<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:thr='http://purl.org/syndication/thread/1.0' version='2.0'><channel><atom:id>tag:blogger.com,1999:blog-12845360</atom:id><lastBuildDate>Fri, 30 Jul 2010 06:28:35 +0000</lastBuildDate><title>Identity Trench</title><description>A blog about Identity Integration, with a very large focus on Microsoft Identity Integration Server (MMS),(MIIS),(ILM), (ILM2), (FIM), (YETA) and identity in the Microsoft platform.</description><link>http://www.identitytrench.com/</link><managingEditor>noreply@blogger.com (Craig Martin)</managingEditor><generator>Blogger</generator><openSearch:totalResults>62</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-8825627279974867743</guid><pubDate>Tue, 20 Jul 2010 23:11:00 +0000</pubDate><atom:updated>2010-07-20T16:11:22.815-07:00</atom:updated><title>Favourable FIM Review</title><description>&lt;p&gt;If you are trying to sell FIM in your organization it helps to have some good reviews (not that FIM is hard to sell these days!).&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.infoworld.com/d/security-central/infoworld-review-microsoft-adfs-20-and-forefront-identity-manager-2010-387?page=0,0&amp;amp;source=rss_security_central"&gt;This review by InfoWorld&lt;/a&gt; is quite favourable.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-8825627279974867743?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/07/favourable-fim-review.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-7323536604924832623</guid><pubDate>Wed, 14 Jul 2010 22:15:00 +0000</pubDate><atom:updated>2010-07-14T15:15:27.687-07:00</atom:updated><title>This API supports the FIM 2010 infrastructure and is not intended to be used directly from your code.</title><description>&lt;p&gt;I’m a big fan of RTFM, and found myself a little confused by some of the MSDN documentation for FIM 2010.&lt;/p&gt;  &lt;p&gt;If you encounter this:&lt;/p&gt;  &lt;p&gt;&lt;em&gt;This API supports the FIM 2010 infrastructure and is not intended to be used directly from your code.&lt;/em&gt;&lt;/p&gt;  &lt;p&gt;It means the item isn’t officially supported.&amp;#160; You’re free to try it of course, and the item is likely used in the product internally but your mileage may vary.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-7323536604924832623?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/07/this-api-supports-fim-2010.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-3654387174316801368</guid><pubDate>Sun, 09 May 2010 19:36:00 +0000</pubDate><atom:updated>2010-05-09T12:36:18.628-07:00</atom:updated><title>TechNet Showcase Videos on FIM</title><description>&lt;p&gt;Oh my RTFM!&amp;#160; A series of &lt;a href="http://207.46.19.190/showcase/en/us/details/de30d488-c321-42f7-847c-90ac5ed05257"&gt;FIM How-To videos on TechNet&lt;/a&gt;!&lt;/p&gt;  &lt;p&gt;We had pretty good documentation when MIIS shipped, or at least I was pretty happy with the &lt;a href="http://go.microsoft.com/fwlink/?LinkId=34336"&gt;Walkthrough Guides&lt;/a&gt;.&amp;#160; For FIM the doc guys have really stepped up their game, which only makes me worse when dishing out the RTFMs :-|.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-3654387174316801368?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/05/technet-showcase-videos-on-fim.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-2428444786471481879</guid><pubDate>Sun, 09 May 2010 19:29:00 +0000</pubDate><atom:updated>2010-05-09T12:29:55.129-07:00</atom:updated><title>Cool video about FIM CM</title><description>&lt;p&gt;Stumbled upon this &lt;a href="http://www.tech-talks.com/managing-identities-with-forefront-identity-manager-2010-pki-and-hsms-webcast-fim-2010-certificate-management-with-thales-hardware-security-modules-ebook/"&gt;video about FIM CM today&lt;/a&gt;, it is cool to see CM get some attention in the huge FIM RTM splash.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-2428444786471481879?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/05/cool-video-about-fim-cm.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-3905012779097609826</guid><pubDate>Sat, 01 May 2010 20:51:00 +0000</pubDate><atom:updated>2010-05-01T13:51:30.407-07:00</atom:updated><title>Another Heckuva TEC</title><description>&lt;p&gt;Back from the TEC conference, oddly wishing it was a day or two longer.&amp;#160; There’s always so many great people to hang out with to trade stories with.&lt;/p&gt;  &lt;h3&gt;The Venue&lt;/h3&gt;  &lt;p&gt;No matter how much money I lose I always have fun in Vegas but this year’s venue was pretty sweet.&amp;#160; The hotel was gorgeous, which worked out really well since I didn’t stray far from it.