Whether you like it or not! Importance increases significantly with SharePoint 2013 Pretty much every investment area relies on Profiles for core.

Slides:



Advertisements
Similar presentations
Implementing Tableau Server in an Enterprise Environment
Advertisements

©2012 Microsoft Corporation. All rights reserved. Content based on SharePoint 15 Technical Preview and published July 2012.
Core identity scenarios Federation and synchronization 2 3 Identity management overview 1 Additional features 4.
SP 2013 User Profile Service Overview Connecting your Profile to the Portal.
Configuring SharePoint 2013 and Office 365 Hybrid – Part 1
DEV392: Extending SharePoint Products And Technologies Through Web Parts And ASP.NET Clint Covington, Program Manager Data And Developer Services - Office.
Federated sign-in WS-Federation WS-Trust SAML 2.0 Metadata Shibboleth Graph API Synchronize accounts Authentication.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
Welcome to the Minnesota SharePoint User Group November 11 th, 2009 SharePoint 2010 Administration Wes Preston, Brian Caauwe.
Internet, 16 July 2014 Predica bag of (FIM)tricks Tomasz Onyszko
7.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 7: Introducing Group Accounts.
3.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 3: Introducing Active Directory.
©2012 Microsoft Corporation. All rights reserved..
Understanding Active Directory
Vikram Thakur Introduction to Active Directory Structure.
TechEd /20/2017 2:02 AM © 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
Manage & Configure SQL Database on the Cloud Haishi Bai Technical Evangelist Microsoft.
Microsoft ® Official Course Module 9 Configuring Applications.
Windows Server 2008 Chapter 4 Last Update
© 2011 PLANET TECHNOLOGIES, INC. Augmenting User Profiles with Line of Business Data Patrick Curran, MCT APRIL 28, 2012.
Migration XenDesktop 7. © 2013 Citrix | Confidential – Do Not Distribute Migration prerequisites Set up a XenDesktop 7 Site, including the site database.
Chapter-4 Windows 2000 Professional Win2K Professional provides a very usable interface and was designed for use in the desktop PC. Microsoft server system.
© 2011 PLANET TECHNOLOGIES, INC. Extending User Profiles with Line of Business Data Patrick Curran, MCT FEBRUARY 24, 2013.
Module 8 Configuring and Securing SharePoint Services and Service Applications.
New SharePoint 2016 Features
Module 7 Active Directory and Account Management.
Microsoft ® Official Course Module 13 Implementing Windows Azure Active Directory.
Module 10 Administering and Configuring SharePoint Search.
Module 11: Read-Only Domain Controllers. Overview Describe the Read-Only Domain Controllers role Use Read-Only Domain Controllers.
1 Chapter Overview Performing Configuration Tasks Setting Up Additional Features Performing Maintenance Tasks.
Paul Andrew. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
4. Managing the Desktop Thomas Lee Chief Technologist – QA plc.
0 SharePoint Search 2013 Rafael de la Cruz SharePoint Developer Seneca Resources twitter.com/delacruz_rafael
Section 11: Implementing Software Restriction Policies and AppLocker What Is a Software Restriction Policy? Creating a Software Restriction Policy Using.
Module 12 Integrating Exchange Server 2010 with Other Messaging Systems.
Chapter 10: Rights, User, and Group Administration.
Module 7 Planning and Deploying Messaging Compliance.
Module 1: Implementing Active Directory ® Domain Services.
Windows SharePoint Services Managing users and rights.
Copyright © 2006 Pilothouse Consulting Inc. All rights reserved. Search Overview Search Features: WSS and Office Search Architecture Content Sources and.
Administering Groups Chapter Eight. Exam Objectives In this Chapter:  Plan a security group hierarchy based upon delegation requirements  Plan a security.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
SkyDrive Pro Personal Timeline Editable and automatically color coded by project Important tasks Tasks you’ve marked as top of mind.
Introduction to Active Directory
Exchange Hybrid: Deployment, best practices, and what’s new
Microsoft ® Official Course Module 9 Working with Business Connectivity Services.
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Active Directory Domain Services (AD DS). Identity and Access (IDA) – An IDA infrastructure should: Store information about users, groups, computers and.
Managing Office 365 Identities and Requirements Question Answer
Productivity Architect Meet Chris Bortlik Author, Blogger, Speaker.
User Profile Synchronization Service
By: Toby McGrail Sr. Software Engineer
Max Fritz Senior Systems Consultant, Now Micro
Implementing Active Directory Domain Services
6/24/ :40 AM BRK4042 User profile synchronization with Identity Manager and SharePoint Server 2016 Spencer Harbar Enterprise Architect © Microsoft.
Business Connectivity Services in SharePoint 2010 and Office 2010
Using Microsoft Identity Manger with SharePoint 2016 to fill the User Profile Sync Gap Max Fritz Senior Systems Consultant Now Micro.
Exam in just 24 hours!!! Pass your exam in first attempt by the help of our latest braindumps
MCSA VCE
Migration to SharePoint 2013
SPC2012 – IT-Pro 11/19/2018 © 2012 Microsoft Corporation. All rights reserved. Microsoft, Windows, and other product names are or may be registered trademarks.
SharePoint 2019 Changes Point of View.
Hybrid Search Technical Guidance.
PSC Group, LLc Office 365/SharePoint Online Migration traps and tricks
What’s changed in the Shibboleth 1.2 Origin
What's New in SharePoint Server 2019
SharePoint 2016 in MIM 2016 Robi Vončina Kompas Xnet.
James Cowling Senior Technical Architect
9/8/ :03 PM © 2006 Microsoft Corporation. All rights reserved.
Presentation transcript:

