Book Image

Microsoft Forefront Identity Manager 2010 R2 Handbook

By : Kent Nordstrom
Book Image

Microsoft Forefront Identity Manager 2010 R2 Handbook

By: Kent Nordstrom

Overview of this book

Microsoft's Forefront Identity Manager simplifies enterprise identity management for end users by automating admin tasks and integrating the infrastructure of an enterprise with strong authentication systems. The "Microsoft Forefront Identity Manager 2010 R2 Handbook" is an in-depth guide to Identity Management. You will learn how to manage users and groups and implement self-service parts. This book also covers basic Certificate Management and troubleshooting. Throughout the book we will follow a fictional case study. You will see how to implement IM and also set up Smart Card logon for strong administrative accounts within Active Directory. You will learn to implement all the features of FIM 2010 R2. You will see how to install a complete FIM 2010 R2 infrastructure including both test and production environment. You will be introduced to Self-Service management of both users and groups. FIM Reports to audit the identity management lifecycle are also discussed in detail. With the "Microsoft Forefront Identity Manager 2010 R2 Handbook" you will be able implement and manage FIM 2010 R2 almost effortlessly.
Table of Contents (21 chapters)
Microsoft Forefront Identity Manager 2010 R2 Handbook
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
8
Using FIM to Manage Office 365 and Other Cloud Identities
Afterword
Index

The environment


The following diagram gives you an overview of the relevant parts of infrastructure within The Company:

The servers you see do not in any way represent any scaling scenario, but rather show the different functions I will be using in my examples in this book.

In the following table, you will find a short summary of the systems involved, so that when they are referenced in the book later on, you will have an idea about their usage:

System

Usage

Products installed/to be installed

DC

Domain Controller for the Active Directory domain ad.company.com.

AD DS and DNS role installed.

CA

Enterprise Root Certification Authority. The Company uses only a one-layer PKI without any HSM.

AD CS, including Web Enrollment role, installed

SQL

Central Microsoft SQL Server used by many systems. Among these systems are the HR and Phone systems.

SQL Server 2008 R2, including Integration Services, installed.

MAIL

E-mail system.

Exchange 2010 installed.

RD

Remote Desktop system used by administrators.

Remote Desktop Services role installed.

TMG

The Company firewall.

Forefront Threat Management Gateway 2010 installed.

UAG

The remote access solution used by The Company.

Forefront Unified Access Gateway 2010 installed.

FIM-Dev

The test and development server for FIM.

SQL Server 2008 R2 and Visual Studio 2008. FIM Sync, Service and Portal will be installed.

FIM-Sync

The FIM Synchronization server.

FIM Synchronization Service will be installed.

FIM-Service

The FIM Web Service and Portal server.

FIM Service and FIM Portal will be installed.

FIM-CM

The FIM Certificate Management Server

FIM CM Service and Portal will be installed.

FIM-PW

The FIM Password Registration and Reset server.

FIM Password Registration and Reset will be installed.

SCSM-MGMT

SCSM Management Server. Used by FIM Reporting.

SQL Server 2008 R2 and System Center Service Manager will be installed.

SCSM-DW

SCSM Data Warehouse Server. Used by FIM Reporting.

SQL Server 2008 R2 and System Center Service Manager will be installed.

All systems have Microsoft Windows Server 2008 R2 as the operating system.

The products installed/to be installed show the status of the systems when we start our journey with The Company in this book. Details about the features and products already installed will be explained in Chapter 2, Installation.

The Active Directory domain within The Company is ad.company.com, using AD as the NetBIOS name. The public domain used by The Company is company.com; this is also the primary email domain used.