&lt;/p&gt;  &lt;h3&gt;The Keynote&lt;/h3&gt;  &lt;p&gt;Opening with a video of the TEC chicken was hilarious, but even funnier was the quip from the audience when Gil announced the challenges to the speakers, “Build FIM with cardboard, duct tape and bailing wire” to which somebody piped up, “Isn’t that what Microsoft did?”.&amp;#160; Ouch indeed, but Conrad soon took the stage to introduce himself as the GM after a pretty big re-org.&amp;#160; My expectations are pretty high for the next major release, and I am confident they’ve organized in such a way to get there.&amp;#160; This will all be fun to track but the reality is that we are going to be very busy deploying FIM, and that subject is what really matters for us in the trenches of identity integration, right?&lt;/p&gt;  &lt;h3&gt;The Sessions&lt;/h3&gt;  &lt;p&gt;The conference was small as usual, and for FIM we had two tracks with no repeats which made for some tough choices sometimes.&amp;#160; My PowerShell session was so much fun to deliver I gave it another go on the last day.&lt;/p&gt;  &lt;p&gt;I missed Fred’s session on FIM Futures, but it will be one of the first ones I look for on YouTube, since everybody seemed to refer to it over and over again.&amp;#160; &lt;/p&gt;  &lt;p&gt;David Lundell offered up his regular guidance on FIM performance, and had some great tips for solving some of the challenges for the initial loading of the FIM service.&lt;/p&gt;  &lt;p&gt;Jeremy Palenchar and Gil had an awesome session that brought back memories of Mission Control.&amp;#160; They were able to demonstrate Request parsing whereby they could dig through the Requests in FIM to reproduce every change to an object in the service.&amp;#160; This has some huge potential, and one could easily argue that this should have been in the box.&lt;/p&gt;  &lt;p&gt;Gil demonstrated the &lt;a href="http://fimpscmdlets.codeplex.com/"&gt;PowerShell cmdlets by Quest built for FIM&lt;/a&gt;.&amp;#160; These are really cool, and I’ve already been able to use them as a workaround for a bug in the cmdlets shipped by the FIM team.&amp;#160; Way to go Gil!&lt;/p&gt;  &lt;p&gt;Jeremy Palenchar did another great session, kind of a part 2 to his Speech Server demo last year.&amp;#160; This year he demonstrated an Authentication WF with integration to Speech Server for self-service password reset.&amp;#160; There were two great things about this session:&lt;/p&gt;  &lt;p&gt;1. How cool to see FIM detect an account lockout then react by calling your phone to notify and prompt for a reset, all accomplished by phone?&lt;/p&gt;  &lt;p&gt;2. The FIM service is complex and it is easy to get overwhelmed by it.&amp;#160; Watching such an elegant demo reminds you that the FIM service can be even more powerful than complex.&lt;/p&gt;  &lt;h3&gt;Next Up&lt;/h3&gt;  &lt;p&gt;I was scrambling to put a session together for Wednesday, but I only found out days before that I even had the opportunity.&amp;#160; Unfortunately the session wasn’t ready, so it wouldn’t have been fair to any attendees to watch me fake it.&lt;/p&gt;  &lt;p&gt;The session topic is something I am quite passionate about, and people I’ve talked to seem to share my passion so next up I am going to propose this session:&lt;/p&gt;  &lt;h4&gt;Dev Tools for the IT Pro Deploying FIM&lt;/h4&gt;  &lt;p&gt;Each release of FIM brings increases in complexity and the product shifts focus farther away from the IT Pro into the realm of the Developer.&amp;#160; The time has come to embrace this shift by treating FIM deployments like the software developments they really are.&amp;#160; This session touches on methodology but stays rooted in fun tools and techniques.&lt;/p&gt;  &lt;p&gt;So, would you come to a session like that?&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-3905012779097609826?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/05/another-heckuva-tec.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-5985084360507840669</guid><pubDate>Tue, 13 Apr 2010 23:08:00 +0000</pubDate><atom:updated>2010-04-13T16:08:10.981-07:00</atom:updated><title>TechNet Virtual Lab for FIM 2010</title><description>&lt;p&gt;For those unable to download the big VHD for FIM2010, there is an alternative: a &lt;a href="https://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032449297&amp;amp;EventCategory=3&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;FIM 2010 VM lab hosted by Microsoft&lt;/a&gt;.&amp;#160; The caveat is plainly stated: they will follow up with a sales call.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-5985084360507840669?