<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Identity Managed</title>
    <link>https://identitymanaged.com/</link>
    <description>Recent content on Identity Managed</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <managingEditor>david@identitymanaged.com (David)</managingEditor>
    <webMaster>david@identitymanaged.com (David)</webMaster>
    <lastBuildDate>Wed, 01 Oct 2025 22:41:06 +0000</lastBuildDate>
    <atom:link href="https://identitymanaged.com/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Custom Attributes in Entra ID -- Decision Tree</title>
      <link>https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/</link>
      <pubDate>Wed, 01 Oct 2025 22:41:06 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/all-the-doors-together2.jpg&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This article is the eighth in a series about Custom Attributes in Entra ID and will step through the decision tree which I hope will be the definitive guide to which way to store custom data in Entra ID.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/#names-and-aliases&#34;&gt;Names and aliases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/&#34;&gt;N﻿aming Conventions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/&#34;&gt;R﻿esource Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/&#34;&gt;D﻿ata Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/&#34;&gt;L﻿ifecycle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/&#34;&gt;L﻿imitations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/&#34;&gt;U﻿se Cases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/&#34;&gt;Decision Tree&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/entra-id-custom-attribute-decision-tree.png&#34; alt=&#34;&#34; title=&#34;Entra ID Custom Attribute Decision Tree&#34;&gt;&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;strong&gt;I﻿s this custom data intended for Enterprise Applications or Managed Identities (both of which are of the &lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/servicePrincipal?view=graph-rest-1.0&#34;&gt;servicePrincipal resource type&lt;/a&gt;)?&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;If &amp;ldquo;Yes,&amp;rdquo; then you must use &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview&#34;&gt;Custom Security Attributes&lt;/a&gt; &amp;ndash; this is the only way to &lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-filter-for-applications&#34;&gt;filter on Applications in Conditional Access Policies&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Custom Attributes in Entra ID -- Use Cases</title>
      <link>https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/</link>
      <pubDate>Wed, 01 Oct 2025 03:46:51 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/entraidcustomattributes_usecases_small.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This article is the seventh in a series about Custom Attributes in Entra ID and will discuss the use cases of each these approaches. There are seven use cases that have only one solution, three exclusive use cases for Extension Attributes, three exclusive for Custom Security Attributes and one for Directory Extensions.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/#names-and-aliases&#34;&gt;Names and aliases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/&#34;&gt;N﻿aming Conventions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/&#34;&gt;R﻿esource Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/&#34;&gt;D﻿ata Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/&#34;&gt;L﻿ifecycle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/&#34;&gt;L﻿imitations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/&#34;&gt;U﻿se Cases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/&#34;&gt;Decision Tree&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Use Cases&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#extension-attributes&#34;&gt;Extension attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#directory-microsoft-entra-id-extensions&#34;&gt;Directory Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#schema-extensions&#34;&gt;Schema Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#open-extensions&#34;&gt;Open Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview&#34;&gt;Custom Security Attributes&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/add-properties-profilecard&#34;&gt;Visible on Profile Card&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y (﻿Exclusive)&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/exchange/recipients-in-exchange-online/manage-dynamic-distribution-groups/create-manage-dynamic-distribution-groups?source=recommendations&amp;amp;tabs=create-new-eac%2Ccreate-new-eac-2%2Ccreate-new-eac-3&#34;&gt;Exchange Dynamic Groups&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/powershell/exchange/recipientfilter-properties?view=exchange-ps&#34;&gt;Y&lt;/a&gt; (﻿Exclusive)&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership#extension-attributes-and-custom-extension-properties&#34;&gt;Group Dynamic Membership Rule&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/admin-units-members-dynamic&#34;&gt;Administrative Unit Dynamic Membership rule&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/app-provisioning/inbound-provisioning-api-configure-app#configure-api-driven-inbound-provisioning-to-microsoft-entra-id&#34;&gt;Inbound Cloud Provisioning&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/app-provisioning/customize-application-attributes#editing-the-list-of-supported-attributes&#34;&gt;Y&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/app-provisioning/customize-application-attributes&#34;&gt;Cloud User App Provisioning&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/app-provisioning/define-conditional-rules-for-provisioning-user-accounts?pivots=app-provisioning&#34;&gt;User App Provisioning Filtering&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sync-feature-directory-extensions&#34;&gt;On Premise Sync&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/multi-tenant-organizations/cross-tenant-synchronization-overview#attributes&#34;&gt;Cross Tenant Sync&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity-platform/optional-claims?tabs=appui#configure-directory-extension-optional-claims&#34;&gt;Customized Token Claims&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://goodworkaround.com/2024/10/14/issuing-custom-security-attributes-in-entra-id-tokens/&#34;&gt;N**&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/domain-services/concepts-custom-attributes&#34;&gt;Entra ID DS&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/aad-advanced-queries?tabs=http#user-properties&#34;&gt;Graph Filterable&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#developer-experience&#34;&gt;Y&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/aad-advanced-queries?tabs=http#user-properties&#34;&gt;Y&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-schema-groups?tabs=http#step-5-get-a-group-and-its-extension-data&#34;&gt;Y&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/aad-advanced-queries?tabs=http#user-properties:~:text=shows%20support%20for%20%24filter%20by%20other%20extension%20properties%20on%20the%20user%20object&#34;&gt;N&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/custom-security-attributes-examples?tabs=http#example-3-list-all-users-with-a-custom-security-attribute-assignment-that-starts-with-a-value&#34;&gt;Y&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/azure/active-directory-b2c/user-flow-custom-attributes&#34;&gt;Azure B2C&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N﻿&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/external-id/user-flow-add-custom-attributes&#34;&gt;External ID Custom User Attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y (﻿Exclusive)&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview#how-do-custom-security-attributes-compare-with-extensions&#34;&gt;Restricted Access/Sensitive Data&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y (﻿Exclusive)&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-filter-for-applications&#34;&gt;Conditional Access Filter on Enterprise Applications&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y (﻿Exclusive)&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-condition-filters-for-devices#supported-operators-and-device-properties-for-filters&#34;&gt;Conditional Access Filter on Devices&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y (﻿Exclusive)&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/users/groups-dynamic-membership#extension-attributes-and-custom-extension-properties&#34;&gt;Conditional Access Filter on Users and Groups (via Dynamic Group Membership)&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-add?tabs=ms-powershell#add-an-attribute-set&#34;&gt;UI to manage the customizations&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/identity/hybrid/connect/how-to-connect-sync-feature-directory-extensions&#34;&gt;N*&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/azure/role-based-access-control/conditions-overview#status-of-condition-features&#34;&gt;Azure ABAC&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y (﻿Exclusive)&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/identitygovernance-rulebasedsubjectset?view=graph-rest-1.0&#34;&gt;Lifecycle Workflows: Scope Filter&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/id-governance/lifecycle-workflow-execution-conditions#attribute-change-trigger&#34;&gt;Lifecycle Workflows: Trigger Attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/attributerulemembers?view=graph-rest-1.0&#34;&gt;Access package assignment Policy&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;h2 id=&#34;my-default-answer-use-a-directory-extension-unless-you-cant&#34;&gt;M﻿y d﻿efault answer: use a Directory Extension unless you can&amp;rsquo;t!&lt;/h2&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;T﻿hey cover most use cases&lt;/p&gt;</description>
    </item>
    <item>
      <title>Custom Attributes in Entra ID -- Limitations</title>
      <link>https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/</link>
      <pubDate>Wed, 01 Oct 2025 02:27:11 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/all-the-doors-together2.jpg&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This article is the sixth in a series about Custom Attributes in Entra ID and will discuss the Limitations of each these approaches.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/#names-and-aliases&#34;&gt;Names and aliases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/&#34;&gt;N﻿aming Conventions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/&#34;&gt;R﻿esource Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/&#34;&gt;D﻿ata Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/&#34;&gt;L﻿ifecycle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/&#34;&gt;L﻿imitations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/&#34;&gt;U﻿se Cases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/&#34;&gt;Decision Tree&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Limitation&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#extension-attributes&#34;&gt;Extension attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#directory-microsoft-entra-id-extensions&#34;&gt;Directory Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#schema-extensions&#34;&gt;Schema Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#open-extensions&#34;&gt;Open Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview&#34;&gt;Custom Security Attributes&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Needs an App to own it&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N but an App must create it&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Values Per Resource&lt;/td&gt;&#xA;          &lt;td&gt;15&lt;/td&gt;&#xA;          &lt;td&gt;100&lt;/td&gt;&#xA;          &lt;td&gt;100&lt;/td&gt;&#xA;          &lt;td&gt;2 kb of data&lt;/td&gt;&#xA;          &lt;td&gt;50&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Per App&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;5 definitions&lt;/td&gt;&#xA;          &lt;td&gt;2 extensions&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Per Tenant&lt;/td&gt;&#xA;          &lt;td&gt;15&lt;/td&gt;&#xA;          &lt;td&gt;Infinte&lt;/td&gt;&#xA;          &lt;td&gt;Infinte&lt;/td&gt;&#xA;          &lt;td&gt;Infinte&lt;/td&gt;&#xA;          &lt;td&gt;500&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Schema can be shared&lt;/td&gt;&#xA;          &lt;td&gt;Built in to every tenant&lt;/td&gt;&#xA;          &lt;td&gt;If other tenants install your mult-tenant app&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-schema-groups?tabs=http#step-1-view-available-schema-extensions&#34;&gt;Discoverable Globally&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can exist on Synced User&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Must Manage on Prem for Synced User&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N*&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;*﻿No, except for Directory extensions from the &amp;ldquo;Tenant Schema Extension App&amp;rdquo; used by Entra ID Connect Sync and Cloud Sync.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Custom Attributes in Entra ID -- Lifecycle</title>
      <link>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/</link>
      <pubDate>Sat, 27 Sep 2025 00:11:34 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/entraidcustomattributes_lifecycles_small.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This article is the fifth in a series about Custom Attributes in Entra ID and will discuss the Lifecycle of each of these approaches.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/#names-and-aliases&#34;&gt;Names and aliases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/&#34;&gt;N﻿aming Conventions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/&#34;&gt;R﻿esource Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/&#34;&gt;D﻿ata Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/&#34;&gt;L﻿ifecycle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/&#34;&gt;L﻿imitations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/&#34;&gt;U﻿se Cases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/&#34;&gt;Decision Tree&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Lifecycle Question&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#extension-attributes&#34;&gt;Extension attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#directory-microsoft-entra-id-extensions&#34;&gt;Directory Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#schema-extensions&#34;&gt;Schema Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#open-extensions&#34;&gt;Open Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview&#34;&gt;Custom Security Attributes&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Has Lifecycle States?&lt;/td&gt;&#xA;          &lt;td&gt;No(﻿always there)&lt;/td&gt;&#xA;          &lt;td&gt;No(﻿there and not there)&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Yes (﻿InDevelopment, Available, Deprecated)&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;No(﻿never there)&lt;/td&gt;&#xA;          &lt;td&gt;Yes(﻿Active,Deactivated)&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can other apps in the same tenant discover the extensions definitions?&lt;/td&gt;&#xA;          &lt;td&gt;Yes (same in every tenant)&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Yes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;No defintions to discover&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview#custom-security-attribute-roles&#34;&gt;Only with the Attribute Definition roles&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can other apps in same Tenant read the data (If app has read permissions to the resource)?&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Yes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview#custom-security-attribute-roles&#34;&gt;Only with Attribute Assignment Roles&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can other apps in same Tenant write the data (If app has write permissions to the resource)?&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Yes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview#custom-security-attribute-roles&#34;&gt;Only with Attribute Assignment Roles&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can defintions be shared with or discovered by other tenants?&lt;/td&gt;&#xA;          &lt;td&gt;They already are&lt;/td&gt;&#xA;          &lt;td&gt;If app is Multi-Tenant and gets installed&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Once the Schema Extension is in Available State&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can the extension be deleted?&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Only when in the InDevelopment State&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A (there are no definitions)&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-add?tabs=ms-powershell#frequently-asked-questions&#34;&gt;No&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can be deactivated or deprecated?&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Yes  &lt;!-- raw HTML omitted --&gt;(deprecated)&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-add?tabs=ms-powershell#frequently-asked-questions&#34;&gt;Yes  &lt;!-- raw HTML omitted --&gt;(deactivated)&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Deletion of owning App&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the definitions?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview#considerations-for-using-directory-extensions&#34;&gt;Deletes the Extensions Definition&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#considerations-for-using-schema-extensions&#34;&gt;Not deleted  but no longer updateable&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#considerations-for-using-open-extensions&#34;&gt;Deleting the Creator app has no impact&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the definitions in other tenants?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;Nothing &amp;ndash; other tenants could not update the definitions anyhow&lt;/td&gt;&#xA;          &lt;td&gt;Nothing &amp;ndash; other tenants could not update the definitions anyhow&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the data?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview#considerations-for-using-directory-extensions&#34;&gt;Makes it undiscoverable&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#considerations-for-using-schema-extensions&#34;&gt;All properties and values are still discoverable&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#considerations-for-using-open-extensions&#34;&gt;Deleting the Creator app has no impact&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the data in other tenants?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;None&lt;/td&gt;&#xA;          &lt;td&gt;None&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can the extension be deleted?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;Yes&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Only when in the InDevelopment State&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A (there are no definitions)&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-add?tabs=ms-powershell#frequently-asked-questions&#34;&gt;No&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the definitions?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview#considerations-for-using-directory-extensions&#34;&gt;Deletes the Extensions Definition&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#considerations-for-using-schema-extensions&#34;&gt;Definition deleted and undiscoverable&lt;/a&gt;[[1]](#_msocom_1)&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the definitions in other tenants?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;Nothing &amp;ndash; other tenants could not update the definitions anyhow&lt;/td&gt;&#xA;          &lt;td&gt;N/A (can&amp;rsquo;t delete when shared)&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the data?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview#considerations-for-using-directory-extensions&#34;&gt;Makes it undiscoverable&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#considerations-for-using-schema-extensions&#34;&gt;Makes it undiscoverable&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the data in other tenants?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;Nothing&lt;/td&gt;&#xA;          &lt;td&gt;N/A (can&amp;rsquo;t delete when shared)&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Can the extension be deactivated or deprecated?&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Yes  &lt;!-- raw HTML omitted --&gt;(deprecated)  &lt;!-- raw HTML omitted --&gt;extension can no longer be read or modified&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;No&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-add?tabs=ms-powershell#frequently-asked-questions&#34;&gt;Yes  &lt;!-- raw HTML omitted --&gt;(deactivated)  &lt;!-- raw HTML omitted --&gt;Can no longer be applied&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Effect on other tenants?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;extension can no longer be read or modified&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;What happens to the data when the Extension is deprecated or deactivated?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;﻿N/﻿A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Can read, update and delete existing property values&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-add#frequently-asked-questions&#34;&gt;*Data is preserved  &lt;!-- raw HTML omitted --&gt;* Can no longer be applied to resources&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Effect on other tenants?&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;﻿N/﻿A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#schema-extensions-lifecycle&#34;&gt;Can read, update and delete existing property values&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Data in Undiscoverable/Deactivated count against limits&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#considerations-for-using-directory-extensions&#34;&gt;Yes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#considerations-for-using-schema-extensions&#34;&gt;Probably&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N/A&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-add#frequently-asked-questions&#34;&gt;Yes&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/custom-security-attributes-vault-door-small.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Custom Attributes in Entra ID -- Data Types</title>
      <link>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/</link>
      <pubDate>Fri, 26 Sep 2025 23:57:15 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/all-the-doors-together2.jpg&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/entra-custom-attribute-data-types_small.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This article is the fourth in a series about Custom Attributes in Entra ID and will discuss the Data Types that each of these approaches can use.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/#names-and-aliases&#34;&gt;Names and aliases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/&#34;&gt;N﻿aming Conventions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/&#34;&gt;R﻿esource Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/&#34;&gt;D﻿ata Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/&#34;&gt;L﻿ifecycle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/&#34;&gt;L﻿imitations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/&#34;&gt;U﻿se Cases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/&#34;&gt;Decision Tree&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Resource Types&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#extension-attributes&#34;&gt;Extension attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#directory-microsoft-entra-id-extensions&#34;&gt;Directory Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#schema-extensions&#34;&gt;Schema Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#open-extensions&#34;&gt;Open Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview&#34;&gt;Custom Security Attributes&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/extensionproperty?view=graph-rest-1.0#properties&#34;&gt;String&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/extensionproperty?view=graph-rest-1.0#properties&#34;&gt;256 characters&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;64 Characters&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/extensionproperty?view=graph-rest-1.0#properties&#34;&gt;Binary&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/extensionproperty?view=graph-rest-1.0#properties&#34;&gt;Boolean&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/extensionproperty?view=graph-rest-1.0#properties&#34;&gt;DateTime&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/extensionproperty?view=graph-rest-1.0#properties&#34;&gt;Integer&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/extensionproperty?view=graph-rest-1.0#properties&#34;&gt;LargeInteger&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/extensionschemaproperty?view=graph-rest-1.0#supported-property-data-types&#34;&gt;N&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Multi-valued Attributes&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Strongly Typed&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;h2 id=&#34;going-beyond-single-valued-strings&#34;&gt;G﻿oing beyond single valued strings&lt;/h2&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/extensionattributes_datatypes_small.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Custom Attributes in Entra ID -- R﻿esource Types</title>
      <link>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/</link>
      <pubDate>Fri, 26 Sep 2025 21:03:55 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/all-together.png_resourcetypes.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This article is the third in a series about Custom Attributes in Entra ID and will discuss the Resource Types that each of these approaches can use.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/#names-and-aliases&#34;&gt;Names and aliases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/&#34;&gt;N﻿aming Conventions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/&#34;&gt;R﻿esource Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/&#34;&gt;D﻿ata Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/&#34;&gt;L﻿ifecycle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/&#34;&gt;L﻿imitations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/&#34;&gt;U﻿se Cases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/&#34;&gt;Decision Tree&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Resource Types&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#extension-attributes&#34;&gt;Extension attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#directory-microsoft-entra-id-extensions&#34;&gt;Directory Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#schema-extensions&#34;&gt;Schema Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#open-extensions&#34;&gt;Open Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview&#34;&gt;Custom Security Attributes&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/servicePrincipal?view=graph-rest-1.0&#34;&gt;servicePrincipal&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/user?view=graph-rest-1.0&#34;&gt;user&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/device?view=graph-rest-1.0&#34;&gt;device&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/group?view=graph-rest-1.0&#34;&gt;group&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/administrativeunit?view=graph-rest-1.0&#34;&gt;administrative unit&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/application?view=graph-rest-1.0&#34;&gt;application&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/organization?view=graph-rest-1.0&#34;&gt;organization&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/contact?view=graph-rest-1.0&#34;&gt;contact&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/event?view=graph-rest-1.0&#34;&gt;event&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/message?view=graph-rest-1.0&#34;&gt;message&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/post?view=graph-rest-1.0&#34;&gt;post&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/todoTask?view=graph-rest-1.0&#34;&gt;todoTask&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/todoTaskList?view=graph-rest-1.0&#34;&gt;todoTaskList&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;          &lt;td&gt;Y&lt;/td&gt;&#xA;          &lt;td&gt;N&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;R﻿ight away it should be noted that contact resources are personal contacts not the Organization contacts &lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/orgcontact?view=graph-rest-1.0&#34;&gt;(orgContact)&lt;/a&gt; that are maintained by the org&amp;rsquo;s admins. Contact resources are Outlook Items (or resources) and not directory resources. orgContact is a directory resource type. You can tell because in the doc it says, &amp;ldquo;Inherits from directoryObject.&amp;rdquo; In other words contacts are visible for a particular user and not to the organization. Whereas orgContact resources are visible for the entire organization through the Global Address List.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Custom Attributes in Entra ID -- N﻿aming Conventions</title>
      <link>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/</link>
      <pubDate>Fri, 26 Sep 2025 20:20:33 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/</guid>
      <description>&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/all-the-doors-together2.jpg&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/entra-id-attribute-naming-conventions_small.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This article is the second in a series about Custom Attributes in Entra ID and will discuss the N﻿aming Conventions so that you can recognize them when you see them in the wild and understand how uniqueness is enforced and guaranteed.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/#names-and-aliases&#34;&gt;Names and aliases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-naming-conventions/&#34;&gt;N﻿aming Conventions&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-resource-types/&#34;&gt;R﻿esource Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-data-types/&#34;&gt;D﻿ata Types&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id-lifecycle/&#34;&gt;L﻿ifecycle&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-limitations/&#34;&gt;L﻿imitations&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-use-cases/&#34;&gt;U﻿se Cases&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://identitymanaged.com/blog/2025/10/custom-attributes-in-entra-id-decision-tree/&#34;&gt;Decision Tree&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;          &lt;th&gt;&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Names&lt;/td&gt;&#xA;          &lt;td&gt;Name or ID&lt;/td&gt;&#xA;          &lt;td&gt;Example&lt;/td&gt;&#xA;          &lt;td&gt;Notes&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#extension-attributes&#34;&gt;Extension attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/onpremisesextensionattributes?view=graph-rest-1.0&#34;&gt;extensionAttribute1 .. extensionAttribute15&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;extensionAttribute15&lt;/td&gt;&#xA;          &lt;td&gt;The names are already pre-determined&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#directory-microsoft-entra-id-extensions&#34;&gt;Directory Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;extension_ {ApplicationId}_attributeName&lt;/td&gt;&#xA;          &lt;td&gt;extension_ 4b2af6e7f3ac4f598e35c364e0126c6d _MgrLvl&lt;/td&gt;&#xA;          &lt;td&gt;The Application ID or Client ID (not the object ID of the Application)&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#schema-extensions&#34;&gt;Schema Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/schemaextension?view=graph-rest-1.0#properties&#34;&gt;verifiedVanityDomain&lt;em&gt;extensionID  &lt;!-- raw HTML omitted --&gt;OR  &lt;!-- raw HTML omitted --&gt;ext{﻿8-random-alphanumeric-chars}&lt;/em&gt;{﻿schema-name}&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;snappyslackers_coordinates  &lt;!-- raw HTML omitted --&gt;OR  &lt;!-- raw HTML omitted --&gt;extwmo14pts_coordinates&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-schema-groups?tabs=http#step-2-register-a-schema-extension-definition&#34;&gt;You can choose between using the verified Vanity Domain Name or allowing EntraID to generate a random prefix for you&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#open-extensions&#34;&gt;Open Extensions&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/opentypeextension?view=graph-rest-1.0&#34;&gt;ReverseFQDN.extensionName&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;com.snappyslackers.coordinates&lt;/td&gt;&#xA;          &lt;td&gt;It looks like this is an unenforced convention&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview&#34;&gt;Custom Security Attributes&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/graph/api/resources/customsecurityattributedefinition?view=graph-rest-1.0#properties&#34;&gt;&amp;lt;AttributeSetName_AttributeName&amp;gt;&lt;/a&gt;&lt;/td&gt;&#xA;          &lt;td&gt;HR_MgrLvl&lt;/td&gt;&#xA;          &lt;td&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/entra/fundamentals/custom-security-attributes-overview#limits-and-constraints&#34;&gt;Both the AttributeSetName and the AttributeName can be up to 32 Unicode Characters with neither spaces nor specials characters.  &lt;!-- raw HTML omitted --&gt;AttributeName must be unique within its Attribute set, which in turn must be unique within the tenant.&lt;/a&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;h2 id=&#34;extension-attributes&#34;&gt;Extension Attributes&lt;/h2&gt;&#xA;&lt;p&gt;Y﻿ou do not get to choose the names of the Extension Attributes as they are predetermined and fixed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Custom Attributes in Entra ID</title>
      <link>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/</link>
      <pubDate>Fri, 26 Sep 2025 06:41:28 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/09/custom-attributes-in-entra-id/</guid>
      <description>&lt;p&gt;Microsoft has had a lot of chefs in the Entra ID kitchen baking up solutions to different problems and now we have an array of confusing choices about where to put your data.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/all-the-doors-together2.jpg&#34; alt=&#34;&#34; title=&#34;The 5 doors of Entra ID Custom Data&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;This is the first of a series of posts to help you choose the correct one for you and your needs.&lt;/p&gt;&#xA;&lt;p&gt;While Microsoft&amp;rsquo;s official documentation provides a &lt;a href=&#34;https://learn.microsoft.com/en-us/graph/extensibility-overview?tabs=http#comparison-of-extension-types&#34;&gt;fairly handy comparison table&lt;/a&gt; it &lt;strong&gt;completely leaves out Custom Security Attributes&lt;/strong&gt;. Overall, I find that there are some gaps, and a couple of contradictions but not a definitive guide to help you know when to use which extension.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cross Tenant Sync for GalSync?</title>
      <link>https://identitymanaged.com/blog/2025/04/cross-tenant-sync-for-galsync/</link>
      <pubDate>Fri, 04 Apr 2025 22:18:27 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2025/04/cross-tenant-sync-for-galsync/</guid>
      <description>&lt;p&gt;Microsoft Entra ID&amp;rsquo;s Cross Tenant Sync can sync users from one tenant to another.  They will sync as External Members or External Guests. In Exchange Admin they will show as MailUsers.&lt;/p&gt;&#xA;&lt;p&gt;Just be sure that showInAddressList is synced to be true or better yet carries over the showInAddressList from your source tenant.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;GalSync done! Yeah!&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Wait a minute! What about Groups? What about contacts? What about internal guests?&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;N﻿O! They are not supported&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIMWAL Can run PowerShell 3.0 and beyond without PSRemoting or Start-Process!</title>
      <link>https://identitymanaged.com/blog/2024/06/mimwal-can-run-powershell-3-0-and-beyond-without-psremoting-or-start-process/</link>
      <pubDate>Fri, 07 Jun 2024 17:11:48 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2024/06/mimwal-can-run-powershell-3-0-and-beyond-without-psremoting-or-start-process/</guid>
      <description>&lt;p&gt;I﻿ just discovered that a colleague had several years prior managed to get MIMWAL PowerShell Activity to run Get-ADUser and other commandlets from the Active Directory Module (which requires PowerShell 3.0 or later) without  using PowerShell Remoting or starting a new Process with Start-Process.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;&amp;lt;﻿Caution&amp;gt; Per &lt;a href=&#34;https://www.facebook.com/groups/155109068156/user/100005144859467/?__cft__%5B0%5D=AZU68Ki5NtCqdDbhcJmXXMYH8jS70-NO2zLap5YaNYuaOFl7mzJBGdzi89MwYPFF35dsLKgj4OXk-RZp700DisXsm3m0EluUUkEhoxsHvnNh0JbeaaLM7l1s_dz3Ck5kA2LYKOc-unW9KRmyS-C4M-_TtwyYi102Ov6RG-aWYRFUCA6k1iSfK6KR6iDFe3BtO7lQLN-Q2NEHN_B3EctAZBIE&amp;amp;__tn__=R%5D-R&#34;&gt;Eugene Sergeev&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;This breaks SSPR AuthN workflows.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;&lt;strong&gt;&amp;lt;﻿/Caution&amp;gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;S﻿o if you aren&amp;rsquo;t using SSPR through MIM this might be an option for you!&lt;/p&gt;&#xA;&lt;p&gt;According to the &lt;a href=&#34;https://github.com/Microsoft/MIMWAL/wiki/Run-PowerShell-Script-Activity&#34;&gt;MIMWAL Wiki&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>SSL v TLS with EntraID Sync and MIM&#39;s Generic LDAP Connector</title>
      <link>https://identitymanaged.com/blog/2024/04/ssl-v-tls-with-entraid-sync-and-mims-generic-ldap-connector/</link>
      <pubDate>Thu, 11 Apr 2024 05:53:35 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2024/04/ssl-v-tls-with-entraid-sync-and-mims-generic-ldap-connector/</guid>
      <description>&lt;p&gt;Everyone knows that SSL is vulnerable and we should therefore use TLS. What isn&amp;rsquo;t well understood is the options presented for Binding (authentication) when using the Generic LDAP Connector with AADConnect or the Generic LDAP ECMA 2.x  with MIM.&lt;/p&gt;&#xA;&lt;p&gt;We are presented 5 options:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Anonymous&lt;/li&gt;&#xA;&lt;li&gt;Basic&lt;/li&gt;&#xA;&lt;li&gt;Kerberos&lt;/li&gt;&#xA;&lt;li&gt;SSL&lt;/li&gt;&#xA;&lt;li&gt;TLS&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/tls-authentication-options.png&#34; alt=&#34;Generic LDAP Authentication Options&#34; title=&#34;Generic LDAP Authentication Options&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;When we tested we could get the SSL option to work over port 636, and we could get the TLS option to work on port 389 but we couldn&amp;rsquo;t get the TLS option to work over port 636. Using a protocol analyzer we confirmed that both ways were using TLS 1.2.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What does MIM&#39;s StoreChk.exe do?</title>
      <link>https://identitymanaged.com/blog/2024/03/what-does-mims-storechk-exe-do/</link>
      <pubDate>Fri, 29 Mar 2024 00:13:51 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2024/03/what-does-mims-storechk-exe-do/</guid>
      <description>&lt;p&gt;I﻿ watched through SQL Profiler to better understand what these checks do, and I found an error with check #10. It says it is &amp;ldquo;Checking Lineage Guid table for MV objects with invalid MV object ids&amp;rdquo; but the SQL query it issues is the same as the query for Check # 9 &amp;ldquo;Checking Lineage Date table for MV objects with invalid MV object ids.&amp;rdquo; It queries the Lineate Date table instead of the Lineage GUID table like it says.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIM StoreChk.exe Assumes SQL is Local</title>
      <link>https://identitymanaged.com/blog/2024/03/mim-storechk-exe-assumes-sql-is-local/</link>
      <pubDate>Thu, 28 Mar 2024 18:55:15 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/blog/2024/03/mim-storechk-exe-assumes-sql-is-local/</guid>
      <description>&lt;p&gt;On occasion you (usually with the help of PSS &amp;ndash; Product Support Services) may need to verify the integrity of the MIM Synchronization Service Database. To do this you can use the Store Check tool, StoreChk.exe located in the bin folder under the root of your MIM Synchronization install.&lt;/p&gt;&#xA;&lt;p&gt;W﻿hile the storechk tool does read the registry to find the name of the database (almost always is FIMSynchronizationService) it does not read the Server or Instance name registry values in the parameters key of the registry. Instead it defaults to assume that the SQL Server is co-located on the same machine as MIM Sync.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Always On Availability Groups for MIM</title>
      <link>https://identitymanaged.com/2022/04/sql-always-on-availability-groups-for.html</link>
      <pubDate>Tue, 26 Apr 2022 14:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2022/04/sql-always-on-availability-groups-for.html</guid>
      <description>&lt;p&gt;Image from: &lt;a href=&#34;https://learn.microsoft.com/en-us/azure/azure-sql/virtual-machines/windows/availability-group-overview&#34;&gt;https://learn.microsoft.com/en-us/azure/azure-sql/virtual-machines/windows/availability-group-overview&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Edited July 2 2022 after reviewing my Facebook discussion with Eugene Sergeev on Microsoft&amp;rsquo;s product team.&lt;/p&gt;&#xA;&lt;p&gt;MIM 2016 SP2 (and 4.4.1459.0 or later &lt;a href=&#34;https://support.microsoft.com/en-us/help/3200896/sql-server-availability-solutions-for-microsoft-identity-manager-servi&#34;&gt;supports SQL Server Always On Availability Groups&lt;/a&gt; (AG))! Yeah!&lt;/p&gt;&#xA;&lt;p&gt;Ok let&amp;rsquo;s implement it!&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;But wait!&lt;/strong&gt; It won&amp;rsquo;t give us all we hope for!&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Up to the moment distributed backup of the data &amp;ndash; yes!&lt;/li&gt;&#xA;&lt;li&gt;Automatic instant failover &amp;ndash; not without a huge caveat!&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;What do you mean it won&amp;rsquo;t give us Automatic Instant Failover?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Wanted: Up and coming Cyber Security Professionals</title>
      <link>https://identitymanaged.com/2020/06/wanted-up-and-coming-cyber-security.html</link>
      <pubDate>Thu, 18 Jun 2020 16:36:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2020/06/wanted-up-and-coming-cyber-security.html</guid>
      <description>&lt;p&gt;Cyber Security &amp;ndash; Identity Management Implementer&lt;/p&gt;&#xA;&lt;p&gt;Secure your identities against the dangers of the Cyber World, automate the repetitive, and empower your users!&lt;/p&gt;&#xA;&lt;p&gt;Let&amp;rsquo;s&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Shut the front door on the most obvious  vector for Cyber-attacks&lt;/li&gt;&#xA;&lt;li&gt;Reduce the IT department&amp;rsquo;s compliance burden (SOX, HIPAA, FERPA, GLBA, ISO etc).&lt;/li&gt;&#xA;&lt;li&gt;Free IT people to do tasks that require more brain power&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;By&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Automating the drone-like work of managing user identities&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Disabling accounts of terminated users&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIM Portal Groups whose displayedOwner isn&#39;t among the Owners</title>
      <link>https://identitymanaged.com/2019/10/mim-portal-groups-whose-displayedowner.html</link>
      <pubDate>Wed, 30 Oct 2019 14:15:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2019/10/mim-portal-groups-whose-displayedowner.html</guid>
      <description>&lt;p&gt;In the MIM Portal it will create issues if you have a group whose displayedOwner isn&amp;rsquo;t among the objects in the multivalued reference attribute Owner. Querying this through XPath is just about impossible so here is the SQL query to do it.&lt;/p&gt;&#xA;&lt;p&gt;SET TRANSACTION ISOLATION LEVEL READ UNCOMMITTED&lt;/p&gt;&#xA;&lt;p&gt;GO​&lt;/p&gt;&#xA;&lt;p&gt;USE FIMService​&lt;/p&gt;&#xA;&lt;p&gt;GO​&lt;/p&gt;&#xA;&lt;p&gt;​&lt;/p&gt;&#xA;&lt;p&gt;SELECT DOwn.*&lt;/p&gt;&#xA;&lt;p&gt;FROM (​&lt;/p&gt;&#xA;&lt;p&gt;SELECT groupObjID = G.[objectID]&lt;/p&gt;&#xA;&lt;p&gt;           , GroupDisplayName = GAOVS.ValueString&lt;/p&gt;&#xA;&lt;p&gt;           , userDisplayName= UAOVS.ValueString&lt;/p&gt;&#xA;&lt;p&gt;           , UserObjID =  U.[objectid]​&lt;/p&gt;</description>
    </item>
    <item>
      <title>Latency vs the Cloud</title>
      <link>https://identitymanaged.com/2019/01/latency-vs-cloud.html</link>
      <pubDate>Wed, 23 Jan 2019 21:26:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2019/01/latency-vs-cloud.html</guid>
      <description>&lt;p&gt;&amp;ldquo;The cloud is so fast! We can spin up servers and services so quickly to extend our environment and then all the users across the globe can access these services, so why does it take so long for you to get our users into the cloud?&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;(Latency) x (# of Round Trips)&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Most Cloud Identity Management APIs are built so that consumers must retrieve the data one object at a time or load it one object at a time. This means one roundtrip per object. Naturally, a data set in the cloud tends to be farther away than between two servers in the same data center. So the one object at time paradigm that worked ok in the data center works fine in the cloud for very small sets of objects. Once you start loading even moderately sized data sets of objects the additional latency shows up quite harshly. More bandwidth won&amp;rsquo;t solve the problem.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIM Open Source Schedulers</title>
      <link>https://identitymanaged.com/2018/12/mim-open-source-schedulers.html</link>
      <pubDate>Mon, 17 Dec 2018 22:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/12/mim-open-source-schedulers.html</guid>
      <description>&lt;p&gt;Your MIM installation is in, the config is done, programming all set and now to automate the running of the Management Agents.&lt;/p&gt;&#xA;&lt;p&gt;Options? Most people use Windows Task Scheduler with a PowerShell script or VBScript &amp;ndash; which works but can get cumbersome to maintain. With my SQL Server background, I often use SQL Server Agent Jobs because it has much better follow up and executing database commands.&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Task Scheduler &amp;ndash; runs as a windows service&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIM Open Source Schedulers - Comments</title>
      <link>https://identitymanaged.com/2018/12/mim-open-source-schedulers-comments.html</link>
      <pubDate>Mon, 17 Dec 2018 22:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/12/mim-open-source-schedulers-comments.html</guid>
      <description>&lt;h4 id=&#34;a-friend-have-point-out-that-my-run-script-was-men&#34;&gt;A friend have point out that my run script was men&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/06291310595946583362&#34; title=&#34;noreply@blogger.com&#34;&gt;Andas&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Apr 0, 2019&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;A friend have point out that my run script was mentioned in you blog.&lt;br&gt;&#xA;Have new version that I have used some time but not update on Github, have done so now.&lt;br&gt;&#xA;The new version have some nice more functions, so you may script disconnects and previews.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to Be an MVP in Life -- Launching Nov 27th</title>
      <link>https://identitymanaged.com/2018/11/how-to-be-mvp-in-life-launching-nov-27th.html</link>
      <pubDate>Wed, 21 Nov 2018 21:26:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/11/how-to-be-mvp-in-life-launching-nov-27th.html</guid>
      <description>&lt;p&gt;We are launching my new book, “&lt;a href=&#34;https://turquoise-poodle-csmt.squarespace.com/mvpinlifebook&#34;&gt;How to Be an MVP in Life: Lessons in Living and Leadership from Sports &amp;amp; Tech MVPs&lt;/a&gt;” on November 27th. It is available now for &lt;a href=&#34;https://www.amazon.com/gp/product/B07K5NKRQK&#34;&gt;Pre-order at Amazon&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Featuring an interview with the 2016 World Series MVP, Ben Zobrist, stories about 2-time Pro-Sports MVPs: Steve Nash, Dale Murphy, Steve Young and Sid the Kid Crosby, as well as interviews with 18 Microsoft MVPs.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.davidplundell.com/mvp-in-life-blog/2018/11/19/how-to-be-an-mvp-in-life-launch-nov-27th&#34;&gt;More info&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Missing the old Directory Experts Conference? Try HIP!</title>
      <link>https://identitymanaged.com/2018/10/missing-old-directory-experts.html</link>
      <pubDate>Mon, 08 Oct 2018 16:13:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/10/missing-old-directory-experts.html</guid>
      <description>&lt;p&gt;On Monday, Nov 5th, and Tuesday the 6th I will be attending and speaking at the &lt;a href=&#34;https://www.hipconf.com/&#34;&gt;Hybrid Identity Protection (HIP) Conference&lt;/a&gt; in NYC. On Monday at 4 PM I will be giving an updated version of Top Lessons Learned from Disasters in Identity Management as well as a sneak peek of my new book, How to be an MVP in Life.&lt;/p&gt;&#xA;&lt;p&gt;I am very excited to attend this conference. Thanks to Darren Mar-Elia and Micky Bresman at Semperis for putting it all together. This should be a lot like the old DEC &amp;ndash; Directory Experts Conference since it looks like DEC co-founder Gil Kirkpatrick is heavily involved.&lt;/p&gt;</description>
    </item>
    <item>
      <title>12 time MVP writes book on MVPs</title>
      <link>https://identitymanaged.com/2018/07/12-time-mvp-writes-book-on-mvps.html</link>
      <pubDate>Wed, 04 Jul 2018 16:11:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/07/12-time-mvp-writes-book-on-mvps.html</guid>
      <description>&lt;p&gt;Soon I will be adding the 2018-2019 ring onto this trophy. This makes 12 times starting back in 2007.&lt;/p&gt;&#xA;&lt;p&gt;The MVP program means a lot to me. So I have written a book about MVPs in both tech and sports. It will be coming out soon. I could use &lt;a href=&#34;https://www.facebook.com/1587066757/posts/10211450777736915/&#34;&gt;your help with the title&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://identitymanaged.com/img/mvp_12-years_400.jpg&#34; alt=&#34;MVP Trophy with 2018-2019 trophy&#34; title=&#34;MVP Trophy&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks,&lt;br&gt;&#xA;David&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>European Identity Conference 2018 - Wednesday</title>
      <link>https://identitymanaged.com/2018/05/european-identity-conference-2018_17.html</link>
      <pubDate>Thu, 17 May 2018 03:41:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/05/european-identity-conference-2018_17.html</guid>
      <description>&lt;p&gt;Jet lag and other issues caught up with me the next day (Tuesday) and I didn&amp;rsquo;t attend any sessions :(&lt;/p&gt;&#xA;&lt;p&gt;One thing I love is that most presentations including keynotes are only 20 min long so even when we get a terrible one &amp;ndash; we know it will be over soon. But most of the sessions were good and some were great!&lt;/p&gt;&#xA;&lt;p&gt;My first Wednesday session was listening to Sebastian Goodrick of SUVA and Dr. Jacek Jonczy discussing how agile methodologies did and didn&amp;rsquo;t work well with replacing their existing Identity Management system with another one. Hire an agile coach! Recognize that replacing an existing system is often big bang and so you won&amp;rsquo;t really be pushing out to production, but you can still do sprints.&lt;/p&gt;</description>
    </item>
    <item>
      <title>European Identity Conference 2018 -- Overview and Mon Night</title>
      <link>https://identitymanaged.com/2018/05/european-identity-conference-2018.html</link>
      <pubDate>Thu, 17 May 2018 03:24:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/05/european-identity-conference-2018.html</guid>
      <description>&lt;p&gt;I have spent this week in Munich Germany, where it has been mostly cloudy, lots of rain, and a little thunder.&lt;/p&gt;&#xA;&lt;p&gt;I have seen a number of familiar faces to those who attended Directory Experts conference: Pamela Dingle, Alex Simons, Alex Weinert, Jackson Shaw, Jonathan Sander, Kim Cameron, and others. Also a lot of faces familiar to those who have attended Cloud Identity Summits: Andrew Hindle, Colin Wallis, Steve Hutchinson, Eve Maler, and Ian Glazer and fellow Microsoft MVP: Naohiro Fujie.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIM Join and spaces</title>
      <link>https://identitymanaged.com/2018/05/mim-join-and-spaces.html</link>
      <pubDate>Sat, 05 May 2018 09:58:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/05/mim-join-and-spaces.html</guid>