Whether you like it or not! Importance increases significantly with SharePoint 2013 Pretty much every investment area relies on Profiles for core functionality App AuthZ, S2S, etc Primarily a political endeavor, NOT a technical one No toolset from any vendor will change this

Especially when Active Directory is externally managed e.g. Reboot of domain controllers, Windows Update Large and/or bulk updates Replicating Directory Changes Additional rights for property export

One of the most common causes of weak deployments, limited functionality and upgrade pain Federate or replicate? Central farms, regional farms, both? Relationship with other services

Security Privacy Policy Operations SQL Server Distributed Cache SharePoint Server Search Managed Metadata Business Data Connectivity

Large organizations should be able to perform a full sync of AD and SharePoint data over a weekend IT Pros should be able to monitor the performance and stability of profile sync and have access to the information that they need to take corrective action when problems occur Common Directory Service configurations should be supported, including Forefront Identity Manager and LDAP

Lightweight LDAP approach internal to SharePoint a.k.a Direct AD Import Embedded Forefront Identity Manager Same approach as SP2010 with improvements “under the hood” External Forefront Identity Manager using the SharePoint Connector Custom Code: User Profiles Web Services and Object Model

SharePoint User Profile Service Application UPS (SharePoint FIM) BCS External System Active Directory ADI (User Profile Service Instance) EIM (External FIM) EIM (Custom Code) Directory

Farm Configuration Wizard (just kidding ) Via Manage Service Applications The default schema issue

Farm Account default schema set incorrectly in Sync DB We will never be able to start the UPS service instance Log on as the Farm Account and execute the PowerShell Fix the schema manually – an unsupported change

Non UAC environmentsUAC Environments Just use this one! Both simulate interactive logon as the Farm account (Log on Locally) Both require Local Machine Administrator

For the most common scenario (AD forest) Import Only! Container selection LDAP filters Inclusion Based One connection per domain That could be a lot of connections!

a.k.a Shadow AccountsFor simple data typesAs SharePoint 2010

Leverages a change log to drive import efficiency DirSyncRequestControl is scoped at the domain level Implement immediately after creating the UPA! Replicating Directory Changes also required on the Configuration partition

You can modify the properties of the UPA to configure Active Directory Import via Windows PowerShell

Central Administration UI can be misleading when creating connections after changing the mode. You don’t need to worry about BCM for the Sync DB! It must exist, but it IS supported to mirror/log ship an empty database

For AD Import only, these cmdlets are NOT supported for UPS Known Issues with Remove-SPProfileSyncConnection only removes the organizational unit (OU) from the profile synchronization connection Fix:

Those that begin with SPS-

Maximum flexibility With great power comes great responsibility Sweet UI! As opposed to exclusion based with UPS Validate your filters with ADSIEdit Just because you can, doesn’t mean you should

Adding or removing OUs Filter changes Property mappings To clean up profiles which are not created as part of the import Profiles are marked for deletion

Adding or removing OUs Filter changes Property mappings To clean up profiles which are not created as part of the import Profiles are marked for deletion

Manual recreation required Or use an XML based provisioning approach

Understand the design constraints Document the configuration!!! Run PurgeNonImportedObjects after a full import to remove items that should not be there

Ships as external download Support for SharePoint Server 2013 now Support for SharePoint Server 2010 in testing Requires FIM 2010 R2 SP1 You need to create and use a metaverse rules extension You may not be able to migrate your existing data Only FIM Sync Service needed

HR SQL Database

Impacts pretty much every product feature e.g. organic growth of domains and/or forests

Sponsored by