For users to be able to log in to the MIM portal and authenticate to MIM Service, we need three attributes populated for the user: AccountName
, Domain
, and ObjectSID
.
But even if we have populated these attributes in MIM Service, and a standard user tries to log in to the portal (https://MIMPortal/IdentityManagement
), the person will get the message shown in the following screenshot:
Why? Well, because there is no MPR enabled by default to allow users to access MIM Portal and/or MIM Service. The MPRs required to allow access to users are disabled by default. We just need to enable them in order for users to have access.
The MPRs we need to enable are as follows:
General: Users can read non-administrative configuration resources
User management: Users can read attributes of their own
Moreover, if you look back, you might recall that we had some options during installation talking about user access as well. There was a checkbox that said Grant Authenticated Users...