<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~d/styles/atom10full.xsl"?><?xml-stylesheet type="text/css" media="screen" href="http://feeds.feedburner.com/~d/styles/itemcontent.css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearch/1.1/" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:feedburner="http://rssnamespace.org/feedburner/ext/1.0" gd:etag="W/&quot;DkICRX0-fSp7ImA9WxNbEEg.&quot;"><id>tag:blogger.com,1999:blog-24940037</id><updated>2009-11-12T12:36:04.355-07:00</updated><title>1dent1ty cHa0s</title><subtitle type="html">finding some semblance of balance amongst the chaos of identity and access management including the Microsoft Identity Integration Server 2003 (MIIS), Identity Lifecycle Manager 2007 (ILM), ILM 2, and Forefront Identity Manager 2010 (FIM).</subtitle><link rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml" href="http://www.identitychaos.com/feeds/posts/default" /><link rel="alternate" type="text/html" href="http://www.identitychaos.com/" /><link rel="hub" href="http://pubsubhubbub.appspot.com/" /><link rel="next" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default?start-index=26&amp;max-results=25&amp;redirect=false&amp;orderby=published&amp;v=2" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email></author><generator version="7.00" uri="http://www.blogger.com">Blogger</generator><openSearch:totalResults>185</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><link rel="license" type="text/html" href="http://creativecommons.org/licenses/by-sa/3.0/" /><logo>http://www.camelogic.com/idchaos/images/preventchaos.jpg</logo><link rel="self" href="http://feeds.feedburner.com/idchaos" type="application/atom+xml" /><feedburner:emailServiceId>idchaos</feedburner:emailServiceId><feedburner:feedburnerHostname>http://feedburner.google.com</feedburner:feedburnerHostname><feedburner:feedFlare href="http://add.my.yahoo.com/rss?url=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://us.i1.yimg.com/us.yimg.com/i/us/my/addtomyyahoo4.gif">Subscribe with My Yahoo!</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsgator.com/ngs/subscriber/subext.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://www.newsgator.com/images/ngsub1.gif">Subscribe with NewsGator</feedburner:feedFlare><feedburner:feedFlare href="http://feeds.my.aol.com/add.jsp?url=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://o.aolcdn.com/favorites.my.aol.com/webmaster/ffclient/webroot/locale/en-US/images/myAOLButtonSmall.gif">Subscribe with My AOL</feedburner:feedFlare><feedburner:feedFlare href="http://www.bloglines.com/sub/http://feeds.feedburner.com/idchaos" src="http://www.bloglines.com/images/sub_modern11.gif">Subscribe with Bloglines</feedburner:feedFlare><feedburner:feedFlare href="http://www.netvibes.com/subscribe.php?url=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://www.netvibes.com/img/add2netvibes.gif">Subscribe with Netvibes</feedburner:feedFlare><feedburner:feedFlare href="http://fusion.google.com/add?feedurl=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://buttons.googlesyndication.com/fusion/add.gif">Subscribe with Google</feedburner:feedFlare><feedburner:feedFlare href="http://www.pageflakes.com/subscribe.aspx?url=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://www.pageflakes.com/ImageFile.ashx?instanceId=Static_4&amp;fileName=ATP_blu_91x17.gif">Subscribe with Pageflakes</feedburner:feedFlare><feedburner:feedFlare href="http://my.feedlounge.com/external/subscribe?url=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://static.feedlounge.com/buttons/subscribe_0.gif">Subscribe with FeedLounge</feedburner:feedFlare><feedburner:feedFlare href="http://www.newsalloy.com/?rss=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://www.newsalloy.com/subrss3.gif">Subscribe with NewsAlloy</feedburner:feedFlare><feedburner:feedFlare href="http://www.live.com/?add=http%3A%2F%2Ffeeds.feedburner.com%2Fidchaos" src="http://tkfiles.storage.msn.com/x1piYkpqHC_35nIp1gLE68-wvzLZO8iXl_JMledmJQXP-XTBOLfmQv4zhj4MhcWEJh_GtoBIiAl1Mjh-ndp9k47If7hTaFno0mxW9_i3p_5qQw">Subscribe with Live.com</feedburner:feedFlare><atom10:link xmlns:atom10="http://www.w3.org/2005/Atom" rel="hub" href="http://pubsubhubbub.appspot.com" /><entry gd:etag="W/&quot;DkICRX0yfSp7ImA9WxNbEEg.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-6777286447956104730</id><published>2009-11-12T12:36:00.001-07:00</published><updated>2009-11-12T12:36:04.395-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-12T12:36:04.395-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM RC1" /><category scheme="http://www.blogger.com/atom/ns#" term="FIM Update 1" /><title>FIM 2010 RC1.1 – Adjusting the Request Object Retention Policy</title><content type="html">&lt;p&gt;Thanks to &lt;a href="http://www.idmcrisis.com/"&gt;Henrik Nilsson&lt;/a&gt; for this little gem – this is the first thing on your list of things to do after installing FIM 2010 in your &lt;em&gt;test&lt;/em&gt; environment. Follow these instructions to adjust how long &lt;em&gt;Request&lt;/em&gt; objects will be retained in the system.&lt;/p&gt;  &lt;h3&gt;System Resource Retention Configuration&lt;/h3&gt;  &lt;p&gt;This is a special resource type in the portal that allows you to adjust how long request objects linger in the portal. Nothing will clog up your database and fill your drives like millions of request objects sitting around for 30 days (the default). And make no mistake, you will end up with millions of objects in a few short days or weeks depending on the item count you're working with. You find your way here by navigating to &lt;strong&gt;Administration/All Resources/System Resource Retention Configuration&lt;/strong&gt;. Once there you'll see the object we're after:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM.1AdjustingtheRequestObjectRetentionP_AA76/image.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM.1AdjustingtheRequestObjectRetentionP_AA76/image_thumb.png" width="644" height="151" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;As you can see from my example, I've already adjusted this to two days from the default of thirty. What you will notice if you click on this object is that you are not allowed to change the value yet! We first have to create a policy that allows members of the Administrators set to modify the value we need.&lt;/p&gt;  &lt;h3&gt;Creating the Management Policy Rule&lt;/h3&gt;  &lt;p&gt;Ok, you're going to create a new &lt;em&gt;Management Policy Rule&lt;/em&gt; with the following specifications:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;&lt;strong&gt;Display Name&lt;/strong&gt;: Administration: Administrators can update system resource retention service objects&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Description&lt;/strong&gt;: Allows members of the Administrators set to adjust the policy for request object retention&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Permissions&lt;/strong&gt;: Grants Permission&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Requestors&lt;/strong&gt;: (Specific Set of Requestors) &lt;u&gt;Administrators&lt;/u&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Operation&lt;/strong&gt;: Modify a single-valued attribute&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Target Resource Definition Before/After Request&lt;/strong&gt; (same): &lt;u&gt;All System Resource Retention Configurations&lt;/u&gt;&lt;/li&gt;    &lt;li&gt;&lt;strong&gt;Resource Attributes&lt;/strong&gt;: (Select specific attributes) &lt;u&gt;Retention Period in Days&lt;/u&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Once you're done, go back and click on the configuration object, now you should be able to adjust the value:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM.1AdjustingtheRequestObjectRetentionP_AA76/image_3.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM.1AdjustingtheRequestObjectRetentionP_AA76/image_thumb_3.png" width="644" height="137" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;Once you submit the change, all new requests will have a 2-day expiration, whereas any previous requests will have the 30-day default. Observe:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM.1AdjustingtheRequestObjectRetentionP_AA76/image_4.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM.1AdjustingtheRequestObjectRetentionP_AA76/image_thumb_4.png" width="644" height="153" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;…versus:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM.1AdjustingtheRequestObjectRetentionP_AA76/image_5.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM.1AdjustingtheRequestObjectRetentionP_AA76/image_thumb_5.png" width="644" height="156" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Notice that even the request to update the policy is stamped with the new policy. I am on a quest to understand exactly how they expire and if there is anything you can do to speed along old requests. There are a few promising looking stored procedures, but those could be very dangerous to an active system.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-6777286447956104730?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aLwXLtHxjA8:xOqYNUfOyHc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aLwXLtHxjA8:xOqYNUfOyHc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aLwXLtHxjA8:xOqYNUfOyHc:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aLwXLtHxjA8:xOqYNUfOyHc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=aLwXLtHxjA8:xOqYNUfOyHc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aLwXLtHxjA8:xOqYNUfOyHc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=aLwXLtHxjA8:xOqYNUfOyHc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aLwXLtHxjA8:xOqYNUfOyHc:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aLwXLtHxjA8:xOqYNUfOyHc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aLwXLtHxjA8:xOqYNUfOyHc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=aLwXLtHxjA8:xOqYNUfOyHc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/aLwXLtHxjA8" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/11/fim-2010-rc11-adjusting-request-object.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/6777286447956104730?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/6777286447956104730?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/aLwXLtHxjA8/fim-2010-rc11-adjusting-request-object.html" title="FIM 2010 RC1.1 – Adjusting the Request Object Retention Policy" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/11/fim-2010-rc11-adjusting-request-object.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUMHQ3kzfip7ImA9WxNUGUQ.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-2772169343120450946</id><published>2009-11-11T14:58:00.002-07:00</published><updated>2009-11-11T19:37:12.786-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-11T19:37:12.786-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM RC1" /><category scheme="http://www.blogger.com/atom/ns#" term="FIM Update 1" /><category scheme="http://www.blogger.com/atom/ns#" term="FIM RCDC" /><title>FIM 2010 RC1.1 – Customizing the Request Object RCDC</title><content type="html">One of my frustrations is tracing down the target of a request and in some cases, the parent request that caused this request to be generated. The default RCDC doesn't expose these values except within the Advanced View/Extended Attributes tab. Having the Applied Policy tab is great to see what policies this request triggered, but being able to see the target and parent request is essential – so here's how to add it yourself. At the end we'll have two new controls:&lt;br /&gt;
&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010.1CustomizingtheRequestObjectRCDC_CB62/image.png"&gt;&lt;img alt="image" border="0" height="193" src="http://www.camelogic.com/idchaos/images/FIM2010.1CustomizingtheRequestObjectRCDC_CB62/image_thumb.png" style="border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline;" title="image" width="644" /&gt;&lt;/a&gt; &lt;br /&gt;
Here we see the Target revealed on the Detailed Content tab, we now know we had a Modify operation to a Person object type and the target was Smith, John; we can even click the hyperlink here and go look at the current status of John's object.&lt;br /&gt;
&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010.1CustomizingtheRequestObjectRCDC_CB62/image_3.png"&gt;&lt;img alt="image" border="0" height="295" src="http://www.camelogic.com/idchaos/images/FIM2010.1CustomizingtheRequestObjectRCDC_CB62/image_thumb_3.png" style="border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline;" title="image" width="644" /&gt;&lt;/a&gt; &lt;br /&gt;
Here we see on the Applied Policy tab we've added the link to the Parent Request, also hyperlinked. In this example a Workflow configured for "Run On Policy Update" triggered a series of System Event Requests which we can examine in more detail. &lt;br /&gt;
&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010.1CustomizingtheRequestObjectRCDC_CB62/image_4.png"&gt;&lt;img alt="image" border="0" height="289" src="http://www.camelogic.com/idchaos/images/FIM2010.1CustomizingtheRequestObjectRCDC_CB62/image_thumb_4.png" style="border-bottom-width: 0px; border-left-width: 0px; border-right-width: 0px; border-top-width: 0px; display: inline;" title="image" width="644" /&gt;&lt;/a&gt; &lt;br /&gt;
After clicking the link we see the policy that was updated which caused this sequence of events – nifty right?&lt;br /&gt;
This should all be by default right? &lt;a href="https://connect.microsoft.com/feedback/ViewFeedback.aspx?FeedbackID=508072&amp;amp;SiteID=433" target="_blank"&gt;Vote here&lt;/a&gt; if you're signed up for the FIM Connect site.&lt;br /&gt;
Ok, so how do you do this yourself – it's pretty easy. I would strongly recommend applying the &lt;a href="https://connect.microsoft.com/Downloads/DownloadDetails.aspx?SiteID=433&amp;amp;DownloadID=23207" target="_blank"&gt;Update 1 packages&lt;/a&gt; prior to doing this as any updates has the chance of overwriting any of your customizations. So, I'll show you how to add the sections manually and provide the entire file for your consumption as well. &lt;br /&gt;
&lt;h3&gt;Warning&lt;/h3&gt;When editing RCDC configurations, it's always recommended to Export the current configuration and save it as an Original copy. If you get into trouble you should restore the original version, edit a copy and use the copy to upload.&lt;br /&gt;
&lt;h3&gt;Adding the Target control to the Detailed Content tab&lt;/h3&gt;Insert the new &lt;em&gt;TargetID&lt;/em&gt; control between the &lt;em&gt;TargetObjectType&lt;/em&gt; and &lt;em&gt;SummaryControl&lt;/em&gt; controls like so:&lt;br /&gt;
&lt;div class="csharpcode-wrapper" id="codeSnippetWrapper"&gt;&lt;div class="csharpcode" id="codeSnippet"&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="TargetObjectType"&lt;/span&gt; &lt;span class="attr"&gt;my:TypeName&lt;/span&gt;&lt;span class="kwrd"&gt;="UocLabel"&lt;/span&gt; &lt;span class="attr"&gt;my:Caption&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=schema, Path=TargetObjectType.DisplayName}"&lt;/span&gt; &lt;span class="attr"&gt;my:RightsLevel&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=rights, Path=TargetObjectType}"&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="Text"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=object, Path=TargetObjectType, Mode=OneWay}"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&amp;nbsp;&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="TargetID"&lt;/span&gt; &lt;span class="attr"&gt;my:TypeName&lt;/span&gt;&lt;span class="kwrd"&gt;="UocHyperLink"&lt;/span&gt; &lt;span class="attr"&gt;my:Caption&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=schema, Path=Target.DisplayName}"&lt;/span&gt; &lt;span class="attr"&gt;my:Description&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=schema, Path=Target.Description}"&lt;/span&gt; &lt;span class="attr"&gt;my:RightsLevel&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=rights, Path=Target}"&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ObjectReference"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=object, Path=Target, Mode=OneWay}"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&amp;nbsp;&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="SummaryControl"&lt;/span&gt; &lt;span class="attr"&gt;my:TypeName&lt;/span&gt;&lt;span class="kwrd"&gt;="UocHtmlSummary"&lt;/span&gt; &lt;span class="attr"&gt;my:Caption&lt;/span&gt;&lt;span class="kwrd"&gt;="%SYMBOL_RequestContentCaption_END%"&lt;/span&gt; &lt;span class="attr"&gt;my:Description&lt;/span&gt;&lt;span class="kwrd"&gt;="%SYMBOL_RequestContentDescription_END%"&lt;/span&gt; &lt;span class="attr"&gt;my:ExpandArea&lt;/span&gt;&lt;span class="kwrd"&gt;="true"&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ModificationsXml"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=requestDetails, Path=DeltaXml , Mode=OneWay}"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="TransformXsl"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=RequestDetailTransformXsl, Path=/, Mode=OneWay}"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;
&lt;h3&gt;Adding the Parent Request control to the Applied Content tab&lt;/h3&gt;Insert the new &lt;em&gt;ParentRequestObj&lt;/em&gt; control between the &lt;em&gt;Policy&lt;/em&gt; grouping and the &lt;em&gt;PolicyList&lt;/em&gt; control like so:&lt;br /&gt;
&lt;div class="csharpcode-wrapper" id="codeSnippetWrapper"&gt;&lt;div class="csharpcode" id="codeSnippet"&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Grouping&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="Policy"&lt;/span&gt; &lt;span class="attr"&gt;my:Caption&lt;/span&gt;&lt;span class="kwrd"&gt;="%SYMBOL_PolicyTabCaption_END%"&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Help&lt;/span&gt; &lt;span class="attr"&gt;my:HelpText&lt;/span&gt;&lt;span class="kwrd"&gt;="%SYMBOL_PolicyTabHelpText_END%"&lt;/span&gt; &lt;span class="attr"&gt;my:Link&lt;/span&gt;&lt;span class="kwrd"&gt;="cb9dbf88-0045-4e1e-ae3a-a2449ea7095a.htm#bkmk_grouping_Policy"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;&lt;/pre&gt;&lt;br /&gt;