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/04/technet-virtual-lab-for-fim-2010.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-7776755390794457026</guid><pubDate>Sat, 27 Mar 2010 17:34:00 +0000</pubDate><atom:updated>2010-03-27T10:34:01.860-07:00</atom:updated><title>FIM Training – So Many Options</title><description>&lt;p&gt;&lt;a href="http://www.sqlsoft.com/Catalog/ForefrontIdentityManager.html?ref=AC.CurrentsEmail.20100309"&gt;SQLSoft has a neat little map of the available FIM training options&lt;/a&gt;.&amp;#160; It stands to reason there’d be lots of options given the size of FIM product.&amp;#160; It is great to see so much training content available, even though I’d prefer to see it broken down into feature areas such as:&lt;/p&gt;  &lt;ul&gt;   &lt;li&gt;FIM Service and Portal&lt;/li&gt;    &lt;li&gt;FIM Synchronization&lt;/li&gt;    &lt;li&gt;FIM Certificate Management&lt;/li&gt; &lt;/ul&gt;  &lt;p&gt;Of course I expect the lines to blur between these feature areas as they all become even more integrated in future releases, at least according my my personal crystal ball (not any official Microsoft plan of record).&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-7776755390794457026?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/03/fim-training-so-many-options.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-733121966140141173</guid><pubDate>Fri, 19 Mar 2010 07:24:00 +0000</pubDate><atom:updated>2010-03-19T00:24:59.062-07:00</atom:updated><title>Suppressing Full Sync Warnings with PowerShell</title><description>&lt;p&gt;Been browsing over the WMI reference for ILM lately and noticed something I hadn’t seen before:&lt;/p&gt;  &lt;p&gt;&lt;a href="http://msdn.microsoft.com/en-us/library/aa965248(VS.85).aspx"&gt;SuppressFullSyncWarning Method of the MIIS_ManagementAgent Class&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;This can be especially useful with FIM since the Sync Service gets versioned quite a bit more now that it lives in symbiosis with the FIM Service.&lt;/p&gt;  &lt;p&gt;Running this method on the MIIS_ManagementAgent WMI class will suppress those warnings but in the Identity Manager user interface and in the Event Log.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-733121966140141173?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/03/suppressing-full-sync-warnings-with.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-5032564718472853645</guid><pubDate>Fri, 05 Mar 2010 01:52:00 +0000</pubDate><atom:updated>2010-03-04T17:52:23.945-08:00</atom:updated><title>RunHistory Parsing</title><description>&lt;p&gt;In writing some scripts to dig out Sync errors lately I ran into a strange bug.&amp;#160; On the plus side, I wasn’t able to repro on FIM, just on ILM.&lt;/p&gt;  &lt;h3&gt;Issue&lt;/h3&gt;  &lt;p&gt;Running this command will eventually start to return null:&lt;/p&gt;  &lt;div id="codeSnippetWrapper"&gt;   &lt;div style="border-bottom-style: none; text-align: left; padding-bottom: 0px; line-height: 12pt; border-right-style: none; background-color: #f4f4f4; padding-left: 0px; width: 100%; padding-right: 0px; font-family: &amp;#39;Courier New&amp;#39;, courier, monospace; direction: ltr; border-top-style: none; color: black; font-size: 8pt; border-left-style: none; overflow: visible; padding-top: 0px" id="codeSnippet"&gt;     &lt;pre style="border-bottom-style: none; text-align: left; padding-bottom: 0px; line-height: 12pt; border-right-style: none; background-color: white; margin: 0em; padding-left: 0px; width: 100%; padding-right: 0px; font-family: &amp;#39;Courier New&amp;#39;, courier, monospace; direction: ltr; border-top-style: none; color: black; font-size: 8pt; border-left-style: none; overflow: visible; padding-top: 0px"&gt;&lt;font color="#0000ff"&gt;Get-WmiObject&lt;/font&gt; -Class &lt;font color="#8000ff"&gt;MIIS_RunHistory&lt;/font&gt; -Namespace &lt;font color="#8000ff"&gt;root/MicrosoftIdentityIntegrationServer&lt;/font&gt; -&lt;span style="color: #0000ff"&gt;filter&lt;/span&gt;(&lt;span style="color: #006080"&gt;&amp;quot;MaName='MyMA'&amp;quot;&lt;/span&gt;)&lt;/pre&gt;&lt;br /&gt;&lt;!--CRLF--&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;This is strange because the query doesn’t change, but eventually it will just stop working.&amp;#160; The cmdlet doesn’t report an error, it just stops returning results.&amp;#160; Once this happens the only way I am able to fix it is to restart the ‘Windows Management Infrastructure’ service.