter_it_2020Roger l brathwaite_cover_letter_it_2020
Roger l brathwaite_cover_letter_it_2020
 
000 010
000 010000 010
000 010
 
informatica mdm training | best informatica mdm Online training - GOT
informatica mdm training | best informatica mdm Online training - GOTinformatica mdm training | best informatica mdm Online training - GOT
informatica mdm training | best informatica mdm Online training - GOT
 
Short Sales Overview of EmpowerID
Short Sales Overview of EmpowerIDShort Sales Overview of EmpowerID
Short Sales Overview of EmpowerID
 
SharePoint 2010 - IT Platform upgrade and Management
SharePoint 2010 - IT Platform upgrade and ManagementSharePoint 2010 - IT Platform upgrade and Management
SharePoint 2010 - IT Platform upgrade and Management
 
Opalis & Service Manager
Opalis & Service ManagerOpalis & Service Manager
Opalis & Service Manager
 
Oracle RightNow Customer Portal Migration
Oracle RightNow Customer Portal MigrationOracle RightNow Customer Portal Migration
Oracle RightNow Customer Portal Migration
 
The Importance of Integration to Salesforce Success
The Importance of Integration to Salesforce SuccessThe Importance of Integration to Salesforce Success
The Importance of Integration to Salesforce Success
 
Webmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques SocietyWebmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques Society
 
Webmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques SocietyWebmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques Society
 
Webmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques SocietyWebmaster's Report - IEEE Microwave Theory and Techniques Society
Webmaster's Report - IEEE Microwave Theory and Techniques Society
 
8 16-10webinarbpos-101007143808-phpapp02
8 16-10webinarbpos-101007143808-phpapp028 16-10webinarbpos-101007143808-phpapp02
8 16-10webinarbpos-101007143808-phpapp02
 
Session #107 - AMSI Hosting Options
Session #107 - AMSI Hosting OptionsSession #107 - AMSI Hosting Options
Session #107 - AMSI Hosting Options
 
MGT310 Reduce Support Costs and Improve Business Alignment with Microsoft Sys...
MGT310 Reduce Support Costs and Improve Business Alignment with Microsoft Sys...MGT310 Reduce Support Costs and Improve Business Alignment with Microsoft Sys...
MGT310 Reduce Support Costs and Improve Business Alignment with Microsoft Sys...
 
02 David Farrell Keynote V2
02 David Farrell Keynote V202 David Farrell Keynote V2
02 David Farrell Keynote V2
 
A SharePoint Developers Guide to Project Server
A SharePoint Developers Guide to Project ServerA SharePoint Developers Guide to Project Server
A SharePoint Developers Guide to Project Server
 
Eliminate Risks in SOA Implementation & Support
Eliminate Risks in SOA Implementation & SupportEliminate Risks in SOA Implementation & Support
Eliminate Risks in SOA Implementation & Support
 

