nerdexam

70-158 · Question #6

You install a Forefront Identity Management (FIM) 2010 server on a member server of an Active Directory Domain Services (AD DS) domain. You configure synchronization between the domain and FIM…

The correct answer is B. Add the user account of User1 to the Administrators set. To grant a user the ability to modify other users' attributes and Management Policy Rules (MPRs) in the FIM Portal, the user must be added to the FIM Administrators set, which controls portal-level administrative permissions.

Submitted by naveen.iyer· Mar 4, 2026Configure Users, Groups, and Management Policy Rules

Question

You install a Forefront Identity Management (FIM) 2010 server on a member server of an Active Directory Domain Services (AD DS) domain. You configure synchronization between the domain and FIM server. A user named User1 must modify other users_ attributes and Management Policy Rules (MPRs) settings through the FIM Portal. You need to delegate the required permissions to User1. What should you do?

Options

  • ACreate and configure a new authorization workflow.
  • BAdd the user account of User1 to the Administrators set.
  • CAdd the user account of User1 to the FIMSyncAdmins group in the domain.
  • DAdd the user account of User1 to the local Administrators group on the FIM server.

How the community answered

(57 responses)
  • A
    9% (5)
  • B
    74% (42)
  • C
    14% (8)
  • D
    4% (2)

Why each option

To grant a user the ability to modify other users' attributes and Management Policy Rules (MPRs) in the FIM Portal, the user must be added to the FIM Administrators set, which controls portal-level administrative permissions.

ACreate and configure a new authorization workflow.

Creating an authorization workflow controls approval processes for requests but does not directly grant User1 the permissions needed to modify user attributes and MPR settings in the FIM Portal.

BAdd the user account of User1 to the Administrators set.Correct

In FIM 2010, the 'Administrators' set is a built-in FIM Portal set that grants members full administrative access to portal resources, including the ability to modify user attributes and configure Management Policy Rules (MPRs). Adding User1 to this set delegates the necessary portal-level permissions through FIM's role-based access control model, without requiring local server or domain group membership.

CAdd the user account of User1 to the FIMSyncAdmins group in the domain.

The FIMSyncAdmins domain group grants administrative access to the FIM Synchronization Service engine, not to the FIM Portal; it does not allow managing portal objects or MPRs.

DAdd the user account of User1 to the local Administrators group on the FIM server.

Adding User1 to the local Administrators group on the FIM server grants OS-level access to the server itself, but does not confer FIM Portal administrative rights to manage user attributes or MPRs.

Concept tested: FIM Portal role-based access control via Administrators set

Source: https://learn.microsoft.com/en-us/microsoft-identity-manager/deploy-use/create-a-new-attribute

Topics

#FIM Portal#Delegation#Administrators Set#Management Policy Rules

Community Discussion

No community discussion yet for this question.

Full 70-158 Practice