&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ParentRequestObj"&lt;/span&gt; &lt;span class="attr"&gt;my:TypeName&lt;/span&gt;&lt;span class="kwrd"&gt;="UocHyperLink"&lt;/span&gt; &lt;span class="attr"&gt;my:Caption&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=schema, Path=ParentRequest.DisplayName}"&lt;/span&gt; &lt;span class="attr"&gt;my:Description&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=schema, Path=ParentRequest.Description}"&lt;/span&gt; &lt;span class="attr"&gt;my:RightsLevel&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=rights, Path=ParentRequest}"&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ObjectReference"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=object, Path=ParentRequest, Mode=OneWay}"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;br /&gt;
&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="PolicyList"&lt;/span&gt; &lt;span class="attr"&gt;my:TypeName&lt;/span&gt;&lt;span class="kwrd"&gt;="UocListView"&lt;/span&gt; &lt;span class="attr"&gt;my:Caption&lt;/span&gt;&lt;span class="kwrd"&gt;="%SYMBOL_PolicyListCaption_END%"&lt;/span&gt; &lt;span class="attr"&gt;my:Description&lt;/span&gt;&lt;span class="kwrd"&gt;="%SYMBOL_PolicyListHint_END%"&lt;/span&gt; &lt;span class="attr"&gt;my:ExpandArea&lt;/span&gt;&lt;span class="kwrd"&gt;="true"&lt;/span&gt; &lt;span class="attr"&gt;my:RightsLevel&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=rights, Path=ManagementPolicy}"&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ColumnsToDisplay"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="DisplayName,GrantRight,AuthenticationWorkflowDefinition,AuthorizationWorkflowDefinition,ActionWorkflowDefinition"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="UsageKeywords"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="ManagementPolicyRule"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ResultObjectType"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="ManagementPolicyRule"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="TargetAttribute"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="ManagementPolicy"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="SelectedValue"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="{Binding Source=object, Path=ManagementPolicy, Mode=OneWay}"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="EmptyResultText"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;=""&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="PageSize"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="10"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ShowActionBar"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="false"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ShowPreview"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="false"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ShowSearchControl"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="false"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ShowTitleBar"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="true"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="EnableSelection"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="false"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="SingleSelection"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="false"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ItemClickBehavior"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="ModelessDialog"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ReadOnly"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="true"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;&lt;/span&gt;&lt;span class="html"&gt;my:Property&lt;/span&gt; &lt;span class="attr"&gt;my:Name&lt;/span&gt;&lt;span class="kwrd"&gt;="ListViewItemHandler"&lt;/span&gt; &lt;span class="attr"&gt;my:Value&lt;/span&gt;&lt;span class="kwrd"&gt;="PolicyItemHandler"&lt;/span&gt;&lt;span class="kwrd"&gt;/&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Properties&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Control&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;&amp;lt;/&lt;/span&gt;&lt;span class="html"&gt;my:Grouping&lt;/span&gt;&lt;span class="kwrd"&gt;&amp;gt;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;h3&gt;Build 2570 (Update 1) Files&lt;/h3&gt;&lt;ul&gt;&lt;li&gt;&lt;a href="http://www.camelogic.com/idchaos/RCDC/Request/Original-Build2570-Request.xml" target="_blank"&gt;Original-Build2570-Request.xml&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.camelogic.com/idchaos/RCDC/Request/Modified-Build2570-Request.xml" target="_blank"&gt;Modified-Build2570-Request.xml&lt;/a&gt;&lt;br /&gt;
&lt;/li&gt;
&lt;/ul&gt;Remember to &lt;em&gt;iisreset&lt;/em&gt; if you can't wait for the cache to refresh.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-2772169343120450946?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=1tJOquqgro0:smufBPdp0Us:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=1tJOquqgro0:smufBPdp0Us:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=1tJOquqgro0:smufBPdp0Us:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=1tJOquqgro0:smufBPdp0Us:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=1tJOquqgro0:smufBPdp0Us:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=1tJOquqgro0:smufBPdp0Us:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=1tJOquqgro0:smufBPdp0Us:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=1tJOquqgro0:smufBPdp0Us:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=1tJOquqgro0:smufBPdp0Us:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=1tJOquqgro0:smufBPdp0Us:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=1tJOquqgro0:smufBPdp0Us:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/1tJOquqgro0" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/11/fim-2010-rc11-customizing-request.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/2772169343120450946?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/2772169343120450946?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/1tJOquqgro0/fim-2010-rc11-customizing-request.html" title="FIM 2010 RC1.1 – Customizing the Request Object RCDC" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/11/fim-2010-rc11-customizing-request.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEAHRn8zeSp7ImA9WxNUEk0.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-1442851428909810101</id><published>2009-11-02T17:05:00.001-07:00</published><updated>2009-11-02T17:05:37.181-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-02T17:05:37.181-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM RC1" /><category scheme="http://www.blogger.com/atom/ns#" term="FIM RCDC" /><title>FIM 2010 RC1 – Resolving the Duplicate SynchronizationRule RCDC</title><content type="html">&lt;p&gt;In the FIM release notes it advises you to adjust the &amp;quot;Applies to Create&amp;quot; setting for one of two Resource Control Display Configuration (aka OVC) objects that share the same Display Name; however, it doesn't tell you how to determine which one to change. You need to do this IF you are exporting and importing your configuration between systems (the source of yet another topic).&lt;/p&gt;  &lt;p&gt;RC1 looks like this by default:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1ResolvingtheDuplicateSynchroni_EF52/clip_image001.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image001" border="0" alt="clip_image001" src="http://www.camelogic.com/idchaos/images/FIM2010RC1ResolvingtheDuplicateSynchroni_EF52/clip_image001_thumb.png" width="644" height="120" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;We need it to look like this:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1ResolvingtheDuplicateSynchroni_EF52/clip_image002.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image002" border="0" alt="clip_image002" src="http://www.camelogic.com/idchaos/images/FIM2010RC1ResolvingtheDuplicateSynchroni_EF52/clip_image002_thumb.png" width="644" height="124" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;…but how do you know which one to change? Both are set to apply to &lt;em&gt;Create&lt;/em&gt;, &lt;em&gt;Edit&lt;/em&gt; and &lt;em&gt;View&lt;/em&gt;, but only one should be &lt;em&gt;Create&lt;/em&gt; while the other should be only &lt;em&gt;Edit&lt;/em&gt; and &lt;em&gt;View&lt;/em&gt;.&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Click the first entry hyperlink and then &lt;em&gt;&lt;strong&gt;Export Configuration&lt;/strong&gt;&lt;/em&gt;, when prompted, just click &lt;strong&gt;Open&lt;/strong&gt;, we're not going to change anything&lt;/li&gt;    &lt;li&gt;On the definition for the Panel/Grouping control you will see one of two entries:&lt;/li&gt; &lt;/ol&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;lt;my:Control my:Name=&amp;quot;caption&amp;quot; my:TypeName=&amp;quot;UocCaptionControl&amp;quot; my:ExpandArea=&amp;quot;true&amp;quot; my:Caption=&amp;quot;{Binding Source=schema, Path=DisplayName}&amp;quot; my:Description=&amp;quot;{Binding Source=object, Path=DisplayName}&amp;quot;&amp;gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;For this object, uncheck &lt;em&gt;Applies to Create. &lt;/em&gt;&lt;/p&gt;  &lt;p&gt;Or…&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&amp;lt;my:Control my:Name=&amp;quot;caption&amp;quot; my:TypeName=&amp;quot;UocCaptionControl&amp;quot; my:ExpandArea=&amp;quot;true&amp;quot; my:Caption=&amp;quot;%SYMBOL_CreateSyncRuleCaption_END%&amp;quot;&amp;gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;For this object, uncheck &lt;em&gt;Applies to Edit&lt;/em&gt; and &lt;em&gt;Applies to View&lt;/em&gt;. &lt;/p&gt;  &lt;p&gt;That's it!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-1442851428909810101?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=OoAvWXi-RZI:mw6XqrcaSUU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=OoAvWXi-RZI:mw6XqrcaSUU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=OoAvWXi-RZI:mw6XqrcaSUU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=OoAvWXi-RZI:mw6XqrcaSUU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=OoAvWXi-RZI:mw6XqrcaSUU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=OoAvWXi-RZI:mw6XqrcaSUU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=OoAvWXi-RZI:mw6XqrcaSUU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=OoAvWXi-RZI:mw6XqrcaSUU:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=OoAvWXi-RZI:mw6XqrcaSUU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=OoAvWXi-RZI:mw6XqrcaSUU:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=OoAvWXi-RZI:mw6XqrcaSUU:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/OoAvWXi-RZI" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/11/fim-2010-rc1-resolving-duplicate.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/1442851428909810101?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/1442851428909810101?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/OoAvWXi-RZI/fim-2010-rc1-resolving-duplicate.html" title="FIM 2010 RC1 – Resolving the Duplicate SynchronizationRule RCDC" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/11/fim-2010-rc1-resolving-duplicate.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUEAR304eCp7ImA9WxNUEU8.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-8754015492348369393</id><published>2009-10-30T14:05:00.001-07:00</published><updated>2009-11-01T19:07:26.330-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-11-01T19:07:26.330-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM Portal Customization" /><category scheme="http://www.blogger.com/atom/ns#" term="FIM RC1" /><title>FIM 2010 RC1 – Portal Time Zone Default</title><content type="html">&lt;p&gt;Here's an easy one, not in the Pacific Time zone? Tired of seeing your requests in GMT –8?&lt;/p&gt;  &lt;h3&gt;How to Change the Default Portal Time Zone&lt;/h3&gt;  &lt;ol&gt;   &lt;li&gt;From the &lt;strong&gt;Identity Management&lt;/strong&gt; Home Page, click the link for &lt;strong&gt;Administration&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;From the Administration page, click the link for Portal Configuration &lt;/li&gt;    &lt;li&gt;In the &lt;strong&gt;Portal Configuration&lt;/strong&gt; dialog, click the &lt;em&gt;Extended Attributes&lt;/em&gt; tab &lt;/li&gt;    &lt;li&gt;Scroll down to the bottom to the &lt;strong&gt;Time Zone&lt;/strong&gt; property – &lt;em&gt;see figure below&lt;/em&gt;. &lt;/li&gt;    &lt;li&gt;Click the Browse button &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1PortalTimeZoneDefault_C2F9/image.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM2010RC1PortalTimeZoneDefault_C2F9/image_thumb.png" width="644" height="613" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;In RC1 there is no Search Scope (although you could create one, but that's another post) for Time Zone configuration objects, so you need to:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;From the &lt;strong&gt;Select an Object&lt;/strong&gt; browse dialog, click the &lt;em&gt;Search within&lt;/em&gt; drop down and select &lt;em&gt;All Resources&lt;/em&gt; &lt;/li&gt;    &lt;li&gt;In the &lt;em&gt;Search for&lt;/em&gt; text box, type in &lt;strong&gt;(GMT&lt;/strong&gt; and then click the search button &lt;/li&gt;    &lt;li&gt;Select the Time Zone object from the list and click OK &lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1PortalTimeZoneDefault_C2F9/image_3.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM2010RC1PortalTimeZoneDefault_C2F9/image_thumb_3.png" width="610" height="205" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;To complete the configuration you'll either need to wait for the cache to refresh or run an &lt;em&gt;iisreset&lt;/em&gt; if you're impatient.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img src="https://blogger.googleusercontent.com/tracker/24940037-8754015492348369393?l=www.identitychaos.com" width="1" height="1" /&gt;&lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-8754015492348369393?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=TEi1TjcTJeQ:Zn06UbGF1Pc:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=TEi1TjcTJeQ:Zn06UbGF1Pc:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=TEi1TjcTJeQ:Zn06UbGF1Pc:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=TEi1TjcTJeQ:Zn06UbGF1Pc:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=TEi1TjcTJeQ:Zn06UbGF1Pc:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=TEi1TjcTJeQ:Zn06UbGF1Pc:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=TEi1TjcTJeQ:Zn06UbGF1Pc:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=TEi1TjcTJeQ:Zn06UbGF1Pc:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=TEi1TjcTJeQ:Zn06UbGF1Pc:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=TEi1TjcTJeQ:Zn06UbGF1Pc:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=TEi1TjcTJeQ:Zn06UbGF1Pc:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/TEi1TjcTJeQ" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/10/fim-2010-rc1-portal-time-zone-default.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/8754015492348369393?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/8754015492348369393?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/TEi1TjcTJeQ/fim-2010-rc1-portal-time-zone-default.html" title="FIM 2010 RC1 – Portal Time Zone Default" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/10/fim-2010-rc1-portal-time-zone-default.html</feedburner:origLink></entry><entry gd:etag="W/&quot;D0QFQnw-cSp7ImA9WxNVEkk.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-3820892561493861528</id><published>2009-10-22T14:01:00.001-07:00</published><updated>2009-10-22T14:01:53.259-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-22T14:01:53.259-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM RC1" /><title>FIM 2010 RC1 – First Impressions, Installation Part 2</title><content type="html">&lt;p&gt;So, ran into several issues trying to get the Portal installed – keep in mind I'm exercising installation options that few use but ones I tend to prefer when deploying our solutions. Let's start with host headers.&lt;/p&gt;  &lt;p&gt;Back in RC0 I &lt;a href="https://connect.microsoft.com/feedback/ViewFeedback.aspx?FeedbackID=363196&amp;amp;SiteID=433" target="_blank"&gt;posted a bug&lt;/a&gt; where the installer would fail if a host header was used in WSS. While it was closed &amp;quot;as fixed&amp;quot;, it still seems to be an issue if you try and install the portal when the default site collection is running under a host header:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_EB81/image.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_EB81/image_thumb.png" width="544" height="388" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Taking a look at the installation log reveals what looks like hardcoded addresses still:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action CheckSharepointWebApporSiteExisting, location: C:\Users\bturner\AppData\Local\Temp\2\MSI3F65.tmp, command: action=IsDefaultWebApplicationOrSiteExisted absoluteURL=&amp;quot;&lt;b&gt;http://localhost&lt;/b&gt;&amp;quot; &lt;/p&gt;    &lt;p&gt;&amp;#160;&lt;/p&gt;    &lt;p&gt;MSI (c) (C4:E8) [15:19:58:400]: Product: Forefront Identity Manager Service and Portal -- Error 1722. There is a problem with this Windows Installer package. A program run as part of the setup did not finish as expected. Contact your support personnel or package vendor. Action CheckSharepointWebApporSiteExisting, location: C:\Users\bturner\AppData\Local\Temp\2\MSI3F65.tmp, command: action=IsDefaultWebApplicationOrSiteExisted absoluteURL=&lt;strong&gt;http://localhost&lt;/strong&gt;&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I've done my best to override everything both in the GUI and using the MSI parameters so I know I'm not passing &amp;quot;localhost&amp;quot; anywhere. Backtracking further and removing all of the host headers I can get a bit further now but then run into this one next:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_EB81/image_3.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_EB81/image_thumb_3.png" width="402" height="156" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;This appears to be linked to an inability to validate the FIM Service account during the installation, resetting the password seems to have resolved this issue for me. I was able to eventually complete the install, and like I said, I chalk much of this up to my incessant tinkering. There was one other error I'd like to see corrected where the installer detects that the WSP solution file has already been deployed and it instructs you to go remove it while it waits for you – not a great experience.