Tech Ed 2011 Preso

  • 1.
  • 2. SESSION CODE: SEC 318 Paul Conroy Technology Specialist Microsoft Fim r2 deep dive (c) 2011 Microsoft. All rights reserved.
  • 3. WARNING This isn’t an introduction to FIM, for that…. BING – technet implementing forefront identity manger (c) 2011 Microsoft. All rights reserved.
  • 4. Agenda Web Based User Self Service Password Reset Enhanced Reporting Simplified Reporting and Troubleshooting Tools Enhanced Performance Enhanced MA connectivity (c) 2011 Microsoft. All rights reserved.
  • 5. Web Based User Self Service Password Reset End user can register and reset from a web browser on a machine that isn’t domain joined ….even if the browser is not Internet Explorer Admin can deploy registration and reset portals on extranet-facing host Admin can configure password reset for external users using the same model as for internal users Upgrade from FIM 2010 SSPR to FIM 2010 R2 without breaking an existing FIMsolution (c) 2011 Microsoft. All rights reserved.
  • 6. FIM Password Reset ComponentsIllustrative Topology (c) 2011 Microsoft. All rights reserved.
  • 7. Setup Experience – PW Reset Portals 2 Specify whether host is extranet accessible Choose to install Password Portals 1 4 3 Password Portals visible in IIS Manager Specify AD user account for Portal
  • 8. Distinguishing Requests from ExtranetHow this works - Registration Security context is determined without reliance upon IP addresses Registration Portal Makes registration request to the FIM Service in the context of the Registration Portal’s AD identity FIM Service Identifies registration requests from the Registration Portal’s identity
  • 9. Distinguishing Requests from ExtranetHow this works - Reset Reset Portal Makes password reset request to the FIM Service in the context of the Reset Portal’s AD identity FIM Service Identifies reset requests from the reset portal. (c) 2011 Microsoft. All rights reserved.
  • 10. Authentication and password reset Registration is a process of establishing credentials for alternative authentication Many have a higher bar for authentication from the Internet, than from a domain-joined machine Extensibility for customer-specific needs (c) 2011 Microsoft. All rights reserved.
  • 11. User Self Service Password Reset demo
  • 12.
  • 13.
  • 14. What groups does a particular person belong to?
  • 15. Who is person Y’s manager?
  • 16. Who joined group A today?
  • 17. What groups had new members today?
  • 18.
  • 19. How did a group’s membership change over time?
  • 20. Who approved a group join?
  • 21. How did a set filter definition change over time?
  • 22. What groups did person A have access to on November 4th, 2009?
  • 23. What was a group’s membership last July?Historic Source: FIM Portal and Reporting Source: FIM reporting
  • 25. Out of Box Reports
  • 26.
  • 29.
  • 33.
  • 35. Policy Rule that Triggered the Request
  • 36.
  • 38. Simplified Deployment and Troubleshooting Tools Best Practices Analyzer (BPA) Improvements for troubleshooting Improvements in the setup process (c) 2011 Microsoft. All rights reserved.
  • 40. Enhanced Performance Improve performance for initial load of customer data from connected system to FIMService Improve performance for bulk addition (e.g., of new division) from connected system to an existing FIMdeployment Provide FIM Service database tuning guidance and enhancements (c) 2011 Microsoft. All rights reserved.
  • 42. Enhanced MA connectivity Enable extensible Management Agents to support Batched call-based import Batched call-based export Programmatic schema, partition, and hierarchy discovery Password management behave as other methods Custom anchors and additional dn styles Support custom parameters Full Export run step .NET 4 support New SAP, Oracle ERP, and Lotus Notes MAs for FIM 2010 R2 developed on top of the new API (c) 2011 Microsoft. All rights reserved.
  • 44. Platform Investments FIM add-in supports Outlook 2010 for group management and approvals FIMportal supports SharePoint Foundation 2010 (c) 2011 Microsoft. All rights reserved.
  • 45. Conclusion Credential Management Web based password reset Reporting Historical reporting for managed resources Service Manager data warehouse integration Ease of Use Enhanced diagnostics Enhanced initial load performance Simplified deployment for password reset Advanced MA configuration improvements More MAs (c) 2011 Microsoft. All rights reserved.
  • 46. Next Steps Search for “Forefront Team Blog” and be part of the Beta program Microsoft.com/ida LinkedIN – ‘Microsoft Forefront Identity Manager’ group (c) 2011 Microsoft. All rights reserved.
  • 47. Questions ? (c) 2011 Microsoft. All rights reserved.
  • 48. Complete an Evaluation online and enter to WIN prizes! (c) 2011 Microsoft. All rights reserved.
  • 49. © 2010 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION. (c) 2011 Microsoft. All rights reserved.
  • 50. www.msteched.com/Australia Sessions On-Demand & Community www.microsoft.com/australia/learning Microsoft Certification & Training Resources http:// technet.microsoft.com/en-au Resources for IT Professionals http://msdn.microsoft.com/en-au Resources for Developers Resources (c) 2011 Microsoft. All rights reserved.

Editor's Notes

  1. (8 labs)
  2. Final point is with caveats
  3. SEC 304 at 11:30 Friday with Phil Whipps will go more into the ECMA in particular doing a demo with integration to the twitter API