MSOL Created AD Account and Group -

I've recently installed Forefront Identity Manager 2010 R2 and we are in the process of creating a tenant connection to Office 365 and setting up Exchange Federation.
I have installed FIM 2010 R2 and have setup DIRSYNC, and we've noticed an account and group were automatically created in the AD Domain USERS OU.
MSOL_xxxxxxxxxxxxxx (user)
MSOL_AD_Sync_Richcoexixtence (group) with the MSOL user the only member.
2 questions:
1). What is this User/Group used for? (as during the install I had to supply another AD Domain credential which I would have thought would have been used for the SYNC process.
2). Can this MSOL user/group be pre-created or have the password modified in some fashon? (our Security folks want to "set" the password on the MSOL user to a known value?)?
THANKS

Hi,
why do you install FIM when you install DirSync?
DirSync installs the FIM 2010R2 Synchronization Service on it's own. In General Dirsync is FIM2010 Sync Engine with a frontend which makes the configuration of the FIM and some scary automatic things in the whole forest.
Also Dirsync creates a service, which starts the runprofiles of the management agents.
1a) The Group "MSOL_AD_Sync_Richcoexixtence" is created by dirsync and has been granted permissions in every domain in the forest (because of this dirsync wants enterprise admin rights) for the write-back attributes described in the article
http://support.microsoft.com/kb/2256198/en-us.
1b) The account "MSOL_<identifier>" is also created by dirsync and is added to the MSOL_AD_Sync... group. Also this account has been granted "Replicate Directory Changes" in every domain in your forest for the dirsync ldap control.
1c) there is a third account which is created by dirsync..but this account is local and is named "AAD_<identifier>".
2.) you can change the password. the account is used in the ad management agent. so you have to go in the FIM Synchronization Service Manager and change it.
In big environments dirsync is crap...
regards

Similar Messages

  • SharePoint tool to create External Users and Groups

    Our organization is currently looking for a product that will allow us to create user account and group for users outside the organization (e.g Clients, subcontractors, etc.) and that will only need to access to our external SharePoint Collaboration site.
    We have one product right now but it is very problematic. For example if one of our clients need to change their email address which is their username it won't allow it so the account has to be re-created with the new email address and the permissions re-configured
    all over again. The groups created using the tool called Roles most of the times don't work. We are testing our SharePoint 2013 environment so we thought it is a good time to find something new. If you know of some products that I can check please let
    me know. I will really appreciate it

    Hi,
    According to your post, my understanding is that you wanted to create user account and group for users outside the organization.
    External User Management seems to be a solution. It allows for easy management of external users and roles.
    More information:
    http://ventigrate.codeplex.com/wikipage?title=External%20User%20Management
    Best Regards,
    Linda Li
    Linda Li
    TechNet Community Support

  • AUDIT action (create, delete, privilege escalation, set and change password from users account and group) users and admins in Solaris 10

    Hello.
    in Solaris 10 i need auditing process create, delete, privilege escalation, set and change password and etc... from users account and group.
    I set settings:
    in file syslog.conf:
    *.info;mail.none;cron.none;audit.notice            @IP-Remote-syslog-server-SIEM
    in file   /etc/security/audit_control:
    dir:/var/audit
    flags:lo,ad,ex,cc,am,no,fc,fd
    minfree:20
    naflags:lo
    plugin:name=audit_syslog.so;p_flags=lo,ad,ex,cc,am,no
    in file   /etc/security/audit_user:
    root:lo,ad:no
    Now I see in the logs only the fact of a connection via SSH and run processes on behalf of users. Creation. delete users, change passwords for some reason do not is logged.
    Many users. For each individual write permissions in the file /etc/security/audit_user not possible, it is likely to forget any new user (or there is a possibility in this file one line to describe the audits for all accounts?)
    Where is the mistake?

    You are most likely hitting Bug 15779000 user/role/groupadd/mod/del don't audit their use.
    And the fix is only available in S11.2.
    -- Renaud

  • BizTalk Service Account and Groups

    Hi,
    I need to install BizTalk server 2013 in Development server, please let me know the list of BizTalk service Account and What are all the groups need to  be created.
    Regards, Aboorva Raja R Please remember to mark the replies as answers if they help and unmark them if they provide no help.