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-3820892561493861528?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=A_FFBJqxTQQ:OKMQ9qZmNtg:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=A_FFBJqxTQQ:OKMQ9qZmNtg:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=A_FFBJqxTQQ:OKMQ9qZmNtg:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=A_FFBJqxTQQ:OKMQ9qZmNtg:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=A_FFBJqxTQQ:OKMQ9qZmNtg:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=A_FFBJqxTQQ:OKMQ9qZmNtg:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=A_FFBJqxTQQ:OKMQ9qZmNtg:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=A_FFBJqxTQQ:OKMQ9qZmNtg:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=A_FFBJqxTQQ:OKMQ9qZmNtg:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=A_FFBJqxTQQ:OKMQ9qZmNtg:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=A_FFBJqxTQQ:OKMQ9qZmNtg:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/A_FFBJqxTQQ" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/10/fim-2010-rc1-first-impressions_5634.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/3820892561493861528?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/3820892561493861528?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/A_FFBJqxTQQ/fim-2010-rc1-first-impressions_5634.html" title="FIM 2010 RC1 – First Impressions, Installation Part 2" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/10/fim-2010-rc1-first-impressions_5634.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0ANRHo5cCp7ImA9WxNVEk8.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-780082222531744710</id><published>2009-10-22T07:23:00.002-07:00</published><updated>2009-10-22T07:29:55.428-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-22T07:29:55.428-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM RC1" /><category scheme="http://www.blogger.com/atom/ns#" term="SQL Server" /><title>FIM 2010 RC1 – First Impressions, Installation Part 1 - Update</title><content type="html">I reported two errors from my last post and I'm happy to report that the bugs I filed are now both closed – here is the scoop:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;&lt;a href="https://connect.microsoft.com/feedback/ViewFeedback.aspx?FeedbackID=497656&amp;amp;SiteID=433" target="_blank"&gt;RC1 - System.InvalidOperationException occurred in Microsoft.IdentityManagement.FindPrivateKey.exe [3124]&lt;/a&gt; – &lt;strong&gt;[Closed, as Fixed]&lt;/strong&gt; this turned out to be a bug fixed post RC1, so while valid it's not entirely new you may still encounter this if you attempt to use your own certificates. For the time being, use the auto-generated certificate.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://connect.microsoft.com/feedback/ViewFeedback.aspx?FeedbackID=497657&amp;amp;SiteID=433" target="_blank"&gt;RC1 - Service and Portal install does not allow for SQL Alias&lt;/a&gt; – &lt;strong&gt;[Closed, by design]&lt;/strong&gt; this turned out to be a user configuration issue. Steps to use an SQL Alias on an x64 system are below. &lt;/li&gt;
&lt;/ul&gt;&lt;h3&gt;How to Create a Named Pipes SQL Server Alias for use with FIM 2010&lt;/h3&gt;There are cases where you may want FIM to communicate with the database server over a specific protocol and not just default to Shared Memory or TCP/IP. There are performance advantages to using Named Pipes when the client and server are on the same box, so here is how you setup an alias for use with Named Pipes. The oh so helpful Microsoft directions are &lt;a href="http://msdn.microsoft.com/en-us/library/ms190445.aspx" target="_blank"&gt;here&lt;/a&gt;. My problem stemmed from an assumption I made that the x86 and x64 SQL Native Clients needed to have different aliases. It would be more assuring if I could find something stated to this effect but I haven't found anything yet. Here are my instructions for creating a Named Pipe alias in SQL Server 2008:&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;Open &lt;strong&gt;SQL Server Configuration Manager&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image.png"&gt;&lt;img alt="image" border="0" height="229" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_thumb.png" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px; display: inline;" title="image" width="644" /&gt;&lt;/a&gt;&lt;br /&gt;
&lt;ol&gt;&lt;li&gt;Expand &lt;strong&gt;SQL Native Client 10.0 Configuration (32bit)&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;Client Protocols&lt;/strong&gt;, right click and take the Properties&lt;/li&gt;
&lt;/ol&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_3.png"&gt;&lt;img alt="image" border="0" height="438" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_thumb_3.png" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px; display: inline;" title="image" width="398" /&gt;&lt;/a&gt; &lt;br /&gt;
&lt;ol&gt;&lt;li&gt;If &lt;strong&gt;Named Pipes&lt;/strong&gt; is under the &lt;em&gt;Disabled Protocols&lt;/em&gt; section, select &lt;strong&gt;Named Pipes&lt;/strong&gt; and click the &amp;gt; button to move it over, and use the up arrow button to move it to the top; click OK to continue&lt;/li&gt;
&lt;li&gt;Repeat these steps for &lt;strong&gt;SQL Native Client 10.0 Configuration&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;NOTE&lt;/strong&gt;: &lt;em&gt;"The SQL Native Client 10.0 Configuration" entry is the x64 client&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Return to the &lt;strong&gt;SQL Native Client 10.0 Configuration (32bit)&lt;/strong&gt;, select Aliases, right click and select &lt;em&gt;New Alias&lt;/em&gt;&lt;/li&gt;
&lt;/ol&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_4.png"&gt;&lt;img alt="image" border="0" height="436" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_thumb_4.png" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px; display: inline;" title="image" width="397" /&gt;&lt;/a&gt; &lt;br /&gt;
&lt;ol&gt;&lt;li&gt;Use the pull-down for &lt;strong&gt;Protocol&lt;/strong&gt; to select &lt;em&gt;Named Pipes&lt;/em&gt;, set the Alias Name to "fim", and the server to "." or "localhost" whichever you prefer; click OK to continue&lt;/li&gt;
&lt;/ol&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_5.png"&gt;&lt;img alt="image" border="0" height="436" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_thumb_5.png" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px; display: inline;" title="image" width="397" /&gt;&lt;/a&gt; &lt;br /&gt;
&lt;ol&gt;&lt;li&gt;Repeat these steps for &lt;strong&gt;SQL Native Client 10.0 Configuration&lt;/strong&gt;&lt;/li&gt;
&lt;/ol&gt;I tried creating a 32-bit alias called ILM and a 64-bit alias called FIM and then feeding either one to the installer to see which one it used and it failed on both tries…which tells me it's somehow trying to use both clients or it's some other validation mechanism I'm not fully understanding. If you have a clue, please elucidate!&lt;br /&gt;
Now, during the installation when it asks you for the SQL Server, you give it the Alias name, not the server name. To validate this is working, run the following SQL Query:&lt;br /&gt;
&lt;div class="csharpcode-wrapper" id="codeSnippetWrapper"&gt;&lt;div class="csharpcode" id="codeSnippet"&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;SELECT&lt;/span&gt;  login_name, program_name, host_name, auth_scheme, net_transport, net_packet_size&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="kwrd"&gt;FROM&lt;/span&gt; sys.dm_exec_connections C &lt;span class="kwrd"&gt;INNER&lt;/span&gt; &lt;span class="kwrd"&gt;JOIN&lt;/span&gt; sys.dm_exec_sessions S&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;ON&lt;/span&gt; C.session_id=S.session_id&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="kwrd"&gt;ORDER&lt;/span&gt; &lt;span class="kwrd"&gt;BY&lt;/span&gt; login_name, auth_scheme

&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;You should see something like this:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_6.png"&gt;&lt;img alt="image" border="0" height="278" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressionsInstallationPa_7450/image_thumb_6.png" style="border-bottom: 0px; border-left: 0px; border-right: 0px; border-top: 0px; display: inline;" title="image" width="644" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-780082222531744710?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=NUN5XJQYWa8:cjr-Vsj_y6M:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=NUN5XJQYWa8:cjr-Vsj_y6M:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=NUN5XJQYWa8:cjr-Vsj_y6M:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=NUN5XJQYWa8:cjr-Vsj_y6M:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=NUN5XJQYWa8:cjr-Vsj_y6M:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=NUN5XJQYWa8:cjr-Vsj_y6M:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=NUN5XJQYWa8:cjr-Vsj_y6M:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=NUN5XJQYWa8:cjr-Vsj_y6M:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=NUN5XJQYWa8:cjr-Vsj_y6M:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=NUN5XJQYWa8:cjr-Vsj_y6M:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=NUN5XJQYWa8:cjr-Vsj_y6M:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/NUN5XJQYWa8" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/10/fim-2010-rc1-first-impressions_22.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/780082222531744710?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/780082222531744710?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/NUN5XJQYWa8/fim-2010-rc1-first-impressions_22.html" title="FIM 2010 RC1 – First Impressions, Installation Part 1 - Update" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/10/fim-2010-rc1-first-impressions_22.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUYMQX4zcSp7ImA9WxNWFEQ.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-5751344471333052204</id><published>2009-10-13T21:06:00.001-07:00</published><updated>2009-10-13T21:06:20.089-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-13T21:06:20.089-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM RC1" /><title>FIM 2010 RC1 – First Impressions, Installation Part 1</title><content type="html">&lt;p&gt;I'm a stickler for installs and installation related issues, I will spend days working on it…this is day one.&lt;/p&gt;  &lt;h3&gt;FIM Synchronization Services Installation&lt;/h3&gt;  &lt;p&gt;No issues that I could see – everything seems to work like it did before and my RC0 install script worked.&lt;/p&gt;  &lt;h3&gt;FIM Service and Portal Installation&lt;/h3&gt;  &lt;p&gt;This is where I encountered my errors…but it starts out well enough. Let's start out with the good news first:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressions_9BC3/image.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressions_9BC3/image_thumb.png" width="542" height="389" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Love the fact that you can change the name, probably won't use it much myself, but customers are always asking for this. Also, note that you can re-use indicating an upgrade or re-install. I did expect to be able to specify a SQL Alias here; however, so I think I'm going to file this as a bug.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressions_9BC3/image_3.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressions_9BC3/image_thumb_3.png" width="542" height="387" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;This interface needs some work, it would be better if it told you what was required on the certificate instead of having to select a certificate, and get an error after clicking Next.&amp;#160; From what I can tell you need a certificate with a valid Subject (not sure if it requires Subject Alternative Name) and the Server Authentication assertion (1.3.6.1.5.5.7.3.1), most commonly known as an SSL certificate. &lt;/p&gt;  &lt;p&gt;In my case, I selected what I thought was a valid certificate but I did get an error later on into the installation that I think is because of this choice.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressions_9BC3/image_4.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/FIM2010RC1FirstImpressions_9BC3/image_thumb_4.png" width="543" height="387" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;Very cool – offer the installer the ability to fix this during the install, excellent work! Now for the bad news…&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Sync Service still supports installation against a SQL Alias (to force Named Pipes access for instance) but the Services and Portal installation does not&lt;/li&gt;    &lt;li&gt;Questionable whether or not selecting an issued certificate works or not – I got the following error later on during the installation which invoked the JIT debugger:&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;System.InvalidOperationException occurred in Microsoft.IdentityManagement.FindPrivateKey.exe [3124]&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;Still indications from my install logs that the installer is not so good about handling existing WSP solutions in SharePoint and recovering from them – these are difficult to clean up I admit&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;More later once I confirm the certificate issue and reinstall SharePoint on my test server.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-5751344471333052204?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tbr1Grm29fs:doE6LNsrKWQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tbr1Grm29fs:doE6LNsrKWQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tbr1Grm29fs:doE6LNsrKWQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tbr1Grm29fs:doE6LNsrKWQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=tbr1Grm29fs:doE6LNsrKWQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tbr1Grm29fs:doE6LNsrKWQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=tbr1Grm29fs:doE6LNsrKWQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tbr1Grm29fs:doE6LNsrKWQ:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tbr1Grm29fs:doE6LNsrKWQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tbr1Grm29fs:doE6LNsrKWQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=tbr1Grm29fs:doE6LNsrKWQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/tbr1Grm29fs" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/10/fim-2010-rc1-first-impressions.html#comment-form" title="2 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/5751344471333052204?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/5751344471333052204?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/tbr1Grm29fs/fim-2010-rc1-first-impressions.html" title="FIM 2010 RC1 – First Impressions, Installation Part 1" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">2</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/10/fim-2010-rc1-first-impressions.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEFQH07fCp7ImA9WxNWE08.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-9020104749450483179</id><published>2009-10-11T21:43:00.001-07:00</published><updated>2009-10-11T21:43:31.304-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-11T21:43:31.304-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><category scheme="http://www.blogger.com/atom/ns#" term="ILM" /><title>A hotfix rollup package (build 3.3.1118.02) is available for Identity Lifecycle Manager 2007 Feature Pack 1</title><content type="html">&lt;p&gt;The 3.3.1118.02 build is available; however, there is a caveat for those of you that have not kept current or are not at build 1087 or better.&amp;#160; Pre-1087 you will need to do full uninstall and then download and install the 3.3.1087.2 slipstreamed build before you can apply later patches. This has to do with an invalid system file that was in the original FP1 build (3.3.0118.2). You can get the 1087 build by calling the support line:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/contactus/?ws=support"&gt;http://support.microsoft.com/contactus/?ws=support&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This build has fixes for both the Certificate and Synchronization components. If you find the following error while attempting to patch your installation:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Error 25009.The Microsoft Identity Integration Server FP1 setup wizard cannot configure the specified database. Invalid object name 'mms_management_agent'. A required privilege is not held by the client.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;…then see the following earlier post on how to fix this:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.identitychaos.com/2009/09/issues-with-sql-server-in-windows-2008.html"&gt;Issues with SQL Server in a Windows 2008 Domain&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;The link to hotfix is here:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/969742"&gt;A hotfix rollup package (build 3.3.1118.02) is available for Identity Lifecycle Manager 2007 Feature Pack 1&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-9020104749450483179?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=olAzHJVN7C4:HEP3WwDUKYQ:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=olAzHJVN7C4:HEP3WwDUKYQ:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=olAzHJVN7C4:HEP3WwDUKYQ:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=olAzHJVN7C4:HEP3WwDUKYQ:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=olAzHJVN7C4:HEP3WwDUKYQ:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=olAzHJVN7C4:HEP3WwDUKYQ:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=olAzHJVN7C4:HEP3WwDUKYQ:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=olAzHJVN7C4:HEP3WwDUKYQ:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=olAzHJVN7C4:HEP3WwDUKYQ:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=olAzHJVN7C4:HEP3WwDUKYQ:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=olAzHJVN7C4:HEP3WwDUKYQ:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/olAzHJVN7C4" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/10/hotfix-rollup-package-build-33111802-is.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/9020104749450483179?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/9020104749450483179?