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3&gt;Workaround&lt;/h3&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Cycling the WMI service is a bit of a pain, so instead I issue the query using the MaGUID: &lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;div id="codeSnippetWrapper"&gt;&lt;br /&gt;  &lt;pre style="border-bottom-style: none; text-align: left; padding-bottom: 0px; line-height: 12pt; border-right-style: none; background-color: #f4f4f4; margin: 0em; padding-left: 0px; width: 100%; padding-right: 0px; font-family: &amp;#39;Courier New&amp;#39;, courier, monospace; direction: ltr; border-top-style: none; color: black; font-size: 8pt; border-left-style: none; overflow: visible; padding-top: 0px" id="codeSnippet"&gt;&lt;font color="#ff0000"&gt;$ma&lt;/font&gt; = &lt;font color="#0000ff"&gt;Get-WmiObject&lt;/font&gt; -Class &lt;font color="#8000ff"&gt;MIIS_ManagementAgent&lt;/font&gt; -Namespace &lt;font color="#8000ff"&gt;root/MicrosoftIdentityIntegrationServer&lt;/font&gt; -Filter(&lt;span style="color: #006080"&gt;&lt;font color="#800000"&gt;&amp;quot;Name='MyMA'&amp;quot;&lt;/font&gt;&lt;/span&gt;)&lt;br /&gt;&lt;font color="#0000ff"&gt;Get-WmiObject&lt;/font&gt; -Class &lt;font color="#8000ff"&gt;MIIS_RunHistory&lt;/font&gt; -Namespace &lt;font color="#8000ff"&gt;root/MicrosoftIdentityIntegrationServer&lt;/font&gt; -&lt;span style="color: #0000ff"&gt;filter&lt;/span&gt;(&lt;span style="color: #006080"&gt;&lt;font color="#800000"&gt;&amp;quot;MaGuid='&amp;quot;&lt;/font&gt;&lt;/span&gt; + &lt;font color="#ff0000"&gt;$ma&lt;/font&gt;.guid + &lt;span style="color: #006080"&gt;&lt;font color="#800000"&gt;&amp;quot;'&amp;quot;&lt;/font&gt;&lt;/span&gt;)&lt;/pre&gt;&lt;br /&gt;&lt;br /&gt;  &lt;br /&gt;Issuing the query using the MA Guid did not repro the problem.&amp;#160; A simple little workaround to a strange little problem. &lt;/div&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-5032564718472853645?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/03/runhistory-parsing.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-5948792866139141322</guid><pubDate>Wed, 03 Mar 2010 04:57:00 +0000</pubDate><atom:updated>2010-03-02T20:57:52.124-08:00</atom:updated><title>FIM 2010 RTM’d!</title><description>&lt;p&gt;Big day today, FIM 2010 RTM was announced at RSA.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://www.microsoft.com/downloads/details.aspx?displaylang=en&amp;amp;FamilyID=22731a2a-5b0f-4c6b-846a-e53588117981"&gt;Microsoft® Forefront™ Identity Manager 2010 Evaluation Version&lt;/a&gt;&lt;/p&gt;  &lt;p&gt;FIM is a very important release as it stands on the shoulders of the sync engine to provide a strong workflow engine along with new UI for both administrators and end users.&amp;#160; The sync engine has been an appliance that could largely hide in a datacenter until now.&amp;#160; In FIM Microsoft takes advantage of Microsoft Office to expose identity data to end users.&lt;/p&gt;  &lt;p&gt;FIM 2010 is a huge leap forward in terms of functionality and extensibility.&amp;#160; I’m happy to see RTM, and excited about what Microsoft and partners will build on top of this new platform.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-5948792866139141322?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/03/fim-2010-rtmd.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-1553381213288246773</guid><pubDate>Fri, 05 Feb 2010 21:10:00 +0000</pubDate><atom:updated>2010-02-05T13:14:58.166-08:00</atom:updated><title>Test Exchange Connectivity</title><description>&lt;p&gt;Stumbled upon a really cool Exchange troubleshooting tool. Could be handy when troubleshooting Exchange errors in FIM deployments.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_K8GDcegT6tc/S2yJ8ylu89I/AAAAAAAAACI/GjYcHp9m-hQ/s1600-h/Capture.JPG"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 400px; FLOAT: left; HEIGHT: 346px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5434870527794541522" border="0" alt="" src="http://4.bp.blogspot.com/_K8GDcegT6tc/S2yJ8ylu89I/AAAAAAAAACI/GjYcHp9m-hQ/s400/Capture.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;p&gt;&lt;a title="https://www.testexchangeconnectivity.com/" href="https://www.testexchangeconnectivity.com/"&gt;https://www.testexchangeconnectivity.com/&lt;/a&gt;&lt;/p&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-1553381213288246773?