nerdexam

70-158 · Question #8

You administer a Forefront Identity Management (FIM) 2010 server in your company network. All users in the network are members of an Active Directory domain. You configure user accounts…

The correct answer is A. Create a new set for the user accounts of service desk personnel. B. Create and configure a new Management Policy Rule. C. Add a set to a Management Policy Rule. To enable service desk personnel to modify domain user account properties via the FIM Portal, it is necessary to create a set for the personnel, define a new Management Policy Rule (MPR), and then add the personnel's set to that MPR.

Submitted by rohit_dlh· Mar 4, 2026Configure FIM Management Policy Rules, Workflows, and Sets

Question

You administer a Forefront Identity Management (FIM) 2010 server in your company network. All users in the network are members of an Active Directory domain. You configure user accounts synchronization between the FIM server and domain. You need to ensure that service desk personnel can modify properties of domain user accounts by using the FIM Portal. What should you do? (Each correct answer presents part of the solution. Choose all that apply.)

Options

  • ACreate a new set for the user accounts of service desk personnel.
  • BCreate and configure a new Management Policy Rule.
  • CAdd a set to a Management Policy Rule.
  • DAdd a workflow to a Management Policy Rule.
  • ECreate a new authorization workflow.
  • FCreate a new authentication workflow.

How the community answered

(17 responses)
  • A
    76% (13)
  • D
    12% (2)
  • E
    6% (1)
  • F
    6% (1)

Why each option

To enable service desk personnel to modify domain user account properties via the FIM Portal, it is necessary to create a set for the personnel, define a new Management Policy Rule (MPR), and then add the personnel's set to that MPR.

ACreate a new set for the user accounts of service desk personnel.Correct

Service desk personnel must be grouped into a specific FIM set, which then acts as the 'actor' for the Management Policy Rule that grants the necessary modification permissions.

BCreate and configure a new Management Policy Rule.Correct

A Management Policy Rule (MPR) is the fundamental FIM object used to define 'who can do what to which resources,' making its creation essential for establishing modification rights.

CAdd a set to a Management Policy Rule.Correct

The set containing the service desk personnel (from choice A) must be explicitly linked to the new Management Policy Rule (from choice B) to designate them as the permitted actors for the modification action.

DAdd a workflow to a Management Policy Rule.

Workflows in MPRs handle complex processes like approvals or provisioning, but are not the primary mechanism for simply enabling property modification permissions.

ECreate a new authorization workflow.

Authorization workflows add conditions or approvals to an action but do not directly grant the underlying permission to perform modifications.

FCreate a new authentication workflow.

Authentication workflows are designed for identity verification and have no direct relevance to configuring permissions for modifying user properties.

Concept tested: FIM Management Policy Rules (MPR) for delegated administration

Source: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/forefront-identity-manager-2010/ff687057(v=ws.10)

Topics

#Management Policy Rules#FIM Sets#FIM Portal#Delegation

Community Discussion

No community discussion yet for this question.

Full 70-158 Practice