      <description>&lt;p&gt;Working on a customer&amp;rsquo;s lab and look what I found. They had created (through some other process) two user accounts for the same user, and the samAccountName was nearly identical, just a space, ascii 32, appended to the end of one of the samAccountNames differentiates the two. Apparently, AD allows this.&lt;/p&gt;&#xA;&lt;p&gt;The account with the space was projected into the Metaverse, and then later in the sync the account without the space attempted to join, and it matched. The join failed because of the ambiguous import flow error. But samAccountName &amp;ldquo;myuser1&amp;rdquo; matched samAccountName &amp;ldquo;myuser1 &amp;quot; already in the metaverse.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Top 10 Lessons from Disasters in Identity Management</title>
      <link>https://identitymanaged.com/2018/03/top-10-lessons-from-disasters-in.html</link>
      <pubDate>Thu, 29 Mar 2018 19:28:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/top-10-lessons-from-disasters-in.html</guid>
      <description>&lt;p&gt;I will speak at &lt;a href=&#34;https://www.kuppingercole.com/events/eic2018&#34;&gt;Kuppinger Cole&amp;rsquo;s European Identity Conference&lt;/a&gt; on &lt;a href=&#34;https://www.youtube.com/watch?v=J0mPzehpzRc&#34;&gt;Top 10 Lessons from Disasters in Identity Management &lt;/a&gt;in May in Munich.&lt;/p&gt;&#xA;&lt;p&gt;With great automation capability comes great responsibility! Come discuss and learn vital lessons gleaned from disasters in Identity Management.&lt;/p&gt;&#xA;&lt;p&gt;So if you would like your disaster story to be considered for inclusion let me know. I would love to add to the stories.&lt;/p&gt;&#xA;&lt;p&gt;This will be a fun interactive session.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Identiverse, Cloud Identity Summit</title>
      <link>https://identitymanaged.com/2018/03/identiverse-cloud-identity-summit.html</link>
      <pubDate>Thu, 29 Mar 2018 17:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/identiverse-cloud-identity-summit.html</guid>
      <description>&lt;p&gt;Last summer I attended and spoke at the Cloud Identity Summit in Chicago. First big news: it was renamed to Identiverse and 2018 will be in Boston. As a consultant I have limited time to attend conferences and speak. So conferences have to be great. I do love this one, but in the interest of time, I will be skipping it this year in favor of speaking at the European Identity Conference in May 2018 in Munich, Germany.&lt;/p&gt;</description>
    </item>
    <item>
      <title>To Farm or not to Farm Part 2</title>
      <link>https://identitymanaged.com/2018/03/to-farm-or-not-to-farm-part-2.html</link>
      <pubDate>Thu, 29 Mar 2018 17:43:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/to-farm-or-not-to-farm-part-2.html</guid>
      <description>&lt;p&gt;In the original &lt;a href=&#34;http://blog.ilmbestpractices.com/2014/05/to-farm-or-not-to-farm-that-is-question.html&#34;&gt;To Farm or Not to Farm post&lt;/a&gt; I discussed the pros and cons of setting up FIM on a SharePoint farm or using Stand Alone. Well we now have SharePoint 2016 and it isn&amp;rsquo;t possible to install Stand Alone, although you can do a single server farm. Also, absolutely everything is virtualized and so we tend to share lots and lots of processing so we can&amp;rsquo;t really think of a server as having spare cycles, because we share those processors with lots of other VM&amp;rsquo;s.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Server Management Studio SQL 2016</title>
      <link>https://identitymanaged.com/2018/03/sql-server-management-studio-sql-2016.html</link>
      <pubDate>Thu, 29 Mar 2018 16:19:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/sql-server-management-studio-sql-2016.html</guid>
      <description>&lt;p&gt;So I went to install SQL 2016 on a server (been using it for a while, I get vm&amp;rsquo;s on CloudShare where SQL is preinstallled, so first time installing it for myself) &amp;ndash; no problem. Hey, where is SQL Management Studio (SSMS)? Well it isn&amp;rsquo;t include in the 2.6  GB SQL Server ISO. You have to download it separately. 800 MB. All I can say is You&amp;rsquo;re Welcome!&lt;/p&gt;&#xA;&lt;p&gt;I get why they did it &amp;ndash; they can update SSMS much more often etc.But what a surprise.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SharePoint Foundations 2013 -- Identity Extensions Installation error</title>
      <link>https://identitymanaged.com/2018/03/sharepoint-foundations-2013-identity.html</link>
      <pubDate>Thu, 29 Mar 2018 16:09:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/sharepoint-foundations-2013-identity.html</guid>
      <description>&lt;p&gt;As you install SharePoint 2013 Foundations pre-reqs if you encounter &amp;ldquo;Microsoft Identity Extensions Installation error&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://4.bp.blogspot.com/-tYOhqyY_mCE/Wr1ysErFnjI/AAAAAAAAAKk/SxiqPGtc4AIgaUt6dgPO-rdlk4_6CpVWgCLcBGAs/s1600/Identity%2BExtensions%2BError.png&#34;&gt;&lt;img src=&#34;https://4.bp.blogspot.com/-tYOhqyY_mCE/Wr1ysErFnjI/AAAAAAAAAKk/SxiqPGtc4AIgaUt6dgPO-rdlk4_6CpVWgCLcBGAs/s320/Identity%2BExtensions%2BError.png&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;and then when you install it manually you might encounter&lt;br&gt;&#xA;&amp;ldquo;Installation of Microsoft Identity Extensions requires Windows Identity Foundation v1.0 to be installed&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://1.bp.blogspot.com/-3aPHBXaDdq8/Wr1zJ3kOV8I/AAAAAAAAAKo/vGKk33EMbFQHcLwwCnTV4AkpJMnk13oPwCLcBGAs/s1600/Identity%2BFoundation%2BRequired.png&#34;&gt;&lt;img src=&#34;https://1.bp.blogspot.com/-3aPHBXaDdq8/Wr1zJ3kOV8I/AAAAAAAAAKo/vGKk33EMbFQHcLwwCnTV4AkpJMnk13oPwCLcBGAs/s320/Identity%2BFoundation%2BRequired.png&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://3.bp.blogspot.com/-ZiPEE93Hcdw/Wr1zJ9WqB2I/AAAAAAAAAKs/iu_QHJbxy7wO46i8v_y1jjnr2CkMiedqQCLcBGAs/s1600/WIF%2B3_5.png&#34;&gt;&lt;img src=&#34;https://3.bp.blogspot.com/-ZiPEE93Hcdw/Wr1zJ9WqB2I/AAAAAAAAAKs/iu_QHJbxy7wO46i8v_y1jjnr2CkMiedqQCLcBGAs/s320/WIF%2B3_5.png&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Then when you go to install WIF through the Server Manager you realize that it is WIF 3.5 rather than WIF 1.0 and you think hmm&amp;hellip; maybe that will work. It will. Take heart.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Finding my groove, again</title>
      <link>https://identitymanaged.com/2018/03/finding-my-groove-again.html</link>
      <pubDate>Thu, 29 Mar 2018 16:05:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/finding-my-groove-again.html</guid>
      <description>&lt;p&gt;In 2017 and the beginning of 2018 I have had some rough times. The Long and the Short of it is that late last year my mother passed away in the hospital. Then early this year, my father died, probably of a broken heart.&lt;/p&gt;&#xA;&lt;p&gt;Thanks to many friends from church, our neighborhood, professionally, other Microsoft MVP&amp;rsquo;s, I have had a lot of support while mourning their temporary absence from my life. Especially, thanks to my wife, kids, siblings, aunts, uncles, and cousins.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SharePoint Foundation 2013 IIS Configuration Error</title>
      <link>https://identitymanaged.com/2018/03/sharepoint-foundation-2013-iis.html</link>
      <pubDate>Thu, 29 Mar 2018 15:54:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/sharepoint-foundation-2013-iis.html</guid>
      <description>&lt;p&gt;SharePoint is a great product but I wish that FIM and MIM did not use it. In my opinion, it adds unnecessary infrastructure and really complicates the setup, because SharePoint must be installed and configured (and maintained). Leaving that aside, allow me to point out some gotchas that might impede your ability to install this MIM/FIM prerequisite.&lt;/p&gt;&#xA;&lt;p&gt;First up: if your server has limited access to the Internet you should probably download all of these prerequisites and copy them to the server &amp;ndash; because that&amp;rsquo;s what the SharePoint Installer has to do &amp;ndash; it doesn&amp;rsquo;t include these items.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Speaking at SQL Saturday Tomorrow</title>
      <link>https://identitymanaged.com/2018/03/speaking-at-sql-saturday-tomorrow.html</link>
      <pubDate>Fri, 16 Mar 2018 15:14:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/speaking-at-sql-saturday-tomorrow.html</guid>
      <description>&lt;p&gt;As most of you know I am regarded as one of the SQL gurus among the Microsoft Identity Management Gurus. For years, in my book and in speaking I have been recommending &lt;a href=&#34;https://ola.hallengren.com/&#34;&gt;Ola Hallengren&amp;rsquo;s SQL Maintenance Solution&lt;/a&gt; to help take care of your ILM/FIM/MIM databases. But the SQL Maintenance Plan Wizard has come a long way. Tomorrow morning at 10 AM at Grand Canyon University I will be presenting as part of &lt;a href=&#34;http://www.sqlsaturday.com/726/Sessions/Schedule.aspx&#34;&gt;SQL Saturday #726&lt;/a&gt; a s&lt;a href=&#34;http://www.sqlsaturday.com/726/Sessions/Details.aspx?sid=77361&#34;&gt;howdown between the SQL Maintenance Plan Wizard and Ola&amp;rsquo;s solution&lt;/a&gt;, discussing when you want to use one vs the other.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Kerberos, FIDO, what&#39;s next?</title>
      <link>https://identitymanaged.com/2018/03/kerberos-fido-whats-next.html</link>
      <pubDate>Tue, 06 Mar 2018 16:29:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2018/03/kerberos-fido-whats-next.html</guid>
      <description>&lt;p&gt;In the 1980&amp;rsquo;s Steve Miller and Clifford Neuman published a new security protocol, called &lt;a href=&#34;https://en.wikipedia.org/wiki/Kerberos_(protocol)&#34;&gt;Kerberos&lt;/a&gt;, after the mythical three headed dog that guards the gates of Hades.&lt;/p&gt;&#xA;&lt;p&gt;In 2014 the &lt;a href=&#34;https://en.wikipedia.org/wiki/FIDO_Alliance&#34;&gt;alliance published the FIDO standard&lt;/a&gt;. This exciting standard is enabling a passwordless world (yet to come). For example you can use a small USB device with a key on it to login instead of entering a password. FIDO 2.0 is requiring two-factor, type in a PIN plus your key. Other options exist as well potentially using Smart Phones, or other devices via USB, Bluetooth or NFC.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open Source: Review of MIMTools</title>
      <link>https://identitymanaged.com/2017/03/open-source-review-of-mimtools.html</link>
      <pubDate>Fri, 31 Mar 2017 20:09:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2017/03/open-source-review-of-mimtools.html</guid>
      <description>&lt;p&gt;JefTek created a &lt;a href=&#34;https://github.com/JefTek/MIMTools&#34;&gt;niche hybrid tool&lt;/a&gt; that tackles a few pieces of the sync and service puzzle in a way that none of the others do.&lt;/p&gt;&#xA;&lt;p&gt;One noteable one for sync:&lt;br&gt;&#xA;Get and Export MIM Deltas to CSV (based on a drop file either stop and drop or the audit log dropped during the export&lt;/p&gt;&#xA;&lt;p&gt;It is great for setting up SharePoint and the Kerberos authentication to it.&lt;/p&gt;&#xA;&lt;p&gt;While it doesn&amp;rsquo;t do all that &lt;a href=&#34;https://github.com/wim-beck/IS4U-FIM-Powershell&#34;&gt;IS4U-FIM-PowerShell&lt;/a&gt; (see my &lt;a href=&#34;http://blog.ilmbestpractices.com/2017/03/open-source-review-of-is4u-fim.html&#34;&gt;review&lt;/a&gt;), does or &lt;a href=&#34;https://github.com/lithnet/resourcemanagement-powershell&#34;&gt;Lithnext resourcemanagement-powershell&lt;/a&gt; or &lt;a href=&#34;https://github.com/lithnet/miis-powershell&#34;&gt;Lithnet-miis-powershell&lt;/a&gt; (&lt;a href=&#34;http://blog.ilmbestpractices.com/2017/03/open-source-review-of-lithnet.html&#34;&gt;see my review&lt;/a&gt;), or even the he  &lt;a href=&#34;http://fimpowershellmodule.codeplex.com/&#34;&gt;FIM PowerShell Module&lt;/a&gt; (&lt;a href=&#34;http://blog.ilmbestpractices.com/2017/03/open-source-review-of-fim-powershell.html&#34;&gt;see my review&lt;/a&gt;), it fills a small niche that none of the rest of them do. This is a solid contribution!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open Source: Review of FIM 2010 PowerShell Cmdlets</title>
      <link>https://identitymanaged.com/2017/03/open-source-review-of-fim-2010.html</link>
      <pubDate>Fri, 31 Mar 2017 20:00:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2017/03/open-source-review-of-fim-2010.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://gilkirkpatrick.com/Blog/&#34;&gt;Gil Kirkpatrick&lt;/a&gt; (a great guy, fellow MVP, who has taught me a lot over the years) created one of the very first, if not the first, P&lt;a href=&#34;http://fimpscmdlets.codeplex.com/&#34;&gt;owerShell commandlets libraries to manage FIM/MIM service&lt;/a&gt;. It hasn&amp;rsquo;t had any activity in years, but it served as a great example to get others going.&lt;/p&gt;&#xA;&lt;p&gt;If you like this simple approach you could check out Adam Weigert&amp;rsquo;s PowerShell for FIM 2010 (see &lt;a href=&#34;http://blog.ilmbestpractices.com/2017/03/open-source-review-of-powershell-for.html&#34;&gt;my review&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;I recommend  &lt;a href=&#34;https://github.com/wim-beck/IS4U-FIM-Powershell&#34;&gt;IS4U-FIM-PowerShell&lt;/a&gt; (see my &lt;a href=&#34;http://blog.ilmbestpractices.com/2017/03/open-source-review-of-is4u-fim.html&#34;&gt;review&lt;/a&gt;), this is what I use. But I also recommend  &lt;a href=&#34;https://github.com/lithnet/resourcemanagement-powershell&#34;&gt;Lithnext resourcemanagement-powershell&lt;/a&gt; (&lt;a href=&#34;http://blog.ilmbestpractices.com/2017/03/open-source-review-of-lithnet.html&#34;&gt;see my review&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open Source: Review of IS4U-FIM-PowerShell</title>
      <link>https://identitymanaged.com/2017/03/open-source-review-of-is4u-fim.html</link>
      <pubDate>Fri, 31 Mar 2017 19:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2017/03/open-source-review-of-is4u-fim.html</guid>
      <description>&lt;p&gt;Wim Beck&amp;rsquo;s &lt;a href=&#34;https://github.com/wim-beck/IS4U-FIM-Powershell&#34;&gt;IS4U-FIM-PowerShell&lt;/a&gt; is a great example of open source, in that he has built on top of the  &lt;a href=&#34;http://fimpowershellmodule.codeplex.com/&#34;&gt;FIM PowerShell Module&lt;/a&gt; (&lt;a href=&#34;http://blog.ilmbestpractices.com/2017/03/open-source-review-of-fim-powershell.html&#34;&gt;see my review&lt;/a&gt;). This is what Open Source is about, building upon each other&amp;rsquo;s contributions to make great stuff!&lt;/p&gt;&#xA;&lt;p&gt;When I looked at it in Dec 2016 I almost dismissed it since it lacked a wiki, but since then Wim has added a lot of pages. They still lack examples, I plan on pitching in to help out with that by adding some examples to my fork and then asking Wim to pull it in.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open Source: Review of Lithnet</title>
      <link>https://identitymanaged.com/2017/03/open-source-review-of-lithnet.html</link>
      <pubDate>Fri, 31 Mar 2017 19:35:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2017/03/open-source-review-of-lithnet.html</guid>
      <description>&lt;p&gt;Ryan Newington&amp;rsquo;s &lt;a href=&#34;https://github.com/lithnet&#34;&gt;Lithnet&lt;/a&gt; consists of several items:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/lithnet/miis-powershell&#34;&gt;miis-powershell&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/lithnet/resourcemanagement-powershell&#34;&gt;resourcemanagement-powershell&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/lithnet/resourcemanagement-webservice&#34;&gt;resourcemanagement-webservice&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/lithnet/googleapps-managementagent&#34;&gt;googleapps-managementagent&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/lithnet/acma&#34;&gt;acma&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&amp;ldquo;Codeless business rules engine for FIM/MIM&amp;rdquo;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://github.com/lithnet/umare&#34;&gt;umare&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&amp;ldquo;Codeless data transform engine for FIM/MIM&amp;rdquo;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;I will only review the items I know&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Managing Sync&lt;/strong&gt;&lt;br&gt;&#xA;&lt;a href=&#34;https://github.com/lithnet/miis-powershell&#34;&gt;miis-powershell&lt;/a&gt; is amazing it can almost everything you can do through the UI. For example, Clear-FullSyncWarning and it has a great wiki. Gotta have it!&lt;/p&gt;&#xA;&lt;p&gt;It wraps WMI calls, existing PowerShell modules, executables and sync client UI to interact with FIM/MIM Sync.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open Source: Review of PowerShell for FIM 2010</title>
      <link>https://identitymanaged.com/2017/03/open-source-review-of-powershell-for.html</link>
      <pubDate>Fri, 31 Mar 2017 19:15:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2017/03/open-source-review-of-powershell-for.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://fim.codeplex.com/&#34;&gt;PowerShell for FIM 2010&lt;/a&gt; by Adam Weigert consists of three parts but I further break the last into two:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Management Agent(MA)  and MetaVerse (MV) Extensions that let you run PowerShell scripts as your extensions&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;A Workflow Activity&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;A PowerShell module&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Managing Sync&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Managing Service&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;&lt;strong&gt;Management Agent(MA)  and MetaVerse (MV) Extensions&lt;/strong&gt;&lt;br&gt;&#xA;The work done to enable you to write PowerShell scripts to be MA and MV extensions is crazy brilliant. However, I suspect (I haven&amp;rsquo;t tested) that large installations should shy away from this as compiled C# and VB.NET code tends to run orders of magnitude faster than PowerShell scripts. Perhaps someone else knows a way to make it more comparable in performance. I can see some smaller shops taking advantage of this as they don&amp;rsquo;t need to worry about performance in the Sync Engine&lt;/p&gt;</description>
    </item>
    <item>
      <title>Open Source: Review of FIM PowerShell Module</title>
      <link>https://identitymanaged.com/2017/03/open-source-review-of-fim-powershell.html</link>
      <pubDate>Fri, 31 Mar 2017 18:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2017/03/open-source-review-of-fim-powershell.html</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://fimpowershellmodule.codeplex.com/&#34;&gt;FIM PowerShell Module&lt;/a&gt; (started by &lt;a href=&#34;http://www.integrationtrench.com/&#34;&gt;Craig Martin&lt;/a&gt; and now updated most frequently by &lt;a href=&#34;http://briandesmond.com/&#34;&gt;Brian Desmond&lt;/a&gt;) is a great set of commandlets that help you to automate Interactions with FIM Service and FIM Sync Service.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Managing Sync&lt;/strong&gt;&lt;br&gt;&#xA;This library is great for automating tests. This library and Ryan Newington&amp;rsquo;s &lt;a href=&#34;https://github.com/lithnet/miis-powershell&#34;&gt;Lithnet-Miis-PowerShell&lt;/a&gt; (see &lt;a href=&#34;http://blog.ilmbestpractices.com/2017/03/open-source-review-of-lithnet.html&#34;&gt;my review on LithNet&lt;/a&gt;) are very complimentary. You can retrieve CS Objects, Run History, start an MA.&lt;br&gt;&#xA;I found that the most interesting Sync related Cmdlets are the&lt;/p&gt;</description>
    </item>
    <item>
      <title>Speaking at Cloud Identity Summit 2017</title>
      <link>https://identitymanaged.com/2017/03/speaking-at-cloud-identity-summit-2017.html</link>
      <pubDate>Wed, 29 Mar 2017 10:20:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2017/03/speaking-at-cloud-identity-summit-2017.html</guid>
      <description>&lt;p&gt;I am excited to announce that I will be speaking at the  &lt;a href=&#34;https://www.cloudidentitysummit.com/en/index.html&#34;&gt;Cloud Identity Summit 2017&lt;/a&gt; in Chicago in June.&lt;/p&gt;&#xA;&lt;p&gt;I will discuss &lt;a href=&#34;https://www.youtube.com/watch?v=h1nCDlD0L4o&#34;&gt;How Identity Management (Employee and Consumer) affects the bottom line&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is MIM dead? Not yet!</title>
      <link>https://identitymanaged.com/2017/03/is-mim-dead-not-yet.html</link>
      <pubDate>Wed, 29 Mar 2017 08:17:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2017/03/is-mim-dead-not-yet.html</guid>
      <description>&lt;p&gt;From time to time I hear people wonder if MIM is dead.&lt;/p&gt;&#xA;&lt;p&gt;Why do people ask?&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;They don&amp;rsquo;t feel like they have heard a good road map recently&lt;/li&gt;&#xA;&lt;li&gt;They aren&amp;rsquo;t seeing the improvements they hoped for&lt;/li&gt;&#xA;&lt;li&gt;They aren&amp;rsquo;t paying attention to the actions of the product group&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Why do I say it isn&amp;rsquo;t dead yet?&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;While the Cloud Identity is the future, we are and will be in hybrid identity for a long time and MIM is Microsoft&amp;rsquo;s key component to that.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Christmastime FIM/MIM Open Source WF Reviews</title>
      <link>https://identitymanaged.com/2016/12/christmastime-fimmim-open-source-wf.html</link>
      <pubDate>Sat, 24 Dec 2016 13:39:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2016/12/christmastime-fimmim-open-source-wf.html</guid>
      <description>&lt;p&gt;Over the years since FIM was first beta&amp;rsquo;d as ILM2 we have seen some cool workflows be released to open source. This is my review of the workflows I can find that are open source. First let me salute everyone who has contributed to the FIM and MIM community with these big undertakings. That said I am trying to give guidance to my readers as to what is the most useful in various situations and so I will make specific recommendations.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIM 2016 SP1 -- Implications</title>
      <link>https://identitymanaged.com/2016/10/mim-2016-sp1-implications.html</link>
      <pubDate>Wed, 19 Oct 2016 04:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2016/10/mim-2016-sp1-implications.html</guid>
      <description>&lt;p&gt;Earlier this month Microsoft &lt;a href=&#34;https://docs.microsoft.com/en-us/microsoft-identity-manager/understand-explore/microsoft-identity-manager-2016-sp1-release-notes&#34;&gt;released MIM 2016 SP1&lt;/a&gt;&lt;br&gt;&#xA;But what does this mean for you?&lt;/p&gt;&#xA;&lt;p&gt;Biggest Implications&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Exchange Online (Office365) for the MIM Service &lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;without losing the ability to approve requests from within Outlook, and the requesting of groups within Outlook.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Since lots of orgs are using Office 365 no more embarrassing conversations about these great features you can&amp;rsquo;t have.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Support for other browsers for MIM Portal&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;SSPR already supported other browsers but now MIM Portal will support Chrome, Firefox and Safari.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Post Migration Your MIM/FIM Attribute Flow Precedence is Incorrect</title>
      <link>https://identitymanaged.com/2016/10/post-migration-your-mimfim-attribute.html</link>
      <pubDate>Mon, 17 Oct 2016 23:53:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2016/10/post-migration-your-mimfim-attribute.html</guid>
      <description>&lt;p&gt;Have you ever found out that attribute flow precedence is messed up, wrong or otherwise in error just after you followed &lt;a href=&#34;https://technet.microsoft.com/en-us/library/ff400277(v=ws.10).aspx&#34;&gt;the steps to migrate your MIM/FIM configuration&lt;/a&gt; from Dev to Prod or vice-versa? Well I am finally blogging about a discovery I made. The list of steps (reproduced below from the above link) are incomplete:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Back up the pilot and production environments by using the Backup and Restore procedures.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Export the FIM Service schema configuration.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SharePoint MA -- avoid the noise</title>
      <link>https://identitymanaged.com/2016/06/sharepoint-ma-avoid-noise.html</link>
      <pubDate>Tue, 28 Jun 2016 19:47:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2016/06/sharepoint-ma-avoid-noise.html</guid>
      <description>&lt;p&gt;In using the &lt;a href=&#34;http://social.technet.microsoft.com/wiki/contents/articles/1589.fim-2010-management-agents-from-partners.aspx#SharePoint_List_Management_Agent_from_Steven_Kean_at_Version3&#34;&gt;SharePoint MA from Steve Kean&lt;/a&gt; I noticed that some of the fields I imported were coming in with some extra noise or crap at the beginning:&lt;/p&gt;&#xA;&lt;p&gt;String;#164&lt;/p&gt;&#xA;&lt;p&gt;All I really wanted was the 164. While I can use the Word function in a sync rule to get past it&lt;br&gt;&#xA;Word(strAttribute,2,&amp;ldquo;2&amp;rdquo;) I really would prefer to bypass it altogether.&lt;/p&gt;&#xA;&lt;p&gt;Well thanks to Jermaine Snipe I found why this happens and how to bypass it:&lt;br&gt;&#xA;These are calculated columns and they use the concatenate function. Instead use a Text formula for the calculated column. This of course supposes that you can get the SharePoint developer to change it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Check your inputs -- Save your job!</title>
      <link>https://identitymanaged.com/2016/02/check-your-inputs-save-your-job.html</link>
      <pubDate>Sat, 06 Feb 2016 15:06:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2016/02/check-your-inputs-save-your-job.html</guid>
      <description>&lt;p&gt;At various times in my 10 years of Identity Management Consulting and 25 years working in the IT industry I have been asked to clean up various messes generated by those before me. Some of those messes involved disk failure or other issues that couldn&amp;rsquo;t be completely prevented. But some involved automated process that didn&amp;rsquo;t check their inputs.&lt;/p&gt;&#xA;&lt;p&gt; If garbage into a computer gives you garbage out, then garbage into an automated process that doesn&amp;rsquo;t check its inputs gives you a meltdown! Even &lt;a href=&#34;http://video.disney.com/watch/sorcerer-s-apprentice-fantasia-4ea9ebc01a74ea59a5867853&#34;&gt;Disney&amp;rsquo;s Sorcerer&amp;rsquo;s Apprentice&lt;/a&gt; Fantasia illustrates what can go wrong with an automated process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Custom Expressions inside Custom Expressions?</title>
      <link>https://identitymanaged.com/2015/11/fim-custom-expressions-inside-custom.html</link>
      <pubDate>Mon, 09 Nov 2015 10:16:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/11/fim-custom-expressions-inside-custom.html</guid>
      <description>&lt;p&gt;Recently, I needed to take Longitude and Latitude data that was given to me in the following format and break it into its individual components and then flow it out to AD.&lt;br&gt;&#xA;Let&amp;rsquo;s suppose the data looks like this:&lt;/p&gt;&#xA;&lt;p&gt;&amp;ldquo;Point -10.1223 45.945&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;I could just use the Left and Right functions to get out the Longitude and Latitude.&lt;/p&gt;&#xA;&lt;p&gt;The problem was it could also look like this depending on the level of precision:&lt;/p&gt;</description>
    </item>
    <item>
      <title>How many attributes can you have in the Metaverse?</title>
      <link>https://identitymanaged.com/2015/08/how-many-attributes-can-you-have-in.html</link>
      <pubDate>Wed, 05 Aug 2015 19:58:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/08/how-many-attributes-can-you-have-in.html</guid>
      <description>&lt;p&gt;Back in 2013 I published 5 posts about the &lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-1.html&#34;&gt;Secrets of the Metaverse&lt;/a&gt;:&lt;/p&gt;&#xA;&lt;p&gt;Parts 1-5:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-1.html&#34;&gt;What is the Metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-2.html&#34;&gt;How is the Metaverse data stored?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-3.html&#34;&gt;Is there a limit to how many Metaverse attributes I can have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-4.html&#34;&gt;Has access to the metaverse gotten faster with recent releases?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-5.html&#34;&gt;How do I safely query the metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Added (Aug 5 2015): &lt;a href=&#34;http://blog.ilmbestpractices.com/2015/08/how-many-attributes-can-you-have-in.html&#34;&gt;How Many Metaverse Attributes can I have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;The &lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-3.html&#34;&gt;third post was about how many attributes you can have in the Metaverse&lt;/a&gt; in which I said that the mms_metaverse_lineageguid table &lt;strong&gt;limits us to 502 single valued non-reference attributes in the Metaverse&lt;/strong&gt;. This is still correct but a client told me of a scenario they encountered where the lineageguid table prevented them from getting to over &lt;strong&gt;450 attributes&lt;/strong&gt; and they encouraged me to blog about how they solved it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIM 2016 is now available</title>
      <link>https://identitymanaged.com/2015/08/mim-2016-is-now-available.html</link>
      <pubDate>Tue, 04 Aug 2015 08:12:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/08/mim-2016-is-now-available.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.microsoft.com/en-us/server-cloud/products/microsoft-identity-manager/&#34;&gt;MIM 2016 is now available&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;MIM &amp;ndash; Microsoft Identity Manager 2016 builds on and replaces Microsoft&amp;rsquo;s Forefront Identity Manager 2010 R2.&lt;/p&gt;&#xA;&lt;p&gt;On Microsoft&amp;rsquo;s site they include an &lt;a href=&#34;https://www.youtube.com/embed/65ueuS3-wTQ&#34;&gt;introductory (2 min) video about Hybrid Identity&lt;/a&gt; but don&amp;rsquo;t mistake that for the MIM UI.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;So has anything been removed?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;No. While the list of deprecated features are still deprecated none of them have been removed from this new version.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;So what&amp;rsquo;s new?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The first thing to call your attention is the focus on Hybrid (Cloud + On Premise) Identity. MIM can still manage on premise but is now even better equipped to work with Microsoft&amp;rsquo;s Identity Management pieces in the cloud.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Still an MVP but now DS MVP</title>
      <link>https://identitymanaged.com/2015/07/still-mvp-but-now-ds-mvp-comments.html</link>
      <pubDate>Thu, 02 Jul 2015 14:49:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/07/still-mvp-but-now-ds-mvp-comments.html</guid>
      <description>&lt;h4 id=&#34;thanks-scott&#34;&gt;Thanks Scott.&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/17202883653808140101&#34; title=&#34;noreply@blogger.com&#34;&gt;David Lundell&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 3, 2015&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks Scott.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Still an MVP but now DS MVP</title>
      <link>https://identitymanaged.com/2015/07/still-mvp-but-now-ds-mvp.html</link>
      <pubDate>Thu, 02 Jul 2015 14:49:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/07/still-mvp-but-now-ds-mvp.html</guid>
      <description>&lt;p&gt;I have been awarded the Microsoft Most Valuable Professional for a 9th time. I started off as an MIIS MVP (even though ILM had been released 4 months previous). Then I became an ILM MVP in 2008, then in 2010 it was FIM MVP (or was that 2011). Now with FIM changing to MIM and in an effort to reduce the administrative paperwork the Microsoft MVP team has every time MMS/MIIS/ILM/FIM/MIM changes names all FIM MVPs have become DS (Directory Services) MVPs. ;) Actually, they decided that there was enough overlap and dependency that it made sense to combine them. So now I am a Directory Services MVP&lt;/p&gt;</description>
    </item>
    <item>
      <title>Big Data needs Identity in order to Act</title>
      <link>https://identitymanaged.com/2015/05/big-data-needs-identity-in-order-to-act.html</link>
      <pubDate>Thu, 28 May 2015 16:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/05/big-data-needs-identity-in-order-to-act.html</guid>
      <description>&lt;p&gt;At the 2015 Identity Summit Scott McNeely declared &amp;ldquo;&lt;strong&gt;Big data without Identity is not actionable&lt;/strong&gt;&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;Let&amp;rsquo;s discuss.&lt;/p&gt;&#xA;&lt;p&gt;Pulling from &lt;a href=&#34;http://www.informationweek.com/big-data/big-data-analytics/5-big-data-use-cases-to-watch/d/d-id/1251031&#34;&gt;Information Week&lt;/a&gt; and &lt;a href=&#34;http://www.ibmbigdatahub.com/podcast/top-5-big-data-use-cases&#34;&gt;IBM&lt;/a&gt; the Top 6 use cases of Big Data are:&lt;br&gt;&#xA;1. Big Data Exploration&lt;br&gt;&#xA;2. 360 degree view of customer&lt;br&gt;&#xA;3. Information Security and Intelligence&lt;br&gt;&#xA;4. Operation Analysis of data from Internet of Things&lt;br&gt;&#xA;5. Data warehouse Augmentation/Optimization&lt;br&gt;&#xA;6. Big Data Efficiency play (break down silos)&lt;/p&gt;&#xA;&lt;p&gt;Big Data use case&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Sync Flow with ScreenShots and Code snippets</title>
      <link>https://identitymanaged.com/2015/04/fim-sync-flow-with-screenshots-and-code-comments.html</link>
      <pubDate>Thu, 30 Apr 2015 22:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/04/fim-sync-flow-with-screenshots-and-code-comments.html</guid>
      <description>&lt;h4 id=&#34;hi-good-job-some-info-was-lost-during-conversion&#34;&gt;Hi, good job! Some info was lost during conversion&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/12600587106910244204&#34; title=&#34;noreply@blogger.com&#34;&gt;hierbaluisa&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Mar 1, 2019&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hi, good job!&lt;br&gt;&#xA;Some info was lost during conversion from Visio to PDF. Is it possible to get it complete? Perhaps rotating image or changing scale.&lt;br&gt;&#xA;Thanks!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>FIM Sync Flow with ScreenShots and Code snippets</title>
      <link>https://identitymanaged.com/2015/04/fim-sync-flow-with-screenshots-and-code.html</link>
      <pubDate>Thu, 30 Apr 2015 22:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/04/fim-sync-flow-with-screenshots-and-code.html</guid>
      <description>&lt;p&gt;Years ago Brad Turner and I created a &lt;a href=&#34;http://www.ilmbestpractices.com/files/FIM_Sync_Flow_with_Screenshots.pdf&#34;&gt;Flow Chart of FIM data flow with Screenshots and Code snippets&lt;/a&gt;. Some of the code examples are funny and it still says ILM rather than FIM. It also doesn&amp;rsquo;t include filter based out bound filter-based sync rules that came with R2. Bearing those things in mind it still provides a good bit of value. Someday I will update it with the latest &amp;ndash; until then enjoy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Hotfix for PCNS to support 2012 R2 DC&#39;s</title>
      <link>https://identitymanaged.com/2015/04/fim-hotfix-for-pcns-to-support-2012-r2.html</link>
      <pubDate>Thu, 30 Apr 2015 13:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/04/fim-hotfix-for-pcns-to-support-2012-r2.html</guid>
      <description>&lt;p&gt;With the &lt;a href=&#34;https://support.microsoft.com/en-us/kb/3048056&#34;&gt;latest hotfix&lt;/a&gt; MSFT now supports running PCNS on Windows Server 2012 R2. FIM still should not be installed on Windows Server 2012 R2 (2012 yes, 2008 R2 yes, 2008 yes). Only PCNS can be installed on Windows Server 2012 R2. The hotfix article has a slight error indicating that it is ok to install FIM Sync Service on 2012 R2 if you have installed the hotfix PCNS on 2012 R2 &amp;ndash; not true (the article should get corrected soon). Be warned this update may break ECMA 1 and ECMA 2.0 based MA&amp;rsquo;s. That is they may not run returning &amp;ldquo;stopped-extension-dll-load&amp;rdquo; There are workarounds published in the article.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Movie Review of Home -- or how IDM could have saved the day.</title>
      <link>https://identitymanaged.com/2015/04/movie-review-of-home-or-how-idm-could.html</link>
      <pubDate>Wed, 08 Apr 2015 08:42:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/04/movie-review-of-home-or-how-idm-could.html</guid>
      <description>&lt;p&gt;Over the weekend I took one of my children to see the new animated film  Home starring Jim Parsons, Rihanna, Steve Martin and Jennifer Lopez. A group of technically superior but very cowardly aliens, called the Boov flee from their implacable enemy, the Gorgs, and decide to take over Earth, relocating all of the primitive natives (us) to Australia. Aside from the political commentary of the entire human race being placed in a reservation, the thing that most struck me was how one of the near disasters could have been averted through solid Identity Management Systems. A hapless and lonely Boov, named &amp;ldquo;Oh&amp;rdquo; invited his new neighbors to a &amp;ldquo;warming of house party.&amp;rdquo; When no one showed, he sought out other acquaintances to invite and sent out an Evite ™ but he accidently did a Send All, which somehow included their implacable enemy. Great hilarity ensues as the evite will take 40 hrs to reach their enemy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Portable 2nd Monitor for the Surface Pro 3 ( and TwoMonUSB issues)</title>
      <link>https://identitymanaged.com/2015/03/portable-2nd-monitor-for-surface-pro-3-comments.html</link>
      <pubDate>Wed, 11 Mar 2015 09:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/03/portable-2nd-monitor-for-surface-pro-3-comments.html</guid>
      <description>&lt;h4 id=&#34;thanks-for-the-awesome-post-and-the-specifications&#34;&gt;Thanks for the awesome post and the specifications&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/07300921410305199561&#34; title=&#34;noreply@blogger.com&#34;&gt;John Smith&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jun 4, 2015&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks for the awesome post and the specifications.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.facebook.com/macmoestore/posts/968687033171171&#34;&gt;AOC Portable Monitor&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Hi thanlks for a great review. I have bought same AOC monitor but can not get it to work from the USB port on the SP3? It works OK off the MS hub but just flashes with the USB port on the actual SP3 itself. Did you have to install the DisplayLink software and if so which version? Thanks&lt;/p&gt;</description>
    </item>
    <item>
      <title>Portable 2nd Monitor for the Surface Pro 3 ( and TwoMonUSB issues)</title>
      <link>https://identitymanaged.com/2015/03/portable-2nd-monitor-for-surface-pro-3.html</link>
      <pubDate>Wed, 11 Mar 2015 09:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/03/portable-2nd-monitor-for-surface-pro-3.html</guid>
      <description>&lt;p&gt;As a road warrior, often in different settings, I am interested in a 2nd, portable monitor for my Surface Pro 3. So here was my thought process.&lt;/p&gt;&#xA;&lt;p&gt;I tried to use TwoMonUSB to make my iPad the second monitor. At first it worked quite well. Great idea, a backup device with some apps I don&amp;rsquo;t have on the surface and I can use it as a second screen. But then my Surface Pro 3 was rebooting randomly during idle times or the screen wouldn&amp;rsquo;t light up after an idle timeout and then I would have to hard boot it. I was getting a bugcheck almost daily, sometimes multiple times a day. So after Refreshing the PC I decided that the $10 app approach wasn&amp;rsquo;t going to work. I am not certain that it was TwoMonUSB but it seems the likely candidate.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Escaping an AD Replication Island</title>
      <link>https://identitymanaged.com/2015/03/escaping-ad-replication-island.html</link>
      <pubDate>Sat, 07 Mar 2015 09:07:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/03/escaping-ad-replication-island.html</guid>
      <description>&lt;p&gt;On a dark and stormy night an Active Directory upgrade was underway, Windows Server 2003 domain controllers decommissioned, consolidated and replaced with Window Server 2008 R2 servers. Suddenly I got a call from those doing the upgrade, &amp;ldquo;I can&amp;rsquo;t see some of the new domain controllers on the existing domain controllers, what&amp;rsquo;s wrong?&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;A replication island had been created and several domain controllers were trapped on it. Could we rescue them in time?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Follow up #1 on How does Identity Management Impact the Bottom Line? Selling IDM</title>
      <link>https://identitymanaged.com/2015/02/follow-up-1-on-how-does-identity.html</link>
      <pubDate>Mon, 02 Feb 2015 09:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/02/follow-up-1-on-how-does-identity.html</guid>
      <description>&lt;p&gt;In my presentation last week at #OCGUS15 The Redmond Summit put on by my friends at OCG, on &amp;ldquo;How does Identity Management Impact the Bottom Line? Selling IDM&amp;rdquo; I illustrated how understanding more about Financial statements such as &lt;a href=&#34;http://www.investopedia.com/articles/04/022504.asp&#34;&gt;Profit/Loss statements&lt;/a&gt; as well as &lt;a href=&#34;http://www.investopedia.com/articles/04/031004.asp&#34;&gt;Balance Sheets&lt;/a&gt; can be helpful. So here is a link to learn more:&lt;/p&gt;&#xA;&lt;p&gt;•&lt;a href=&#34;http://www.investopedia.com/articles/basics/06/financialreporting.asp&#34;&gt;http://www.investopedia.com/articles/basics/06/financialreporting.asp&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Among other things this is helpful to be able to articulate how your projects and programs can impact the bottom line such as how User provisioning/Deprovisioning impacts the Profit and Loss Statement:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Redmond Summit 2015</title>
      <link>https://identitymanaged.com/2015/01/redmond-summit-2015.html</link>
      <pubDate>Wed, 28 Jan 2015 14:21:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2015/01/redmond-summit-2015.html</guid>
      <description>&lt;p&gt;I am looking forward to presenting in an hour or so on &amp;ldquo;How Identity Management Impacts the bottom line.&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;Yesterday I had fun delivering a session on &amp;ldquo;ADFS vs Password Sync? It depends&amp;rdquo; This morning Alex Simons of Microsoft revealed a few new things that change some of my advice.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;Soon Azure AD can do the location restriction by application for SSO. This potentially eliminates a deal breaker for some people&lt;/li&gt;&#xA;&lt;li&gt;You can now run Password Sync and ADFS at the same time.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Both of which make it more likely that you will do Password Sync. The second one makes it more likely that you will run both because Password Sync can be a warm standby for failing over from ADFS.&lt;/p&gt;</description>
    </item>
    <item>
      <title>&#39;Twas the night before Christmas </title>
      <link>https://identitymanaged.com/2014/12/twas-night-before-christmas.html</link>
      <pubDate>Wed, 24 Dec 2014 18:34:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/12/twas-night-before-christmas.html</guid>
      <description>&lt;p&gt;&amp;lsquo;Twas the night before Christmas, when all through the internet&lt;br&gt;&#xA;Not an identity was stirring, not even a Passport .NET&lt;br&gt;&#xA;The user accounts requests were submitted with care&lt;br&gt;&#xA;Hoping that their access would soon be there&lt;/p&gt;&#xA;&lt;p&gt;The users were nestled all snug in their beds&lt;br&gt;&#xA;While visions of being able to do their jobs danced in their heads&lt;br&gt;&#xA;The servers and computers were in sleep mode&lt;br&gt;&#xA;Awaiting someone to move a mouse and send the wake up code&lt;/p&gt;</description>
    </item>
    <item>
      <title>Speaking at 2015 Redmond Summit (Jan 27-29 &#39;15)</title>
      <link>https://identitymanaged.com/2014/12/speaking-at-2015-redmond-summit-jan-27.html</link>
      <pubDate>Fri, 12 Dec 2014 13:57:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/12/speaking-at-2015-redmond-summit-jan-27.html</guid>
      <description>&lt;p&gt;I will be speaking at the 2015 Redmond Summit: Where Identity Meets Enterprise Mobility.&lt;br&gt;&#xA;This summit is put on by my friends at Oxford Computer Group.&lt;/p&gt;&#xA;&lt;p&gt;I will be speaking on Password Sync vs.  ADFS. Then the next day I will speak on the Business track about How Identity Management Impacts the Bottom Line.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://oxfordcomputergroup.com/us/summit/&#34;&gt;See you there&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;January 27-29, 2015 in Redmond, WA on the Microsoft Campus&lt;/p&gt;&#xA;&lt;p&gt;Join OCG, Microsoft, and industry experts for two and a half days of networking and talks on the latest thinking on identity and enterprise mobility. If you’re overwhelmed by devices, have a hybrid environment, wish to simplify access, or manage identity in an increasingly complex digital world then you won’t want to miss this event. Sessions will assess and look in detail at the largest release of new identity products in Microsoft’s history, including Enterprise Mobility Suite, Intune, Azure Active Directory, Hybrid Identity, and more! Discover how other organizations have tackled the same problems you face through case studies and get technical insight from Microsoft product managers and engineers. Registration is $800 per delegate. &lt;a href=&#34;http://oxfordcomputergroup.com/us/summit/&#34;&gt;Find our more and register!&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>What AD Attributes are indexed? ANR? Tuple? PowerShell</title>
      <link>https://identitymanaged.com/2014/12/what-ad-attributes-are-indexed-anr.html</link>
      <pubDate>Thu, 04 Dec 2014 11:50:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/12/what-ad-attributes-are-indexed-anr.html</guid>
      <description>&lt;p&gt;Import-Module ActiveDirectory&lt;br&gt;&#xA;Write-Host &amp;ldquo;Tuple Index Enabled Attributes&amp;rdquo;&lt;br&gt;&#xA;Get-ADObject -SearchBase ((Get-ADRootDSE).schemaNamingContext)  -SearchScope OneLevel -LDAPFilter &amp;ldquo;(searchFlags:1.2.840.113556.1.4.803:=32)&amp;rdquo; -Property objectClass, name, whenChanged,  whenCreated, LDAPDisplayNAme  | Out-GridView&lt;br&gt;&#xA;Write-Host &amp;ldquo;ANR Enabled Attributes&amp;rdquo;&lt;br&gt;&#xA;Get-ADObject -SearchBase ((Get-ADRootDSE).schemaNamingContext)  -SearchScope OneLevel -LDAPFilter &amp;ldquo;(searchFlags:1.2.840.113556.1.4.803:=4)&amp;rdquo; -Property objectClass, name, whenChanged,  whenCreated, LDAPDisplayNAme | Out-GridView&lt;br&gt;&#xA;Write-Host &amp;ldquo;Indexed Enabled Attributes&amp;rdquo;&lt;br&gt;&#xA;Get-ADObject -SearchBase ((Get-ADRootDSE).schemaNamingContext)  -SearchScope OneLevel -LDAPFilter &amp;ldquo;(searchFlags:1.2.840.113556.1.4.803:=1)&amp;rdquo; -Property objectClass, name, whenChanged,  whenCreated, LDAPDisplayNAme  | Out-GridView&lt;/p&gt;&#xA;&lt;p&gt;The above script is something I use to quickly look and see what is indexed in an AD environment&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Maintenance for FIM and anything other databases</title>
      <link>https://identitymanaged.com/2014/10/sql-maintenance-for-fim-and-anything.html</link>
      <pubDate>Fri, 24 Oct 2014 17:36:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/10/sql-maintenance-for-fim-and-anything.html</guid>
      <description>&lt;p&gt;An easy way to take care for your FIM databases is to &amp;ldquo;use Ola Hallengren&amp;rsquo;s script (&lt;a href=&#34;http://ola.hallengren.com/scripts/MaintenanceSolution.sql&#34;&gt;http://ola.hallengren.com/scripts/MaintenanceSolution.sql&lt;/a&gt;). Download the script, adjust the backup paths and run the script on each instance of SQL Server. It will automatically create several jobs some for maintaining the system databases and some for maintain the user databases. You will need to create schedules for each of the jobs.&amp;rdquo; &amp;ndash; FIM Best Practices Volume 1&lt;/p&gt;&#xA;&lt;p&gt;I love using Ola script for index maintenance because it is so much smart than the Database Maintenance wizard which wants to spend lots of time rebuilding indexes that only needed to be reorganized and messing with indexes that were just fine or too small to matter. A table with less than 1000 pages is usually too small to matter. Less than 5% fragmentation and why bother. Less than 20% and a reorg will usually solve it. Over 20% and you should usually rebuild.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mistaken Identity</title>
      <link>https://identitymanaged.com/2014/10/mistaken-identity.html</link>
      <pubDate>Fri, 03 Oct 2014 12:03:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/10/mistaken-identity.html</guid>
      <description>&lt;p&gt;Years ago, I walked into the client site a few months into an Identity Management project, and the PM told me his account had been deactivated by mistake as an employee with the same last name and same first initial was terminated, and they termed his account by mistake.&lt;/p&gt;&#xA;&lt;p&gt;Ironic.&lt;/p&gt;&#xA;&lt;p&gt;A few years before that I visited a client whose VP of HR had his account disabled when they let the janitor go. Again same last name but this time the same first name.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Phoenix MVP Roadshow Transform the DataCenter Wed Sept 24 4 PM-8PM</title>
      <link>https://identitymanaged.com/2014/09/phoenix-mvp-roadshow-transform.html</link>
      <pubDate>Tue, 16 Sep 2014 12:19:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/09/phoenix-mvp-roadshow-transform.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://msevents.microsoft.com/CUI/EventDetail.aspx?EventID=1032595074&amp;amp;Culture=en-US&amp;amp;community=1&#34;&gt;Register Now! to attend MVP Roadshow&lt;/a&gt; Sept 24th 4 PM - 8PM&lt;/p&gt;&#xA;&lt;p&gt;I will be presenting on why we want to get to Active Directory based on Windows Server 2012 R2 and how to get there. My fellow MVP&amp;rsquo;s will be covering the rest of the agenda. I also created an IT clue game to play in small groups where the objective is to figure out who stole the data and how it could have been prevented.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ADUC Common Queries: Days Since Last Logon</title>
      <link>https://identitymanaged.com/2014/09/aduc-common-queries-days-since-last.html</link>
      <pubDate>Tue, 16 Sep 2014 12:08:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/09/aduc-common-queries-days-since-last.html</guid>
      <description>&lt;p&gt;Recently a client asked me how Active Directory Users and Computers (ADUC) performs the Days Since Last Logon query found in the Find Dialog box&amp;rsquo;s Common Queries option.&lt;/p&gt;&#xA;&lt;p&gt;LastLogon is not replicated so to really get it you have to query every single DC. So I was reasonably certain that the query didn&amp;rsquo;t use LastLogon but rather used the &lt;a href=&#34;http://blogs.technet.com/b/askds/archive/2009/04/15/the-lastlogontimestamp-attribute-what-it-was-designed-for-and-how-it-works.aspx&#34;&gt;LastLogonTimestamp&lt;/a&gt; which was created &amp;ldquo;to help identify inactive computer and user accounts.&amp;rdquo;  Assuming default settings &amp;ldquo;the &lt;em&gt;lastLogontimeStamp&lt;/em&gt; will be 9-14 days behind the current date.&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Happy Independence Day -- Using PowerShell for Reporting</title>
      <link>https://identitymanaged.com/2014/07/happy-independence-day-using-powershell.html</link>
      <pubDate>Fri, 04 Jul 2014 15:06:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/07/happy-independence-day-using-powershell.html</guid>
      <description>&lt;p&gt;Unfortunately, my Independence day is not free &amp;ndash; I am working. Just so happens I need to report on when computer objects are getting migrated to a new AD forest. Day 1 4 Day 2 30 Day 3 25 etc.&lt;/p&gt;&#xA;&lt;p&gt;Now I could have taken the data and imported it into SQL and then busted out some awesome queries in no time flat. But my buddy Craig Martin, keeps insisting how awesome this PowerShell stuff is. So I decided to give it a try, plus if I can get it to work then it will be faster to run this repeatedly from PowerShell rather than needing to import it into SQL Server. I am actually a big believer in using the right tool for the job. Otherwise you end up blaming the tool for failing you when you should have picked a different tool, one better suited for your task.&lt;/p&gt;</description>
    </item>
    <item>
      <title>8 Time MVP</title>
      <link>https://identitymanaged.com/2014/07/8-time-mvp.html</link>
