<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The IDA Guys</title><link>http://blogs.technet.com/b/idaguys/</link><description>The IDA Guys are made up of Identity Management experts from the Microsoft Technical Field. This blog will bring to you "on-the-street news", experiences and ideas about the Identity Management products from Microsoft that we live and breathe every day.   </description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>FIM 2010 RC1 Resource Management Client Sample Announcement</title><link>http://blogs.technet.com/b/idaguys/archive/2009/10/06/fim-2010-rc1-resource-management-client-sample-announcement.aspx</link><pubDate>Wed, 07 Oct 2009 00:14:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3285160</guid><dc:creator>IDAguys</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3285160</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/10/06/fim-2010-rc1-resource-management-client-sample-announcement.aspx#comments</comments><description>&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE: 12pt; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT face=Calibri&gt;The &lt;/FONT&gt;&lt;A href="http://code.msdn.microsoft.com/imexsamples/Release/ProjectReleases.aspx?ReleaseId=3276" mce_href="http://code.msdn.microsoft.com/imexsamples/Release/ProjectReleases.aspx?ReleaseId=3276"&gt;&lt;SPAN style="COLOR: blue"&gt;&lt;FONT face=Calibri&gt;FIM 2010 RC1 client&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt; is unsupported sample source code and documentation that shows how you could build a client to communicate with the FIM Web Service.&amp;nbsp; This sample client was inspired by Joe Schulman’s &lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://blogs.msdn.com/imex/archive/2008/11/19/how-to-build-your-custom-client.aspx" mce_href="http://blogs.msdn.com/imex/archive/2008/11/19/how-to-build-your-custom-client.aspx"&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: blue"&gt;public client&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="FONT-SIZE: 12pt; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; last year and the documentation is based on the &lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;A href="http://blogs.msdn.com/imex/archive/2009/04/23/prototype-v2-overview-of-the-new-api.aspx" mce_href="http://blogs.msdn.com/imex/archive/2009/04/23/prototype-v2-overview-of-the-new-api.aspx"&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; COLOR: blue"&gt;documentation&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 12pt; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt; Joe released in April.&amp;nbsp; Joe's client was written for&amp;nbsp;RC0 and cannot be used with RC1. You&amp;nbsp;may&amp;nbsp;now&amp;nbsp; use&amp;nbsp;this new client&amp;nbsp;with FIM 2010 RC1.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="FONT-SIZE: 12pt; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;The DefaultClientScenario.cs test case shows basic usage including Create, Read, Update, Delete, and Enumerate operations.&amp;nbsp; This sample client does not include documentation on how to complete approvals or the password reset scenario.&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="FONT-SIZE: 12pt; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;Please be prepared to step into the code and make adjustments. The most common issue people have with the client is correctly configuring WCF to communicate with the FIM Web Service. Ensure that you are setting the client credentials correctly and that you’ve modified the app.config file to include the service’s account name.&amp;nbsp; See the readme for more information.&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="FONT-SIZE: 12pt; mso-bidi-font-family: Calibri; mso-fareast-font-family: 'Times New Roman'; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;FONT face=Calibri&gt;While we hope that the client is useful in evaluating FIM, &lt;B&gt;&lt;U&gt;there is no commitment from Microsoft or from The IDA Guys&lt;/U&gt;&lt;/B&gt; to address any issues uncovered in the client or the examples provided.&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Times New Roman','serif'; FONT-SIZE: 12pt; mso-fareast-font-family: 'Times New Roman'"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3285160" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/idaguys/archive/tags/Forefront+Identity+Manager/">Forefront Identity Manager</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/FIM/">FIM</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ILM+2007/">ILM 2007</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ILM2/">ILM2</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/FIM+Web+Services+client/">FIM Web Services client</category></item><item><title>Forefront Identity Manager 2010 RC1 released</title><link>http://blogs.technet.com/b/idaguys/archive/2009/10/06/forefront-identity-manager-2010-rc1-released.aspx</link><pubDate>Tue, 06 Oct 2009 22:35:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3285144</guid><dc:creator>johnmcg</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3285144</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/10/06/forefront-identity-manager-2010-rc1-released.aspx#comments</comments><description>&lt;P&gt;&lt;FONT size=3&gt;The long awaited RC1 release of Microsoft Forefront Identity Manager is finally here.&amp;nbsp; Yes, we've been waiting a long time but good things take time and when it comes to FIM 2010 there are a lot of good things.&amp;nbsp; FIM 2010, aka "ILM2", is the next iteration of Identity Management tools from Microsoft.&amp;nbsp; While it is technically the successor to ILM 2007, aka "ILM1", it is by no means simply an upgrade.&amp;nbsp; FIM 2010 dramatically improves enterprise identity management by delivering powerful self-service capabilities for Office end-users, rich administrative tools and enhanced automation for IT professionals, and .NET and WS-* based extensibility for developers. The final release is slated for the first quarter of 2010. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;What’s new in FIM RC1:&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-ansi-language: EN" lang=EN&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 7pt; mso-ansi-language: EN" lang=EN&gt;&lt;FONT face="Times New Roman"&gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;Significant &lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'"&gt;performance and scalability improvements&lt;/SPAN&gt;&lt;/STRONG&gt; across the product.&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-ansi-language: EN" lang=EN&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 7pt; mso-ansi-language: EN" lang=EN&gt;&lt;FONT face="Times New Roman"&gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;Key feature enhancements&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;, such as the ability to show invalid security group members and to disable batch approve/reject of membership requests if needed. A System Center Operations Manager (SCOM) management pack and configuration migration tools are also new for RC1.&lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-ansi-language: EN" lang=EN&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 7pt; mso-ansi-language: EN" lang=EN&gt;&lt;FONT face="Times New Roman"&gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;The FIM 2010 &lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'"&gt;user interface has enhanced usability and layout&lt;/SPAN&gt;&lt;/STRONG&gt; in many areas, resulting directly from RC0 customer feedback. &lt;BR&gt;&lt;BR&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-ansi-language: EN" lang=EN&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-SIZE: 7pt; mso-ansi-language: EN" lang=EN&gt;&lt;FONT face="Times New Roman"&gt; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;The product is now &lt;STRONG&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'"&gt;rebranded as Forefront Identity Manager&lt;/SPAN&gt;&lt;/STRONG&gt; 2010, with a few exceptions, replacing the old “ILM 2” codename.&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;New documentation will be published to Connect as well as TechNet and MSDN in the next few days. Keep an eye on the &lt;/SPAN&gt;&lt;SPAN style="mso-ansi-language: EN" lang=EN&gt;&lt;A href="http://www.microsoft.com/forefront/identitymanager/en/us/technical-resources.aspx" mce_href="http://www.microsoft.com/forefront/identitymanager/en/us/technical-resources.aspx"&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'"&gt;&lt;FONT color=#0000ff&gt;Technical Resources&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt; page for updates. &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;FIM is part of Microsoft’s continued, far-reaching commitment to enabling more secure, identity-based access to applications - on-premises and in the cloud, from virtually any location or device&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style="FONT-FAMILY: 'Calibri','sans-serif'; mso-ansi-language: EN" lang=EN&gt;&lt;FONT size=3&gt;To learn more about the IDA solution you can find a webcast on the Launch website:&lt;BR&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;A href="http://www.thenewefficiency.com/" mce_href="http://www.thenewefficiency.com/"&gt;&lt;FONT color=#0000ff&gt;www.thenewefficiency.com&lt;/FONT&gt;&lt;/A&gt;&lt;/SPAN&gt; - browse to Business Ready Security – Identity and Access Management Solution &lt;/FONT&gt;&lt;/SPAN&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P&gt;Download FIM 2010 RC1 from the Microsoft TechNET Evaluation Center:&lt;BR&gt;&amp;nbsp;&lt;A href="http://technet.microsoft.com/en-us/evalcenter/cc872861.aspx" mce_href="http://technet.microsoft.com/en-us/evalcenter/cc872861.aspx"&gt;http://technet.microsoft.com/en-us/evalcenter/cc872861.aspx&lt;/A&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3285144" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/idaguys/archive/tags/FIM/">FIM</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ILM/">ILM</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ILM2/">ILM2</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/MIIS/">MIIS</category></item><item><title>Poor Man's Secure eDirectory Synchronization</title><link>http://blogs.technet.com/b/idaguys/archive/2009/09/17/poor-man-s-secure-edirectory-synchronization.aspx</link><pubDate>Thu, 17 Sep 2009 15:42:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3281639</guid><dc:creator>bpmohr</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3281639</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/09/17/poor-man-s-secure-edirectory-synchronization.