70-158 · Question #54
You deploy Forefront Identity Manager (FIM) in your company network to synchronize user accounts between Active Directory and an HR application. End users use the FIM Self-Service Portal to reset…
The correct answer is C. Split the FIM Synchronization Service, and then install it on a new separate physical server. To resolve performance delays in the Active Directory Management Agent (AD MA) due to increased user and group counts, the FIM Synchronization Service, which hosts the MAs, should be dedicated to its own server.
Question
Exhibit
Options
- AConfigure the AD MA to run as a different service account.
- BAdd an additional front-end server to the two load-balanced front-end servers.
- CSplit the FIM Synchronization Service, and then install it on a new separate physical server.
- DSplit the FIM Portal from the back end, and then install it on a new separate physical server.
How the community answered
(38 responses)- A11% (4)
- B5% (2)
- C61% (23)
- D24% (9)
Why each option
To resolve performance delays in the Active Directory Management Agent (AD MA) due to increased user and group counts, the FIM Synchronization Service, which hosts the MAs, should be dedicated to its own server.
Configuring the AD MA to run as a different service account addresses potential permission issues, not a performance bottleneck caused by increased processing load.
Adding more front-end servers would improve the performance and availability of the FIM Self-Service Portal, not the underlying synchronization engine (MA) performance.
The Active Directory Management Agent (AD MA) runs as part of the FIM Synchronization Service, which performs the actual data synchronization. By splitting the FIM Synchronization Service and installing it on a new separate physical server, you provide dedicated resources (CPU, memory, I/O) to handle the increased synchronization load, thereby directly improving MA performance.
Splitting the FIM Portal from the back end would improve portal responsiveness, but the performance issue is specifically with the AD MA, which is part of the Synchronization Service, not the portal.
Concept tested: FIM architecture, Synchronization Service scaling, performance optimization
Source: https://learn.microsoft.com/en-us/microsoft-identity-manager/supported-topologies
Topics
Community Discussion
No community discussion yet for this question.