      <pubDate>Tue, 01 Jul 2014 08:44:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/07/8-time-mvp.html</guid>
      <description>&lt;p&gt;Today I received notification that for the 8th time (2007, 2008, 2009, 2010, 2011, 2012, 2013, 2014) I have been honored by Microsoft as a Microsoft Most Valuable Professional (MVP). According to the MVP web site there are currently 10 Identity Management MVP&amp;rsquo;s in the world, and only three in North America.&lt;/p&gt;&#xA;&lt;p&gt;Looking forward to the on-going journey with this product set and wonderful friends I have made along the way, product group members (past and present), MVP&amp;rsquo;s (past and present), readers (book, blog, twitter) and other Identity Management professionals.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Projects and Heisenberg&#39;s Uncertainty Principle</title>
      <link>https://identitymanaged.com/2014/06/projects-and-heisenbergs-uncertainty-comments.html</link>
      <pubDate>Tue, 24 Jun 2014 11:15:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/06/projects-and-heisenbergs-uncertainty-comments.html</guid>
      <description>&lt;h4 id=&#34;good-analogy---i-might-try-that-one-next-time-i&#34;&gt;Good analogy - I might try that one next time. I&amp;amp;#&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/06215045052400009812&#34; title=&#34;noreply@blogger.com&#34;&gt;Carol Wapshere&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 4, 2014&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Good analogy - I might try that one next time. I&amp;rsquo;ve had a stressful few weeks with a barrage of last-minute solution changes along with demands for documentation inclusive of the changes&amp;hellip; A couple of times I&amp;rsquo;ve had to say &amp;ldquo;which do you want right now? The changes or the documentation? Because I can only do one thing at a time!&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Projects and Heisenberg&#39;s Uncertainty Principle</title>
      <link>https://identitymanaged.com/2014/06/projects-and-heisenbergs-uncertainty.html</link>
      <pubDate>Tue, 24 Jun 2014 11:15:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/06/projects-and-heisenbergs-uncertainty.html</guid>
      <description>&lt;p&gt;Is it done yet? What&amp;rsquo;s the status? How much longer? If I get asked these questions too often on a project I take a moment to explain about Heisenberg&amp;rsquo;s Uncertainty Principle. Which states states that you can&amp;rsquo;t know both the position and velocity of an electron because in measuring the one you alter the other.&lt;/p&gt;&#xA;&lt;p&gt;The old saying goes &amp;ldquo;a watched pot never boils,&amp;rdquo; especially if you keep sticking  a new thermometer into a heating pot of water every two seconds. Observations change the system. Frequent observations can change it even more.&lt;/p&gt;</description>
    </item>
    <item>
      <title>To Farm, or not to Farm, that is the question --</title>
      <link>https://identitymanaged.com/2014/05/to-farm-or-not-to-farm-that-is-question-comments.html</link>
      <pubDate>Thu, 01 May 2014 12:37:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/05/to-farm-or-not-to-farm-that-is-question-comments.html</guid>
      <description>&lt;h4 id=&#34;in-some-environments-like-government-having-that&#34;&gt;In some environments, like government, having that&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/02468754628550304845&#34; title=&#34;noreply@blogger.com&#34;&gt;REALHIPHOPINYOURLIFE&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;May 5, 2014&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;In some environments, like government, having that local SQL means a whole different security profile&amp;hellip;a lot of security groups aren&amp;rsquo;t going to make a distinction between that local SQL and Full Blown SQL when they scan the system since they use some of the same binaries.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Good comment. So in those environments that could be an extra reason to farm to avoid local SQL and the extra security&lt;/p&gt;</description>
    </item>
    <item>
      <title>To Farm, or not to Farm, that is the question --</title>
      <link>https://identitymanaged.com/2014/05/to-farm-or-not-to-farm-that-is-question.html</link>
      <pubDate>Thu, 01 May 2014 12:37:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/05/to-farm-or-not-to-farm-that-is-question.html</guid>
      <description>&lt;ul&gt;&#xA;&lt;li&gt;Whether &amp;rsquo;tis nobler in the mind to suffer&lt;/li&gt;&#xA;&lt;li&gt;the slings and arrows of outrageous fortune&lt;/li&gt;&#xA;&lt;li&gt;Or to take &lt;strong&gt;Farms&lt;/strong&gt; against a sea of &lt;strong&gt;patches&lt;/strong&gt;&lt;/li&gt;&#xA;&lt;li&gt;and by opposing end them? To, die, to sleep &amp;ndash;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Today I will be &amp;ldquo;moderating&amp;rdquo; the debate about using SharePoint Farms vs. Stand-Alone as the foundation for the FIM Portal. In this corner we have &lt;a href=&#34;http://blog.msresource.net/&#34;&gt;Paul Williams of Microsoft&lt;/a&gt; sharing knowledge from &lt;a href=&#34;http://blog.msresource.net/2013/05/15/fim-portal-in-a-sharepoint-farmwhy-you-should-not-do-this/&#34;&gt;his hard fought victories with FIM&lt;/a&gt; and &lt;a href=&#34;http://blog.msresource.net/2013/05/16/editing-the-fim-portal-web-config-in-a-farm-topology/&#34;&gt;painful experiences with Farms&lt;/a&gt;. In the other corner we have &lt;a href=&#34;http://www.harbar.net/&#34;&gt;Spencer Harbar&lt;/a&gt;, SharePoint MVP, applying his years of &lt;a href=&#34;http://www.harbar.net/articles/fimportal.aspx&#34;&gt;SharePoint expertise to the FIM world&lt;/a&gt; providing a &lt;a href=&#34;http://www.harbar.net/articles/fimportal.aspx&#34;&gt;definitive guide to installing FIM 2012 R2 SP1 portal on SharePoint 2013&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIM&#39;s the word -- New name for FIM</title>
      <link>https://identitymanaged.com/2014/04/mim-word-new-name-for-fim.html</link>
      <pubDate>Wed, 30 Apr 2014 14:47:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/04/mim-word-new-name-for-fim.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://blogs.technet.com/b/server-cloud/archive/2014/04/23/forefront-identity-manager-vnext-roadmap-now-microsoft-identity-manager.aspx&#34;&gt;Last week the Product group announced the new name for FIM and MIM&amp;rsquo;s the word&lt;/a&gt; Microsoft Identity Manager.&lt;/p&gt;&#xA;&lt;p&gt;Of course as a good futurist I had made enough guesses that I got &lt;a href=&#34;http://blog.ilmbestpractices.com/2013/07/the-mvp-7-year-itch.html?m=1&#34;&gt;this one right&lt;/a&gt;, even though as an honest man I must admit &lt;a href=&#34;http://blog.ilmbestpractices.com/2014/04/new-name-for-fim.html&#34;&gt;I also had it wrong&lt;/a&gt; &amp;ndash; Azure is not part of the name.&lt;/p&gt;&#xA;&lt;p&gt;Fortunately, they didn&amp;rsquo;t go with APE nor AILMENT, nor MIME, nor MIAMI, nor MICE, nor MAIM, nor WIMP. MIM&amp;rsquo;s the word!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Mailbag: Learning FIM, SQL and IIS</title>
      <link>https://identitymanaged.com/2014/04/mailbag-learning-fim-sql-and-iis.html</link>
      <pubDate>Fri, 18 Apr 2014 17:21:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/04/mailbag-learning-fim-sql-and-iis.html</guid>
      <description>&lt;p&gt;Recently, a reader reached out to me for advice on learning FIM, SQL and IIS. As well as guidance on setting up a lab (more advice on that part in a later post).&lt;/p&gt;&#xA;&lt;p&gt;First think for a moment about your best learning styles for technology. Do you need to read the concepts and architecture first and then do it? Do you need to watch a video and then read, and then do it? Do you need to try it and then go back and read? Do you need an instructor? Sometimes you have to learn through experimentation. In the early days of ILM 2 Beta there wasn&amp;rsquo;t much info so we had to experiment. Brad Turner and I spent many days in a lab configuring and trying things out to see what was the best practice.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New name for FIM?</title>
      <link>https://identitymanaged.com/2014/04/new-name-for-fim-comments.html</link>
      <pubDate>Thu, 17 Apr 2014 08:29:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/04/new-name-for-fim-comments.html</guid>
      <description>&lt;h4 id=&#34;actually-its-mim-microsoft-identity-manager&#34;&gt;Actually it&amp;rsquo;s MIM (Microsoft Identity Manager)&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/14486405181820122799&#34; title=&#34;noreply@blogger.com&#34;&gt;Oliver Hanappi&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Apr 3, 2014&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Actually it&amp;rsquo;s MIM (Microsoft Identity Manager). See &lt;a href=&#34;http://blogs.technet.com/b/server-cloud/archive/2014/04/23/forefront-identity-manager-vnext-roadmap-now-microsoft-identity-manager.aspx&#34;&gt;http://blogs.technet.com/b/server-cloud/archive/2014/04/23/forefront-identity-manager-vnext-roadmap-now-microsoft-identity-manager.aspx&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Like any good futurist I guessed so many things that one of them was bound to be right &lt;a href=&#34;http://blog.ilmbestpractices.com/2013/07/the-mvp-7-year-itch.html?m=1&#34;&gt;http://blog.ilmbestpractices.com/2013/07/the-mvp-7-year-itch.html?m=1&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>New name for FIM?</title>
      <link>https://identitymanaged.com/2014/04/new-name-for-fim.html</link>
      <pubDate>Thu, 17 Apr 2014 08:29:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/04/new-name-for-fim.html</guid>
      <description>&lt;p&gt;Did you know that if you subscribe to &lt;a href=&#34;http://windowsitpro.com/identity-management/overview-microsoft-azure-active-directory-premium&#34;&gt;Azure AD Premium you also get licenses for FIM&lt;/a&gt;? Well if that isn&amp;rsquo;t a hand tipper I don&amp;rsquo;t know what is. I think we can safely assume the next version of FIM will have Azure in the name. Safe or not I am going speculate that it will.&lt;/p&gt;&#xA;&lt;p&gt;Azure Identity Manager (AIM) &amp;ndash; I would be ok with this&lt;br&gt;&#xA;Azure Role Based Access Manager (ARBAM) &amp;ndash; Explosive sounding name&lt;br&gt;&#xA;Azure Provisioning Engine (APE) &amp;ndash; Please no!!&lt;br&gt;&#xA;Azure Identity Technology (AIT) &amp;ndash; pronounced 8 or aight. Nah.&lt;br&gt;&#xA;Azure Identity Sync Lifecycle Engine (AISLE) &amp;ndash; Certainly when people walk down the aisle they have an identity changing event.&lt;br&gt;&#xA;Azure Identity Lifecycle Management Engine Next Technology (AILMENT). I really hope not we want to cure ailments not install one for you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Hints of FIM&#39;s Future: Azure Active Directory (AAD) Sync</title>
      <link>https://identitymanaged.com/2014/04/hints-of-fims-future-azure-active.html</link>
      <pubDate>Thu, 17 Apr 2014 08:19:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/04/hints-of-fims-future-azure-active.html</guid>
      <description>&lt;p&gt;For years I have been trying to predict the future of Identity Management, but every time I look in my crystal ball it is just too cloudy to see anything. In fact anytime I look in my crystal ball on just about any technology topic the only thing it shows me are clouds! I was beginning to think it was broken.&lt;/p&gt;&#xA;&lt;p&gt;But then, yesterday, I watched Andreas Kjellman present at the FIM user group&lt;br&gt;&#xA;Andreas unveiled the AADSync, the Azure Active Directory Sync that will replace DirSync to sync from your Active Directory to the cloud. I finally got it! My crystal ball wasn&amp;rsquo;t broken!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Good RID(ance, I mean issuance)</title>
      <link>https://identitymanaged.com/2014/04/good-ridance-i-mean-issuance.html</link>
      <pubDate>Wed, 16 Apr 2014 08:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2014/04/good-ridance-i-mean-issuance.html</guid>
      <description>&lt;p&gt;As we know a SID is 12 Bytes long or 96 bits long and is composed of several components, among them the domain identifier and the relative identifier or RID of a particular object. The RID is 30 bits long which means you have approximately 1 billion RIDs. So while you think it is unlikely that you will run out of RIDs, according to &lt;a href=&#34;http://technet.microsoft.com/en-us/library/jj574229.aspx&#34;&gt;http://TechNet.microsoft.com/en-us/library/jj574229.aspx&lt;/a&gt; you can encountering this if you have accidentally used scripts or provisioning tools (like FIM) to shoot your self in the foot and create gobs and gobs of users, you let some end-user go out of control creating waaaay too many groups, you increased the RID pool size to be too big, did lots of DC demotion and promotion, cleanups, forest recoveries or invalidated RID pools.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Deprecated Features FIM TEAM user group meeting</title>
      <link>https://identitymanaged.com/2013/11/fim-deprecated-features-fim-team-user.html</link>
      <pubDate>Wed, 13 Nov 2013 12:41:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/11/fim-deprecated-features-fim-team-user.html</guid>
      <description>&lt;p&gt;So in 1 hr and 20 min I will present on&lt;/p&gt;&#xA;&lt;p&gt;November 13, 2013 21:00 UTC&lt;br&gt;&#xA;&lt;a href=&#34;http://www.timeanddate.com/worldclock/fixedtime.html?msg=The+FIM+Team+User+Group+November+Meeting&amp;amp;iso=20131114T08&amp;amp;p1=57&amp;amp;ah=1&#34;&gt;See when this is in your timezone&lt;/a&gt;&lt;br&gt;&#xA;David Lundell&lt;br&gt;&#xA;Impact of deprecated features.This session will go over various deprecated features that the FIM product group have announced are to be eliminated in future releases, such as XMA v1 (ECMA v1), transaction properties, multi-mastery and equal precedence, with advice on planning for and working around their future absence.&lt;/p&gt;</description>
    </item>
    <item>
      <title>DirSync w/ domain if NetBios and FQDN don&#39;t match</title>
      <link>https://identitymanaged.com/2013/10/dirsync-w-domain-if-netbios-and-fqdn.html</link>
      <pubDate>Fri, 04 Oct 2013 16:14:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/10/dirsync-w-domain-if-netbios-and-fqdn.html</guid>
      <description>&lt;p&gt;If one of your AD domains has a NetBios domain name that doesn&amp;rsquo;t match the leftmost part of your FQDN you need to have the Replicating Directory Changes permission given to your AD MA account. This is documented in a few places including my book. However, DirSync misses this step. Normally, Dirsync does a very good job of installing and configuring everything which you need without needing you to be an expert in FIM, but this is one thing it misses.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Declarative or Bust!</title>
      <link>https://identitymanaged.com/2013/10/declarative-or-bust-comments.html</link>
      <pubDate>Fri, 04 Oct 2013 15:55:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/10/declarative-or-bust-comments.html</guid>
      <description>&lt;h4 id=&#34;i-see-two-challenges-1-there-is-not-feature-pari&#34;&gt;I see two challenges: 1. There is not feature pari&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/09808879680127031778&#34; title=&#34;noreply@blogger.com&#34;&gt;Craig Martin&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Oct 3, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;I see two challenges:&lt;br&gt;&#xA;1. There is not feature parity between the two types of sync rules&lt;br&gt;&#xA;2. The imperative support (VBA) in the new sync rules is limited and difficult to debug&lt;/p&gt;&#xA;&lt;p&gt;My wish is that we had better extensibility in the new sync rules (scrap VBA, or figure out how to improve the extensibility and debugging).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Declarative or Bust!</title>
      <link>https://identitymanaged.com/2013/10/declarative-or-bust.html</link>
      <pubDate>Fri, 04 Oct 2013 15:55:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/10/declarative-or-bust.html</guid>
      <description>&lt;p&gt;Michael Pearn from down under wrote about his &lt;a href=&#34;http://blog.kloud.com.au/2013/10/04/fim-case-study-trying-to-achieve-a-100-declarative-or-codeless-architecture/&#34;&gt;experience trying to use just Declarative Sync Rules&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;His experience &amp;ndash; especially the religious debates are similar to my own. It made me recall my presentation at TEC 2012 the FIM 2010 R2 Showdown: Classic vs. Declarative&lt;/p&gt;&#xA;&lt;p&gt;The vast majority of old hands at the presentation declared for Classic both before and after the presentation. During the presentation I attempted to view anything you could do without code as declarative whether it came from a sync rule or not, especially if it was a new feature. But the crowd wouldn&amp;rsquo;t let me claim anything configured in the sync engine as declarative. But in this post only classic code counts as not declarative.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Windows 2012 R2 and Windows 8.1 RTM now on MSDN and Technet</title>
      <link>https://identitymanaged.com/2013/09/windows-2012-r2-and-windows-81-rtm-now.html</link>
      <pubDate>Wed, 11 Sep 2013 13:11:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/09/windows-2012-r2-and-windows-81-rtm-now.html</guid>
      <description>&lt;p&gt;One of my fellow MVPs and Insight teammates Alessandro Cardoso (he runs one of our practices down under) announced on his blog that &lt;a href=&#34;http://cloudtidings.com/2013/09/10/windows-2012-r2-and-windows-8-1-released-to-msdn-and-technet-subscriptions/#!&#34;&gt;Windows 2012 R2 and Windows 8.1 RTM now on MSDN and Technet&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;He goes on to mention the salient points around 2012 R2 for virtualization so I thought I would discuss some of the benefits for &lt;a href=&#34;http://technet.microsoft.com/en-us/library/dn268294(v=ws.11)&#34;&gt;Active Directory and ADFS&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;One key thing is that ADFS on Windows Server 2012 R2 doesn&amp;rsquo;t require IIS so now it can and should be installed on domain controllers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MS13-066 causes ADFS 2.0 problems</title>
      <link>https://identitymanaged.com/2013/08/ms13-066-causes-adfs-20-problems.html</link>
      <pubDate>Thu, 15 Aug 2013 08:55:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/08/ms13-066-causes-adfs-20-problems.html</guid>
      <description>&lt;p&gt;Microsoft put out a release day before yesterday (8/13/13) to fix a security vulnerability in ADFS 2.0&lt;/p&gt;&#xA;&lt;p&gt;It caused an outage for SSO with Office365 for a customer of ours (they had the servers set to auto update).&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://technet.microsoft.com/en-us/security/bulletin/ms13-066&#34;&gt;http://technet.microsoft.com/en-us/security/bulletin/ms13-066&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://support.microsoft.com/kb/2843639&#34;&gt;http://support.microsoft.com/kb/2843639&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://support.microsoft.com/kb/2843638&#34;&gt;http://support.microsoft.com/kb/2843638&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;At the moment we recommend NOT installing these updates.&lt;/p&gt;&#xA;&lt;p&gt;We saw the following error repeated for every authentication attempt:&lt;/p&gt;&#xA;&lt;p&gt;Event ID 111 Federation service encountered an error while processing the ws-trust request.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is the Password dead? Gotta eat what you kill!</title>
      <link>https://identitymanaged.com/2013/07/is-password-dead-gotta-eat-what-you-kill.html</link>
      <pubDate>Mon, 08 Jul 2013 08:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/07/is-password-dead-gotta-eat-what-you-kill.html</guid>
      <description>&lt;p&gt;At last year&amp;rsquo;s Cloud Identity Summit in Vail I heard a lot about how the password is dead. I expect to hear a lot more this year.&lt;/p&gt;&#xA;&lt;p&gt;Most of it fit into one of several categories:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Complaints about why passwords should be dead&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;In other words all of the various problems with passwords &amp;ndash; and there are&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Schemes to have various applications depend on someone else&amp;rsquo;s password&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;While this is helpful it doesn&amp;rsquo;t kill the password&lt;/p&gt;</description>
    </item>
    <item>
      <title>The MVP 7 year itch</title>
      <link>https://identitymanaged.com/2013/07/the-mvp-7-year-itch-comments.html</link>
      <pubDate>Mon, 01 Jul 2013 09:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/07/the-mvp-7-year-itch-comments.html</guid>
      <description>&lt;h4 id=&#34;congratz-david&#34;&gt;Congratz, David&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/08267883246883901938&#34; title=&#34;noreply@blogger.com&#34;&gt;Søren Granfeldt&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 1, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Congratz, David&amp;hellip;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>The MVP 7 year itch</title>
      <link>https://identitymanaged.com/2013/07/the-mvp-7-year-itch.html</link>
      <pubDate>Mon, 01 Jul 2013 09:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/07/the-mvp-7-year-itch.html</guid>
      <description>&lt;p&gt;This morning I received an email letting me know that for the 7th time (every year since 2007) I have been honored by Microsoft with the Microsoft Most Valuable Professional (MVP) Award. All 7 times I have received the award for my &amp;ldquo;outstanding contributions in Forefront Identity Manager technical communities&amp;rdquo; and its predecessors.&lt;/p&gt;&#xA;&lt;p&gt;In 2007 despite the product rename Identity Lifecycle Manager (ILM) 2007 the MVP award was for Microsoft Identity Integration Server (MIIS) 2003. By 2008 it was changed to ILM, in 2010 it was changed to FIM.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Implications of Office 365 Password Sync for ADFS (SSO)</title>
      <link>https://identitymanaged.com/2013/06/implications-of-office-365-password-comments.html</link>
      <pubDate>Wed, 26 Jun 2013 07:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/06/implications-of-office-365-password-comments.html</guid>
      <description>&lt;h4 id=&#34;nice-recap-on-the-implications-of-office-365s&#34;&gt;Nice recap on the implications of Office 365&amp;rsquo;s&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/15780725194112690512&#34; title=&#34;noreply@blogger.com&#34;&gt;@binarybrewery&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jun 4, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Nice recap on the implications of Office 365&amp;rsquo;s Password Sync and why you may still need ADFS.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Implications of Office 365 Password Sync for ADFS (SSO)</title>
      <link>https://identitymanaged.com/2013/06/implications-of-office-365-password.html</link>
      <pubDate>Wed, 26 Jun 2013 07:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/06/implications-of-office-365-password.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://technet.microsoft.com/en-us/library/dn246918.aspx&#34;&gt;The article on Password Sync for Office 365&lt;/a&gt; is interesting news and clearly states that Federated users can&amp;rsquo;t have their password&amp;rsquo;s synced. In the Community Additions many curious users asked their questions treating it as a forum. Well here are my responses:&lt;/p&gt;&#xA;&lt;p&gt;If you do Password Sync do you still need ADFS or any other SSO tool that works with Office365? &lt;/p&gt;&#xA;&lt;p&gt;Password Sync gives you the ability to login to Office365 using the same username and password that you use with your Active Directory. This is usually referred to as Simplified SignOn or Reduced SignOn. &lt;/p&gt;</description>
    </item>
    <item>
      <title>How to get from the Sync-Rule-ID to the Sync Rule Resource ID</title>
      <link>https://identitymanaged.com/2013/05/how-to-get-from-sync-rule-id-to-sync-comments.html</link>
      <pubDate>Wed, 01 May 2013 12:03:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/05/how-to-get-from-sync-rule-id-to-sync-comments.html</guid>
      <description>&lt;h4 id=&#34;thanks-david-you-had-the-knowledge-answered-my-&#34;&gt;Thanks, David. You had the knowledge, answered my &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/15296851519869737050&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;May 3, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks, David. You had the knowledge, answered my forum question and blogged about it as well. Nice work.&lt;/p&gt;&#xA;&lt;p&gt;PeteA&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>How to get from the Sync-Rule-ID to the Sync Rule Resource ID</title>
      <link>https://identitymanaged.com/2013/05/how-to-get-from-sync-rule-id-to-sync.html</link>
      <pubDate>Wed, 01 May 2013 12:03:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/05/how-to-get-from-sync-rule-id-to-sync.html</guid>
      <description>&lt;p&gt;If you are looking at the XML export of the FIM synchronization config and you are trying to track down which sync rule is supplying a particular flow you just need to know which numbers lead you where.&lt;/p&gt;&#xA;&lt;p&gt;For example:&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;The key to finding the Sync rule is of course the Sync rule ID. However, this is not the resource ID that I can search for in the FIM Portal. Rather this is the metaverse ID.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Functions Updated, Bitwise Functions</title>
      <link>https://identitymanaged.com/2013/04/fim-functions-updated-bitwise-functions.html</link>
      <pubDate>Fri, 12 Apr 2013 10:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/04/fim-functions-updated-bitwise-functions.html</guid>
      <description>&lt;p&gt;In addition to the &lt;a href=&#34;http://technet.microsoft.com/en-us/library/ff800820(WS.10).aspx&#34;&gt;official reference for functions&lt;/a&gt; I thought I would update &lt;a href=&#34;http://blog.ilmbestpractices.com/2009/01/ilm-2-functions-explained.html&#34;&gt;my examples from back in the ILM 2 Beta days&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Function Name&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;BitAnd&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Parameters&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;mask&lt;/strong&gt; Type: Integer&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;strong&gt;flag&lt;/strong&gt; Type: Integer&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Description&lt;/p&gt;&#xA;&lt;p&gt;BitAnd is a bitwise operation anding &lt;strong&gt;mask&lt;/strong&gt; and &lt;strong&gt;flag&lt;/strong&gt;. So if &lt;strong&gt;Flag&lt;/strong&gt; is the UserAccountControl Attribute in AD and &lt;strong&gt;mask&lt;/strong&gt; is **-3&lt;br&gt;&#xA;**(the 64-bit &lt;a href=&#34;http://mathforum.org/library/drmath/view/54344.html&#34;&gt;two&amp;rsquo;s complement&lt;/a&gt; of 2) Then the result is that the disable bit (bit 2) is turned off leaving all of the other bits unchanged.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Insight Cloud SSO Solution and FIM Jumpstart offerings</title>
      <link>https://identitymanaged.com/2013/03/insight-cloud-sso-solution-and-fim.html</link>
      <pubDate>Fri, 22 Mar 2013 15:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/03/insight-cloud-sso-solution-and-fim.html</guid>
      <description>&lt;p&gt;I wrote an article for the Insight Newsletter about two of our new offerings.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://cl.exct.net/?qs=4a5cccc49bcfcb371a80dfbe6ccebf797ddc3c7825a02908137ab51c297a3c27&#34;&gt;&lt;strong&gt;Solving identity and access management for mid-sized business&lt;/strong&gt;&lt;/a&gt;&lt;br&gt;&#xA;By David Lundell, Sr. Manager, Identity and Security Practice&lt;br&gt;&#xA;User productivity, IT budgets, and security and compliance all suffer from ineffective identity and access management. Insight has two new packages aimed at helping mid-sized businesses confront these challenges in the age of the cloud. &lt;a href=&#34;http://cl.exct.net/?qs=4a5cccc49bcfcb371a80dfbe6ccebf797ddc3c7825a02908137ab51c297a3c27&#34;&gt;Read more&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secrets of the Metaverse Part 5</title>
      <link>https://identitymanaged.com/2013/03/secrets-of-metaverse-part-5.html</link>
      <pubDate>Fri, 22 Mar 2013 15:42:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/03/secrets-of-metaverse-part-5.html</guid>
      <description>&lt;p&gt;Parts 1-5:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-1.html&#34;&gt;What is the Metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-2.html&#34;&gt;How is the Metaverse data stored?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-3.html&#34;&gt;Is there a limit to how many Metaverse attributes I can have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-4.html&#34;&gt;Has access to the metaverse gotten faster with recent releases?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-5.html&#34;&gt;How do I safely query the metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Added (Aug 5 2015): &lt;a href=&#34;http://blog.ilmbestpractices.com/2015/08/how-many-attributes-can-you-have-in.html&#34;&gt;How Many Metaverse Attributes can I have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;First of all the FIM Product group does not support direct modification of the data in any of the FIM databases. Do so can leave your database in a state that is entirely unsupportable.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secrets of the Metaverse Part 4</title>
      <link>https://identitymanaged.com/2013/03/secrets-of-metaverse-part-4.html</link>
      <pubDate>Mon, 11 Mar 2013 14:44:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/03/secrets-of-metaverse-part-4.html</guid>
      <description>&lt;p&gt;Parts 1-5:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-1.html&#34;&gt;What is the Metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-2.html&#34;&gt;How is the Metaverse data stored?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-3.html&#34;&gt;Is there a limit to how many Metaverse attributes I can have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-4.html&#34;&gt;Has access to the metaverse gotten faster with recent releases?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-5.html&#34;&gt;How do I safely query the metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Added (Aug 5 2015): &lt;a href=&#34;http://blog.ilmbestpractices.com/2015/08/how-many-attributes-can-you-have-in.html&#34;&gt;How Many Metaverse Attributes can I have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Has access to the metaverse gotten faster with recent releases? Well I won&amp;rsquo;t cover everything they have done but two really significant things:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secrets of the Metaverse Part 3</title>
      <link>https://identitymanaged.com/2013/02/secrets-of-metaverse-part-3.html</link>
      <pubDate>Mon, 18 Feb 2013 05:10:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/02/secrets-of-metaverse-part-3.html</guid>
      <description>&lt;p&gt;Parts 1-5:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-1.html&#34;&gt;What is the Metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-2.html&#34;&gt;How is the Metaverse data stored?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-3.html&#34;&gt;Is there a limit to how many Metaverse attributes I can have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-4.html&#34;&gt;Has access to the metaverse gotten faster with recent releases?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-5.html&#34;&gt;How do I safely query the metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Added (Aug 5 2015): &lt;a href=&#34;http://blog.ilmbestpractices.com/2015/08/how-many-attributes-can-you-have-in.html&#34;&gt;How Many Metaverse Attributes can I have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Many times people wonder how many attributes they can create in the Metaverse Designer tool.&lt;/p&gt;&#xA;&lt;p&gt;The answer is confusing because &amp;hellip; it depends.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secrets of the Metaverse Part 2</title>
      <link>https://identitymanaged.com/2013/02/secrets-of-metaverse-part-2.html</link>
      <pubDate>Fri, 15 Feb 2013 06:16:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/02/secrets-of-metaverse-part-2.html</guid>
      <description>&lt;p&gt;Parts 1-5:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-1.html&#34;&gt;What is the Metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-2.html&#34;&gt;How is the Metaverse data stored?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-3.html&#34;&gt;Is there a limit to how many Metaverse attributes I can have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-4.html&#34;&gt;Has access to the metaverse gotten faster with recent releases?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-5.html&#34;&gt;How do I safely query the metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Added (Aug 5 2015): &lt;a href=&#34;http://blog.ilmbestpractices.com/2015/08/how-many-attributes-can-you-have-in.html&#34;&gt;How Many Metaverse Attributes can I have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Where and how is the Metaverse data stored?&lt;/p&gt;&#xA;&lt;p&gt;Before I get into that I must caution you that modifying data directly will put you in a position that is unsupported by Microsoft. Even querying the data is something of a touchy issue (see &lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-5.html&#34;&gt;Part 5&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secrets of the Metaverse Part 1</title>
      <link>https://identitymanaged.com/2013/02/secrets-of-metaverse-part-1-comments.html</link>
      <pubDate>Thu, 14 Feb 2013 21:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/02/secrets-of-metaverse-part-1-comments.html</guid>
      <description>&lt;h4 id=&#34;great-explanation-this-really-came-in-handy-for-t&#34;&gt;Great explanation. This really came in handy for t&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/05999995915573981349&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 2, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Great explanation. This really came in handy for troubleshooting.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;I am so glad it was of use&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;I am using MV extension to create users in AD from FIM.&lt;br&gt;&#xA;Need to flow password to AD which is any Random number say &amp;ldquo;$random123&amp;rdquo;&lt;br&gt;&#xA;This attribute flows to AD but can be viewed in account preview etc or the attribute value can be seen. How can we flow the password value so that it can not be viewed in metaverse etc by any one like ********** ?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Secrets of the Metaverse Part 1</title>
      <link>https://identitymanaged.com/2013/02/secrets-of-metaverse-part-1.html</link>
      <pubDate>Thu, 14 Feb 2013 21:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/02/secrets-of-metaverse-part-1.html</guid>
      <description>&lt;p&gt;Many FIMsters wonder about the Metaverse and how works, how the data is stored. In this series I will reveal the secrets of the Metaverse. Parts 1-5 (links live but post yet to come)&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-1.html&#34;&gt;What is the Metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-2.html&#34;&gt;How is the Metaverse data stored?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/02/secrets-of-metaverse-part-3.html&#34;&gt;Is there a limit to how many Metaverse attributes I can have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-4.html&#34;&gt;Has access to the metaverse gotten faster with recent releases?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2013/03/secrets-of-metaverse-part-5.html&#34;&gt;How do I safely query the metaverse?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Added (Aug 5 2015): &lt;a href=&#34;http://blog.ilmbestpractices.com/2015/08/how-many-attributes-can-you-have-in.html&#34;&gt;How Many Metaverse Attributes can I have?&lt;/a&gt;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Forefront Identity Manager 2010 R2 SP1 (and its predecessors) can be classified as a MetaDirectory based Identity Management Solution. A MetaDirectory collects, aggregates, and stores data from various directories and data sources, such as Active Directory and your HR database.&lt;br&gt;&#xA;The Metaverse is the heart of FIM&amp;rsquo;s MetaDirectory. As an implementer of FIM you customize the data model, you decide what object types and attributes you need.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Updated Vote: Top 5 Deprecated Features of FIM 2010 R2 SP1</title>
      <link>https://identitymanaged.com/2013/02/updated-vote-top-5-deprecated-features.html</link>
      <pubDate>Thu, 14 Feb 2013 10:39:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/02/updated-vote-top-5-deprecated-features.html</guid>
      <description>&lt;p&gt;Here is an update on the impact of the &lt;a href=&#34;http://blog.ilmbestpractices.com/2013/01/voted-top-5-deprecated-features-of-fim.html&#34;&gt;newly deprecated features&lt;/a&gt;: The big change is that XMA has caught up to Multi-Mastery and is tied for first.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/42fc7fcc310e_9567/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/42fc7fcc310e_9567/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Massive FIM and AD LDS project at DPDHL</title>
      <link>https://identitymanaged.com/2013/02/massive-fim-and-ad-lds-project-at-dpdhl.html</link>
      <pubDate>Thu, 14 Feb 2013 10:26:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/02/massive-fim-and-ad-lds-project-at-dpdhl.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.brighttalk.com/webcast/8503/65277&#34;&gt;Watch the presentation that James Booth (who worked with us on the project) and Joe Gasowski (DPDHL)&lt;/a&gt; gave at the Redmond Identity Summit 2013 about our project at DHL to replace the DPDHL Sun One Directory and deploy FIM to replace both CriticalPath and a home-grown admin portal.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Voted: Top 5 Deprecated Features of FIM 2010 R2 SP1</title>
      <link>https://identitymanaged.com/2013/01/voted-top-5-deprecated-features-of-fim-comments.html</link>
      <pubDate>Tue, 29 Jan 2013 11:15:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/01/voted-top-5-deprecated-features-of-fim-comments.html</guid>
      <description>&lt;h4 id=&#34;looks-like-ecma1-deprecation-has-caught-up-to-the-&#34;&gt;Looks like ECMA1 deprecation has caught up to the &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/10516535229626774213&#34; title=&#34;noreply@blogger.com&#34;&gt;Ross&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Feb 4, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Looks like ECMA1 deprecation has caught up to the equal precedence issue since you posted this.&lt;/p&gt;&#xA;&lt;p&gt;I think I&amp;rsquo;ll start offering some ECMA1-&amp;gt;ECMA2 upgrade services. I suppose not everybody has an xMA developer in their back pocket!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Voted: Top 5 Deprecated Features of FIM 2010 R2 SP1</title>
      <link>https://identitymanaged.com/2013/01/voted-top-5-deprecated-features-of-fim.html</link>
      <pubDate>Tue, 29 Jan 2013 11:15:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/01/voted-top-5-deprecated-features-of-fim.html</guid>
      <description>&lt;p&gt;I conducted a &lt;a href=&#34;http://www.linkedin.com/groupAnswers?viewQuestionAndAnswers=&amp;amp;discussionID=205602647&amp;amp;gid=1714607&amp;amp;trk=eml-anet_dig-b_nd-pst_ttle-cn&amp;amp;ut=2lbE2Ag1j_KRA1&#34;&gt;linkedIn poll&lt;/a&gt; to find out what others thought of the &lt;a href=&#34;http://technet.microsoft.com/en-us/library/jj879229(v=ws.10).aspx&#34;&gt;features that are deprecated&lt;/a&gt; starting in FIM 2010 R2 SP1. For the poll I only listed the ones I put in my &lt;a href=&#34;http://blog.ilmbestpractices.com/2013/01/top-5-deprecated-features-as-of-fim.html&#34;&gt;top 5 list&lt;/a&gt;. With 15 votes and 1 abstention I thought it would be worthwhile to publish the results:&lt;/p&gt;&#xA;&lt;p&gt;Here we can see the winner:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/996fa00a2a44_9737/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/996fa00a2a44_9737/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Multi-mastery/equal precedence (I had this 2nd)&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;ECMA1 (XMA) (I had this third)&lt;/p&gt;</description>
    </item>
    <item>
      <title>The rest of the FIM 2010 R2 SP1 Deprecations</title>
      <link>https://identitymanaged.com/2013/01/the-rest-of-fim-2010-r2-sp1-deprecations.html</link>
      <pubDate>Thu, 17 Jan 2013 11:22:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/01/the-rest-of-fim-2010-r2-sp1-deprecations.html</guid>
      <description>&lt;p&gt;Remember that these features are still here but will be removed in a future version (probably the next major release or the one after)&lt;/p&gt;&#xA;&lt;p&gt;Feature&lt;/p&gt;&#xA;&lt;p&gt;Impact&lt;/p&gt;&#xA;&lt;p&gt;Unselect “allow nulls” for exported values&lt;/p&gt;&#xA;&lt;p&gt;You need to be more careful to ensure that you aren&amp;rsquo;t deleting values&lt;/p&gt;&#xA;&lt;p&gt;Web Service configuration interface&lt;/p&gt;&#xA;&lt;p&gt;You will no longer be able to send a request to the web service to update the mv-data or ma-data objects in order to configure the sync engine. The article says that we will be able to use PowerShell to configure the sync engine.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Top 5 Deprecated features as of FIM 2010 R2 SP1</title>
      <link>https://identitymanaged.com/2013/01/top-5-deprecated-features-as-of-fim-comments.html</link>
      <pubDate>Wed, 16 Jan 2013 11:28:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/01/top-5-deprecated-features-as-of-fim-comments.html</guid>
      <description>&lt;h4 id=&#34;i-have-heard-that-investments-in-fim-cm-are-contin&#34;&gt;I have heard that investments in FIM CM are contin&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/17202883653808140101&#34; title=&#34;noreply@blogger.com&#34;&gt;David Lundell&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jan 2, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;I have heard that investments in FIM CM are continuing. So don&amp;rsquo;t worry about FIM CM disappearing.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Top 5 Deprecated features as of FIM 2010 R2 SP1</title>
      <link>https://identitymanaged.com/2013/01/top-5-deprecated-features-as-of-fim.html</link>
      <pubDate>Wed, 16 Jan 2013 11:28:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/01/top-5-deprecated-features-as-of-fim.html</guid>
      <description>&lt;p&gt;Yesterday Microsoft published a list of features that have been &lt;a href=&#34;http://technet.microsoft.com/en-us/library/jj879229(v=ws.10).aspx&#34;&gt;deprecated in FIM&lt;/a&gt; and will be removed from the product at some point in the future. In other words these don&amp;rsquo;t require immediate action but when the next major release of * Identity Manager (* because we don&amp;rsquo;t know what the new name will be &amp;ndash; see my tweet from last week at the Redmond Identity Summit) emerges those features will likely be gone. So over the next 18-36 months you need to begin working away from these issues.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Top 11 new features of FIM 2010 R2 SP1</title>
      <link>https://identitymanaged.com/2013/01/fim-2010-r2-sp1-documentation-and-bits-comments.html</link>
      <pubDate>Tue, 15 Jan 2013 20:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/01/fim-2010-r2-sp1-documentation-and-bits-comments.html</guid>
      <description>&lt;h4 id=&#34;hello-is-fim-r2-sp1-support-sql-server-2012-sp1&#34;&gt;Hello, Is Fim r2 sp1 support sql server 2012 sp1&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/10907643659245129628&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Mar 2, 2015&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hello,&lt;br&gt;&#xA;Is Fim r2 sp1 support sql server 2012 sp1&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Top 11 new features of FIM 2010 R2 SP1</title>
      <link>https://identitymanaged.com/2013/01/fim-2010-r2-sp1-documentation-and-bits.html</link>
      <pubDate>Tue, 15 Jan 2013 20:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2013/01/fim-2010-r2-sp1-documentation-and-bits.html</guid>
      <description>&lt;p&gt;My comments on What&amp;rsquo;s new and the release notes for FIM 2010 R2 SP1:&lt;/p&gt;&#xA;&lt;p&gt;Rank&lt;/p&gt;&#xA;&lt;p&gt;Feature&lt;/p&gt;&#xA;&lt;p&gt;Impact&lt;/p&gt;&#xA;&lt;p&gt;1&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://technet.microsoft.com/en-us/library/jj863243(v=ws.10).aspx&#34;&gt;Deferred evaluation of criteria based groups&lt;/a&gt;&lt;br&gt;&#xA;This setting can be enabled one group at a time. You can also change the default so that as new criteria based groups are created they will be set for Deferred. The default is to calculate group membership twice a day at 2:30 AM and 2:30 PM.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Revisiting GUIDs, Octets and Base64</title>
      <link>https://identitymanaged.com/2012/12/revisiting-guids-octets-and-base64.html</link>
      <pubDate>Sun, 02 Dec 2012 20:59:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/12/revisiting-guids-octets-and-base64.html</guid>
      <description>&lt;p&gt;After re-reading my &lt;a href=&#34;http://blog.ilmbestpractices.com/2011/12/guids-to-octets-guids-to-base64-strings.html&#34;&gt;earlier post&lt;/a&gt; on this subject I decided I could be clearer.&lt;/p&gt;&#xA;&lt;p&gt;GUIDs are often used in three different formats:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Representation&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Example&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Canonical form&lt;/p&gt;&#xA;&lt;p&gt;8c4ac332-975f-4717-ad7b-ba4a4e968fff&lt;/p&gt;&#xA;&lt;p&gt;Octet String&lt;/p&gt;&#xA;&lt;p&gt;32c34a8c5f971747ad7bba4a4e968fff&lt;/p&gt;&#xA;&lt;p&gt;Base64 Encoded&lt;/p&gt;&#xA;&lt;p&gt;MsNKjF+XF0ete7pKTpaP/w==&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Representation&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Comment&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Used in&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Canonical form&lt;/p&gt;&#xA;&lt;p&gt;This format stems from the way GUIDs (UUIDs) are generated. Each dash separating the various components. In version one of the &lt;a href=&#34;http://www.ietf.org/rfc/rfc4122.txt&#34;&gt;UUID specification&lt;/a&gt;, the first the last component was the MAC address of the computer that generated the GUID.&lt;/p&gt;</description>
    </item>
    <item>
      <title>5 reasons to be thankful for Identity Management</title>
      <link>https://identitymanaged.com/2012/11/5-reasons-to-be-thankful-for-identity.html</link>
      <pubDate>Wed, 21 Nov 2012 15:48:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/11/5-reasons-to-be-thankful-for-identity.html</guid>
      <description>&lt;p&gt;On the eve of Thanksgiving I offer 5 reasons to be thankful for Identity Management (user provisioning, deprovisioning, group and role management, etc.):&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;What other compliance project can actually have a positive ROI?&#xA;&lt;ol&gt;&#xA;&lt;li&gt;You get improved compliance (and the ability to show it)&lt;/li&gt;&#xA;&lt;li&gt;You also get better security as accounts are disabled quickly&lt;/li&gt;&#xA;&lt;li&gt;Then you save money through the automation&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Identity Management can help support your corporate goals&lt;/li&gt;&#xA;&lt;li&gt;You can empower users to serve themselves with password resets, group/role requests&lt;/li&gt;&#xA;&lt;li&gt;It can help keep your organization out of the shame columns in the trade rags&#xA;&lt;ol&gt;&#xA;&lt;li&gt;We have all read about the disgruntled former employee accessing data.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;The joy of automation, the joy of not having to do double data entry!&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;5 things in Identity Management in 2012 for which I am thankful&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Lives! UAG Lives! TMG will not</title>
      <link>https://identitymanaged.com/2012/09/fim-lives-uag-lives-tmg-will-not.html</link>
      <pubDate>Wed, 12 Sep 2012 20:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/09/fim-lives-uag-lives-tmg-will-not.html</guid>
      <description>&lt;p&gt;Today &lt;a href=&#34;http://blogs.technet.com/b/server-cloud/archive/2012/09/12/important-changes-to-forefront-product-roadmaps.aspx&#34;&gt;Microsoft announced the discontinuing or subsuming of many products in the Forefront line&lt;/a&gt; &lt;/p&gt;&#xA;&lt;p&gt;To be crystal clear Forefront Identity Manager (FIM) and Forefront Unified Access Gateway (UAG) live on as separate products with ongoing investment!&lt;/p&gt;&#xA;&lt;p&gt;Insert the obligatory Mark Twain quote here. “The rumors of my death have been greatly exaggerated”&lt;/p&gt;&#xA;&lt;p&gt;Product&lt;/p&gt;&#xA;&lt;p&gt;Fate&lt;/p&gt;&#xA;&lt;p&gt;Forefront Identity Manager (FIM)&lt;/p&gt;&#xA;&lt;p&gt;Lives on. R2 was just released in June&lt;/p&gt;&#xA;&lt;p&gt;Forefront Unified Access Gateway (UAG)&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Best Practices Volume 1 has been updated for R2</title>
      <link>https://identitymanaged.com/2012/09/fim-best-practices-volume-1-has-been-comments.html</link>
      <pubDate>Tue, 04 Sep 2012 09:13:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/09/fim-best-practices-volume-1-has-been-comments.html</guid>
      <description>&lt;h4 id=&#34;we-have-purchased-to-original-copy-are-we-entitle&#34;&gt;We have purchased to original copy, are we entitle&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13262547059508577331&#34; title=&#34;noreply@blogger.com&#34;&gt;FMustafa&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 2, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;We have purchased to original copy, are we entitled to get a free upgrade to R2 version??&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;This comment has been removed by the author.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Any tentative date for print edition&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;The print edition is already available.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Best Practices Volume 1 has been updated for R2</title>
      <link>https://identitymanaged.com/2012/09/fim-best-practices-volume-1-has-been.html</link>
      <pubDate>Tue, 04 Sep 2012 09:13:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/09/fim-best-practices-volume-1-has-been.html</guid>
      <description>&lt;p&gt;Just this morning I have published the updated for R2 edition of FIM Best Practices Volume 1. Now called &lt;a href=&#34;http://ar.gy/1jkC&#34;&gt;FIM R2 Best Practices Volume 1: Introduction, Architecture And Installation Of Forefront Identity Manager 2010 R2&lt;/a&gt;. The &lt;a href=&#34;http://ar.gy/1jkC&#34;&gt;EBook&lt;/a&gt; edition is in color!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://ar.gy/1jkI&#34;&gt;Print Edition of FIM R2 Best Practices Volume 1&lt;/a&gt; is still B/W&lt;/p&gt;&#xA;&lt;p&gt;Go to the &lt;a href=&#34;http://www.lulu.com/&#34;&gt;lulu.com home page&lt;/a&gt; to get a coupon code for 20% off (offer expires 11:59 PM Sept 7 2012).&lt;/p&gt;</description>
    </item>
    <item>
      <title>New version PCNS, new FIM hotfix</title>
      <link>https://identitymanaged.com/2012/08/new-version-pcns-new-fim-hotfix-comments.html</link>
      <pubDate>Thu, 30 Aug 2012 09:59:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/08/new-version-pcns-new-fim-hotfix-comments.html</guid>
      <description>&lt;h4 id=&#34;so-where-or-when--can-we-download-that-hotfix-&#34;&gt;SO, where (or when !?) can we download that hotfix ?&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/10767317920469206168&#34; title=&#34;noreply@blogger.com&#34;&gt;redarc coder&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Nov 2, 2014&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;SO, where (or when !?) can we download that hotfix ?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;So, where (or when !?) can we download that hotfix !?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>New version PCNS, new FIM hotfix</title>
      <link>https://identitymanaged.com/2012/08/new-version-pcns-new-fim-hotfix.html</link>
      <pubDate>Thu, 30 Aug 2012 09:59:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/08/new-version-pcns-new-fim-hotfix.html</guid>
      <description>&lt;p&gt;On Aug 24th Microsoft released a new version of PCNS. Version number 4.1.2515.0.&lt;/p&gt;&#xA;&lt;p&gt;No release notes are provided with the download. However, this version number matches the version number of the latest FIM R2 hotfix rollup &lt;a href=&#34;http://support.microsoft.com/kb/2734159&#34; title=&#34;http://support.microsoft.com/kb/2734159&#34;&gt;http://support.microsoft.com/kb/2734159&lt;/a&gt; and it does tell us what is fixed:&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Assume that you run Password Change Notification Service (PCNS) setup together with the &lt;strong&gt;SCHEMAUPDATE=TRUE&lt;/strong&gt; option and the schema is updated successfully. In this situation, an error message is displayed at the end of the setup process incorrectly.&lt;br&gt;&#xA;After this update is installed, the Setup program does not display the error message when the schema update is successful.&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to import the Domain attribute into the FIM Portal Part 2</title>