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/02/test-exchange-connectivity.html</link><author>noreply@blogger.com (Craig Martin)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_K8GDcegT6tc/S2yJ8ylu89I/AAAAAAAAACI/GjYcHp9m-hQ/s72-c/Capture.JPG' height='72' width='72'/><thr:total>2</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-2934014084297505119</guid><pubDate>Mon, 11 Jan 2010 23:19:00 +0000</pubDate><atom:updated>2010-01-11T15:19:48.206-08:00</atom:updated><title>FIM Group Management Competition</title><description>&lt;p&gt;Couldn’t resist posting a link to a demo of the &lt;a href="http://www.microsoft.com/liveatedu/student-email.aspx?locale=en-US&amp;amp;country=US#3"&gt;group management feature in Exchange 2010&lt;/a&gt;.&amp;#160; It raises the bar for group management demos at &lt;a href="http://tec2010.com/"&gt;TEC&lt;/a&gt; this year.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-2934014084297505119?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2010/01/fim-group-management-competition.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-3351237630757582159</guid><pubDate>Fri, 11 Dec 2009 03:35:00 +0000</pubDate><atom:updated>2010-02-03T15:07:50.557-08:00</atom:updated><title>Microsoft Acquisition of Sentillion</title><description>Very interesting, Microsoft intends to buy Sentillion. I worked on a project a few years ago where we used MIIS to sync with Sentillion.  &lt;br /&gt;  &lt;br /&gt;Wonder if this will drive FIM adoption in Healthcare.  &lt;p&gt;UPDATE: Seems like &lt;a href="http://news.softpedia.com/news/Microsoft-Amalga-to-Evolve-with-Sentillion-Identity-and-Access-Solutions-133907.shtml"&gt;Sentillion integration will make its way into FIM 2010 eventually&lt;/a&gt;.&lt;/p&gt;  &lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-3351237630757582159?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/12/microsoft-acquisition-of-sentillion.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>2</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-8370236321915041602</guid><pubDate>Fri, 20 Nov 2009 19:53:00 +0000</pubDate><atom:updated>2009-11-20T11:57:47.874-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>FIM</category><title>FIM 2010 SDK and IT Pro Docs</title><description>&lt;a href="http://msdn.microsoft.com/en-us/library/ee652263(VS.100).aspx"&gt;FIM 2010 SDK on MSDN&lt;/a&gt;&lt;br /&gt;I look in here all the time when trying to figure out the details on how things work in FIM, as well as looking into all the extensibility points.  For some reason I wasn't able to find this until just recently.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://technet.microsoft.com/en-us/library/cc626295.aspx"&gt;FIM 2010 IT Pro Docs on TechNet&lt;/a&gt;&lt;br /&gt;The IT Pro Docs on TechNet are really useful if you're new to FIM and want to try it out in your own lab.  Also handy to sanity checking your lab configurations.  The installation guide is especially handy.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-8370236321915041602?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/11/fim-2010-sdk-and-it-pro-docs.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-2603340496019053067</guid><pubDate>Fri, 20 Nov 2009 18:24:00 +0000</pubDate><atom:updated>2009-11-20T10:31:55.819-08:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>FIM Password WMI PowerShell</category><title>Troublshooting Password Resets</title><description>FIM Self-Service Password Reset makes use of the FIM Sync Service to deliver the passwords to Active Directory, as described in &lt;a href="http://blogs.technet.com/aho/archive/2009/11/09/forefront-identity-manager-credential-management-part-4.aspx"&gt;Anthony Ho's Blog&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;When troubleshooting you are probably going to be focusing on different product components:&lt;br /&gt;1. FIM Self-Service Password Reset Client Issues&lt;br /&gt;2. FIM Service Issues&lt;br /&gt;3. FIM Sync Issues&lt;br /&gt;&lt;br /&gt;If you've narrowed it down to #3 then it is handy to repro without having to constantly go through the SSPR gates. &lt;br /&gt;&lt;br /&gt;To troubleshoot FIM Sync password issues try using PowerShell to call WMI against the ADMA in question.  It will quickly tell you what the error is, allowing you to make configuration changes to test different options.&lt;br /&gt;&lt;br /&gt;T'here's a &lt;a href="http://msdn.microsoft.com/en-us/library/ms696061(VS.85,classic).aspx"&gt;WMI script in the MSDN Developer Reference for ILM&lt;/a&gt;, but if you look at the bottom of the page there is also a much shorter PowerShell script.&lt;br /&gt;&lt;br /&gt;Happy troubleshooting!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-2603340496019053067?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/11/troublshooting-password-resets.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-5422543059379279777</guid><pubDate>Fri, 18 Sep 2009 09:02:00 +0000</pubDate><atom:updated>2009-09-18T02:05:57.530-07:00</atom:updated><title>TEC 2010 - Got a speaker slot!