Support Tip: How to deprovision an Azure AD CS object

*** DISCLAIMER *** This blog has been put together for the purpose of illustration.  You may have to change certain properties to fit your specific business needs. *** DISCLAIMER *** PRODUCT USED FOR TESTING/WRITNG BLOG Azure AD Connect (Build:   SCENARIO DESCRIPTION / GOAL Think about this scenario.  You have synchronized several objects to… Read more

Support Tip: BHOLD–Attestation Portal stops working

PROBLEM SCENARIO DESCRIPTION In rare cases, the BHOLD Attestation portal fails to render. In the logs, you see something about unable to load file. From research, there is a problem with how ASP.NET manages the files it generates in C:\Windows\Microsoft.NET\Framework\v2.0.50727\Temporary ASP.NET Files\bhold_attestation Attestation log: <Data>Could not load file or assembly ‘App_Web_b2ggad-k, Version=, Culture=neutral, PublicKeyToken=null’ or… Read more

[Support Tip] :: MIM 2016 SP1 Slip Stream build is now available

Microsoft Identity Manager 2016 with Service Pack 1 Slipstream is now live on subscriber downloads. You can see it at: Or at the new VS portal (Note: You need a subscription to view files): *NOTE: If you are utilizing the initial MIM 2016 SP1 (4.4.1297.0), we do encourage you to upgrade to… Read more

KB: SQL Server availability solutions for Microsoft Identity Manager services databases

Just a quick FYI to let you know about a new KB article we published that describes the availability solutions for Microsoft SQL Server for the Microsoft Identity Manager service (FIMService) and Synchronization service (FIMSynchronizationService) databases. As currently noted in the KB, high availability is supported in the following scenarios for a configuration of SQL Server:… Read more

Support Tip: How to merge a group object with a contact object

PROBLEM SCENARIO DESCRIPTION The problem we are attempting to resolve here is how to take a Group Object from Forest A and merge it with a Contact Object from Forest B using Azure AD Connect. The goal is to have a Group Object with information provided from both objects in Office 365. KEY POINTS TO… Read more

On startup a system with the SSPR Rich client installed posts "Unable to Launch Web Browser"

A system with the Self Service Password Reset Rich client posts an error, “Unable to Launch Web Browser …” on startup. It is expected to navigate to the SSPR portal prompting a user to register. Research into this issue using Process Monitor from Sysinternals shows that two registry keys are utilized by the client, HKCU\Software\Policies\Microsoft\Forefront… Read more

Microsoft Identity Manager 2016 Service Pack 1 update package

Greetings Since the release of MIM 2016 SP1 just over a month ago, we received overwhelming feedback from our partners and customers regarding the upgrade paths for the service pack. Today I’m pleased to announce the availability of the MIM 2016 SP1 Update MSP. This MSP allows current customers on MIM 2016 RTM, or any… Read more

Support Tip: MIM SP1 PAM install failure: CreateAuthenticationPolicyAndSilo Error The user has insufficient access rights.

When installing Microsoft Identity Manager Service Pack 1 (MIM SP1) with PAM using an installer account (MIMAdmin), you encounter a SILO error. When installing with verbose logging enabled ( msiexec /i “Service and Portal.msi” /l*v C:\temp\setup.log ) you will see the following: Failed creating authentication policy/silo.The user has insufficient access System.DirectoryServices.Protocols.LdapConnection.ConstructResponse(Int32 messageId, LdapOperation operation,… Read more

Tuning FIM Service MA Export Processing

An introduction to FIM Service MA export configuration, system event requests, and FIMService partitioning.  This applies to both FIM 2010 R2 and MIM 2016. Credits: Thank you to David Steadman for his collaboration in this post. Introduction When working with the FIM Service management agent, it’s possible to get into a situation where an export… Read more

[SUPPORT TIP]: GalSync Related Information

  What is a GalSync Solution? GalSync is a Global Address List Synchronization Solution.  It is a way for Microsoft Exchange Organizations to share their Global Address Lists (GAL).  Additionally, once a GalSync Solution is setup, it provides the ability to share Free/Busy information. NEW GALSYNC SOLUTION – Contacts are not provisioning Contacts not provisioning… Read more