Skip to main content

 

Implementing Forefront
Identity Manager 2010

This course introduces and explains the features and capabilities of Microsoft Forefront Identity Manager 2010 (FIM), and provides an overview of the solution scenarios that FIM addresses. The course format includes presentation, discussion, demonstration, and many hands-on exercises. It is intended for students who have no previous Forefront Identity Manager 2010 or Microsoft Identity Lifecycle Manager 2007 (ILM) experience.

After completing this course, students will be able to:

  • Understand FIM concepts and components.
  • Identify appropriate FIM scenarios.
  • Manage users, groups, and passwords using FIM.
  • Synchronize identity data across systems, such as Active Directory and HR.
  • Understand the issues involved in loading data (initial load, backup, and disaster recovery).
  • Configure security for different levels of user.
  • Manage password self-service reset and synchronization.
  • Automate run cycles.
  • Handle sets, simple workflows, and management policy rules (MPRs).

Learning Resources

Published on: June 14, 2010

 
Step 1

Introducing Forefront Identity Manager 2010

This module is a tour of many of the built-in features of FIM focusing on the user experience. The student will explore the FIM interface, the high level architecture of FIM, and the business needs that FIM addresses. In this module, the student will examine FIM in its installed and configured state, whereas the rest of the course will be spent understanding how FIM works, and building the fully configured FIM from a raw installation. The lab explores creating a new user, managing groups and credentials for that user, and the experience of that new user.

Step 2

The Synchronization Service Manager

This module introduces the FIM Synchronization Service Manager and explains its features through scenarios that do not use the FIM Portal. It introduces the main tools (such as Metaverse Designer, Operations Tool, and Joiner), and covers the basic configuration of a Management Agent along with run profiles, results verification, and simple Metaverse search. During the lab, students will create a new Management Agent for a simple HR system.

Step 3

More about Synchronization

This module looks at various types of Management Agent (MA), including LDAP and file-based sources. It covers concepts such as schema discovery, filters, join and projection rules, connectors and disconnectors, joining, provisioning, deprovisioning, and different kinds of attribute flow. In the lab, students create two more Management Agents, and establish a simple data-driven scenario for managing a directory (AD LDS).

Step 4

The FIM Service and Portal

This module introduces the Forefront Identity Manager (FIM) Service with its associated portal and application database, initially as a standalone application, while covering the key concepts of Sets and Management Policy Rules (MPRs) through user management. The module then looks at how you integrate the FIM Service with the FIM Synchronization Service, by using the FIM Service Management Agent (MA) to synchronize data.

Step 5

Managing Synchronization from the Portal

This module explores creation of an Active Directory MA, and configuration via the portal to manage mailbox-enabled users in AD. Aspects of this process include synchronization rules, workflows, and management policy rules, including complex attribute flows. In the labs, students configure FIM so that users are automatically created (provisioned) into AD, renamed, and removed (deprovisioned) as necessary.

Step 6

Credential Management

This module primarily explores passwords. First, it addresses the essentials of Certificate Management, and then explores in detail the self-service password reset and password synchronization functions. The two labs cover all aspects of password management in FIM (with the exception of writing custom password management workflows and extensions).

Step 7

Group Management

This module covers the management of distribution and security groups, including the relationship between groups in Active Directory and other systems. Synchronization rules, workflows, and MPRs are explored further, along with the configuration of workflow approvals.

Step 8

Other Considerations

This module examines management policy rules (MPRs)—perhaps the most important feature of FIM. It explores the different types of management policy rules, their different uses, how they are processed, and how to troubleshoot them. Then it examines some operational considerations, such as the management of run cycles using scripts, and also covers backup, restore, and disaster recovery.

Microsoft is conducting an online survey to understand your opinion of the MSDN Web site. If you choose to participate, the online survey will be presented to you when you leave the MSDN Web site.

Would you like to participate?