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/olAzHJVN7C4/hotfix-rollup-package-build-33111802-is.html" title="A hotfix rollup package (build 3.3.1118.02) is available for Identity Lifecycle Manager 2007 Feature Pack 1" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/10/hotfix-rollup-package-build-33111802-is.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CU8BSXg7fCp7ImA9WxNXGU8.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-9137986152533665849</id><published>2009-10-07T06:57:00.001-07:00</published><updated>2009-10-07T06:57:38.604-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-07T06:57:38.604-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Webinar" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>Webinar: Accelerate Your Businesses for the Future with Microsoft Geneva (ADFS) and the Cloud</title><content type="html">&lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/WebinarAccelerateYourBusinessesfortheFut_61A0/clip_image001.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="clip_image001" border="0" alt="clip_image001" src="http://www.camelogic.com/idchaos/images/WebinarAccelerateYourBusinessesfortheFut_61A0/clip_image001_thumb.jpg" width="611" height="267" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;When:&lt;/strong&gt;&lt;b&gt;     &lt;br /&gt;&lt;strong&gt;Wednesday, October 14, 2009&lt;/strong&gt;      &lt;br /&gt;&lt;strong&gt;10:30 to 11:30 (PST)&lt;/strong&gt;      &lt;br /&gt;&lt;strong&gt;12:30 to 1:30 (CST)&lt;/strong&gt;      &lt;br /&gt;&lt;strong&gt;1:30 to 2:30 (EST)&lt;/strong&gt;&lt;/b&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Where: &lt;/strong&gt;    &lt;br /&gt;Web/Online    &lt;br /&gt;Live Meeting Information     &lt;br /&gt;will be sent to attendees&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Presenters:&lt;/strong&gt;    &lt;br /&gt;&lt;a href="http://www.ilmbestpractices.com/blog/blogger.html"&gt;David Lundell&lt;/a&gt;, Identity Management     &lt;br /&gt;Practice Leader, Ensynch&lt;/p&gt;  &lt;p&gt;Jonathan Sander   &lt;br /&gt;IAM and Security Analyst    &lt;br /&gt;Quest Software &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Webinar: Accelerate Your Businesses for the Future with Microsoft Geneva (ADFS) and the Cloud&lt;/strong&gt;    &lt;br /&gt;Has your organization been considering moving applications to the cloud or using Software as a Service (SaaS) providers? Have you already done it? Have you realized the cost savings? &lt;/p&gt;  &lt;p&gt;Have you encountered the difficulties in managing the identities and passwords across the various identities? &lt;/p&gt;  &lt;p&gt;Using Microsoft Geneva (ADFS) and Quest Java SSO, and Quest inTrust, you can lower the cost of moving applications to the cloud and to SaaS, which can remove a big hurdle to a key strategic initiative. &lt;/p&gt;  &lt;p&gt;I would like to invite you to our latest exclusive &amp;quot;no frills&amp;quot; webinar: &amp;quot;How Microsoft Geneva Streamlines Business,&amp;quot; the final part in a Identity Management Webinar Series from Ensynch's Identity Management Practice Director, Frequent Industry Speaker, and Microsoft Identity Management MVP, David Lundell, and Quest Software IAM and Security Analyst, Jonathan Sander. (Previous webinars are available for &lt;a href="http://cl.exct.net/?qs=ae57dcbc36f810608655ab3d77c78db41b3c624cb7a1a6ff7a45aa42e75b2e76"&gt;download here&lt;/a&gt;) &lt;/p&gt;  &lt;p&gt;This webinar is designed for business leaders, and will present discuss the business value of Microsoft Geneva and the Cloud. Whether identity management within the Cloud and SaaS is a major concern for your organization or if you are simply curious about using Microsoft Geneva as an asset to help your business, this webinar is for you.    &lt;br /&gt;&lt;strong&gt;Webinar Agenda:&lt;/strong&gt;    &lt;br /&gt;- The Cloud’s little secret: Multiplying identity stores &lt;/p&gt;  &lt;p&gt;- High level discussion of The Cloud (Azure, Amazon, SaaS, etc)&lt;/p&gt;  &lt;p&gt;- High Level discussion of Geneva (ADFS, WIF) &lt;/p&gt;  &lt;p&gt;- The Value of the Cloud &lt;/p&gt;  &lt;p&gt;- The hidden Costs of the Cloud &lt;/p&gt;  &lt;p&gt;- How Geneva(ADFS) helps lower the cost of the Cloud &lt;/p&gt;  &lt;p&gt;- Gaps of the Cloud&lt;/p&gt;  &lt;p&gt;- Possible Solutions &lt;/p&gt;  &lt;p&gt;- Gaps of Geneva with the cloud &lt;/p&gt;  &lt;p&gt;- Possible Solutions from Quest &lt;/p&gt;  &lt;p&gt;&lt;a href="http://cl.exct.net/?qs=ae57dcbc36f810606fbc9bc44fc29a040dc2c326b815e7d30ab7bb56472585cc"&gt;     &lt;br /&gt;[Register Now]&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-9137986152533665849?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=dAnQESyJdpI:L8vKlJt0jeo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=dAnQESyJdpI:L8vKlJt0jeo:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=dAnQESyJdpI:L8vKlJt0jeo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=dAnQESyJdpI:L8vKlJt0jeo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=dAnQESyJdpI:L8vKlJt0jeo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=dAnQESyJdpI:L8vKlJt0jeo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=dAnQESyJdpI:L8vKlJt0jeo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=dAnQESyJdpI:L8vKlJt0jeo:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=dAnQESyJdpI:L8vKlJt0jeo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=dAnQESyJdpI:L8vKlJt0jeo:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=dAnQESyJdpI:L8vKlJt0jeo:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/dAnQESyJdpI" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/10/webinar-accelerate-your-businesses-for.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/9137986152533665849?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/9137986152533665849?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/dAnQESyJdpI/webinar-accelerate-your-businesses-for.html" title="Webinar: Accelerate Your Businesses for the Future with Microsoft Geneva (ADFS) and the Cloud" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/10/webinar-accelerate-your-businesses-for.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DEMMRXw8eyp7ImA9WxNXGEo.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-5286557804726217225</id><published>2009-10-06T17:48:00.001-07:00</published><updated>2009-10-06T17:48:04.273-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-10-06T17:48:04.273-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SharePoint" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>Ensynch Hiring SharePoint Talent</title><content type="html">&lt;p&gt;It looks like our Portals and Collaboration (SharePoint) practice is booming and looking for new talent:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Ensynch’s SharePoint business has been booming recently and as such, we are in need of additional highly skilled SharePoint talent. We are looking for folks that have skills in look &amp;amp; feel, infrastructure architecture &amp;amp; design, web part and custom development, etc.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;If you think you have what it takes drop me a line and I'll direct you to the people you'll need to talk to. At least one of our &lt;a href="http://tec2010.com/agenda-speakers/sharepoint-training/speaker-bios/"&gt;top guys&lt;/a&gt; is speaking with us on the SharePoint track next year at TEC 2010 as well as delivering a session with our own &lt;a href="http://blog.identityjunkie.com/"&gt;Chris Calderon&lt;/a&gt; entitled &amp;quot;Federated SSO Solutions Using SharePoint 2010&amp;quot;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-5286557804726217225?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=K_fXI25NvpU:2tA9eubOYHM:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=K_fXI25NvpU:2tA9eubOYHM:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=K_fXI25NvpU:2tA9eubOYHM:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=K_fXI25NvpU:2tA9eubOYHM:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=K_fXI25NvpU:2tA9eubOYHM:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=K_fXI25NvpU:2tA9eubOYHM:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=K_fXI25NvpU:2tA9eubOYHM:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=K_fXI25NvpU:2tA9eubOYHM:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=K_fXI25NvpU:2tA9eubOYHM:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=K_fXI25NvpU:2tA9eubOYHM:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=K_fXI25NvpU:2tA9eubOYHM:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/K_fXI25NvpU" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/10/ensynch-hiring-sharepoint-talent.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/5286557804726217225?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/5286557804726217225?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/K_fXI25NvpU/ensynch-hiring-sharepoint-talent.html" title="Ensynch Hiring SharePoint Talent" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/10/ensynch-hiring-sharepoint-talent.html</feedburner:origLink></entry><entry gd:etag="W/&quot;AkQBRH4-eCp7ImA9WxNXE04.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-7761962611917271093</id><published>2009-09-30T12:19:00.001-07:00</published><updated>2009-09-30T12:19:15.050-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-30T12:19:15.050-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>Download details: FIM 2010 Release Candidate 1</title><content type="html">&lt;p&gt;RC1 of Forefront Identity Manager 2010 is out, go get it! &lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=4bb3f16b-27f8-4c1d-922f-2c7b522d9ad6#tm"&gt;Download details: FIM 2010 Release Candidate 1&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-7761962611917271093?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tqzaT5sYDao:R2jkQMEmfRI:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tqzaT5sYDao:R2jkQMEmfRI:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tqzaT5sYDao:R2jkQMEmfRI:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tqzaT5sYDao:R2jkQMEmfRI:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=tqzaT5sYDao:R2jkQMEmfRI:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tqzaT5sYDao:R2jkQMEmfRI:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=tqzaT5sYDao:R2jkQMEmfRI:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tqzaT5sYDao:R2jkQMEmfRI:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tqzaT5sYDao:R2jkQMEmfRI:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=tqzaT5sYDao:R2jkQMEmfRI:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=tqzaT5sYDao:R2jkQMEmfRI:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/tqzaT5sYDao" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/09/download-details-fim-2010-release.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7761962611917271093?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7761962611917271093?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/tqzaT5sYDao/download-details-fim-2010-release.html" title="Download details: FIM 2010 Release Candidate 1" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/09/download-details-fim-2010-release.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0UBRHs4fSp7ImA9WxNXE04.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-4270950994735633469</id><published>2009-09-30T10:16:00.003-07:00</published><updated>2009-09-30T10:20:55.535-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-30T10:20:55.535-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="PowerShell" /><category scheme="http://www.blogger.com/atom/ns#" term="ILM" /><title>Using PowerShell to Clear ILM Run and Password History</title><content type="html">With our latest implementation running completely Windows Server 2008, SQL Server 2008 in a Windows 2008 Active Directory I've noticed that my old standby of calling the &lt;strong&gt;MIIS Resource Kit&lt;/strong&gt; utility &lt;em&gt;ClearRunHistory&lt;/em&gt; no longer works. Despite having the following in place:&lt;br /&gt;
&lt;ul&gt;&lt;li&gt;Domain service account&lt;/li&gt;
&lt;li&gt;Member of the ILM Administrators domain group (our renamed MIISAdmins)&lt;/li&gt;
&lt;li&gt;Granted the "Logon as batch" right via policy&lt;/li&gt;
&lt;li&gt;Runs fine logged in as the service account interactively&lt;/li&gt;
&lt;/ul&gt;My scheduled task runs fine, but when it executes the utility it fails with a generic "Access Denied" error. So, I've said goodbye to the last of my Resource Kit buddies and hello to PowerShell! I'm now using the following script to clear both the run history and the password history (in the event you are using PCNS). &lt;br /&gt;
The script below is parameterized and I borrowed heavily from earlier work by &lt;a href="http://miisexperts.org/craigm/"&gt;Craig Martin&lt;/a&gt; and Markus Vilcinskas. If you pass no parameters it should default to 14 days of history to maintain, otherwise you can pass the value, in days, to the script for each. To call this from your own scheduled task, setup the task to call a CMD file of your creation and add the following:&lt;br /&gt;
&lt;div class="csharpcode-wrapper" id="codeSnippetWrapper"&gt;&lt;div class="csharpcode" id="codeSnippet"&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum1"&gt;   1:&lt;/span&gt; &lt;span class="rem"&gt;# Call ClearHistory.ps1 from a CMD file&lt;/span&gt;&amp;nbsp;&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum2"&gt;   2:&lt;/span&gt; powershell -nologo -command &lt;span class="str"&gt;"&amp;amp; D:\ILMTasks\ClearHistory.ps1 5 10"&lt;/span&gt;&lt;/pre&gt;&lt;br /&gt;
&lt;/div&gt;Remember that you must always refer to your script with the full path.&lt;br /&gt;
&lt;/div&gt;&lt;br /&gt;
&lt;h3&gt;ClearHistory.ps1&lt;/h3&gt;&lt;div class="csharpcode-wrapper" id="codeSnippetWrapper"&gt;&lt;div class="csharpcode" id="codeSnippet"&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum1"&gt;   1:&lt;/span&gt; &lt;span class="rem"&gt;# Setup the argument parameters and declare defaults&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum2"&gt;   2:&lt;/span&gt; &lt;span class="rem"&gt;# Default is two weeks of history to retain&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum3"&gt;   3:&lt;/span&gt; &lt;span class="kwrd"&gt;param&lt;/span&gt;([string]$NumDaysToKeepRunHistory = 14,[string]$NumDaysToKeepPwdHistory = 14)&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum4"&gt;   4:&lt;/span&gt;&amp;nbsp; &lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum5"&gt;   5:&lt;/span&gt; &lt;span class="rem"&gt;# Calculate the date to clear runs against&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum6"&gt;   6:&lt;/span&gt; [string]$ClearRunsDate = [DateTime]::Now.AddDays(-$NumDaysToKeepRunHistory).ToUniversalTime()&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum7"&gt;   7:&lt;/span&gt; &lt;span class="rem"&gt;# Calculate the date to clear password history against&lt;/span&gt;&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum8"&gt;   8:&lt;/span&gt; [string]$ClearPwdHistoryDate = [DateTime]::Now.AddDays(-$NumDaysToKeepPwdHistory).ToUniversalTime()&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum9"&gt;   9:&lt;/span&gt;&amp;nbsp; &lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum10"&gt;  10:&lt;/span&gt; &lt;span class="rem"&gt;# Get the WMI Object for MIIS_Server&lt;/span&gt;
&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum11"&gt;  11:&lt;/span&gt; $miiserver = @(get-wmiobject -class &lt;span class="str"&gt;"MIIS_SERVER"&lt;/span&gt; -namespace &lt;span class="str"&gt;"root\MicrosoftIdentityIntegrationServer"&lt;/span&gt; -computer &lt;span class="str"&gt;"."&lt;/span&gt;)&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum12"&gt;  12:&lt;/span&gt;&amp;nbsp; &lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum13"&gt;  13:&lt;/span&gt; &lt;span class="rem"&gt;# Clear the Run History&lt;/span&gt;&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum14"&gt;  14:&lt;/span&gt; Write-Host &lt;span class="str"&gt;"Clearing the Run History prior to (UTC)"&lt;/span&gt; $ClearRunsDate&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum15"&gt;  15:&lt;/span&gt; Write-Host &lt;span class="str"&gt;"Result: "&lt;/span&gt; $miiserver[0].ClearRuns($ClearRunsDate).ReturnValue&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum16"&gt;  16:&lt;/span&gt; &lt;span class="rem"&gt;#--------------------------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum17"&gt;  17:&lt;/span&gt;  &lt;span class="kwrd"&gt;trap&lt;/span&gt; &lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum18"&gt;  18:&lt;/span&gt;  { &lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum19"&gt;  19:&lt;/span&gt;     Write-Host &lt;span class="str"&gt;"`nError: $($_.Exception.Message)`n"&lt;/span&gt; -foregroundcolor white -backgroundcolor darkred&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum20"&gt;  20:&lt;/span&gt;  }&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum21"&gt;  21:&lt;/span&gt; &lt;span class="rem"&gt;#--------------------------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum22"&gt;  22:&lt;/span&gt;&amp;nbsp; &lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum23"&gt;  23:&lt;/span&gt; &lt;span class="rem"&gt;# Clear the Password History&lt;/span&gt;&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum24"&gt;  24:&lt;/span&gt; Write-Host &lt;span class="str"&gt;"Clearing the Password History prior to (UTC)"&lt;/span&gt; $ClearPwdHistoryDate&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum25"&gt;  25:&lt;/span&gt; Write-Host &lt;span class="str"&gt;"Result: "&lt;/span&gt; $miiserver[0].ClearPasswordHistory($ClearPwdHistoryDate).ReturnValue&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum26"&gt;  26:&lt;/span&gt; &lt;span class="rem"&gt;#--------------------------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum27"&gt;  27:&lt;/span&gt;  &lt;span class="kwrd"&gt;trap&lt;/span&gt; &lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum28"&gt;  28:&lt;/span&gt;  { &lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum29"&gt;  29:&lt;/span&gt;     Write-Host &lt;span class="str"&gt;"`nError: $($_.Exception.Message)`n"&lt;/span&gt; -foregroundcolor white -backgroundcolor darkred&lt;/pre&gt;&lt;pre class="alteven"&gt;&lt;span class="lnum" id="lnum30"&gt;  30:&lt;/span&gt;  }&lt;/pre&gt;&lt;pre class="alt"&gt;&lt;span class="lnum" id="lnum31"&gt;  31:&lt;/span&gt; &lt;span class="rem"&gt;#--------------------------------------------------------------------------------------------------------------------&lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;