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 10pt; tab-stops: list 51.05pt" class=MsoNormal&gt;&lt;A title=_Toc185386123 name=_Toc185386123&gt;&lt;/A&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT size=3 face=Calibri&gt;Securing Transactions between ILM 2007 and eDirectory&lt;/FONT&gt;&lt;/B&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;I had a client that required that I connect securely between ILM and eDirectory for provisioning and synchronization of Active Directory to eDirectory user objects.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;To use TLS there are two options.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;First, certificate services can be utilized to provide the necessary security for making the connection.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Second, secure tunnel (stunnel) can be utilized from the ILM server to provide the encryption.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Because of its ease of use, and the fact that the customer did not want to mess with PKI, we went with the latter option.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;But before we go down the securing path, we need to make sure the eDirectory Management Agent can connect to the eDirectory server.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The LDAP Server object for that server needs to be modified to support the connection.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The following steps will need to be performed from Novell ConsoleOne:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 110%; TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 29.35pt; mso-list: l1 level1 lfo2" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Double-Click on the &lt;B style="mso-bidi-font-weight: normal"&gt;LDAP Server&lt;/B&gt; object of the server that the eDirectory Management Agent will be connecting&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 110%; TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 29.35pt; mso-list: l1 level1 lfo2" class=MsoNormal&gt;&lt;IMG style="WIDTH: 258px; HEIGHT: 33px" src="http://2k2r7g.blu.livefilestore.com/y1putimu4k8cpp2o0wtxeFznXbsrGNEEgNkVlAD0jhgprlFTOBhtYvgdiuwc88xk4XdaaUajdlev_3bd9IGaUX-AEz-KCpQDKSc/edir1.JPG" width=385 height=43 mce_src="http://2k2r7g.blu.livefilestore.com/y1putimu4k8cpp2o0wtxeFznXbsrGNEEgNkVlAD0jhgprlFTOBhtYvgdiuwc88xk4XdaaUajdlev_3bd9IGaUX-AEz-KCpQDKSc/edir1.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;?xml:namespace prefix = v ns = "urn:schemas-microsoft-com:vml" /&gt;&lt;v:shapetype id=_x0000_t75 coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt;&lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 110%; TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 29.35pt; mso-list: l1 level1 lfo2" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;On the “General” tab, select the &lt;B style="mso-bidi-font-weight: normal"&gt;Enable old ADSI and Netscape schema output&lt;/B&gt; checkbox and click the &lt;B style="mso-bidi-font-weight: normal"&gt;Refresh NLDAP Server Now&lt;/B&gt; button&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 110%; TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 29.35pt; mso-list: l1 level1 lfo2" class=MsoNormal&gt;&lt;IMG src="http://2k2r7g.blu.livefilestore.com/y1putimu4k8cppqfOBWAiZ3EwGfXNiczpmouxO1gzfcpG4VPvIzVoHvaXCxS2v5Rf1Kpgcdkvjf7kAcmfGiJ8-Qy-_b8rnAFtmA/edir2.JPG" width=379 height=389 mce_src="http://2k2r7g.blu.livefilestore.com/y1putimu4k8cppqfOBWAiZ3EwGfXNiczpmouxO1gzfcpG4VPvIzVoHvaXCxS2v5Rf1Kpgcdkvjf7kAcmfGiJ8-Qy-_b8rnAFtmA/edir2.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 110%; TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 29.35pt; mso-list: l1 level1 lfo2" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="LINE-HEIGHT: 110%; TEXT-INDENT: -0.25in; MARGIN: 6pt 0in 3pt 29.35pt; mso-list: l1 level1 lfo2" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Close &lt;B style="mso-bidi-font-weight: normal"&gt;ConsoleOne&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Then it becomes time to install and configure Stunnel.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Quote from the website, they can tell you better than I can, what Stunnel is about.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;“Stunnel is a program that allows you to encrypt arbitrary TCP connections inside SSL (&lt;/FONT&gt;&lt;A href="http://www.netscape.com/eng/ssl3" mce_href="http://www.netscape.com/eng/ssl3"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Secure Sockets Layer&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;) available on both Unix and Windows. Stunnel can allow you to secure non-SSL aware daemons and protocols (like POP, IMAP, LDAP, etc) by having Stunnel provide the encryption, requiring no changes to the daemon's code.”&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Oh yea, it is open source under the GNU General Public License.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;1.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Download the latest Stunnel binaries from &lt;/FONT&gt;&lt;A href="http://www.stunnel.org/download/binaries.html" mce_href="http://www.stunnel.org/download/binaries.html"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;http://www.stunnel.org/download/binaries.html&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; to the ILM server&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;2.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Double-Click the installation executable.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For example, &lt;B style="mso-bidi-font-weight: normal"&gt;stunnel-4.27-installer.exe&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;3.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;Run&lt;/B&gt; on the Security Warning&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG src="http://2k2r7g.blu.livefilestore.com/y1pjiJ_55avaAC6h9zCLjeKE1aYL-v5lsF3pag7XdDs3ttJmBbrTA3pyeQEzV6H8e3p9BbzAD5jIG9j943wmOsOgUH1O1OuT9O7/edir3.JPG" width=372 height=344 mce_src="http://2k2r7g.blu.livefilestore.com/y1pjiJ_55avaAC6h9zCLjeKE1aYL-v5lsF3pag7XdDs3ttJmBbrTA3pyeQEzV6H8e3p9BbzAD5jIG9j943wmOsOgUH1O1OuT9O7/edir3.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;4.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;I Agree&lt;/B&gt;, on the License Agreement&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG src="http://2k2r7g.blu.livefilestore.com/y1pT8Urc1e9ajzGRxBY6eE1Mm6YTn3_uyLjgCbkfMSszBm7f36IFE_awFheFF7a_trEOGpE8wvCIGc6EbTlxa6h7cM9foA__Rmu/edir4.JPG" width=312 height=335 mce_src="http://2k2r7g.blu.livefilestore.com/y1pT8Urc1e9ajzGRxBY6eE1Mm6YTn3_uyLjgCbkfMSszBm7f36IFE_awFheFF7a_trEOGpE8wvCIGc6EbTlxa6h7cM9foA__Rmu/edir4.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;5.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Accept the defaults and click &lt;B style="mso-bidi-font-weight: normal"&gt;Next&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG src="http://2k2r7g.blu.livefilestore.com/y1pt9VvuYhkEe8HxV_PKVFASDyQDBKsifwOnWp_F1fFM3-j1woL_ax1qqTqXgZ9osiAaU1uoGPtu1fvO9wwYSz_L69tO7ILhKUm/edir5.JPG" width=373 height=300 mce_src="http://2k2r7g.blu.livefilestore.com/y1pt9VvuYhkEe8HxV_PKVFASDyQDBKsifwOnWp_F1fFM3-j1woL_ax1qqTqXgZ9osiAaU1uoGPtu1fvO9wwYSz_L69tO7ILhKUm/edir5.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;6.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Accept the default installation folder and click &lt;B style="mso-bidi-font-weight: normal"&gt;Install&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG src="http://2k2r7g.blu.livefilestore.com/y1phuRpwc5JLJLFtJPUtlALRPuJkpCF4wAA1mngvLp7ZufdMEF4Iaheqz0XlNkiMKcYpi_QNZw9Od3TdpJPZdyAH2mwOurkp4z1/edir6.JPG" width=381 height=284 mce_src="http://2k2r7g.blu.livefilestore.com/y1phuRpwc5JLJLFtJPUtlALRPuJkpCF4wAA1mngvLp7ZufdMEF4Iaheqz0XlNkiMKcYpi_QNZw9Od3TdpJPZdyAH2mwOurkp4z1/edir6.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;7.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;Close&lt;/B&gt; when completed&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG src="http://2k2r7g.blu.livefilestore.com/y1pRBJyVbWfJmMB0KDOQTvrOM1pz5-VJrwFC1_CA_pO9dkBtAGDX7uGVSWQC3q9JtjrIvq-3vP4SAiTD45jQaO6AlEuydVjiYWv/edir7.JPG" width=380 height=298 mce_src="http://2k2r7g.blu.livefilestore.com/y1pRBJyVbWfJmMB0KDOQTvrOM1pz5-VJrwFC1_CA_pO9dkBtAGDX7uGVSWQC3q9JtjrIvq-3vP4SAiTD45jQaO6AlEuydVjiYWv/edir7.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;8.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Edit &lt;B style="mso-bidi-font-weight: normal"&gt;c:\program files\stunnel\stunnel.conf&lt;/B&gt; by using only the following information.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Delete all other information:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG style="WIDTH: 411px; HEIGHT: 514px" src="http://2k2r7g.blu.livefilestore.com/y1pz0R8Ekq9aO1R8AROWVIeMXJ54MShnAJKVEwdFEnCvcTVvGBUlUvSzFLhN5obG4IwPn4UdygJbek7F4SxQisNMBR5Cs_PSiev/edir8.JPG" width=569 height=594 mce_src="http://2k2r7g.blu.livefilestore.com/y1pz0R8Ekq9aO1R8AROWVIeMXJ54MShnAJKVEwdFEnCvcTVvGBUlUvSzFLhN5obG4IwPn4UdygJbek7F4SxQisNMBR5Cs_PSiev/edir8.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;*Note:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The &lt;B style="mso-bidi-font-weight: normal"&gt;connect = 192.168.1.18:636&lt;/B&gt; will need to be changed to reflect the production eDirectory server.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;9.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Close and save&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;10.