70-158 · Question #9
Your company network uses Forefront Identity Manager (FIM) 2010 to synchronize user accounts in an Active Directory Domain Services (AD DS) domain. You are implementing Password Change Notification…
The correct answer is A. Select the .dll file of the HR MA extension as the extension name. C. Enable Password Management in the extensions of the HR Data MA. D. Set the Password Synchronization target MA to HR Data in the AD MA. E. Enable password synchronization in Synchronization Service Manager. G. Configure the Directory Partition of the AD MA to Enable this partition as a password synchronization source. Configuring PCNS-based password synchronization in FIM 2010 requires enabling password sync globally, configuring the AD MA as a password source, targeting the HR Data MA, and enabling password management on the HR Data MA with the correct extension DLL.
Question
Options
- ASelect the .dll file of the HR MA extension as the extension name.
- BSelect the .dll file of the metaverse extension as the extension name.
- CEnable Password Management in the extensions of the HR Data MA.
- DSet the Password Synchronization target MA to HR Data in the AD MA.
- EEnable password synchronization in Synchronization Service Manager.
- FCreate the HR Data MA import attribute flow for the resetPassword metaverse attribute.
- GConfigure the Directory Partition of the AD MA to Enable this partition as a password synchronization source.
How the community answered
(21 responses)- A67% (14)
- B10% (2)
- F24% (5)
Why each option
Configuring PCNS-based password synchronization in FIM 2010 requires enabling password sync globally, configuring the AD MA as a password source, targeting the HR Data MA, and enabling password management on the HR Data MA with the correct extension DLL.
The HR Data MA extension DLL must be specified as the extension name so that the MA can process password change notifications through its custom password management code.
The metaverse extension DLL is not used for password management on the HR Data MA; the MA's own extension DLL (option A) is required to handle password operations.
Enabling Password Management in the HR Data MA extensions is required so that the MA can accept and process inbound password synchronization calls from the synchronization engine.
Setting the Password Synchronization target MA to HR Data in the AD MA configuration establishes the flow path so that password changes captured by the AD MA via PCNS are forwarded to the HR Data MA.
Enabling password synchronization in Synchronization Service Manager is the global setting that activates the password synchronization infrastructure within FIM, without which no password sync operations will occur.
Creating an import attribute flow for resetPassword is not required for PCNS-based password synchronization, as password sync uses a dedicated password pipeline rather than standard attribute flow rules.
Configuring the Directory Partition of the AD MA to enable it as a password synchronization source allows the AD MA to receive PCNS notifications from domain controllers and initiate the password sync flow.
Concept tested: FIM 2010 PCNS password synchronization configuration
Source: https://learn.microsoft.com/en-us/previous-versions/mim/ff608278(v=ws.10)
Topics
Community Discussion
No community discussion yet for this question.