nerdexam

70-158 · Question #48

You use Forefront Identity Manager (FIM) 2010 in your company network. The Management Agent for Active Directory (AD MA) is unable to process password reset requests for users who have configured…

The correct answer is B. The group membership of user accounts is incorrect. C. Password Management is not enabled on the AD MA. E. The FIM MA Service account does not have Replicating Directory Changes permissions. This question tests knowledge of FIM 2010 AD MA configuration requirements for processing password reset requests, including service account permissions and MA settings.

Submitted by rachelw· Mar 4, 2026Configure password management

Question

You use Forefront Identity Manager (FIM) 2010 in your company network. The Management Agent for Active Directory (AD MA) is unable to process password reset requests for users who have configured the Password Reset authentication challenge questions. What are some possible causes of the issue? (Choose all that apply.)

Options

  • APermission settings of the AD MA service account.
  • BThe group membership of user accounts is incorrect.
  • CPassword Management is not enabled on the AD MA.
  • DThe FIM Service account does not have Replicating Directory Changes permissions.
  • EThe FIM MA Service account does not have Replicating Directory Changes permissions.

How the community answered

(68 responses)
  • A
    13% (9)
  • B
    57% (39)
  • D
    29% (20)

Why each option

This question tests knowledge of FIM 2010 AD MA configuration requirements for processing password reset requests, including service account permissions and MA settings.

APermission settings of the AD MA service account.

While AD MA service account permissions are important for general operations, incorrect permission settings alone on the AD MA service account are not a direct cause of failed password reset request processing when the specific scenario involves authentication challenge questions.

BThe group membership of user accounts is incorrect.Correct

Incorrect group membership of user accounts can prevent password reset processing because FIM uses group membership to determine which users are in scope for password management workflows and self-service password reset operations.

CPassword Management is not enabled on the AD MA.Correct

Password Management must be explicitly enabled on the AD MA configuration; without this setting enabled, the AD MA will not process any inbound or outbound password synchronization or reset requests regardless of other settings.

DThe FIM Service account does not have Replicating Directory Changes permissions.

The FIM Service account is used for FIM portal and service operations, but it is the FIM MA Service account (not the general FIM Service account) that requires Replicating Directory Changes permissions to process password resets through the AD MA.

EThe FIM MA Service account does not have Replicating Directory Changes permissions.Correct

The FIM MA Service account (distinct from the FIM Service account) requires Replicating Directory Changes permissions on Active Directory to detect and process password changes and resets; without this permission, the AD MA cannot read password-related changes from the AD domain controllers.

Concept tested: FIM 2010 AD MA password reset configuration requirements

Source: https://learn.microsoft.com/en-us/microsoft-identity-manager/reference/microsoft-identity-manager-2016-ma-ws

Topics

#FIM Password Reset#Active Directory Management Agent#Password Management#Service Permissions

Community Discussion

No community discussion yet for this question.

Full 70-158 Practice