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;Start &amp;gt; stunnel &amp;gt; Service install&lt;/B&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG style="WIDTH: 388px; HEIGHT: 167px" src="http://2k2r7g.blu.livefilestore.com/y1pq3gkcnJ-iw-AWIekPby2flrCixlRxJ0JeHUGA60PHyacGrEtNXmA9Sy2MZ91VX9BJqO7b1QNMdNSHfzp_S2vvmVTTNE6islf/edir9.JPG" width=1080 height=417 mce_src="http://2k2r7g.blu.livefilestore.com/y1pq3gkcnJ-iw-AWIekPby2flrCixlRxJ0JeHUGA60PHyacGrEtNXmA9Sy2MZ91VX9BJqO7b1QNMdNSHfzp_S2vvmVTTNE6islf/edir9.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;11.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Click &lt;B style="mso-bidi-font-weight: normal"&gt;OK&lt;/B&gt; on Service installed&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG src="http://2k2r7g.blu.livefilestore.com/y1p-M894-gU1umNh6rz08BexZLDs7Limf5QSim9rzfQszK_2gNwrqMvEHpZEP1FNXNt3uCxnROq13M8XZffmBDK-d4iytl_H2GZ/edir10.JPG" width=232 height=125 mce_src="http://2k2r7g.blu.livefilestore.com/y1p-M894-gU1umNh6rz08BexZLDs7Limf5QSim9rzfQszK_2gNwrqMvEHpZEP1FNXNt3uCxnROq13M8XZffmBDK-d4iytl_H2GZ/edir10.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;SPAN style="mso-bidi-font-family: Calibri; mso-bidi-theme-font: minor-latin"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;12.&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Start the &lt;B style="mso-bidi-font-weight: normal"&gt;stunnel &lt;/B&gt;service&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.25in; mso-list: l0 level1 lfo1; tab-stops: list .25in" class=MsoNormal&gt;&lt;IMG src="http://2k2r7g.blu.livefilestore.com/y1pJVaZTVAyqrp6NBxM83Kv07dZYLVryyz9PmS5DQa30tMAp1e0xWhN88NqZmg2i6_EKtwUO1g9iUSrdnIUHGYFn0deXxqonecX/edir11.JPG" width=408 height=387 mce_src="http://2k2r7g.blu.livefilestore.com/y1pJVaZTVAyqrp6NBxM83Kv07dZYLVryyz9PmS5DQa30tMAp1e0xWhN88NqZmg2i6_EKtwUO1g9iUSrdnIUHGYFn0deXxqonecX/edir11.JPG"&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3281639" width="1" height="1"&gt;</description></item><item><title>Manageability for Identity and Access Management solutions</title><link>http://blogs.technet.com/b/idaguys/archive/2009/07/29/manageability-for-identity-and-access-management-solutions.aspx</link><pubDate>Wed, 29 Jul 2009 14:59:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3269046</guid><dc:creator>glenn walton - Microsoft</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3269046</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/07/29/manageability-for-identity-and-access-management-solutions.aspx#comments</comments><description>&lt;P&gt;this is a cross posting, the article is here: &lt;A href="http://blogs.technet.com/architect_viewpoint/archive/2009/07/29/manageability-for-identity-and-access-management-solutions.aspx"&gt;http://blogs.technet.com/architect_viewpoint/archive/2009/07/29/manageability-for-identity-and-access-management-solutions.aspx&lt;/A&gt;. &lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3269046" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/idaguys/archive/tags/Forefront+Identity+Manager/">Forefront Identity Manager</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/FIM/">FIM</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ILM+2007/">ILM 2007</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/RMS/">RMS</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/Identity/">Identity</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ADFS/">ADFS</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ILM/">ILM</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/SystemCenter/">SystemCenter</category></item><item><title>Overiview of authentication mechanisms in AD LDS</title><link>http://blogs.technet.com/b/idaguys/archive/2009/06/19/overiview-of-authentication-in-ad-lds.aspx</link><pubDate>Fri, 19 Jun 2009 23:24:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3256898</guid><dc:creator>aungoo-MSFT</dc:creator><slash:comments>3</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3256898</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/06/19/overiview-of-authentication-in-ad-lds.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Hello All,&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;I have been working with a customer on application authentication project with AD LDS (Active Directory Lightweight Directory Services) and ADAM (Active Directory in Application Mode) and I thought it might be interested to share my experience on this blog.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;There are many things to share but I will focus this blog entry on available authentication options and will try to break it down their usage depending on the scenario.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Since this entry explores only the authentication aspect of AD LDS or ADAM, this can apply to both products.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I will stick with AD LDS for the remainder of the blog for the sake of clarity.&amp;nbsp; &lt;/FONT&gt;&lt;FONT size=3&gt;If you are not familiar with AD LDS or ADAM, look at the Windows Server Tech Center page at &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc731868.aspx" mce_href="http://technet.microsoft.com/en-us/library/cc731868.aspx"&gt;&lt;FONT size=3&gt;http://technet.microsoft.com/en-us/library/cc731868.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Brian Puhl’s recorded session at &lt;/FONT&gt;&lt;A href="http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=342" mce_href="http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=342"&gt;&lt;FONT size=3&gt;http://www.microsoft.com/emea/spotlight/sessionh.aspx?videoid=342&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;covers when to use AD LDS or AD DS.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;You can use one of three authentication mechanisms available with AD LDS to authenticate:&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;AD LDS principal authentication, Windows principal authentication and AD LDS proxy authentication.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;AD LDS principal authentication is the most common scenario that I have seen at customer implementations.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Customers who have legacy applications which require specific directory applications for simple LDAP authentication and they do not want to extend schema of their AD DS.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is a simple LDAP authentication which allows users to bind with DN (distinguished name) of their AD LDS account in X.500 format and its password.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;User account policies such as account locked out and password complexity are enforced by the local security policy of the machine that AD LDS instance is configured, if the server is in a workgroup.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Active Directroy Domain account polices are applied, if the server belongs to a domain.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The drawback in this authentication type is that users’ password are transmitted in clear text format so it requires additional step to configure LDAP over SSL.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The instructions on how to configure LDAP over SSL for AD LDS is at &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc725767.aspx" mce_href="http://technet.microsoft.com/en-us/library/cc725767.aspx"&gt;&lt;FONT size=3&gt;http://technet.microsoft.com/en-us/library/cc725767.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;Let’s look at Windows principal authentication (also known as SSPI authentication).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Customers are usually not aware of this authentication type.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This approach allows users to authenticate to AD LDS instance using their AD DS domain account or local user accounts on the server that AD LDS instance is hosted.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In order for users to authenticate using their domain account, the server that the AD LDS instance is hosted must be a member of the domain.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The authentication using the domain account leverages Kerberos protocol (although may fall back to NTLM depending on the AD domain policies) and thus more secure than using a local account which leverages NTLM.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This MSDN article &lt;/FONT&gt;&lt;A href="http://msdn.microsoft.com/en-us/magazine/dvdarchive/cc300806.aspx" mce_href="http://msdn.microsoft.com/en-us/magazine/dvdarchive/cc300806.aspx"&gt;&lt;FONT size=3&gt;http://msdn.microsoft.com/en-us/magazine/dvdarchive/cc300806.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; explains the capabilities of different authentication protocols and explains why Kerberos protocol is more secured than using other Windows authentication type.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Using Windows principal authentication obviates the need to configure LDAP over SSL as it leverages Kerberos or NTLM Sign and Encrypt mechanism to encrypt the traffic.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is also easier to manage domain accounts with domain policies and security groups.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If the Windows principal is leveraged to authenticate to an AD LDS instance, users must provide their windows credentials with user name and the domain.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The con of Windows principal authentication is that it cannot accommodate legacy and non-Windows applications which still require binding with an X.500 path.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;The third option is ADAM proxy user authentication, also known as bind redirection, in which users authenticate with their AD LDS principals but can leverage their corresponding AD DS passwords.