question

DeanMaher-2819 avatar image
0 Votes"
DeanMaher-2819 asked DeanMaher-2819 commented

Creating Portal user inbound sync rule from LDAP

Hi I'm new to MiM 2016 . Try to learn so sorry for the newbie questions .

I wish to populate the MiM portal identity from a LDAP I have . I also wish to Filter (scope ) the entry I wish to create . to just a few users on my choosing . Employee Id = user1

I've done this via the MA projection Rule but I like to do it via 100% portal .
I've read in other forms this (MA projection Rule ) is sometimes the prefer way as the don't need Cals but I only want create the one that have Cal so this seem like a good way .

I came across this how to ,

https://docs.microsoft.com/en-us/previous-versions/mim/ee534911(v=ws.10)?redirectedfrom=MSDN

It's fim 2010

It for a Txt file, CRV

but should that matter ?

It 's should work the same using right LDAP MA , With similar attitudes and flow match

I just deleted my old LDAP MA and created and a new one .


ALL goes as it should , Searching CS and MV ,Nothing looks wrong . I'm seeing the Rule Added

Except when I do final export to MIM MA ( Fabrikam FIMMA in this doc ), the creation of the portal user

I don't see this

128039-export.gif

It all 0 . No Add , no error , and No user in the portal

How would one troubleshoot this issue ?


Any guidance would be helpful.



microsoft-identity-manager
export.gif (1.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LeoErlandsson avatar image
0 Votes"
LeoErlandsson answered DeanMaher-2819 commented

Hi,

That looks fine I think (except there's not projection). Really strange.

Try removing the inbound scope? You don't have any connector filters on the connector?

Also try manually syncing the sync rule in the MetaVerse (Full Sync, Commit on MIMMA).

Br,
Leo

· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Try removing the inbound scope? If I remove the scope , I going project 1500000 user to metaverse which isn't ideal . is there another way ?

There is No Connector filter on any MA . LDAP or MA

130178-image.png

130230-image.png


try manually syncing the sync rule in the MetaVerse (Full Sync, Commit on MIMMA). Can you clarify this statement , I'm not sure What to do


0 Votes 0 ·
image.png (89.3 KiB)
image.png (111.7 KiB)

Hi,

You can remove the inbound scope, and then just manually try to sync one user (as you did before). Remember to import the updates sync rule from the portal.
Or you can use connector filter (on your LDAP Connector!) to filter out the users you don't want in the connector space. This may require a FI and FS on the connector.


When I say manually sync the sync rule:
Go to MetaVerse Search, select the synchronizationRule object type. Then double click your inbound sync rule, select the MIMMA connector and do at Commit preview.

Br,
Leo

0 Votes 0 ·

Hi Leo

Thanks for pointing me in the right direction . It looks like I not able to scope one of my custom Ldap attitude .


Dean

0 Votes 0 ·
LeoErlandsson avatar image
0 Votes"
LeoErlandsson answered DeanMaher-2819 commented

Hi Dean,

There are several ways of filtering inbound users. One is an MA Projection Rule, as you say. Another way is a Connector Filter on the inbound MA. Yet another way is using a Scoped Sync Rule with an inbound scope.

Regarding CALs for the MIM Portal you'll need one for each managed user in the Portal. Either directly, or via Azure Premium.

The guide you're referring to is an old one, but should still work. And also for the LDAP Connector.

Could you please check what the user created in the MetaVerse looks like? What happens when you Generate Preview in the Sync for this user?

Br,
Leo
128221-2021-09-01-08-16-09-coor-mim2016-utv-172174850-fja.png



· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hi Leo

Sorry for the late reply , the end of last week was a blur .

Thanks for the info.

First I can't find this user in the Metaverse . Which Is kind excepted isn't the metaverse and portal are kind of one in the same . (Always been confused with this aspect )

Second when I search connector space on Ldap ma connect space and generate preview for that user , all I'm seeing is "Synchronization successful".
Can't find this user in Mim MA so can't generate preview

Hope I provided all info you requested






0 Votes 0 ·
LeoErlandsson avatar image
0 Votes"
LeoErlandsson answered DeanMaher-2819 edited

Hi,

Ok, so no projection is done from the Connector Space to the MetaVerse?

What does your Inbound Sync Rule look like?
Is Sync Rules enabled in Options in the Sync Engine?

What does the sync resuls from the preview look like (screenshot)?

Br,
Leo

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Ok, so no projection is done from the Connector Space to the MetaVerse? If not in the metaverse then I would have to agree

Here some screenshots of my rule

129839-image.png


129936-image.png


129943-image.png
129944-image.png

Is Sync Rules enabled in Options in the Sync Engine? YEs
129928-image.png

Here the Preview

!132008-image.png

131985-image.png


Thanks for your help . I've done most of these steps before , it's good to know I'm at lease looking in the right location




0 Votes 0 ·
image.png (56.2 KiB)
image.png (141.1 KiB)
image.png (39.6 KiB)