70-158 · Question #6
You install a Forefront Identity Management (FIM) 2010 server on a member server of an Active Directory Domain Services (AD DS) domain. You configure synchronization between the domain and FIM…
The correct answer is B. Add the user account of User1 to the Administrators set. To grant a user the ability to modify other users' attributes and Management Policy Rules (MPRs) in the FIM Portal, the user must be added to the FIM Administrators set, which controls portal-level administrative permissions.
Question
Options
- ACreate and configure a new authorization workflow.
- BAdd the user account of User1 to the Administrators set.
- CAdd the user account of User1 to the FIMSyncAdmins group in the domain.
- DAdd the user account of User1 to the local Administrators group on the FIM server.
How the community answered
(57 responses)- A9% (5)
- B74% (42)
- C14% (8)
- D4% (2)
Why each option
To grant a user the ability to modify other users' attributes and Management Policy Rules (MPRs) in the FIM Portal, the user must be added to the FIM Administrators set, which controls portal-level administrative permissions.
Creating an authorization workflow controls approval processes for requests but does not directly grant User1 the permissions needed to modify user attributes and MPR settings in the FIM Portal.
In FIM 2010, the 'Administrators' set is a built-in FIM Portal set that grants members full administrative access to portal resources, including the ability to modify user attributes and configure Management Policy Rules (MPRs). Adding User1 to this set delegates the necessary portal-level permissions through FIM's role-based access control model, without requiring local server or domain group membership.
The FIMSyncAdmins domain group grants administrative access to the FIM Synchronization Service engine, not to the FIM Portal; it does not allow managing portal objects or MPRs.
Adding User1 to the local Administrators group on the FIM server grants OS-level access to the server itself, but does not confer FIM Portal administrative rights to manage user attributes or MPRs.
Concept tested: FIM Portal role-based access control via Administrators set
Source: https://learn.microsoft.com/en-us/microsoft-identity-manager/deploy-use/create-a-new-attribute
Topics
Community Discussion
No community discussion yet for this question.