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Proxy authentication allows reduced sign on for users where users still need to leverage DN of AD LDS account to authenticate but can use the same password as their AD DS account.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This option simplifies the account management as account management can be done from AD DS.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This option requires the server the AD LDS instance is hosted to join to the AD DS domain or needs a trust relationship with the AD DS domain in which users’ AD DS account resides.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This option also requires additional synchronization tools like Identity Lifecycle Manager 2007 or Forefront Identity Manager 2010 (currently in Beta) to synchronize the objectSID of AD DS user account to the corresponding AD LDS account.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;LDAP over SSL should be configured for users to authenticate with their AD LDS account in order to keep their domain account password secure.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This technet article &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/magazine/2008.12.proxy.aspx" mce_href="http://technet.microsoft.com/en-us/magazine/2008.12.proxy.aspx"&gt;&lt;FONT size=3&gt;http://technet.microsoft.com/en-us/magazine/2008.12.proxy.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; provides more insight into proxy authentication.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;This article &lt;/FONT&gt;&lt;A href="http://technet.microsoft.com/en-us/library/cc784622.aspx" mce_href="http://technet.microsoft.com/en-us/library/cc784622.aspx"&gt;&lt;FONT size=3&gt;http://technet.microsoft.com/en-us/library/cc784622.aspx&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt; explains how to set up each of the authentication available in AD LDS.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;My recommendation is to leverage Windows principal authentication leveraging users’ AD DS domain accounts when possible for the reasons mentioned above unless applications cannot support Windows authentication.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If your environment has synchronization product like ILM, Bi-directional proxy authentication should be explored to simplify the account management.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3256898" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/idaguys/archive/tags/AD+LDS/">AD LDS</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ADAM/">ADAM</category></item><item><title>TEC 2009 Part 3</title><link>http://blogs.technet.com/b/idaguys/archive/2009/06/12/tec-2009-part-3.aspx</link><pubDate>Fri, 12 Jun 2009 15:10:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3254402</guid><dc:creator>erichue</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3254402</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/06/12/tec-2009-part-3.aspx#comments</comments><description>&lt;P&gt;Greetings All,&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;This is my first public blog post.&amp;nbsp;&amp;nbsp; Like many of the other posters on this blog, I was at the Las Vegas 2009 TEC conference as a speaker.&amp;nbsp; I presented on ILM “2” Best Practices, which was largely a repeat of a presentation that Bahram Rushenas and I presented internally shortly before TEC based on our experiences working with Rapid Deployment Program (RDP) customers that have been working with pre-release versions of FIM.&lt;BR&gt;We tried to focus on both the technical “gotchas” in ILM “2” / FIM 2010 RC0 as well as the deeper, longer-term concerns in implementing a system that touches on so many aspects of the business including system availability and security.&amp;nbsp; &lt;BR&gt;Some of the technical gotchas we talked about were naming standards and MPR interactions.&amp;nbsp; Those are the easy, straight forward points.&amp;nbsp; &lt;/P&gt;
&lt;P&gt;&lt;BR&gt;The other area is a bit of a passion of mine.&amp;nbsp; While there are reams of information on how many products work at the nuts and bolts level, there is rarely very good documentation on how to take a business problem from genesis through to a documented, supportable, long-term solution.&amp;nbsp; (A notable exception is the Identity and Access Management Series at &lt;A href="http://technet.microsoft.com/en-us/library/cc162924.aspx"&gt;http://technet.microsoft.com/en-us/library/cc162924.aspx&lt;/A&gt;.)&amp;nbsp;&amp;nbsp; Implementation of an Identity Management System relies on the architect or design team to wear a number of hats.&amp;nbsp; Infrastructure expert, Development guru, and Process Analyst skills are all required to make a fully effective IdM system.&amp;nbsp; &lt;BR&gt;&lt;/P&gt;
&lt;P&gt;In ILM 2007 there really wasn’t a need to be more that a basic developer for the technology side.&amp;nbsp; Everything processed on a per-object, serial manner and occurred in the back room out of sight.&amp;nbsp; If you had a problem, then you just tied in the debugger and stepped through an object or two.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;In FIM 2010 (formerly ILM “2”), you now need to handle workflow, web-services and concurrency on the development side and security, availability and performance much more than before on the infrastructure side.&amp;nbsp; Placing a debugger on the production FIM Service will likely generate a lot of helpdesk tickets since it will inhibit requests from processing while you are stepping through the code (if you can figure out which transaction you are looking for).&lt;BR&gt;&lt;/P&gt;
&lt;P&gt;The scope of scenarios that FIM can handle is very much larger and more complicated than the scenarios for which we typically used ILM 2007.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;Also, we need to take into account that the solution needs to run long after the implementer has left the environment.&amp;nbsp; Preferably as something other than a “black box”.&amp;nbsp; More on that point in a later post.&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;You will find the presentation from TEC by clicking on this link:&amp;nbsp; &lt;A title='ILM "2" Best Practices Deck' href="http://cid-4bdcfb3accaf11c8.skydrive.live.com/self.aspx/IDAGuys/TEC2009%20ILM%20Best%20Practices%20-%20Huebner.ppt" target=_blank mce_href="http://cid-4bdcfb3accaf11c8.skydrive.live.com/self.aspx/IDAGuys/TEC2009%20ILM%20Best%20Practices%20-%20Huebner.ppt"&gt;ILM "2" Best Practices Deck&lt;/A&gt;.&lt;BR&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3254402" width="1" height="1"&gt;</description></item><item><title>NEVER Say it will only take Five Minutes…. (The case of the ILM SQL Management Agent trying to connect to a database with a trailing space in the name)</title><link>http://blogs.technet.com/b/idaguys/archive/2009/06/06/never-say-it-will-only-take-five-minutes-the-case-of-the-ilm-sql-management-agent-trying-to-connect-to-a-database-with-a-trailing-space-in-the-name.aspx</link><pubDate>Sat, 06 Jun 2009 03:15:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3251020</guid><dc:creator>mkradel</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3251020</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/06/06/never-say-it-will-only-take-five-minutes-the-case-of-the-ilm-sql-management-agent-trying-to-connect-to-a-database-with-a-trailing-space-in-the-name.aspx#comments</comments><description>&lt;H2 style="MARGIN: 10pt 0in 0pt"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/H2&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Before I begin to explain this post heading, I wanted to say a few words about my contribution to the “IDA Guys” blog.&amp;nbsp; I was excited for the opportunity to participate in this blog.&amp;nbsp; One of the reasons I wanted to participate is that through the years I have received help from many, many people in the community via their blogs and forum posts.&amp;nbsp; They don’t know they’ve helped me because most of the time I ended up at their post via a search engine, looking for a specific answer to a question or problem.&amp;nbsp; It is hard to imagine how we ever lived without community support.&amp;nbsp; I really hope that through this blog others too will find some information that will be useful in getting their job done.&amp;nbsp; The content of this specific post is a completely different subject from the previous posts, and the one that follows this is likely to be different yet again.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Now, back to the subject at hand….&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Never say it will only take five minutes. Why? Because you never know the issues that you are going to face.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Yes, I am a consultant, so there is some suspicion when I’m asked “how long” and I hesitate and am reluctant to give an answer.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But the reluctance is born from experience.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I really need to think before I answer a question about the level of effort.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;I know I’m getting old, my kids remind me of that with every additional strand of gray hair that I proudly accumulate.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I also know I’m getting old when I see younger IT professionals proudly and quickly saying, “That’s easy, it will only take a few minutes”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Call me cynical, but my personal opinion is, “Nothing is easy”.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I prefer to think of myself as a realist.&amp;nbsp; Except when I forget my own advice, like I'm about to relate.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Given that backdrop, I want to share an experience I had recently where I was requested to do a fairly small item with an ILM 2007 implementation.