</title><description>I'm honoured to have a speaking opportunity at &lt;a href="http://www.your-story.org/quest-software-announces-speakers-sessions-for-the-experts-conference-2010-32110/"&gt;TEC next year&lt;/a&gt;. Hopefully next year I won't lose my voice the night before sessions begin!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-5422543059379279777?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/09/tec-2010-got-speaker-slot.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-9179255793711731155</guid><pubDate>Fri, 17 Apr 2009 15:55:00 +0000</pubDate><atom:updated>2009-04-17T08:59:26.261-07:00</atom:updated><title>Out to Pasture</title><description>&lt;div&gt;Some might have noticed (hopefully) that the URL for my blog has changed. The advent of FIM and the passing of the domain name were motivation to change (the URL).&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;One last gasp though, because I love this logo!&lt;/div&gt;&lt;div&gt; &lt;/div&gt;&lt;a href="http://3.bp.blogspot.com/_K8GDcegT6tc/SeinNenPWYI/AAAAAAAAABo/mWIv15rtXkk/s1600-h/goat4.jpg"&gt;&lt;img id="BLOGGER_PHOTO_ID_5325690409363396994" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 320px; CURSOR: hand; HEIGHT: 142px" alt="" src="http://3.bp.blogspot.com/_K8GDcegT6tc/SeinNenPWYI/AAAAAAAAABo/mWIv15rtXkk/s320/goat4.jpg" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-9179255793711731155?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/04/out-to-pasture.html</link><author>noreply@blogger.com (Craig Martin)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_K8GDcegT6tc/SeinNenPWYI/AAAAAAAAABo/mWIv15rtXkk/s72-c/goat4.jpg' height='72' width='72'/><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-7969269558713845914</guid><pubDate>Wed, 15 Apr 2009 20:02:00 +0000</pubDate><atom:updated>2009-04-17T11:19:45.198-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>MIIS</category><category domain='http://www.blogger.com/atom/ns#'>FIM</category><category domain='http://www.blogger.com/atom/ns#'>ILM.MMS</category><title>ILM2 Renamed to Forefront Identity Manager 2010</title><description>Phew, the cat is out of the bag! MMS --&gt; MIIS --&gt; ILM --&gt; &lt;a href="http://social.technet.microsoft.com/Forums/en-US/ilm2/thread/e7c054c9-9a21-43ad-85c7-c66bfef8eef7"&gt;FIM&lt;/a&gt;&lt;br /&gt;(Couldn't resist a one-up to Brad's SmartArt)&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/_K8GDcegT6tc/SejIHCLRnAI/AAAAAAAAAB4/yLJhlsv2EX0/s1600-h/WhatsInAName.JPG"&gt;&lt;img id="BLOGGER_PHOTO_ID_5325726582534413314" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 476px; CURSOR: hand; HEIGHT: 174px" alt="" src="http://4.bp.blogspot.com/_K8GDcegT6tc/SejIHCLRnAI/AAAAAAAAAB4/yLJhlsv2EX0/s400/WhatsInAName.JPG" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;div&gt;&lt;a href="http://3.bp.blogspot.com/_K8GDcegT6tc/SejHygdeAsI/AAAAAAAAABw/SSo44LSYruY/s1600-h/WhatsInAName.JPG"&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;span style="color:#0066cc;"&gt;&lt;/span&gt;&lt;/u&gt;&lt;a href="http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032413570&amp;amp;EventCategory=4&amp;amp;culture=en-US&amp;amp;CountryCode=US"&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-7969269558713845914?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/04/ilm2-renamed-to-forefront-identity.html</link><author>noreply@blogger.com (Craig Martin)</author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_K8GDcegT6tc/SejIHCLRnAI/AAAAAAAAAB4/yLJhlsv2EX0/s72-c/WhatsInAName.JPG' height='72' width='72'/><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-8412866444687671761</guid><pubDate>Wed, 15 Apr 2009 03:38:00 +0000</pubDate><atom:updated>2009-04-14T20:39:20.607-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>TEC2009 ILM</category><title>TEC 2009 Decks Available</title><description>FYI - The decks from TEC2009 are available now:&lt;br /&gt;&lt;a href="http://jacksonshaw.blogspot.com/2009/04/tec-presentations-now-available.html"&gt;http://jacksonshaw.blogspot.com/2009/04/tec-presentations-now-available.html&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-8412866444687671761?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/04/tec-2009-decks-available.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-813553492728462981</guid><pubDate>Mon, 13 Apr 2009 18:51:00 +0000</pubDate><atom:updated>2009-04-13T11:59:56.714-07:00</atom:updated><title>YOU Can File HIGH Priority Bugs for ILM2 Too</title><description>At TEC I got to chat with somebody from the ILM team and learned something pretty neat.  