Using Microsoft Identity Manger with SharePoint 2016 to fill the User Profile Sync Gap Max Fritz Senior Systems Consultant Now Micro.

Slides:



Advertisements
Similar presentations
Agenda 2 factor authentication Smart cards Virtual smart cards FIM CM
Advertisements

Service Manager for MSPs
Office 365 Identity June 2013 Microsoft Office365 4/2/2017
Agenda AD to Windows Azure AD Sync Options Federation Architecture
Core identity scenarios Federation and synchronization 2 3 Identity management overview 1 Additional features 4.
SP 2013 User Profile Service Overview Connecting your Profile to the Portal.
Configuring SharePoint 2013 and Office 365 Hybrid – Part 1
Whether you like it or not! Importance increases significantly with SharePoint 2013 Pretty much every investment area relies on Profiles for core.
Installation and Deployment in Microsoft Dynamics CRM 4.0
RequirementsDeployment Options 2 3 Dirsync Overview 1 Understanding Synchronization 4.
Acceleratio Ltd. is a software development company based in Zagreb, Croatia, founded in Acceleratio specializes in developing high-quality enterprise.
Identity management integration options for Office 365
Internet, 16 July 2014 Predica bag of (FIM)tricks Tomasz Onyszko
Understanding Active Directory
Microsoft ® Official Course Module 9 Configuring Applications.
OM. Brad Gall Senior Consultant
First Look Clinic: What’s New for IT Professionals in Microsoft® SharePoint® Server 2013 Sayed Ali (MCTS, MCITP, MCT, MCSA, MCSE )
© 2011 PLANET TECHNOLOGIES, INC. Extending User Profiles with Line of Business Data Patrick Curran, MCT FEBRUARY 24, 2013.
Module 8 Configuring and Securing SharePoint Services and Service Applications.
Single Sign-On with Microsoft Azure
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
4. Managing the Desktop Thomas Lee Chief Technologist – QA plc.
Module 14: Migrating Users from Exchange Server 5.5 to Exchange Server 2003.
System Center & SharePoint On- Prem Matija Blagus, Acceleratio
Intro to Datazen.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
Integrating Active Directory with eDirectory ™ Using Novell Account Manager Reid Oakes Technical Team Manager Novell, Inc.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Three Managing Recipients.
Office 365: SharePoint Online 31 May | SharePoint Saturday Calgary – 31 MAY 2014 About Me – Jason Kaczor
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
 Step 2 Deployment Overview  What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Understanding.
 What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Demo.
Productivity Architect Meet Chris Bortlik Author, Blogger, Speaker.
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
Follow OCG Learning Twitter Facebook LinkedIn
Planning, Implementing and Supporting Office 365
Recording Brief EMS Partner Bootcamp Variables Values Module Title
Microsoft Azure Active Directory Identity Solutions
By: Toby McGrail Sr. Software Engineer
SQL Server PowerPivot for IT Pros
Max Fritz Senior Systems Consultant, Now Micro
Assignment # 8.
A Hitchhiker's Guide to Azure Active Directory
SharePoint Hybrid Capabilities
Get to know SQL Manager SQL Server administration done right 
Microsoft - Managing Office 365 Identities and Requirements
Microsoft Virtual Academy
Directory Synchronization in Office 365
Power BI Security Best Practices
Leverage your on-premise investments with cloud innovation
SharePoint Online Management and Control
Dev Test on Windows Azure Solution in a Box
SPC2012 – IT-Pro 11/19/2018 © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Hybrid Search Planning Implementation.
PSC Group, LLc Office 365/SharePoint Online Migration traps and tricks
05 | AD to Windows Azure AD IT Professionals
Microsoft Ignite /20/2018 2:21 PM
SharePoint Online Hybrid – Configure Outbound Search
M7: New Features for Office 365 Identity Management
Office 365 Identity Management
Matthew Levy Azure AD B2B vs B2C Matthew Levy
SharePoint 2016 in MIM 2016 Robi Vončina Kompas Xnet.
2/27/2019 © 2014 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks and/or trademarks.
Office 365 Identity Management
10 | Implementing Directory Synchronization
Preparing for the Windows 8. 1 MCSA Module 6: Securing Windows 8
SysKit Security Manager
Presentation transcript:

Using Microsoft Identity Manger with SharePoint 2016 to fill the User Profile Sync Gap Max Fritz Senior Systems Consultant Now Micro

Max Fritz Senior Consultant MCSA Office 365, MCSE Productivity Founder/President of Minnesota Office 365 User Group Working with Office 365 for over 6 years Specialize in the Education & Government Industries Focus in Azure AD, Exchange, and SharePoint Online Contact Details Email : maxf@nowmicro.com Twitter : @TheCloudSherpa Blog: maxafritz.com LinkedIn : in/maxafritz