This script is calling the WMI provider and invoking the functions. The API calls for handing the dates formatted as UTC. I have these scripts posted separately in the &lt;a href="http://social.technet.microsoft.com/Forums/en-US/identitylifecyclemanager/thread/dcfe6a74-6deb-471c-ae16-d18bfe8f39d4"&gt;ILM ScriptBox&lt;/a&gt; in the &lt;a href="http://forums.technet.microsoft.com/en-US/identitylifecyclemanager/threads/"&gt;ILM Forum&lt;/a&gt;.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-4270950994735633469?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=J9MesX0HC9s:Akhqxh7PIjo:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=J9MesX0HC9s:Akhqxh7PIjo:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=J9MesX0HC9s:Akhqxh7PIjo:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=J9MesX0HC9s:Akhqxh7PIjo:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=J9MesX0HC9s:Akhqxh7PIjo:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=J9MesX0HC9s:Akhqxh7PIjo:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=J9MesX0HC9s:Akhqxh7PIjo:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=J9MesX0HC9s:Akhqxh7PIjo:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=J9MesX0HC9s:Akhqxh7PIjo:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=J9MesX0HC9s:Akhqxh7PIjo:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=J9MesX0HC9s:Akhqxh7PIjo:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/J9MesX0HC9s" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/09/using-powershell-to-clear-ilm-run-and.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/4270950994735633469?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/4270950994735633469?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/J9MesX0HC9s/using-powershell-to-clear-ilm-run-and.html" title="Using PowerShell to Clear ILM Run and Password History" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/09/using-powershell-to-clear-ilm-run-and.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A0EDQ3c5eSp7ImA9WxNRFE8.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-1428079311063320680</id><published>2009-09-08T10:07:00.001-07:00</published><updated>2009-09-08T10:07:52.921-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-08T10:07:52.921-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Chaos Chat" /><title>Acceptance Testing Confessional</title><content type="html">&lt;p&gt;Our daily morning team meetings for the project I'm currently on have become less team meeting and more confessional now that we're getting close to go-live. This is what a typical morning sounds like now:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;&lt;strong&gt;Tester 1&lt;/strong&gt;: Bless me PM for I have tested. I found 4 bugs today. &amp;lt;tester 1 leaves&amp;gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;PM&lt;/strong&gt;: &amp;lt;documents the bugs&amp;gt; Very good, hand your results to the developer.&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;Tester 2&lt;/strong&gt;: Bless me PM for I have tested. I found 2 bugs today. &amp;lt;tester 2 leaves&amp;gt;&lt;/p&gt;    &lt;p&gt;&lt;strong&gt;PM&lt;/strong&gt;: &amp;lt;documents the bugs&amp;gt; Very good, hand your results to the developer.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;You get the idea, it was &lt;em&gt;much&lt;/em&gt; funnier when I made the observation this morning.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-1428079311063320680?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=88CG9C6ctgI:dTJo5b8dR3k:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=88CG9C6ctgI:dTJo5b8dR3k:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=88CG9C6ctgI:dTJo5b8dR3k:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=88CG9C6ctgI:dTJo5b8dR3k:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=88CG9C6ctgI:dTJo5b8dR3k:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=88CG9C6ctgI:dTJo5b8dR3k:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=88CG9C6ctgI:dTJo5b8dR3k:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=88CG9C6ctgI:dTJo5b8dR3k:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=88CG9C6ctgI:dTJo5b8dR3k:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=88CG9C6ctgI:dTJo5b8dR3k:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=88CG9C6ctgI:dTJo5b8dR3k:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/88CG9C6ctgI" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/09/acceptance-testing-confessional.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/1428079311063320680?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/1428079311063320680?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/88CG9C6ctgI/acceptance-testing-confessional.html" title="Acceptance Testing Confessional" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/09/acceptance-testing-confessional.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CE4FQHgzeSp7ImA9WxNREE4.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-3610099775525578895</id><published>2009-09-03T19:55:00.001-07:00</published><updated>2009-09-03T19:55:11.681-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-03T19:55:11.681-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="AD 2008" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><category scheme="http://www.blogger.com/atom/ns#" term="ILM" /><title>Issues with SQL Server in a Windows 2008 Domain</title><content type="html">&lt;p&gt;Oh boy, where to start, we have been having various issues with SQL applications failing with different security related error messages and we did not see a connection until just today. The two prominent issues we saw were:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Could not apply patches to an ILM 2007 FP1 installation running on SQL Server 2008 with the servers in a Windows 2008 domain/forest, the errors we got were:&lt;/li&gt;    &lt;blockquote&gt;     &lt;p&gt;Error 25009.The Microsoft Identity Integration Server FP1 setup wizard cannot configure the specified database. Invalid object name 'mms_management_agent'. A required privilege is not held by the client. &lt;/p&gt;      &lt;p&gt;MSI (s) (6C!80) [16:34:17:656]: Product: Microsoft Identity Integration Server -- Error 25009.The Microsoft Identity Integration Server FP1 setup wizard cannot configure the specified database. Invalid object name 'mms_management_agent'. A required privilege is not held by the client.&lt;/p&gt;   &lt;/blockquote&gt;    &lt;li&gt;SQL Server Reporting Services report subscriptions were failing to run in the SQL Agent with the following errors:&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;SQL Server Scheduled Job '52840C4F-5D9F-4CAA-96BE-4C587F655571' (0xBB61E338688B8C459E28A61A6761669D) - Status: Failed - Invoked on: 2009-09-03 17:40:03 - Message: The job failed.&amp;#160; Unable to determine if the owner (DEV\svc.ssrs.ilm) of job 52840C4F-5D9F-4CAA-96BE-4C587F655571 has server access (reason: Could not obtain information about Windows NT group/user DEV\svc.ssrs.ilm', error code 0x5. [SQLSTATE 42000] (Error 15404)).&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Subsequently, it was this troubleshooting technique using &lt;a href="http://msdn.microsoft.com/en-us/library/ms190369.aspx"&gt;xp_logininfo&lt;/a&gt; found by Jaime Martinez that led us to the eventual solution posted by &lt;a href="http://matticus-au.blogspot.com/2009/08/windows-2008-and-xplogininfo.html"&gt;Matticus&lt;/a&gt;:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Find the account that you're getting the error on and open up a new query in SQL Management Studio and then run the xp_logininfo command against it – in our case it looked like this:&lt;/li&gt; &lt;/ul&gt;  &lt;blockquote&gt;   &lt;p&gt;xp_logininfo 'DEV\svc.ssrs.ilm'&lt;/p&gt; &lt;/blockquote&gt;  &lt;ul&gt;   &lt;li&gt;This command generated the following new error:&lt;/li&gt;    &lt;blockquote&gt;     &lt;p&gt;Msg 15404, Level 16, State 11, Procedure xp_logininfo, Line 62       &lt;br /&gt;Could not obtain information about Windows NT group/user DEV\svc.ssrs.ilm', error code 0x5.&lt;/p&gt;   &lt;/blockquote&gt; &lt;/ul&gt;  &lt;p&gt;As it turns out there is a new built-in security group in Windows Server 2008 domains called &lt;em&gt;BUILTIN\Windows Authorization Access Group&lt;/em&gt;. The description on this group reads, &amp;quot;Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects&amp;quot;. This somehow causes issues when certain operations require enumeration of a person's group memberships (the computed tokenGroupsGlobalAndUniversal attribute).&lt;/p&gt;  &lt;h3&gt;Resolution&lt;/h3&gt;  &lt;p&gt;Add the domain service account for your SQL Server (your SQL Server service account) to the &lt;em&gt;BUILTIN\Windows Authorization Access Group&lt;/em&gt; group. You don't need to restart anything, it just starts working from that point forward. What was bizarre is that this also fixed my problem with applying the patches to ILM!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-3610099775525578895?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=UREOFSR6QOs:cfjAITGX4Bw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=UREOFSR6QOs:cfjAITGX4Bw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=UREOFSR6QOs:cfjAITGX4Bw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=UREOFSR6QOs:cfjAITGX4Bw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=UREOFSR6QOs:cfjAITGX4Bw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=UREOFSR6QOs:cfjAITGX4Bw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=UREOFSR6QOs:cfjAITGX4Bw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=UREOFSR6QOs:cfjAITGX4Bw:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=UREOFSR6QOs:cfjAITGX4Bw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=UREOFSR6QOs:cfjAITGX4Bw:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=UREOFSR6QOs:cfjAITGX4Bw:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/UREOFSR6QOs" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/09/issues-with-sql-server-in-windows-2008.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/3610099775525578895?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/3610099775525578895?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/UREOFSR6QOs/issues-with-sql-server-in-windows-2008.html" title="Issues with SQL Server in a Windows 2008 Domain" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/09/issues-with-sql-server-in-windows-2008.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUIFQn05eCp7ImA9WxNSGE4.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-7474246060855135545</id><published>2009-09-01T13:38:00.001-07:00</published><updated>2009-09-01T13:38:33.320-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-09-01T13:38:33.320-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Office 2010" /><title>Office 2010 Technical Preview: Unable to Read or Save to SharePoint</title><content type="html">&lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/Office2010TechnicalPreviewUnabletoReador_B9BE/Office2010TPBanner.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="Office 2010 TP Banner" border="0" alt="Office 2010 TP Banner" src="http://www.camelogic.com/idchaos/images/Office2010TechnicalPreviewUnabletoReador_B9BE/Office2010TPBanner_thumb.jpg" width="640" height="171" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;p&gt; I've been running the Office 2010 Technical Preview for a few weeks now and I really like it…once again. For a time there I was really cursing it due to some issues when reading or writing changes to documents (in this case Office 2007 documents, including OneNote notebooks) stored in our Microsoft Office SharePoint Server 2007 document libraries. I first noticed the issue when attempting to modify a shared OneNote 2007 notebook which, again, is hosted in MOSS 2007 – changes could not be replicated back to the document library and OneNote 2010 would return the following error:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;This section contains changes that could not be synced because the     &lt;br /&gt;section file was not found. The section may have been moved or      &lt;br /&gt;deleted. If OneNote finds the section file later, it will sync the      &lt;br /&gt;changes. Alternatively, you can move this section to a new location.      &lt;br /&gt;Click here for more information.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I would get a similar problem when using Word 2010 to check out and edit a document hosted in a MOSS 2007 document library; however, in this case it manifested in the Office Synchronization Center failing to upload the modified document. You get a nasty red bar in the Pending Uploads section.&lt;/p&gt;  &lt;p&gt;If you're part of the Technical Preview then you can track down these threads and the solutions in &lt;em&gt;microsoft.connect.o2010techprev._general&lt;/em&gt; and search for &amp;quot;sharepoint&amp;quot;. This problem has affected people in the following conditions it seems:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;MOSS 2007 or WSS 3.0 document libraries&lt;/li&gt;    &lt;li&gt;Opening files in a document library&lt;/li&gt;    &lt;li&gt;Opening local files&lt;/li&gt;    &lt;li&gt;Saving files to a document library&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Mark Knight of Microsoft posted the workaround as follows:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;1. In your LAN settings, check &amp;quot;Use a proxy server for your LAN&amp;quot; (you can      &lt;br /&gt;keep &amp;quot;Automatically detect&amp;quot; checked)      &lt;br /&gt;2. Assuming you do not require proxy to reach any servers, you can specify       &lt;br /&gt;http://fake in the Address field to give it a fake proxy      &lt;br /&gt;3. Click Advanced      &lt;br /&gt;4. In the Exceptions field, type the wildcard * to manually bypass the fake       &lt;br /&gt;proxy for all servers you are trying to reach.      &lt;br /&gt;5. OK out of the dialogs to accept the settings and retry opening files from       &lt;br /&gt;SharePoint.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;The only thing I did differently was in step 2 I used &lt;a href="http://127.0.0.1"&gt;http://127.0.0.1&lt;/a&gt; instead of &lt;a href="http://fake"&gt;http://fake&lt;/a&gt; since I don't seemingly random hosts. At least in my case, using the above workaround has resolved my issues. If you continue to have issues I would encourage you to post to the newsgroup.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-7474246060855135545?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=ANzvexiLymc:wz5hbK15q_U:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=ANzvexiLymc:wz5hbK15q_U:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=ANzvexiLymc:wz5hbK15q_U:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=ANzvexiLymc:wz5hbK15q_U:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=ANzvexiLymc:wz5hbK15q_U:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=ANzvexiLymc:wz5hbK15q_U:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=ANzvexiLymc:wz5hbK15q_U:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=ANzvexiLymc:wz5hbK15q_U:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=ANzvexiLymc:wz5hbK15q_U:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=ANzvexiLymc:wz5hbK15q_U:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=ANzvexiLymc:wz5hbK15q_U:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/ANzvexiLymc" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/09/office-2010-technical-preview-unable-to.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7474246060855135545?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7474246060855135545?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/ANzvexiLymc/office-2010-technical-preview-unable-to.html" title="Office 2010 Technical Preview: Unable to Read or Save to SharePoint" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/09/office-2010-technical-preview-unable-to.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEFQ3Y8eSp7ImA9WxNSFEo.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-7509199190494848004</id><published>2009-08-28T08:16:00.001-07:00</published><updated>2009-08-28T08:16:52.871-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-28T08:16:52.871-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>Amazon: XBox 360 Elite with Halo 3 &amp; Fable 2 for $299</title><content type="html">&lt;p&gt;Wow, just saw this in the inbox this morning, just after a night of trying to convince an old friend to pick one up! $299 for the Elite!&lt;/p&gt; &lt;a href="http://www.amazon.com/gp/product/B0026GQ8WA?ie=UTF8&amp;amp;tag=idenchao-20&amp;amp;linkCode=as2&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B0026GQ8WA"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; border-top: 0px; border-right: 0px" border="0" src="https://images-na.ssl-images-amazon.com/images/I/51bHvVldvrL._SL160_.jpg" /&gt;&lt;/a&gt;&lt;img style="border-bottom-style: none !important; border-right-style: none !important; margin: 0px; border-top-style: none !important; border-left-style: none !important" border="0" alt="" src="http://www.assoc-amazon.com/e/ir?t=idenchao-20&amp;amp;l=as2&amp;amp;o=1&amp;amp;a=B0026GQ8WA" width="1" height="1" /&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-7509199190494848004?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=r_Q0G5ny4bs:gqWx13RPnic:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=r_Q0G5ny4bs:gqWx13RPnic:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=r_Q0G5ny4bs:gqWx13RPnic:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=r_Q0G5ny4bs:gqWx13RPnic:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=r_Q0G5ny4bs:gqWx13RPnic:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=r_Q0G5ny4bs:gqWx13RPnic:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=r_Q0G5ny4bs:gqWx13RPnic:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=r_Q0G5ny4bs:gqWx13RPnic:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=r_Q0G5ny4bs:gqWx13RPnic:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=r_Q0G5ny4bs:gqWx13RPnic:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=r_Q0G5ny4bs:gqWx13RPnic:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/r_Q0G5ny4bs" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/08/amazon-xbox-360-elite-with-halo-3-fable.