How to configure password synchronization between two Active Directory Domains with Microsoft Identity Manager PCNS? The 2019 Stack Overflow Developer Survey Results Are In Unicorn Meta Zoo #1: Why another podcast? Announcing the arrival of Valued Associate #679: Cesar Manara Come Celebrate our 10 Year Anniversary!synchronization of file locations between two machinesPassword Manager, integrated with Active DirectoryPassword expiration notice for Active Directoryactive directory servers synchronizationReplication of lockoutTime attribute is not urgent on AD-LDSHow to combine two Active Directory domainsSecurity-Kerberos Error, event ID 4Active Directory password policy for Business Days?Active Directory: LDAP over SSL between two DomainsHow to configure domain trust and DNS to share content with an external domain?
Did the new image of black hole confirm the general theory of relativity?
Sub-subscripts in strings cause different spacings than subscripts
Working through the single responsibility principle (SRP) in Python when calls are expensive
Word for: a synonym with a positive connotation?
Why don't hard Brexiteers insist on a hard border to prevent illegal immigration after Brexit?
Can each chord in a progression create its own key?
Why can't wing-mounted spoilers be used to steepen approaches?
How do I design a circuit to convert a 100 mV and 50 Hz sine wave to a square wave?
Are there continuous functions who are the same in an interval but differ in at least one other point?
"... to apply for a visa" or "... and applied for a visa"?
Huge performance difference of the command find with and without using %M option to show permissions
Drawing vertical/oblique lines in Metrical tree (tikz-qtree, tipa)
Windows 10: How to Lock (not sleep) laptop on lid close?
How to read αἱμύλιος or when to aspirate
How do you keep chess fun when your opponent constantly beats you?
Keeping a retro style to sci-fi spaceships?
What force causes entropy to increase?
Variable with quotation marks "$()"
What happens to a Warlock's expended Spell Slots when they gain a Level?
Using dividends to reduce short term capital gains?
How to support a colleague who finds meetings extremely tiring?
How do spell lists change if the party levels up without taking a long rest?
University's motivation for having tenure-track positions
What was the last x86 CPU that did not have the x87 floating-point unit built in?
How to configure password synchronization between two Active Directory Domains with Microsoft Identity Manager PCNS?
The 2019 Stack Overflow Developer Survey Results Are In
Unicorn Meta Zoo #1: Why another podcast?
Announcing the arrival of Valued Associate #679: Cesar Manara
Come Celebrate our 10 Year Anniversary!synchronization of file locations between two machinesPassword Manager, integrated with Active DirectoryPassword expiration notice for Active Directoryactive directory servers synchronizationReplication of lockoutTime attribute is not urgent on AD-LDSHow to combine two Active Directory domainsSecurity-Kerberos Error, event ID 4Active Directory password policy for Business Days?Active Directory: LDAP over SSL between two DomainsHow to configure domain trust and DNS to share content with an external domain?
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I have two domains with a two-ways trust relationship (selective authentication). Microsoft Identity Manager is installed, configured and "Password Change Notification Service" is configured and properly delivers password changes with RPC requests to the target FIMSyncronization Service (Kerberos authentication also working properly).
Two AD management agents are configured in MIM: One for the "source" domain and another one for the "target" domain.
Which attributes and join/projection rules need to be configured in order to allow password synchronization on "source" agent and "target" agent?
Official documentation is unclear on that matter and all examples on the Web don't give any hints regarding needed rules/attributes/mapping for password Synchronization.
Plus 'unicodePwd' attribute is write only in Active Directory and there doesn't seem to be any relevant attribute in Metaverse to store this password hash.
active-directory synchronization password-management microsoft-forefront
add a comment |
I have two domains with a two-ways trust relationship (selective authentication). Microsoft Identity Manager is installed, configured and "Password Change Notification Service" is configured and properly delivers password changes with RPC requests to the target FIMSyncronization Service (Kerberos authentication also working properly).
Two AD management agents are configured in MIM: One for the "source" domain and another one for the "target" domain.
Which attributes and join/projection rules need to be configured in order to allow password synchronization on "source" agent and "target" agent?
Official documentation is unclear on that matter and all examples on the Web don't give any hints regarding needed rules/attributes/mapping for password Synchronization.