Bugs filed on &lt;a href="http://connect.microsoft.com/"&gt;Connect &lt;/a&gt;are not just tossed aside, they actually make it into the ILM team's bug tracking system with high priority.  The reasoning is that bugs found while the product is in Release Candidate are customer facing bugs that need high priority. &lt;br /&gt;&lt;br /&gt;Enthusiasm here should be tempered, because AFAIK a bug of this priority can still fall victim to "won't fix" unless it has enough support.&lt;br /&gt;&lt;br /&gt;The moral of the story is: working with pre-release software is not easy (unless you're running Win7) but if bugs aren't filed then customers and the ILM team lose because those bugs won't get the attention they need.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-813553492728462981?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/04/you-can-file-high-priority-bugs-for.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-5374480948580167537</guid><pubDate>Mon, 13 Apr 2009 18:19:00 +0000</pubDate><atom:updated>2009-04-13T11:25:46.280-07:00</atom:updated><title>Exchange Labs MA and Certificate Authentication</title><description>Anybody using the Exchange Labs MA may have had a rough time with certificates since the only authentication supported by the MA in R2 was client certificate authentication.&lt;br /&gt;&lt;br /&gt;PowerShell is your friend when troubleshooting certificate issues.  For example, to verify the existence of the certificate in the correct store you could run this from the PowerShell command line:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;color:#33ff33;"&gt;Get-ChildItem  -path cert:\LocalMachine\Root   where {$_.subject -like '*thatschool*'}  fl&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Output from the command on my computer is:&lt;br /&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;Subject      : &lt;/span&gt;&lt;a href="mailto:E=ed-desk@microsoft.com"&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;E=ed-desk@microsoft.com&lt;/span&gt;&lt;/a&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;, CN=sapipartner.com, O=Oxford Computer Group thatschool.org, L=Snohomish, S=WA, C=US&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;Issuer       : CN=Microsoft Secure Server Authority, DC=redmond, DC=corp, DC=microsoft, DC=com&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;Thumbprint   : 49B71EE8925C4028150874C78E8B180E15C75FAD&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;FriendlyName : Oxford Computer Group thatschool.org&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;NotBefore    : 7/3/2008 7:39:46 AM&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;NotAfter     : 7/3/2009 7:39:46 AM&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;color:#33ff33;"&gt;Extensions   : {System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid, System.Security.Cryptography.Oid...}&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;What does that prove?  Well it proves that you've installed the certificate into the correct store so that ELMA can find it.  If you still get authentication errors then you've at least ruled this one out.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-5374480948580167537?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/04/exchange-labs-ma-and-certificate.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-5480481513803761235</guid><pubDate>Tue, 07 Apr 2009 17:42:00 +0000</pubDate><atom:updated>2009-04-07T10:46:29.139-07:00</atom:updated><category domain='http://www.blogger.com/atom/ns#'>PowerShell</category><title>PowerShell Breakpoints!!!</title><description>PowerShell is one of those things that is just too cool.  For the longest time I've been writing scripts, and when I run out of road with scripts I would resort to managed code.  The debugging environment for managed code is excellent with breakpoints and such, which is why I would tend to favour managed code.&lt;br /&gt;&lt;br /&gt;Today while fiddling with a PowerShell script I tried running it in the PowerShell ISE (Integrated Scripting Environment).  Had this sneaky little icon been named PowerShell IDE I might have clued in earlier.&lt;br /&gt;&lt;br /&gt;Anyhow, running scripts in here gives you the command line feel, but also gives you breakpoints if you want to stop a script mid-stride to analyze the environment and variables. &lt;br /&gt;&lt;br /&gt;AWESOME!&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-5480481513803761235?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/04/powershell-breakpoints.