FIM R2 SP1 MPR changes giving me "No policy grants the Requestor permission to complete all changes" no matter what I do

I am implementing FIM R2 SP1 on win 2012 servers and migrating FIM 2010 RTM configurations to the new environment.  Some of the custom Sets, MPRs etc did not import correctly into the new portal and when I try to manually add a set or
alter an MPR I recieve the following error
Error processing your request: The operation was rejected because of access control policies.
Reason: The operation failed as a result of insufficient access rights.
Attributes: ActionParameter,ActionType
Correlation Id: 11a13390-6a1f-4776-a796-fd0f05101120
Request Id:
Details: No policy grants the Requestor permission to complete all changes.
I have tried enabling "all attributes" in "Administration: Administrators control set resources" and "Administration: Administrators control management policy rule resources" and recieved the same errors.  I am logged in
as the user who installed the portal and it is a member of the administartors set.
What am I missing?  Any ideas welcome please.

Hi Peter,
I found the import had not completely imported the configuration while trying to import the configuration (as I said above) and while trying to troubleshoot this issue I discovered this error.
I have tried importing the old database and this does not help.
I should mention that the configuration is coming from the production environment into a stand-alone development environment for testing.
I have, today, in an attempt to resolve this error, uninstalled the portal and service (which are installed on the same server) and reinstalled it creating a new database.  This is to attempt to resolve any "overwritten" default sets or MPRs
as you have suggested.
I thought I would try out the FIM 2010 R2 Service and Portal configuration Backup Tool described here
http://technet.microsoft.com/en-us/library/jj134311(v=ws.10).aspx but note there is no instructions for their use in restoring the environment.  I assume you just copy the
files to the appropriate place, run the reg keys and sql scripts that it creates and that does it all for you?  I was hoping that this might be a successful alternative to the old Import-FIMconfig way of doing things.

Similar Messages

  • SSPR - Unlock User - No policy grants the Requestor permission to complete all changes.

    When trying to unlock a user in FIM Portal I get the below error with FIM Admin account.
    Error processing your request: The operation was rejected because of access control policies.
    Reason: The operation failed as a result of insufficient access rights.
    Attributes: GateData
    Correlation Id: eda9f21c-a777-4ef2-b12f-25e82aef7973
    Request Id: 
    Details: No policy grants the Requestor permission to complete all changes.
    Any ideas?

    You need to update the MPR for Administration: Administrators can read and update Users and under the Target Resources tab, add the Attribute GateData in the Attributes Box.
    If you are doing this through the Sync Engine, also do the same in the MPR
    Synchronization: Synchronization account controls users
    it synchronizes
    That should solve the problem.
    You need to do this for all the attributes you get the error for. FIM does not give all the attributes that it fails with insufficient rights, it fails at the first attribute, so once you have solved this attribute there may be others generating the same
    error. So watchout for that Attributes: GateData it may change, so any attribute that fails you need to follow the above streps.

  • I live in Australia but when I upgraded to IOS6 it changed my App Store region to the US. How can I change it back? I have been trying to find the answer.

    I live in Australia but when I upgraded to IOS6 it changed my App Store region to the US. How can I change it back? I have been trying to find the answer.

    Contact iTunes support & request they clear the balance:
    http://www.apple.com/support/itunes/

  • Hi, after submission of the form, can the respondents make changes to their answers and submit the form again without completing every single question?

    Hi there,
    After submission of the form, can the respondents make changes to their answers and submit the form again without completing every single question?
    Thanks for your help
    Paline

    Hi Paline,
    Unfortunately this cannot be done.However, being the author of the form you can make the required changes in the response file.
    Thanks,
    Vikrantt Singh

  • I changed my apple I'd but the iCloud I'd didn't change. Now the old I'd won't take the password

    I changed my apple I'd but the iCloud I'd didn't change now the old I'd won't work-help

    To change your iCloud ID and/or password, go to Settings>iCloud, tap Delete Account, then sign back in with your updated credentials.  Deleting the account will only delete the account and any iCloud data from your iPad, not from iCloud.  Provided you are signing back into the same account and not changing accounts, your data will be synced back to your device when you sign back in.
    If, however, you are changing to a new account, when you deleted the existing account be sure to choose Keep on My iPad, then set up the new account and choose Merge when you turn on data syncing again.
    Also, if you have any photos in your my photo stream album that are not in your camera roll or backed up somewhere else save these to your camera roll before deleting the account by opening the photo stream album in the thumbnail view, tapping Edit, then tap all the photos you want to save, tap Share and tap Save to Camera Roll.

  • I keep getting a message on startup saying 'Do you want the application "KodakAiOBonjourAgent .app" to accept incoming network connections?' It says settings may be changed in the Firewall pane of Security? Doesn't matter what I click (Deny/Submit).

    I keep getting a message on startup saying 'Do you want the application "KodakAiOBonjourAgent .app" to accept incoming network connections?' It says settings may be changed in the Firewall pane of Security but I don't see how.  Doesn't matter what I click (Deny/Submit). The message still pops up on starup. I have a Kodak printer and am running Mavericks but I don't think it started when I upgraded.

    Just fixed this on my machine, the easiest way to remove this pop-up assuming you are no longer needing that software to print is the following:
    Open Finder
    Go > Go To Folder...
    Type In: "~/Library/Application Support"
    Delete All Folders Named Kodak
    Open System Preferences
    Go to "Security & Privacy"
    Click the lock and enter your admin password
    Click the Firewall Tab
    Go to "Firewall Options..."
    Find KodakAiO
    Right-click KodakAiOBonjourAgent or equivalent (I forget the exact name)
    Click "Show in Finder"
    Go Back to a folder and delete the Kodak Folder there.
    Remove Kodak from Firewall Options by selecting it and clicking the " - " button the base of the list.
       or
    Open Finder
    Go > Go To Folder...
    Type In: "~/Library/Printers"
    Delete All Folders Named Kodak
    I'm going off memory, so If I forgot something let me know.

  • I cant change my icloud account password, email was hacked and need this all changed

    I cant seem to change my icloud account info, need to change the email and password. was able to change it on the computer once but cant change that in my phone or ipad. any ideas

    To change the iCloud ID you have to go to Settings>iCloud, tap Delete Account, provide the password for the old ID when prompted (if running iOS 7), then sign back in with the ID you wish to use. 
    If you don't know the password for your old ID, or if it isn't accepted, go to https://appleid.apple.com, click Manage my Apple ID and sign in with your current iCloud ID.  Click edit next to the primary email account, change it back to your old email address and save the change.  Then edit the name of the account to change it back to your old email address.  You can now use your current password to turn off Find My iPhone on your device, even though it prompts you for the password for your old account ID. Then save any photo stream photos that you wish to keep to your camera roll.  When finished go to Settings>iCloud, tap Delete Account and choose Delete from My iDevice when prompted (your iCloud data will still be in iCloud).  Next, go back to https://appleid.apple.com and change your primary email address and iCloud ID name back to the way it was.  Now you can go to Settings>iCloud and sign in with your current iCloud ID and password.

  • HT1311 Can I find out who changed a password on my account? It was for the game center. It was changed from out of state and would like to find the source to prove it.

    I need to know if I can pin point the source of what device was used to change a password on my account?

    I was notified by Itunes a request for a password change was requested and they granted the change. An X used my email address is how I found out. I changed my password again. Shame on Itunes for allowing anyone to do that. I want to know if I can find the devise or phone that requested a new password.

  • Sales order as complete and change the delivery status.

    Hello All,
    We  produces an order but then the customer calls and does not want the material so we in turn will scrap the material against the production order using transaction MB1A mvmt type 951 E. 
    Since the material were scrapped and no material were shipped against the sales order, the sales order u201Coverall statusu201D remains open and the delivery status is u201Cnot deliveredu201D.
    To close the order  we u201CRejected line itemu201D and moved on.
    I would like to know if there is another way we can set the sales order as complete and change the delivery status. 
    Regards
    Amit

    Hello,
    you can use the status profile for the same. but a better way would still be to use the rejection reasons . the rejectionr reasons are very well integrated with the document flow as well as transfer of requreiemnts to Production
    so a best practise would be to use rejection reason
    hope this helps
    Thanks
    akasha

  • Best way to remove all changes

    What is the best way to remove all changes that were done to an image in Camera Raw, to get the image back to the way it was originally?

    Thanks for the suggestion. That would probably work if the file was still open in Camera Raw. But when the file has been opened in Camera Raw, changes are made, then click Done and the image is closed -- the next time it is opened in Camera Raw, Alt/Option clicking the Reset button does not return the image to it's original condition.

  • ODI CDC using Logminer - how to capture all changes for one PK

    Hi,
    Let me explain our scenario and challenges we are facing -
    *1.     Captures all changes in CDC –*
    We are using CDC (LOGMINER) to capture change. Currently current ODI code capture latest change happened during last execution.
    Now requirement is to capture all changes happened after last execution cycle.
    To achieve this, can you please suggest what changes we need to do in current code.
    *2. Performance Improvement* - Current CDC can handle 400 TPS (Transactions per second, here transactions means single record) and we are looking for 2000 TPS
    we are expecting 15 million records for INIT load and 7-8 million records on daily basis for CDC
    What needs to be done to improve the performance. In case if you need more details to answer this, please let me know.
    Oracle database version at source and target - 11g
    ODI - 11g
    Thanks in advance.
    Regards,
    Dinesh.

    Hi Dinesh,
    I have some experience with ODI And Logminer / Streams.
    Can you confirm what JKM you are using?.
    For your 1st point - the logic to only get the latest update is contained within the JV$ / JV$D view , you can edit the definitions of these views if you want to bring through all transactions - there should be an SCN number in the change table you can order by if you are interested in the order the transactions occurred - I assume you are otherwise your target DB will get out of sync.
    As for performance - Have you tweaked the Streams settings ? How many Change sets do you have ?

  • Same Sync Engine Encryption keys when upgrading FIM R2 to FIM R2 Sp1. why?

