Today, March 2, at the RSA conference Microsoft announced the release to manufacturing of Forefront Identity Manager 2010 (FIM, formerly codenamed ILM “2”) with General Availability starting next month.
Download the eval here:
FIM gives us capabilities for User provisioning (and deprovisioning), Group management, Self-Service Password Reset, Password Synchronization, Workflows with Approvals, User profile self-service management, and accomplishing these items through Declarative Provisioning. Yet FIM retains an incredible set of extensibility points, allows customization of the Portal, schema of the objects, managing new systems, custom workflows, custom clients to the FIM web service.
According to the release notes there are some nice new enhancements:
You can now have explicit members in a set which has a defined filter (so sets can have dynamic members based on the filter and explicitly added members).
Password Reset now accepts the user principal name (UPN) as well as the fully qualified domain name (FQDN) when specifying user credentials
Adds support for SQL Server Failover Clusters for High Availability
New type of MPR (Set based Transition vs. Request based)
· Adds support for taking database backups without stopping the FIM Service.
· New Supported Platforms for FIM Certificate Management
· Windows Server 2008 R2
· Windows Server Datacenter edition
· Added support for Exchange 2010 for the following scenarios:
· FIM Synchronization Service support for Active Directory Management Agent and GAL Management Agent
· The FIM Service sending and receiving mail
· Outlook 2007 on Exchange 2010 sending approvals and group membership requests
· You can now copy and paste a vertical list from Excel to the Resource Picker input box. This is especially useful for doing bulk Adds.
· The UOC text box now lets you check uniqueness using a custom XPATH statement that you provide.
The FIMMA will now store error messages with the operation during export. You do not have to look in the FIMService event log anymore to see the errors.
You can now have several MAs that are responsible for deleting a resource, which solves a common problem where custom code still was needed for declarative provisioning.
· Added two new Declarative provisioning functions:
· Null – This Synchronization Rule should not contribute a value to support not flowing values to disabled accounts.
· ReplaceString – Find and replace a substring in another string
Added support for Exchange 14 mailbox provisioning