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;T&lt;/FONT&gt;&lt;A style="mso-comment-reference: md_3; mso-comment-date: 20090605T1636"&gt;&lt;/A&gt;&lt;A style="mso-comment-reference: mjk_2; mso-comment-date: 20090605T1636"&gt;&lt;/A&gt;&lt;A style="mso-comment-reference: md_1; mso-comment-date: 20090605T1636"&gt;&lt;SPAN style="mso-comment-continuation: 2"&gt;&lt;SPAN style="mso-comment-continuation: 3"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;he customer wanted me to set up a simple SQL MA, which was not part of the original work plan.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; I figured I could get this done very quickly, the proverbial five minutes.&amp;nbsp; T&lt;/SPAN&gt;he supposed five minute easy change, took almost a full day.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;In relating this experience, I also hope to drop a few bread crumbs along the way so that if you hit this problem, you may remember this post, and your five minutes won’t grow into hours.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;The simple SQL Management Agent&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;How long should it take to create a simple Proof of Concept connection to a SQL database?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Five minutes?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;You would think, but experience has taught me that things rarely go as planned. The company I’m working at is large and complex.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The SQL database was on a remote server and is controlled by the SQL team.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The developer I’m working with is six time zones away.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is a development database, so the developer does have administrative access, so getting access to the database wasn’t a problem.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Minor problem number 1 hits me when I go to setup the MA.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The account I gave the developer to give access to the SQL table is not going to work.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;My development environment is in an untrusted domain from the target SQL server.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The account I had permissions granted to is in the forest of the SQL server, but “Integrated Authentication” won’t work from the ILM development environment in the untrusted domain.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I need a new SQL account provisioned, but just to be sure that was the problem I did a little research on the SQL authentication options.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;All in all, my five minutes is up to an hour.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;That though, didn’t turn out to be the biggest problem.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Once I received the SQL account, I still could not get connected, and repeatedly received the following dialog, “Failed to retrieve the schema.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Cannot open the database table you’ve specified”.&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="mso-no-proof: yes"&gt;&lt;?xml:namespace prefix = v ns = "urn:schemas-microsoft-com:vml" /&gt;&lt;v:shapetype id=_x0000_t75 stroked="f" filled="f" path="m@4@5l@4@11@9@11@9@5xe" o:preferrelative="t" o:spt="75" coordsize="21600,21600"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:connecttype="rect" gradientshapeok="t" o:extrusionok="f"&gt;&lt;/v:path&gt;&lt;o:lock aspectratio="t" v:ext="edit"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The first bit of troubleshooting was to verify the account had privileges.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I had no problem using that account through various other tools, including osql and SQL Server Management Studio.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;I could not figure out what was going on.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I was getting a bit frustrated at this point, so to completely eliminate permissions I got on the phone with the developer and we temporarily elevated the account privileges, but as expected, that didn’t work either. &lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;I really needed to get things moving, so I decided I would just recreate the table on my local development SQL box.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;So I auto-generated, via the SQL Server Management studio, the creation of the table that I would then develop against, and I’d worry about the real connectivity later.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Here is a snippet of the SQL generated to create the table, and see if you notice anything:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;USE [Database1 ]&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;GO&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;CREATE TABLE [dbo].[TESTTABLENAME](&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;[USER_ID] [varchar](30) NOT NULL,&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt 0.5in" class=MsoNormal&gt;&lt;SPAN style="LINE-HEIGHT: 115%; FONT-SIZE: 12pt"&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="mso-tab-count: 1"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;…)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Do you see the issue?&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;There is a trailing space in the database name.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I noticed it immediately when I looked at the script.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;I didn’t bring it up at first, because using osql from the command line, I could add or strip the space on the command line and it would still work.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;But when all else failed, I asked the developer owning the database to copy the table to another database on the server, and sure enough that was the issue.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;After that, I confirmed with my colleagues on the ILM Product Team that this would be a problem.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;They were able to review the code and validate that ILM trims the input from the Management Agent Setup UI.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This was what was causing the connection failure.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;That is the bread crumb that I hope helps somebody else some day, in the unlikely event that their database name has a trailing space.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;The five minute MA creation took me the better part of the day, and the reality is we still need to come up with a solution to deal with this table in production as I was told that changing the database wasn’t going to be an option, but that is for another day.&lt;B style="mso-bidi-font-weight: normal"&gt; &lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3251020" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/idaguys/archive/tags/ILM+2007/">ILM 2007</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/SQL+Server+Management+Agent/">SQL Server Management Agent</category></item><item><title>The Experts Conference Continued... </title><link>http://blogs.technet.com/b/idaguys/archive/2009/05/21/the-experts-conference-continued.aspx</link><pubDate>Thu, 21 May 2009 04:07:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3243935</guid><dc:creator>MikeDube</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3243935</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/05/21/the-experts-conference-continued.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Following on from Brian’s last post about The Experts Conference, I also wanted to share my experience with the conference and talk about a session that Markus Vilcinskas and I delivered.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;?xml:namespace prefix = v ns = "urn:schemas-microsoft-com:vml" /&gt;&lt;v:shapetype id=_x0000_t75 coordsize="21600,21600" o:spt="75" o:preferrelative="t" path=" m@4@5 l@4@11@9@11@9@5 xe" filled="f" stroked="f"&gt;&lt;v:stroke joinstyle="miter"&gt;&lt;/v:stroke&gt;&lt;v:formulas&gt;&lt;v:f eqn="if lineDrawn pixelLineWidth 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 1 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum 0 0 @1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @2 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @3 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @0 0 1"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @6 1 2"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelWidth"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @8 21600 0"&gt;&lt;/v:f&gt;&lt;v:f eqn="prod @7 21600 pixelHeight"&gt;&lt;/v:f&gt;&lt;v:f eqn="sum @10 21600 0"&gt;&lt;/v:f&gt;&lt;/v:formulas&gt;&lt;v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"&gt;&lt;/v:path&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:lock v:ext="edit" aspectratio="t"&gt;&lt;/o:lock&gt;&lt;/v:shapetype&gt;&lt;v:shape style="Z-INDEX: 1; POSITION: absolute; MARGIN-TOP: 172.15pt; WIDTH: 94.5pt; HEIGHT: 126pt; VISIBILITY: visible; MARGIN-LEFT: 380.25pt; mso-wrap-style: square; mso-wrap-distance-left: 9pt; mso-wrap-distance-top: 0; mso-wrap-distance-right: 9pt; mso-wrap-distance-bottom: 0; mso-position-horizontal: absolute; mso-position-horizontal-relative: text; mso-position-vertical: absolute; mso-position-vertical-relative: text" id=Picture_x0020_0 alt="belgium_hospital.jpg" o:spid="_x0000_s1029" type="#_x0000_t75"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;v:imagedata src="file:///C:\Users\MIKEDU~1.RED\AppData\Local\Temp\msohtmlclip1\01\clip_image001.jpg" o:title="belgium_hospital"&gt;&lt;/v:imagedata&gt;&lt;?xml:namespace prefix = w ns = "urn:schemas-microsoft-com:office:word" /&gt;&lt;w:wrap type="square"&gt;&lt;/w:wrap&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/v:shape&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;This year marked the&amp;nbsp;6th TEC event that I attended, and I firmly believe that if you work with Microsoft Identity and Access technology (and now Exchange) and you have to pick one conference a year to attend, TEC is the event to go to.