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7509199190494848004?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7509199190494848004?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/r_Q0G5ny4bs/amazon-xbox-360-elite-with-halo-3-fable.html" title="Amazon: XBox 360 Elite with Halo 3 &amp;amp; Fable 2 for $299" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/08/amazon-xbox-360-elite-with-halo-3-fable.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DU8MQX0_cSp7ImA9WxNTGUs.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-6140115837859757906</id><published>2009-08-21T18:14:00.001-07:00</published><updated>2009-08-22T12:04:40.349-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-08-22T12:04:40.349-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="SSL" /><category scheme="http://www.blogger.com/atom/ns#" term="ADAM" /><category scheme="http://www.blogger.com/atom/ns#" term="Server Core" /><title>Issues when binding to AD LDS (ADAM) userProxy</title><content type="html">&lt;h3&gt;aka &amp;quot;Configuring SSL for AD LDS on Windows Server 2008 Server Core&amp;quot;&lt;/h3&gt;  &lt;p&gt;You may have found your way here because:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;you are having issues binding to an ADAM &lt;em&gt;userProxy&lt;/em&gt; &lt;/li&gt;    &lt;li&gt;you are getting the error &amp;quot;&lt;em&gt;Invalid Credentials Server error: 8009030C: LdapErr: DSID-0C0903AA, comment: AcceptSecurityContext error, data 202d, v1772&lt;/em&gt; &lt;em&gt;Error 0x8009030C The logon attempt failed&amp;quot;&lt;/em&gt; in &lt;strong&gt;LDP&lt;/strong&gt; &lt;/li&gt;    &lt;li&gt;you are trying to setup SSL for AD LDS on Windows Server 2008 &lt;em&gt;Server Core&lt;/em&gt; &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;In my case, the solution to the first two problems ended up being the impetus to write the solution for the third bullet above. My problem first began when testing binds to &lt;em&gt;userProxy&lt;/em&gt; objects in AD LDS connecting back to an AD 2008 forest. Here was my configuration:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;AD LDS running on Windows Server 2008 Standard, Server Core (SP2) (6.0.6002.18005) (~300k objects) &lt;/li&gt;    &lt;li&gt;AD DS running on Windows Server 2008 Standard (SP2) &lt;/li&gt;    &lt;li&gt;All servers are in the same domain/forest, including the AD LDS servers (domain joined) &lt;/li&gt;    &lt;li&gt;&lt;em&gt;userProxy&lt;/em&gt; schema loaded into ADAM among others, inetorgperson and custom extensions in use &lt;/li&gt;    &lt;li&gt;&lt;em&gt;userProxy&lt;/em&gt; objects currently being provisioned via ILM and linked to AD with &lt;em&gt;objectSID&lt;/em&gt; (verified) &lt;/li&gt;    &lt;li&gt;SSL certificate already assigned to the ADAM server with &lt;em&gt;Server Authentication&lt;/em&gt; assertion and fullname &lt;/li&gt;    &lt;li&gt;Using LDP to test… &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Binding to &lt;em&gt;inetOrgPerson&lt;/em&gt; objects in ADAM worked fine, but &lt;em&gt;userProxy&lt;/em&gt; binds did not. All attempts to verify that the linked AD account was not locked, disabled, expired with a valid password were validated. Binding against the &lt;em&gt;userProxy&lt;/em&gt; with LDP using UPN or DN yielded the following results:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;res = ldap_simple_bind_s(ld, &lt;a href="mailto:'user@foo.edu'"&gt;'user@foo.edu'&lt;/a&gt;, &amp;lt;unavailable&amp;gt;); // v.3&lt;/p&gt;    &lt;p&gt;Error &amp;lt;49&amp;gt;: ldap_simple_bind_s() failed: Invalid Credentials&lt;/p&gt;    &lt;p&gt;Server error: 8009030C: LdapErr: DSID-0C0903AA, comment: AcceptSecurityContext error, data 202d, v1772&lt;/p&gt;    &lt;p&gt;Error 0x8009030C The logon attempt failed&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Further digging in the LDS server's Security Event Log yielded this error:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;Log Name:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Security&lt;/p&gt;    &lt;p&gt;Source:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Microsoft-Windows-Security-Auditing&lt;/p&gt;    &lt;p&gt;Date:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 8/21/2009 9:37:36 AM&lt;/p&gt;    &lt;p&gt;Event ID:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 4776&lt;/p&gt;    &lt;p&gt;Task Category: Credential Validation&lt;/p&gt;    &lt;p&gt;Level:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Information&lt;/p&gt;    &lt;p&gt;Keywords:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; Audit Failure&lt;/p&gt;    &lt;p&gt;User:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; N/A&lt;/p&gt;    &lt;p&gt;Computer:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; LDSIDI01VDO.foo.intg&lt;/p&gt;    &lt;p&gt;Description:&lt;/p&gt;    &lt;p&gt;The domain controller attempted to validate the credentials for an account.&lt;/p&gt;    &lt;p&gt;Authentication Package:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; ADAM_LDSIDI01VDO&lt;/p&gt;    &lt;p&gt;Logon Account: CN=user,OU=Employees,OU=Bar,OU=Administration,O=Foo,C=us&lt;/p&gt;    &lt;p&gt;Source Workstation:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 10.x.x.x:52186&lt;/p&gt;    &lt;p&gt;Error Code:&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160;&amp;#160; 0xc000006d&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I posted this issue to a group of Directory Service MVP's and we eventually arrived at a solution; &lt;a href="http://joeware.net"&gt;joe&lt;/a&gt; of joeware fame rightly pointed out that I was NOT using LDAPS (SSL) to bind to ADAM as the &lt;a href="http://technet.microsoft.com/en-us/library/cc784622(WS.10).aspx"&gt;documentation&lt;/a&gt; clearly spells out. Kurt Hudson pointed out that the 202d error code was pointing out that SSL was required:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;202d is ERROR_DS_CONFIDENTIALITY_REQUIRED (This request requires a secure connection.)&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;So, first problem solved, if you are binding to AD LDS/ADAM over 389 then you will not be able to test or use &lt;em&gt;userProxy&lt;/em&gt; bind redirection back to AD. Therefore, you must enable SSL for your ADAM instance and this is where things got tricky if you are using Server Core. There is a certain lack of documentation as to how to do this in Server Core. With Kurt Hudson's help (Kurt writes documentation for the AD team at Microsoft!) we finally stumbled upon an answer. Here are my high-level notes:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;The processes documented &lt;a href="http://technet.microsoft.com/en-us/library/cc725767(WS.10).aspx"&gt;here&lt;/a&gt; and &lt;a href="http://www.microsoft.com/windowsserver2003/adam/ADAMfaq.mspx#E2GAC"&gt;here&lt;/a&gt; are somewhat misleading in that… &lt;/li&gt;    &lt;li&gt;You do not have to import the certificate into the ADAM instance or &lt;em&gt;Network Service&lt;/em&gt; account as the instructions mention – this side tracked me for hours trying to figure out how to do this with &lt;em&gt;certutil&lt;/em&gt; &lt;/li&gt;    &lt;li&gt;Finding the files in &lt;em&gt;MachineKeys&lt;/em&gt; is not as easy as it sounds &lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;So, assuming you already have a certificate assigned to your server for the &lt;em&gt;full server name&lt;/em&gt;, you should be able to follow these steps to enable AD LDS/ADAM for SSL on a Server Core box:&lt;/p&gt;  &lt;h3&gt;Configuring SSL for AD LDS on Windows Server 2008 Server Core&lt;/h3&gt;  &lt;ul&gt;   &lt;li&gt;Step 1: Remote into your ADAM server – you'll have a command prompt &lt;/li&gt;    &lt;li&gt;Step 2: Change directory to:      &lt;br /&gt;&lt;strong&gt;C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys&lt;/strong&gt;       &lt;br /&gt;&lt;a href="http://www.camelogic.com/idchaos/images/IssueswhenbindingtoADLDSADAMuserProxy_F5F3/image.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/IssueswhenbindingtoADLDSADAMuserProxy_F5F3/image_thumb.png" width="644" height="181" /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Step 3: Where are the files? Try looking for files with the System attribute set:      &lt;br /&gt;&lt;strong&gt;dir /as&lt;/strong&gt;&lt;a href="http://www.camelogic.com/idchaos/images/IssueswhenbindingtoADLDSADAMuserProxy_F5F3/image_3.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/IssueswhenbindingtoADLDSADAMuserProxy_F5F3/image_thumb_3.png" width="644" height="310" /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Step 4: Find out which of these files relate to your SSL certificate – run:      &lt;br /&gt;&lt;strong&gt;certutil –store My        &lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.camelogic.com/idchaos/images/IssueswhenbindingtoADLDSADAMuserProxy_F5F3/image_4.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/IssueswhenbindingtoADLDSADAMuserProxy_F5F3/image_thumb_4.png" width="644" height="231" /&gt;&lt;/a&gt; &lt;/li&gt;    &lt;li&gt;Step 5: Locate the Key Container GUID, this is the file you need for our next operation – run &lt;strong&gt;icacls &amp;lt;key container&amp;gt; /grant &amp;quot;NETWORK SERVICE&amp;quot;:(R)        &lt;br /&gt;&lt;/strong&gt;&lt;a href="http://www.camelogic.com/idchaos/images/IssueswhenbindingtoADLDSADAMuserProxy_F5F3/image_5.png"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/IssueswhenbindingtoADLDSADAMuserProxy_F5F3/image_thumb_5.png" width="644" height="33" /&gt;&lt;/a&gt;       &lt;br /&gt;&lt;strong&gt;HINT&lt;/strong&gt;: the file will tab-expand! &lt;/li&gt;    &lt;li&gt;Step 6: Try your LDP bind against the FQDN of your ADAM sever, remember to set the SSL flag and change the port to 636. Now you should be able to bind to &lt;em&gt;userProxy&lt;/em&gt; objects!       &lt;br /&gt;&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;Thanks to everyone that pitched in!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-6140115837859757906?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=Tamz3ppi55Q:CZjT9j26GmU:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=Tamz3ppi55Q:CZjT9j26GmU:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=Tamz3ppi55Q:CZjT9j26GmU:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=Tamz3ppi55Q:CZjT9j26GmU:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=Tamz3ppi55Q:CZjT9j26GmU:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=Tamz3ppi55Q:CZjT9j26GmU:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=Tamz3ppi55Q:CZjT9j26GmU:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=Tamz3ppi55Q:CZjT9j26GmU:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=Tamz3ppi55Q:CZjT9j26GmU:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=Tamz3ppi55Q:CZjT9j26GmU:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=Tamz3ppi55Q:CZjT9j26GmU:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/Tamz3ppi55Q" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/08/issues-when-binding-to-ad-lds-adam.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/6140115837859757906?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/6140115837859757906?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/Tamz3ppi55Q/issues-when-binding-to-ad-lds-adam.html" title="Issues when binding to AD LDS (ADAM) userProxy" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/08/issues-when-binding-to-ad-lds-adam.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C0YMR3s_fSp7ImA9WxJbFk4.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-5644588869321254920</id><published>2009-07-26T10:59:00.001-07:00</published><updated>2009-07-26T10:59:46.545-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-26T10:59:46.545-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Windows 7" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>Windows 7 Available for Pre-order</title><content type="html">&lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:7dc1bd33-94bd-46fd-a20b-0131235bcd47:f537ebef-e90f-4227-a48d-de0d753ea83d" class="wlWriterEditableSmartContent"&gt;&lt;table cellspacing="0" cellpadding="2" width="400" border="0" unselectable="on"&gt;&lt;br /&gt;&lt;tbody&gt;&lt;tr&gt;&lt;br /&gt;&lt;td valign="top" width="400"&gt;&lt;br /&gt;&lt;p&gt;&lt;a title="Amazon.com: Microsoft Windows 7 Ultimate: Software" href="http://www.amazon.com/exec/obidos/ASIN/B002DHGMVY/idenchao-20"&gt;&lt;img src="http://images.amazon.com/images/P/B002DHGMVY.01.MZZZZZZZ.jpg" border="0" align="left"&gt;Amazon.com: Microsoft Windows 7 Ultimate: Software&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;  &lt;div style="padding-bottom: 0px; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; float: none; padding-top: 0px" id="scid:7dc1bd33-94bd-46fd-a20b-0131235bcd47:e35914e0-03f0-4bee-94b2-bbdbbc54d534" class="wlWriterEditableSmartContent"&gt;&lt;table cellspacing="0" cellpadding="2" width="400" border="0" unselectable="on"&gt;&lt;br /&gt;&lt;tbody&gt;&lt;tr&gt;&lt;br /&gt;&lt;td valign="top" width="400"&gt;&lt;br /&gt;&lt;p&gt;&lt;a title="Amazon.com: Microsoft Windows 7 Professional" href="http://www.amazon.com/exec/obidos/ASIN/B002DHLVII/idenchao-20"&gt;&lt;img src="http://images.amazon.com/images/P/B002DHLVII.01.MZZZZZZZ.jpg" border="0" align="left"&gt;Amazon.com: Microsoft Windows 7 Professional&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;/p&gt;&lt;br /&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;  &lt;p&gt;Windows 7 was released to manufacturing and will be available in stored on October 22nd! You can pre-order your copies now! Many hardware manufacturers are now including vouchers for Windows 7 if you buy a PC today so be sure to get one if you're in the market for a new computer.&lt;/p&gt;  &lt;p&gt;Be advised that if you are running any of the prior beta releases (including the Release Candidate) there is no upgrade path – you will need to do a full load. Despite this oversight, I'm floored by the number of Mac enthusiasts that are impressed by Win 7. &lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-5644588869321254920?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aDcUsNHDIDw:FlBznOD61E0:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aDcUsNHDIDw:FlBznOD61E0:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aDcUsNHDIDw:FlBznOD61E0:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aDcUsNHDIDw:FlBznOD61E0:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=aDcUsNHDIDw:FlBznOD61E0:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aDcUsNHDIDw:FlBznOD61E0:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=aDcUsNHDIDw:FlBznOD61E0:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aDcUsNHDIDw:FlBznOD61E0:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aDcUsNHDIDw:FlBznOD61E0:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=aDcUsNHDIDw:FlBznOD61E0:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=aDcUsNHDIDw:FlBznOD61E0:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/aDcUsNHDIDw" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/07/windows-7-available-for-pre-order.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/5644588869321254920?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/5644588869321254920?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/aDcUsNHDIDw/windows-7-available-for-pre-order.html" title="Windows 7 Available for Pre-order" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/07/windows-7-available-for-pre-order.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CUEAQnc5fCp7ImA9WxJbFU0.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-7623141612418689381</id><published>2009-07-24T23:34:00.001-07:00</published><updated>2009-07-24T23:34:03.924-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-24T23:34:03.924-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Webinar" /><category scheme="http://www.blogger.com/atom/ns#" term="SharePoint" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>Webinar: Transforming SharePoint – Chaos to Order</title><content type="html">&lt;p&gt;The good folks over in our SharePoint practice is putting on a webinar regarding SharePoint governance and taxonomy. Wonder why no one is using that fancy portal of yours?&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/WebinarTransformingSharePointChaostoOrde_14B2C/image.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/WebinarTransformingSharePointChaostoOrde_14B2C/image_thumb.png" width="602" height="278" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Webinar: Transforming SharePoint      &lt;br /&gt;from Chaos to Order&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;When:     &lt;br /&gt;Thursday, July 30, 2009      &lt;br /&gt;10:30 to 11:30 (PST)      &lt;br /&gt;12:30 to 1:30 (CST)      &lt;br /&gt;1:30 to 2:30 (EST)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Where: &lt;/strong&gt;    &lt;br /&gt;Web/Online    &lt;br /&gt;Live Meeting Information     &lt;br /&gt;will be sent to attendees&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Presenters:&lt;/strong&gt;    &lt;br /&gt;Sean Stecker,    &lt;br /&gt;Portals and Collaboration    &lt;br /&gt;Practice Director, Ensynch&lt;/p&gt;  &lt;p&gt;Jeff Holliday   &lt;br /&gt;Solutions Architect, Ensynch&lt;/p&gt;  &lt;p&gt;Does your IT team spend too much time administering SharePoint?&lt;/p&gt;  &lt;p&gt;Feel like your employees already have too many places to go to get their jobs done, and adding SharePoint just adds another location?&lt;/p&gt;  &lt;p&gt;Simply fed up with your SharePoint environment?&lt;/p&gt;  &lt;p&gt;If you even considered answering yes to any of these questions, chances are high that your SharePoint environment is in some kind of Chaos.&lt;/p&gt;  &lt;p&gt;It’s time to Leave Chaos Behind.&lt;/p&gt;  &lt;p&gt;I would like to take this moment to offer you an exclusive invitation to our exciting new informational webinar: &amp;quot;Transforming SharePoint from Chaos to Order.“&lt;/p&gt;  &lt;p&gt;Whether your environment already suffers from chaos, or if you are still in the planning stages, the taxonomy and governance of your information architecture is critical to the success of your SharePoint environment. &lt;/p&gt;  &lt;p&gt;The webinar will be presented by Ensynch's resident Portals and Collaboration Practice Director, Sean Stecker, alongside Ensynch Solutions Architect, Jeff Holliday.