Monday, May 30, 2011

"The breakpoint will not currently be hit. No symbols have been loaded for this document." when debugging FIM 2010 Code in VS2008/2010

I have been running into situations where I tried to debug some FIM MA and MV extension code in VS2008/2010 and hit the "The breakpoint will not currently be hit. No symbols have been loaded for this document." problem even though I was:
  • Correctly attaching to the "miiserver.exe" process

  • Setting breakpoint that would be hit
  • Manually forcing a Debugger.Launch()
  • Not running the code in a separate process
  • Running VS2008/2010 in Administrator context.
When i started looking at the problem more closely I remembered a similar problem with MIIS pre- SP1 that occurred once framework 2.0 was installed and the MIIServer.exe.config was not forces to run in Framework 1.1. So I had two choices, either force the framework or change my compiling framework to 3.0-3.5 which is natively supported by FIM 2010.

So my initial VS advanced compiling configuration looked as follows:

Once I changed the settings to the settings below, and recompiled the code I was able to debug my code with no issues.

Monday, February 14, 2011

"The Forefront Identity Manager Service has not started yet." errors when trying to do a password reset you via the FIM 2010 Password Portal

When trying to do a password reset from the FIM Password Portal you get the following error: "The Forefront Identity Manager Service has not started yet."

This error is mostly caused by the Forefront Identity Manager Password Reset Client Service (FIMPasswordReset) service not being started. This can be easily remedied by starting the service. However, if you have verified that the service is running on the workstation you are trying to do the reset from, there could be a problem with the IE zone and protected mode setting for the Local Intranet Zone.
Please note that you need to make sure that the site is running under a "Local Intranet" zone and that Protected mode is switched OFF.

A configuration as shown below will cause the error as the ActiveX component cannot check the service status if incorrectly configured, and generates the error in question.
Applying the defaults zone settings to the Local Intranet Zone should allow the components to run as expected

Thursday, January 27, 2011

Error: The WinRM client received an HTTP status code of 456 from the remote WS-Management service


When connect to an Outlook Live Powershell session you get:
[ps.outlook.com] Connecting to remote server failed with the following error message : The WinRM client received an HTTP status code of 456 f
rom the remote WS-Management service. For more information, see the about_Remote_Troubleshooting Help topic.
    + CategoryInfo          : OpenError: (System.Manageme....RemoteRunspace:RemoteRunspace) [], PSRemotingTransportException
    + FullyQualifiedErrorId : PSSessionOpenFailed
Import-PSSession : Cannot validate argument on parameter 'Session'. The argument is null. Supply a non-null argument and try the command again.
At line:3 char:17
+ Import-PSSession <<<<  $Session
    + CategoryInfo          : InvalidData: (:) [Import-PSSession], ParameterBindingValidationException
    + FullyQualifiedErrorId : ParameterArgumentValidationError,Microsoft.PowerShell.Commands.ImportPSSessionCommand
or

When trying to run the Outlook Live MA may get an stopped-extensible-extension-error with the following stack trace:
"Microsoft.MetadirectoryServices.ExtensibleExtensionException: Connecting to remote server failed with the following error message : The WinRM client received an HTTP status code of 456 from the remote WS-Management service. For more information, see the about_Remote_Troubleshooting Help topic.

 at Microsoft.Exchange.XmaConnector.PSDataProvider.ReportError(Exception e, ScorecardCounter scorecard)
 at Microsoft.Exchange.XmaConnector.PSDataProvider.InvokeCmdlet(PSCommand cmd)
 at Microsoft.Exchange.XmaConnector.PSDataProvider.ReportScorecard()
 at Microsoft.Exchange.XmaConnector.XmaExportExLabs.ReportScorecard()
 at Microsoft.Exchange.XmaConnector.MAExtension.IlmMAExtension.EndExport()
Microsoft Identity Integration Server 3.3.1139.2"
This error occurs when the account that you are connecting with is blocked for sign-in as can be seen below.

