Enabling password management in AD

The goal for SSPR is, usually, to reset the password of users' account in Active Directory, but the SSPR feature in FIM is not limited to that. It can be used to reset passwords in other CDSs as well.

In order for FIM to change the password of a user in AD (or any other CDS), the account used by FIM needs to have the Reset password permission in AD, or a similar permission in another CDS:

Enabling password management in AD

In Management Agents for the target CDS, in this case the AD, we need to check the Enable password management checkbox:

Enabling password management in AD

If we then ...

Get Microsoft Forefront Identity Manager 2010 R2 Handbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.