70-158 · Question #8
You administer a Forefront Identity Management (FIM) 2010 server in your company network. All users in the network are members of an Active Directory domain. You configure user accounts…
The correct answer is A. Create a new set for the user accounts of service desk personnel. B. Create and configure a new Management Policy Rule. C. Add a set to a Management Policy Rule. To enable service desk personnel to modify domain user account properties via the FIM Portal, it is necessary to create a set for the personnel, define a new Management Policy Rule (MPR), and then add the personnel's set to that MPR.
Question
Options
- ACreate a new set for the user accounts of service desk personnel.
- BCreate and configure a new Management Policy Rule.
- CAdd a set to a Management Policy Rule.
- DAdd a workflow to a Management Policy Rule.
- ECreate a new authorization workflow.
- FCreate a new authentication workflow.
How the community answered
(17 responses)- A76% (13)
- D12% (2)
- E6% (1)
- F6% (1)
Why each option
To enable service desk personnel to modify domain user account properties via the FIM Portal, it is necessary to create a set for the personnel, define a new Management Policy Rule (MPR), and then add the personnel's set to that MPR.
Service desk personnel must be grouped into a specific FIM set, which then acts as the 'actor' for the Management Policy Rule that grants the necessary modification permissions.
A Management Policy Rule (MPR) is the fundamental FIM object used to define 'who can do what to which resources,' making its creation essential for establishing modification rights.
The set containing the service desk personnel (from choice A) must be explicitly linked to the new Management Policy Rule (from choice B) to designate them as the permitted actors for the modification action.
Workflows in MPRs handle complex processes like approvals or provisioning, but are not the primary mechanism for simply enabling property modification permissions.
Authorization workflows add conditions or approvals to an action but do not directly grant the underlying permission to perform modifications.
Authentication workflows are designed for identity verification and have no direct relevance to configuring permissions for modifying user properties.
Concept tested: FIM Management Policy Rules (MPR) for delegated administration
Source: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/forefront-identity-manager-2010/ff687057(v=ws.10)
Topics
Community Discussion
No community discussion yet for this question.