      <link>https://identitymanaged.com/2012/08/how-to-import-domain-attribute-into-fim_16.html</link>
      <pubDate>Thu, 16 Aug 2012 13:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/08/how-to-import-domain-attribute-into-fim_16.html</guid>
      <description>&lt;p&gt;In &lt;a href=&#34;http://blog.ilmbestpractices.com/2012/08/how-to-import-domain-attribute-into-fim.html&#34;&gt;Part 1 of How to import the Domain attribute into the FIM Portal&lt;/a&gt; I provided you the simple technique for the single domain forest, and the technique that works although is a bit unwieldy – that of looking at the first 41 characters of the object’s SID and using a lookup table through nested IIF statements and this doesn’t .&lt;/p&gt;&#xA;&lt;p&gt;What if there was a simpler way?&lt;/p&gt;&#xA;&lt;p&gt;What about using the Domain Component option in the attribute flow?&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to import the Domain attribute into the FIM Portal Part 1</title>
      <link>https://identitymanaged.com/2012/08/how-to-import-domain-attribute-into-fim.html</link>
      <pubDate>Thu, 16 Aug 2012 12:47:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/08/how-to-import-domain-attribute-into-fim.html</guid>
      <description>&lt;p&gt;If you have a single domain forest then you should use a constant flow in your sync rule or advanced attribute flow. If you have a multi-domain forest, then using a constant in the advanced attribute flow won’t work.&lt;/p&gt;&#xA;&lt;p&gt;You could create multiple inbound sync rules one for each domain with scoping filters and then use a constant. However, this seems like a waste.&lt;/p&gt;&#xA;&lt;p&gt;You could also follow the guidance provided in article originated by my friend &lt;a href=&#34;http://social.technet.microsoft.com/wiki/2315/ProfileUrlRedirect.ashx&#34;&gt;Markus Vilcinskas&lt;/a&gt; and maintained by the community &lt;a href=&#34;http://social.technet.microsoft.com/wiki/contents/articles/648.how-do-i-synchronize-users-from-active-directory-domain-services-to-fim.aspx&#34; title=&#34;http://social.technet.microsoft.com/wiki/contents/articles/648.how-do-i-synchronize-users-from-active-directory-domain-services-to-fim.aspx&#34;&gt;http://social.technet.microsoft.com/wiki/contents/articles/648.how-do-i-synchronize-users-from-active-directory-domain-services-to-fim.aspx&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Award for Me, Award for Insight</title>
      <link>https://identitymanaged.com/2012/07/award-for-me-award-for-insight-comments.html</link>
      <pubDate>Mon, 02 Jul 2012 06:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/07/award-for-me-award-for-insight-comments.html</guid>
      <description>&lt;h4 id=&#34;congratulations-on-your-renewal-david&#34;&gt;Congratulations on your renewal David!&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/18443138260083249969&#34; title=&#34;noreply@blogger.com&#34;&gt;Henrik Nilsson&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 1, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Congratulations on your renewal David!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Congratulations!!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Way to go man!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Award for Me, Award for Insight</title>
      <link>https://identitymanaged.com/2012/07/award-for-me-award-for-insight.html</link>
      <pubDate>Mon, 02 Jul 2012 06:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/07/award-for-me-award-for-insight.html</guid>
      <description>&lt;p&gt;What a good week – &lt;a href=&#34;https://www.insight.com/pages/landingpage.web?id=12933&amp;amp;cm_re=homepage_SMB-_-week26-_-Banner_1&#34;&gt;Insight was awarded Microsoft Desktop Partner of the Year&lt;/a&gt;, and I just received news of &lt;a href=&#34;https://mvp.support.microsoft.com/profile/Lundell&#34;&gt;my MVP award&lt;/a&gt; in the Forefront Identity Management area has been renewed.&lt;/p&gt;&#xA;&lt;p&gt;The Desktop Partner of the Year is a great accomplishment by our Systems Management and Virtualization practice. This one will be added to all of the awards we won as Ensynch:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/a35d4e8a030b_5507/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/a35d4e8a030b_5507/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;As for the MVP, I am always honored. I truly enjoy trying to enhance the FIM community. This marks the 6th time I have received the award (2007, 2008, 2009, 2010, 2011, and 2012). There are so many cool experiences I get to have with the the other FIM MVPs, I treasure them.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM 2010 R2 released today to MSDN</title>
      <link>https://identitymanaged.com/2012/06/fim-2010-r2-released-today-to-msdn.html</link>
      <pubDate>Fri, 01 Jun 2012 19:29:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/06/fim-2010-r2-released-today-to-msdn.html</guid>
      <description>&lt;p&gt;Look what just turned up on the MSDN list of downloads:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/FIM-2010-R2-released-to-MSDN_EBA6/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/FIM-2010-R2-released-to-MSDN_EBA6/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/FIM-2010-R2-released-to-MSDN_EBA6/image_3.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/FIM-2010-R2-released-to-MSDN_EBA6/image_thumb_3.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Along with FIM 2010 R2 it looks like the BHOLD Suite is available too! Although you can see that it appears to be a separate download.&lt;/p&gt;&#xA;&lt;p&gt;I don’t know when the retail version will be available.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2012 Summary</title>
      <link>https://identitymanaged.com/2012/05/tec-2012-summary-comments.html</link>
      <pubDate>Wed, 02 May 2012 21:10:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/tec-2012-summary-comments.html</guid>
      <description>&lt;h4 id=&#34;thanks-david-for-a-great-overview-of-what-was-disc&#34;&gt;Thanks David for a great overview of what was disc&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/18443138260083249969&#34; title=&#34;noreply@blogger.com&#34;&gt;Henrik Nilsson&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;May 4, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks David for a great overview of what was discussed at TEC this year. I wish I could have attended but way too much work right now but I hope I&amp;rsquo;ll be able to attend TEC Europe this year (if there&amp;rsquo;s gonna be any) and US next year.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2012 Summary</title>
      <link>https://identitymanaged.com/2012/05/tec-2012-summary.html</link>
      <pubDate>Wed, 02 May 2012 21:10:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/tec-2012-summary.html</guid>
      <description>&lt;p&gt;Wow TEC 2012 is already over and I am already back home. What a week!&lt;/p&gt;&#xA;&lt;p&gt;The venue was great. San Diego is always a great place to be, cool yet not too cold. Right on the bay. Great hotel. The Marriot Marquis and Marinas has an awesome pool – went for a great swim on Monday night. Tuesday morning I really enjoyed a jog on the Boardwalk. I ran up to the USS Midway. Tons of other attractions right nearby.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RCDC Replacement</title>
      <link>https://identitymanaged.com/2012/05/rcdc-replacement-comments.html</link>
      <pubDate>Wed, 02 May 2012 12:08:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/rcdc-replacement-comments.html</guid>
      <description>&lt;h4 id=&#34;is-this-video-posted-anywhere-i-would-love-to-see&#34;&gt;Is this video posted anywhere? I would love to see&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/14116263447168005389&#34; title=&#34;noreply@blogger.com&#34;&gt;itswithinmyreach&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jun 2, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Is this video posted anywhere? I would love to see what the cons are. Currently we have a consultant very eager to re-do our UI.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>RCDC Replacement</title>
      <link>https://identitymanaged.com/2012/05/rcdc-replacement.html</link>
      <pubDate>Wed, 02 May 2012 12:08:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/rcdc-replacement.html</guid>
      <description>&lt;p&gt;&lt;strong&gt;FIM User Interface Implementation: Replace the rigid RCDC with a customizable UI&lt;br&gt;&#xA;Speaker:&lt;/strong&gt; &lt;a href=&#34;http://www.theexpertsconference.com/us/2012/directory-identity/speaker-bios/#eisaac&#34;&gt;Eihab Isaac&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Eihab delivered a very well-reasoned presentation on the pros and cons of replacing some of the forms, especially the create person (user) form. Excellent demo showing creating multiple requests for creating the user as well as requests for additional attributes, and application access. Great session.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Reporting Craig Martin style</title>
      <link>https://identitymanaged.com/2012/05/fim-reporting-craig-martin-style-comments.html</link>
      <pubDate>Tue, 01 May 2012 12:10:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/fim-reporting-craig-martin-style-comments.html</guid>
      <description>&lt;h4 id=&#34;thanks-for-attending-the-session-glad-you-liked-i&#34;&gt;Thanks for attending the session, glad you liked i&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/09808879680127031778&#34; title=&#34;noreply@blogger.com&#34;&gt;Craig Martin&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;May 2, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks for attending the session, glad you liked it! I had fun talking and running with Scissors.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>FIM Reporting Craig Martin style</title>
      <link>https://identitymanaged.com/2012/05/fim-reporting-craig-martin-style.html</link>
      <pubDate>Tue, 01 May 2012 12:10:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/fim-reporting-craig-martin-style.html</guid>
      <description>&lt;p&gt;Craig’s session is on how to get data out from the FIM Service and FIM Sync with PowerShell and displaying it with SSRS, which he has dubbed Scissors!&lt;/p&gt;&#xA;&lt;p&gt;Ok Craig we get it! You have even persuaded me that PowerShell is important! I have started writing scripts. SQL Server of course is still important.&lt;/p&gt;&#xA;&lt;p&gt;Key is to hook up a pipeline from PowerShell to pass into &lt;a href=&#34;http://psdpe.codeplex.com/&#34;&gt;his custom SSRS PowerShell Data Processing Extension (DPE).&lt;/a&gt; Craig uses export-clixml and import-clixml to serialize data before it is expired from the FIM system.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Migrating from ILM to FIM</title>
      <link>https://identitymanaged.com/2012/05/migrating-from-ilm-to-fim.html</link>
      <pubDate>Tue, 01 May 2012 11:04:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/migrating-from-ilm-to-fim.html</guid>
      <description>&lt;p&gt;Carol Wapshere delivered an excellent session yesterday at TEC 2012 on the thought process for migrating from MIIS/ILM to FIM.&lt;/p&gt;&#xA;&lt;p&gt;I loved the incisive logic to focus on the main issue being solved: getting the customer onto supported software (getting the MIIS database off SQL 2000, getting off MIIS/ILM). Avoid the temptation to try and fix everything else at the same time. She had a great list of gotchas. Even more impressive were her discovery scripts designed to analyze the existing implementations and her rubric for estimating the work.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Look what I found in the news</title>
      <link>https://identitymanaged.com/2012/05/look-what-i-found-in-news.html</link>
      <pubDate>Tue, 01 May 2012 07:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/look-what-i-found-in-news.html</guid>
      <description>&lt;p&gt;I didn’t even know that Identity and Access Management (IAM) workers had a union!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/Look-what-I-found-in-the-news_6B6D/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/Look-what-I-found-in-the-news_6B6D/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Of course, imagine my disappointment to learn that it is International Association of Machinists and Aerospace Workers union.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>SharePoint 2010 User Profile Synchronization Service</title>
      <link>https://identitymanaged.com/2012/05/sharepoint-2010-user-profile-comments.html</link>
      <pubDate>Tue, 01 May 2012 01:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/sharepoint-2010-user-profile-comments.html</guid>
      <description>&lt;h4 id=&#34;neat-indeed-they-are-at-the-forefront-of-fim-aut&#34;&gt;Neat indeed. They are at the forefront of FIM aut&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/09808879680127031778&#34; title=&#34;noreply@blogger.com&#34;&gt;Craig Martin&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;May 1, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Neat indeed. They are at the forefront of FIM automation, since they use the FIM Service component to automate the FIM Sync service. AFAIK they are the reason this automation functionality exists in the FIM Service at all.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>SharePoint 2010 User Profile Synchronization Service</title>
      <link>https://identitymanaged.com/2012/05/sharepoint-2010-user-profile.html</link>
      <pubDate>Tue, 01 May 2012 01:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/05/sharepoint-2010-user-profile.html</guid>
      <description>&lt;p&gt;The SharePoint 2010 User Profile Synchronization Service is really FIM 2010 pre-packaged in a very special way. Need evidence? Look at the tables in User Profile Service Application_SyncDB&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/SharePoint-2010-User-Profile-Synchroniza_196F/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/SharePoint-2010-User-Profile-Synchroniza_196F/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;See how it has mms_connectorspace, mms_cs_link etc. Those are table commonly found in the FIM sync database. See the attributeInternal, the BindingInternal, all of the Membership* tables those are all part of the FIM Service database. So interestingly enough they have both FIM Service and FIM sync merged into a single DB.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM 2010 R2 Showdown: Classic vs. Declarative</title>
      <link>https://identitymanaged.com/2012/04/fim-2010-r2-showdown-classic-vs-comments.html</link>
      <pubDate>Mon, 30 Apr 2012 15:39:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/fim-2010-r2-showdown-classic-vs-comments.html</guid>
      <description>&lt;h4 id=&#34;can-you-use-both-declarative-and-non-declarative-a&#34;&gt;Can you use both declarative and non-declarative a&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/14152565077987685781&#34; title=&#34;noreply@blogger.com&#34;&gt;yekolo&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Aug 4, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Can you use both declarative and non-declarative at the same time? Declarative for some attribute mappings and non declarative for others?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>FIM 2010 R2 Showdown: Classic vs. Declarative</title>
      <link>https://identitymanaged.com/2012/04/fim-2010-r2-showdown-classic-vs.html</link>
      <pubDate>Mon, 30 Apr 2012 15:39:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/fim-2010-r2-showdown-classic-vs.html</guid>
      <description>&lt;p&gt;Well I delivered my session FIM 2010 R2 Showdown: Classic vs. Declarative. During lunch they changed the location. But the room was packed by 5 min after I began (guessing about 45-50 people). Many familiar faces.&lt;/p&gt;&#xA;&lt;p&gt;We had a rollicking good time. I presented how things worked with Classic and Declarative presented some findings and asked for other opinions. Boy did I receive them.&lt;/p&gt;&#xA;&lt;p&gt;My basic conclusion is that Declarative can reduce the code used and in turn improve the maintainability of the FIM implementation.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Picking a mobile phone plan: AT&amp;T</title>
      <link>https://identitymanaged.com/2012/04/picking-mobile-phone-plan-at.html</link>
      <pubDate>Fri, 27 Apr 2012 17:00:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/picking-mobile-phone-plan-at.html</guid>
      <description>&lt;p&gt;I am currently a Sprint customer, and I am in the process of considering a replacement. So I analyzed AT&amp;amp;T’s plans. I found some interesting things:&lt;/p&gt;&#xA;&lt;p&gt;They have three individual plans that don’t include long distance to Canada but do include US long distance.&lt;/p&gt;&#xA;&lt;p&gt;min&lt;/p&gt;&#xA;&lt;p&gt;cost&lt;/p&gt;&#xA;&lt;p&gt;$/min&lt;/p&gt;&#xA;&lt;p&gt;Over $/min&lt;/p&gt;&#xA;&lt;p&gt;Min over to break even with next plan&lt;/p&gt;&#xA;&lt;p&gt;Rollover&lt;/p&gt;&#xA;&lt;p&gt;Weekend min&lt;/p&gt;&#xA;&lt;p&gt;450&lt;/p&gt;&#xA;&lt;p&gt; $   39.99&lt;/p&gt;&#xA;&lt;p&gt; $   0.089&lt;/p&gt;&#xA;&lt;p&gt;0.45&lt;/p&gt;&#xA;&lt;p&gt;44&lt;/p&gt;&#xA;&lt;p&gt;yes&lt;/p&gt;&#xA;&lt;p&gt;5000&lt;/p&gt;&#xA;&lt;p&gt;900&lt;/p&gt;</description>
    </item>
    <item>
      <title>Phoenix area part-time MBA program comparisons at public universities</title>
      <link>https://identitymanaged.com/2012/04/phoenix-area-part-time-mba-program-comments.html</link>
      <pubDate>Fri, 27 Apr 2012 16:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/phoenix-area-part-time-mba-program-comments.html</guid>
      <description>&lt;h4 id=&#34;if-you-want-to-study-for-an-master-in-business-adm&#34;&gt;If you want to study for an Master in Business Adm&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/15002354364018973597&#34; title=&#34;noreply@blogger.com&#34;&gt;way2 college&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Apr 3, 2014&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;If you want to study for an Master in Business Administration (MBA) while still having time for a full time job, the finest way that you could achieve this is to study in an &lt;a href=&#34;http://www.way2college.com/mba-master-of-business-administration-through-distance-correspondence.htm&#34;&gt;mba distance learning&lt;/a&gt; course.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Distance learning is the best mode of education for the professionals and for the people who cannot attend the college regularly.MBA is a postgraduate course and most of the people opt for it if they want to make career in Management and the business Administration.&lt;br&gt;&#xA;&lt;a href=&#34;http://www.way2college.com/mba-through-distance-education-in-symbiosis.htm&#34;&gt;MBA through distance education in symbiosis&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Phoenix area part-time MBA program comparisons at public universities</title>
      <link>https://identitymanaged.com/2012/04/phoenix-area-part-time-mba-program.html</link>
      <pubDate>Fri, 27 Apr 2012 16:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/phoenix-area-part-time-mba-program.html</guid>
      <description>&lt;p&gt;Even though I already have the MBA from Eller College at the U of A I recently put together the following analysis for a friend comparing the MBA options in Phoenix from U of A and ASU.&lt;/p&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;Eller College of Management&lt;/p&gt;&#xA;&lt;p&gt;(University of Arizona) Evening&lt;/p&gt;&#xA;&lt;p&gt;Eller College of Management&lt;/p&gt;&#xA;&lt;p&gt;(University of Arizona) Executive&lt;/p&gt;&#xA;&lt;p&gt;WP Carey School of Business (ASU) Professional Evening&lt;/p&gt;&#xA;&lt;p&gt;WP Carey School of Business (ASU) Professional Weekend&lt;/p&gt;&#xA;&lt;p&gt;ASU Executive&lt;/p&gt;</description>
    </item>
    <item>
      <title>Opening Edit instead of view from a uocListView</title>
      <link>https://identitymanaged.com/2012/04/opening-edit-instead-of-view-from.html</link>
      <pubDate>Fri, 27 Apr 2012 06:57:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/opening-edit-instead-of-view-from.html</guid>
      <description>&lt;p&gt;When using the uocListView control in the FIM RCDC you can have it return a list of objects. However when you open them, they also open for viewing, not editing.&lt;/p&gt;&#xA;&lt;p&gt;The key to this is to add a button control inside the uocListView control. You then specify the redirectURL property for the button. Additionally ShowActionBar must be true, ItemClickBehavior must be ModelessDialog (which is the default). Enable Selection must also be true.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM DB Sizing Calculator</title>
      <link>https://identitymanaged.com/2012/04/fim-db-sizing-calculator-comments.html</link>
      <pubDate>Wed, 25 Apr 2012 23:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/fim-db-sizing-calculator-comments.html</guid>
      <description>&lt;h4 id=&#34;pretty-slick-man&#34;&gt;Pretty slick, man!&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/09808879680127031778&#34; title=&#34;noreply@blogger.com&#34;&gt;Craig Martin&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;May 3, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Pretty slick, man!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Thanks Craig. Glad you like it!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;WAY too timely! Thanks Dave!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Thanks, very helpful.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Hi very helpul, do you have something like that for the Reporting data base of FIM (SCSM DW)?&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM DB Sizing Calculator</title>
      <link>https://identitymanaged.com/2012/04/fim-db-sizing-calculator.html</link>
      <pubDate>Wed, 25 Apr 2012 23:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/fim-db-sizing-calculator.html</guid>
      <description>&lt;p&gt;FIM has two databases (well three if we count the FIM Certificate Management service):&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;FIMService&lt;/li&gt;&#xA;&lt;li&gt;FIMSynchronizationService&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/files/FIM%20DB%20Sizing.xlsx&#34;&gt;Here is a calculator in excel&lt;/a&gt; that you can download and use to calculate how big to make your databases.&lt;/p&gt;&#xA;&lt;p&gt;In my experience the FIMService database size depends mostly on how many request objects are in the database.&lt;/p&gt;&#xA;&lt;p&gt;The FIM Sync Database depends mostly on how much run history details (step object details) you generate and keep.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Darth Vader – Project Manager Part 2</title>
      <link>https://identitymanaged.com/2012/04/darth-vader-project-manager-part-2.html</link>
      <pubDate>Tue, 24 Apr 2012 11:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/darth-vader-project-manager-part-2.html</guid>
      <description>&lt;p&gt;Have you ever wondered what it would be like to be on a project that was managed by Darth Vader?&lt;/p&gt;&#xA;&lt;p&gt;In &lt;a href=&#34;http://blog.ilmbestpractices.com/2012/02/darth-vader-project-manager-part-1.html&#34;&gt;Part 1&lt;/a&gt; I analyzed the good side of his skills. In Part 2 I tried to find the bad but I only find more good.&lt;/p&gt;&#xA;&lt;p&gt;Once more thanks to George Lucas for inventing Star Wars and thanks again my co-workers for not utilizing Darth Vader&amp;rsquo;s style.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;More Good&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Characteristic&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Example&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Nothing new under the sun</title>
      <link>https://identitymanaged.com/2012/04/nothing-new-under-sun.html</link>
      <pubDate>Tue, 24 Apr 2012 09:48:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/nothing-new-under-sun.html</guid>
      <description>&lt;p&gt;Just a few weeks ago I was discussing with my team how Cloud computing bore a lot of similarities to outsourcing of Data Processing back in the height of the mainframe era. Just this morning I saw the following on &lt;a href=&#34;http://blogs.kuppingercole.com/kearns/2012/04/24/eic-2012-my-pickings/&#34;&gt;Dave Kearns blog&lt;/a&gt; “While it’s true that there is really nothing new under the sun – “cloud computing,” for example, has remarkable similarities to datacenter computing from the ‘60s and ‘70s – it’s also true that there is always a different way to look at data, facts, or technology which can give insights into better ways to conduct business.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>What does “no commitment” really mean?</title>
      <link>https://identitymanaged.com/2012/04/what-does-no-commitment-really-mean.html</link>
      <pubDate>Mon, 23 Apr 2012 21:35:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/04/what-does-no-commitment-really-mean.html</guid>
      <description>&lt;p&gt;I recently received a mailer for &lt;a href=&#34;http://www.youfithealthclubs.com/index.html&#34;&gt;YouFit Health Clubs&lt;/a&gt;, offering me “$1 down, $10 month with no commitment” for a club they opened near my house (limited to the first 125 to sign up).&lt;/p&gt;&#xA;&lt;p&gt;Sounds good, but following the principle of caveat emptor (buyer beware), I always read the fine print. According to the “Billing for Monthly Dues” agreement you may “discontinue your Month-to-Month membership you may do so at any time with a payment of a twenty-five (25) dollar processing fee.”&lt;/p&gt;</description>
    </item>
    <item>
      <title>Vol 1 -- 1000 copies! -- 29% off</title>
      <link>https://identitymanaged.com/2012/02/vol-1-1000-copies-29-off-comments.html</link>
      <pubDate>Wed, 29 Feb 2012 12:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/02/vol-1-1000-copies-29-off-comments.html</guid>
      <description>&lt;h4 id=&#34;great-news--any-idea-when-the-next-volumes-will-&#34;&gt;Great news &amp;ndash; Any idea when the next volumes will &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/00743973039013866644&#34; title=&#34;noreply@blogger.com&#34;&gt;Michelle Rutherford&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Mar 4, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Great news &amp;ndash; Any idea when the next volumes will be out?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Vol 1 -- 1000 copies! -- 29% off</title>
      <link>https://identitymanaged.com/2012/02/vol-1-1000-copies-29-off.html</link>
      <pubDate>Wed, 29 Feb 2012 12:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/02/vol-1-1000-copies-29-off.html</guid>
      <description>&lt;p&gt;A few weeks ago &lt;a href=&#34;http://www.lulu.com/browse/search.php?fSearchData%5Bauthor%5D=David+Lundell&amp;amp;fSearchData%5Blang_code%5D=all&amp;amp;fSort=salesRankEver_asc&amp;amp;showingSubPanels=advancedSearchPanel_title_creator&#34;&gt;FIM Best Practices Volume 1&lt;/a&gt; has surpassed 1000 copies! In honor of that achievement and Leap Day use the following code to get 29% off &lt;strong&gt;LEAPYEAR305&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM 2010 -- Update Rollup 2 4.0.3606.2</title>
      <link>https://identitymanaged.com/2012/02/fim-2010-update-rollup-2-4036062.html</link>
      <pubDate>Tue, 28 Feb 2012 09:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/02/fim-2010-update-rollup-2-4036062.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://support.microsoft.com/kb/2635086&#34;&gt;FIM 2010 Update Rollup 2&lt;/a&gt; is now available. &lt;a href=&#34;http://catalog.update.microsoft.com/v7/site/Search.aspx?q=forefront%20identity%20manager&#34;&gt;Download from here&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Before blindly applying this update it is critical that you read the release notes, as XMA&amp;rsquo;s or ECMA&amp;rsquo;s may not run after the update. If you changed the MIISServer.exe.config file to tweak the FIM MA performance the update won&amp;rsquo;t replace your file. So you have to make some updates to it by hand. This is documented in the &lt;a href=&#34;http://support.microsoft.com/kb/2635086&#34;&gt;release notes&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;There are lots of fixes, my most favorite is that they have rolled back the change I mentioned [ranted about] in a previous blog post: &lt;a href=&#34;http://blog.ilmbestpractices.com/2011/11/ok-i-am-not-actually-swearing-nor-are.html&#34;&gt;What the %_ is the deal with wildcards in FIM Queries in the latest hotfix?&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Darth Vader – Project Manager Part 1</title>
      <link>https://identitymanaged.com/2012/02/darth-vader-project-manager-part-1-comments.html</link>
      <pubDate>Tue, 14 Feb 2012 20:28:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/02/darth-vader-project-manager-part-1-comments.html</guid>
      <description>&lt;h4&gt;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13686993130117527666&#34; title=&#34;noreply@blogger.com&#34;&gt;Tarah&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Mar 2, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;This comment has been removed by the author.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Is that course being offered at The Darth Vader School of Project Management?&lt;/p&gt;&#xA;&lt;p&gt;Part of Lord Vader&amp;rsquo;s project management style coming soon&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Darth Vader – Project Manager Part 1</title>
      <link>https://identitymanaged.com/2012/02/darth-vader-project-manager-part-1.html</link>
      <pubDate>Tue, 14 Feb 2012 20:28:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/02/darth-vader-project-manager-part-1.html</guid>
      <description>&lt;p&gt;Have you ever wondered what it would be like to be on a project that was managed by Darth Vader? &lt;/p&gt;&#xA;&lt;p&gt;Let’s analyze the good side of his skills.&lt;/p&gt;&#xA;&lt;p&gt;But before we do a little housekeeping:&lt;/p&gt;&#xA;&lt;p&gt;I would like to thank my George Lucas for inventing such wonderful characters and a wonderful story, that has entertained me and so many others, many many times. I would also like to thank my co-workers for not utilizing Darth Vader&amp;rsquo;s style.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM R2 Showdown -- Classic vs. Declarative</title>
      <link>https://identitymanaged.com/2012/01/fim-r2-showdown-classic-vs-declarative.html</link>
      <pubDate>Wed, 25 Jan 2012 10:43:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2012/01/fim-r2-showdown-classic-vs-declarative.html</guid>
      <description>&lt;p&gt;Come join me at &lt;a href=&#34;http://www.theexpertsconference.com/us/2012/&#34;&gt;The Experts Conference 2012&lt;/a&gt; in San Diego April 29 - May2 where I will be presenting:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;FIM R2 Showdown — Classic vs. Declarative&lt;br&gt;&#xA;Speaker:&lt;/strong&gt; &lt;a href=&#34;http://www.theexpertsconference.com/us/2012/directory-identity/speaker-bios/#dlundell&#34;&gt;David Lundell&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Is there room enough for both in this town? FIM 2010 R2 has two ways of accomplishing many tasks: Classic and Declarative. Attend this showdown to learn when to saddle up Classic vs. when to saddle up with Declarative Sync Rules and why. Dissenting opinions politely welcomed — join the controversy! Discussion will take into account performance, ease of implementation and maintainability.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Property Sets for Permissions in AD and AD LDS</title>
      <link>https://identitymanaged.com/2011/12/property-sets-for-permissions-in-ad-and-comments.html</link>
      <pubDate>Mon, 26 Dec 2011 12:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/12/property-sets-for-permissions-in-ad-and-comments.html</guid>
      <description>&lt;h4 id=&#34;its-very-good-post-congratulations-i-really-enj&#34;&gt;It’s very good post! Congratulations! I really enj&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/14790267611332318019&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 4, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;It’s very good post! Congratulations! I really enjoyed to reading your blog. Thanks for share all this information. I’m looking forward your next post&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Property Sets for Permissions in AD and AD LDS</title>
      <link>https://identitymanaged.com/2011/12/property-sets-for-permissions-in-ad-and.html</link>
      <pubDate>Mon, 26 Dec 2011 12:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/12/property-sets-for-permissions-in-ad-and.html</guid>
      <description>&lt;p&gt;A while back I needed to set up Property Sets in AD LDS for granting of permissions to many of the attributes on the person object all at once, as I reviewed the Technet documentation on &lt;a href=&#34;http://technet.microsoft.com/en-us/library/cc755430(WS.10).aspx&#34;&gt;AD Property Sets&lt;/a&gt; I realized that it doesn’t tell you what object type property sets are, nor does it tell you how to create a property set, nor does it tell you how to assign an attribute to a property set. The &lt;a href=&#34;http://msdn.microsoft.com/en-us/library/ms683990(v=VS.85).aspx&#34;&gt;MSDN documentation on Property Sets&lt;/a&gt; lets you see which attributes where included in which property sets in the different versions of AD, and it hints that property sets are part of &lt;a href=&#34;http://msdn.microsoft.com/en-us/library/ms680945(v=VS.85).aspx&#34;&gt;Control Access Rights&lt;/a&gt;. Finally there is some more MSDN documentation on &lt;a href=&#34;http://msdn.microsoft.com/en-us/library/ms675747(v=VS.85).aspx&#34;&gt;Control Access Rights&lt;/a&gt; that starts to spell it out:&lt;/p&gt;</description>
    </item>
    <item>
      <title>GUIDs to Octets, GUIDs to Base64 strings and back again</title>
      <link>https://identitymanaged.com/2011/12/guids-to-octets-guids-to-base64-strings-comments.html</link>
      <pubDate>Mon, 26 Dec 2011 12:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/12/guids-to-octets-guids-to-base64-strings-comments.html</guid>
      <description>&lt;h4 id=&#34;not-sure-if-anyone-is-still-looking-at-this-but-i-&#34;&gt;not sure if anyone is still looking at this but i &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/14935611282987980574&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jan 6, 2015&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;not sure if anyone is still looking at this but i have a question that seems simple but its puzzling me!&lt;br&gt;&#xA;I am trying to follow the instructions to convert a GUID into a string. I have done this:&lt;/p&gt;&#xA;&lt;p&gt;Which you can do with this one line of PowerShell script&lt;/p&gt;</description>
    </item>
    <item>
      <title>GUIDs to Octets, GUIDs to Base64 strings and back again</title>
      <link>https://identitymanaged.com/2011/12/guids-to-octets-guids-to-base64-strings.html</link>
      <pubDate>Mon, 26 Dec 2011 12:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/12/guids-to-octets-guids-to-base64-strings.html</guid>
      <description>&lt;p&gt;Suppose I generate a GUID of 8c4ac332-975f-4717-ad7b-ba4a4e968fff by running the following PowerShell Command line&lt;/p&gt;&#xA;&lt;p&gt;[system.guid]::newguid()&lt;/p&gt;&#xA;&lt;p&gt;Don’t worry if your GUID is different from mine; it should be! If it isn’t let me know because I think I’ll partner with you for the lottery (aka a tax on the mathematically impaired).&lt;/p&gt;&#xA;&lt;p&gt;Some attributes (like the attributeSecurityGUID) when edited through ADSI Edit require you to convert the GUID to octet string (for little endian systems – Intel processors are little endian): 32c34a8c5f971747ad7bba4a4e968fff&lt;/p&gt;</description>
    </item>
    <item>
      <title>Referenced by Other works and Sale at Lulu</title>
      <link>https://identitymanaged.com/2011/11/referenced-by-other-works-and-sale-at.html</link>
      <pubDate>Mon, 28 Nov 2011 07:07:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/referenced-by-other-works-and-sale-at.html</guid>
      <description>&lt;p&gt;I was pleasantly surprised today to find three other books, referencing FIM Best Practices Volume 1, which because of a Lulu Sale you can get at 25% off until 12/14/2011 &lt;strong&gt;Coupon Code: BUYMYBOOK305 Coupon expires December 14, 2011 $50 Max Savings. Of course today only 30% off, CYBERMONDAY305.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;All three have an identical blurb about FIM and reference FIM Best Practices Volume 1 as additional material.&lt;/p&gt;&#xA;&lt;p&gt;Title&lt;/p&gt;&#xA;&lt;p&gt;Author&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.amazon.com/User-Provisioning-High-impact-Strategies-Definitions/dp/1743045581/ref=sr_1_2?s=books&amp;amp;ie=UTF8&amp;amp;qid=1322487529&amp;amp;sr=1-2&#34;&gt;User Provisioning: High-impact Strategies - What You Need to Know: Definitions, Adoptions, Impact, Benefits, Maturity, Vendors&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM exam 70-158 is now live oh and I passed</title>
      <link>https://identitymanaged.com/2011/11/exam-70-158-ts-forefront-identity-comments.html</link>
      <pubDate>Tue, 22 Nov 2011 07:03:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/exam-70-158-ts-forefront-identity-comments.html</guid>
      <description>&lt;h4 id=&#34;congrats-this-is-interesting-area--and-product-&#34;&gt;Congrats! This is interesting area -and product &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/04921441272705803455&#34; title=&#34;noreply@blogger.com&#34;&gt;Savolainen Semi Seniori&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;May 6, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Congrats!&lt;/p&gt;&#xA;&lt;p&gt;This is interesting area -and product but suffers from availability of learning materials..&lt;/p&gt;&#xA;&lt;p&gt;Like i couldn&amp;rsquo;t find practice tests at all. And im used to study with those MS presss books and their companion CD&amp;rsquo;s with practice tests.&lt;br&gt;&#xA;Sure i do labs in virtual environments too but for me those practice tests give that last confidence that i need to book exam. :)&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM exam 70-158 is now live oh and I passed</title>
      <link>https://identitymanaged.com/2011/11/exam-70-158-ts-forefront-identity.html</link>
      <pubDate>Tue, 22 Nov 2011 07:03:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/exam-70-158-ts-forefront-identity.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.microsoft.com/learning/en/us/Exam.aspx?ID=70-158&amp;amp;Locale=en-us&#34;&gt;Exam 70-158: TS: Forefront Identity Manager 2010, Configuring&lt;/a&gt; is now live according to the MSL web site. I also received an email indicating that I passed the beta.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>What the %_ is the deal with wildcards in FIM Queries in the latest hotfix?</title>
      <link>https://identitymanaged.com/2011/11/ok-i-am-not-actually-swearing-nor-are.html</link>
      <pubDate>Wed, 16 Nov 2011 10:38:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/ok-i-am-not-actually-swearing-nor-are.html</guid>
      <description>&lt;p&gt;Ok I am not actually swearing, nor are those substitute words, rather % and _ are two characters that until &lt;a href=&#34;http://support.microsoft.com/kb/2520954&#34;&gt;hotfix rollup package (build 4.0.3594.2)&lt;/a&gt; could be used to perform some &lt;a href=&#34;http://blog.ilmbestpractices.com/2010/06/fim-sets-xpath-finding-nulls-with.html&#34;&gt;much needed and cool searches for sets, search scopes, groups and 3rd party client queries against FIM&lt;/a&gt;. Such as querying for the presence of string attributes.&lt;/p&gt;&#xA;&lt;p&gt;I am sure what happened is that someone created a resource with an underscore in the name and then couldn’t search for it. So the fix. However it wasn’t broken. We need this functionality. Furthermore, simply enclosing the wildcard character in [] would cause it to be evaluated as a literal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>What the %_ is the deal with wildcards in FIM Queries in the latest hotfix?-Comments</title>
      <link>https://identitymanaged.com/2011/11/ok-i-am-not-actually-swearing-nor-are-comments.html</link>
      <pubDate>Wed, 16 Nov 2011 10:38:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/ok-i-am-not-actually-swearing-nor-are-comments.html</guid>
      <description>&lt;h4 id=&#34;david---just-came-across-your-post-others-readin&#34;&gt;David - just came across your post. Others readin&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;%22noreply@blogger.com%22&#34;&gt;Anonymous&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jan 1, 2012&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;David - just came across your post. Others reading it now may wish to follow this thread on the FIM Forum where the issue continues to be discussed at length.&lt;br&gt;&#xA;Cheers&lt;br&gt;&#xA;Bob&lt;br&gt;&#xA;&lt;a href=&#34;http://social.technet.microsoft.com/Forums/en-US/ilm2/thread/ec15b1d0-3f4c-42fd-a833-3983330be963&#34;&gt;http://social.technet.microsoft.com/Forums/en-US/ilm2/thread/ec15b1d0-3f4c-42fd-a833-3983330be963&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;10 years on David and your post came in handy just now - learned something new about the [_] thing in xpath statements :) - kudos - just the ticket!&lt;br&gt;&#xA;My xpath: &amp;ldquo;/*[starts-with(DisplayName,&amp;rsquo;[_]&amp;rsquo;)]&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM 2010 hotfix available (4.0.3594.2)</title>
      <link>https://identitymanaged.com/2011/11/microsoft-has-released-new-hotfix-kb.html</link>
      <pubDate>Wed, 16 Nov 2011 10:22:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/microsoft-has-released-new-hotfix-kb.html</guid>
      <description>&lt;p&gt;Microsoft has released a &lt;a href=&#34;http://support.microsoft.com/kb/2520954&#34;&gt;new hotfix&lt;/a&gt; (kb 2520954) at the end of October with some key fixes in it as well as one item that I will &lt;a href=&#34;http://blog.ilmbestpractices.com/2011/11/ok-i-am-not-actually-swearing-nor-are.html&#34;&gt;blog about next&lt;/a&gt; that prevents me from loading this on most implementations, until it is addressed.&lt;/p&gt;&#xA;&lt;p&gt;Highlights&lt;/p&gt;&#xA;&lt;p&gt;Component&lt;/p&gt;&#xA;&lt;p&gt;Official Description&lt;/p&gt;&#xA;&lt;p&gt;Comments&lt;/p&gt;&#xA;&lt;p&gt;Workflow Engine (FIM Service)&lt;/p&gt;&#xA;&lt;p&gt;Assume that you perform an operation that accesses the SQL database when the Microsoft SQL Server connection pooling feature is enabled in the FIM server. For example, you run a query or a request. If the operation times out for any reason, a future operation on the same thread may fail until that thread is removed from the SQL connection pool. An error message that resembles the following is displayed in the FIM Service Application event log, in the &lt;strong&gt;RequestStatusDetails&lt;/strong&gt; property for a request, or in the &lt;strong&gt;WorkflowStatusDetails&lt;/strong&gt; property of a workflow instance: Cannot enlist in the transaction because a local transaction is in progress on the connection.&lt;br&gt;&#xA;Additionally, the time stamp is the same as the time when the operation fails.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2012 call for papers open for 2 more days</title>
      <link>https://identitymanaged.com/2011/11/experts-conference-call-for-papers.html</link>
      <pubDate>Wed, 16 Nov 2011 10:05:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/experts-conference-call-for-papers.html</guid>
      <description>&lt;p&gt;The Experts Conference Call for Papers still open until Nov 18th&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.theexpertsconference.com/us/2012/submit-a-paper/&#34; title=&#34;http://www.theexpertsconference.com/us/2012/submit-a-paper/&#34;&gt;http://www.theexpertsconference.com/us/2012/submit-a-paper/&lt;/a&gt; &lt;/p&gt;&#xA;&lt;p&gt;For general info: &lt;a href=&#34;http://www.theexpertsconference.com/us/2012/&#34; title=&#34;http://www.theexpertsconference.com/us/2012/&#34;&gt;http://www.theexpertsconference.com/us/2012/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;I have attended at spoke at this conference since 2007. I love it. It is a great experience and loads of great in-depth technical training by top experts on Directory &amp;amp; Identity, as well as SharePoint, Exchange, Virtualization &amp;amp; Cloud and PowerShell Deep Dive. Also come and learn about the inside joke dealing with the rubber chicken.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Awesome FIM Case Study</title>
      <link>https://identitymanaged.com/2011/11/microsoft-recently-published-case-study-comments.html</link>
      <pubDate>Wed, 16 Nov 2011 09:54:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/microsoft-recently-published-case-study-comments.html</guid>
      <description>&lt;h4 id=&#34;is-fim-21010-a-much-more-advanced-version-of-the-f&#34;&gt;Is FIM 21010 a much more advanced version of the F&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/09808879680127031778&#34; title=&#34;noreply@blogger.com&#34;&gt;Craig Martin&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Nov 3, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Is FIM 21010 a much more advanced version of the FIM we know today?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Awesome FIM Case Study</title>
      <link>https://identitymanaged.com/2011/11/microsoft-recently-published-case-study.html</link>
      <pubDate>Wed, 16 Nov 2011 09:54:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/microsoft-recently-published-case-study.html</guid>
      <description>&lt;p&gt;Microsoft recently published a case study about our work (Ensynch &amp;ndash; now Insight) at Grand Canyon University, implementing a FIM 2010 based identity management solution.&lt;br&gt;&#xA;The document is available for download directly from &lt;a href=&#34;http://www.microsoft.com/casestudies/Microsoft-Forefront-Identity-Manager-2010/Grand-Canyon-University/Private-University-Reduces-Identity-Management-Workload-by-320-Hours-per-Month/4000011192&#34;&gt;http://www.microsoft.com/casestudies/Microsoft-Forefront-Identity-Manager-2010/Grand-Canyon-University/Private-University-Reduces-Identity-Management-Workload-by-320-Hours-per-Month/4000011192&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>O Blog how I have neglected thee</title>
      <link>https://identitymanaged.com/2011/11/ok-so-i-have-neglected-my-blog-bit-comments.html</link>
      <pubDate>Wed, 16 Nov 2011 09:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/ok-so-i-have-neglected-my-blog-bit-comments.html</guid>
      <description>&lt;h4 id=&#34;wow-sorry-to-hear-about-the-past-few-months-soun&#34;&gt;Wow, sorry to hear about the past few months, soun&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/12709935231831153954&#34; title=&#34;noreply@blogger.com&#34;&gt;Derek A. Hanson&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Nov 3, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Wow, sorry to hear about the past few months, sounds like it was pretty rough. Congrats on the acquisition and all the best with your projects.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>O Blog how I have neglected thee</title>
      <link>https://identitymanaged.com/2011/11/ok-so-i-have-neglected-my-blog-bit.html</link>
      <pubDate>Wed, 16 Nov 2011 09:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/11/ok-so-i-have-neglected-my-blog-bit.html</guid>
      <description>&lt;p&gt;Ok so I have neglected my blog a bit. You all saw the news that Ensynch is now part of Insight.&lt;/p&gt;&#xA;&lt;p&gt;Wow the same day we announced the merger (9/19), I was also given word that my uncle and cousin died in a plane crash, that wound up making the regional news.&lt;/p&gt;&#xA;&lt;p&gt;Later my kids earned their trip to Disneyland, so we took them in early October.&lt;/p&gt;&#xA;&lt;p&gt;One of our architects had to disengage from a &lt;em&gt;big&lt;/em&gt; project (for personal reasons) and I needed to step in and play that role too.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Big news–Insight &#43; Ensynch</title>
      <link>https://identitymanaged.com/2011/09/big-newsinsight-ensynch.html</link>
      <pubDate>Fri, 23 Sep 2011 12:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/09/big-newsinsight-ensynch.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.insight.com/us/en/12760.html&#34;&gt;Insight to acquire Ensynch.&lt;/a&gt;&lt;br&gt;&#xA;As my colleague &lt;a href=&#34;http://www.apollojack.com/2011/09/ensynch-joins-insight.html?utm_source=feedburner&amp;amp;utm_medium=feed&amp;amp;utm_campaign=Feed%3A+ApolloJack+%28Apollo+Jack%29&#34;&gt;Rebecca Croft said&lt;/a&gt;:&lt;br&gt;&#xA;We are very excited about the union of Insight and Ensynch and the benefits that it will bring to our clients. Both companies are focused on helping our clients find innovative, cost effective solutions to address business needs. Bringing Ensynch into the Insight organization will offer clients more robust software services, particularly around Microsoft Enterprise Agreements, as well as improved services delivery, enhanced virtualization and cloud capabilities and solution-focused approach to software sales. This acquisition will further simplify our clients’ ability to acquire, procure, implement and manage IT solutions across their technology environment.&lt;br&gt;&#xA;For more information, read the press release &lt;a href=&#34;https://www.insight.com/us/en/12760.html&#34;&gt;here&lt;/a&gt;, visit &lt;a href=&#34;http://www.insight.com/&#34;&gt;www.insight.com&lt;/a&gt; or &lt;a href=&#34;http://www.ensynch.com/&#34;&gt;www.ensynch.com&lt;/a&gt;, or contact me with any questions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Get 15% off of FIM Best Practices Volume 1</title>
      <link>https://identitymanaged.com/2011/09/get-15-off-of-fim-best-practices-volume.html</link>
      <pubDate>Fri, 23 Sep 2011 12:11:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/09/get-15-off-of-fim-best-practices-volume.html</guid>
      <description>&lt;p&gt;Through Sept 26th get 15% of FIM Best Practices Volume 1 at lulu.com&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Use the following code at checkout OKTOBERFEST305&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Get 20% of FIM Best Practices Volume 1</title>
      <link>https://identitymanaged.com/2011/09/get-20-of-fim-best-practices-volume-1.html</link>
      <pubDate>Tue, 06 Sep 2011 05:33:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/09/get-20-of-fim-best-practices-volume-1.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.lulu.com/commerce/index.php?fBuyContent=9139861&#34;&gt;Buy FIM Best Practices Volume 1 in Soft Cover&lt;/a&gt; or &lt;a href=&#34;https://www.lulu.com/product/file-download/fim-best-practices-volume-1-introduction-architecture-and-installation-of-forefront-identity-manager-2010/15146855&#34;&gt;E-Book&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Enter coupon code &lt;strong&gt;SEPTEMBER305&lt;/strong&gt; at checkout and receive 20% off your order. The maximum savings for this offer is $100. Offer expires on September 9 at 11:59 PM&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Calling a stored procedure in an ADFS claims rule</title>
      <link>https://identitymanaged.com/2011/09/calling-stored-procedure-in-adfs-claims.html</link>
      <pubDate>Thu, 01 Sep 2011 06:34:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/09/calling-stored-procedure-in-adfs-claims.html</guid>
      <description>&lt;p&gt;After you have setup your &lt;a href=&#34;http://blog.ilmbestpractices.com/2011/09/troubleshooting-sql-attribute-stores.html&#34;&gt;SQL Attribute Claims Store in ADFS&lt;/a&gt;. If you want to use it and in fact test it you must set up a claims rule that makes use of it. To do this you must create a claim using a custom rule, which allows you to employ the &lt;a href=&#34;http://technet.microsoft.com/en-us/library/adfs2-help-the-claim-rule-language(WS.10).aspx&#34;&gt;claims rule language&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;The following &lt;a href=&#34;http://technet.microsoft.com/en-us/library/adfs2-help-attribute-stores(WS.10).aspx&#34;&gt;technet entry is a good start&lt;/a&gt; as it illustrates how to enter a SQL Query and even a stored procedure.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Troubleshooting SQL Attribute Stores with ADFS</title>
      <link>https://identitymanaged.com/2011/09/troubleshooting-sql-attribute-stores.html</link>
      <pubDate>Thu, 01 Sep 2011 06:21:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/09/troubleshooting-sql-attribute-stores.html</guid>
      <description>&lt;p&gt;Several &lt;a href=&#34;http://www.spmcm.me/Blog/Lists/Posts/Post.aspx?ID=8&#34;&gt;others have showed how to define SQL attribute stores with ADFS&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Note that when entering the connection string there is no validation or feedback to the administrator. If there is a problem you usually won’t see it until you setup a claims rule that uses it and you get an error. So make certain to carefully build and test your &lt;a href=&#34;http://connectionstrings.com/&#34;&gt;connection string&lt;/a&gt;. Remember that if you use integrated authentication to connect to the SQL Server that it will run under the context of your ADFS Service account so you will need to grant your ADFS service account permissions to the SQL Server and Database.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using FIM Best Practices Volume 1 to study for the FIM exam</title>