You will need to contact the Live@Edu support services in order to resolve this issue

Thursday, December 23, 2010

FIM CM Search Errors

We recently deployed FIM CM at a client with a large Active Directory (120000+ objects), and ran into two very specific issues when we tried to search for a user to enroll them for a smart card. Here are both issues listed with both solutions:
1.       'ADSDSOObject' Failed with no error message available, result code:  -2147016669(0x80072023).
This error code simply means that the search scope you are trying to read is too large. Plainly your result set is too large; add additional search parameters to limit the search scope. By default AD has a search scope limit for queries and the amount of AD objects a FIM CM search can return is limited by these same limits (to my knowledge it is 1000 objects). Unfortunately this value cannot be increased in FIM CM.
Firstly You need to make sure that you limit the search scope by adding the FIM CM group you created for FIM CM users to the CLM.RequestSecurity.Groups in the FIM CM web.config file. This will allow FIM CM to determine which users are elligible for using FIM CM.
Secondly, if you are searching in a big directory, try to further limit the scope by typing at least 3 or more characters of the login name and adding additional search fields like email address, first name or last name to the search criteria.

2.       “value does not fall within the expected range” error
In short this error occurs because Authorization Agent account does not have sufficient rights on the object it is trying to access. Check that the account is part of the “Pre-Windows 2000 Compatible Access” Group and that the group rights are not applied differently across the Active Directory. Our problem stemmed from the fact that a set of OU’s had the permission for the group altered from the initially delegated permission. So if you get this error on a user, you can be sure that there is a permissions issue on the OU where they are located.


Tuesday, November 30, 2010

Exchange 2007 Management Console on Windows 2008 R2 for Exchange 2007 mailbox Provisioning on FIM 2010

If you have recently deployed FIM 2010 on Windows 2008 R2 and tried to install the Exchange 2007 SP2 or earlier Management tools (required for exchange 2007 mailbox provisioning via the AD MA), you would have noticed that the SP2 or below was not supported on Windows 2008 R2. Fortunately Exchange 2007 SP3 solves this problem by adding support for Windows 2008 R2.

You can download Exchange 2007 SP3 at http://www.microsoft.com/downloads/en/details.aspx?FamilyID=1687160b-634a-43cb-a65a-f355cff0afa6&displaylang=en

Monday, October 25, 2010

Restoring ILM/FIM Database in a different domain

Hi When you need to have to restore your ILM/FIM SyncService server to a different domain either for recovery for development, you will need to do the following in order to access the database:
  1. Install ILM/FIM Sync Service.
  2. Backup the existing configuration of databases and encryption keys.
  3. Restore the database overwriting the existing database.
  4. Run MIISActivate to activate the server.
Here however the fun begins, as you will not be able to access the server, due to the fact that the group SID's differ between data the stored database and actual group SID's of the domain. You have two choices regarding this. Rerun the setup (easiest IMO) or get the SID's from AD and update the SID values in the mms_server_configuration table. The values are stored in the following fields:
  • administrators_sid - stores the SID for the ILM/FIM Administrators Group
  • operators_sid - stores the SID for the ILM/FIM Operators Group
  • account_joiners_sid - stores the SID for the ILM/FIM Account Joiners Group
  • browse_sid - stores the SID for the ILM/FIM Browsers Group
  • passwordset_sid - stores the SID for the ILM/FIM Password Set Group
As these values are binary, you will need to run a sql CONVERT when setting the values as per the example below:
UPDATE [FIMSynchronizationService].[dbo].[mms_server_configuration]
   SET [administrators_sid] = CONVERT(varbinary,0x0105000000000005150000002BA93955DBAC7A56E35F9DA76C040000)
      ,[operators_sid] = CONVERT(varbinary, 0x0105000000000005150000002BA93955DBAC7A56E35F9DA76D040000)
      ,[account_joiners_sid] = CONVERT(varbinary, 0x0105000000000005150000002BA93955DBAC7A56E35F9DA76E040000 )
      ,[browse_sid] = CONVERT(varbinary,  0x0105000000000005150000002BA93955DBAC7A56E35F9DA76F040000)
      ,[passwordset_sid] = CONVERT(varbinary,  0x0105000000000005150000002BA93955DBAC7A56E35F9DA770040000)
   
 WHERE instance_id ='976E8CFB-46C3-425B-85B1-96726DFB044D'
GO
Restart the ILM/FIM SyncService Service and all will accessible again.

Wednesday, October 20, 2010

Tech-Ed South Africa is done and Dusted!!

Hi Everyone,
Tech-Ed SA is done, back to reality!!! Thank you to everyone that attended the event and our sessions. Thank you for your valuable contribution in making this event a big success.