&lt;/p&gt;  &lt;p&gt;Webinar Agenda:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;Learn how to manage the risk, cost and adoption of your SharePoint environment&lt;/li&gt;    &lt;li&gt;Learn how to classify your important business information to meet your needs today and provide scalability for the future&amp;#160; &lt;/li&gt;    &lt;li&gt;Gain insight on indentifying dependencies between Governance and Taxonomy to ensure a highly functional information architecture&lt;/li&gt;    &lt;li&gt;Best Practices Round Table for driving user adoption in SharePoint .&amp;#160; (All attendees are invited to participate in this informational discussion.&amp;#160; Moderator will field questions)&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;&lt;a href="https://www.clicktoattend.com/register.aspx?eventid=139564"&gt;[Register Now]&lt;/a&gt;*    &lt;br /&gt;*external registration through Microsoft Partner Events site&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-7623141612418689381?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=2LiQjRh3_W0:J9qup7Yincw:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=2LiQjRh3_W0:J9qup7Yincw:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=2LiQjRh3_W0:J9qup7Yincw:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=2LiQjRh3_W0:J9qup7Yincw:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=2LiQjRh3_W0:J9qup7Yincw:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=2LiQjRh3_W0:J9qup7Yincw:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=2LiQjRh3_W0:J9qup7Yincw:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=2LiQjRh3_W0:J9qup7Yincw:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=2LiQjRh3_W0:J9qup7Yincw:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=2LiQjRh3_W0:J9qup7Yincw:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=2LiQjRh3_W0:J9qup7Yincw:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/2LiQjRh3_W0" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/07/webinar-transforming-sharepoint-chaos.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7623141612418689381?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7623141612418689381?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/2LiQjRh3_W0/webinar-transforming-sharepoint-chaos.html" title="Webinar: Transforming SharePoint – Chaos to Order" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/07/webinar-transforming-sharepoint-chaos.html</feedburner:origLink></entry><entry gd:etag="W/&quot;A08HQ304cCp7ImA9WxJbFEk.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-8290015161065298844</id><published>2009-07-24T08:37:00.001-07:00</published><updated>2009-07-24T08:37:12.338-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-24T08:37:12.338-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="WIF" /><category scheme="http://www.blogger.com/atom/ns#" term="Webinar" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>Webinar: How Microsoft Geneva Streamlines Business</title><content type="html">&lt;p&gt;Ensynch is proud to present a series of webinars around Microsoft Geneva, now known as the Windows Identity Foundation.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/1fba0971133e_7745/image.png"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="image" border="0" alt="image" src="http://www.camelogic.com/idchaos/images/1fba0971133e_7745/image_thumb.png" width="601" height="280" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Webinar: How Microsoft Geneva Streamlines Business&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;When:     &lt;br /&gt;Wednesday, July 29, 2009      &lt;br /&gt;10:30 to 11:30 (PST)      &lt;br /&gt;12:30 to 1:30 (CST)      &lt;br /&gt;1:30 to 2:30 (EST)&lt;/strong&gt;&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Where: &lt;/strong&gt;    &lt;br /&gt;Web/Online    &lt;br /&gt;Live Meeting Information will be sent to attendees&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Presenters:&lt;/strong&gt;    &lt;br /&gt;David Lundell, Identity Management Practice Leader, Ensynch&lt;/p&gt;  &lt;p&gt;Jonathan Sander, IAM and Security Analyst, Quest Software &lt;/p&gt;  &lt;p&gt;&lt;strong&gt;- Learn How to Reap the Benefits of True Web      &lt;br /&gt; Single-Sign-On and Federation&lt;/strong&gt;    &lt;br /&gt;Has your organization been forced to deploy one-off solutions to solve login or compliance problems with a newly deployed technology?&lt;/p&gt;  &lt;p&gt;Are your employees tired of using multiple logins for all kinds of access needs?&lt;/p&gt;  &lt;p&gt;Having trouble managing shared resources users both inside and outside of your organization?&lt;/p&gt;  &lt;p&gt;Using open platform identity management solution &lt;strong&gt;Microsoft Geneva&lt;/strong&gt;, you can save money and make your business more efficient today, and also make it more easily scalable for the future.    &lt;br /&gt;I would like to invite you to our latest exclusive &amp;quot;no frills&amp;quot; webinar: &amp;quot;&lt;strong&gt;How Microsoft Geneva Streamlines Business&lt;/strong&gt;,&amp;quot; the 1st in a 4-part Identity Management Webinar Series from Ensynch's Identity Management Practice Leader and Microsoft Identity Management MVP, David Lundell, and Quest Software IAM and Security Analyst, Jonathan Sander.&lt;/p&gt;  &lt;p&gt;This webinar is designed for business leaders, and will present business value propositions for the Microsoft Geneva framework. Whether identity management is a major concern for your organization or if you are simply curious about using Microsoft Geneva as an asset to help your business, this webinar is for you.   &lt;br /&gt;&lt;strong&gt;Webinar Agenda:&lt;/strong&gt;    &lt;br /&gt;- Yikes! The business pain points of managing lots of identities&lt;/p&gt;  &lt;p&gt;- High level discussion of Microsoft Geneva&lt;/p&gt;  &lt;p&gt;- Business value of Geneva&lt;/p&gt;  &lt;p&gt;- Gaps of the Geneva framework&lt;/p&gt;  &lt;p&gt;- Possible solutions to the gaps&lt;/p&gt;  &lt;p&gt;- ROI of Geneva versus other Single-Sign-On solutions&lt;/p&gt;  &lt;p&gt;- Geneva and the Cloud&lt;/p&gt;  &lt;p&gt;- Q &amp;amp; A    &lt;br /&gt;&lt;strong&gt;     &lt;br /&gt;Stay Tuned for the other three parts of this webinar series:&lt;/strong&gt;    &lt;br /&gt;&lt;strong&gt;A Technical Overview of the Microsoft Geneva Infrastructure&lt;/strong&gt;    &lt;br /&gt;Thursday, August 20, 2009&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Using the Microsoft Geneva Framework to Solve      &lt;br /&gt;Your Federation Needs&lt;/strong&gt;    &lt;br /&gt;Thursday, September 10, 2009&lt;/p&gt;  &lt;p&gt;&lt;strong&gt;Accelerate Your Businesses for the Future with Microsoft Geneva and the Cloud&lt;/strong&gt;    &lt;br /&gt;Thursday, October 1, 2009&lt;/p&gt;  &lt;p&gt;&lt;a href="https://www.clicktoattend.com/register.aspx?eventid=139425"&gt;[Register Now]&lt;/a&gt;*    &lt;br /&gt;*external registration through Microsoft Partner Events site&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-8290015161065298844?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=-0kbd0iTh8s:Y2UDl7BkfJA:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=-0kbd0iTh8s:Y2UDl7BkfJA:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=-0kbd0iTh8s:Y2UDl7BkfJA:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=-0kbd0iTh8s:Y2UDl7BkfJA:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=-0kbd0iTh8s:Y2UDl7BkfJA:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=-0kbd0iTh8s:Y2UDl7BkfJA:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=-0kbd0iTh8s:Y2UDl7BkfJA:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=-0kbd0iTh8s:Y2UDl7BkfJA:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=-0kbd0iTh8s:Y2UDl7BkfJA:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=-0kbd0iTh8s:Y2UDl7BkfJA:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=-0kbd0iTh8s:Y2UDl7BkfJA:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/-0kbd0iTh8s" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/07/webinar-how-microsoft-geneva.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/8290015161065298844?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/8290015161065298844?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/-0kbd0iTh8s/webinar-how-microsoft-geneva.html" title="Webinar: How Microsoft Geneva Streamlines Business" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/07/webinar-how-microsoft-geneva.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DUUHQHc-cSp7ImA9WxJbE0o.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-2657800271444836361</id><published>2009-07-23T12:27:00.001-07:00</published><updated>2009-07-23T12:27:11.959-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-23T12:27:11.959-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Convergence" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos Chat" /><title>Security Squared: Converging Physical and Logical Identities, Hands-On (SecureNet)</title><content type="html">&lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/SecuritySquaredConvergingPhysicalandLogi_D7E8/preventchaos.jpg"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="preventchaos" border="0" alt="preventchaos" src="http://www.camelogic.com/idchaos/images/SecuritySquaredConvergingPhysicalandLogi_D7E8/preventchaos_thumb.jpg" width="241" height="184" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;There is another great interview on &lt;a href="http://www.experteditorial.net/securitysquared/"&gt;Security Squared&lt;/a&gt;, this one focusing on &lt;a href="http://www.securenetinc.com"&gt;SecureNet&lt;/a&gt;, a new Ensynch partner. The interview can be found &lt;a href="http://www.experteditorial.net/securitysquared/2009/07/securenet-transcript-converged-identities.html"&gt;here&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;In the interview, Sharon J. Watson (interviewer from Security Squared) asks:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;SJW: Eric had mentioned earlier he'd read my interview with Dave Hansen over at CA, and Dave really thought Active Directory should not be the authoritative source. He said that put IT in control of creating identities and that to him was a problem. He thought that responsibility should be backed up to HR and its systems. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;I'll come back to this in a bit, but first SecureNet's Greg Thornbury has some great responses based on practical experiences:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;GT: We've done some deployments where we've pointed to HR systems like Peoplesoft, SAP, things like that. We typically have found, even when we're doing that, a lot of resistance on the part of the end user to allow us to really connect to that production HR system. So when we have done it, we've typically done it through some middle connection or step. A batch process at the end of the day or an instance of that database copied out there that's not running in production. &lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;First comment – this parallels what we see in the IDA deployments we've done. In some cases you can get great interaction with HR (my current customer is one of the rare few that don't mind working very closely with internal IDA) and in others you are a second class citizen and can only see a text file extracted nightly; delta's, forget it! I've even had customers where HR is outsourced so completely that they have no way to get regular automated extracts.&lt;/p&gt;  &lt;p&gt;Greg continues with:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;A lot of what we do as an integrator is speak to our client and do a lot of listening and find out what is the best authoritative source. In a lot of organizations, you're going to find that answer isn't going to be consistent. We're flexible. We've done it both ways. It's great to connect to HR; that's truly the originating point for a lot of that data. In other cases, it seems like HR doesn't keep up everything from an employee location standpoint the way IT does. In those cases, Active Directory may be the better source. At the end of the day, it's always the end user's decision. We try to help them and consult with them. We can look at different sources, so it doesn't really matter to us as long as it's the authoritative source.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;Greg is being kind here to his customers to soften the blow a bit – in practically every case we've found dirty HR data in various forms. This goes back to one of the primary drivers for HR data – payroll. If I'm getting my paycheck and my benefits then I have no reason to talk to anyone at HR unless I want to file a grievance, change my address or change my benefits or deductions. In my experience, the number of companies that have mature HR self-service portals that employees actually use is quite slim. This results in primary identity and departmental information being correct but few are going to update phone number and physical location information here. For instance, my job code might identify me as a developer in Department 200 with a location code of 350, but that information doesn't always coincide with the actual location I reside at. In many cases HR may only care to identify the campus you are at but not the actual building, floor or mail-drop (your mileage varies widely here). What you end up with here is a partial disconnect from what HR cares to track versus what you need for a full PACS/IDA solution; it's an issue of fidelity here.&lt;/p&gt;  &lt;p&gt;Greg makes a point earlier here:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;But a lot of companies are using contractors now as well. In a lot of cases, the contractors aren't managed inside of Active Directory in the same way employees are managed. Typically we'll have several authoritative sources: one for employees and a separate authoritative source for contractors. We've also got solutions that tie in visitor management systems creating visitor credentials and in that case, you've got even a third authoritative source for where the visitor data comes from.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;This is a serious hole in the &amp;quot;use HR only&amp;quot; approach and one we've seen quite regularly as well. Only on rare occasions have we seen businesses actually manage non-employees in HR; this has to do with what drives HR (keep reading). Hooking into multiple data sources means your business rules just became a lot more complex. Using Active Directory as the consolidated identity directory bypasses much of that.&lt;/p&gt;  &lt;p&gt;Eric Rohleder adds later:&lt;/p&gt;  &lt;blockquote&gt;   &lt;p&gt;ER: Another nice part of connecting to Active Directory, since we're talking about physical/logical convergence, is the logical access is usually tied to Active Directory. So you go to Active Directory and deactivate an identity, you know in one step you're going to get physical and logical turned off at the same time.&lt;/p&gt; &lt;/blockquote&gt;  &lt;p&gt;What Eric is describing here is important, the fact that you have an abstraction layer between what HR says and what logical access is enforcing. If I need to walk an employee out of the building, do I wait for HR to process the paperwork so that the termination date field is populated, or do I just disable their AD account? In reality what happens is the manager makes two calls, one to HR to start the process, and one to the administrators to terminate access immediately. HR is less concerned with updating their database than they are worrying about following all of the complex termination processes in order to avoid any wrongful termination lawsuits. It could take HR days to process the real request, so which would you rather rely on?&lt;/p&gt;  &lt;h3&gt;HR or AD?&lt;/h3&gt;  &lt;p&gt;Obviously you can make either work, but which is better? The answer is that &lt;em&gt;it depends&lt;/em&gt;. When the question is framed from the point of view of an IDA implementer our answer is always &amp;quot;THE authoritative source, no middle men&amp;quot;, so when implementing an ILM solution we want to talk as directly as possible (and as often as possible) to HR; however, that's because we're responsible for all of the business logic that Eric and Greg allude to and we're built for connecting to multiple data sources. We are responsible for building the rules for when and how the AD accounts are created in the first place, therefore, the same question, from a physical security perspective is best answered as &amp;quot;AD&amp;quot;, with the proviso that some sort of IDA automation (like ILM/FIM) is responsible for driving identity provisioning and deprovisioning. Once you have a robust process driving the identities then physical access integration becomes possible as it becomes another client of the directory and some very nifty ROI can be achieved by levering the existing investments in IDA. In short, when IDA and PACS work together you can truly realize convergence with a single identity.&lt;/p&gt;  &lt;h3&gt;What about Directory Chaff?&lt;/h3&gt;  &lt;p&gt;With any directory you're going to build up a small amount of detritus; orphaned accounts in addition to valid accounts like service accounts, administrator accounts, computer accounts, etc. As Greg points out, there are easy ways to filter out much, if not all of that with SecureNet's solution, but only a good IDA solution is able to keep terminated and inactive users out of the system and if PACS is connected to AD then that investment pays off without any complex business logic changes on the physical security side.&lt;/p&gt;  &lt;p&gt;Consider another problem, a recent customer of mine has a requirement that all employees maintain active AD accounts in order for them to come back and access self-service W2 information from HR up to 6 months after termination. In HR, this person is terminated, with a termination date, and a status indicator; however, in AD I can maintain an active account because we've built that business logic into how ILM handles terminated accounts coming from HR. If that requirement changes to 9 months then we have a single very simple change to make within our ILM configuration without any re-coding of flows. Now this presents a small challenge to the &amp;quot;use AD as the source&amp;quot; as you'd now have a terminated person with badge access, right? Nope, enter SecureNet's solutions for RBAC. They have the ability to either map directly against AD group or to build roles based on attributes of a user. In either case, since we control the data present on the user and their group memberships through ILM, we remove the users from any physical security based groups or modify the user attributes such that the derived roles in the PACS system remove badge access while the AD account remains active. What you gain here by using an IDA driven AD is flexibility.