70-158 · Question #92
You use Forefront Identity Manager (FIM) 2010 in your company network. You use Management Policy Rules (MPRs) and synchronization rules to provision users. You discover that from yesterday, the…
The correct answer is A. Review the MPR Explorer for MPRs triggered by an update to user object attributes. To determine the scope of pending expected rule entries for external users, you should review the MPR Explorer for Management Policy Rules (MPRs) that are triggered by user object attribute updates, as MPRs govern user provisioning logic.
Question
Options
- AReview the MPR Explorer for MPRs triggered by an update to user object attributes.
- BReview the FIM application log in Event Viewer for event IDs that match synchronization errors.
- CVerify whether the Create resource in FIM option is selected for the inbound synchronization rules that
- DVerify whether the Create resource in External System option is selected for the outbound synchronization
How the community answered
(58 responses)- A60% (35)
- B12% (7)
- C22% (13)
- D5% (3)
Why each option
To determine the scope of pending expected rule entries for external users, you should review the MPR Explorer for Management Policy Rules (MPRs) that are triggered by user object attribute updates, as MPRs govern user provisioning logic.
Expected rule entries being in 'Pending' status often indicates that Management Policy Rules (MPRs) are not being triggered or are failing to process correctly, which can be caused by changes in user object attributes. Reviewing the MPR Explorer allows you to identify which specific MPRs are intended to handle these external users and see if their conditions or triggers related to user attribute updates are met or have recently changed, directly addressing the scope of the problem.
Reviewing synchronization errors in the Event Viewer addresses issues during the synchronization process itself, but 'Pending' rule entries suggest a problem upstream with MPR evaluation or rule generation, not necessarily a sync error that has already occurred.
Verifying the 'Create resource in FIM' option for inbound synchronization rules is a specific configuration check, but the 'Pending' status of rule entries implies a problem before this option would even be relevant, often at the MPR or initial rule generation stage.
Verifying the 'Create resource in External System' option for outbound synchronization rules is a specific configuration check for the final provisioning step, but 'Pending' rule entries suggest the issue is earlier in the process, preventing the rule from reaching the outbound synchronization stage.
Concept tested: FIM provisioning troubleshooting using MPR Explorer
Topics
Community Discussion
No community discussion yet for this question.