Book Image

Microsoft Identity Manager 2016 Handbook

By : David Steadman, Jeff Ingalls
Book Image

Microsoft Identity Manager 2016 Handbook

By: David Steadman, Jeff Ingalls

Overview of this book

Microsoft Identity Manager 2016 is Microsoft’s solution to identity management. When fully installed, the product utilizes SQL, SharePoint, IIS, web services, the .NET Framework, and SCSM to name a few, allowing it to be customized to meet nearly every business requirement. The book is divided into 15 chapters and begins with an overview of the product, what it does, and what it does not do. To better understand the concepts in MIM, we introduce a fictitious company and their problems and goals, then build an identity solutions to fit those goals. Over the course of this book, we cover topics such as MIM installation and configuration, user and group management options, self-service solutions, role-based access control, reducing security threats, and finally operational troubleshooting and best practices. By the end of this book, you will have gained the necessary skills to deploy, manage and operate Microsoft Identity Manager 2016 to meet your business requirements and solve real-world customer problems.
Table of Contents (22 chapters)
Microsoft Identity Manager 2016 Handbook
Credits
About the Authors
About the Reviewers
www.PacktPub.com
Preface
Index

Modifying MPRs for group management


There are less than a dozen Management Policy Rules (MPRs) that control how group objects can be modified by self-service, administrators, or the synchronization engine. But when it comes to group management, almost every MPR is disabled by default:

To start with, let's take a look at the distribution groups.

The Financial Company only wants employees to be able to create static distribution groups. The following steps will be required to allow that:

  1. Enable and change the MPR Distribution List management: Users can create Static Distribution Groups. The MPR allowing the creation of this type of group is Distribution List management: Users can create Static Distribution Groups:

  2. The set called All Active People is the default value of Requestor. We need to change that to All Employees, or confirm that we have employees only:

  3. Lets navigate over to the All Active People set and update the MPR to confirm that it only contains employees. As a note, we need to make...