    Hellos,
    Just a quick clarification to help me write up the upgrade report.
    I managed to upgrade FIM 2010 R2 to FIM 2010 R2 Sp1 without any issues. It was quite straightforward. However, my brief was to create a report for others describing not just the WHAT but the WHY.
    The first step before uninstalling the FIM 2010 R2 software was to backup database and to save the encryption keys (generated by the FIM 2010 R2 installation)
    These keys were then used by the FIM 2010 R2 Sp1 installation. WHY? Does this mean that the underlying encrypting mechanism has not changed and will unlikely ever change? 

    It would be bad if the mechanism will change, in this case you could not re-use your FIM DB.
    From what I know the mechanism is still the same since MIIS 203, as I have da customer DB which was created at that Version and migrated to all version of the product.
    Regards
    Peter
    Peter Stapf - ExpertCircle GmbH - My blog:
    JustIDM.wordpress.com

  • Bug with criteria based groups in FIM R2 SP1

    Hello all,
    We experience following unusual behavior within the FIM portal (FIM R2 SP1) with criteria based groups, which looks like a bug.
    The behavior applies for all kind of criteria groups and can be reproduced with following steps:
      1. Open your criteria based group and click on your members tab: 
    2. Click on General Tabs 
    3. Click back to Members tab -->the criteria is not available anymore 
    Do anybody else experiences the same? This behaviour confuses our customers and leads to corrupted criteria based groups.
    Regards Fatih

    Hi,
    Please check the cache properties in Portal Configuration. Try and test your issue by increasing the cache values.
    I am not sure, it will help you or not. But a try.
    Regards,
    Manuj Khurana

  • Firefox sync error, changed password and on other devices the new password keeps giving me an error.

    Okay so I have several Linux devices in sync and one of them is synced also with a Microsoft 8 and the latest updates of Firefox. All of them are updated to the lastest. I had to change my password becaue for some odd reason the pass I wrote down was not being registered in my computer. Now because of that I had to change it for all of the other devices and none of them are detecting the new firefox password change. It just seems like a round circle where I change pass, and I have to continue to do that but each device wants to do the same thing.
    What could be done is there some bug with respect to this!? Thanks.

    Please let me confirm what you are saying: when you change the password on one device, all of the other devices connected to the account are not disconnected and continue syncing?
    [Bug 987719 - If user changes FXA password as Syncing client, don't kick them out of Sync]- this is outdated I think*
    Do the other devices ever prompt you for a new password? And if you check about:sync-logs are there any errors after the time you changed the password on one of the devices?
    Edit* ignore this post, though these are the steps we would take if there is a bug for future reference.

  • Iphoto date change giving wrong date

    When I try to change the date of a scanned photo I get a strange and incorrect date in response.
    For example if I put in 25/01/1985 I get a return date of 12/11/573. Each time I try to input the correct date the return date is earlier and earlier.
    I have tried changing the file date through terminal. I have tried resetting the system date but the changed photo date still won't move to the one I input.
    Does anyone know how to fix this?
    Cheers
    Paul

    Hi
    Yep that is where I made the previous changes. I went back there and reset everything to default settings. I also went into the Date and Time pane and changed automatic time, date and zone settings on and off, trying various combinations. But no joy. The photo date won't accept the one I give it.
    This is really annoying. I am otherwise very happy with the Mac. Such a shame that a part of the iPhoto functionality is ruined by this. I was looking forward to having my photos in chronological order.
    Oh well. Hopefully Apple will do something to fix the issue soon.
    Thanks for trying to solve it anyway.
    Regards
    Paul

Maybe you are looking for

  • Is it possible to close all apps in one one click?

    Is there a simpler way of closing all apps on your iphone than doube-clicking the home button and then closing each one individually? I don't see a "close all apps" option anywhere.  Sometimes I find myself with 20 apps open all at once and it's tedi

  • Testing Resume extractor is configured - I am getting following error.

    To test the Resume Extractor configured, navigate to Set Up HRMS -> Product Related ->Recruiting ->Vendor click "Search" if it is configured. Click the "Test" link to browse a resume/CV and click "Upload". After Press Upload button I am getting Follo

  • Sales order Tracking

    HEllo Experts I require help for following situation. My scenario is SOURCE ODS1: <b>ZMB_CR.</b> Objects: <b>1.ZQUALITY</b> (Its an indicator that consists of "S" and "X". <b>2. ZTRPOST</b> (Its an indicator that consists of "S" and "X"). Target ODS:

  • What are the 4 settings in ZoneAlarm FREE 7.1.248.000

    ZoneAlarm FREE has 4 settings it needs answered: ACCESS & SERVER, each with INTERNET & trusted ZONEs... ...so what should Bonjour Service mDNSResponder.exe firewall settings be under ZA ??? Thanks

  • Modifier Keys Not Restoring to Default

    I changed my modifier key mapping so that I could use a Windows keyboard with my MacBook Pro (late 2008). I set the Control key to function as the Command key and vice versa. Now it won't change back. I've changed the key selections. Restored Default