      <link>https://identitymanaged.com/2011/07/using-fim-best-practices-volume-1-to-comments.html</link>
      <pubDate>Thu, 28 Jul 2011 21:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/07/using-fim-best-practices-volume-1-to-comments.html</guid>
      <description>&lt;h4 id=&#34;took-the-exam-last-week-the-book-was-a-very-helpf&#34;&gt;Took the exam last week, the book was a very helpf&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;%22noreply@blogger.com%22&#34;&gt;Anonymous&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Aug 3, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Took the exam last week, the book was a very helpful study tool.&lt;br&gt;&#xA;Phil&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Using FIM Best Practices Volume 1 to study for the FIM exam</title>
      <link>https://identitymanaged.com/2011/07/using-fim-best-practices-volume-1-to.html</link>
      <pubDate>Thu, 28 Jul 2011 21:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/07/using-fim-best-practices-volume-1-to.html</guid>
      <description>&lt;p&gt;Ok so &lt;a href=&#34;http://borntolearn.mslearn.net/btl/b/weblog/archive/2011/07/18/forefront-identity-manager-fim-beta-exam-now-available.aspx&#34;&gt;info on the exam and its list of items covered is provided here&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;For fun I thought I would map out the domain objectives to items in the &lt;a href=&#34;http://www.lulu.com/product/paperback/fim-best-practices-volume-1-introduction-architecture-and-installation-of-forefront-identity-manager-2010/12917401?productTrackingContext=search_results/search_shelf/center/1&#34;&gt;FIM Best Practices Volume 1&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;The book helps with items in area 1 Planning a FIM Implementation and Installing FIM.&lt;/p&gt;&#xA;&lt;p&gt;Objective&lt;/p&gt;&#xA;&lt;p&gt;Chapter&lt;/p&gt;&#xA;&lt;h6 id=&#34;1-planning-a-fim-implementation-and-installing-fim&#34;&gt;1. Planning a FIM Implementation and Installing FIM&lt;/h6&gt;&#xA;&lt;p&gt; &lt;/p&gt;&#xA;&lt;p&gt;1.1 Plan and design FIM topology&lt;/p&gt;&#xA;&lt;p&gt;4 and 5&lt;/p&gt;&#xA;&lt;p&gt;1.2. Install the FIM Service and the FIM Portal.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Beta Exam for FIM available until Aug 4th</title>
      <link>https://identitymanaged.com/2011/07/beta-exam-for-fim-available-until-aug.html</link>
      <pubDate>Thu, 28 Jul 2011 21:17:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/07/beta-exam-for-fim-available-until-aug.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://borntolearn.mslearn.net/btl/b/weblog/archive/2011/07/18/forefront-identity-manager-fim-beta-exam-now-available.aspx&#34; title=&#34;http://borntolearn.mslearn.net/btl/b/weblog/archive/2011/07/18/forefront-identity-manager-fim-beta-exam-now-available.aspx&#34;&gt;http://borntolearn.mslearn.net/btl/b/weblog/archive/2011/07/18/forefront-identity-manager-fim-beta-exam-now-available.aspx&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Beta exam 71-158_, TS: Forefront Identity Manager 2010, Configuring_&lt;/p&gt;&#xA;&lt;p&gt;So in a short while we should see some folks who are actually Microsoft Certified Technical Specialists(MCTS)  for FIM!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Bug for multi-valued strings that need approval</title>
      <link>https://identitymanaged.com/2011/06/fim-bug-for-multi-valued-strings-that.html</link>
      <pubDate>Tue, 28 Jun 2011 09:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/06/fim-bug-for-multi-valued-strings-that.html</guid>
      <description>&lt;p&gt;I think I found a bug in FIM Version 4.0.3576.2 take a look:&lt;/p&gt;&#xA;&lt;p&gt;It appears that when you have a multi-valued string attribute when you add more than 1 value at a time and you need approval to create the object or to update the attribute, the request will fail. In the event log you will see an error (UnwillingToPerformException … CREATE UNIQUE INDEX statement terminated because a duplicate key was found for the object).&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Extensible Management Agents That Scale (Rebecca Croft)</title>
      <link>https://identitymanaged.com/2011/06/sql-extensible-management-agents-that.html</link>
      <pubDate>Thu, 23 Jun 2011 15:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/06/sql-extensible-management-agents-that.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.apollojack.com/&#34;&gt;Rebecca&lt;/a&gt;, a fellow Ensynchian, presented at TEC 2011 on the limitations of the standard out of the box SQL Management and how she overcame them by writing a very fast eXtensible Management Agent (XMA).&lt;/p&gt;&#xA;&lt;p&gt;First attempt use ado.net sql reader to read data (really fast) and write one row at a time to the AVP file (but that gets slow when dealing with large data sets).&lt;/p&gt;&#xA;&lt;p&gt;Second attempt use the T-SQL “FOR XML” clause to transform the data to XML and then use an XSLT to transform to LDIF.&lt;/p&gt;</description>
    </item>
    <item>
      <title>RCDC Editor</title>
      <link>https://identitymanaged.com/2011/06/rcdc-editor.html</link>
      <pubDate>Fri, 17 Jun 2011 06:58:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/06/rcdc-editor.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2009/11/fim-rcdc-explained-in-brief.html&#34;&gt;As previously discussed the RCDC&lt;/a&gt; is a very powerful tool for customizing FIM without writing your own front-end and web client. There are several drawbacks to the RCDC. The worst is that you have to export the RCDC to an xml file, open it up in your favorite XML editor, modify it by hand, load it back into the FIM Portal and then run iisreset. All of which means that mistakes are quite painful, as it can take you several minutes to discover your mistake. Worse if you made more than one change. Ugh!&lt;br&gt;&#xA;So thanks to my friends over at OCG there is an &lt;a href=&#34;https://oxfordcomputertraining.com/tools/rcdc-editor/&#34;&gt;RCDC editor&lt;/a&gt;. While not perfect it can shave hours off your time to edit RCDC’s.&lt;br&gt;&#xA;You get an almost WYSIWYG editor that saves you from making many easy simple mistakes. If I need to tweak something simple I might for go it, but then again I have lots of experience tweaking the RCDC by hand (painful experience). For $775 for a project I can get an editor that makes life much simpler. No brainer!&lt;br&gt;&#xA;The UI is good but not perfectly intuitive. I found several “bugs” only to discover that I needed to learn just a bit more about the tool.&lt;br&gt;&#xA;You will need to run a PowerShell command to export the FIM Configuration, install the software before you can use it at all. After activating the license you can save the RCDC’s as XML. Then yes you still have to load the RCDC manually and run iisreset. Nonetheless, this is still much easier.&lt;br&gt;&#xA;While you are still learning more about what the RCDC can do, this is still an iterative process. Creating an RCDC for a new FIM resource type is now a 2-8 hour job instead of 8-32 hour job.&lt;br&gt;&#xA;The Resultant Rights Editor is a nice bonus that allows you to setup scenarios (who is accessing what resource and which attributes to include) so that you can see what control will be visible, and enabled for the different users.&lt;br&gt;&#xA;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/RCDC-Editor_A2C7/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/RCDC-Editor_A2C7/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;br&gt;&#xA;Three complaints (with paraphrased responses from Tools4FIM):&lt;/p&gt;</description>
    </item>
    <item>
      <title>RCDC Requiring another field</title>
      <link>https://identitymanaged.com/2011/06/rcdc-requiring-another-field.html</link>
      <pubDate>Tue, 14 Jun 2011 20:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/06/rcdc-requiring-another-field.html</guid>
      <description>&lt;p&gt;Ok I just had to blog this.&lt;/p&gt;&#xA;&lt;p&gt;I created a custom resource type in FIM for resource mailboxes (Room and Equipment) with accompanying RCDC’s. Based on a Boolean attribute I &lt;a href=&#34;http://www.identitytrench.com/2010/08/hiding-tabs-in-fim-2010-rcdcs.html&#34;&gt;hide or make visible a tab&lt;/a&gt; of info about Room resources on the edit and view RCDC’s.  (You can’t do that to the create RCDC because the object doesn’t yet exist)&lt;/p&gt;&#xA;&lt;p&gt;But, I would like to make room number on the Hidden tab to be required when the tab is visible, and not when the tab isn’t. Obviously I can’t do that on the create because the object doesn’t yet exist and so I can’t reference the Boolean attribute. So I just set the required property to true and figured it would work or not. – It does not work. The tab is still hidden until I click finish and then the tab is revealed and it insists on input to the field “The required field cannot be empty”.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM 2010 R2 News</title>
      <link>https://identitymanaged.com/2011/05/fim-2010-r2-news.html</link>
      <pubDate>Mon, 23 May 2011 08:00:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/05/fim-2010-r2-news.html</guid>
      <description>&lt;p&gt;At &lt;a href=&#34;http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/SIM332&#34;&gt;Tech Ed Atlanta Brjann Brekkan and Mark Wahl discussed FIM 2010 R2&lt;/a&gt; in a public forum – so here is a lot of info that is now in the public forum.&lt;/p&gt;&#xA;&lt;p&gt;Mark covered the new items that will come out in R2:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Web Based Password reset (no need for a domain joined computer, no need to install Password Client no need for Active X, support for Firefox)&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Although for integration with the GINA (the login screen) you still need to install the FIM Password Reset Client&lt;/p&gt;</description>
    </item>
    <item>
      <title>Behind the scenes of RoomResources–Custom Properties</title>
      <link>https://identitymanaged.com/2011/05/behind-scenes-of-roomresourcescustom.html</link>
      <pubDate>Mon, 16 May 2011 22:26:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/05/behind-scenes-of-roomresourcescustom.html</guid>
      <description>&lt;p&gt;While using FIM and PowerShell to manage Exchange 2010 I was following along a &lt;a href=&#34;http://www.msexchange.org/articles_tutorials/exchange-server-2010/management-administration/resource-mailboxes-exchange-2010-part2.html&#34;&gt;wonderful article on resource mailboxes&lt;/a&gt; that left me wondering a few things.&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Exactly how is the data stored in the msExchResourceDisplay and msExchResourceSearchProperties attributes?&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;How is it stored with multiple custom properties?&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Is manipulating those AD attributes sufficient or is PowerShell storing something in the Exchange Data store?&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Here are the answers:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/81f9f4fbd19b_133C8/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/81f9f4fbd19b_133C8/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;msExchResourceDisplay = “Room,FlatScreenTV” It appears to be a single valued string with commas.&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;msExchResourceSearchProperties at first blush appears to be a single-valued string with semi-colons, however further examination reveals it to be a multi-valued attribute&lt;/p&gt;</description>
    </item>
    <item>
      <title>RSS feed for FIM Hotfixes</title>
      <link>https://identitymanaged.com/2011/05/rss-feed-for-fim-hotfixes.html</link>
      <pubDate>Wed, 11 May 2011 12:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/05/rss-feed-for-fim-hotfixes.html</guid>
      <description>&lt;p&gt;Now you can be informed about FIM 2010 hotfixes through an RSS newsfeed&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://services.social.microsoft.com/feeds/feed/FIM2010_Hotfixes&#34; title=&#34;http://services.social.microsoft.com/feeds/feed/FIM2010_Hotfixes&#34;&gt;http://services.social.microsoft.com/feeds/feed/FIM2010_Hotfixes&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using FIM to manage BPOS/Office 365</title>
      <link>https://identitymanaged.com/2011/04/using-fim-to-managing-bposoffice-365.html</link>
      <pubDate>Wed, 20 Apr 2011 10:57:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/using-fim-to-managing-bposoffice-365.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.wapshere.com/missmiis&#34;&gt;Carol&lt;/a&gt; presented a solution to a very thorny problem – how to overcome the lack of delegation in BPOS. In BPOS a user is either an admin or a user. So she used FIM to provide the delegation. Very detailed, very complete solution. She illustrated some of the scripts she has posted on her blog such as &lt;a href=&#34;http://www.wapshere.com/missmiis/a-script-to-create-sets-and-mprs-from-templates&#34; title=&#34;http://www.wapshere.com/missmiis/a-script-to-create-sets-and-mprs-from-templates&#34;&gt;http://www.wapshere.com/missmiis/a-script-to-create-sets-and-mprs-from-templates&lt;/a&gt; &lt;/p&gt;&#xA;&lt;p&gt;Well done Carol!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM 2010 reporting using SQL Server Reporting Services (Jeremy and Craig)</title>
      <link>https://identitymanaged.com/2011/04/fim-2010-reporting-using-sql-server-comments.html</link>
      <pubDate>Wed, 20 Apr 2011 10:53:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/fim-2010-reporting-using-sql-server-comments.html</guid>
      <description>&lt;h4 id=&#34;link-to-jeremy-and-craigs-solution-please&#34;&gt;Link to Jeremy and Craig&amp;rsquo;s solution please?&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/02792335048476601154&#34; title=&#34;noreply@blogger.com&#34;&gt;Sami&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 1, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Link to Jeremy and Craig&amp;rsquo;s solution please?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.identitytrench.com/2010/11/simple-reporting-in-fim-2010-with-ssrs.html&#34;&gt;http://www.identitytrench.com/2010/11/simple-reporting-in-fim-2010-with-ssrs.html&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>FIM 2010 reporting using SQL Server Reporting Services (Jeremy and Craig)</title>
      <link>https://identitymanaged.com/2011/04/fim-2010-reporting-using-sql-server.html</link>
      <pubDate>Wed, 20 Apr 2011 10:53:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/fim-2010-reporting-using-sql-server.html</guid>
      <description>&lt;p&gt;Jeremy and Craig had an interesting shoot out showing off their differing versions of reporting from FIM. Jeremy has an “agent” that he uses to pull the data out of FIM and store it in SQL, after which doing SSRS reports is not terribly difficult. Craig’s approach was to start off by creating a generic SSRS Data Processing extension for PowerShell, and then adjusted to pull data from FIM. Both approaches look very slick. Afterwards they explained how their efforts actually turned out to be quite complimentary. Two thumbs up gentlemen!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Cloud computing single sign-on. Making ADFS work with Google and Salesforce (Nikita Ryumin)</title>
      <link>https://identitymanaged.com/2011/04/cloud-computing-single-sign-on-making.html</link>
      <pubDate>Wed, 20 Apr 2011 10:47:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/cloud-computing-single-sign-on-making.html</guid>
      <description>&lt;p&gt;This TEC session on the Directory Services track was short but sweet illustrating how to connect ADFS to Google and SalesForce.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Desktop Virtualization and Identity Management</title>
      <link>https://identitymanaged.com/2011/04/desktop-virtualization-and-identity-comments.html</link>
      <pubDate>Tue, 19 Apr 2011 14:36:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/desktop-virtualization-and-identity-comments.html</guid>
      <description>&lt;h4 id=&#34;any-chance-of-getting-an-online-version-of-this-talk&#34;&gt;Any chance of getting an online version of this talk?&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/12441782705251142051&#34; title=&#34;noreply@blogger.com&#34;&gt;Paul&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Apr 2, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Any chance of getting an online version of this talk?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Desktop Virtualization and Identity Management</title>
      <link>https://identitymanaged.com/2011/04/desktop-virtualization-and-identity.html</link>
      <pubDate>Tue, 19 Apr 2011 14:36:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/desktop-virtualization-and-identity.html</guid>
      <description>&lt;p&gt;I did a lunch time presentation in partnership with Jonathan Sander. We presented how we can use Quest VWorkspace and Quest One Identity Manager to build a corporate store (we code named it VIPER) to provide a dynamic desktop experience.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Creating Authentication Activities in FIM (Ikrima Elhassan)</title>
      <link>https://identitymanaged.com/2011/04/creating-authentication-activities-in.html</link>
      <pubDate>Tue, 19 Apr 2011 14:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/creating-authentication-activities-in.html</guid>
      <description>&lt;p&gt;This session at TEC was quite interesting. Ikrima presented quite a lot of material about how to extend FIM with your own authentication activities, demonstrating a OTP password reset approach.&lt;/p&gt;&#xA;&lt;p&gt;Code is available at &lt;a href=&#34;https://github.com/ikrima/Public-Development&#34; title=&#34;https://github.com/ikrima/Public-Development&#34;&gt;https://github.com/ikrima/Public-Development&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Recruiting</title>
      <link>https://identitymanaged.com/2011/04/recruiting.html</link>
      <pubDate>Tue, 19 Apr 2011 14:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/recruiting.html</guid>
      <description>&lt;p&gt;Hey readers, our Identity Practice at Ensynch is keeping us very busy. We would like to have more Identity consultants as part of our team. Come work with me and the rest of our fantastically talented Identity Team.&lt;/p&gt;&#xA;&lt;p&gt;We are looking for people with experience in Forefront Identity Manager 2010 and people with experience in ADFS 2.0. We are looking for both Full Time Employees as well as people interested in being contractors for us.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Designing and Implementing RBAC Solutions with FIM 2010 Group Management</title>
      <link>https://identitymanaged.com/2011/04/designing-and-implementing-rbac.html</link>
      <pubDate>Mon, 18 Apr 2011 16:33:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/designing-and-implementing-rbac.html</guid>
      <description>&lt;p&gt;After I introduced Brad Turner and turned the time over to him, he showed off some really cool FIM extensions to enable RBAC. He even showed how it fits the NIST RBAC definitions even through level 3.&lt;/p&gt;&#xA;&lt;p&gt;The key design decision was to extend the Set and Group objects. The Set then functions as a role. This allows for both explicit and criteria based membership. A new object type for a Role Membership allows for the user’s membership in a role to expire at an individual time.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Best Practices: Sizing Your FIM Installation</title>
      <link>https://identitymanaged.com/2011/04/fim-best-practices-sizing-your-fim.html</link>
      <pubDate>Mon, 18 Apr 2011 16:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/fim-best-practices-sizing-your-fim.html</guid>
      <description>&lt;p&gt;I had a lot of fun presenting this session. Largely based on chapter 5 in &lt;a href=&#34;http://www.lulu.com/commerce/index.php?fBuyContent=9139861&#34;&gt;volume 1&lt;/a&gt; I showed how to decide on your High availability approach, how that impacts your topology choice, and then how to estimate your scale, load, and complexity points. Then based on those factors figure out how big to make your SQL Server that hosts the FIM service database.&lt;/p&gt;&#xA;&lt;p&gt;In the middle I did enjoy putting in a plug for our Ensynch sponsored green, dishwasher safe water bottles, as I took a drink of my fruit punch Gatorade mix.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Can PXEs Fly? FIM and SCCM Integration (Rob Allen)</title>
      <link>https://identitymanaged.com/2011/04/can-pxes-fly-fim-and-sccm-integration.html</link>
      <pubDate>Mon, 18 Apr 2011 16:16:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/can-pxes-fly-fim-and-sccm-integration.html</guid>
      <description>&lt;p&gt;I was looking forward to this one, but got called away. I hope to look at the slides soon.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Creating Management Agents with the new EZMA (Andreas Kjellman)</title>
      <link>https://identitymanaged.com/2011/04/creating-management-agents-with-new.html</link>
      <pubDate>Mon, 18 Apr 2011 13:00:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/creating-management-agents-with-new.html</guid>
      <description>&lt;p&gt;At TEC 2011, Andreas Kjellman of Microsoft, who “owns” the FIM synchronization engine, showed off the upcoming EZMA framework.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;The problem:&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;The existing eXtensible Management Agent (XMA) does not have a call based import method, we are limited to using GUIDs as the initial anchors, and we don’t have partitions in an XMA.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Solution&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;EZMA – which, IMO, will actually be a little harder to do than an XMA but will allow the developer to do much more that will make the FIM admin’s life easier.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Files, FIM, and PowerShell (James Booth)</title>
      <link>https://identitymanaged.com/2011/04/files-fim-and-powershell-james-booth.html</link>
      <pubDate>Mon, 18 Apr 2011 11:38:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/files-fim-and-powershell-james-booth.html</guid>
      <description>&lt;p&gt;James Booth former Microsoft Group Program Manager for MIIS (precursor to FIM) presented on using PowerShell to process files in preparation for consumption by FIM.&lt;/p&gt;&#xA;&lt;p&gt;James points out that “In the beginning, it was all files.” These call based MA’s are the new kids on the block, also said that at Microsoft in 2000 the philosophy was “XML is the answer, now what is your question?”&lt;/p&gt;&#xA;&lt;p&gt;James has posted his new commandlets to GitHub &lt;a href=&#34;https://github.com/jhbooth/LDIF-PowerShell&#34;&gt;https://github.com/jhbooth/LDIF-PowerShell&lt;/a&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2011–FIM Workflows Deep dive</title>
      <link>https://identitymanaged.com/2011/04/tec-2011fim-workflows-deep-dive.html</link>
      <pubDate>Sat, 16 Apr 2011 16:13:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/tec-2011fim-workflows-deep-dive.html</guid>
      <description>&lt;p&gt;I am already in Las Vegas, prepping to assist my fellow Ensynch coworkers, Joe Zamora, and Rebecca Croft as they lead an awesome value packed pre-conference workshop tomorrow (Sunday) morning at 8 AM to 12 PM (noon). Jerry Camel and Brad Turner will also be around to assist.&lt;/p&gt;&#xA;&lt;p&gt;There are so many good sessions to attend this time here are some of the ones I am looking forward to:&lt;/p&gt;&#xA;&lt;p&gt;Monday morning gets the FIMsters off to a great start with a choice of two great sessions:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Making Sense of the Cloud</title>
      <link>https://identitymanaged.com/2011/04/making-sense-of-cloud.html</link>
      <pubDate>Wed, 13 Apr 2011 21:15:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/04/making-sense-of-cloud.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/fc23f9acc479_12A03/clip_image002.jpg&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/fc23f9acc479_12A03/clip_image002_thumb.jpg&#34; alt=&#34;clip_image002&#34; title=&#34;clip_image002&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;National Roadshow Series:  2 High Value Sessions in 1 Business Focused Technology Briefing from Leading Industry Experts at Ensynch and Microsoft&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;It’s time to make sense of the plethora of rhetoric around the term &amp;ldquo;Cloud.&amp;rdquo; It&amp;rsquo;s time to cut through the hype and figure out how to leverage the latest &lt;strong&gt;Dynamic Private Cloud&lt;/strong&gt; and &lt;strong&gt;Public Cloud&lt;/strong&gt; technologies and provide real value to your business.&lt;br&gt;&#xA;&lt;strong&gt;Why Attend?&lt;/strong&gt;&lt;br&gt;&#xA;Learn how organizations worldwide are realizing tremendous business value as they begin to migrate portions of their business to securely provide IT as a service through private and public cloud solutions.  Unlike many product-focused technology events, this event is focused on business use cases and solutions.  You will leave this event having gained real value and perspective that you can immediately apply to your business&amp;rsquo;s information technology strategy and roadmap.&lt;/p&gt;</description>
    </item>
    <item>
      <title>EBook of Vol 1 is now available</title>
      <link>https://identitymanaged.com/2011/03/ebook-of-vol-1-is-now-available.html</link>
      <pubDate>Tue, 15 Mar 2011 17:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/03/ebook-of-vol-1-is-now-available.html</guid>
      <description>&lt;p&gt;After listening to many pleas for an e-book version of FIM Best Practices Volume 1, I have relented and created an e-book version. List price is $22.00 but here is a 10% off discount for the next week to $19.80.&lt;/p&gt;&#xA;&lt;p&gt;Most of the requests were for speed of delivery, searching, but the one that got me was a request based on eyesight made by Bill Singh. So you can all thank him for there being an e-book of volume 1.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Webinar: Cloud’s Silver Lining: Identity Management</title>
      <link>https://identitymanaged.com/2011/03/webinar-clouds-silver-lining-identity.html</link>
      <pubDate>Wed, 02 Mar 2011 11:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/03/webinar-clouds-silver-lining-identity.html</guid>
      <description>&lt;p&gt;&lt;img src=&#34;http://info.ensynch.net/rs/ensynch/images/ensynch.jpg&#34; alt=&#34;ensynch logo&#34;&gt;&lt;img src=&#34;http://info.ensynch.net/rs/ensynch/images/Forefront-IM2010_h_rgb.jpg&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Business Insights Webcast: &lt;br&gt;&#xA;The Cloud&amp;rsquo;s Silver Lining: Identity Management&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;http://info.ensynch.net/rs/ensynch/images/marbles.jpg&#34; alt=&#34;main image&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Join Us for an Informative Webcast on the Value of IDA in the Cloud&lt;br&gt;&#xA;&lt;strong&gt;- Part 2 in a Series of Webcasts from Microsoft FIM MVP David Lundell -&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Identity Management is a critical component to realizing the true value of the Cloud.&lt;/p&gt;&#xA;&lt;p&gt;Solutions from Microsoft including Forefront Identity Manager (FIM), Active Directory Federation Services (AD FS), and Microsoft Forefront Unified Access Gateway (Forefront UAG) allow you to get the most out of your cloud applications (such as Office 365, BPOS, and other Software a Service (SaaS) solutions); while enabling a seamless transition in managing the identities of your users.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Training back—on May 23-26 in Phoenix</title>
      <link>https://identitymanaged.com/2011/02/fim-training-backon-may-23-26-in.html</link>
      <pubDate>Mon, 14 Feb 2011 11:36:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/02/fim-training-backon-may-23-26-in.html</guid>
      <description>&lt;p&gt;Last week I taught a group of students &lt;a href=&#34;http://www.microsoft.com/learning/en/us/course.aspx?ID=50382A&#34;&gt;50382A Implementing Forefront Identity Manager 2010&lt;/a&gt;, and referenced &lt;a href=&#34;http://blog.ilmbestpractices.com/2010/08/book-is-here-fim-best-practices-volume.html&#34;&gt;FIM Best Practices Volume 1&lt;/a&gt; to supplement. It was a great bunch, full of humor. We even had one gentleman fly all the way from Australia to attend my class. I felt quite honored.&lt;/p&gt;&#xA;&lt;p&gt;Well due to popular demand we are going to run it again May 23-May 26 (M-Th) once more in downtown Phoenix.&lt;/p&gt;&#xA;&lt;p&gt;Register by emailing &lt;a href=&#34;mailto:FIMTraining@Ensynch.com?subject=FIM%20Training%2050382A%20Feb%208%202011&#34;&gt;FIMTraining@Ensynch.com&lt;/a&gt;, providing your contact info, which class and date you want to attend. You will then be contacted to complete the registration. The cost of the course is  $1895 USD&lt;/p&gt;</description>
    </item>
    <item>
      <title>Get FIM Training from Author of FIM Best Practices Volume 1</title>
      <link>https://identitymanaged.com/2011/01/get-fim-training-from-author-of-fim.html</link>
      <pubDate>Tue, 04 Jan 2011 09:13:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2011/01/get-fim-training-from-author-of-fim.html</guid>
      <description>&lt;p&gt;Come get FIM training from David Lundell, FIM MVP and author of FIM Best Practices Volume 1.&lt;/p&gt;&#xA;&lt;p&gt;Register by emailing &lt;a href=&#34;mailto:FIMTraining@Ensynch.com?subject=FIM%20Training%2050382A%20Feb%208%202011&#34;&gt;FIMTraining@Ensynch.com&lt;/a&gt;, providing your contact info, which class and date you want to attend. You will then be contacted to complete the registration.&lt;/p&gt;&#xA;&lt;p&gt;On Feb 8th - Feb 11th in downtown Phoenix (class will start at 8 AM), I will be teaching &lt;a href=&#34;http://www.microsoft.com/learning/en/us/course.aspx?ID=50382A&#34;&gt;50382A Implementing Forefront Identity Manager 2010&lt;/a&gt; and of course adding in lots of valuable information from various FIM implementations that I have performed and supervised. Additionally, material from &lt;a href=&#34;http://blog.ilmbestpractices.com/2010/08/book-is-here-fim-best-practices-volume.html&#34;&gt;FIM Best Practices Volume 1&lt;/a&gt; will be referenced during class (bring your copy to class). The cost of the course is  $1895 USD.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Amazon–FIM Best Practices Volume 1</title>
      <link>https://identitymanaged.com/2010/12/amazonfim-best-practices-volume-1.html</link>
      <pubDate>Thu, 16 Dec 2010 10:02:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/12/amazonfim-best-practices-volume-1.html</guid>
      <description>&lt;p&gt;Apparently one of the Amazon marketplace sellers has decided to &lt;a href=&#34;http://amzn.com/B004GCHH22&#34;&gt;list my book on Amazon&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;So I am excited that it can now be found on Amazon, but it should be noted that Old Shingled House has marked it up to $49.95 a 99.5% markup. Old Shingled House is buying them through Lulu at the regular rate of $25.00. If you buy it through Amazon or through &lt;a href=&#34;http://www.lulu.com/product/paperback/fim-best-practices-volume-1-introduction-architecture-and-installation-of-forefront-identity-manager-2010/12917401?productTrackingContext=search_results/search_shelf/center/2#&#34;&gt;Lulu&lt;/a&gt;, I still get my normal cut, the question is how much you pay. Now lest you think Old Shingled House is being greedy, I did look at what it takes to make the book available on Amazon through the marketplace or by having Lulu place it out there, and there certainly are extra costs. So if you found it through Amazon good. If you found it at &lt;a href=&#34;http://www.lulu.com/product/paperback/fim-best-practices-volume-1-introduction-architecture-and-installation-of-forefront-identity-manager-2010/12917401?productTrackingContext=search_results/search_shelf/center/2#&#34;&gt;Lulu&lt;/a&gt; and bought there even better for you.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Buy FIM Vol 1 and Get free ground shipping through Dec 12th</title>
      <link>https://identitymanaged.com/2010/12/buy-fim-vol-1-and-get-free-ground.html</link>
      <pubDate>Tue, 07 Dec 2010 17:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/12/buy-fim-vol-1-and-get-free-ground.html</guid>
      <description>&lt;p&gt;From LULU:&lt;/p&gt;&#xA;&lt;p&gt;Enter coupon code &lt;strong&gt;HOLIDAY305&lt;/strong&gt; to receive free ground shipping. Shipping address must be within the United States. The maximum savings for this offer is $45. Sorry, but this offer is only valid in US dollars and cannot be applied to previous orders. You can only use this code once per account, and unfortunately you can&amp;rsquo;t use this coupon in combination with other coupon codes. This great offer expires on December 12, 2010 at 11:59 PM PST, so don&amp;rsquo;t miss out! While very unlikely, we do reserve the right to change or revoke this offer at anytime, and of course we cannot offer this coupon where it is against the law to do so.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Law of Unintended Consequences</title>
      <link>https://identitymanaged.com/2010/12/law-of-unintended-consequences-comments.html</link>
      <pubDate>Fri, 03 Dec 2010 16:41:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/12/law-of-unintended-consequences-comments.html</guid>
      <description>&lt;h4 id=&#34;any-news-on-certification-paths-for-idm&#34;&gt;Any news on certification paths for IDM?&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/12709935231831153954&#34; title=&#34;noreply@blogger.com&#34;&gt;Derek A. Hanson&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Dec 6, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Any news on certification paths for IDM?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Hey Derek,&lt;/p&gt;&#xA;&lt;p&gt;No news yet. Just my own speculation but I would expect to see an exam covering several Microsoft Identity Technologies emerging sometime next year.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Law of Unintended Consequences</title>
      <link>https://identitymanaged.com/2010/12/law-of-unintended-consequences.html</link>
      <pubDate>Fri, 03 Dec 2010 16:41:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/12/law-of-unintended-consequences.html</guid>
      <description>&lt;p&gt;In the process of setting up to teach &lt;a href=&#34;http://www.microsoft.com/learning/en/us/Course.aspx?ID=50382A&amp;amp;Locale=en-us&#34;&gt;50382A - Implementing Forefront Identity Manager 2010&lt;/a&gt; in Phoenix, AZ (Feb 8-11 and May 23 – May 26 – registration info to follow in a subsequent post) and looking at other courses in the Microsoft Courseware library I have noticed an interesting trend – most courses have lots of very bland reviews like this:&lt;/p&gt;&#xA;&lt;p&gt;“Good Course”&lt;/p&gt;&#xA;&lt;p&gt;“Good one”&lt;/p&gt;&#xA;&lt;p&gt;“Good content and best practices”&lt;/p&gt;</description>
    </item>
    <item>
      <title>Get 25% off of FIM Best Practices Volume 1 Today only</title>
      <link>https://identitymanaged.com/2010/11/get-25-off-of-fim-best-practices-volume.html</link>
      <pubDate>Tue, 30 Nov 2010 13:39:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/11/get-25-off-of-fim-best-practices-volume.html</guid>
      <description>&lt;p&gt;Valid today only through 11:59 PM (EST) and only valid in the US, Lulu is offering 25% off. So you can order FIM Best Practices at 25% off. Enter the following promo code at Checkout: CYBER305&lt;/p&gt;&#xA;&lt;p&gt;Click here to look at the book: &lt;a href=&#34;http://www.lulu.com/spotlight/david_lundell&#34;&gt;http://www.lulu.com/spotlight/david_lundell&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Webinar is available for viewing</title>
      <link>https://identitymanaged.com/2010/11/webinar-is-available-for-viewing.html</link>
      <pubDate>Sun, 14 Nov 2010 18:35:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/11/webinar-is-available-for-viewing.html</guid>
      <description>&lt;p&gt;The webinar on Friday went well. Here it is available for viewing at your pleasure.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Case Study: Real World organizations simplify Identity Management</title>
      <link>https://identitymanaged.com/2010/11/case-study-real-world-organizations.html</link>
      <pubDate>Thu, 11 Nov 2010 16:53:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/11/case-study-real-world-organizations.html</guid>
      <description>&lt;p&gt;Tomorrow morning at 8 AM PST I will be participating as a speaker in a &lt;a href=&#34;http://www.brighttalk.com/webcast/22703&#34;&gt;webinar&lt;/a&gt; with Jonathan Sander from Quest.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.brighttalk.com/webcast/22703&#34; title=&#34;http://www.brighttalk.com/webcast/22703&#34;&gt;http://www.brighttalk.com/webcast/22703&lt;/a&gt; &lt;/p&gt;&#xA;&lt;p&gt;Successful identity and access management means different things to different organizations, but in almost every case, it requires complex, time-consuming, and expensive solutions. However, an ever-growing number of organizations have found a new way to achieve their identity and access management objectives simply, inexpensively, and powerfully.&lt;/p&gt;&#xA;&lt;p&gt;In this webcast, identity and access management experts will discuss how organizations like yours have discovered and are implementing a simplified approach to identity and access management.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2010 Europe – Sweet German Chocolate!</title>
      <link>https://identitymanaged.com/2010/10/tec-2010-europe-sweet-german-chocolate-comments.html</link>
      <pubDate>Mon, 18 Oct 2010 14:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/10/tec-2010-europe-sweet-german-chocolate-comments.html</guid>
      <description>&lt;h4 id=&#34;sounds-like-a-great-conference-the-berliners-will&#34;&gt;Sounds like a great conference. The Berliners will&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/12657275235326387872&#34; title=&#34;noreply@blogger.com&#34;&gt;johnkaiser&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Nov 2, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Sounds like a great conference. The Berliners will want you back soon with Volume2!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>TEC 2010 Europe – Sweet German Chocolate!</title>
      <link>https://identitymanaged.com/2010/10/tec-2010-europe-sweet-german-chocolate.html</link>
      <pubDate>Mon, 18 Oct 2010 14:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/10/tec-2010-europe-sweet-german-chocolate.html</guid>
      <description>&lt;p&gt;Overall TEC 2010 Europe  in Dusseldorf Germany was pretty cool. I enjoyed the speakers reception on Sunday night and got to meet some folks from the SharePoint side some of whom are even interested in FIM and one of them bought my book!&lt;/p&gt;&#xA;&lt;p&gt;For the first time I was able to bring my wife along to TEC! We enjoyed some good time in Dusseldorf including seeing Schloss (Palace) Benrather.&lt;/p&gt;&#xA;&lt;p&gt;Monday we started off with a keynote from  Uday Hegde and Mark Wahl on the future of Directory and Identity Technologies. It was mostly an overview and demo of the various MSFT Identity technologies, FIM, RMS, ADFS etc. I did enjoy Mark’s well prepared video demo. He clearly had practiced the timing quite well, explaining as the mouse moved across the screen carrying out his demo.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Details of Errata</title>
      <link>https://identitymanaged.com/2010/09/details-of-errata.html</link>
      <pubDate>Wed, 29 Sep 2010 15:29:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/details-of-errata.html</guid>
      <description>&lt;p&gt;Here is what the text on page 183 should say (the italicized items are the new or changed bits of text)&lt;/p&gt;&#xA;&lt;h5 id=&#34;unattended-install-of-the-fim-client&#34;&gt;Unattended Install of the FIM Client&lt;/h5&gt;&#xA;&lt;p&gt;This is the component that you will perhaps most desperately see the need for unattended install.&lt;/p&gt;&#xA;&lt;p&gt;Use the following table to help you plan your install as well as to understand the relationship between the UI parameters, the Unattended parameters and where these items are persisted. &lt;em&gt;These items can also be controlled through Group Policy templates that are shipped with the product.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Errata and Updates to FIM Best Practices Volume 1</title>
      <link>https://identitymanaged.com/2010/09/errata-and-updates-to-fim-best-comments.html</link>
      <pubDate>Wed, 29 Sep 2010 07:11:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/errata-and-updates-to-fim-best-comments.html</guid>
      <description>&lt;h4 id=&#34;could-you-post-a-complete-listing-of-the-correctio&#34;&gt;Could you post a complete listing of the correctio&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13416728309090644719&#34; title=&#34;noreply@blogger.com&#34;&gt;Keith Crosby&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 3, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Could you post a complete listing of the corrections? In particular, the changes around the unattended client install. BTW, great job on Volume 1. I&amp;rsquo;m, looking forward to Volume 2 (and an eBook version would be great as well).&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;I love volume 1! Is it too soon to start asking about volume 2 :-)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Errata and Updates to FIM Best Practices Volume 1</title>
      <link>https://identitymanaged.com/2010/09/errata-and-updates-to-fim-best.html</link>
      <pubDate>Wed, 29 Sep 2010 07:11:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/errata-and-updates-to-fim-best.html</guid>
      <description>&lt;p&gt;Thanks to several readers including Freek Berson, for catching a few errors I made while revising after my first round of reviewers.&lt;/p&gt;&#xA;&lt;p&gt;Changes: in version 1.1 (Sept 28, 2010)&lt;/p&gt;&#xA;&lt;p&gt;Chapter 1, updated the manager to director card, previously the word director was not visible (page 2)&lt;/p&gt;&#xA;&lt;p&gt;Manager&lt;/p&gt;&#xA;&lt;p&gt;Director&lt;/p&gt;&#xA;&lt;p&gt;Chapter 1 Fixed “Error Missing Reference” in Chapter 1 (page 4) to refer to Figure 1-2 Actual Photo of Smart Card&lt;/p&gt;&#xA;&lt;p&gt;Fixed client unattended install in Chapter 7: deleted reference to config files and corrected registry references.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Extinguishing Cystic Fibrosis</title>
      <link>https://identitymanaged.com/2010/09/extinguishing-cystic-fibrosis.html</link>
      <pubDate>Wed, 15 Sep 2010 09:43:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/extinguishing-cystic-fibrosis.html</guid>
      <description>&lt;p&gt;Well, we are on our way towards our goal of $2000, but we need more help (please &lt;a href=&#34;http://azstairclimb.kintera.org/faf/donorReg/donorPledge.asp?ievent=429516&amp;amp;lis=1&amp;amp;kntae429516=8A9E846281D84357B19B34FDF5DDFFCA&amp;amp;supId=0&amp;amp;team=3867503&amp;amp;cj=&#34;&gt;make a donation&lt;/a&gt;).&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ExtinguishingCysticFibrosis_880F/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ExtinguishingCysticFibrosis_880F/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Refresher:&lt;/p&gt;&#xA;&lt;p&gt;Every year Ensynch sponsor’s the Ensynch Stairclimb and Firefighter challenge. The purpose of the event is to raise money for research on Cystic Fibrosis. The &lt;a href=&#34;http://azstairclimb.kintera.org/faf/help/helpEventInfo.asp?ievent=429516&#34;&gt;event is this Saturday&lt;/a&gt;, in Phoenix at Arizona Center - 5th Street &amp;amp; Van Buren.  This year I am heading up the Stripes team, we have a goal of raising $2000 by this Saturday. Many of our team mates at Ensynch will be climbing stairs. If you live in Phoenix or will be here this Saturday you can &lt;a href=&#34;https://www.kintera.org/faf/reg_new/register.asp?ievent=429516&amp;amp;lis=1&amp;amp;kntae429516=8A9E846281D84357B19B34FDF5DDFFCA&amp;amp;jt=3867503&amp;amp;teamsName=Ensynch+PS+Stripes&#34;&gt;participate too&lt;/a&gt; (you can climb or come and cheer as part of the no-sweat supporters). Alternatively, you can sponsor one, &lt;a href=&#34;http://azstairclimb.kintera.org/faf/donorReg/donorPledge.asp?ievent=429516&amp;amp;lis=1&amp;amp;kntae429516=8A9E846281D84357B19B34FDF5DDFFCA&amp;amp;supId=0&amp;amp;team=3867503&amp;amp;cj=&#34;&gt;make a donation&lt;/a&gt; in our team’s name. The event also includes cheering on different firefighting teams as they perform their challenges!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fighting Cystic Fibrosis</title>
      <link>https://identitymanaged.com/2010/09/fighting-cystic-fibrosis.html</link>
      <pubDate>Mon, 13 Sep 2010 11:24:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/fighting-cystic-fibrosis.html</guid>
      <description>&lt;p&gt;Every year Ensynch sponsor’s the Ensynch Stairclimb and Firefighter challenge. The purpose of the event is to raise money for research on Cystic Fibrosis. The &lt;a href=&#34;http://azstairclimb.kintera.org/faf/help/helpEventInfo.asp?ievent=429516&#34;&gt;event is this Saturday&lt;/a&gt;, in Phoenix at Arizona Center - 5th Street &amp;amp; Van Buren.  This year I am heading up the Stripes team, we have a goal of raising $2000 by this Saturday. Many of our team mates at Ensynch will be climbing stairs. If you live in Phoenix or will be here this Saturday you can &lt;a href=&#34;https://www.kintera.org/faf/reg_new/register.asp?ievent=429516&amp;amp;lis=1&amp;amp;kntae429516=8A9E846281D84357B19B34FDF5DDFFCA&amp;amp;jt=3867503&amp;amp;teamsName=Ensynch+PS+Stripes&#34;&gt;participate too&lt;/a&gt; (you can climb or come and cheer as part of the no-sweat supporters). Alternatively, you can sponsor one, &lt;a href=&#34;http://azstairclimb.kintera.org/faf/donorReg/donorPledge.asp?ievent=429516&amp;amp;lis=1&amp;amp;kntae429516=8A9E846281D84357B19B34FDF5DDFFCA&amp;amp;supId=0&amp;amp;team=3867503&amp;amp;cj=&#34;&gt;make a donation&lt;/a&gt; in our team’s name. The event also includes cheering on different firefighting teams as they perform their challenges!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Default GalSync Connector Filter</title>
      <link>https://identitymanaged.com/2010/09/default-galsync-connector-filter-comments.html</link>
      <pubDate>Tue, 07 Sep 2010 11:35:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/default-galsync-connector-filter-comments.html</guid>
      <description>&lt;h4 id=&#34;hi--if-i-want-to-exclude-a-handful-of-users-fr&#34;&gt;Hi , If I want to exclude a handful of users fr&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/08959288275341385389&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Aug 3, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hi ,&lt;/p&gt;&#xA;&lt;p&gt;If I want to exclude a handful of users from an OU moving across with the GALSync , am I correct to click on the user datasource object type and do a declared import filter then add their display names equals , will this work ?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Default GalSync Connector Filter</title>
      <link>https://identitymanaged.com/2010/09/default-galsync-connector-filter.html</link>
      <pubDate>Tue, 07 Sep 2010 11:35:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/default-galsync-connector-filter.html</guid>
      <description>&lt;p&gt;Using FIM 2010 RTM Update 1:&lt;/p&gt;&#xA;&lt;p&gt;The default GalSync Connector Filter is to filter out user objects that are hidden from the addressbook, OR missing the legacyExchangeDN, OR missing both the msExchangeHomeServerName and targetAddress are missing, OR proxyAddresses are missing, OR if it is a Mailbox Plan, Arbitration Mailbox, or Discovery Mailbox.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/DefaultGalSyncConnectorFilter_A2DC/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/DefaultGalSyncConnectorFilter_A2DC/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Consequently, this answers the question are mail-enabled users filtered out by default?&lt;/p&gt;&#xA;&lt;p&gt;No they are not, as a mail-enabled user will have the target address populated, and none of the other rules will filter it out.&lt;/p&gt;</description>
    </item>
    <item>
      <title>When moving the FIM DB ensure FT Indexing enabled</title>
      <link>https://identitymanaged.com/2010/09/when-moving-fim-db-ensure-ft-indexing.html</link>
      <pubDate>Sat, 04 Sep 2010 06:39:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/when-moving-fim-db-ensure-ft-indexing.html</guid>
      <description>&lt;p&gt;I just found a very intriguing blog post from &lt;a href=&#34;http://setspn.blogspot.com/&#34;&gt;Thomas&lt;/a&gt; Vuylsteke, about a potential danger when moving your FIM Service Database from SQL Server to another: &lt;a href=&#34;http://setspn.blogspot.com/2010/09/case-of-new-attributes-that-didnt-want.html&#34; title=&#34;The case of the new attributes that didn’t want to be found&#34;&gt;The case of the new attributes that didn’t want to be found&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;In short there is the potential that when you move the database that it might arrive on the new server with the Full Text Indexing disabled. The way Thomas tumbled to the problem was that he couldn’t search for a new attribute.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC Europe – Come hear me speak!</title>
      <link>https://identitymanaged.com/2010/09/tec-europe-come-hear-me-speak.html</link>
      <pubDate>Wed, 01 Sep 2010 20:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/09/tec-europe-come-hear-me-speak.html</guid>
      <description>&lt;p&gt;I will be presenting at TEC Europe in Dusseldorf Germany Oct 4-6. During my sessions I will give away a copy or two of my book &lt;a href=&#34;http://www.lulu.com/content/paperback-book/fim-best-practices-volume-1-introduction-architecture-and-installation-of-forefront-identity-manager-2010/9139861&#34;&gt;FIM Best Practices Volume 1&lt;/a&gt; .&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.theexpertsconference.com/europe/&#34;&gt;&lt;img src=&#34;http://www.theexpertsconference.com/europe/wp-content/uploads/2010/06/tec-speaker.jpg&#34; alt=&#34;tec-speaker&#34; title=&#34;tec-speaker&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;FIM 2010 Performance Tuning (SQL and more)&lt;br&gt;&#xA;Speaker:&lt;/strong&gt; &lt;a href=&#34;http://www.theexpertsconference.com/agenda-speakers/directory-identity-training/speaker-bios/#lundell&#34;&gt;David Lundell&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Learn how to tune FIM 2010 to make it scream. Take a look at the various architectures and what they buy you. Learn how crucial SQL is to FIM performance and what to do about it. You’ll also learn tips for workflows and the FIM web service and receive a crash course in the SQL Server Optimization.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Book is here! FIM Best Practices Volume 1 is Available</title>
      <link>https://identitymanaged.com/2010/08/book-is-here-fim-best-practices-volume-comments.html</link>
      <pubDate>Sun, 29 Aug 2010 23:17:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/08/book-is-here-fim-best-practices-volume-comments.html</guid>
      <description>&lt;h4 id=&#34;congratulations-ill-order-it-immediately&#34;&gt;Congratulations!! I&amp;rsquo;ll order it immediately.&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/17688001430167255272&#34; title=&#34;noreply@blogger.com&#34;&gt;Naohiro Fujie&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Aug 1, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Congratulations!!&lt;br&gt;&#xA;I&amp;rsquo;ll order it immediately.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Congrats, any chance of an ebook?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Dan,&lt;br&gt;&#xA;I considered the e-book route, but at least for the time being decided to go with a printed version. Feel free to lobby and persuade me why an ebook version would be better.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Book is here! FIM Best Practices Volume 1 is Available</title>
      <link>https://identitymanaged.com/2010/08/book-is-here-fim-best-practices-volume.html</link>
      <pubDate>Sun, 29 Aug 2010 23:17:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/08/book-is-here-fim-best-practices-volume.html</guid>
      <description>&lt;h3 id=&#34;to-purchase-a-copy-of-the-book-please-follow-this-link&#34;&gt;&lt;a href=&#34;http://www.lulu.com/content/paperback-book/fim-best-practices-volume-1-introduction-architecture-and-installation-of-forefront-identity-manager-2010/9139861&#34;&gt;&lt;strong&gt;To purchase a copy of the book please follow this link&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt;&lt;/h3&gt;&#xA;&lt;p&gt;The best view to present from the lulu site is probably this one: &lt;a href=&#34;http://www.lulu.com/spotlight/david_lundell&#34; title=&#34;http://www.lulu.com/spotlight/david_lundell&#34;&gt;http://www.lulu.com/spotlight/david_lundell&lt;/a&gt; as it has the brief description of the book and the author bio.&lt;br&gt;&#xA;You also have the ability to &lt;a href=&#34;http://www.lulu.com/product/paperback/fim-best-practices-volume-1-introduction-architecture-and-installation-of-forefront-identity-manager-2010/12453182#&#34;&gt;preview a few parts of the book&lt;/a&gt;&lt;br&gt;&#xA;The book came out to be 258 pages from cover to cover, and yes we included an index! By publishing it through Lulu.com (a Print on Demand company) we got to be much more in control of the whole process, and had faster time to market.&lt;br&gt;&#xA;Here are some comments from folks that have had access to pre-release copies:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Book update</title>