&lt;/p&gt;  &lt;h3&gt;Getting Identity data into your Intelligent Controllers&lt;/h3&gt;  &lt;p&gt;SecureNet uses a really nifty product for automating the data import from sources like databases, flat files, or AD itself. This is not something I would turn to ILM or another identity provider to attempt to do given the antiquity of the protocols used to communicate with even modern intelligent controllers. The good news here for companies that have &lt;a href="http://www.mercury-security.com/"&gt;Mercury Security&lt;/a&gt; (Lenel's On-Guard, Open Options, Honeywell, RS2, Arinc, and Indenticard to name a few) based PACS is that this system is fully compatible with some minor migration efforts required; that means you keep all or most of your hardware (controllers, readers, panels, etc) and just upgrade the software. SecureNet specializes in this sort of physical integration and Ensynch is happy to partner with them to extend their reach on the IDA side. Ensynch just completed an internal conversion of our PACS using SecureNet and are extremely happy with not just the results, but the possibilities of finally converging physical and logical access…and yes, we're using AD as the source!&lt;/p&gt;  &lt;h3&gt;How Do I Converge?&lt;/h3&gt;  &lt;p&gt;Contact me and let's talk – we're happy to connect you directly with &lt;a href="http://www.securenetinc.com/contact/contact.htm"&gt;SecureNet&lt;/a&gt; or feel free to contact them directly if you have questions regarding physical security. &lt;a href="http://www.ensynch.com/"&gt;Ensynch&lt;/a&gt; would be happy to help you get ILM/FIM implemented so that SecureNet has the best possible chance in leveraging AD directly.&lt;/p&gt;  &lt;p&gt;&lt;img style="border-right-width: 0px; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" border="0" src="http://www.securenetinc.com/images/snetlogo2.gif" /&gt;&amp;#160;&lt;a href="http://www.camelogic.com/idchaos/images/SecuritySquaredConvergingPhysicalandLogi_D7E8/logo2cSMALLRGB.jpg"&gt;&lt;img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; border-left-width: 0px" title="logo 2cSMALL-RGB" border="0" alt="logo 2cSMALL-RGB" src="http://www.camelogic.com/idchaos/images/SecuritySquaredConvergingPhysicalandLogi_D7E8/logo2cSMALLRGB_thumb.jpg" width="196" height="98" /&gt;&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-2657800271444836361?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=HwDnp4WREHI:3dyuNZlxczY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=HwDnp4WREHI:3dyuNZlxczY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=HwDnp4WREHI:3dyuNZlxczY:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=HwDnp4WREHI:3dyuNZlxczY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=HwDnp4WREHI:3dyuNZlxczY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=HwDnp4WREHI:3dyuNZlxczY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=HwDnp4WREHI:3dyuNZlxczY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=HwDnp4WREHI:3dyuNZlxczY:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=HwDnp4WREHI:3dyuNZlxczY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=HwDnp4WREHI:3dyuNZlxczY:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=HwDnp4WREHI:3dyuNZlxczY:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/HwDnp4WREHI" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/07/security-squared-converging-physical.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/2657800271444836361?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/2657800271444836361?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/HwDnp4WREHI/security-squared-converging-physical.html" title="Security Squared: Converging Physical and Logical Identities, Hands-On (SecureNet)" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/07/security-squared-converging-physical.html</feedburner:origLink></entry><entry gd:etag="W/&quot;C04GRX4-cCp7ImA9WxJbE0s.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-8799813952983467449</id><published>2009-07-23T08:11:00.001-07:00</published><updated>2009-07-23T08:12:04.058-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-23T08:12:04.058-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="The Experts Conference" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>Quest Software Announces The Expert Conference 2010</title><content type="html">&lt;p&gt;Save the date: April 25th – 28th 2010 in Los Angeles, CA at the JW Marriott!&lt;/p&gt;  &lt;p&gt;There will be three tracks next year:&lt;/p&gt;  &lt;ol&gt;   &lt;li&gt;Directory &amp;amp; Identity&lt;/li&gt;    &lt;li&gt;Exchange&lt;/li&gt;    &lt;li&gt;SharePoint&lt;/li&gt; &lt;/ol&gt;  &lt;p&gt;If you have topics or experiences you'd like to share then I would encourage you to submit sessions through the &lt;a href="http://www.tec2010.com/call-for-papers/index.html"&gt;call for papers&lt;/a&gt;. Or, if you'd just rather hawk your product or services and gain some exposure you won't fine a more influential crowd than at TEC so consider becoming a &lt;a href="http://www.tec2010.com/tec-sponsors/index.html"&gt;sponsor&lt;/a&gt;.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.quest.com/newsroom/news-releases-show.aspx?contentid=10107"&gt;Quest Software Announces The Expert Conference 2010&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-8799813952983467449?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=BgFav5LCygE:3qKs_CTxTQY:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=BgFav5LCygE:3qKs_CTxTQY:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=BgFav5LCygE:3qKs_CTxTQY:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=BgFav5LCygE:3qKs_CTxTQY:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=BgFav5LCygE:3qKs_CTxTQY:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=BgFav5LCygE:3qKs_CTxTQY:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=BgFav5LCygE:3qKs_CTxTQY:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=BgFav5LCygE:3qKs_CTxTQY:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=BgFav5LCygE:3qKs_CTxTQY:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=BgFav5LCygE:3qKs_CTxTQY:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=BgFav5LCygE:3qKs_CTxTQY:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/BgFav5LCygE" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/07/quest-software-announces-expert.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/8799813952983467449?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/8799813952983467449?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/BgFav5LCygE/quest-software-announces-expert.html" title="Quest Software Announces The Expert Conference 2010" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/07/quest-software-announces-expert.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CkEDQX05eip7ImA9WxJbEkU.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-7953388046146293670</id><published>2009-07-22T09:37:00.001-07:00</published><updated>2009-07-22T09:37:50.322-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-22T09:37:50.322-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="PowerShell" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><category scheme="http://www.blogger.com/atom/ns#" term="ILM" /><title>ILM 2007 FP1 PowerShell Cmdlets</title><content type="html">&lt;p&gt;In my first official day back from vacation after the birth of our daughter Piper, I've noticed that Markus Vilcinskas posted two links for PowerShell enabling existing ILM 2007 FP1 deployments in the following forum thread:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://social.technet.microsoft.com/Forums/en-US/identitylifecyclemanager/thread/25be15c1-c1b6-4073-bcf4-53dc76f165a5"&gt;Identity Lifecycle Manager 2007 FP1 Sync Engine Configuration PowerShell Commandlets&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;I should note that the documentation incorrectly lists this as for ILM &amp;quot;2&amp;quot;; however, Markus assures me that this is intended for ILM 2007 FP1.&amp;#160; You will want to be running at least the 3.3.1080.2 (FP1) build before you attempt it (no guarantees this will work with MIIS 2003 SP2). The latest released hotfix rollup as of this posting is 3.3.1101.2:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://support.microsoft.com/kb/960765"&gt;A hotfix rollup package (build 3.3.1101.2) is available for Identify Lifecycle Manager 2007 Feature Pack 1&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;Now I finally have a real excuse to learn PowerShell!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-7953388046146293670?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=IUS7shVzxm0:zvy_OmohEzE:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=IUS7shVzxm0:zvy_OmohEzE:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=IUS7shVzxm0:zvy_OmohEzE:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=IUS7shVzxm0:zvy_OmohEzE:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=IUS7shVzxm0:zvy_OmohEzE:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=IUS7shVzxm0:zvy_OmohEzE:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=IUS7shVzxm0:zvy_OmohEzE:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=IUS7shVzxm0:zvy_OmohEzE:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=IUS7shVzxm0:zvy_OmohEzE:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=IUS7shVzxm0:zvy_OmohEzE:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=IUS7shVzxm0:zvy_OmohEzE:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/IUS7shVzxm0" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/07/ilm-2007-fp1-powershell-cmdlets.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7953388046146293670?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/7953388046146293670?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/IUS7shVzxm0/ilm-2007-fp1-powershell-cmdlets.html" title="ILM 2007 FP1 PowerShell Cmdlets" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/07/ilm-2007-fp1-powershell-cmdlets.html</feedburner:origLink></entry><entry gd:etag="W/&quot;DE8AQX49fCp7ImA9WxJVFEU.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-5984503754230701086</id><published>2009-07-01T15:20:00.001-07:00</published><updated>2009-07-01T15:20:40.064-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-07-01T15:20:40.064-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="Chaos News" /><title>MVP Year Four and MCADD</title><content type="html">&lt;p&gt;&lt;a href="http://www.camelogic.com/idchaos/images/MVPYearFourandMCADD_D512/mvp.jpg"&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="mvp" border="0" alt="mvp" src="http://www.camelogic.com/idchaos/images/MVPYearFourandMCADD_D512/mvp_thumb.jpg" width="128" height="54" /&gt;&lt;/a&gt; &lt;/p&gt;  &lt;p&gt;My notice informing me that I have been graced with the Microsoft MVP award for work in the MIIS/ILM/FIM area came this morning alongside news late yesterday that our three week old daughter Piper tested positive for a genetic disorder called &lt;a href="http://www.savebabies.org/professionals/diseasedescriptions/mcadd.html"&gt;MCADD&lt;/a&gt;. So while I'm very excited that I'll remain in close contact with the ILM/FIM Product Group at Microsoft it does mean that our family dynamic will evolve yet again beyond the &amp;quot;new baby&amp;quot; and &amp;quot;big sister/little sister&amp;quot; changes we were already experiencing.&lt;/p&gt;  &lt;p&gt;&lt;img style="border-bottom: 0px; border-left: 0px; display: inline; border-top: 0px; border-right: 0px" title="IMG_0484" border="0" alt="IMG_0484" src="http://www.camelogic.com/idchaos/images/MVPYearFourandMCADD_D512/IMG_0484.jpg" width="184" height="244" /&gt; &lt;/p&gt;  &lt;p&gt;&lt;/p&gt;  &lt;p&gt;We appreciate all of the support and well wishing from friends and family!&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-5984503754230701086?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=KQQqEpj4S_Q:SgwfCRE1u3A:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=KQQqEpj4S_Q:SgwfCRE1u3A:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=KQQqEpj4S_Q:SgwfCRE1u3A:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=KQQqEpj4S_Q:SgwfCRE1u3A:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=KQQqEpj4S_Q:SgwfCRE1u3A:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=KQQqEpj4S_Q:SgwfCRE1u3A:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=KQQqEpj4S_Q:SgwfCRE1u3A:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=KQQqEpj4S_Q:SgwfCRE1u3A:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=KQQqEpj4S_Q:SgwfCRE1u3A:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=KQQqEpj4S_Q:SgwfCRE1u3A:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=KQQqEpj4S_Q:SgwfCRE1u3A:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/KQQqEpj4S_Q" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/07/mvp-year-four-and-mcadd.html#comment-form" title="3 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/5984503754230701086?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/5984503754230701086?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/KQQqEpj4S_Q/mvp-year-four-and-mcadd.html" title="MVP Year Four and MCADD" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">3</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/07/mvp-year-four-and-mcadd.html</feedburner:origLink></entry><entry gd:etag="W/&quot;CEEHQnk9eCp7ImA9WxJVFE0.&quot;"><id>tag:blogger.com,1999:blog-24940037.post-1459727443996342115</id><published>2009-06-30T15:57:00.001-07:00</published><updated>2009-06-30T15:57:13.760-07:00</updated><app:edited xmlns:app="http://www.w3.org/2007/app">2009-06-30T15:57:13.760-07:00</app:edited><category scheme="http://www.blogger.com/atom/ns#" term="FIM" /><category scheme="http://www.blogger.com/atom/ns#" term="Chaos Chat" /><title>Security Squared: 4 Part Series on Converging Logical-Physical IAM</title><content type="html">&lt;p&gt;Security Squared has a nice four part article on how Identity and Access Management is rapidly converging with Logical-Physical access control systems (PACS). Think about tying your badge access control (perimeter, interior, etc) to your AD account; AD account is disabled and your badge is immediately cut off. These are capabilities Ensynch has recently acquired through a partnership that I hope to see announced very soon. Now you'll be able to completely tie-in access control across all aspects of IT and if you factor in the request management capabilities of FIM 2010 then you can begin to conceptualize a solution that would allow for complete paperless automation (with approvals) of physical access control requests! Combine that with PKI and data protection initiatives (like RMS) and you can begin to realize solutions within everyone's budget – not just the big enterprises.&lt;/p&gt;  &lt;p&gt;This isn't some emerging technology, the software and hardware exists today and is fully available, we are only just recently bridging the gulf between IAM and PACS solutions providers to offer a unified and converged solution. Contact me if this interests you.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.experteditorial.net/securitysquared/2009/06/one-person-one-identity-one-credential-converging-logical-physical-identity-and-access-management.html"&gt;One Person, One Identity, One Credential: Converging Logical-Physical Identity and Access Management -- Part 1&lt;/a&gt;&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/24940037-1459727443996342115?l=www.identitychaos.com'/&gt;&lt;/div&gt;&lt;div class="feedflare"&gt;
&lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=uls2AJ46cjQ:Ny5j4DExFo4:yIl2AUoC8zA"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=yIl2AUoC8zA" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=uls2AJ46cjQ:Ny5j4DExFo4:63t7Ie-LG7Y"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=63t7Ie-LG7Y" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=uls2AJ46cjQ:Ny5j4DExFo4:dnMXMwOfBR0"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=dnMXMwOfBR0" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=uls2AJ46cjQ:Ny5j4DExFo4:F7zBnMyn0Lo"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=uls2AJ46cjQ:Ny5j4DExFo4:F7zBnMyn0Lo" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=uls2AJ46cjQ:Ny5j4DExFo4:V_sGLiPBpWU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=uls2AJ46cjQ:Ny5j4DExFo4:V_sGLiPBpWU" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=uls2AJ46cjQ:Ny5j4DExFo4:YwkR-u9nhCs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=YwkR-u9nhCs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=uls2AJ46cjQ:Ny5j4DExFo4:qj6IDK7rITs"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?d=qj6IDK7rITs" border="0"&gt;&lt;/img&gt;&lt;/a&gt; &lt;a href="http://feeds.feedburner.com/~ff/idchaos?a=uls2AJ46cjQ:Ny5j4DExFo4:4cEx4HpKnUU"&gt;&lt;img src="http://feeds.feedburner.com/~ff/idchaos?i=uls2AJ46cjQ:Ny5j4DExFo4:4cEx4HpKnUU" border="0"&gt;&lt;/img&gt;&lt;/a&gt;
&lt;/div&gt;&lt;img src="http://feeds.feedburner.com/~r/idchaos/~4/uls2AJ46cjQ" height="1" width="1"/&gt;</content><link rel="replies" type="text/html" href="http://www.identitychaos.com/2009/06/security-squared-4-part-series-on.html#comment-form" title="0 Comments" /><link rel="edit" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/1459727443996342115?v=2" /><link rel="self" type="application/atom+xml" href="http://www.blogger.com/feeds/24940037/posts/default/1459727443996342115?v=2" /><link rel="alternate" type="text/html" href="http://feedproxy.google.com/~r/idchaos/~3/uls2AJ46cjQ/security-squared-4-part-series-on.html" title="Security Squared: 4 Part Series on Converging Logical-Physical IAM" /><author><name>Brad Turner</name><uri>http://www.blogger.com/profile/13950085747222995199</uri><email>bradturner32@yahoo.com</email><gd:extendedProperty name="OpenSocialUserId" value="16147201446879994555" /></author><thr:total xmlns:thr="http://purl.org/syndication/thread/1.0">0</thr:total><feedburner:origLink>http://www.identitychaos.com/2009/06/security-squared-4-part-series-on.html</feedburner:origLink></entry></feed>