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As a little backgrounder, the Directory Experts Conference (DEC) was conceived by NetPro’s Gil Kirkpatrick (CTO) and Christine McDermott (VP of Marketing) back in 2002 and was originally designed to be a “get together” of smart AD professionals that would discuss AD over pizza and beer (at least that was Gil’s plan).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Gil tells the story better than I could, so here’s a &lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.gilkirkpatrick.com/Blog/post/2005/12/18/Happy-Birthday-DEC.aspx"&gt;&lt;FONT size=3 face=Calibri&gt;link&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; to his account on the conception of the event.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;Since the 2002 event in Arizona, NetPro continued the event, growing its constituency and technology focus year over year.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;DEC 2005 in Vancouver was the first event I attended, and it was the first event to host a dedicated MIIS track.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;We had a small out of the way room, and between 20 and 30 peop&lt;IMG style="WIDTH: 150px; HEIGHT: 200px" title="Mike's Brussels Hospital Experience" border=10 hspace=10 alt="Mike's Brussels Hospital Experience" vspace=10 align=right src="http://0pbtsa.bay.livefilestore.com/y1pMbQ3s4TrWRj6OfLPjJYP-bqLMk8_uoLBY2CeXaWcjfjeRH3dlgpT9YRtuDBRTrRIKKf0oIPEfayMldqAOyYxLn8ZpvfH_hPe/belgium_hospital.jpg" width=150 height=200 mce_src="http://0pbtsa.bay.livefilestore.com/y1pMbQ3s4TrWRj6OfLPjJYP-bqLMk8_uoLBY2CeXaWcjfjeRH3dlgpT9YRtuDBRTrRIKKf0oIPEfayMldqAOyYxLn8ZpvfH_hPe/belgium_hospital.jpg"&gt;le in most of the sessions.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;That year I presented with Andreas Luther, then GPM of the MIIS Product Team, on the changes introduced in MIIS 2003 SP1… man that was a long time ago.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For a flash back to that time, here’s the deck&amp;nbsp;for that session.&lt;/FONT&gt;&lt;IFRAME style="BORDER-BOTTOM: #dde5e9 1px solid; BORDER-LEFT: #dde5e9 1px solid; PADDING-BOTTOM: 0px; BACKGROUND-COLOR: #ffffff; MARGIN: 3px; PADDING-LEFT: 0px; WIDTH: 180px; PADDING-RIGHT: 0px; HEIGHT: 26px; BORDER-TOP: #dde5e9 1px solid; BORDER-RIGHT: #dde5e9 1px solid; PADDING-TOP: 0px" marginHeight=0 src="http://cid-993d99f6b52174a6.skydrive.live.com/embedrow.aspx/IDA%20Guys/DEC%20-%20MIIS%20SP1%20-%20v2.ppt" frameBorder=0 marginWidth=0 scrolling=no&gt;&lt;/IFRAME&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Since 2005, I’ve presented at a few events in Las Vegas, once in Chicago and even once in Belgium (where I badly sprained my ankle on an excursion to Luxemburg and got to spend a lovely evening in the Brussels hospital and the rest of the conference on crutches).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;As Brian pointed out in last week’s post, the conference has been renamed from DEC to TEC since Quest’s acquisition of NetPro.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This is in part to break the “D” for Directory out of the primary name of the conference since the event is branching out to include other technologies.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;TEC now includes:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.75in; mso-list: l1 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;The Experts Conference for Directory and Identity&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.75in; mso-list: l1 level1 lfo2; mso-add-space: auto" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;The Experts Conference for Exchange&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;v:shape style="Z-INDEX: 2; POSITION: absolute; MARGIN-TOP: 30.7pt; WIDTH: 150pt; HEIGHT: 112.35pt; VISIBILITY: visible; MARGIN-LEFT: 1.5pt; mso-wrap-style: square; mso-wrap-distance-left: 9pt; mso-wrap-distance-top: 0; mso-wrap-distance-right: 9pt; mso-wrap-distance-bottom: 0; mso-position-horizontal: absolute; mso-position-horizontal-relative: text; mso-position-vertical: absolute; mso-position-vertical-relative: text" id=Picture_x0020_3 alt="MikeHolgerAndJorg.JPG" o:spid="_x0000_s1028" type="#_x0000_t75"&gt;&lt;/v:shape&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;What I love most about this conference are the people that I meet and the experiences that they have to share, both on stage and off.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Not only is the conference well attended by &lt;IMG style="WIDTH: 200px; HEIGHT: 150px" title="Holger Reiners, Jörg Finkeisen and Mike" border=10 hspace=10 alt="Holger Reiners, Jörg Finkeisen and Mike" vspace=10 align=left src="http://0pbtsa.bay.livefilestore.com/y1pSgcZvt5fH060QOqBni9p2a5I_lMHlv2dxZh0CGPtuveBdrtmcgb8PjjSYQHmSJg8ajc-ORZUPqUvBqNEqtkpclxKZZgK-90k/MikeHolgerAndJorg.jpg" width=200 height=150 mce_src="http://0pbtsa.bay.livefilestore.com/y1pSgcZvt5fH060QOqBni9p2a5I_lMHlv2dxZh0CGPtuveBdrtmcgb8PjjSYQHmSJg8ajc-ORZUPqUvBqNEqtkpclxKZZgK-90k/MikeHolgerAndJorg.jpg"&gt;the Microsoft Product Teams that are building the technology the conference is focused on, but they are also well attended by our partner community, both ISVs and SIs, and as such is a great opportunity to get together with the people that do the same thing you do and share stories and experiences.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;My friend Craig Martin talked about this a little during his “ILM 2 Migration Strategies” session this year and compared TEC to the place where the bumble-bee girl finds happiness in the Blind Mellon video for their song &lt;/FONT&gt;&lt;/FONT&gt;&lt;A href="http://www.youtube.com/watch?v=dYlAwvz8uwc"&gt;&lt;FONT size=3 face=Calibri&gt;“No Rain”&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt;.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In the video, a little girl finds herself estranged from everyone else because she went around wearing a bumble-bee costume, but finally found her bliss in a place where everyone wears bumble-bee costumes.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This hit it on the head for me.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In my “normal life”, nobody really wants to hear about the trials and tribulations of Enterprise Identity and Access Management.&amp;nbsp; Of course they do ask, but the&amp;nbsp;deer-in-the-headlights stare&amp;nbsp;quickly makes it evident that they were hoping for a more generic answer.&amp;nbsp; However,&amp;nbsp;at TEC, people do&amp;nbsp;care and we all have stories to share with each other.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;These experiences help us grow both in our professional and our personal lives, as the connections made at these&amp;nbsp;events lead to friendships as well as a larger networking circle.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;IMG style="WIDTH: 150px; HEIGHT: 200px" title="Craig Martin, Mike and the TEC Chicken" border=10 hspace=10 alt="Craig Martin, Mike and the TEC Chicken" vspace=10 align=right src="http://0pbtsa.bay.livefilestore.com/y1pLBQdna4J2nTZSbUDDHQXLH82itQuI2vMK7SJCHWRWI0d6qppLSfqWxIVi9T3HBEWEBn4eMDKlhIeQAYOr_tWchrPODqPuQBN/Chicken2.JPG" width=150 height=200 mce_src="http://0pbtsa.bay.livefilestore.com/y1pLBQdna4J2nTZSbUDDHQXLH82itQuI2vMK7SJCHWRWI0d6qppLSfqWxIVi9T3HBEWEBn4eMDKlhIeQAYOr_tWchrPODqPuQBN/Chicken2.JPG"&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;While the conference is very serious in its purpose of providing highly technical content to its constituents, there is also a lot of fun to be had.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; This year included a large chicken making its way around the conference, making for fun photo-ops.&amp;nbsp; Also, e&lt;/SPAN&gt;very year there is a challenge&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;presented by Stuart Kwan called the Wook Lee Challenge (now called the Wook Lee Memorial Challenge as Wook has failed to make the past few events).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Each year, Stuart throws out some suggestions for how to incorporate Microsoft’s IDA technology into some humorous and artistic endeavor (poetry, music, art).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;For some examples, check out these links:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;v:shape style="Z-INDEX: 3; POSITION: absolute; TEXT-ALIGN: left; MARGIN-TOP: -150.5pt; WIDTH: 128.55pt; HEIGHT: 171pt; VISIBILITY: visible; MARGIN-LEFT: 390.75pt; LEFT: 0px; mso-wrap-style: square; mso-wrap-distance-left: 9pt; mso-wrap-distance-top: 0; mso-wrap-distance-right: 9pt; mso-wrap-distance-bottom: 0; mso-position-horizontal: absolute; mso-position-horizontal-relative: text; mso-position-vertical: absolute; mso-position-vertical-relative: text" id=Picture_x0020_5 alt="Chicken2.JPG" o:spid="_x0000_s1027" type="#_x0000_t75"&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&lt;v:imagedata src="file:///C:\Users\MIKEDU~1.RED\AppData\Local\Temp\msohtmlclip1\01\clip_image005.jpg" o:title="Chicken2"&gt;&lt;/v:imagedata&gt;&lt;w:wrap type="square"&gt;&lt;/w:wrap&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/v:shape&gt;&lt;FONT size=3 face=Calibri&gt;&lt;A href="http://eternallyoptimistic.com/2008/03/10/dec-2008-this-ones-for-you-wook/" mce_href="http://eternallyoptimistic.com/2008/03/10/dec-2008-this-ones-for-you-wook/"&gt;2008 Winner&lt;/A&gt; (From Pam Dingle's Blog) &lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt 0.5in" class=MsoNormal&gt;&lt;A href="http://www.youtube.com/watch?v=Qdq4wC062-U&amp;amp;feature=related"&gt;&lt;FONT size=3 face=Calibri&gt;2009 Winner&lt;/FONT&gt;&lt;/A&gt;&amp;nbsp;&lt;FONT size=3 face=Calibri&gt;(From YouTube)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;v:shape style="Z-INDEX: 4; POSITION: absolute; MARGIN-TOP: 37.75pt; WIDTH: 153pt; HEIGHT: 114.75pt; VISIBILITY: visible; MARGIN-LEFT: -12.75pt; mso-wrap-style: square; mso-wrap-distance-left: 9pt; mso-wrap-distance-top: 0; mso-wrap-distance-right: 9pt; mso-wrap-distance-bottom: 0; mso-position-horizontal: absolute; mso-position-horizontal-relative: text; mso-position-vertical: absolute; mso-position-vertical-relative: text" id=Picture_x0020_8 alt="DSCN0461.JPG" o:spid="_x0000_s1026" type="#_x0000_t75"&gt;&lt;/v:shape&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Well… enough about that and on to the session that &lt;/FONT&gt;&lt;A href="http://tec2009.com/berlin/agenda/directory/speaker_bios.php#vilcinskas"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Markus&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; and I delivered.