nerdexam

70-158 · Question #57

You administer a Forefront Identity Management (FIM) 2010 server in your company network. You need to be able to synchronize user accounts between Active Directory Domain Services (AD DS) and…

The correct answer is B. Add the FIM Service (FIMService) account to the FIMSyncAdmins group. To enable synchronization of user accounts between Active Directory and third-party directories via the FIM Portal, the FIM Service account needs administrative control over the FIM Synchronization Service.

Submitted by obi.ng· Mar 4, 2026Configure the FIM Service and FIM Portal

Question

You administer a Forefront Identity Management (FIM) 2010 server in your company network. You need to be able to synchronize user accounts between Active Directory Domain Services (AD DS) and third-party directory services by using the FIM Portal. What should you do?

Options

  • AAdd the FIM Synchronization Service (FIMSynchronizationService) account to the FIMSyncAdmins Group.
  • BAdd the FIM Service (FIMService) account to the FIMSyncAdmins group.
  • CChange the FIM Service (FIMService) account configuration to logon as local system account.
  • DChange the FIM Synchronization Service (FIMSynchronizationService) account configuration to logon as

How the community answered

(61 responses)
  • A
    3% (2)
  • B
    84% (51)
  • C
    8% (5)
  • D
    5% (3)

Why each option

To enable synchronization of user accounts between Active Directory and third-party directories via the FIM Portal, the FIM Service account needs administrative control over the FIM Synchronization Service.

AAdd the FIM Synchronization Service (FIMSynchronizationService) account to the FIMSyncAdmins Group.

The FIM Synchronization Service account already has inherent permissions to operate its service and does not need to be added to FIMSyncAdmins for the FIM Portal to manage it.

BAdd the FIM Service (FIMService) account to the FIMSyncAdmins group.Correct

The FIM Service account is responsible for running the FIM Portal and its associated workflows. Adding the FIM Service account to the FIMSyncAdmins group grants it the necessary permissions to administer and interact with the FIM Synchronization Service, which is essential for managing synchronization operations through the portal.

CChange the FIM Service (FIMService) account configuration to logon as local system account.

Changing a service account to log on as Local System is a security risk and is not the correct method for granting specific FIM synchronization management permissions.

DChange the FIM Synchronization Service (FIMSynchronizationService) account configuration to logon as

Changing a service account's logon configuration does not grant the specific FIM administrative permissions needed for the FIM Portal to manage synchronization.

Concept tested: FIM service account permissions for synchronization management

Source: https://learn.microsoft.com/en-us/microsoft-identity-manager/mim-design-considerations

Topics

#FIM Service Account#FIMSyncAdmins#Directory Synchronization#FIM Portal

Community Discussion

No community discussion yet for this question.

Full 70-158 Practice