nerdexam

70-158 · Question #54

You deploy Forefront Identity Manager (FIM) in your company network to synchronize user accounts between Active Directory and an HR application. End users use the FIM Self-Service Portal to reset…

The correct answer is C. Split the FIM Synchronization Service, and then install it on a new separate physical server. To resolve performance delays in the Active Directory Management Agent (AD MA) due to increased user and group counts, the FIM Synchronization Service, which hosts the MAs, should be dedicated to its own server.

Submitted by yousef_jo· Mar 4, 2026Deploy Forefront Identity Manager

Question

You deploy Forefront Identity Manager (FIM) in your company network to synchronize user accounts between Active Directory and an HR application. End users use the FIM Self-Service Portal to reset passwords and manage groups. You use a two-tiered architecture according to the following table Currently, the number of users and groups has doubled. You experience delays in performance of the Active Directory Management Agent (AD MA). You need to improve the performance of the MA . What should you do?

Exhibit

70-158 question #54 exhibit

Options

  • AConfigure the AD MA to run as a different service account.
  • BAdd an additional front-end server to the two load-balanced front-end servers.
  • CSplit the FIM Synchronization Service, and then install it on a new separate physical server.
  • DSplit the FIM Portal from the back end, and then install it on a new separate physical server.

How the community answered

(38 responses)
  • A
    11% (4)
  • B
    5% (2)
  • C
    61% (23)
  • D
    24% (9)

Why each option

To resolve performance delays in the Active Directory Management Agent (AD MA) due to increased user and group counts, the FIM Synchronization Service, which hosts the MAs, should be dedicated to its own server.

AConfigure the AD MA to run as a different service account.

Configuring the AD MA to run as a different service account addresses potential permission issues, not a performance bottleneck caused by increased processing load.

BAdd an additional front-end server to the two load-balanced front-end servers.

Adding more front-end servers would improve the performance and availability of the FIM Self-Service Portal, not the underlying synchronization engine (MA) performance.

CSplit the FIM Synchronization Service, and then install it on a new separate physical server.Correct

The Active Directory Management Agent (AD MA) runs as part of the FIM Synchronization Service, which performs the actual data synchronization. By splitting the FIM Synchronization Service and installing it on a new separate physical server, you provide dedicated resources (CPU, memory, I/O) to handle the increased synchronization load, thereby directly improving MA performance.

DSplit the FIM Portal from the back end, and then install it on a new separate physical server.

Splitting the FIM Portal from the back end would improve portal responsiveness, but the performance issue is specifically with the AD MA, which is part of the Synchronization Service, not the portal.

Concept tested: FIM architecture, Synchronization Service scaling, performance optimization

Source: https://learn.microsoft.com/en-us/microsoft-identity-manager/supported-topologies

Topics

#FIM Synchronization Service#AD MA#Performance Optimization#FIM Architecture

Community Discussion

No community discussion yet for this question.

Full 70-158 Practice