nerdexam

70-158 · Question #7

You administer a Forefront Identity Management (FIM) 2010 server in your company network. All user accounts are members of an Active Directory Domain Services (AD DS) domain. You configure user…

The correct answer is C. Create a new Request Management Policy Rule (MPR). To allow users to update only their own profiles in the FIM Portal, a new Management Policy Rule (MPR) must be created that scopes requestors to themselves as the target resource. MPRs are the mechanism FIM uses to define who can perform what operations on which resources.

Submitted by jian89· Mar 4, 2026Configure FIM Policies

Question

You administer a Forefront Identity Management (FIM) 2010 server in your company network. All user accounts are members of an Active Directory Domain Services (AD DS) domain. You configure user accounts synchronization between the FIM server and domain. You provide read access to the domain users to the FIM Portal. You need to ensure that users can update only their own personal profile through the FIM Portal. What should you do?

Options

  • AAdd All People to the Specific Set of Requestors list of the User management:
  • BCreate a new Request Management Policy Rule (MPR).
  • CCreate a new Request Management Policy Rule (MPR).
  • DCopy settings of the User management:

How the community answered

(40 responses)
  • A
    8% (3)
  • B
    3% (1)
  • C
    75% (30)
  • D
    15% (6)

Why each option

To allow users to update only their own profiles in the FIM Portal, a new Management Policy Rule (MPR) must be created that scopes requestors to themselves as the target resource. MPRs are the mechanism FIM uses to define who can perform what operations on which resources.

AAdd All People to the Specific Set of Requestors list of the User management:

Adding All People to the Specific Set of Requestors on an existing MPR without properly scoping the target to the requestor's own object would grant users the ability to modify other users' profiles, not just their own.

BCreate a new Request Management Policy Rule (MPR).

Although worded similarly to C, this choice as presented in the context of the question refers to an incorrectly configured or insufficiently scoped MPR creation that does not properly restrict the target to the requesting user's own profile.

CCreate a new Request Management Policy Rule (MPR).Correct

Creating a new Request MPR allows you to define a policy where the requestor set is 'All People' and the target resource set is scoped to 'the requestor themselves,' enforcing self-service profile editing. MPRs in FIM 2010 control authorization by binding a set of requestors, a target resource set, and allowed operations (such as attribute-level write permissions), making this the correct and precise method to grant users edit access only to their own profiles.

DCopy settings of the User management:

Copying settings of an existing User Management MPR without the correct self-service target scoping would replicate existing broad permissions rather than creating a new, correctly scoped self-update policy.

Concept tested: FIM 2010 MPR configuration for self-service profile updates

Source: https://learn.microsoft.com/en-us/previous-versions/mim/ff393653(v=ws.10)

Topics

#Management Policy Rules#FIM Portal#Self-Service#Access Control

Community Discussion

No community discussion yet for this question.

Full 70-158 Practice