      <link>https://identitymanaged.com/2010/08/book-update.html</link>
      <pubDate>Fri, 20 Aug 2010 18:11:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/08/book-update.html</guid>
      <description>&lt;p&gt;Early last week I sent the book out for review. I have been digesting the excellent feedback I have gotten (thanks to Peter Geelen, Paul Loonen, Andreas Kjellman, and Glenn Zuckerman). Apparently, they liked Brad’s architecture diagrams more than mine (so do I) so I need to update the other architecture diagrams to be like his. They really do look neater. Check out this one on FIM multi-tier with an admin partition:&lt;/p&gt;</description>
    </item>
    <item>
      <title>ADFS v2 Test Report -- Found</title>
      <link>https://identitymanaged.com/2010/08/adfs-v2-test-report-found.html</link>
      <pubDate>Fri, 20 Aug 2010 07:58:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/08/adfs-v2-test-report-found.html</guid>
      <description>&lt;p&gt;Something has happened with the project liberty website and most links to it are now broken, including the link to the test results from last year which includes which profiles ADFS v2 passed. So here it is:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://projectliberty.org/liberty/content/download/4732/32917/file/SAML_3Q09_%20IOP_Test_Event_Final_Report.pdf&#34; title=&#34;http://projectliberty.org/liberty/content/download/4732/32917/file/SAML_3Q09_%20IOP_Test_Event_Final_Report.pdf&#34;&gt;http://projectliberty.org/liberty/content/download/4732/32917/file/SAML_3Q09_%20IOP_Test_Event_Final_Report.pdf&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;ADFS v2 passed: IDP Lite, SP Lite, eGov 1.5&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Book: FIM Best Practices Volume 1</title>
      <link>https://identitymanaged.com/2010/07/book-fim-best-practices-volume-1-comments.html</link>
      <pubDate>Thu, 29 Jul 2010 17:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/07/book-fim-best-practices-volume-1-comments.html</guid>
      <description>&lt;h4 id=&#34;hi-david-any-update-on-the-availability-date&#34;&gt;Hi David, any update on the availability date?&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/06706336872347412761&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Aug 2, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hi David, any update on the availability date?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;The day it&amp;rsquo;s out I&amp;rsquo;ll have my card ready!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Hi David, any news on the book? Hope your back is better!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://blog.ilmbestpractices.com/2010/08/book-is-here-fim-best-practices-volume.html&#34;&gt;The book is now available&lt;/a&gt;! My back is better too!&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Book: FIM Best Practices Volume 1</title>
      <link>https://identitymanaged.com/2010/07/book-fim-best-practices-volume-1.html</link>
      <pubDate>Thu, 29 Jul 2010 17:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/07/book-fim-best-practices-volume-1.html</guid>
      <description>&lt;p&gt;In two weeks we (Brad Turner is my co-author) will make available for ordering a book on FIM entitled:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;FIM Best Practices Volume 1: Introduction, Architecture And Installation Of Forefront Identity Manager 2010&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Information on order will be posted here on my blog&lt;/p&gt;&#xA;&lt;p&gt;This will be the first book on Forefront Identity Manager in English that is not focused on Certificate Management (Brian Komar wrote on book on FIM Certificate Management deployment and two gentlemen from Japan wrote a &lt;a href=&#34;http://www.microsofttranslator.com/BV.aspx?ref=BVNav&amp;amp;from=&amp;amp;to=en&amp;amp;a=http%3A%2F%2Fidmlab.eidentity.jp%2F2010%2F06%2Factive-directory-id-fim2010.html&#34;&gt;book on FIM in Japanese&lt;/a&gt; as blogged about by fellow MVP, &lt;a href=&#34;http://idmlab.eidentity.jp/&#34;&gt;Naohiro  Fujie&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Embedding comments in your XPATH Filters</title>
      <link>https://identitymanaged.com/2010/07/embedding-comments-in-your-xpath.html</link>
      <pubDate>Tue, 20 Jul 2010 13:22:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/07/embedding-comments-in-your-xpath.html</guid>
      <description>&lt;p&gt;One thing I love to do is provide self-documenting code and configurations. Well when I have to customize sets the XPATH filter can get a bit complex so I recently found a way to comment the XPATH Filter in my sets and groups:&lt;/p&gt;&#xA;&lt;p&gt;/Person[starts-with(DisplayName,&amp;rsquo;%&amp;rsquo;)]  &lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;By using  to enclose my comments and only after the last closing ] of the predicate I can comment on the filter itself.&lt;/p&gt;</description>
    </item>
    <item>
      <title>MVP’d again</title>
      <link>https://identitymanaged.com/2010/07/mvpd-again-comments.html</link>
      <pubDate>Fri, 09 Jul 2010 14:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/07/mvpd-again-comments.html</guid>
      <description>&lt;h4 id=&#34;congratulations-i-hope-your-continuous-writing-f&#34;&gt;Congratulations! I hope your continuous writing f&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/17688001430167255272&#34; title=&#34;noreply@blogger.com&#34;&gt;Naohiro Fujie&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 2, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Congratulations!&lt;/p&gt;&#xA;&lt;p&gt;I hope your continuous writing for exciting articles!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>MVP’d again</title>
      <link>https://identitymanaged.com/2010/07/mvpd-again.html</link>
      <pubDate>Fri, 09 Jul 2010 14:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/07/mvpd-again.html</guid>
      <description>&lt;p&gt;Thanks to the folks at Microsoft for continuing to recognize my contributions to the world of FIM. I awarded MVP for the fourth time.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Finding a Binary Value in the Haystack (FIMService Database)</title>
      <link>https://identitymanaged.com/2010/07/finding-binary-value-in-haystack.html</link>
      <pubDate>Fri, 09 Jul 2010 14:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/07/finding-binary-value-in-haystack.html</guid>
      <description>&lt;p&gt;While Query the FIM Service Database at the SQL layer is not supported by Microsoft I had an issue the other day where I couldn’t find what object had a conflicting SID that was preventing the update of another user. I could see in the error detail that it referenced the ObjectSID attribute. So I created this script and replaced the binary value down below with the SID of the object I was looking for.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Technical Overview Whitepaper on FIM released!</title>
      <link>https://identitymanaged.com/2010/06/technical-overview-whitepaper-on-fim.html</link>
      <pubDate>Wed, 30 Jun 2010 19:28:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/technical-overview-whitepaper-on-fim.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://blogs.technet.com/b/identitymanagement/archive/2010/06/29/technical-overview-whitepaper-on-fim-2010.aspx&#34;&gt;Technical overview whitepaper on FIM 2010&lt;/a&gt; (&lt;a href=&#34;http://download.microsoft.com/download/0/8/4/0846D14C-B2D5-4BEA-9061-311BBF5BB76B/FIM%202010%20Technical%20Overview.docx&#34;&gt;download&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt;Brad and I spent many long hours writing this! Glad to see it come out in the long form. Thanks to the product group for the opportunity and the Brjann, Mark, and Markus for reviewing and editing it.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ensynch’s Identity Practice -- Finalist for WPC Award</title>
      <link>https://identitymanaged.com/2010/06/ensynchs-identity-practice-finalist-for.html</link>
      <pubDate>Wed, 30 Jun 2010 19:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/ensynchs-identity-practice-finalist-for.html</guid>
      <description>&lt;p&gt;Microsoft has honored the efforts of our Identity and Secure Access Management Practice by making us a finalist for 2010 Partner of the Year, Core Infrastructure Solutions, Server Platform, as a result of our work with FIM, ILM, AD, AD FS and AD CS.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/EnsynchsIdentityPracticeFinalistforWPCAw_110E7/CIS_SvrPltfrm_Fin_Color.jpg&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/EnsynchsIdentityPracticeFinalistforWPCAw_110E7/CIS_SvrPltfrm_Fin_Color_thumb.jpg&#34; alt=&#34;CIS_SvrPltfrm_Fin_Color&#34; title=&#34;CIS_SvrPltfrm_Fin_Color&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/EnsynchsIdentityPracticeFinalistforWPCAw_110E7/WPC10_WebBnnr_Static_Fin.jpg&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/EnsynchsIdentityPracticeFinalistforWPCAw_110E7/WPC10_WebBnnr_Static_Fin_thumb.jpg&#34; alt=&#34;WPC10_WebBnnr_Static_Fin&#34; title=&#34;WPC10_WebBnnr_Static_Fin&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dependent Sync Rules – Disconnection on removal of a dependent Sync Rule</title>
      <link>https://identitymanaged.com/2010/06/dependent-sync-rules-disconnection-on-comments.html</link>
      <pubDate>Tue, 29 Jun 2010 14:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/dependent-sync-rules-disconnection-on-comments.html</guid>
      <description>&lt;h4 id=&#34;hi-david-i-have-a-dependent-sync-rule-and-i-have&#34;&gt;Hi David, I have a dependent sync rule and I have&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/07657669311243080791&#34; title=&#34;noreply@blogger.com&#34;&gt;V&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jul 1, 2013&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hi David,&lt;/p&gt;&#xA;&lt;p&gt;I have a dependent sync rule and I have confirmed that it will not disconnect the object when the dependent sync rule is removed. However, everytime the dependent sync rule is removed, FIM tries to export a &amp;ldquo;Provisioning Delete/Add&amp;rdquo; to AD. Have you experienced this issue? Any tips would be appreciated. Thanks&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dependent Sync Rules – Disconnection on removal of a dependent Sync Rule</title>
      <link>https://identitymanaged.com/2010/06/dependent-sync-rules-disconnection-on.html</link>
      <pubDate>Tue, 29 Jun 2010 14:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/dependent-sync-rules-disconnection-on.html</guid>
      <description>&lt;p&gt;Recently, I discovered that under certain conditions the removal of a dependent sync rule could cause the disconnection of objects in AD or other connected data sources. So I had to investigate the inner workings of dependent Sync Rules to uncover this mystery and fix it.&lt;/p&gt;&#xA;&lt;p&gt;FIM allows us to create dependent Sync Rules. First let me explain the what and then a little why. Then allow me to explain a bug that I discovered and how to work around it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Object reference not set to an instance of an object</title>
      <link>https://identitymanaged.com/2010/06/object-reference-not-set-to-instance-of-comments.html</link>
      <pubDate>Sun, 13 Jun 2010 12:00:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/object-reference-not-set-to-instance-of-comments.html</guid>
      <description>&lt;h4&gt;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/10727925205994704553&#34; title=&#34;noreply@blogger.com&#34;&gt;/Remi&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Nov 3, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;This comment has been removed by the author.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Hello David! :) Have you got the time to test this in a lab ?&lt;br&gt;&#xA;I`am experiencing the same problem. And I`ve tried everything without any luck.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://social.technet.microsoft.com/Forums/en/ilm2/thread/deae65d0-ede6-4b36-994b-3695d0cc8260&#34;&gt;http://social.technet.microsoft.com/Forums/en/ilm2/thread/deae65d0-ede6-4b36-994b-3695d0cc8260&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Object reference not set to an instance of an object</title>
      <link>https://identitymanaged.com/2010/06/object-reference-not-set-to-instance-of.html</link>
      <pubDate>Sun, 13 Jun 2010 12:00:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/object-reference-not-set-to-instance-of.html</guid>
      <description>&lt;p&gt;Lessons learned:&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Run the &lt;a href=&#34;http://social.technet.microsoft.com/Forums/en-US/ilm2/thread/215ae0cf-e406-4a76-8596-057c7e184626&#34;&gt;Do a FIM MA account configuration quick test&lt;/a&gt; script.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Always refresh the schema of the FIM MA using the real FIM MA Service Account which we usually call svc-FIMMA.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;Scenario:&lt;/p&gt;&#xA;&lt;p&gt;You have just modified the schema of FIM Service by creating a new Boolean attribute and have bound it to the user resource type. You refresh the FIM Schema, select the new attribute setup a direct export attribute flow from the corresponding Boolean metaverse attribute to the FIM MA attribute. You sync and the only pending export is to this attribute, and then when you run the export to FIM MA you get:&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Sets, XPATH, finding nulls with Strings</title>
      <link>https://identitymanaged.com/2010/06/fim-sets-xpath-finding-nulls-with-comments.html</link>
      <pubDate>Thu, 10 Jun 2010 00:29:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/fim-sets-xpath-finding-nulls-with-comments.html</guid>
      <description>&lt;h4 id=&#34;watch-out-for-the-latest-fim-hotfix-it-appears-i&#34;&gt;Watch out for the latest FIM hotfix. It appears i&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/03350112765650890956&#34; title=&#34;noreply@blogger.com&#34;&gt;Chris Clayton&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Nov 4, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Watch out for the latest FIM hotfix. It appears it will treat the % as a literal rather than a SQL wildcard.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>FIM Sets, XPATH, finding nulls with Strings</title>
      <link>https://identitymanaged.com/2010/06/fim-sets-xpath-finding-nulls-with.html</link>
      <pubDate>Thu, 10 Jun 2010 00:29:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/fim-sets-xpath-finding-nulls-with.html</guid>
      <description>&lt;p&gt;A little while ago I encountered some rather strange behavior of a Set vs. the XPATH query in FIM 2010.&lt;/p&gt;&#xA;&lt;p&gt;Using the Export-FIMConfig with the -onlyBaseResources -CustomConfig switches I run the following query to see if there are any users without a DisplayName&lt;/p&gt;&#xA;&lt;p&gt;/Person[not(starts-with(DisplayName,&amp;rsquo;&amp;rsquo;))]&lt;/p&gt;&#xA;&lt;p&gt;It showed 20&lt;/p&gt;&#xA;&lt;p&gt;So then I created a set, called “~ People with no displayname”, with that as the custom filter. I checked it doesn&amp;rsquo;t violate any of the limitations listed in the &lt;a href=&#34;http://technet.microsoft.com/en-us/library/ff356871(WS.10).aspx&#34;&gt;Business Policy Modeling doc&lt;/a&gt; (which I must say is a pretty good doc)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Accelerate Your Business Now with Identity Management &amp; Single-Sign-On (SSO)</title>
      <link>https://identitymanaged.com/2010/06/accelerate-your-business-now-with--comments.html</link>
      <pubDate>Wed, 09 Jun 2010 21:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/accelerate-your-business-now-with--comments.html</guid>
      <description>&lt;h4 id=&#34;i-think-they-can-really-help-in-a-lot-of-ways-acc&#34;&gt;I think they can really help in a lot of ways. Acc&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/02995477115559876615&#34; title=&#34;noreply@blogger.com&#34;&gt;Karl&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 4, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;I think they can really help in a lot of ways. Accelerate your business with the help of these factors. Thanks a lot for sharing.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.corporation.com/&#34;&gt;business consultant&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Accelerate Your Business Now with Identity Management &amp; Single-Sign-On (SSO)</title>
      <link>https://identitymanaged.com/2010/06/accelerate-your-business-now-with.html</link>
      <pubDate>Wed, 09 Jun 2010 21:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/accelerate-your-business-now-with.html</guid>
      <description>&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Jun 10, 2010&lt;/p&gt;&#xA;&lt;p&gt;1:00 p.m. Eastern / 10:00 a.m. Pacific (60 minutes)&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.eseminarslive.com/c/a/Security/Quest061010/?partnerref=CL061010Ensynch1&#34;&gt;To Register follow this link&lt;/a&gt;&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;h6 id=&#34;featured-speakers&#34;&gt;&lt;img src=&#34;http://www.eseminarslive.com/images/esem/label_featured_speakers.gif&#34; alt=&#34;Featured Speakers&#34;&gt;&lt;/h6&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.eseminarslive.com/cp/bio/Christopher-Yeich/&#34;&gt;Christopher Yeich&lt;/a&gt; - Editor, Strategic Content - Ziff Davis Enterprise&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.eseminarslive.com/cp/bio/David-Lundell/&#34;&gt;David Lundell&lt;/a&gt; - Identity Management Practice Director, Ensynch | Microsoft Identity Management MVP&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.eseminarslive.com/cp/bio/Jonathan-Sander/&#34;&gt;Jonathan Sander&lt;/a&gt; - IAM and Security Analyst - Quest Software&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Has your business experienced identity theft, with unauthorized access to your systems, data, and/or trade secrets?&lt;br&gt;&#xA;Have you lost business because your customers and/or employees didn’t have access when needed?&lt;br&gt;&#xA;How much time have you wasted in producing compliance/regulatory reports for various auditors?&lt;/strong&gt;&lt;br&gt;&#xA;These are all real-life situations that business and IT leaders like you are experiencing every day. Breaches lead to millions—sometimes billions—in lost monies every year. Additionally, there&amp;rsquo;s also confusion, frustration, and lost productivity that organizations deal with every day as they fight to manage appropriate access to information and tools that employees, business partners, and customers actually need.&lt;br&gt;&#xA;Join Microsoft Identity MVP David Lundell of Ensynch, and Jonathan Sander, IAM and Security Analyst of Quest Software, for a candid presentation that uncovers ways you can protect and accelerate your business—as well as save money—with identity and secure access management (ISAM).&lt;br&gt;&#xA;&lt;strong&gt;Topics of discussion will include:&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Searching an entire database for a Guid or Unique Identifier</title>
      <link>https://identitymanaged.com/2010/06/searching-entire-database-for-guid-or.html</link>
      <pubDate>Tue, 01 Jun 2010 08:47:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/06/searching-entire-database-for-guid-or.html</guid>
      <description>&lt;p&gt;Searching an entire database for a Guid or Unique Identifier can be a bit of a tricky proposition. However a little bit of using T-SQL to generate T-SQL and viola&lt;/p&gt;&#xA;&lt;p&gt;DECLARE @GUIDHunted nvarchar(60)&lt;br&gt;&#xA;SET @GUIDHunted = &amp;lsquo;0A24EC0C-65EE-4519-89DF-ABD3DD24F7EF&amp;rsquo;&lt;/p&gt;&#xA;&lt;p&gt;SELECT *, &amp;lsquo;UNION ALL SELECT &amp;rsquo;&amp;rsquo;&amp;rsquo; + s.name + &amp;lsquo;.&amp;rsquo;  +  ao.name + &amp;lsquo;&amp;rsquo;&amp;rsquo;, count(*) FROM &amp;rsquo;&lt;br&gt;&#xA;+ s.name +&amp;rsquo;.[&amp;rsquo; + ao.name  + &amp;lsquo;] WHERE &amp;rsquo; + ac.name + &amp;rsquo; = &amp;rsquo;&amp;rsquo;&amp;rsquo; + @GuidHunted + &amp;rsquo;&amp;rsquo;&amp;rsquo;&amp;rsquo;&lt;br&gt;&#xA;FROM sys.all_columns ac&lt;br&gt;&#xA;JOIN sys.all_objects ao&lt;br&gt;&#xA;    ON ac.[object_id] = ao.[object_id]&lt;br&gt;&#xA;JOIN sys.schemas s&lt;br&gt;&#xA;    ON ao.[schema_id] = s.[schema_id] &lt;br&gt;&#xA;where user_type_id = 36 &amp;ndash; UniqueIdentifier&lt;br&gt;&#xA;and s.name != &amp;lsquo;sys&amp;rsquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Restoring your FIM databases to the moment before oops</title>
      <link>https://identitymanaged.com/2010/05/restoring-your-fim-databases-to-moment.html</link>
      <pubDate>Thu, 20 May 2010 10:04:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/05/restoring-your-fim-databases-to-moment.html</guid>
      <description>&lt;p&gt;At the FIM Birds of a Feather (BOF) after a discussion about FIM database backups I was asked to make a blog post to more fully elucidate the benefits of using the full recovery model.&lt;/p&gt;&#xA;&lt;p&gt;Since Recovery models affect the transaction log you may find it useful to have the following background about transaction logs:&lt;/p&gt;&#xA;&lt;p&gt;•The Data in tables and indexes are stored in data files not the transaction log&lt;/p&gt;</description>
    </item>
    <item>
      <title>ADFS v.2 shipped</title>
      <link>https://identitymanaged.com/2010/05/adfs-v2-shipped.html</link>
      <pubDate>Tue, 18 May 2010 15:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/05/adfs-v2-shipped.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://channel9.msdn.com/shows/Identity/Active-Directory-Federation-Services-v2-Ships/&#34; title=&#34;Active Directory Federation Services v2 Ships!&#34;&gt;Active Directory Federation Services v2 Ships!&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This is awesome stuff – with ADFS v2 we can help you setup SSO with your SaaS vendors.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ADFSv.2shipped_DDC6/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ADFSv.2shipped_DDC6/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Here is an example that has been rendered generic.&lt;/p&gt;&#xA;&lt;p&gt;ADFS 2.0 supports SAML 2.0 (the idp lite profile and rdp lite profile) which opens up many federation doors and WIF allows us to write custom security token services (sts) just in case the idp lite and rdp lite profile support isn’t up to handling the interaction.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC Decks Posted!</title>
      <link>https://identitymanaged.com/2010/05/tec-decks-posted.html</link>
      <pubDate>Tue, 18 May 2010 11:34:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/05/tec-decks-posted.html</guid>
      <description>&lt;p&gt;If you attended TEC you can now get the Slide Decks by registering on TheExpertsCommunity.com&lt;/p&gt;&#xA;&lt;p&gt;and accessing the following item: &lt;a href=&#34;http://theexpertscommunity.com/item/view/id/4452&#34;&gt;TEC 2010 Conference Materials Have Been Posted!&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;You can find my sessions here:&lt;/p&gt;&#xA;&lt;p&gt; &lt;a href=&#34;http://theexpertscommunity.com/item/list/type/session/meta_expert_tag/speaker%3Adavidlundell&#34; title=&#34;http://theexpertscommunity.com/item/list/type/session/meta_expert_tag/speaker%3Adavidlundell&#34;&gt;http://theexpertscommunity.com/item/list/type/session/meta_expert_tag/speaker%3Adavidlundell&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h6 id=&#34;session-proper-care-and-feeding-of-your-databases-fim-ilm-clm-rms-sharepoint-and-ocs&#34;&gt;&lt;img src=&#34;http://theexpertscommunity.com/images/type-session.png&#34; alt=&#34;session&#34;&gt; &lt;a href=&#34;http://theexpertscommunity.com/item/view/id/2774&#34;&gt;Proper Care and Feeding of Your Databases: FIM, ILM, CLM, RMS, SharePoint and OCS&lt;/a&gt;&lt;/h6&gt;&#xA;&lt;p&gt;Without proper care and feeding of your databases (FIM Meta Directory Services, FIM Certificate Services, FIM Web Service, RM&amp;hellip; &lt;a href=&#34;http://theexpertscommunity.com/item/view/id/2774&#34;&gt;continue reading &amp;ldquo;Proper Care and Feeding of Your Databases: FIM, ILM, CLM, RMS, SharePoint and OCS&amp;rdquo;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2010 -- Results</title>
      <link>https://identitymanaged.com/2010/05/tec-2010-results.html</link>
      <pubDate>Mon, 17 May 2010 15:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/05/tec-2010-results.html</guid>
      <description>&lt;p&gt;TEC 2010 was a blast. In the Kickoff Gil Kirkpatrick issued several challenges including one to Brad Turner to simulate the workings of the FIM Sync Engine. Eventually we expect to see a video of the final presentation posted to YouTube. In the interim Brad has some nice pictures posted: &lt;a href=&#34;http://www.identitychaos.com/2010/04/tec-2010-annual-wook-lee-memorial_29.html&#34; title=&#34;TEC 2010 – Annual Wook Lee Memorial Challenge for Identity Results&#34;&gt;TEC 2010 – Annual Wook Lee Memorial Challenge for Identity Results&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Escape from Prague – Good to go for TEC</title>
      <link>https://identitymanaged.com/2010/04/escape-from-prague-good-to-go-for-tec.html</link>
      <pubDate>Fri, 23 Apr 2010 15:20:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/04/escape-from-prague-good-to-go-for-tec.html</guid>
      <description>&lt;p&gt;I went to Prague for a project intending to stay one week, but unfortunately I was delayed an additional week (volcanic ash cloud from Iceland – reread the news if you missed it). While Prague is a beautiful city and I met many wonderful people, the uncertainty of when I would be able to get home weighed heavily on me. I was worried about being separated from my family for weeks? months? More importantly ;) I was worried about getting back for The Experts Conference!&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM 2010 Technical Overview Published – short version</title>
      <link>https://identitymanaged.com/2010/04/fim-2010-technical-overview-published-comments.html</link>
      <pubDate>Thu, 08 Apr 2010 22:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/04/fim-2010-technical-overview-published-comments.html</guid>
      <description>&lt;h4 id=&#34;great-job-david-and-crew&#34;&gt;Great job David and crew!&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/08377013014366853881&#34; title=&#34;noreply@blogger.com&#34;&gt;Marc Mac Donell, CISSP&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Apr 4, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Great job David and crew!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>FIM 2010 Technical Overview Published – short version</title>
      <link>https://identitymanaged.com/2010/04/fim-2010-technical-overview-published.html</link>
      <pubDate>Thu, 08 Apr 2010 22:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/04/fim-2010-technical-overview-published.html</guid>
      <description>&lt;p&gt;Microsoft has published a short version of the &lt;a href=&#34;http://technet.microsoft.com/en-us/library/ff621362(WS.10).aspx&#34;&gt;FIM Technical Overview whitepaper&lt;/a&gt; written by David Lundell (me), &lt;a href=&#34;http://www.identitychaos.com&#34;&gt;Brad Turner&lt;/a&gt;, &lt;a href=&#34;http://blog.identityjunkie.com/&#34;&gt;Chris Calderon&lt;/a&gt; and &lt;a href=&#34;http://c--shark.blogspot.com/&#34;&gt;Joe Zamora&lt;/a&gt;. The longer version will come out a bit later. Short version, long version makes me feel kind of like I am figure skating in the Olympics. Thank you to Brjann Brekkan, Mark Wahl, Joe Schulman, Darryl Russi, Jack Kabat and Andreas Kjellman for their support, editing, eluciations on blogs and encouragement on this paper.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Pitfall for old ILM hands</title>
      <link>https://identitymanaged.com/2010/03/fim-pitfall-for-old-ilm-hands.html</link>
      <pubDate>Thu, 25 Mar 2010 21:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/03/fim-pitfall-for-old-ilm-hands.html</guid>
      <description>&lt;p&gt;In the days of MIIS 2003 and ILM 2007 we usually wrote our provisioning code to provision a new AD account only when the particular metaverse object didn’t already have any connectors in the AD connector space. With FIM your outbound synchronization rule is quite happy to provision another AD account if the existing one it is joined to doesn’t meet the relationship criteria. So I have usually been in the habit of not worrying about extraneous provisioning if I already had an account connected to that metaverse object.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Register for TEC 2010 – hope to see you there</title>
      <link>https://identitymanaged.com/2010/03/register-for-tec-2010-hope-to-see-you.html</link>
      <pubDate>Wed, 17 Mar 2010 17:34:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/03/register-for-tec-2010-hope-to-see-you.html</guid>
      <description>&lt;p&gt; &lt;img src=&#34;http://www.theexpertsconference.com/us/wp-content/uploads/2010/01/banner-im-speaking.gif&#34; alt=&#34;banner-im-speaking&#34; title=&#34;banner-im-speaking&#34;&gt;&lt;strong&gt;&lt;img src=&#34;http://www.theexpertsconference.com/us/wp-content/uploads/2009/09/sponsor-ensynch2.jpg&#34; alt=&#34;sponsor-ensynch&#34; title=&#34;sponsor-ensynch&#34;&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Register using this code to get a discount: ATESENSYNC&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2010 – Speaking and Sponsoring</title>
      <link>https://identitymanaged.com/2010/03/tec-2010-speaking-and-sponsoring.html</link>
      <pubDate>Wed, 17 Mar 2010 15:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/03/tec-2010-speaking-and-sponsoring.html</guid>
      <description>&lt;p&gt;I am super excited about speaking at &lt;a href=&#34;http://www.theexpertsconference.com/us&#34;&gt;The Experts Conference 2010&lt;/a&gt; (I also spoke at Directory Experts in ‘07, and ‘08 as well as last year’s The Experts Conference). &lt;img src=&#34;http://www.theexpertsconference.com/us/wp-content/uploads/2010/01/banner-im-speaking.gif&#34; alt=&#34;banner-im-speaking&#34; title=&#34;banner-im-speaking&#34;&gt;&lt;strong&gt;&lt;img src=&#34;http://www.theexpertsconference.com/us/wp-content/uploads/2009/09/sponsor-ensynch2.jpg&#34; alt=&#34;sponsor-ensynch&#34; title=&#34;sponsor-ensynch&#34;&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Register using this code to get a discount: ATESENSYNC&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Once more Ensynch is sponsoring TEC but this year we are a &lt;a href=&#34;http://www.theexpertsconference.com/us/sponsor-information/current-sponsors/&#34;&gt;gold sponsor&lt;/a&gt; for &lt;a href=&#34;http://www.tec2010.com&#34;&gt;TEC 2010&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;Here is the lineup of Ensynch Speakers at The Experts Conference (also see &lt;a href=&#34;http://www.identitychaos.com/2010/03/ensynch-sponsors-and-speaks-at-tec-2010.html&#34;&gt;Brad Turner’s take on our new speakers&lt;/a&gt;)&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Technet Webcasts</title>
      <link>https://identitymanaged.com/2010/03/fim-technet-webcasts.html</link>
      <pubDate>Tue, 09 Mar 2010 15:36:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/03/fim-technet-webcasts.html</guid>
      <description>&lt;p&gt;The FIM product group has some great webcasts coming up on technet&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://blogs.technet.com/identitymanagement/archive/2010/03/02/forefront-identity-manager-2010-has-rtm-ed.aspx&#34; title=&#34;Forefront Identity Manager 2010 has RTM&#39;ed&#34;&gt;Forefront Identity Manager 2010 has RTM&amp;rsquo;ed&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;This first webinar is using many of the slides that I created as part of our engagement to write the FIM 2010 Technical Overview Whitepaper (due out soon). Anyhow it makes me feel cool.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;3/9/2010&lt;/strong&gt; 6 PM Pacific time- &lt;em&gt;TechNet Webcast: Forefront Identity Manager 2010: Technical Overview and Deployment (Level 300)&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM 2010 RTM Today!</title>
      <link>https://identitymanaged.com/2010/03/fim-2010-rtm-today.html</link>
      <pubDate>Tue, 02 Mar 2010 13:03:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/03/fim-2010-rtm-today.html</guid>
      <description>&lt;p&gt;Today, March 2, at the RSA conference Microsoft announced the release to manufacturing of Forefront Identity Manager 2010 (FIM, formerly codenamed ILM “2”) with General Availability starting next month.&lt;/p&gt;&#xA;&lt;p&gt;Download the eval here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=22731a2a-5b0f-4c6b-846a-e53588117981&#34;&gt;Microsoft® Forefront™ Identity Manager 2010 Evaluation Version&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Yeah!&lt;/p&gt;&#xA;&lt;p&gt;FIM gives us capabilities for User provisioning (and deprovisioning), Group management, Self-Service Password Reset, Password Synchronization, Workflows with Approvals, User profile self-service management, and accomplishing these items through Declarative Provisioning. Yet FIM retains an incredible set of extensibility points, allows customization of the Portal, schema of the objects, managing new systems, custom workflows, custom clients to the FIM web service.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Final Update for FIM RC1 released</title>
      <link>https://identitymanaged.com/2010/02/final-update-for-fim-rc1-released.html</link>
      <pubDate>Mon, 01 Feb 2010 10:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/02/final-update-for-fim-rc1-released.html</guid>
      <description>&lt;p&gt;On Friday the product group released Update 3 for Forefront Identity Manager 2010 RC1 available through connect&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://connect.microsoft.com/site433/Downloads&#34; title=&#34;https://connect.microsoft.com/site433/Downloads&#34;&gt;https://connect.microsoft.com/site433/Downloads&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Major changes as part of Update 3 (my regurgitation and comments from the release notes):&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Fewer trips to the FIM Service event log – since the FIM MA export errors will now show up in the Synchronization Service Manager! Hallelujah!&lt;/li&gt;&#xA;&lt;li&gt;Less need for custom old style code&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Now more than 1 MA can be authoritative for deleting an object (resource)&lt;/li&gt;&#xA;&lt;li&gt;New functions for Sync Rules (Declarative Provisioning) – I guess I will have to update &lt;a href=&#34;http://www.ilmbestpractices.com/blog/2009/01/ilm-2-functions-explained.html&#34;&gt;my function cheatsheet&lt;/a&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Null – not certain what they mean by this – null out the value or let another sync rule provide the value.&lt;/li&gt;&#xA;&lt;li&gt;ReplaceString&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;New type of MPR – Set Transition MPRs vs. request based MPRs&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Run on Policy Update only applies to this type&lt;/li&gt;&#xA;&lt;li&gt;All other MPRs are – request based MPRs&lt;/li&gt;&#xA;&lt;li&gt;This should easy some of the difficulty in wrapping heads around MPRs.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;DBA’s will love these:&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Backups without stopping the FIM Service and now supported!&lt;/li&gt;&#xA;&lt;li&gt;SQL Failover Clusters are now supported! (I don’t know if this means that clustering the Synchronization Service is supported)&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;Prereqs have changed&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Server Components&#xA;&lt;ul&gt;&#xA;&lt;li&gt;Windows Installer 4.5 is required,&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;FIM Service requires SQL 2008 SP 1&lt;/li&gt;&#xA;&lt;li&gt;The addin for Outlook now needs Outlook 2007 SP 2&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;Even the certificate management side got some improvements: Windows Server 2008 R2&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM Hand on Labs</title>
      <link>https://identitymanaged.com/2010/02/fim-hand-on-labs.html</link>
      <pubDate>Mon, 01 Feb 2010 01:20:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2010/02/fim-hand-on-labs.html</guid>
      <description>&lt;p&gt;More Hands on Labs for Forefront Identity Manager will be coming up (similar to the &lt;a href=&#34;http://www.ilmbestpractices.com/blog/2009/11/identity-synchronization-fim-2010-hol.html&#34;&gt;one I did in Irvine, CA&lt;/a&gt;) – Phoenix April 7th and 8th and then Dallas sometime in May.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM RCDC explained in brief</title>
      <link>https://identitymanaged.com/2009/11/fim-rcdc-explained-in-brief.html</link>
      <pubDate>Sun, 29 Nov 2009 09:50:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/11/fim-rcdc-explained-in-brief.html</guid>
      <description>&lt;p&gt;In this post I attempt to give you the reader a quick overview of how the FIM RCDC works conceptually. As for the mechanics of modifying the RCDC the nearly complete but growing collection of documents downloadable from MSFT will suffice.&lt;/p&gt;&#xA;&lt;p&gt;As you will recall FIM is the new abbreviation for ILM, since it has been renamed Forefront Identity Manager, and RCDC is the Resource Control Display Configuration formerly known as the Object Visualization Configuration (OVC). RCDC is the way you custom how FIM displays objects (now called resources) in the portal. Now for English: If you need to change the options and information users see in the FIM portal when they create new users, groups (security or distribution), or edit or view these resources you do it by modifying the RCDC. The RCDC is an XML object, and each resource type (user, group, request, etc) has three: Create, Edit and View. To get a handle on the terms take a look at the figure below:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Answering my FIM RC 1 question</title>
      <link>https://identitymanaged.com/2009/11/answering-my-fim-rc-1-question.html</link>
      <pubDate>Tue, 24 Nov 2009 09:58:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/11/answering-my-fim-rc-1-question.html</guid>
      <description>&lt;p&gt;Thanks to &lt;a href=&#34;http://blogs.msdn.com/darrylru/default.aspx&#34;&gt;Darryl Russi&lt;/a&gt; for answering my questions in my earlier post &lt;a href=&#34;http://www.ilmbestpractices.com/blog/2009/11/update-to-fim-rc1.html&#34; title=&#34;An Update to FIM RC1&#34;&gt;An Update to FIM RC1&lt;/a&gt; where I was asked about something I had read in the release notes:&lt;/p&gt;&#xA;&lt;p&gt;Some of those items raise a few questions, like how to setup a FIM service that only takes requests from the sync service? Do we setup multiple FIM Service instances and then configure the FIM MA to talk to one of them, and not make that one available to web clients?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Identity Synchronization FIM 2010 HOL Irvine California</title>
      <link>https://identitymanaged.com/2009/11/identity-synchronization-fim-2010-hol.html</link>
      <pubDate>Mon, 23 Nov 2009 17:44:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/11/identity-synchronization-fim-2010-hol.html</guid>
      <description>&lt;p&gt;&lt;strong&gt;I will be at the Microsoft Technical Center in Irvine on Dec 1 and 2 presenting this HOL with Marvin Tansley of Gemalto.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Identity Synchronization – Hands on Training&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;&lt;img src=&#34;http://i.microsoft.com/global/forefront/identitymanager/en/us/PublishingImages/Forefront-IM2010_h_rgb.jpg&#34; alt=&#34;Home&#34;&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/IdentitySynchronizationFIM2010HOLIrvineC_F980/clip_image001.jpg&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/IdentitySynchronizationFIM2010HOLIrvineC_F980/clip_image001_thumb.jpg&#34; alt=&#34;clip_image001&#34; title=&#34;clip_image001&#34;&gt;&lt;/a&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/IdentitySynchronizationFIM2010HOLIrvineC_F980/clip_image0014.jpg&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/IdentitySynchronizationFIM2010HOLIrvineC_F980/clip_image0014_thumb.jpg&#34; alt=&#34;clip_image001[4]&#34; title=&#34;clip_image001[4]&#34;&gt;&lt;/a&gt;&lt;a href=&#34;http://www.ensynch.com/default.aspx&#34;&gt;&lt;img src=&#34;http://www.ensynch.com/images/logo.gif&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Date:&lt;/strong&gt; &lt;strong&gt;December 1-2, 2009&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Location:&lt;/strong&gt;   3 Park Plaza, Suite 1800   Irvine, CA  92614     949-263-3000&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Microsoft, Gemalto and Ensynch&lt;/strong&gt; invite you to a free 2-day training seminar and hands-on-lab on Microsoft’s Forefront Lifecycle Manager (FIM 2010).&lt;/p&gt;&#xA;&lt;p&gt;Come and learn how FIM 2010 can help you by delivering simplicity, agility and efficiency while increasing security and compliance within your enterprise identity infrastructure.&lt;/p&gt;</description>
    </item>
    <item>
      <title>An Update to FIM RC1</title>
      <link>https://identitymanaged.com/2009/11/update-to-fim-rc1.html</link>
      <pubDate>Sun, 08 Nov 2009 23:14:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/11/update-to-fim-rc1.html</guid>
      <description>&lt;p&gt;Microsoft has posted an update to FIM RC 1, dated Nov 6.&lt;/p&gt;&#xA;&lt;p&gt;It looks like this update covers pretty much everywhere except Certificate Services (sorry Brian and Paul).&lt;/p&gt;&#xA;&lt;p&gt;The Release notes included in the download lists the follow improvements:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Query and Sets&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Resolved a number of issues that resulted in incorrect dynamic set membership.&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Removed support for the use of the != operator with multivalued attributes. Xpath equality expressions on multivalued attributes must use the not() function.  For example, the following xpath is not supported: /Group[Owner != /Person].  Instead, use the following xpath: /Group[not(Owner = /Person)]&lt;/p&gt;</description>
    </item>
    <item>
      <title>Identity Management Luncheon NYC</title>
      <link>https://identitymanaged.com/2009/10/identity-management-luncheon-nyc.html</link>
      <pubDate>Thu, 29 Oct 2009 14:44:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/10/identity-management-luncheon-nyc.html</guid>
      <description>&lt;p&gt;I will be speaking at an Identity Management Luncheon in New York City on Nov 12th. I will be speaking on FIM.&lt;/p&gt;&#xA;&lt;p&gt;Come on down and join me if you can. (Please Register)&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/IdentityManagementLuncheonNYC_97DF/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/IdentityManagementLuncheonNYC_97DF/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;**When:&lt;strong&gt;Thursday, November 12, 200910:45 AM to 2:00 PM (EST)&lt;/strong&gt;&lt;br&gt;&#xA;&lt;strong&gt;Where:&lt;/strong&gt;&lt;br&gt;&#xA;**Del Frisco&amp;rsquo;s&lt;br&gt;&#xA;Double Eagle Steak House&lt;br&gt;&#xA;1221 Avenue of the Americas&lt;br&gt;&#xA;New York, New York 10020&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;Come join us at this exclusive luncheon at one of the best steak houses in NYC!&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Password Reset?</title>
      <link>https://identitymanaged.com/2009/10/password-reset.html</link>
      <pubDate>Tue, 06 Oct 2009 20:59:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/10/password-reset.html</guid>
      <description>&lt;p&gt;How would you feel if this was the only barrier between the hacker and your data – a single password reset question? Just one!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/PasswordReset_821F/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/PasswordReset_821F/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;I won’t tell you who this is since then you’ll just want to go after my data on that site.&lt;/p&gt;&#xA;&lt;p&gt;Oh well. The barn door won’t be shut until the wolf has gotten into the sheep&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Webinar: Accelerate Your Businesses for the Future with Microsoft Geneva (ADFS) and the Cloud</title>
      <link>https://identitymanaged.com/2009/10/webinar-accelerate-your-businesses-for.html</link>
      <pubDate>Mon, 05 Oct 2009 11:07:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/10/webinar-accelerate-your-businesses-for.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/73de5400c0cd_9B71/clip_image001.jpg&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/73de5400c0cd_9B71/clip_image001_thumb.jpg&#34; alt=&#34;clip_image001&#34; title=&#34;clip_image001&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/73de5400c0cd_9B71/clip_image002.jpg&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/73de5400c0cd_9B71/clip_image002_thumb.jpg&#34; alt=&#34;clip_image002&#34; title=&#34;clip_image002&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/73de5400c0cd_9B71/clip_image003.gif&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/73de5400c0cd_9B71/clip_image003_thumb.gif&#34; alt=&#34;clip_image003&#34; title=&#34;clip_image003&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Get the rundown on Geneva from Frequent Industry Speaker and Nationally Recognized Microsoft ILM MVP,&lt;/strong&gt;**&lt;br&gt;&#xA;&lt;strong&gt;David Lundell&lt;/strong&gt;**&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;When:&lt;/strong&gt;**&lt;br&gt;&#xA;&lt;strong&gt;Wednesday, October 14, 2009&lt;/strong&gt;&lt;br&gt;&#xA;&lt;strong&gt;10:30 to 11:30 (PST)&lt;/strong&gt;&lt;br&gt;&#xA;&lt;strong&gt;12:30 to 1:30 (CST)&lt;/strong&gt;&lt;br&gt;&#xA;&lt;strong&gt;1:30 to 2:30 (EST)&lt;/strong&gt;**&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Where:&lt;/strong&gt;&lt;br&gt;&#xA;Web/Online&lt;br&gt;&#xA;Live Meeting Information&lt;br&gt;&#xA;will be sent to attendees&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Presenters:&lt;/strong&gt;&lt;br&gt;&#xA;David Lundell,&lt;br&gt;&#xA;Identity Management&lt;br&gt;&#xA;Practice Leader, Ensynch&lt;/p&gt;&#xA;&lt;p&gt;Jonathan Sander&lt;br&gt;&#xA;IAM and Security Analyst&lt;br&gt;&#xA;Quest Software&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://cl.exct.net/?qs=ae57dcbc36f810606fbc9bc44fc29a040dc2c326b815e7d30ab7bb56472585cc&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/73de5400c0cd_9B71/clip_image004.gif&#34; alt=&#34;clip_image004&#34; title=&#34;clip_image004&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Webinar: Accelerate Your Businesses for the Future with Microsoft Geneva (ADFS) and the Cloud&lt;/strong&gt;&lt;br&gt;&#xA;Has your organization been considering moving applications to the cloud or using Software as a Service (SaaS) providers? Have you already done it? Have you realized the cost savings?&lt;/p&gt;</description>
    </item>
    <item>
      <title>FIM RC 1 is here – what’s new?</title>
      <link>https://identitymanaged.com/2009/10/fim-rc-1-is-here-whats-new.html</link>
      <pubDate>Sun, 04 Oct 2009 22:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/10/fim-rc-1-is-here-whats-new.html</guid>
      <description>&lt;p&gt;FIM RC 1 is here.  Microsoft released it on Sept 30th which is the end of Q3 of 2009 which means the ILM/FIM team at Microsoft met their stated deadline announced back in March.&lt;/p&gt;&#xA;&lt;p&gt;Here is the download:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://technet.microsoft.com/en-us/evalcenter/cc872861.aspx&#34; title=&#34;http://technet.microsoft.com/en-us/evalcenter/cc872861.aspx&#34;&gt;http://technet.microsoft.com/en-us/evalcenter/cc872861.aspx&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;What’s new:&lt;/p&gt;&#xA;&lt;p&gt;Gil Kirkpatrick has a nice post about the differences in the data structure:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.gilkirkpatrick.com/Blog/post/2009/09/02/Auditing-FIM-2010-RC1.aspx&#34; title=&#34;Auditing FIM 2010 RC1&#34;&gt;Auditing FIM 2010 RC1&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Darryl Russi a Sr. Test Lead at Microsoft has started blogging about FIM RC 1 performance:&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 RC 0 -- Luke, Check the Transaction Log!</title>
      <link>https://identitymanaged.com/2009/08/ilm-2-rc-0-luke-check-transaction-log.html</link>
      <pubDate>Fri, 14 Aug 2009 21:16:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/08/ilm-2-rc-0-luke-check-transaction-log.html</guid>
      <description>&lt;p&gt;A few weeks ago I encountered an ASP.NET error when I tried to access &lt;a href=&#34;http://myilmserver/identitymanagement/&#34;&gt;http://myilmserver/identitymanagement/&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Eventually I went to my SQL Server and discovered that despite having space on the disk and Autogrow turned on the Transaction Log was full and wouldn&amp;rsquo;t grow anymore.&lt;/p&gt;&#xA;&lt;p&gt;So if you encounter this error then maybe you too can listen to the force telling you to check the SQL Server Transaction Log for MSILM.&lt;/p&gt;&#xA;&lt;p&gt;In the event log I saw this:&lt;/p&gt;</description>
    </item>
    <item>
      <title>AD RMS on R2 -- new Federation Features</title>
      <link>https://identitymanaged.com/2009/08/ad-rms-on-r2-new-federation-features.html</link>
      <pubDate>Fri, 14 Aug 2009 21:06:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/08/ad-rms-on-r2-new-federation-features.html</guid>
      <description>&lt;p&gt;AD RMS on Windows Server 2008 R2 adds a really slick feature blogged about here: &lt;a href=&#34;http://blogs.msdn.com/rms/archive/2009/06/09/group-expansion-for-federated-users.aspx&#34; title=&#34;Group Expansion for Federated Users&#34;&gt;Group Expansion for Federated Users&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Prior to R2 to issue a use license to a federated user they need to specifically be granted permissions. With Windows Server 2008 R2 you can create a contact matching the external federated user and then place the contact in the group and then they have the same RMS permissions as that group.&lt;/p&gt;</description>
    </item>
    <item>
      <title>At it again -- Geneva Part II</title>
      <link>https://identitymanaged.com/2009/08/at-it-again-geneva-part-ii.html</link>
      <pubDate>Fri, 14 Aug 2009 16:11:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/08/at-it-again-geneva-part-ii.html</guid>
      <description>&lt;p&gt;Once more we invite you to another Ensynch Identity Management webinar. This is part 2 in our series of 4 on Geneva (ADFS, WIF). This one is going to be led by &lt;a href=&#34;http://blog.identityjunkie.com/&#34;&gt;Chris Calderon&lt;/a&gt; one of our ADFS Experts, so naturally this will be filled with excellent technical content. As will Part 3 as it focuses on Windows Identity Foundation.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://cl.exct.net/?qs=a632b4587e1eb31645ff2be8cd633006ceb2f3a010a4c718cf923c87625b5075&#34; title=&#34;Geneva Webinar Presentation&#34;&gt;&lt;img src=&#34;https://identitymanaged.com/img/image.png&#34; alt=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Webinar Agenda:&lt;/strong&gt;&lt;br&gt;&#xA;- How Geneva provides business value to organizations seeking Single-Sign-On (SSO)?&lt;/p&gt;</description>
    </item>
    <item>
      <title>MVP for the 3rd time</title>
      <link>https://identitymanaged.com/2009/07/mvp-for-3rd-time.html</link>
      <pubDate>Mon, 20 Jul 2009 17:42:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/07/mvp-for-3rd-time.html</guid>
      <description>&lt;p&gt;Both my colleague Brad Turner and I were renewed for ILM MVP.&lt;/p&gt;&#xA;&lt;p&gt;I am glad to receive this honor another year.&lt;/p&gt;&#xA;&lt;p&gt;Congrats to new &lt;a href=&#34;http://assurancesinidentity.blogspot.com/&#34;&gt;ILM MVP Marc Mac Donnell&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;You can see a list of all ILM MVP&amp;rsquo;s that have chosen to make their profiles public (Marc hasn&amp;rsquo;t setup his yet).&lt;/p&gt;&#xA;&lt;p&gt;I just hope I can win the MVP at home!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Webinar: How Microsoft Geneva Streamlines Business</title>
      <link>https://identitymanaged.com/2009/07/webinar-how-microsoft-geneva.html</link>
      <pubDate>Mon, 20 Jul 2009 17:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/07/webinar-how-microsoft-geneva.html</guid>