Agenda User Profile Sync Overview Microsoft Identity Manager Overview History Setup Configuration

What is (was) SharePoint User Profile Sync? A way for user properties to be synchronized to SharePoint from Active Directory (and back) Department, Description, Profile Picture, Phone, etc… Allows that information to be accessed within SharePoint, and synchronized back to active directory In 2010-2013, SharePoint uses a lightweight, built in, version of FIM One of the most frustrating services within SharePoint

What is Microsoft Identity Manager? Successor to Forefront Identity Manager Introduced in 2016 Manage the users, credentials, policies, and access within your organization Provide self service group management and user properties management through a web interface Synchronize identities across platforms Privileged Access Management for administrator accounts

History Lesson

SharePoint User Profile Sync History Import from AD SharePoint 2010 Built in FIM SharePoint 2013 AD Import SharePoint 2016

SharePoint User Profile Sync History 2010: SharePoint got together with FIM team Built a lightweight version of FIM for use in SharePoint Required a lot of maintenance Failed to start constantly All around frustrating SharePoint 2007 Import from AD SharePoint 2010 Built in FIM SharePoint 2013 AD Import SharePoint 2016

SharePoint User Profile Sync History 2013: Oops Built in FIM didn’t work so well Introduced AD Import Easier to configure and run Less features Kept Built in FIM as an option SharePoint 2007 Import from AD SharePoint 2010 Built in FIM SharePoint 2013 AD Import SharePoint 2016

SharePoint User Profile Sync History 2016: AD Import extremely popular in 2013 Led to the removal of Built in FIM completely Those who need FIM features can deploy MIM Easier to manage when it’s deployed separately SharePoint 2007 Import from AD SharePoint 2010 Built in FIM SharePoint 2013 AD Import SharePoint 2016

MIM vs Active Directory Import (ADI) With SharePoint 2013 or 2016 Pros Flexibility allows for customized import. Can be customized for bidirectional flow. Imports user profile photos automatically. Supports non-Active Directory LDAP sources. Multi-forest scenarios are supported. Very fast and performant. Known to be reliable (used by Office 365). Configurable inside of Central Administration. (Less complex.) Cons A separate MIM server is recommended for use with your SharePoint farm. The more customized the more complex the architecture, deployment, and management. Import is unidirectional (changes go from Active Directory to SharePoint Server Profile). Import from a single Active Directory forest only. Does not import user photos. Supports Active Directory LDAP only. Multi-forest scenarios are not supported.

Deploying MIM 2016 One of the more difficult tools to deploy from Microsoft They failed to take the “F” out of “FIM” Windows Server 2012 R2 or higher .NET 3.5 Requires a SQL 2012 SP2 or higher Can exist on the same server If on separate server, install SQL Server native client Can use a separate installation of SharePoint 2013 single server Must be installed on the same server Required to use the MIM portal (self service features)

Deploying MIM 2016 Version: Install MIM 2016 with Service Pack 1 Accounts Service Account for MIM Log on as a service and Run as a service permissions on the server (automatically assigned) (make sure they don’t get overwritten by a GPO!) Domain user for AD Connector Replicate Directory Changes, Create Child Objects, and Write all properties permissions Install Account SQL Server Admin & Local Admin on server

MIM Installation Demo Setup Service Accounts/Groups Add .NET 3.5 Install SQL Server Native Client Install MIM MIM Installation Demo

MIM Setup & Configuration Management Agents MIM uses Management Agents to connect to identity resources and endpoints We will need to use the built in Active Directory Management Agent (ADMA) and the downloadable SharePoint Management Agent (SPMA) Solution Files Available from GitHub Allows easy configuration of the SharePoint synchronization and Management Agent

What is synced by default from AD? name department description displayName givenName mail manager member thumbnailPhoto physicalDeliveryOfficeName msDS-PhoneticDisplayName msDS-PhoneticFirstName msDS-PhoneticLastName proxyAddresses telephoneNumber title wWWHomePage

01 02 03 04 Extra Configuration Filter users from AD Scheduling the synchronization 02 Determining user profile picture flow direction 03 Advanced/custom attribute sync 04

MIM & SharePoint Configuration Demo Install SPMA Configure SharePoint Configure SPMA and ADMA Test Sync Schedule Sync MIM & SharePoint Configuration Demo

Questions ?

Thank you! Please fill out the survey on your app Come ask me questions and stay in touch @theCloudSherpa