70-158 · Question #57
You administer a Forefront Identity Management (FIM) 2010 server in your company network. You need to be able to synchronize user accounts between Active Directory Domain Services (AD DS) and…
The correct answer is B. Add the FIM Service (FIMService) account to the FIMSyncAdmins group. To enable synchronization of user accounts between Active Directory and third-party directories via the FIM Portal, the FIM Service account needs administrative control over the FIM Synchronization Service.
Question
Options
- AAdd the FIM Synchronization Service (FIMSynchronizationService) account to the FIMSyncAdmins Group.
- BAdd the FIM Service (FIMService) account to the FIMSyncAdmins group.
- CChange the FIM Service (FIMService) account configuration to logon as local system account.
- DChange the FIM Synchronization Service (FIMSynchronizationService) account configuration to logon as
How the community answered
(61 responses)- A3% (2)
- B84% (51)
- C8% (5)
- D5% (3)
Why each option
To enable synchronization of user accounts between Active Directory and third-party directories via the FIM Portal, the FIM Service account needs administrative control over the FIM Synchronization Service.
The FIM Synchronization Service account already has inherent permissions to operate its service and does not need to be added to FIMSyncAdmins for the FIM Portal to manage it.
The FIM Service account is responsible for running the FIM Portal and its associated workflows. Adding the FIM Service account to the FIMSyncAdmins group grants it the necessary permissions to administer and interact with the FIM Synchronization Service, which is essential for managing synchronization operations through the portal.
Changing a service account to log on as Local System is a security risk and is not the correct method for granting specific FIM synchronization management permissions.
Changing a service account's logon configuration does not grant the specific FIM administrative permissions needed for the FIM Portal to manage synchronization.
Concept tested: FIM service account permissions for synchronization management
Source: https://learn.microsoft.com/en-us/microsoft-identity-manager/mim-design-considerations
Topics
Community Discussion
No community discussion yet for this question.