      <description>&lt;p&gt;&lt;strong&gt;When:&lt;br&gt;&#xA;Wednesday, July 29, 2009&lt;br&gt;&#xA;10:30 to 11:30 (PST)&lt;br&gt;&#xA;12:30 to 1:30 (CST)&lt;br&gt;&#xA;1:30 to 2:30 (EST)&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://cl.exct.net/?qs=5764967e8af6a1915d4fac3aab4439a2ba6f0a472de9dc49d09ac35e64abcdd5&#34;&gt;[Register Now]&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Presenters:&lt;/strong&gt;&lt;br&gt;&#xA;David Lundell, ILM MVP&lt;br&gt;&#xA;Identity Management&lt;br&gt;&#xA;Practice Leader, Ensynch&lt;/p&gt;&#xA;&lt;p&gt;Jonathan Sander&lt;br&gt;&#xA;IAM and Security Analyst&lt;br&gt;&#xA;Quest Software&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Webinar: How Microsoft Geneva&lt;br&gt;&#xA;Streamlines Business&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;- Learn How to Reap the Benefits of True Web&lt;br&gt;&#xA;Single-Sign-On and Federation&lt;/strong&gt;&lt;br&gt;&#xA;Has your organization been forced to deploy one-off solutions to solve login or compliance problems with a newly deployed technology?&lt;br&gt;&#xA;Are your employees tired of using multiple logins for all kinds of access needs?&lt;br&gt;&#xA;Having trouble managing shared resources users both inside and outside of your organization?&lt;br&gt;&#xA;Using open platform identity management solution &lt;strong&gt;Microsoft Geneva&lt;/strong&gt;, you can save money and make your business more efficient today, and also make it more easily scalable for the future.&lt;br&gt;&#xA;I would like to invite you to our latest exclusive &amp;ldquo;no frills&amp;rdquo; webinar: &amp;ldquo;&lt;strong&gt;How Microsoft Geneva Streamlines Business&lt;/strong&gt;,&amp;rdquo; the 1st in a 4-part Identity Management Webinar Series from Ensynch&amp;rsquo;s Identity Management Practice Leader and Microsoft Identity Management MVP, David Lundell, and Quest Software IAM and Security Analyst, Jonathan Sander.&lt;br&gt;&#xA;This webinar is designed for business leaders, and will present business value propositions for the Microsoft Geneva framework. Whether identity management is a major concern for your organization or if you are simply curious about using Microsoft Geneva as an asset to help your business, this webinar is for you.&lt;br&gt;&#xA;&lt;strong&gt;Webinar Agenda:&lt;/strong&gt;&lt;br&gt;&#xA;- Yikes! The business pain points of managing lots of identities&lt;/p&gt;</description>
    </item>
    <item>
      <title>4th of July -- Independence Day</title>
      <link>https://identitymanaged.com/2009/07/4th-of-july-independence-day.html</link>
      <pubDate>Sun, 05 Jul 2009 22:00:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/07/4th-of-july-independence-day.html</guid>
      <description>&lt;p&gt;233 years ago, 56 men signed a document and began a labor to give birth to a nation. I am very grateful for their service and for their sacrifices and for each and every soldier, and dutiful civil servant since then. They have afforded me and my family a great many blessings. As well some of my family members have been privileged to serve. One of my grandfathers taught ground school during World War II and the other served in the Army and was stationed in Greenland. I honor their service.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The attributes behind Message Delivery Restrictions</title>
      <link>https://identitymanaged.com/2009/06/attributes-behind-message-delivery-comments.html</link>
      <pubDate>Mon, 29 Jun 2009 00:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/06/attributes-behind-message-delivery-comments.html</guid>
      <description>&lt;h4 id=&#34;very-helpfull-i-was-about-to-block-sending-email&#34;&gt;Very helpfull!! I was about to block sending email&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13335116341105925023&#34; title=&#34;noreply@blogger.com&#34;&gt;Paweł Jarosz&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 1, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Very helpfull!! I was about to block sending emails to disabled accounts - not mailbox but accounts - so I can easily and quick retrieve some data from inactive inboxes. The solution is to create an empty group in AD and set the &amp;ldquo;dLMemSubmitPerms&amp;rdquo; parameter to accept messages only from that empty group! Amazing and great many thanks! If somebody else has problem here is the link to the forum with whole conversation -&amp;gt; &lt;a href=&#34;http://wss.pl/frmThread.aspx?tid=98879&#34;&gt;http://wss.pl/frmThread.aspx?tid=98879&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>The attributes behind Message Delivery Restrictions</title>
      <link>https://identitymanaged.com/2009/06/attributes-behind-message-delivery.html</link>
      <pubDate>Mon, 29 Jun 2009 00:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/06/attributes-behind-message-delivery.html</guid>
      <description>&lt;p&gt;Do you know what attributes are used to control who can and can&amp;rsquo;t send to a Distribution List in Exchange 2003 and Exchange 2007? or Does it use a DACL?&lt;/p&gt;&#xA;&lt;p&gt;Knowing such things is key if you are going to automate distribution list management through .NET programs, or MIIS/ILM/FIM, Quest ARS or any other tool that is talking to LDAP attributes. For Powershell you need a separate list since the names are different.&lt;/p&gt;</description>
    </item>
    <item>
      <title>H30, Geneva Cola, Sitrus and Orange Fizz</title>
      <link>https://identitymanaged.com/2009/06/h30-geneva-cola-sitrus-and-orange-fizz.html</link>
      <pubDate>Wed, 24 Jun 2009 22:23:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/06/h30-geneva-cola-sitrus-and-orange-fizz.html</guid>
      <description>&lt;p&gt;Back in business school I was a connoisseur of fine commercials.  Recently I watched a commercial for Lipton Ice Tea (note I am a &lt;a href=&#34;http://en.wikipedia.org/wiki/Teetotaler&#34;&gt;teetotaler&lt;/a&gt; who doesn&amp;rsquo;t drink tea) and I have to admire their cleverness in coming up with names for competitor products (see the title) in their &amp;ldquo;&lt;a href=&#34;http://www.youtube.com/watch?v=P195E4KHggU&#34;&gt;Lipton Tea&lt;/a&gt;, I think I love you&amp;rdquo; commercial. (&lt;a href=&#34;http://www.superseventies.com/sl_ithinkiloveyou.html&#34;&gt;Lyrics here&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt;Really the names are clever although the best is the H30 &amp;ndash; I just love it, a chemical compound that as far as I can tell can&amp;rsquo;t exist, but we all know they are making fun of flavored water. Of course I also love ordering water by requesting Di-Hydrogen-Oxide.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Best Practices ILM 2007 Coding Conventions and Habits</title>
      <link>https://identitymanaged.com/2009/06/best-practices-ilm-2007-coding-comments.html</link>
      <pubDate>Mon, 22 Jun 2009 15:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/06/best-practices-ilm-2007-coding-comments.html</guid>
      <description>&lt;h4 id=&#34;thanks-for-writing-this-up-david-thats-goo&#34;&gt;Thanks for writing this up, David. That&amp;rsquo;s goo&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/00592893535303741690&#34; title=&#34;noreply@blogger.com&#34;&gt;matthew gibson&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jun 2, 2009&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks for writing this up, David. That&amp;rsquo;s good information.&lt;/p&gt;&#xA;&lt;p&gt;Can you explain this point&amp;hellip;&lt;br&gt;&#xA;I have seen one developer use the flow rule names as a language to processor module to handle 90% of his string manipulation. That certainly cut down on the need for re-coding.&lt;/p&gt;&#xA;&lt;p&gt;I&amp;rsquo;m not sure I follow.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Best Practices ILM 2007 Coding Conventions and Habits</title>
      <link>https://identitymanaged.com/2009/06/best-practices-ilm-2007-coding.html</link>
      <pubDate>Mon, 22 Jun 2009 15:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/06/best-practices-ilm-2007-coding.html</guid>
      <description>&lt;p&gt;In response to question in the MMSUG yahoo group I thought I would post the following:&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Naming conventions for MV objects and attributes.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Most CS objects and attributes come to us with names &amp;ndash; the exception being when we are writing our own views in SQL or Oracle&lt;/p&gt;&#xA;&lt;p&gt;There are many object types and attributes pre-defined in the metaverse if you use those no need to rename most of them seem to come from the required and suggested  attributes for either an X.500 Directory or LDAP Directory.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Desert Code Camp -- SQL, XPath and FIM</title>
      <link>https://identitymanaged.com/2009/06/desert-code-camp-sql-xpath-and-fim.html</link>
      <pubDate>Fri, 19 Jun 2009 14:57:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/06/desert-code-camp-sql-xpath-and-fim.html</guid>
      <description>&lt;p&gt;I just presented 3 sessions at the 2009 Desert Code Camp on Saturday June 13, 2009  at Devry University&lt;/p&gt;&#xA;&lt;p&gt;Thanks to Devry for hosting it and thanks to Lorin Thwaits of KB Alertz for being the Code Camp Director and to all other volunteers.&lt;/p&gt;&#xA;&lt;p&gt;Title (and link to Desert Code Camp site)&lt;/p&gt;&#xA;&lt;p&gt;Abstract&lt;/p&gt;&#xA;&lt;p&gt;Presentation Link&lt;/p&gt;&#xA;&lt;p&gt;Comments&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://desertcodecamp.com/signUp.aspx?session=515&#34;&gt;I dream in SQL (writing queries)&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Learn how to write SQL queries: SELECT statements, JOIN clauses, group by with Practical examples from the realm of Identity Management&lt;/p&gt;</description>
    </item>
    <item>
      <title>To PKI or not to PKI?</title>
      <link>https://identitymanaged.com/2009/06/to-pki-or-not-to-pki-comments.html</link>
      <pubDate>Tue, 02 Jun 2009 11:12:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/06/to-pki-or-not-to-pki-comments.html</guid>
      <description>&lt;h4 id=&#34;hey-dave-i-didnt-notice-your-blog-before-go&#34;&gt;Hey Dave, I didn&amp;rsquo;t notice your blog before. Go&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/03913540078710260918&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jun 0, 2009&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hey Dave, I didn&amp;rsquo;t notice your blog before. Good work. Gimme a call&amp;hellip; Lets have lunch sometime soon. It would be nice to see you.&lt;/p&gt;&#xA;&lt;p&gt;justin harris&lt;br&gt;&#xA;&lt;a href=&#34;mailto:justin@jwheel.com&#34;&gt;justin@jwheel.com&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>To PKI or not to PKI?</title>
      <link>https://identitymanaged.com/2009/06/to-pki-or-not-to-pki.html</link>
      <pubDate>Tue, 02 Jun 2009 11:12:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/06/to-pki-or-not-to-pki.html</guid>
      <description>&lt;p&gt;When should one implement a Public Key Infrastructure and when should one not? Obviously we implement a PKI to solve a problem, usually around security, enabling secure communications with a web server, multi-factor authentication, encryption. A PKI solution can be very versatile, but it comes at a price in setup and maintenance. But what alternatives do we have? Let&amp;rsquo;s examine each problem in turn&lt;/p&gt;&#xA;&lt;p&gt;Problem&lt;/p&gt;&#xA;&lt;p&gt;PKI difficulties&lt;/p&gt;&#xA;&lt;p&gt;Alternatives&lt;/p&gt;&#xA;&lt;p&gt;Benefits for Alternatives&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Business Impact of Identity and Access Management with Forefront Identity Manager 2010</title>
      <link>https://identitymanaged.com/2009/05/business-impact-of-identity-and-access-comments.html</link>
      <pubDate>Fri, 15 May 2009 11:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/05/business-impact-of-identity-and-access-comments.html</guid>
      <description>&lt;h4 id=&#34;its-nice-to-know-its-impact-to-the-business-&#34;&gt;It&amp;rsquo;s nice to know its impact to the business. &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/02995477115559876615&#34; title=&#34;noreply@blogger.com&#34;&gt;Karl&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 4, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;It&amp;rsquo;s nice to know its impact to the business. Thanks a lot for sharing that valuable information.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.corporation.com/&#34;&gt;business consultant&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>The Business Impact of Identity and Access Management with Forefront Identity Manager 2010</title>
      <link>https://identitymanaged.com/2009/05/business-impact-of-identity-and-access.html</link>
      <pubDate>Fri, 15 May 2009 11:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/05/business-impact-of-identity-and-access.html</guid>
      <description>&lt;p&gt;&lt;strong&gt;Brad and I are going to cover the value of the whole Identity Management Stack from Microsoft and a few additional pieces from partners.&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;**When:&lt;br&gt;&#xA;Thursday, May 28th&lt;br&gt;&#xA;**&lt;strong&gt;Where:&lt;/strong&gt;&lt;br&gt;&#xA;Webinar/Online&lt;br&gt;&#xA;(Live Meeting links will be&lt;br&gt;&#xA;sent to all registrants) (&lt;a href=&#34;http://www.ensynch.com/EventRegister.aspx?eventID=267&#34;&gt;Click Here to RSVP&lt;/a&gt;)&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Presenters:&lt;/strong&gt;&lt;br&gt;&#xA;David Lundell – Microsoft MVP for ILM, Ensynch Practice Director&lt;br&gt;&#xA;Brad Turner – Microsoft MVP for ILM, Ensynch Sr. Technical Architect&lt;br&gt;&#xA;**Time:&lt;br&gt;&#xA;**&lt;strong&gt;9am-10am Pacific/Arizona&lt;/strong&gt;&lt;br&gt;&#xA;10am-11am Mountain&lt;br&gt;&#xA;11am-12pm Central&lt;br&gt;&#xA;12pm-1pm Eastern&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dealing with the ILM 2 RC 0 Cert in Windows server 2003 domain</title>
      <link>https://identitymanaged.com/2009/04/dealing-with-ilm-2-rc-0-cert-in-windows.html</link>
      <pubDate>Wed, 29 Apr 2009 14:54:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/dealing-with-ilm-2-rc-0-cert-in-windows.html</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://technet.microsoft.com/en-us/library/cc561138.aspx&#34;&gt;Password Reset&lt;/a&gt;  instructions ask us to use Group Policy to distribute the cert to the clients. This only works in Windows Server 2008 functional level domains. In Windows Server 2003 domains you can automate this using cerutil.exe&lt;br&gt;&#xA;The following command will export the cert generated by ILM 2 install to the ilm2cert.cer file in the working directory&lt;/p&gt;&#xA;&lt;p&gt;certutil -store trustedpeople IdentityLifeCycleManager2 ilm2cert.cer&lt;/p&gt;&#xA;&lt;p&gt;This command can be used to import the cert from the command line&lt;br&gt;&#xA;certutil -f -addstore trustedpeople ilm2cert.cer&lt;/p&gt;</description>
    </item>
    <item>
      <title>Problems with Sync Rules in ILM 2 RC0 (err FIM RC0)?</title>
      <link>https://identitymanaged.com/2009/04/problems-with-sync-rules-in-ilm-2-rc0-comments.html</link>
      <pubDate>Mon, 20 Apr 2009 18:08:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/problems-with-sync-rules-in-ilm-2-rc0-comments.html</guid>
      <description>&lt;h4 id=&#34;if-you-will-take-a-look-at-fimilm-connections-sc&#34;&gt;If you will take a look at FIM(ILM) connections sc&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/06128691531408607025&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Apr 2, 2009&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;If you will take a look at FIM(ILM) connections schema you will see that ILM MA has a direct SQL connectivity to FIM database (not through web service). As far as I know any change to metaverse schema fires up synchronization of this change to FIM database directly through SQL connection.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Problems with Sync Rules in ILM 2 RC0 (err FIM RC0)?</title>
      <link>https://identitymanaged.com/2009/04/problems-with-sync-rules-in-ilm-2-rc0.html</link>
      <pubDate>Mon, 20 Apr 2009 18:08:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/problems-with-sync-rules-in-ilm-2-rc0.html</guid>
      <description>&lt;p&gt;Well I had a problem with a recent install &amp;ndash; the Metaverse Object Type Dropdown list was empty!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ProblemswithSyncRulesinILM2_EF00/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ProblemswithSyncRulesinILM2_EF00/image_thumb.png&#34; alt=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Turns out the source of this drop down list is the mv-data object type. However my install didn&amp;rsquo;t have this object. Obviously something was wrong. How does one create this object in the first place? Not directly in the portal. I am not certain when this object is supposed to be created. Install time? First export through the ILM MA? None of these seem to match up based on time stamps. It wasn&amp;rsquo;t created during install. It was created before the first import of the ILM MA, and the first Export of the ILM MA. It does match the time of the creation of the ILM MA in the Identity Manager tool in the synchronization engine.  The object is created by a request generated by the &lt;a href=&#34;http://www.identitychaos.com/2008/08/ilm-2-beta-3-built-in-synchronization.html&#34;&gt;Built In Synchronization Account (BISA)&lt;/a&gt; this is the account used by the ILM MA.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Earth Hour -- Mandatory?</title>
      <link>https://identitymanaged.com/2009/04/earth-hour-mandatory.html</link>
      <pubDate>Mon, 20 Apr 2009 16:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/earth-hour-mandatory.html</guid>
      <description>&lt;p&gt;Just because we didn&amp;rsquo;t participate in Earth Hour, didn&amp;rsquo;t mean that our Power company, Salt River Project (SRP) needed to turn off power to the whole neighborhood last night and again this morning ;)&lt;/p&gt;&#xA;&lt;p&gt;I am all for using our resources wisely. But sometimes I rebel against the symbolic gestures.&lt;/p&gt;&#xA;&lt;p&gt;I mean if the power company needs an hour off can&amp;rsquo;t they just schedule downtime like we do with computer systems?&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM FIM Webinar Custom Workflow -- Joe Zamora</title>
      <link>https://identitymanaged.com/2009/04/ilm-fim-webinar-custom-workflow-joe.html</link>
      <pubDate>Mon, 20 Apr 2009 11:54:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/ilm-fim-webinar-custom-workflow-joe.html</guid>
      <description>&lt;p&gt;Joe Zamora the maintainer of the Ensynch ILM 2 Custom Workflow Walkthrough is our main presenter at our next Webinar this Thursday at 9 AM Pacific. To register click on the image below. The code from our Pre-con workshop is posted on CodePlex &lt;a href=&#34;http://ilm2rc0enswf.codeplex.com/&#34; title=&#34;Ensynch Custom WF Activities&#34;&gt;Ensynch Custom WF Activities&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://cl.exct.net/?qs=45744f93df68b50f7de1c8e4b39f36f2fb99bf91221edddc4ca0f6eaee73d451&#34;&gt;&lt;img src=&#34;http://www.camelogic.com/idchaos/images/6ece7bbccd59_7581/image.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Install ILM 2 in a SharePoint Farm</title>
      <link>https://identitymanaged.com/2009/04/install-ilm-2-in-sharepoint-farm.html</link>
      <pubDate>Thu, 16 Apr 2009 17:40:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/install-ilm-2-in-sharepoint-farm.html</guid>
      <description>&lt;p&gt;As I endeavored to install the ILM 2 Portal into a SharePoint farm (WSS 3.0 SP 1) with a remote database I encountered the following problem:&lt;/p&gt;&#xA;&lt;p&gt;The dreaded Premature Failure during installation.&lt;/p&gt;&#xA;&lt;p&gt;When I turned on logging for the install and examined the file, I found:&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;Action 14:55:25: ConfigPortalAnonymousAccess.&lt;/em&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;CAQuietExec:&lt;/em&gt; &lt;/p&gt;&#xA;&lt;p&gt;&lt;em&gt;CAQuietExec:  This operation can be performed only on a computer that is joined to a server farm by users who have permissions in SQL Server to read from the configuration database. To connect this server to the server farm, use the SharePoint Products and Technologies Configuration Wizard, located on the Start menu in Administrative Tools.&lt;/em&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>What&#39;s in name? Forefront Identity Manager 2010</title>
      <link>https://identitymanaged.com/2009/04/what-in-name-forefront-identity-manager.html</link>
      <pubDate>Thu, 16 Apr 2009 17:26:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/what-in-name-forefront-identity-manager.html</guid>
      <description>&lt;p&gt;In case you haven&amp;rsquo;t heard Zoomit VIA or rather Microsoft MetaDirectory Services has been renamed yet again, from Microsoft Identity Integration Server 2003 to Identity Lifecycle Manager 2007 to Forefront Identity Manager 2010 or FIM for short. For obvious reasons the L was dropped when the F was added (Forefront + ILM = FILM).&lt;/p&gt;&#xA;&lt;h1 id=&#34;so-ilm-2--fim-2010&#34;&gt;So ILM 2 =&amp;gt; FIM 2010&lt;/h1&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.camelogic.com/idchaos/images/ForefrontIdentityManager_A598/image.png&#34;&gt;&lt;img src=&#34;http://www.camelogic.com/idchaos/images/ForefrontIdentityManager_A598/image_thumb.png&#34; alt=&#34;image&#34; title=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;(stole this graphic from &lt;a href=&#34;http://www.identitychaos.com/2009/04/forefront-identity-manager.html&#34;&gt;Brad Turner&amp;rsquo;s blog&lt;/a&gt; &amp;ndash; his Smart Art creations are beautiful &amp;ndash; recently I have been studying smart art under his tutelage I hope to soon approach his level of skill)&lt;/p&gt;</description>
    </item>
    <item>
      <title>Ensynch The Place to Be</title>
      <link>https://identitymanaged.com/2009/04/ensynch-place-to-be.html</link>
      <pubDate>Wed, 15 Apr 2009 07:46:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/ensynch-place-to-be.html</guid>
      <description>&lt;p&gt;In the last four months two very talented people have joined Ensynch, Chris Calderon, ILM MVP, and Mark Struck.&lt;/p&gt;&#xA;&lt;p&gt;Chris Calderon of &lt;a href=&#34;http://blog.identityjunkie.com&#34;&gt;IdentityJunkie.com&lt;/a&gt; fame is extremely talented with ILM, AD Federated Services (AD FS) and many other tools.&lt;/p&gt;&#xA;&lt;p&gt;Mark Struck, is a very talented developer, and experienced implementer of ILM. Even before Mark joined the team he and I collaborated to figure out how to use the ILM 2 web services.&lt;/p&gt;</description>
    </item>
    <item>
      <title>A few excellent Live@edu (Outlook Live) Blogs</title>
      <link>https://identitymanaged.com/2009/04/few-excellent-liveedu-outlook-live.html</link>
      <pubDate>Tue, 14 Apr 2009 12:35:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/04/few-excellent-liveedu-outlook-live.html</guid>
      <description>&lt;p&gt;I have been involved with the Microsoft &lt;a href=&#34;mailto:Live@edu&#34;&gt;Live@edu&lt;/a&gt; (formerly Windows &lt;a href=&#34;mailto:Live@edu&#34;&gt;Live@edu&lt;/a&gt;) and the Outlook Live (formerly Exchange Labs) programs for quite sometime.&lt;/p&gt;&#xA;&lt;p&gt;What a wonderful opportunity for schools to alleviate the cost of hosting email for students and then to be able to offer it to alumni helping provide them with lifelong connection to the university and way to keep their email address from their student days. Maintaining stronger ties leads to more evangelism on the school&amp;rsquo;s behalf and will lead to more Alumni donations. I would have love have kept my &lt;a href=&#34;mailto:dpl@bigdog.engr.arizona.edu&#34;&gt;dpl@bigdog.engr.arizona.edu&lt;/a&gt;, &lt;a href=&#34;mailto:lundelld@gas.uug.arizona.edu&#34;&gt;lundelld@gas.uug.arizona.edu&lt;/a&gt; or &lt;a href=&#34;mailto:dlundell@u.arizona.edu&#34;&gt;dlundell@u.arizona.edu&lt;/a&gt; accounts. Instead of rediscovering friends on facebook I might never have lost touch with them in the first place.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 addons</title>
      <link>https://identitymanaged.com/2009/03/ilm-2-addons.html</link>
      <pubDate>Wed, 25 Mar 2009 14:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/ilm-2-addons.html</guid>
      <description>&lt;p&gt;Marvin Tansley of Gemalto demonstrated their add-on to ILM 2 for provisioning One Time Password (OTP) devices using ILM 2, with the goal of minimizing the # of portals that users visit in order to perform self service management. It looks really good, it even accounts for lost device management.&lt;/p&gt;&#xA;&lt;p&gt;Gil Kirkpatrick of Quest interviewed me on camera to discuss my experiences at the conference. That was fun.&lt;/p&gt;&#xA;&lt;p&gt;At lunch Gil handed out prizes (we provided a red colored XBox &amp;ndash; I guess the red had something to do with Resident Evil). But you had to present to win, and I do mean present &amp;ndash; you had to respond within 10 seconds to get your prize.&lt;/p&gt;</description>
    </item>
    <item>
      <title>New Certificate and Identity Blogger on the Loose</title>
      <link>https://identitymanaged.com/2009/03/new-certificate-and-identity-blogger-on.html</link>
      <pubDate>Wed, 25 Mar 2009 11:34:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/new-certificate-and-identity-blogger-on.html</guid>
      <description>&lt;p&gt;Marc Mac Donnell has just launched his blog on &lt;a href=&#34;http://assurancesinidentity.blogspot.com/&#34; title=&#34;http://assurancesinidentity.blogspot.com/&#34;&gt;http://assurancesinidentity.blogspot.com/&lt;/a&gt; and called it Assurances in Identity, and has posted the links to the CLM API documentation and &lt;a href=&#34;http://www.microsoft.com/casestudies/casestudy.aspx?casestudyid=4000003478&#34;&gt;case study&lt;/a&gt; about some work he did with MCS UK and CapGemini.&lt;/p&gt;&#xA;&lt;p&gt;I look forward to many more posts from Mark about some of the wizardry and trick in managing certificates and identities.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>MSIT&#39;s implementation of ILM 2</title>
      <link>https://identitymanaged.com/2009/03/msit-implementation-of-ilm-2.html</link>
      <pubDate>Wed, 25 Mar 2009 11:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/msit-implementation-of-ilm-2.html</guid>
      <description>&lt;p&gt;TEC 2009 continues onto the last day.&lt;/p&gt;&#xA;&lt;p&gt;Joel Silver spoke on his efforts and plans to implement ILM 2 for Microsoft. He presented a very interesting workflow to show how he addressed the challenge of creating unique email aliases.&lt;/p&gt;&#xA;&lt;p&gt;Then I listened to &lt;a href=&#34;http://blogs.kuppingercole.com/gaehtgens/&#34;&gt;Felix&lt;/a&gt; as he discussed some of the interesting aspects of LDAP enhancements from around the vendorscape (I think I just made that word up).&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2009</title>
      <link>https://identitymanaged.com/2009/03/tec-2009.html</link>
      <pubDate>Tue, 24 Mar 2009 15:50:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/tec-2009.html</guid>
      <description>&lt;p&gt;Now that our pre-conference workshop on &lt;a href=&#34;http://www.tec2009.com/session_abstracts.php#wstaming&#34;&gt;Taming the Chaos – Building a Practical Lifecycle Mgt. Application in the ILM “2” Portal&lt;/a&gt; is done&lt;/p&gt;&#xA;&lt;p&gt;and our (Brad, Chris and me) sessions  done: &lt;a href=&#34;http://www.tec2009.com/session_abstracts.php#ridechaos&#34;&gt;Proper Care &amp;amp; Feeding of ILM, CLM and RMS&lt;/a&gt; , &lt;a href=&#34;http://www.tec2009.com/session_abstracts.php#designobjectilm2&#34;&gt;Designing an Object Expiration &amp;amp; Reconciliation process in ILM 2&lt;/a&gt; , &lt;a href=&#34;http://www.tec2009.com/session_abstracts.php#rescue&#34;&gt;Rescue Your Identity Metasystem from Chaos&lt;/a&gt; (reporting against ILM 2), and &lt;a href=&#34;http://www.tec2009.com/session_abstracts.php#adfsextensibility&#34;&gt;ADFS Extensibility&lt;/a&gt;, we are all able to relax a little and enjoy everyone else&amp;rsquo;s sessions.&lt;/p&gt;</description>
    </item>
    <item>
      <title>TEC 2009 -- Ensynch Identity Bus</title>
      <link>https://identitymanaged.com/2009/03/tec-2009-ensynch-identity-bus-comments.html</link>
      <pubDate>Tue, 24 Mar 2009 15:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/tec-2009-ensynch-identity-bus-comments.html</guid>
      <description>&lt;h4 id=&#34;great-dinner--identity-bus-was-also-an-excell&#34;&gt;great dinner. ;) identity bus was also an excell&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/03816260089954773888&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Mar 3, 2009&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;great dinner. ;) identity bus was also an excellent idea - kudos!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>TEC 2009 -- Ensynch Identity Bus</title>
      <link>https://identitymanaged.com/2009/03/tec-2009-ensynch-identity-bus.html</link>
      <pubDate>Tue, 24 Mar 2009 15:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/tec-2009-ensynch-identity-bus.html</guid>
      <description>&lt;p&gt;Last night Fellow ILM MVP&amp;rsquo;s &lt;a href=&#34;http://www.identitychaos.com/&#34;&gt;Brad Turner&lt;/a&gt;, &lt;a href=&#34;http://blog.identityjunkie.com/&#34;&gt;Chris Calderon&lt;/a&gt;, &lt;a href=&#34;http://www.wapshere.com/missmiis/&#34;&gt;Carol Wapshere&lt;/a&gt; (pronounced Wap shear and well known as Miss MIIS) and I along with a number of other TEC 2009 attendees rode on the Ensynch Identity Bus to take us from the Green Valley Ranch Resort to the Las Vegas Strip. After a great steak dinner at Smith and Wollansky&amp;rsquo;s (across from New York New York) a few us of walked the strip hoping to see the fountains at the Bellagio, but alas they shut off at midnight.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Posted: ILM 2 Business Value webinar recording</title>
      <link>https://identitymanaged.com/2009/03/posted-ilm-2-business-value-webinar.html</link>
      <pubDate>Mon, 16 Mar 2009 11:00:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/posted-ilm-2-business-value-webinar.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.ensynch.com/Documents.aspx?docID=137&#34; title=&#34;ILM 2 Business Value Webinar Recording&#34;&gt;ILM 2 Business Value Webinar Recording&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;It has actually been posted for some time now, I have just been a bit busy (apology to my readers).&lt;/p&gt;&#xA;&lt;p&gt;Other items will also get posted here in the column on the right hand side:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://ensynch.com/pa_ci_identity_and_access_management.aspx&#34; title=&#34;http://ensynch.com/pa_ci_identity_and_access_management.aspx&#34;&gt;http://ensynch.com/pa_ci_identity_and_access_management.aspx&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM/MIIS Sync Engine Clustering Windows 2008</title>
      <link>https://identitymanaged.com/2009/03/ilmmiis-sync-engine-clustering-windows-comments.html</link>
      <pubDate>Mon, 16 Mar 2009 10:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/ilmmiis-sync-engine-clustering-windows-comments.html</guid>
      <description>&lt;h4 id=&#34;david&#34;&gt;David,&lt;/h4&gt;&#xA;&lt;p&gt;I can&amp;rsquo;t figure this one out easily s&amp;hellip;&#xA;&lt;a href=&#34;https://www.blogger.com/profile/16607719880402498029&#34; title=&#34;noreply@blogger.com&#34;&gt;Anu&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Mar 1, 2009&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;David,&lt;/p&gt;&#xA;&lt;p&gt;I can&amp;rsquo;t figure this one out easily since I don&amp;rsquo;t have a deep knowledge of SQL. I&amp;rsquo;d appreciate your feedback. I am beginning to understand the different options and implementaions for scaling out SQL HA/DR/automatic failover.&lt;/p&gt;&#xA;&lt;p&gt;In ILM &amp;ldquo;2&amp;rdquo; architecture, with scaling out MIIS and its SQL, can performace improvements and concurrent MA runs be achieved? I think not but I&amp;rsquo;d like to wrong this time!&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM/MIIS Sync Engine Clustering Windows 2008</title>
      <link>https://identitymanaged.com/2009/03/ilmmiis-sync-engine-clustering-windows.html</link>
      <pubDate>Mon, 16 Mar 2009 10:31:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/ilmmiis-sync-engine-clustering-windows.html</guid>
      <description>&lt;p&gt;First, let me say thank you to &lt;a href=&#34;http://blogs.msdn.com/alextch/default.aspx&#34;&gt;Alex Tcherniakhovski&lt;/a&gt; for pioneering the way in clustering the MIIS Service or as it is now known the ILM Sync Engine. That blog, presentation and script was an excellent set of work. &lt;a href=&#34;http://blogs.msdn.com/alextch/archive/2005/12/17/clusteredmiis.aspx&#34; title=&#34;http://blogs.msdn.com/alextch/archive/2005/12/17/clusteredmiis.aspx&#34;&gt;http://blogs.msdn.com/alextch/archive/2005/12/17/clusteredmiis.aspx&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;On Windows Server 2008, a few things have changed that break the script that Alex T. provides.&lt;/p&gt;&#xA;&lt;p&gt;In Windows Server 2003 the cluster services runs as a domain account and as long as the user has access to all nodes, to stop and start services, and as an MIIS Administrator then it should be able to do the trick.&lt;/p&gt;</description>
    </item>
    <item>
      <title>At TEC get on the Ensynch Identity Bus</title>
      <link>https://identitymanaged.com/2009/03/at-tec-get-on-ensynch-identity-bus.html</link>
      <pubDate>Thu, 12 Mar 2009 00:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/at-tec-get-on-ensynch-identity-bus.html</guid>
      <description>&lt;p&gt;If you are coming to &lt;a href=&#34;http://www.tec2009.com/&#34;&gt;TEC 2009&lt;/a&gt; at the Green Valley Ranch Resort outside of Las Vegas, and want to take a trip to the strip Monday or Tuesday night then you are in luck &amp;ndash; Ensynch is sponsoring the Identity Bus &amp;ndash; we&amp;rsquo;ll have some buses that will be running from the Resort to one of the Monorail stops on the strip. Details will be provided at the conference in your handouts. I will riding on the Identity Bus some of the time and hope to see you there!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Netpro DEC -&gt; Quest TEC -- Ensynch&#39;s Sessions</title>
      <link>https://identitymanaged.com/2009/03/netpro-dec-quest-tec-ensynch-sessions.html</link>
      <pubDate>Wed, 11 Mar 2009 12:09:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/03/netpro-dec-quest-tec-ensynch-sessions.html</guid>
      <description>&lt;p&gt;Back in business school we always studied name changes and rebranding, and this one has been interesting&lt;/p&gt;&#xA;&lt;p&gt;Last summer NetPro deciding to expand the Directory Experts Conference (DEC) to include an exchange conference and so they re-branded the conference NetPro&amp;rsquo;s The Experts Conference. Then Quest acquired NetPro, so it became a completely re-branded conference as Quest&amp;rsquo;s The Expert Conference. &lt;/p&gt;&#xA;&lt;p&gt;So NetPro DEC became Quest TEC.&lt;/p&gt;&#xA;&lt;p&gt;Sunday Mar 22nd - Wed Mar 25th in Vegas &lt;a href=&#34;http://www.tec2009.com&#34;&gt;www.tec2009.com&lt;/a&gt; &lt;/p&gt;</description>
    </item>
    <item>
      <title>Another talented Ensynchian joins the blogosphere</title>
      <link>https://identitymanaged.com/2009/02/another-talented-ensynchian-joins.html</link>
      <pubDate>Thu, 12 Feb 2009 13:21:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/02/another-talented-ensynchian-joins.html</guid>
      <description>&lt;p&gt;My colleague Joe Zamora, a talented developer, who has been instrumental in helping us advance our knowledge of custom workflows, has just launched his own blog: &lt;a href=&#34;http://c--shark.blogspot.com:80/&#34;&gt;CShark&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;His first post is on how to &amp;ldquo;&lt;a href=&#34;http://c--shark.blogspot.com/2009/02/generate-accountname-in-ilm-2-custom.html&#34;&gt;Generate AccountName in ILM2 custom workflow activity&lt;/a&gt;&amp;rdquo; and it came in response to a question in the ILM 2 connect forum entitled:  Custom Workflow Activity to Generate samAccountName.&lt;/p&gt;&#xA;&lt;p&gt;Go Joe Go!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Webinar: Business Impact of ILM 2</title>
      <link>https://identitymanaged.com/2009/02/webinar-business-impact-of-ilm-2.html</link>
      <pubDate>Mon, 02 Feb 2009 10:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/02/webinar-business-impact-of-ilm-2.html</guid>
      <description>&lt;p&gt;Thanks to everyone that attended our Technical webinar on ILM 2 an overview and diving into how password reset works.&lt;/p&gt;&#xA;&lt;p&gt;We are at it again. Only this time we are presenting on the &lt;a href=&#34;http://www.ensynch.com/EventRegister.aspx?eventID=258&#34;&gt;business impact of Identity Management with ILM 2&lt;/a&gt;. So invite your decision makers!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ensynch.com/EventRegister.aspx?eventID=258&#34;&gt;&lt;img src=&#34;http://www.ensynch.com/beta/email/images/ILM_Webinar_Business2.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>What’s new in Identity Lifecycle Manager 2, Ask the experts</title>
      <link>https://identitymanaged.com/2009/01/whats-new-in-identity-lifecycle-manager.html</link>
      <pubDate>Mon, 19 Jan 2009 12:19:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/01/whats-new-in-identity-lifecycle-manager.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.identitychaos.com/&#34;&gt;Brad Turner&lt;/a&gt; and I are putting on a &lt;a href=&#34;http://www.ensynch.com/EventRegister.aspx?eventID=257&#34;&gt;webinar on ILM 2&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ensynch.com/EventRegister.aspx?eventID=257&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/WhatsnewinIdentityLifecycleManager2Askth_AA8F/Webinar.png&#34; alt=&#34;Webinar&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 Functions Explained</title>
      <link>https://identitymanaged.com/2009/01/ilm-2-functions-explained-comments.html</link>
      <pubDate>Tue, 06 Jan 2009 13:08:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/01/ilm-2-functions-explained-comments.html</guid>
      <description>&lt;h4 id=&#34;excellent-post-david-thanks-for-putting-this-toge&#34;&gt;Excellent post David, thanks for putting this toge&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13950085747222995199&#34; title=&#34;noreply@blogger.com&#34;&gt;Brad Turner&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jan 3, 2009&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Excellent post David, thanks for putting this together!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;To remove bit #2 shouldn&amp;rsquo;t you use BitAnd(-3,userAccountControl) ?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Paolo is correct in pointing out that the numbers I calculated for masks are wrong. I did 32-bit numbers and tested it back on the 32-bit version of the ILM 2 Beta 3 VM. The calcs should be done using 64-bit as explained here: Using FIM to enable or disable accounts in Active Directory (&lt;a href=&#34;http://social.technet.microsoft.com/wiki/contents/articles/using-fim-to-enable-or-disable-accounts-in-active-directory.aspx&#34;&gt;http://social.technet.microsoft.com/wiki/contents/articles/using-fim-to-enable-or-disable-accounts-in-active-directory.aspx&lt;/a&gt; )&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 Functions Explained</title>
      <link>https://identitymanaged.com/2009/01/ilm-2-functions-explained.html</link>
      <pubDate>Tue, 06 Jan 2009 13:08:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/01/ilm-2-functions-explained.html</guid>
      <description>&lt;p&gt;Function Name&lt;/p&gt;&#xA;&lt;p&gt;Parameters&lt;/p&gt;&#xA;&lt;p&gt;David&amp;rsquo;s Description&lt;/p&gt;&#xA;&lt;p&gt;Example&lt;/p&gt;&#xA;&lt;p&gt;Example Explanation&lt;/p&gt;&#xA;&lt;p&gt;BitAnd&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;mask&lt;br&gt;&#xA;Type: Integer&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;flag&lt;br&gt;&#xA;Type: Integer&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;BitAnd is a bitwise operation anding &lt;strong&gt;mask&lt;/strong&gt; and &lt;strong&gt;flag&lt;/strong&gt;. So if &lt;strong&gt;Flag&lt;/strong&gt; is the UserAccountControl Attribute in AD and &lt;strong&gt;mask&lt;/strong&gt; is negative 2147483645 (the &lt;a href=&#34;http://mathforum.org/library/drmath/view/54344.html&#34;&gt;two&amp;rsquo;s complement&lt;/a&gt; of 2) Then the result is that the disable bit (bit 2) is turned off leaving all of the other bits unchanged.&lt;/p&gt;&#xA;&lt;p&gt;BitAnd can be combined with Eq to detect if a bit is set&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 Functions all in one place</title>
      <link>https://identitymanaged.com/2009/01/ilm-2-functions-all-in-one-place.html</link>
      <pubDate>Mon, 05 Jan 2009 15:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2009/01/ilm-2-functions-all-in-one-place.html</guid>
      <description>&lt;p&gt;I couldn&amp;rsquo;t find in the ILM 2 RC 0 documentation anyplace that listed all of the functions available to you in sync rules and action workflows so here they are:&lt;/p&gt;&#xA;&lt;p&gt;Don&amp;rsquo;t forget about the &lt;a href=&#34;http://blogs.technet.com/doittoit/archive/2008/08/07/if.aspx&#34;&gt;boolean functions available for use in the IIF function&lt;/a&gt;  Now you can at a glance see the list of functions, their list of parameters and their official explanations&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image001.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image001_thumb.png&#34; alt=&#34;clip_image001&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image002.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image002_thumb.png&#34; alt=&#34;clip_image002&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image003.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image003_thumb.png&#34; alt=&#34;clip_image003&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image004.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image004_thumb.png&#34; alt=&#34;clip_image004&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image005.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image005_thumb.png&#34; alt=&#34;clip_image005&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image006.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image006_thumb.png&#34; alt=&#34;clip_image006&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image007.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image007_thumb.png&#34; alt=&#34;clip_image007&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image008.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image008_thumb.png&#34; alt=&#34;clip_image008&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image009.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ILM2SynchRuleFunctionsallinoneplace_DB36/clip_image009_thumb.png&#34; alt=&#34;clip_image009&#34;&gt;&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM &#34;2&#34; confirmHumanity=&#34;false&#34;</title>
      <link>https://identitymanaged.com/2008/12/ilm-confirmhumanity-comments.html</link>
      <pubDate>Tue, 23 Dec 2008 12:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/12/ilm-confirmhumanity-comments.html</guid>
      <description>&lt;h4 id=&#34;with-joes-permissions-i-am-posting-the-comment-he&#34;&gt;With Joe&amp;rsquo;s permissions I am posting the comment he&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/17202883653808140101&#34; title=&#34;noreply@blogger.com&#34;&gt;David Lundell&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Dec 3, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;With Joe&amp;rsquo;s permissions I am posting the comment he attempted to post earlier:&lt;br&gt;&#xA;Apologies for spoiling the fun, but the confirm humanity config setting has no effect in ILM “2”.&lt;/p&gt;&#xA;&lt;p&gt;This config setting is leftover from the early days of the product when we included Captcha support for AuthN. Setting this to true meant that users would go through a Captcha gate during AuthN, much like I had to do when submitting a comment. We removed that feature early on in ILM and omitted cleaning up the default config file. Today if you want a Captcha gate you would have to add a custom AuthN workflow.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM &#34;2&#34; confirmHumanity=&#34;false&#34;</title>
      <link>https://identitymanaged.com/2008/12/ilm-confirmhumanity.html</link>
      <pubDate>Tue, 23 Dec 2008 12:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/12/ilm-confirmhumanity.html</guid>
      <description>&lt;p&gt;I was getting ready to try out some of the various installation topologies that may be possible with ILM &amp;ldquo;2&amp;rdquo; including: separating the Portal and the Service (definitely possible), having two portals point back to the same service (I think it&amp;rsquo;s possible), when I came across the most interesting item in the &lt;a href=&#34;http://technet.microsoft.com/en-us/library/cc561135.aspx&#34;&gt;ILM &amp;ldquo;2&amp;rdquo; installation guide&lt;/a&gt; in the section on Installing the ILM Service and ILM Portal on separate servers. Let&amp;rsquo;s see if you can spot it too:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Business Problems and their Technical Roots</title>
      <link>https://identitymanaged.com/2008/12/business-problems-and-their-technical.html</link>
      <pubDate>Mon, 22 Dec 2008 17:26:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/12/business-problems-and-their-technical.html</guid>
      <description>&lt;p&gt;&lt;strong&gt;Business Problem&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Possible Underlying Business Problem&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Cause&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Technical Cause&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Business launches a strategic initiative late&lt;/p&gt;&#xA;&lt;p&gt;Employees don&amp;rsquo;t receive communications that they should&lt;/p&gt;&#xA;&lt;p&gt;Don&amp;rsquo;t have email accounts&lt;/p&gt;&#xA;&lt;p&gt;Aren&amp;rsquo;t in the right distribution lists&lt;/p&gt;&#xA;&lt;p&gt;Lack of automated distribution list management and self service fulfillment&lt;/p&gt;&#xA;&lt;p&gt;Employee  can&amp;rsquo;t fulfill a customer order&lt;/p&gt;&#xA;&lt;p&gt;Employees don&amp;rsquo;t have access to resources&lt;/p&gt;&#xA;&lt;p&gt;Accounts haven&amp;rsquo;t been provisioned to the systems they need&lt;/p&gt;&#xA;&lt;p&gt;Aren&amp;rsquo;t member of the groups or roles they need&lt;/p&gt;</description>
    </item>
    <item>
      <title>Business Problems VS Technical Problems</title>
      <link>https://identitymanaged.com/2008/12/business-problems-vs-technical-problems-comments.html</link>
      <pubDate>Mon, 22 Dec 2008 17:17:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/12/business-problems-vs-technical-problems-comments.html</guid>
      <description>&lt;h4 id=&#34;i-like-how-you-linked-business-problems-to-technic&#34;&gt;I like how you linked business problems to technic&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/15021806128343588742&#34; title=&#34;noreply@blogger.com&#34;&gt;William Wagner&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 4, 2011&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;I like how you linked business problems to technical problems. I think they affect each other in a lot of ways. You always need to balance them so you can succeed.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.mycorporation.com/business-formations/llc.jsp&#34;&gt;form an llc&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Business Problems VS Technical Problems</title>
      <link>https://identitymanaged.com/2008/12/business-problems-vs-technical-problems.html</link>
      <pubDate>Mon, 22 Dec 2008 17:17:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/12/business-problems-vs-technical-problems.html</guid>
      <description>&lt;p&gt;A business problem is when employees can&amp;rsquo;t execute their job duties in an efficient fashion. In fact sometimes they are unable to complete the tasks at all. Business problems are especially costly when they directly affect customers. These problems can cause cash flowing into the company to be delayed as a customer waits to place an order, or to receive goods (and hence to pay), they can cause revenue to be lost as a customer temporarily takes their business to a competitor or a finds a substitute, sometimes this leads to customers forming new business relationships and loss of all future revenue from that customer. Non-customer affecting business problems may result in higher costs without affecting revenue. For example a problem on the job shop floor causes workers to put in overtime to complete customer jobs on time, raising costs without directly affecting the customer.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Millionaire Next Door and All Your Worth</title>
      <link>https://identitymanaged.com/2008/12/millionaire-next-door-and-all-your.html</link>
      <pubDate>Sat, 06 Dec 2008 04:04:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/12/millionaire-next-door-and-all-your.html</guid>
      <description>&lt;p&gt;No this post isn&amp;rsquo;t about my new neighbors, or my new house.&lt;/p&gt;&#xA;&lt;p&gt;Its about the secret to wealth.&lt;/p&gt;&#xA;&lt;p&gt;First you buy two copies of the &lt;a href=&#34;http://www.amazon.com/Millionaire-Next-Door-Thomas-Stanley/dp/0671015206/ref=pd_bbs_sr_1?ie=UTF8&amp;amp;s=books&amp;amp;qid=1228560713&amp;amp;sr=8-1&#34;&gt;Millionaire Next Door&lt;/a&gt; and then you give one to each of your next door neighbors. Suddenly your odds of getting rich will improve.&lt;/p&gt;&#xA;&lt;p&gt;Ok hopefully that gives you a chuckle. Nonetheless, here is my prescription for improving America&amp;rsquo;s financial health. While I normally write on the topics of Identity Management and SQL Server, I did also earn an MBA from the Eller College of Business at the University of Arizona, and have done some financial counseling as a volunteer through church. So I have done some deep thinking on these matters.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 Web Services Part 1 and 1/2</title>
      <link>https://identitymanaged.com/2008/12/ilm-2-web-services-part-1-and-12.html</link>
      <pubDate>Sat, 06 Dec 2008 03:49:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/12/ilm-2-web-services-part-1-and-12.html</guid>
      <description>&lt;p&gt;A few days after my post about setting up the ILM 2 Web Service reference Joe Schulman and others from the ILM product group began a &lt;a href=&#34;http://blogs.msdn.com/imex/archive/2008/11/04/introduction-to-this-blog.aspx&#34;&gt;new blog&lt;/a&gt; designed to fill in the gaps in the knowledge in the community about how to use the web services. So far the blog looks great and is a welcome addition to my knowledge and the communities knowledge base! Great job Joe and Company and thanks for the link to my blog.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Live@edu Partner Airlift and SQL PASS, Flat Tires, and Thanksgiving</title>
      <link>https://identitymanaged.com/2008/12/liveedu-partner-airlift-and-sql-pass.html</link>
      <pubDate>Sat, 06 Dec 2008 03:49:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/12/liveedu-partner-airlift-and-sql-pass.html</guid>
      <description>&lt;p&gt;As for me why no posts since Nov 11th &amp;ndash; well, I have attended the &lt;a href=&#34;mailto:Live@edu&#34;&gt;Live@edu&lt;/a&gt; Partner Airlift in Redmond, SQL PASS, had a flat tire, and enjoyed Thanksgiving. In this post&lt;/p&gt;&#xA;&lt;p&gt;I attended the &lt;a href=&#34;mailto:Live@edu&#34;&gt;Live@edu&lt;/a&gt; Partner Airlift in Redmond to see what&amp;rsquo;s new under the sun for schools and universities. Exchange Labs is now available on a widespread basis (&lt;a href=&#34;http://www.puttyq.com/windows-live-edu&#34;&gt;see fellow MVP Almero Steyn&amp;rsquo;s blog posts on Live@edu&lt;/a&gt; and on &lt;a href=&#34;http://www.puttyq.com/2008/11/updating-exchangelabs-groups-using-powershell&#34;&gt;Exchange Labs&lt;/a&gt;) ! Students and alumni can now have school domain based exchange hosted email accounts for life at no cost to their schools. While this program has offered hotmail accounts now you can have hosted exchange accounts. I had a great time at the Airlift, thanks to Michael Wegman, Richard Wakeman, Andy Hoag, Steve Winfield (not Dave Winfield, nor Steve Winwood) and Anna Kinney and everyone else for putting it on.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSExport -- Getting the ILM Connector Space into SQL</title>
      <link>https://identitymanaged.com/2008/11/csexport-getting-ilm-connector-space.html</link>
      <pubDate>Tue, 11 Nov 2008 14:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/csexport-getting-ilm-connector-space.html</guid>
      <description>&lt;p&gt;How can I query the ILM Connector Space?&lt;/p&gt;&#xA;&lt;p&gt;&amp;ldquo;You can&amp;rsquo;t.&amp;rdquo; &amp;ndash; Yes you can.&lt;/p&gt;&#xA;&lt;p&gt;&amp;ldquo;You have to WMI.&amp;rdquo; &amp;ndash;  But WMI is limited in what you can query and slow&lt;/p&gt;&#xA;&lt;p&gt;&amp;ldquo;You have to use CSExport and then use XML tools.&amp;rdquo; &amp;ndash; that works, but this may be better&lt;/p&gt;&#xA;&lt;p&gt;The above are various answers you may receive. However, thanks to the power of SQLXML we can issue SQL queries against the ILM Connector Space (after it has been exported using CSExport).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Other interesting changes in ILM RC0</title>
      <link>https://identitymanaged.com/2008/11/other-interesting-changes-in-ilm-rc0.html</link>
      <pubDate>Mon, 03 Nov 2008 16:22:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/other-interesting-changes-in-ilm-rc0.html</guid>
      <description>&lt;p&gt;From the release Notes:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://technet.microsoft.com/en-us/library/dd239143.aspx&#34; title=&#34;http://technet.microsoft.com/en-us/library/dd239143.aspx&#34;&gt;http://technet.microsoft.com/en-us/library/dd239143.aspx&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://blogs.technet.com/doittoit/archive/2008/11/03/announcing-identity-lifecycle-manager-2-release-candidate.aspx&#34; title=&#34;Announcing Identity Lifecycle Manager “2” Release Candidate&#34;&gt;Announcing Identity Lifecycle Manager “2” Release Candidate&lt;/a&gt;&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Don&amp;rsquo;t create a multi-valued boolean attribute &amp;ndash; you will have to reinstall the ILM webservice&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;We can now create a required attribute binding without affecting existing objects!&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;support for separating the Portal from the database and having multiple portal servers&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;li&gt;&#xA;&lt;p&gt;Enhancements for customizing notification and request emails&lt;/p&gt;&#xA;&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;a) Request details will be included in the out of the box notifications&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 RC 0 is here!</title>
