nerdexam

70-158 · Question #41

You use Forefront Identity Manager (FIM) 2010 in your company network. You configure the Self- Service Password Reset feature for the FIM Portal. You discover that existing users are able to submit…

The correct answer is A. Anonymous users can reset their password B. Users can create registration objects for themselves. In FIM 2010 Self-Service Password Reset (SSPR), specific Management Policy Rules (MPRs) control both the registration and reset workflow. When new users cannot register, the MPRs governing anonymous access and self-registration must be validated.

Submitted by kevin_r· Mar 4, 2026Configure Credential Management

Question

You use Forefront Identity Manager (FIM) 2010 in your company network. You configure the Self- Service Password Reset feature for the FIM Portal. You discover that existing users are able to submit password reset requests but new users are unable to register for Self-Service Password Reset. You need to identify the cause of the issue. Which Management Policy Rule settings should you validate? (Choose all that apply.)

Options

  • AAnonymous users can reset their password
  • BUsers can create registration objects for themselves
  • CPassword reset users can read password reset objects
  • DUser management: Users can read attributes of their own
  • EGeneral: Users can read non-administrative configuration resources
  • FPassword reset users can update the lockout attribute of themselves

How the community answered

(47 responses)
  • A
    60% (28)
  • C
    4% (2)
  • D
    21% (10)
  • E
    4% (2)
  • F
    11% (5)

Why each option

In FIM 2010 Self-Service Password Reset (SSPR), specific Management Policy Rules (MPRs) control both the registration and reset workflow. When new users cannot register, the MPRs governing anonymous access and self-registration must be validated.

AAnonymous users can reset their passwordCorrect

The 'Anonymous users can reset their password' MPR governs whether unauthenticated (anonymous) users can initiate a password reset request through the FIM Portal; if this MPR is misconfigured or disabled, the reset workflow is broken for users who cannot authenticate first, directly impacting new users.

BUsers can create registration objects for themselvesCorrect

The 'Users can create registration objects for themselves' MPR specifically controls whether users have the rights to create the registration data objects required to enroll in SSPR; if this MPR is disabled or incorrectly scoped, new users will be blocked from completing the registration process even though existing (already-registered) users are unaffected.

CPassword reset users can read password reset objects

This MPR controls read access to existing password reset objects, which affects visibility for users already enrolled in SSPR but does not impact the ability for new users to register.

DUser management: Users can read attributes of their own

This MPR governs users' ability to read their own attribute values in the FIM Portal and is unrelated to the SSPR registration workflow for new users.

EGeneral: Users can read non-administrative configuration resources

This MPR controls read access to general non-administrative configuration resources and does not specifically govern the creation of SSPR registration objects or the reset request flow.

FPassword reset users can update the lockout attribute of themselves

This MPR controls whether password reset users can update their own lockout attribute, which is relevant to the post-reset unlock process but has no bearing on whether new users can register for SSPR.

Concept tested: FIM 2010 SSPR Management Policy Rule validation

Source: https://learn.microsoft.com/en-us/previous-versions/mim/ff356225(v=ws.10)

Topics

#Self-Service Password Reset#Management Policy Rules#FIM Portal#Registration Objects

Community Discussion

No community discussion yet for this question.

Full 70-158 Practice