Plus 'unicodePwd' attribute is write only in Active Directory and there doesn't seem to be any relevant attribute in Metaverse to store this password hash.
active-directory synchronization password-management microsoft-forefront
add a comment |
I have two domains with a two-ways trust relationship (selective authentication). Microsoft Identity Manager is installed, configured and "Password Change Notification Service" is configured and properly delivers password changes with RPC requests to the target FIMSyncronization Service (Kerberos authentication also working properly).
Two AD management agents are configured in MIM: One for the "source" domain and another one for the "target" domain.
Which attributes and join/projection rules need to be configured in order to allow password synchronization on "source" agent and "target" agent?
Official documentation is unclear on that matter and all examples on the Web don't give any hints regarding needed rules/attributes/mapping for password Synchronization.
Plus 'unicodePwd' attribute is write only in Active Directory and there doesn't seem to be any relevant attribute in Metaverse to store this password hash.
active-directory synchronization password-management microsoft-forefront
I have two domains with a two-ways trust relationship (selective authentication). Microsoft Identity Manager is installed, configured and "Password Change Notification Service" is configured and properly delivers password changes with RPC requests to the target FIMSyncronization Service (Kerberos authentication also working properly).
Two AD management agents are configured in MIM: One for the "source" domain and another one for the "target" domain.
Which attributes and join/projection rules need to be configured in order to allow password synchronization on "source" agent and "target" agent?
Official documentation is unclear on that matter and all examples on the Web don't give any hints regarding needed rules/attributes/mapping for password Synchronization.
Plus 'unicodePwd' attribute is write only in Active Directory and there doesn't seem to be any relevant attribute in Metaverse to store this password hash.
active-directory synchronization password-management microsoft-forefront
active-directory synchronization password-management microsoft-forefront
edited Feb 11 at 9:11
donmelchior
asked Feb 11 at 9:00
donmelchiordonmelchior
12
12
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
Typically, you would have a projection rule in your source MA to generate an object in the metaverse along with at least one import attribute flow to an indexed attribute - say sAMAccountName, employeeID, etc.
You would also have one join rule in your target MA, to link the target accounts to the metaverse objects created by your source MA.
Once the accounts are linked and the password synch service is notified of a new password, the password will be sent over to the target without any need for additional attribute flows.
New contributor
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f953313%2fhow-to-configure-password-synchronization-between-two-active-directory-domains-w%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
Typically, you would have a projection rule in your source MA to generate an object in the metaverse along with at least one import attribute flow to an indexed attribute - say sAMAccountName, employeeID, etc.
You would also have one join rule in your target MA, to link the target accounts to the metaverse objects created by your source MA.
Once the accounts are linked and the password synch service is notified of a new password, the password will be sent over to the target without any need for additional attribute flows.
New contributor
add a comment |
Typically, you would have a projection rule in your source MA to generate an object in the metaverse along with at least one import attribute flow to an indexed attribute - say sAMAccountName, employeeID, etc.
You would also have one join rule in your target MA, to link the target accounts to the metaverse objects created by your source MA.
Once the accounts are linked and the password synch service is notified of a new password, the password will be sent over to the target without any need for additional attribute flows.
New contributor
add a comment |
Typically, you would have a projection rule in your source MA to generate an object in the metaverse along with at least one import attribute flow to an indexed attribute - say sAMAccountName, employeeID, etc.
You would also have one join rule in your target MA, to link the target accounts to the metaverse objects created by your source MA.
Once the accounts are linked and the password synch service is notified of a new password, the password will be sent over to the target without any need for additional attribute flows.
New contributor
Typically, you would have a projection rule in your source MA to generate an object in the metaverse along with at least one import attribute flow to an indexed attribute - say sAMAccountName, employeeID, etc.
You would also have one join rule in your target MA, to link the target accounts to the metaverse objects created by your source MA.
Once the accounts are linked and the password synch service is notified of a new password, the password will be sent over to the target without any need for additional attribute flows.
New contributor
New contributor
answered Apr 8 at 14:27
FrancoisFrancois
1
1
New contributor
New contributor
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f953313%2fhow-to-configure-password-synchronization-between-two-active-directory-domains-w%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown