Export to FIM Portal
Hi,
Once again I am working through this online walk-through - http://technet.microsoft.com/en-us/library/ff686263(WS.10).aspx
When I create a user in the FIM Portal, it writes the user in AD, great :-)
How about the reverse though...I would like all users from AD to now be available in FIM Portal. This is what I have done:
on the AD Sync rule (which works one way) I selected the Inbound/Outbound data flow direction; and on the Inbound attribute flow I have selected the following attributes: displayname, firstName, lastName, accountname
on the FIM MA itself (which is also working one way) I now have added the following attributes as 'export' -> MVObjectID, lastname, firstname, displayname, accountname
Unfortunately no new user objects appear in the FIM Portal - the only objects that are provisioned are in AD.
Also just confirmed that the data from AD does not even land up in the FIM MV, yet.
Please could someone suggest the next steps, thank you
November 28th, 2010 6:46am
Hi!
Have you checked the "Create Resource in FIM" checkbox in your sync-rule?
//HenrikHenrik Nilsson, ILM/FIM MVP Blog: http://www.idmcrisis.com Company: Cortego (http://www.cortego.se)
Free Windows Admin Tool Kit Click here and download it now
November 28th, 2010 6:56am
yep, I do...after re-running the profiles about 5 times over and over, I now have the AD data in the MV.
there are also a number of Person objects in the Connector Space of the FIM MA.
However, when running the Export Run Profile I get a number of the following errors:
failed creation via web services failed modification via web services
any ideas?
PS. I am really looking forward to the next version of this product...i somehow feel this is a Beta product, and we're the guinea pigs from all the issues people are posting about FIM ;-)
November 28th, 2010 7:13am
Sounds like a permission issue, you should have a look at your event log...
Either you have problems with FIM MA account that should match the "Built-in Synchronization account", Attribute validation problems or MPR's that aren't configured correctly...
Check this out:
http://setspn.blogspot.com/2010/06/error-when-exporting-to-fim-ma-failed.htmlHenrik Nilsson, ILM/FIM MVP Blog: http://www.idmcrisis.com Company: Cortego (http://www.cortego.se)
Free Windows Admin Tool Kit Click here and download it now
November 28th, 2010 7:32am
OK, so I reviewed your link...and I do not have any new attributes...just using the out-the-box defaults.
I did however change this MPR "Administration: Administrators can read and update users" to 'all attributes'
I still have 2 failed modification via web serviceserrors:
One for a user account that was initially created in the FIM Portal, exported to AD, and even though nothing has changed its trying to replicate itself back to FIM Portal
AD Users Inbound/Outbound Sync Rule
BUT now I have a new error message :-)
I open FIM Portal, search for users to see if anything has been replicated and now see this error message in the Portal (in red):
"An Internal Error occurred and your request cannot be processed. please contact your system administrator"
Anyone seen this before?
November 28th, 2010 10:25am
OK, so I reviewed your link...and I do not have any new attributes...just using the out-the-box defaults.
I did however change this MPR "Administration: Administrators can read and update users" to 'all attributes'
I still have 2 failed modification via web serviceserrors:
One for a user account that was initially created in the FIM Portal, exported to AD, and even though nothing has changed its trying to replicate itself back to FIM Portal
AD Users Inbound/Outbound Sync Rule
BUT now I have a new error message :-)
I open FIM Portal, search for users to see if anything has been replicated and now see this error message in the Portal (in red):
"An Internal Error occurred and your request cannot be processed. please contact your system administrator"
Anyone seen this before?
Free Windows Admin Tool Kit Click here and download it now
November 28th, 2010 10:25am
but wait there is more - I now cannot even connect to the portal -> "Service is not available" error message in the browser...yes, I have checked that all services are running....
November 28th, 2010 10:44am
There are various reasons for the "service is not available".
Are you visiting the portal using a user which is known to the portal? Such as the one who did the install, or users which you later on synced with those in AD.
Other reasons are wrong urls, downed SQL, ...http://setspn.blogspot.com
Free Windows Admin Tool Kit Click here and download it now
November 28th, 2010 2:33pm
There are various reasons for the "service is not available".
Are you visiting the portal using a user which is known to the portal? Such as the one who did the install, or users which you later on synced with those in AD.
Other reasons are wrong urls, downed SQL, ...http://setspn.blogspot.com
November 28th, 2010 2:33pm
I am using the same user as before - Administrator - and checked services, application pools, and other posts about this problem.
due to time constraints, we cannot afford any more time on this issue and are rebuilding the virtual environment.
thank you for the assistance thus far.
Free Windows Admin Tool Kit Click here and download it now
November 29th, 2010 4:17am