For users to be able to log in to the FIM portal and authenticate to the FIM Service, we need, as I said before, three attributes populated for the user—AccountName
, Domain
, and ObjectSID
.
But even if we have populated these attributes in FIM Service and a standard user tries to log in to the portal (https://FIMPortal/IdentityManagement) he will get the message shown in the following screenshot:
Why? Well because there is no MPR enabled, by default, to allow users to access the FIM portal and/or FIM Service. The MPRs required allowing access to users is disabled by default. We just need to enable them in order for users to have access.
The MPRs we need to enable are as follows:
General: Users can read non-administrative configuration resources
User management: Users can read attributes of their own
Also if you look back, you might recall that we had some options during installation talking about user access as well. It was a checkbox with Grant Authenticated...