      <link>https://identitymanaged.com/2008/11/ilm-2-rc-0-is-here.html</link>
      <pubDate>Mon, 03 Nov 2008 10:56:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/ilm-2-rc-0-is-here.html</guid>
      <description>&lt;p&gt;Identity Lifecycle Manager &amp;ldquo;2&amp;rdquo; Release Candidate 0 is released.&lt;/p&gt;&#xA;&lt;p&gt; &lt;a href=&#34;https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=433&amp;amp;DownloadID=14714&#34; title=&#34;ILM &#39;2&#39; Release Candidate (RC)&#34;&gt;ILM &amp;lsquo;2&amp;rsquo; Release Candidate (RC)&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Improvements at  First Glance&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;ol&gt;&#xA;&lt;li&gt;No need for &amp;ldquo;Managed:&amp;rdquo; to prefix metaverse attributes so that they can be managed by ILM 2 Web Service&lt;/li&gt;&#xA;&lt;li&gt;Changes to Workflow to make it easier&lt;/li&gt;&#xA;&lt;li&gt;Install routines improved&lt;/li&gt;&#xA;&lt;li&gt;The confusing ARP file needed for custom activities has been replaced by an Object in the Data store&lt;/li&gt;&#xA;&lt;li&gt;SQL 2008 is required&lt;/li&gt;&#xA;&lt;/ol&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Is ILM 2 RC0 is out? Well the docs are!</title>
      <link>https://identitymanaged.com/2008/11/is-ilm-2-rc0-is-out-well-docs-are.html</link>
      <pubDate>Sun, 02 Nov 2008 20:16:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/is-ilm-2-rc0-is-out-well-docs-are.html</guid>
      <description>&lt;p&gt;Most of the online Technet docs now read &amp;ldquo;ILM &amp;ldquo;2&amp;rdquo; (Release Candidate)&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;For example check out the new ILM 2 Release Candidate Installation Guide&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://technet.microsoft.com/en-us/library/cc561135.aspx&#34; title=&#34;http://technet.microsoft.com/en-us/library/cc561135.aspx&#34;&gt;http://technet.microsoft.com/en-us/library/cc561135.aspx&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;No more support for SQL 2005 from here on it is all SQL 2008&lt;/p&gt;&#xA;&lt;p&gt;&amp;ldquo;SQL Server 2008 64-bit Standard or Enterprise Editions&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;Good thing I just got back my score reports on my two SQL 2008 beta exams:&lt;/p&gt;&#xA;&lt;p&gt;I am now an&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.microsoft.com/learning/mcp/mcts/sql/2008/&#34;&gt;MCTS: SQL Server 2008, Implementation and Maintenance&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 Web Services Part 1 The Service Reference</title>
      <link>https://identitymanaged.com/2008/11/ilm-2-web-services-part-1-service-comments.html</link>
      <pubDate>Sat, 01 Nov 2008 10:22:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/ilm-2-web-services-part-1-service-comments.html</guid>
      <description>&lt;h4 id=&#34;does-ilm-open-soap-interfaces-native-so-that-dev&#34;&gt;Does ILM open SOAP interfaces native? So that dev&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/10052579402864563736&#34; title=&#34;noreply@blogger.com&#34;&gt;RobertW&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Mar 4, 2009&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Does ILM open SOAP interfaces native? So that developers who are simply looking for a .wsdl file to build their client can get up and running quickly.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;not exactly you need to use the WCF approach.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>ILM 2 Web Services Part 1 The Service Reference</title>
      <link>https://identitymanaged.com/2008/11/ilm-2-web-services-part-1-service.html</link>
      <pubDate>Sat, 01 Nov 2008 10:22:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/ilm-2-web-services-part-1-service.html</guid>
      <description>&lt;p&gt;Together, Mark Struck of Ipseity Inc and I, have figured out (after much beating of our heads against brick walls) how to use the ILM 2 Enumeration Endpoint to perform some basic reporting. (I figured out how to send the enumeration and get a response and then Mark figured out how to correctly form the pull messages so as to be able to retrieve the actual objects &amp;ndash; teamwork at its finest). We would also like to thank Mark Gabarra and Rob Ward for their input.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Under the hood of ILM 2 -- Part 2 Read the WCF Trace!</title>
      <link>https://identitymanaged.com/2008/11/under-hood-of-ilm-2-part-2-read-wcf.html</link>
      <pubDate>Sat, 01 Nov 2008 10:01:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/under-hood-of-ilm-2-part-2-read-wcf.html</guid>
      <description>&lt;p&gt;Take a look at &lt;a href=&#34;https://identitymanaged.com/blog/2008/11/under-hood-of-ilm-2-part-1-enable-wcf.html&#34;&gt;Part 1 to enable tracing&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;To view the log you need to have installed the Windows SDK and then you use the Service Trace Viewer&lt;/p&gt;&#xA;&lt;p&gt;C:\Program Files\Microsoft SDKs\Windows\v6.0A\Bin\SvcTraceViewer.exe&lt;/p&gt;&#xA;&lt;p&gt;If the file is over 50 MB you will get the partial loading screen like this one. Try and limited the estimated size, if you open too much it will be very slow. Even 20 MB can be really slow.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Under the hood of ILM 2 -- Part 1 Enable WCF Tracing!</title>
      <link>https://identitymanaged.com/2008/11/under-hood-of-ilm-2-part-1-enable-wcf-comments.html</link>
      <pubDate>Sat, 01 Nov 2008 09:23:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/under-hood-of-ilm-2-part-1-enable-wcf-comments.html</guid>
      <description>&lt;h4 id=&#34;thanks-david-for-those-of-you-looking-for-the-rig&#34;&gt;Thanks David, for those of you looking for the rig&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13950085747222995199&#34; title=&#34;noreply@blogger.com&#34;&gt;Brad Turner&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Nov 5, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks David, for those of you looking for the right SDK, you&amp;rsquo;re likely going to want the most recent version for Server 2008 and .NET 3.5 which can be found here:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.microsoft.com/downloads/details.aspx?FamilyId=F26B1AA4-741A-433A-9BE5-FA919850BDBF&amp;amp;displaylang=en&#34;&gt;http://www.microsoft.com/downloads/details.aspx?FamilyId=F26B1AA4-741A-433A-9BE5-FA919850BDBF&amp;amp;displaylang=en&lt;/a&gt;&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Under the hood of ILM 2 -- Part 1 Enable WCF Tracing!</title>
      <link>https://identitymanaged.com/2008/11/under-hood-of-ilm-2-part-1-enable-wcf.html</link>
      <pubDate>Sat, 01 Nov 2008 09:23:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/under-hood-of-ilm-2-part-1-enable-wcf.html</guid>
      <description>&lt;p&gt;Want to understand what is happening with your custom ILM 2 workflow? or your calls to the web service?&lt;/p&gt;&#xA;&lt;p&gt;Try enabling WCF Tracing. By enabling WCF tracing for the Identity Lifecycle Manager Resource Management Service you get to track requests to the webservice. This can help you figure out if your requests are even getting to the webservice.&lt;/p&gt;&#xA;&lt;p&gt;To enable tracing open the config file:&lt;/p&gt;&#xA;&lt;p&gt;C:\Program Files\Microsoft Identity Management\Common Services\&lt;/p&gt;</description>
    </item>
    <item>
      <title>Happy Halloween -- It&#39;s all about Identity Management</title>
      <link>https://identitymanaged.com/2008/11/happy-halloween-it-all-about-identity.html</link>
      <pubDate>Sat, 01 Nov 2008 09:14:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/11/happy-halloween-it-all-about-identity.html</guid>
      <description>&lt;p&gt;Last night as I took my children trick or treating through our neighborhood I thought about Halloween from an Identity Management Perspective:&lt;/p&gt;&#xA;&lt;p&gt;We provision temporary identities to our children (costumes) that allow them to make a claim when they show up at neighbors&amp;rsquo; doors &amp;ldquo;Trick or Treat (I am wearing costume &amp;ndash; the claim; will your grant me access to candy &amp;ndash; the resource request)?&amp;rdquo;&lt;/p&gt;&#xA;&lt;p&gt;At which point the neighbor will almost invariably give out some candy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Live ID&#39;s are now Open ID&#39;s, Geneva supports SAML 2.0</title>
      <link>https://identitymanaged.com/2008/10/live-id-are-now-open-id-geneva-supports.html</link>
      <pubDate>Thu, 30 Oct 2008 16:37:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/10/live-id-are-now-open-id-geneva-supports.html</guid>
      <description>&lt;p&gt;At the &lt;a href=&#34;http://channel9.msdn.com/pdc2008/BB11/&#34;&gt;PDC Microsoft&amp;rsquo;s Kim Cameron and colleague Bertocci Vittorio&lt;/a&gt; announced that Microsoft Live is now an Open Id provider. Additionally, when signing into Live you can use Information Cards (Info Card, Card Space, Geneva Card Space).&lt;/p&gt;&#xA;&lt;p&gt;They also demonstrated the new Geneva Framework (formerly known as Zermat) &amp;ndash; essentially a successor to Windows Server 2008 Active Directory Federation Services, and showed it supporting SAML 2.0 the &amp;ldquo;protocol&amp;rdquo; not just SAML 2.0 the token.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Semi-Automated Install of ILM 2 Beta 3</title>
      <link>https://identitymanaged.com/2008/10/semi-automated-install-of-ilm-2-beta-3.html</link>
      <pubDate>Wed, 22 Oct 2008 21:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/10/semi-automated-install-of-ilm-2-beta-3.html</guid>
      <description>&lt;p&gt;ILM 2 Beta 3 won&amp;rsquo;t perform a completely automatic quiet install but we can come close. Colleague Brad Turner and I have developed the following approach to the install and the post install tasks.&lt;/p&gt;&#xA;&lt;p&gt;Brad worked out most of the issues with the ILM 2 Services install itself and then I worked on most of the issues with the post install tasks. I will cover the install of the Metadirectory services first, then the ILM 2 Beta 3 Identity Management Platform Services including its batch files and then discuss the post install tasks and present its related files.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Server Agent should be running or install of ILM 2 Services fails</title>
      <link>https://identitymanaged.com/2008/10/sql-server-agent-should-be-running-or.html</link>
      <pubDate>Wed, 22 Oct 2008 20:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/10/sql-server-agent-should-be-running-or.html</guid>
      <description>&lt;p&gt;I posted the following to the Community Content Section of the &lt;a href=&#34;http://technet.microsoft.com/en-us/library/cc561135.aspx&#34;&gt;ILM 2 Beta 3 Installation Guide&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;The SQL Agent Service account must be a sql sysadmin and the SQL Agent Service must be running or during install you may get &amp;ldquo;error -2147217900&lt;/p&gt;&#xA;&lt;p&gt;Failed to execute sql string addtemporaleventsjobtoSQLServer&amp;rdquo; while trying to install ILM 2 Beta 3 Identity Management Platform Services. Apparently, the install routine needs to create a SQL Agent Job and with SQL 2005 the Agent must be running to create a job.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Changing SQL Service Account Passwords for a Cluster</title>
      <link>https://identitymanaged.com/2008/10/changing-sql-service-account-passwords.html</link>
      <pubDate>Wed, 22 Oct 2008 13:23:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/10/changing-sql-service-account-passwords.html</guid>
      <description>&lt;p&gt;Here is an &lt;a href=&#34;http://www.microsoft.com/technet/scriptcenter/guide/sas_ser_jpez.mspx?mfr=true&#34;&gt;excellent script for changing service account passwords&lt;/a&gt; and should work fine as long as you restart the SQL services afterwards.&lt;/p&gt;&#xA;&lt;p&gt;However the &lt;a href=&#34;http://blogs.msdn.com/stuartpa/archive/2005/09/02/460363.aspx&#34;&gt;following blog post&lt;/a&gt; indicates that more is going on than just a password change:&lt;/p&gt;&#xA;&lt;p&gt;&amp;ldquo;never use the plain old Windows Service Control Manager (SCM) to manipulate SQL Services.  The SQL Server Configuration Manager does a lot more work in the background to keep security consistent across the installation. &amp;quot;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Installing a Multi-Instance SQL 2005 Cluster</title>
      <link>https://identitymanaged.com/2008/10/installing-multi-instance-sql-2005-comments.html</link>
      <pubDate>Wed, 15 Oct 2008 00:54:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/10/installing-multi-instance-sql-2005-comments.html</guid>
      <description>&lt;h4 id=&#34;hi-im-installing-sql-server-2005-in-2-node-&#34;&gt;Hi, I&amp;rsquo;m installing SQL Server 2005 in 2 node &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/05001115668295519336&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jun 3, 2010&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I&amp;rsquo;m installing SQL Server 2005 in 2 node cluster setup and I&amp;rsquo;m getting the below error:&lt;/p&gt;&#xA;&lt;p&gt;TITLE: Microsoft SQL Server 2005 Setup&lt;br&gt;&#xA;-&amp;mdash;&amp;mdash;&amp;mdash;&amp;mdash;&amp;mdash;&amp;mdash;&amp;mdash;&amp;mdash;&amp;mdash;&amp;ndash;&lt;/p&gt;&#xA;&lt;p&gt;SQL Server Setup has determined that the following account properties are not specified: &amp;lsquo;SQLBROWSERACCOUNT&amp;rsquo; . The properties specify the startup account for the services that are installed. To proceed, refer to the template.ini and set the properties to valid account names. If you are specifying a windows user account, you must also specify the password for the account.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Installing a Multi-Instance SQL 2005 Cluster</title>
      <link>https://identitymanaged.com/2008/10/installing-multi-instance-sql-2005.html</link>
      <pubDate>Wed, 15 Oct 2008 00:54:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/10/installing-multi-instance-sql-2005.html</guid>
      <description>&lt;p&gt;Some of you may run into a problem when installing a multi-instance SQL Server Cluster, in particular when you install the second or third instance in your cluster.&lt;/p&gt;&#xA;&lt;p&gt;Like this one:&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/InstallingaMultiInstanceSQL2005Cluster_12B3D/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/InstallingaMultiInstanceSQL2005Cluster_12B3D/image_thumb.png&#34; alt=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Microsoft SQI Server 2005 Setup&lt;br&gt;&#xA;SQL server Setup has determined that the Following account properties are not specified: &lt;br&gt;&#xA;‘SQLBROWSERACCOUNT’. The properties specify the startup account for the services that are installed. To proceed, refer to the template.ini and set the properties to valid account names. If you are specifying a windows user account, you must also specify the password for the account.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Projections showing up as Joins?</title>
      <link>https://identitymanaged.com/2008/10/projections-showing-up-as-joins-comments.html</link>
      <pubDate>Wed, 08 Oct 2008 14:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/10/projections-showing-up-as-joins-comments.html</guid>
      <description>&lt;h4 id=&#34;hi-david-i-this-fast-paced-growing-technology-s&#34;&gt;Hi David, I this fast paced growing technology s&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/09304611564808148707&#34; title=&#34;noreply@blogger.com&#34;&gt;Unknown&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Jun 5, 2021&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Hi David,&lt;/p&gt;&#xA;&lt;p&gt;I this fast paced growing technology space, dominating cloud technologies how do you feel about MIM&amp;rsquo;s future. Give i don&amp;rsquo;t see Microsoft doing any innovations/upgrade in this arena. Please help me understand.&lt;/p&gt;&#xA;&lt;p&gt;Thank you,&lt;br&gt;&#xA;Durgesh&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Projections showing up as Joins?</title>
      <link>https://identitymanaged.com/2008/10/projections-showing-up-as-joins.html</link>
      <pubDate>Wed, 08 Oct 2008 14:27:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/10/projections-showing-up-as-joins.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://connect.microsoft.com/feedback/ViewFeedback.aspx?FeedbackID=373881&amp;amp;SiteID=433&#34; title=&#34;https://connect.microsoft.com/feedback/ViewFeedback.aspx?FeedbackID=373881&amp;amp;SiteID=433&#34;&gt;https://connect.microsoft.com/feedback/ViewFeedback.aspx?FeedbackID=373881&amp;amp;SiteID=433&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;So I found a slight inconsistency when following some of the ILM 2 walk-throughs. When you setup an inbound synch rule that creates objects in ILM the lineage says that the connector space object became a connector through join rules instead of projection rules. Minor bug &amp;ndash; but it sure can be confusing.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ProjectionsshowingupasJoins_C61F/image.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ProjectionsshowingupasJoins_C61F/image_thumb.png&#34; alt=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ProjectionsshowingupasJoins_C61F/image_3.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ProjectionsshowingupasJoins_C61F/image_thumb_3.png&#34; alt=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ProjectionsshowingupasJoins_C61F/image_4.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/ProjectionsshowingupasJoins_C61F/image_thumb_4.png&#34; alt=&#34;image&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;HR Inbound Sync Rule&lt;/p&gt;&#xA;&lt;p&gt;General Information&lt;/p&gt;&#xA;&lt;p&gt;Created Time&lt;/p&gt;&#xA;&lt;p&gt;8/27/2008 8:10:09 PM&lt;/p&gt;&#xA;&lt;p&gt;Connected System&lt;/p&gt;</description>
    </item>
    <item>
      <title>ILM 2 Workflow Activity Walkthrough &#34;Awesome&#34;</title>
      <link>https://identitymanaged.com/2008/09/ilm-2-workflow-activity-walkthrough-comments.html</link>
      <pubDate>Wed, 24 Sep 2008 17:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/ilm-2-workflow-activity-walkthrough-comments.html</guid>
      <description>&lt;h4 id=&#34;thanks-david-it-was-a-team-effort-for-sure&#34;&gt;Thanks David, it was a team effort for sure.&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13950085747222995199&#34; title=&#34;noreply@blogger.com&#34;&gt;Brad Turner&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 3, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Thanks David, it was a team effort for sure.&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>ILM 2 Workflow Activity Walkthrough &#34;Awesome&#34;</title>
      <link>https://identitymanaged.com/2008/09/ilm-2-workflow-activity-walkthrough.html</link>
      <pubDate>Wed, 24 Sep 2008 17:18:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/ilm-2-workflow-activity-walkthrough.html</guid>
      <description>&lt;p&gt;Paul Divan, a sharp coworker and fellow Solutions Architect at Ensynch has authored an &amp;ldquo;awesome&amp;rdquo; whitepaper on custom activities in ILM 2 Workflow using Windows Workflow Foundations. (&lt;a href=&#34;http://www.identitychaos.com/2008/09/ilm-2-workflow-activity-walkthrough.html&#34;&gt;Brad Turner&lt;/a&gt; contributed a bunch, and I made a few contributions as well)&lt;/p&gt;&#xA;&lt;p&gt;Check out &lt;a href=&#34;http://blogs.msdn.com/markgabarra/archive/2008/09/24/give-a-product-an-extensibility-point-feed-a-community.aspx&#34;&gt;Mark Gabarra&amp;rsquo;s (part of the MSFT ILM Product Group) &amp;ldquo;awesome&amp;rdquo; comments&lt;/a&gt; on the whitepaper.&lt;/p&gt;&#xA;&lt;p&gt;I especially want to thank some of the folks from Microsoft who were so helpful in figuring out some of these pieces and for their general support. Steve Klem, Mark Gabarra, Andreas Kjellman, Markus Vilcinskas, Jeff Staiman, Larry Buerk and Ahmad Abdel-wahed.&lt;/p&gt;</description>
    </item>
    <item>
      <title>a sprinkling of understanding Workflow in ILM 2</title>
      <link>https://identitymanaged.com/2008/09/sprinkling-of-understanding-workflow-in.html</link>
      <pubDate>Tue, 16 Sep 2008 17:48:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/sprinkling-of-understanding-workflow-in.html</guid>
      <description>&lt;p&gt;So by now all of you know that understanding Windows Workflow Foundation is going to be quite helpful in implementing ILM 2.&lt;/p&gt;&#xA;&lt;p&gt;Having lived 9 of the last 12 months in Redmond, WA, I now understand a lot more about sprinkling&lt;/p&gt;&#xA;&lt;p&gt;So I thought I would provide a sprinkling of understanding about Windows Workflow Foundation: a categorization of the built in workflows.&lt;/p&gt;&#xA;&lt;table&gt;&#xA;  &lt;thead&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;th&gt;Cateory&lt;/th&gt;&#xA;          &lt;th&gt;Activity&lt;/th&gt;&#xA;          &lt;th&gt;Composite&lt;/th&gt;&#xA;          &lt;th&gt;Notes&lt;/th&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/thead&gt;&#xA;  &lt;tbody&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Conditional&lt;/td&gt;&#xA;          &lt;td&gt;Invoke Web Service&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Conditional&lt;/td&gt;&#xA;          &lt;td&gt;Conditional Activity Group&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Conditional&lt;/td&gt;&#xA;          &lt;td&gt;IfElse&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Conditional&lt;/td&gt;&#xA;          &lt;td&gt;Policy&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;Akin to a switch statement or Select Case&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Conditional&lt;/td&gt;&#xA;          &lt;td&gt;While&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Custom&lt;/td&gt;&#xA;          &lt;td&gt;Code&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Error&lt;/td&gt;&#xA;          &lt;td&gt;Compensate&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Error&lt;/td&gt;&#xA;          &lt;td&gt;Fault Handler&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Error&lt;/td&gt;&#xA;          &lt;td&gt;Throw&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;Delay&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;EventDriven&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;Listen&lt;/td&gt;&#xA;          &lt;td&gt;X&lt;/td&gt;&#xA;          &lt;td&gt;2+ event driven&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;Parallel&lt;/td&gt;&#xA;          &lt;td&gt;x&lt;/td&gt;&#xA;          &lt;td&gt;2+ sequence for each&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;State&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;Sequence&lt;/td&gt;&#xA;          &lt;td&gt;X&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;SetState&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;StateInitialization&lt;/td&gt;&#xA;          &lt;td&gt;X&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;Suspend&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;Terminate&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;      &lt;tr&gt;&#xA;          &lt;td&gt;Flow&lt;/td&gt;&#xA;          &lt;td&gt;Transaction Scope&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;          &lt;td&gt;&lt;/td&gt;&#xA;      &lt;/tr&gt;&#xA;  &lt;/tbody&gt;&#xA;&lt;/table&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>a sprinkling of understanding Workflow in ILM 2 -- Comment</title>
      <link>https://identitymanaged.com/2008/09/sprinkling-of-understanding-workflow-in-Comment.html</link>
      <pubDate>Tue, 16 Sep 2008 17:48:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/sprinkling-of-understanding-workflow-in-Comment.html</guid>
      <description>&lt;h4 id=&#34;very-nice-david-i-would-also-urge-readers-to-chec&#34;&gt;Very nice David, I would also urge readers to chec&amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13950085747222995199&#34;&gt;Brad Turner&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 3, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Very nice David, I would also urge readers to check out Mark Gabarra&amp;rsquo;s blog for information relating WF and ILM 2. I also hope that we&amp;rsquo;ll be able to goad our own Paul Divan into bringing his experiences to the blogosphere!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>ILM 2 Beta 3 Bug: Action Process Function Evaluator Activity doesn&#39;t work when using only one field</title>
      <link>https://identitymanaged.com/2008/09/ilm-2-beta-3-bug-action-process-comments.html</link>
      <pubDate>Fri, 12 Sep 2008 02:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/ilm-2-beta-3-bug-action-process-comments.html</guid>
      <description>&lt;h4 id=&#34;yeah-so-this-one-frustrated-me-for-awhile-and-if-&#34;&gt;Yeah, so this one frustrated me for awhile and if &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13950085747222995199&#34; title=&#34;noreply@blogger.com&#34;&gt;Brad Turner&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 3, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Yeah, so this one frustrated me for awhile and if you hadn&amp;rsquo;t discovered this I would have lost even more time!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>ILM 2 Beta 3 Bug: Action Process Function Evaluator Activity doesn&#39;t work when using only one field</title>
      <link>https://identitymanaged.com/2008/09/ilm-2-beta-3-bug-action-process.html</link>
      <pubDate>Fri, 12 Sep 2008 02:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/ilm-2-beta-3-bug-action-process.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://connect.microsoft.com/feedback/ViewFeedback.aspx?FeedbackID=367381&amp;amp;SiteID=433&#34;&gt;ID: 367381&lt;/a&gt;&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;Description&lt;/p&gt;&#xA;&lt;p&gt;Action Process Function Evaluator Activity doesn&amp;rsquo;t work when using only one field, but when I concatenate with 2 it works.&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Repro Steps&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;Create an action Process&lt;br&gt;&#xA;Add one activity &amp;ndash; Function Evaluator&lt;br&gt;&#xA;Set a destination to an attribute (like DisplayName) and select only one field in the value &amp;ndash; LastName&lt;br&gt;&#xA;Then build an MPR to apply to All People (don&amp;rsquo;t check Grants Permission), Operations: Create and Modify&lt;br&gt;&#xA;Requestors: All People&lt;br&gt;&#xA;All Attributes&lt;br&gt;&#xA;Condition Before All People&lt;br&gt;&#xA;Condition After All People&lt;br&gt;&#xA;Policy Workflows: Add your Action Process&lt;br&gt;&#xA;Then create or modify a user&lt;br&gt;&#xA;open the user again and note that it did not work&lt;br&gt;&#xA;Then look at search requests, view the request and note the following error: Data at the root level is invalid. Line 1, position 1.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Expanding a Windows Server 2008 System partition on a HyperV Guest</title>
      <link>https://identitymanaged.com/2008/09/expanding-windows-server-2008-system-comments.html</link>
      <pubDate>Tue, 02 Sep 2008 19:47:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/expanding-windows-server-2008-system-comments.html</guid>
      <description>&lt;h4 id=&#34;yeah-wow-not-a-quick-and-easy-process-by-any-means&#34;&gt;Yeah, WOW, not a quick and easy process by any means!&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13950085747222995199&#34; title=&#34;noreply@blogger.com&#34;&gt;Brad Turner&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 3, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;Yeah, WOW, not a quick and easy process by any means!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;&#xA;&lt;p&gt;Good Info - Important Note: If you are dealing with a vm guest attached to a Hyper-V Cluster, You&amp;rsquo;ll need to use Failover Cluster Manager in Administration Tools on one of the Cluster Nodes - After making the change, go to a Command Prompt and enter the following:&lt;br&gt;&#xA;diskpart&lt;br&gt;&#xA;DISKPART&amp;gt; list&lt;br&gt;&#xA;DISKPART&amp;gt; list volume&lt;br&gt;&#xA;DISKPART&amp;gt; select volume #&lt;br&gt;&#xA;DISKPART&amp;gt; extend&lt;br&gt;&#xA;DISKPART&amp;gt; extend filesystem&lt;br&gt;&#xA;You&amp;rsquo;ll need to run extend filesystem on ant 2008+ server regardless if it is in a Cluster or not&amp;hellip;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Expanding a Windows Server 2008 System partition on a HyperV Guest</title>
      <link>https://identitymanaged.com/2008/09/expanding-windows-server-2008-system.html</link>
      <pubDate>Tue, 02 Sep 2008 19:47:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/expanding-windows-server-2008-system.html</guid>
      <description>&lt;p&gt;While building out some virtual machines for our ILM 2 Beta 3 environment&amp;hellip;&lt;/p&gt;&#xA;&lt;p&gt;We setup a few virtual machines 64 bit Windows Server 2008 SP 1 (since SP 1 is built in to the RTM) running on HyperV. Everything is very slick! Except we only set aside 16 GB for the virtual disk for the system partition. Despite installing SQL, SharePoint, and ILM 2 to another drive the system partition quickly filled up, and didn&amp;rsquo;t have enough room for Visual Studio (even though I wanted to install it on another partition). All of these programs install a lot of stuff on the system partition no matter what I select. While moving the paging file freed up some space it wasn&amp;rsquo;t enough.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Experts Conference (TEC) -- the conference formerly known as DEC (Directory Experts Conference)</title>
      <link>https://identitymanaged.com/2008/09/experts-conference-tec-conference-comments.html</link>
      <pubDate>Tue, 02 Sep 2008 18:16:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/experts-conference-tec-conference-comments.html</guid>
      <description>&lt;h4 id=&#34;i-am-really-looking-forward-to-this-next-year-and-&#34;&gt;I am really looking forward to this next year and &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/13950085747222995199&#34; title=&#34;noreply@blogger.com&#34;&gt;Brad Turner&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Sep 3, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;I am really looking forward to this next year and can&amp;rsquo;t wait to showcase what we&amp;rsquo;ve unearthed as part of our TAP/RDP experience with ILM 2!&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>The Experts Conference (TEC) -- the conference formerly known as DEC (Directory Experts Conference)</title>
      <link>https://identitymanaged.com/2008/09/experts-conference-tec-conference.html</link>
      <pubDate>Tue, 02 Sep 2008 18:16:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/09/experts-conference-tec-conference.html</guid>
      <description>&lt;p&gt;Well the results are in! A good number of Ensynchians have been selected to speak at &lt;a href=&#34;http://www.tec2009.com/&#34;&gt;The Experts Conference&lt;/a&gt; March 22-25, 2009 just outside of Las Vegas, NV. This will be my third time speaking at this event. They renamed it TEC because Gil Kirkpatrick and Company at Netpro have expanded the event to include a conference on Exchange Server. All three of these sessions were highlighted in the &lt;a href=&#34;http://www.tec2009.com/vegas/general_info/news/pr_announcement.php&#34;&gt;press release&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Topic&lt;/strong&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>How to be a pro at Google</title>
      <link>https://identitymanaged.com/2008/08/how-to-be-pro-at-google.html</link>
      <pubDate>Thu, 28 Aug 2008 15:07:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/08/how-to-be-pro-at-google.html</guid>
      <description>&lt;p&gt;My friend and coworker, &lt;a href=&#34;http://www.identitychaos.com/&#34;&gt;Brad Turner&lt;/a&gt;, once joked that if asked what search engine he used he would say &amp;ldquo;David Lundell&amp;rdquo;. While I do have a way of phrasing my searches just so, I thought I would point everyone to some great lessons on how to be better at google. I learned about these from a former business associate, Gary Thede, now the President of Boost eLearning.&lt;/p&gt;&#xA;&lt;p&gt;Check out the following 3 free lessons from &lt;a href=&#34;http://www.boostelearning.com/&#34;&gt;Boost eLearning&lt;/a&gt; on how to be a pro at googling!&lt;/p&gt;</description>
    </item>
    <item>
      <title>MIIS/ILM Error: System.BadImageFormatException</title>
      <link>https://identitymanaged.com/2008/08/miisilm-error-systembadimageformatexcep.html</link>
      <pubDate>Wed, 20 Aug 2008 17:08:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/08/miisilm-error-systembadimageformatexcep.html</guid>
      <description>&lt;p&gt;So I had MIIS 2003 SP 1 reporting to me that the format of my GalSync-Extension.dll is invalid. So I tried recompiling it &amp;ndash; no luck. Same error. The only &lt;a href=&#34;http://msdn.microsoft.com/en-us/library/k7137bfe(VS.80).aspx&#34;&gt;MSDN article&lt;/a&gt; on this indicated that unmanaged code is being passed to the load method.&lt;/p&gt;&#xA;&lt;p&gt;Through trial and error we found the solution: stop and start the MicrosoftIdentityIntegrationService. If that doesn&amp;rsquo;t work try a reboot.&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/WeirdMIISILMerroranditsresolution_AAE7/BadImageFormatException_screenshot.png&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/WeirdMIISILMerroranditsresolution_AAE7/BadImageFormatException_screenshot_thumb.png&#34; alt=&#34;BadImageFormatException_screenshot&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>I just got pranked by Laura Hunter</title>
      <link>https://identitymanaged.com/2008/08/i-just-got-pranked-by-laura-hunter.html</link>
      <pubDate>Sun, 17 Aug 2008 19:45:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/08/i-just-got-pranked-by-laura-hunter.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.shutuplaura.com/journal/2008/8/16/if-you-get-the-joke-you-will-be-joining-me-in-laughing-until.html&#34;&gt;Laura Hunter&lt;/a&gt; is perpetuating a prank that according to &lt;a href=&#34;http://en.wikipedia.org/wiki/Rickroll&#34;&gt;Wikipedia&lt;/a&gt; has reached such mainstream acceptance that Youtube pranked all of its visitors on April 1st of this year.&lt;/p&gt;&#xA;&lt;p&gt;Only Laura has pulled off this prank with such utter geekiness!&lt;/p&gt;&#xA;&lt;p&gt;You&amp;rsquo;ll probably need help to solve this one. Try this &lt;a href=&#34;http://morsecode.scphillips.com/jtranslator.html&#34;&gt;link&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Good one Laura!&lt;/p&gt;&#xA;&lt;p&gt;No spoilers just some hints and links that may spoil it!&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL 2008: Processor or Server/CAL</title>
      <link>https://identitymanaged.com/2008/08/sql-2008-processor-or-servercal.html</link>
      <pubDate>Sat, 16 Aug 2008 12:57:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/08/sql-2008-processor-or-servercal.html</guid>
      <description>&lt;p&gt;Congrats to the SQL Server team for shipping 2008. It looks like a great product. Congrats as well for keeping the licensing costs the same and adding a new option with the web edition.&lt;/p&gt;&#xA;&lt;p&gt;One question that many still have in mind is how to license SQL server. Processor licensing allows unlimited users and devices, whereas a server license allows unlimited users or devices as long as they have a CAL. Server CAL can be much cheaper than Processor license or it can become much more expensive.&lt;/p&gt;</description>
    </item>
    <item>
      <title>IDM in pop culture</title>
      <link>https://identitymanaged.com/2008/08/idm-in-pop-culture.html</link>
      <pubDate>Sat, 16 Aug 2008 11:30:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/08/idm-in-pop-culture.html</guid>
      <description>&lt;p&gt;Some days I am amazed at how deeply the identity management concepts have penetrated into popular culture:&lt;/p&gt;&#xA;&lt;p&gt;&amp;ldquo;Mr Big Stuff, who do you think you are?&amp;rdquo; clearly relates to an authentication issue or authorization issue.&lt;/p&gt;&#xA;&lt;p&gt;&amp;ldquo;Won&amp;rsquo;t get fooled again&amp;rdquo; by the WHO is clearly making a reference to a Certificate Revocation List, now that I have revoked your certificate you won&amp;rsquo;t be authenticated again.&lt;/p&gt;&#xA;&lt;p&gt;One area where pop culture is still shockingly uninformed still need help is in asset protection. I guess the authors of many forlorn love songs wish they could have used Rights Management Service and issued a use license that did not contain the permission to &amp;ldquo;Steal my heart&amp;rdquo; and &amp;ldquo;Break my heart.&amp;rdquo;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Love One Note -- hate KB&#39;s with unintended consequences</title>
      <link>https://identitymanaged.com/2008/08/love-one-note-hate-office-diagnostics-comments.html</link>
      <pubDate>Sat, 16 Aug 2008 09:44:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/08/love-one-note-hate-office-diagnostics-comments.html</guid>
      <description>&lt;h4 id=&#34;i-posted-this-on-a-newsgroup-and-a-powerpoint-mvp-&#34;&gt;I posted this on a newsgroup and a Powerpoint MVP &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/17202883653808140101&#34; title=&#34;noreply@blogger.com&#34;&gt;David Lundell&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;Aug 6, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;I posted this on a newsgroup and a Powerpoint MVP saved the day. Apparently, Powerpoint relies on the default printer driver to render the text. Since the KB article directed me to make the One Note Printer I created by hand the default print driver I wound up with scrunched text. Once I have his permission I will thank him by name&lt;/p&gt;</description>
    </item>
    <item>
      <title>Love One Note -- hate KB&#39;s with unintended consequences</title>
      <link>https://identitymanaged.com/2008/08/love-one-note-hate-office-diagnostics.html</link>
      <pubDate>Sat, 16 Aug 2008 09:44:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/08/love-one-note-hate-office-diagnostics.html</guid>
      <description>&lt;p&gt;I love One Note. Especially on a tablet PC. I can take notes either by typing or writing on the screen, I can sign contracts it is great.&lt;/p&gt;&#xA;&lt;p&gt;We recently purchased a home. My real estate agent would send me documents, I would print to One Note and then sign them, print to PDF using Primo PDF and send them back.&lt;/p&gt;&#xA;&lt;p&gt;It was great until Print to One Note stopped working. The Send to One Note 2007 printer was gone. My old Send to One note 2003 (BC) was still there but of course could not work. So I followed a KB article and created the printer by hand, and could not get it to work.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Pending Exports Report in ILM</title>
      <link>https://identitymanaged.com/2008/07/pending-exports-report-in-ilm.html</link>
      <pubDate>Wed, 30 Jul 2008 14:52:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/07/pending-exports-report-in-ilm.html</guid>
      <description>&lt;p&gt;Hopefully this topic will stir up some excitement among those wondering how to query objects in the connector space. The technique I am about to explicate for you works for both exports and imports.&lt;/p&gt;&#xA;&lt;p&gt;As many of you aware, my colleague and fellow ILM MVP Brad Turner created the community reporting pack for MIIS/ILM some time ago. This is a package of reports written in SQL Server Reporting Services (SSRS).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Scripting / SysAdmin Survey</title>
      <link>https://identitymanaged.com/2008/07/scripting-sysadmin-survey.html</link>
      <pubDate>Thu, 10 Jul 2008 10:15:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/07/scripting-sysadmin-survey.html</guid>
      <description>&lt;p&gt;In repsonse to the &lt;a href=&#34;http://www.shutuplaura.com/journal/2008/6/21/scripting-sysadmin-meme.html&#34;&gt;&amp;ldquo;tagging&amp;rdquo; of my friend Laura Hunter&lt;/a&gt; I now respond with the answers to these deep mysteries. But first &amp;ldquo;tagging&amp;rdquo;? Is this equivalent to the gang tagging? I hope not!&lt;/p&gt;&#xA;&lt;p&gt;**How old were you when you started using computers?&lt;br&gt;&#xA;**I was 4 or 5 when &amp;hellip;&lt;br&gt;&#xA;&lt;strong&gt;What was your first machine?&lt;/strong&gt;&lt;br&gt;&#xA;My Dad brought home an Atari 800 computer &amp;ndash; not the game console all though we did have games they just weren&amp;rsquo;t as cool as the ones on the game console.&lt;br&gt;&#xA;&lt;strong&gt;What was the first real script you wrote?&lt;/strong&gt;&lt;br&gt;&#xA;For me the breakthrough came when I was 7 or 8 and I was puzzling through a the Atari 800 book on BASIC and I was able to accept the abtract concept of a variable! Years later in 7th grade when I was introduced to algebra I realized that I had already done the hard part &amp;ndash; wrap my brain around this concept of a variable!&lt;/p&gt;</description>
    </item>
    <item>
      <title>I like my passwords Plain --in plaintext that is</title>
      <link>https://identitymanaged.com/2008/07/i-like-my-passwords-plain-in-plaintext.html</link>
      <pubDate>Thu, 03 Jul 2008 16:32:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/07/i-like-my-passwords-plain-in-plaintext.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/PlainPasswords_small-736260.jpg&#34;&gt;&lt;img src=&#34;http://www.ilmbestpractices.com/blog/uploaded_images/PlainPasswords_small-736256.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;Bug in ILM2 Beta 3 &amp;ndash; go vote on MSConnect to register your taste!&lt;/p&gt;&#xA;&lt;p&gt;Look for Bug ID 354953&lt;/p&gt;&#xA;&lt;p&gt;&lt;strong&gt;Do you like your passwords plain or with encrypted butter?&lt;/strong&gt;&lt;/p&gt;&#xA;&lt;p&gt;As for me and my house we will choose the encrypted butter! I mean passwords.&lt;/p&gt;&#xA;&lt;p&gt;ILM 2 codeless provisioning looks great! You can add complex rules without code and then you can even see these rules as they get synchronized into the ILM synch engine (what we know and love from the MIIS 2003 and ILM 2007 days). But then oops! you can see my default password in plaintext!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tech Ed -- Lotsa Buzz ILM 2 and CLM</title>
      <link>https://identitymanaged.com/2008/06/tech-ed-lotsa-buzz-ilm-2-and-clm.html</link>
      <pubDate>Mon, 16 Jun 2008 16:33:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/06/tech-ed-lotsa-buzz-ilm-2-and-clm.html</guid>
      <description>&lt;p&gt;On Tuesday &lt;a href=&#34;http://www.microsoft.com/presspass/exec/bobmuglia/default.mspx&#34;&gt;Bob Muglia&lt;/a&gt; made a big announcement &amp;ndash; ILM 2 Beta 3 has been released. While the beta install is only 64 bit on Microsoft Connect you can download the 32-bit Virtual PC. At the ILM 2 booth at Tech Ed the Microsoft ILM Product Group and I were handing them out like crazy.&lt;/p&gt;&#xA;&lt;p&gt;Thanks to Nima for inviting me to participate at the booth.&lt;/p&gt;&#xA;&lt;p&gt;Best session I went was by Candy Stark from MS IT. She presented on the smart card deployment at MSFT using CLM.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Tech Ed Anyone?</title>
      <link>https://identitymanaged.com/2008/06/tech-ed-anyone.html</link>
      <pubDate>Sun, 01 Jun 2008 21:58:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/06/tech-ed-anyone.html</guid>
      <description>&lt;p&gt;&lt;a href=&#34;http://www.microsoft.com/events/teched2008/images/pro_track/buttons/TechEd_MeetMeThere_IT_180x200.jpg&#34;&gt;&lt;img src=&#34;http://www.microsoft.com/events/teched2008/images/pro_track/buttons/TechEd_MeetMeThere_IT_180x200.jpg&#34; alt=&#34;&#34;&gt;&lt;/a&gt;&lt;/p&gt;&#xA;&lt;p&gt;I will be attending Tech-Ed IT-Pro in a little over a week. My employer Ensynch has a booth. I will also be spending some time at the Microsoft ILM Product Group&amp;rsquo;s booth.&lt;/p&gt;&#xA;&lt;p&gt;Looking forward to seeing a bunch of folks out there and helping to demonstrate ILM 2 Beta 3! (Once it is released;)&lt;/p&gt;&#xA;&lt;p&gt;&lt;a href=&#34;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&#34;&gt;http://feeds.feedburner.com/IdentityLifecycleManagerilmBestPractices&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Processing Actions Asynchronously outside of ILM MA&#39;s</title>
      <link>https://identitymanaged.com/2008/05/processing-actions-asynchronously.html</link>
      <pubDate>Thu, 15 May 2008 06:25:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/05/processing-actions-asynchronously.html</guid>
      <description>&lt;p&gt;For years developers have had access to the Microsoft Message Queue (MSMQ) as a way to be able to queue up actions for processing later or on a remote machine. With the release of SQL 2005 back in well 2005, developers with access to SQL 2005 could replace these MSMQ apps with SQL Service Broker Queues (SSB). With ILM 2007 /MIIS 2003 SP 2 supporting SQL 2005 the use of SQL Service Broker Queues became much more accessible to ILM Developers.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SQL Business Intelligence</title>
      <link>https://identitymanaged.com/2008/05/sql-business-intelligence.html</link>
      <pubDate>Wed, 14 May 2008 17:37:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/05/sql-business-intelligence.html</guid>
      <description>&lt;p&gt;This evening I attended a nice SQL 2005 BI presentation by Kathrine Lord of Microsoft.&lt;br&gt;&#xA;She took the &lt;a href=&#34;http://www.azsqlserver.com/index.html&#34;&gt;Arizona SQL Server Users Group&lt;/a&gt; through a nice tour of a datawarehouse that she built for a call center. (Thanks to Pete Miller of Statera for all these years of running and organizing the AZ SQL Server User&amp;rsquo;s group).&lt;/p&gt;&#xA;&lt;p&gt;Her presentation was a quick end to end walkthrough: building cubes, MDX calculations, creation of named sets, Key Performance Indicators (KPI&amp;rsquo;s) and using the Pivot Tables inside of Excel 2007.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Identity Chaos? Get your Identities Ensynch!</title>
      <link>https://identitymanaged.com/2008/05/identity-chaos-get-your-identities-comments.html</link>
      <pubDate>Wed, 14 May 2008 10:55:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/05/identity-chaos-get-your-identities-comments.html</guid>
      <description>&lt;h4 id=&#34;if-i-post-a-comment-on-my-own-blog-does-that-mean-&#34;&gt;If I post a comment on my own blog does that mean &amp;hellip;&lt;/h4&gt;&#xA;&lt;p&gt;&lt;a href=&#34;https://www.blogger.com/profile/17202883653808140101&#34; title=&#34;noreply@blogger.com&#34;&gt;David Lundell&lt;/a&gt; - &lt;!-- raw HTML omitted --&gt;May 3, 2008&lt;!-- raw HTML omitted --&gt;&lt;/p&gt;&#xA;&lt;p&gt;If I post a comment on my own blog does that mean I am having an Identity Crisis?&lt;/p&gt;&#xA;&lt;!-- raw HTML omitted --&gt;</description>
    </item>
    <item>
      <title>Identity Chaos? Get your Identities Ensynch!</title>
      <link>https://identitymanaged.com/2008/05/identity-chaos-get-your-identities.html</link>
      <pubDate>Wed, 14 May 2008 10:55:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/05/identity-chaos-get-your-identities.html</guid>
      <description>&lt;p&gt;I recently joined the Identity Management Practice, as a Solution Architect, at &lt;a href=&#34;http://www.ensynch.com/&#34;&gt;Ensynch&lt;/a&gt; Inc, an &lt;a href=&#34;http://www.ensynch.com/PRItem.aspx?prID=70&amp;amp;year=2008&#34;&gt;award winning&lt;/a&gt; Microsoft Gold Partner based in Tempe, AZ, with a strong award winning presence in Southern California. In 2006 Ensynch won &lt;a href=&#34;http://www.ensynch.com/PRItem.aspx?prID=46&amp;amp;year=2006&#34;&gt;Microsoft Worldwide Partner Award for Excellence in Active Directory and Identity Management&lt;/a&gt; and in 2007 was the only finalist from North America. In fact the only finalist from the Western Hemisphere.&lt;/p&gt;&#xA;&lt;p&gt;I am especially happy to be working with &lt;a href=&#34;http://www.identitychaos.com/&#34;&gt;Brad Turner&lt;/a&gt;, fellow ILM MVP and a good friend. I am also excited to work with the creator of the Camel Logic Configurator &amp;ndash; &lt;a href=&#34;http://digitalcamel.blogspot.com/&#34;&gt;Jerry Camel&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>The Grand Unified Demo of Identity Management</title>
      <link>https://identitymanaged.com/2008/05/grand-unified-demo-of-identity.html</link>
      <pubDate>Wed, 07 May 2008 13:57:00 -0700</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/2008/05/grand-unified-demo-of-identity.html</guid>
      <description>&lt;p&gt;As I was architecting and assembling the Identity All Up workshop (part of the 2008 Directory Experts Conference see the &lt;a href=&#34;http://blogs.kuppingercole.com/gaehtgens/2008/03/03/netpro-dec-2008-sneak-preview-of-microsoft-ilm-2/&#34;&gt;review by Felix Gaehtgens, an analyst for Kuppinger Cole&lt;/a&gt;) designed to expose the attendees (or delegates) to all facets of the Microsoft Identity Access Platform, Lori Craw, from Microsoft referred to this as the &amp;ldquo;Grand Unified Demo&amp;rdquo;. I chuckled, instantly catching the reference to the still undiscovered Grand Unified Field theory that eluded Einstein and even today&amp;rsquo;s theoretical physicists.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Books</title>
      <link>https://identitymanaged.com/www.davidplundell.com/books</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/www.davidplundell.com/books</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://www.davidplundell.com/books&#34;&gt;Books&lt;/a&gt;&lt;/p&gt;</description>
    </item>
    <item>
      <title>Case Studies</title>
      <link>https://identitymanaged.com/about/case-studies/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/about/case-studies/</guid>
      <description>&lt;div class=&#34;container-fluid&#34; style=&#34;padding-bottom: 20px&#34;&gt;&#xA;  &lt;img&#xA;    class=&#34;img-responsive col-sm-5&#34;&#xA;    src=&#34;https://identitymanaged.com/img/retail.webp&#34;&#xA;    alt=&#34;User &amp;#43; Group Lifecycle Management&#34;&#xA;  /&gt;&#xA;  &lt;div class=&#34;col-sm-6&#34;&gt;&#xA;    &lt;h2&gt;User + Group Lifecycle Management&lt;/h2&gt;&#xA;    &lt;h4&gt;Retail (50k + Identities)&lt;/h4&gt;&#xA;    &lt;p&gt;We saved this retail company $10’s of millions in Office365 license fees, and effort to manage the users, by implementing MIM for Largest Region over 1M identities and 4 additional instances of MIM to manage 6 other regions, which enabled the client to assign different license levels based on job roles and reclaim licenses promptly.&lt;/p&gt;</description>
    </item>
    <item>
      <title>FAQ</title>
      <link>https://identitymanaged.com/faq/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/faq/</guid>
      <description>&lt;p&gt;- Identity Management (IDM) is a framework that encompasses the processes, technologies, and policies to manage the digital identities of individuals and entities within an organization.&lt;/p&gt;&#xA;&lt;p&gt;- The goal of IDM is to ensure secure, reliable, and efficient access to digital resources while protecting sensitive information.&lt;/p&gt;&#xA;&lt;p&gt;- Key concepts in IDM include identity provisioning, authentication, authorization, and access control.&lt;/p&gt;&#xA;&lt;p&gt;- Identity governance is an essential aspect of IDM, involving policies, workflows, and controls to manage and govern identities throughout their lifecycle.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Our Founder</title>
      <link>https://identitymanaged.com/about/founder/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/about/founder/</guid>
      <description>&lt;h3 id=&#34;david-lundell&#34;&gt;David Lundell&lt;/h3&gt;&#xA;&lt;p&gt;David got started in technology when his dad brought home first an Atari PC (not the video game console) and later an IBM PC. David picked up a book on programming in BASIC when he was 8. Every week when he was a teenager his dad dragged him into the office of his startup software company to vacuum, clean the bathrooms and haul out the trash. One day his dad handed him the manual for their network management software, sat him down at the computer and commanded, “Test the software!” That was just over 30 years ago.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Privacy Policy</title>
      <link>https://identitymanaged.com/privacy-policy/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>david@identitymanaged.com (David)</author>
      <guid>https://identitymanaged.com/privacy-policy/</guid>
      <description>&lt;h5 id=&#34;a-genuine-commitment-to-your-privacy&#34;&gt;A genuine commitment to your privacy&lt;/h5&gt;&#xA;&lt;p&gt;Identity Managed LLC (IDM) and our people are committed to protecting the privacy of our website vistors/users, customers and prospective customers.&lt;/p&gt;&#xA;&lt;p&gt;We do not sell, rent or otherwise disclose your personal data to any third party except where it is necessary to provide you with services you have requested, and only then for that purpose.&lt;/p&gt;&#xA;&lt;p&gt;We will protect your personal data against loss and unauthorized access using appropriate security measures.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