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Markus and I have presented together at the last&amp;nbsp;4 events and I’ve had a lot of fun in the process.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Markus is &lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&lt;IMG style="WIDTH: 200px; HEIGHT: 150px" title="Mike and Markus" border=10 hspace=10 alt="Mike and Markus" vspace=10 align=left src="http://0pbtsa.bay.livefilestore.com/y1pKEHL1gSpWeAd4SYJgWHHsoKPH0hKrK5miouCkwnX3rMiNNmZiKjF3dZS6-DtXwZssMG-qJ7h5-0ezmHetWcDtYx8RtCYQ7v3/DSCN0461.jpg" width=200 height=150 mce_src="http://0pbtsa.bay.livefilestore.com/y1pKEHL1gSpWeAd4SYJgWHHsoKPH0hKrK5miouCkwnX3rMiNNmZiKjF3dZS6-DtXwZssMG-qJ7h5-0ezmHetWcDtYx8RtCYQ7v3/DSCN0461.jpg"&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;deeply technical, being one of the longest standing members of the ILM&amp;nbsp;Product Team and he has a great sense of humor, which definitely comes through in his presentation style.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The session was a 300/400 level session on Declarative Provisioning (formerly called Codeless Provisioning) in Forefront Identity Manager 2010.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This session was a deep dive into how Declarative Provisioning works, which includes a bunch of new acronyms (we Micropeeps love our acronyms!).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;In the session we explained in detail how the following work and interact with each other:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Management Policy Rules (MPRs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Action Workflows (AWs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Synchronization Rule Objects (SROs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Inbound Sync Rules (ISRs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Outbound Sync Rules (OSRs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Expected Rules Lists (ERLs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Expected Rules Entries (EREs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Detected Rules Lists (DRLs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Detected Rules Entries (DREs)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In addition to giving a deep dive into how Declarative Provisioning works, we also introduced a problem space called “Object State Detection” (OSD). Object State Detection is a new feature in FIM 2010 that&amp;nbsp;enables you to document and detect specific states of an object in a connected data source and to take action based on them, allowing rules to be processed based on confirmation of the detected state. In our presentation we used as an example the states of “Enabled AD User” and “Disabled AD User” and demonstrated how to configure the system to send email notifications to a user’s manager when their state was manually changed in the connected system (in this case AD).&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This scenario implements something Markus and I termed an “Operational Outbound Sync Rule”, whose purpose is simply to define the state of the object, via an Existence Test, that you are looking to perform actions on. &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;Operational OSRs do not actually result in the flow of data to the connected data source because they are not linked to an Action Workflow; their only purpose is to define the Existence Test that will be evaluated during Inbound Synchronization in the FIM Synchronization Service.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Note: OSRs that are configured with Existence Tests are processed at the end of an Inbound Synchronization process (in the FIM Synchronization Service)&amp;nbsp;for the purpose of generating DREs.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This concept can be applied to any type of state that can be detected via an FIM MA.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;Some other examples of states that you might be interested in managing via OSD:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpFirst&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Account exists in system X (perhaps a finance application under SOX scrutiny?)&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;AD User is Mailbox Enabled&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;AD User is OCS Enabled&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpMiddle&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;RACF User has TSO Access&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 10pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraphCxSpLast&gt;&lt;SPAN style="mso-fareast-font-family: Calibri; mso-bidi-font-family: Calibri; mso-ascii-font-family: Calibri; mso-hansi-font-family: Calibri"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3 face=Calibri&gt;-&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3 face=Calibri&gt;Etc.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;The session was well received and is available &lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;here&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; for you to review. &lt;IFRAME style="BORDER-BOTTOM: #dde5e9 1px solid; BORDER-LEFT: #dde5e9 1px solid; PADDING-BOTTOM: 0px; BACKGROUND-COLOR: #ffffff; MARGIN: 3px; PADDING-LEFT: 0px; WIDTH: 220px; PADDING-RIGHT: 0px; HEIGHT: 26px; BORDER-TOP: #dde5e9 1px solid; BORDER-RIGHT: #dde5e9 1px solid; PADDING-TOP: 0px" marginHeight=0 src="http://cid-993d99f6b52174a6.skydrive.live.com/embedrow.aspx/IDA%20Guys/Declarative%20Provisioning%20Deep%20Dive.pptx" frameBorder=0 marginWidth=0 scrolling=no&gt;&lt;/IFRAME&gt;&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;This deck was not the deck used at TEC, but is a revised version that we used to present the content internally, and as such has a little more content.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Thanks for taking the time to visit The IDA Guys blog.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;If you have any questions, feel free to post them and I’ll do my best to get back to you shortly.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Have fun,&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 10pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Mike&lt;/FONT&gt;&lt;/P&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3243935" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/b/idaguys/archive/tags/Declarative+Provisioning/">Declarative Provisioning</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/Object+State+Detection/">Object State Detection</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/TEC/">TEC</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/Codeless+Provisioning/">Codeless Provisioning</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/Forefront+Identity+Manager/">Forefront Identity Manager</category><category domain="http://blogs.technet.com/b/idaguys/archive/tags/FIM/">FIM</category></item><item><title>The Experts Conference</title><link>http://blogs.technet.com/b/idaguys/archive/2009/05/14/the-experts-conference.aspx</link><pubDate>Thu, 14 May 2009 22:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3241410</guid><dc:creator>bpmohr</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3241410</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/05/14/the-experts-conference.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;In the spirit of sharing a conference experience, I wanted to create this summary.&amp;nbsp; I returned recently from &lt;/FONT&gt;&lt;A href="http://www.tec2009.com/vegas/index.php"&gt;&lt;FONT size=3 face=Calibri&gt;The Experts Conference&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3 face=Calibri&gt; (formally The Directory Experts Conference).&amp;nbsp; This conference was hosted by Netpro in the past, but is now hosted by &lt;/FONT&gt;&lt;A href="http://www.quest.com/"&gt;&lt;FONT size=3 face=Calibri&gt;Quest Software&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt; because they purchased Netpro last year.&amp;nbsp; This conference is focused on Microsoft’s directory, identity and messaging technologies and this year had tracks for ILM, Federation, AD, Exchange and Information Protection.&amp;nbsp; Personally I focused on the ILM and AD track.&amp;nbsp; Overall I will have to say this is one of the best conferences I have ever attended.&amp;nbsp; I think because it was so focused and it was small in size (~450 attendees).&amp;nbsp; The following is a quick summary of some of the breakouts that I attended:&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&lt;B&gt;&lt;U&gt;Exchange Provisioning with ILM and ILM “2”&lt;/U&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;A href="http://www.avanade.com/"&gt;&lt;FONT size=3 face=Calibri&gt;Avanade&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt; (Jeremy Palenchar &amp;amp; Andrew Weiss) provide a unique method of provisioning Exchange mailboxes that goes beyond what is capable from ILM out-of-the-box.&amp;nbsp; Only caveat is that it goes against the best practice of calling outside systems from provisioning or extension code.&amp;nbsp; Avanade have created a Web Service that performs .NET calls for Powershell and WMI to manage Exchange 2003/2007 environments.