Creating Portal user inbound sync rule from LDAP

Dean Maher 71 Reputation points
2021-09-01T00:36:59.643+00:00

Hi I'm new to MiM 2016 . Try to learn so sorry for the newbie questions .

I wish to populate the MiM portal identity from a LDAP I have . I also wish to Filter (scope ) the entry I wish to create . to just a few users on my choosing . Employee Id = user1

I've done this via the MA projection Rule but I like to do it via 100% portal .
I've read in other forms this (MA projection Rule ) is sometimes the prefer way as the don't need Cals but I only want create the one that have Cal so this seem like a good way .

I came across this how to ,

https://learn.microsoft.com/en-us/previous-versions/mim/ee534911(v=ws.10)?redirectedfrom=MSDN

It's fim 2010

It for a Txt file, CRV

but should that matter ?

It 's should work the same using right LDAP MA , With similar attitudes and flow match

I just deleted my old LDAP MA and created and a new one .

ALL goes as it should , Searching CS and MV ,Nothing looks wrong . I'm seeing the Rule Added

Except when I do final export to MIM MA ( Fabrikam FIMMA in this doc ), the creation of the portal user

I don't see this

128039-export.gif

It all 0 . No Add , no error , and No user in the portal

How would one troubleshoot this issue ?

Any guidance would be helpful.

Microsoft Identity Manager
Microsoft Identity Manager
A family of Microsoft products that manage a user's digital identity using identity synchronization, certificate management, and user provisioning.
617 questions
0 comments No comments
{count} votes

Accepted answer
  1. Leo Erlandsson 1,656 Reputation points
    2021-09-08T06:08:47.657+00:00

    Hi,

    That looks fine I think (except there's not projection). Really strange.

    Try removing the inbound scope? You don't have any connector filters on the connector?

    Also try manually syncing the sync rule in the MetaVerse (Full Sync, Commit on MIMMA).

    Br,
    Leo


2 additional answers

Sort by: Most helpful
  1. Leo Erlandsson 1,656 Reputation points
    2021-09-01T06:16:59.517+00:00

    Hi Dean,

    There are several ways of filtering inbound users. One is an MA Projection Rule, as you say. Another way is a Connector Filter on the inbound MA. Yet another way is using a Scoped Sync Rule with an inbound scope.

    Regarding CALs for the MIM Portal you'll need one for each managed user in the Portal. Either directly, or via Azure Premium.

    The guide you're referring to is an old one, but should still work. And also for the LDAP Connector.

    Could you please check what the user created in the MetaVerse looks like? What happens when you Generate Preview in the Sync for this user?

    Br,
    Leo
    128221-2021-09-01-08-16-09-coor-mim2016-utv-172174850-fja.png


  2. Leo Erlandsson 1,656 Reputation points
    2021-09-07T14:59:52.183+00:00

    Hi,

    Ok, so no projection is done from the Connector Space to the MetaVerse?

    What does your Inbound Sync Rule look like?
    Is Sync Rules enabled in Options in the Sync Engine?

    What does the sync resuls from the preview look like (screenshot)?

    Br,
    Leo