Forefront Identity Manager

{{update|date=April 2017}}

{{Infobox software

| name = Microsoft Forefront Identity Manager

| released = {{Start date and age|2010}}

| developer = Microsoft

| latest release version = 2010 R2

| latest release date = {{Start date and age|2012|06|14}}

| latest preview version =

| latest preview date =

| operating system = Windows Server 2008 R2

| platform = x86-64

| genre = Identity management

| license = Proprietary

| website = {{URL|https://learn.microsoft.com/en-us/microsoft-identity-manager/microsoft-identity-manager-2016}}

}}

Microsoft Forefront Identity Manager (FIM) is a state-based identity management software product, designed to manage users' digital identities, credentials, and groupings throughout the lifecycle of their membership in an enterprise computer system. FIM integrates with Active Directory and Exchange Server to provide identity synchronization, certificate management, user password resets, and user provisioning from a single interface.

Overview

Part of the Microsoft Identity and Access Management platform product line, FIM superseded Microsoft Identity Lifecycle Manager (ILM),{{Cite web |title=FIM 2010 RTM Announcement |url=http://blogs.technet.com/forefront/archive/2010/03/02/rsa-conference-2010-identity-at-the-forefront.aspx |archive-url=https://web.archive.org/web/20100313142637/http://blogs.technet.com/forefront/archive/2010/03/02/rsa-conference-2010-identity-at-the-forefront.aspx |archive-date=2010-03-13 |publisher=Microsoft Corporation}} and was known as ILM 2 during development. ILM 2007 was created by merging Microsoft Identity Integration Server 2003 (MIIS) and Certificate Lifecycle Manager (CLM).

FIM 2010 utilizes Windows Workflow Foundation concepts, using transactional workflows to manage and propagate changes to a user's state-based identity. This is in contrast to most of the transaction-based competing products that do not have a state-based element. Administrators not only can create workflows with the web-based GUI of ILM 2 portal but also include more complex workflows designed outside of the portal by importing XAML files.{{Cite web |title=ILM "2" Glossary |url=https://technet.microsoft.com/en-us/library/cc561128.aspx |archive-url=https://web.archive.org/web/20081208040338/https://technet.microsoft.com/en-us/library/cc561128.aspx |archive-date=2008-12-08 |publisher=Microsoft Corporation}}

FIM 2010 R2 (Release 2) was released in June 2012 and has extra capabilities:

  • Improved Self-service Password Reset which supports all current web browsers
  • Role Based Access Control (RBAC) via the acquisition of BHOLD Software
  • Improvement to the Reporting engine via the System Center Service Manager and MS SQL Server reporting Services (SSRS)
  • A WebServices Connector to connect to SAP ECC 5/6, Oracle PeopleSoft, and Oracle eBusiness
  • Improvements in the areas of performance, simplified deployment and troubleshooting, better documentation, and more language support.

Codeless provisioning

Forefront Identity Manager introduces the concept of "codeless provisioning",{{Cite web|url= https://technet.microsoft.com/en-us/magazine/2007.05.workflow.aspx| title= Build a Single-Step Provisioning Workflow| date= 8 September 2016|publisher= Aung Oo, Microsoft Corporation}} which allows administrators to create objects in any connected data source without writing any code in one of the .NET Framework languages.

The codeless provisioning provided in FIM should be able to sustain most of the simple to medium complexity scenarios for account lifecycle management. FIM fully honors existing MIIS implementations and supports "traditional" coded provisioning side-by-side with code-less provisioning methods.

See also

References

{{Reflist}}