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-1350068363768938216</guid><pubDate>Sun, 29 Mar 2009 16:33:00 +0000</pubDate><atom:updated>2009-03-29T09:56:16.029-07:00</atom:updated><title>Heck of a TEC</title><description>Just got back from TEC (OK, I stayed in Vegas longer than I should have).  Given the economic turmoil I was worried the sessions would be empty and speakers absent but was very excited to see lots of people and a great crew of speakers.  Against the odds Gil, Stella and Christine put on a great show.&lt;br /&gt;&lt;br /&gt;The best analogy I have for TEC is the video for &lt;a href="http://en.wikipedia.org/wiki/No_Rain"&gt;"No Rain" from Blind Melon &lt;/a&gt;where that funky little bee-girl runs around seeminly confusing the snot out of people as she dances around dressed like a bee in tap shoes. Identity and Access is just like that, we spend all year telling people about it, customers eventually get it, relatives just smile, and spouses do their best, but at TEC we find ourselves surrounded by people speaking the same jargon even if their native language is different, our acronyms are harmonic.&lt;br /&gt;&lt;br /&gt;Somewhat absent was the ILM PG, likley constrained by scaled back travel budgets but I missed seeing them all there.  Hats off to Andreas and Mark for being on the front lines when the bad news of the ILM delay landed.  Those guys had a tough job last week facing all the customers and partners with fear, uncertainty and doubt.  &lt;a href="http://jacksonshaw.blogspot.com/2009/03/microsofts-ilm2-delay-hurts.html"&gt;Jackson's post on the delay &lt;/a&gt;nailed it.  This is going to be a tough year for ILM partners but shipping the wrong product would hurt even more.&lt;br /&gt;&lt;br /&gt;My TEC 2009 highlights:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;losing my voice the night before my sessions started&lt;/li&gt;&lt;li&gt;Craig (not me) getting booted from the casino&lt;/li&gt;&lt;li&gt;pre-con labs running perfectly, and no all-nighters!&lt;/li&gt;&lt;li&gt;I love Vegas, but my wallet tells a different story&lt;/li&gt;&lt;li&gt;great speakers, and recorded sessions so overlaps don't hurt&lt;/li&gt;&lt;/ul&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-1350068363768938216?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2009/03/heck-of-tec.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>2</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-790800612184751061</guid><pubDate>Fri, 03 Oct 2008 22:44:00 +0000</pubDate><atom:updated>2008-10-03T15:51:32.164-07:00</atom:updated><title>.NET Remoting with IIS and Kernel Mode Authentication</title><description>Working on an XMA lately I ran into an issue trying to use an object with .NET Remoting hosted on IIS7 (Windows Server 2008 x64).  Turns out that IIS7 has a feature called &lt;a href="http://technet.microsoft.com/en-us/library/cc771945.aspx"&gt;Kernel Mode Authentication&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;When .NET Remoting is configured to Negotiate the authentication type, it caused an error with the XMA.  Turning off Kernel Mode Authentication fixed the problem.&lt;br /&gt;&lt;br /&gt;Changing the authentication type probably would have worked too.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-790800612184751061?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2008/10/net-remoting-with-iis-and-kernel-mode.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>1</thr:total></item><item><guid isPermaLink='false'>tag:blogger.com,1999:blog-12845360.post-2100020493804028372</guid><pubDate>Thu, 11 Sep 2008 17:42:00 +0000</pubDate><atom:updated>2008-09-11T10:47:54.827-07:00</atom:updated><title>ILM 2 Beta3 Metadirectory Services with SQL 2008</title><description>Short blog post to note that I'm running SQL Server 2008 in a &lt;span style="color:#ff0000;"&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;LAB ENVIRONMENT&lt;/span&gt; &lt;/strong&gt;&lt;/span&gt;this week with ILM 2 Beta 3 Metadirectory Services. &lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="color:#ffff00;"&gt;I EXPECT THIS IS NOT SUPPORTED YET&lt;/span&gt;&lt;/strong&gt;, so don't try this at home.&lt;br /&gt;&lt;br /&gt;I expected the installation's SQL check to stop the installation but to my delight it passed.  Haven't hit any snags yet, using the ADMA, some file MAs and an XMA.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/12845360-2100020493804028372?l=www.identitytrench.com' alt='' /&gt;&lt;/div&gt;</description><link>http://www.identitytrench.com/2008/09/ilm-2-beta3-metadirectory-services-with.html</link><author>noreply@blogger.com (Craig Martin)</author><thr:total>0</thr:total></item></channel></rss>