Tag Archives: AD

How can I logon to my ADAM or AD LDS Management Agent (MA)?

What credentials can I use for the Active Directory Application Mode (ADAM) or Active Directory Lightweight Directory Services (AD LDS) Management Agent (MA) in Forefront Identity Manager (FIM) 2010 or R2? Bit basic this post but I had to install … Continue reading

Posted in FIM | Tagged , , , , , , , , | Leave a comment

How to use Sort Keys in LDP

I knocked up an example PowerShell one liner for a colleague to get the oldest item in the Deleted Objects container because of a need to identify the default tombstone lifetime (i.e. when there’s no value on the nTDSService object’s … Continue reading

Posted in Active Directory, Scripting | Tagged , , , , , , | Leave a comment

Delegating the minimum set of permissions for mailbox-enabled user and linked mailbox provisioning

In my previous post I described the minimum set of permissions required by the ADMA account to provision an AD DS user object.  In this post I’d like to expand on that and provide the minimum set of permissions required … Continue reading

Posted in FIM, Active Directory, FIM 2010 R2, FIM 2010 | Tagged , , , , , , , , , , , , , , , , , , , | 2 Comments

Delegating the minimum set of permissions for user provisioning

The purpose of this post is to provide information on the permissions required by the user account that the Active Directory Domain Services (AD DS) Management Agent (MA) or ADMA uses when it interfaces with an AD domain.  I’ve seen … Continue reading

Posted in Active Directory, FIM, FIM 2010, FIM 2010 R2 | Tagged , , , , , , , , , , , , , , , | 2 Comments

exported-change-not-reimported error when provisioning a linked mailbox

When provisioning a linked-mailbox using Forefront Identity Manager (FIM) 2010, Identity Lifecycle Manager (ILM) 2007 or Identity Integration Server (MIIS) 2003 the Active Directory Management Agent (ADMA) throws an exported-change-not-reimported error for each new mailbox-enabled user. Upon closer inspection you … Continue reading

Posted in Active Directory, FIM, FIM 2010 | Tagged , , , , , , , , , , , , , , , | 2 Comments

Resetting an AD DS password and honouring password history and age using the LDAP_SERVER_POLICY_HINTS control

I recently had to do some frantic experimenting around the area of password reset. I was working with a customer on a convoluted solution that necessitated a password synchronisation operation from the DMZ into a production network without a trust. … Continue reading

Posted in Active Directory, Programming | Tagged , , , , , , , , | 6 Comments