&amp;nbsp; If you are not aware, ILM will only provision a new mailbox / user.&amp;nbsp; If you want to mailbox enable an existing user, create a shared mailbox, move a mailbox or provision a mix of Exchange 2003 / 2007 on the same MA, you need to be creative.&amp;nbsp; This presentation showed how they did this using calls to a Web Service.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;&lt;B&gt;&lt;U&gt;Human Behavior&lt;/U&gt;&lt;/B&gt;&lt;U&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/U&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;This presentation was put on by our ILM product group (Andreas Kjellman and Mark Wahl) and for me was one of the best.&amp;nbsp; Within ILM 2 there are many interactions with the end user, from emails to a web portal.&amp;nbsp; They showed that we need to consider how we modify the existing defaults and templates to convey valuable communication to the users.&amp;nbsp; Here are few highlight of things to consider:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;How will the users get to the portal?&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Hide technical information from the user in the communications.&amp;nbsp; “Please contact your ILM administration.” Is not a good idea.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Install Clients silently (GINA extensions, Outlook Add-ins)&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Password Reset questions:&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Run the questions through HR and Legal&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Check out goodsecurityquestions.com&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 1in; mso-list: l0 level2 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: 'Courier New'; mso-fareast-font-family: 'Courier New'"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;o&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Avoid Facebook or MySpace questions from surveys.&amp;nbsp; They make it easy to socially engineer your users password reset questions.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT face=Calibri&gt;&lt;FONT size=3&gt;Customize the help links on the portal sites&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="TEXT-INDENT: -0.25in; MARGIN: 0in 0in 0pt 0.5in; mso-list: l0 level1 lfo1" class=MsoListParagraph&gt;&lt;SPAN style="FONT-FAMILY: Symbol; mso-fareast-font-family: Symbol; mso-bidi-font-family: Symbol"&gt;&lt;SPAN style="mso-list: Ignore"&gt;&lt;FONT size=3&gt;·&lt;/FONT&gt;&lt;SPAN style="FONT: 7pt 'Times New Roman'"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;Customize the email templates&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;U&gt;Codeless Provisioning Deep Dive&lt;/U&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;This was a wonderful presentation by Microsoft Services (Mike Dube and Markus Vilcinskas).&amp;nbsp; They went into deep details to explain and demonstrate the provisioning process in ILM “2”.&amp;nbsp; Let me tell you that it was very deep and a good refresher for me.&amp;nbsp; What I found the most interesting was the use of what they call “Operational Synchronization Rules” (OSR).&amp;nbsp; This was a rule that was evaluated on the end of an inbound synchronization.&amp;nbsp; It would allow you to determine the current state of an attribute of an already created object.&amp;nbsp; For example, if you want to determine who has a disabled account.&amp;nbsp; It would return true for those accounts and based on that, you could generate a notification via email.&amp;nbsp; Great possibilities with using OSRs.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;B style="mso-bidi-font-weight: normal"&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;*Note: Keep your eye open for a more detail post from Mike Dube next week right here.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/B&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;U&gt;ILM “2” from an IT Pro’s Perspective&lt;/U&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;This was another presentation from our ILM Product Team (Andreas Kjellman).&amp;nbsp; This presentation provided a perspective for implementing ILM “2” by using steps for planning, identifying business processes, rules and roles and how to map the processes to those rules and roles.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;U&gt;Migration Scenarios – MMS\MIIS\ILM to ILM “2”&lt;/U&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;This was a useful presentation by &lt;/FONT&gt;&lt;A href="http://www.oxfordcomputergroup.com/"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Oxford Computing Group&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; (Craig Martin) to show the simplicity of upgrading to ILM “2”.&amp;nbsp; The process is pretty straight forward if you are going from apples to apples.&amp;nbsp; But when it is time to utilize some of the improvements of ILM “2”, &lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp;&lt;/SPAN&gt;it will require more work.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;U&gt;Managing Active Directory with AD Administrative Center&lt;/U&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;This was a presentation from our product group (Ivan Lam).&amp;nbsp; This presentation was about the Windows Server 2008 R2 Administration Center.&amp;nbsp; This new management console which is similar to &lt;/FONT&gt;&lt;A href="http://www.systemtools.com/hyena/"&gt;&lt;FONT size=3 face=Calibri&gt;Hyena&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;, if you are familiar with it, does not use MMC.&amp;nbsp; It is built to use a web service that will need to be installed on a domain controller.&amp;nbsp; It uses Powershell on the back end to perform the necessary AD administrative activities.&amp;nbsp; It seems to be a really nice replacement/enhancement for ADUC.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;B&gt;&lt;U&gt;Overseeing an IDA Project&lt;/U&gt;&lt;/B&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;This presentation was from &lt;/FONT&gt;&lt;A href="http://www.oxfordcomputergroup.com/"&gt;&lt;FONT color=#0000ff size=3 face=Calibri&gt;Oxford Computing Group&lt;/FONT&gt;&lt;/A&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt; (Peter LaCrosse).&amp;nbsp; It was a good presentation on project management.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;The processes he discussed can be geared toward any project.&amp;nbsp; The presentation talked about such things as learning the cultural differences for international projects and defining the frequency of communication.&amp;nbsp; It also pointed to Gartner’s latest communication that companies will start to need faster ROI.&amp;nbsp; The presenter stated that Gartner is saying the companies will expect to see ROI in less than twelve months.&amp;nbsp; This will be a difficult task for large projects that last beyond twelve months.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;If you work in this field, I suggest you make it a point to attend one of these conferences in the future.&lt;SPAN style="mso-spacerun: yes"&gt;&amp;nbsp; &lt;/SPAN&gt;It is well worth the information and networking you will receive.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3241410" width="1" height="1"&gt;</description></item><item><title>Welcome to the IDA Guys TechNet Blog</title><link>http://blogs.technet.com/b/idaguys/archive/2009/04/21/welcome-to-the-idm-guys-technet-blog.aspx</link><pubDate>Tue, 21 Apr 2009 15:50:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3228778</guid><dc:creator>johnmcg</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.technet.com/b/idaguys/rsscomments.aspx?WeblogPostID=3228778</wfw:commentRss><comments>http://blogs.technet.com/b/idaguys/archive/2009/04/21/welcome-to-the-idm-guys-technet-blog.aspx#comments</comments><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;FONT size=3 face=Calibri&gt;We are launching this blog to bring you "on-the-street news", experiences and ideas about the Identity Management products from Microsoft that we live and breathe every day.&amp;nbsp; &amp;nbsp;The IDA Guys are made up of Identity Management experts&amp;nbsp;from the Microsoft Technical Field.&amp;nbsp; &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;FONT size=3 face=Calibri&gt;Let us start this out with some good news.&amp;nbsp; Identity Lifecycle Manager “2” has now been branded &lt;B&gt;&lt;A href="http://www.microsoft.com/forefront/en/us/identity-manager.aspx" mce_href="http://www.microsoft.com/forefront/en/us/identity-manager.aspx"&gt;Forefront &amp;nbsp;Identity Manager 2010&lt;/A&gt;&lt;/B&gt;&lt;/FONT&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;.&amp;nbsp;&amp;nbsp; We will be releasing a new release candidate(RC1) in Q3 (approximately July).&amp;nbsp; The product group responsible for Forefront Identity Manager, based on customer feedback from early adopters both in the public and private sector and including our own internal Microsoft IT (MSIT), want to make sure that the next version is easier for customers to deploy and use.&amp;nbsp; They also wanted to fulfill requests made&amp;nbsp;by current TAP and RDP&amp;nbsp;customers that include tools and strong documentation available for the release of the product.&amp;nbsp; Believe us, these will be good things to have when it comes time to deploy the new product.&amp;nbsp; The current schedule for RTM is Q1 CY2010. &lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;SPAN style="COLOR: #1f497d"&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;&lt;SPAN style="COLOR: #1f497d"&gt;Again, welcome to this new blog.&amp;nbsp; W&lt;/SPAN&gt;&lt;SPAN style="COLOR: black"&gt;e&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d"&gt; look forward to bringing you&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style="COLOR: #1f497d"&gt;regular updates that will help you to deploy the various Identity Management products that Microsoft develops.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3228778" width="1" height="1"&gt;</description></item></channel></rss>