    Hi
    You can find complete list of service accounts and groups on
    Windows Group and User Accounts in BizTalk Server MSDN page.
    These accounts needs to be created in your Active Directory server. 
    I would suggest you to have a look of
    Installing BizTalk Server 2010 in a Basic Multi-Computer Environment: The need for a Domain Controller – Windows Groups and Service Accounts (Part 2) blog post . Although this is for BizTalk 2010, but this may give you some idead about Accounts used in
    BizTalk setup.
    Also please have a read of
    Installation Overview for BizTalk Server 2013 and 2013 R2 
    Feel free to post any errors you get while installing. 
    Greetings,HTH
    Naushad Alam
    When you see answers and helpful posts, please click Vote As Helpful, Propose As Answer, and/or
    Mark As Answer
    alamnaushad.wordpress.com

  • Can I transfer money to other accounts on my iPad with iOS 5.1.1? I created another account and put an iTunes gift card on it, but then I realized that all of my apps are on another account, so how do I move that money over?

    Can I transfer money to other accounts on my iPad with iOS 5.1.1? I created another account and put an iTunes gift card on it, but then I realized that all of my apps ere on another account, so when I recovered the password of my previous account, I had money on an account that I do not want to use. Can I transfer the money over?

    Not on your own. Click here and ask the iTunes Store staff to put it back onto the card; they'll only do this if none of the balance has been spent.
    (115868)

  • My husband plugged my iPhone into his computer, created an account and now when I want to add apps it asks for his password not mine.  How do I get my account back?  Tried plugging it into his computer again.  No prompt to change account back to mine.

    My husband plugged my iPhone into his computer, created an account and now when I want to add apps it asks for his password not mine.  How do I get my account back?  Tried plugging it into his computer again.  No prompt to change account back to mine.

    Hi Trishw,
    At the top of the iTunes Store window, you will see who is logged into iTunes. I'm guessing from your description, that it is your husband. If it is, click on the name to display the dropdown, log him out and sign yourself back in:\
    Cheers,
    GB

  • I once created an account and changed meanwhile my Apple ID. Now, when trying to log in to iCloud, I get the message: "You are already logged in". I cannot get access to the account in the way, that, for example, the options appear on the right hand side.

    I once created an account and changed meanwhile my Apple ID. Now, when trying to log in to iCloud, I get the message: "You are already logged in". I cannot get access to the account in the way, that, for example, the options appear on the right hand side.
    What can I do?

    Thank you, pvonk, but:
    To be more precise: I am talking about the logging-in within the System Preferences on my iMac.
    When trying to log in with the old ID, I get no access, i.e. it says "Try again"...-Trying the same with the new one gives me the result I mentioned in my first question...
    Now I found out how to do it: I had to erase all accounts-then I could sign in with my Apple-ID. Thanks again.

  • IBooks Author. I am not allowed to sign in with my Apple ID on iTunes Connect when I am trying to publish my book in iBooks Author. I do not understand why because I have fulfilled the first steps creating an account and informed my IRS tax number...

    I am not allowed to sign in with my Apple ID on iTunes Connect when I am trying to publish my book in iBooks Author. I do not understand why because I have fulfilled the first steps creating an account and informed my IRS tax number...

    The recommendation is always to make another ID for use with a paid books account. And while I can't swear this is at the root of your issue, you should in any case reach out to Apple for assistance on this one, I think.
    Account Applications:
    [email protected]
    Global Phone Support
    We have expanded English-language publisher phone support. To make contacting the iBookstore support even easier, new local phone numbers are now available for Australia, France, Germany, Italy, Netherlands, Spain, and the U.K. Support is available Monday to Friday, from 7 a.m. to 5 p.m. (PT).
    Country
    Phone Number
    Australia
    1300 307 504
    Note that this is a low tariff number.
    France
    0805 540 117
    Germany
    0800 664 5307
    Italy
    800 915 902
    Netherlands
    0800 0201 578
    Spain
    900 812 687
    U.K.
    0800 975 0615
    U.S.
    +1 (877) 206-2092
    Toll-free from U.S. and Canada.
    Good luck

  • Creating OAAM users and groups in external LDAP i.e. OID

    Hi Experts,
    I am looking for the procedure to create OAAM users and groups in external LDAP i.e. OID.
    I am using 11gR2.
    Any pointers would be appreciated.
    Regards,
    Subin

    Check this link http://docs.oracle.com/cd/E27559_01/dev.1112/e27206/lcm.htm#autoId3

  • Mapping NT user accounts and groups in BOXI 3.1.i'm getting below error

    Mapping NT user accounts and groups in BOXI 3.1.i'm getting below error
    In BOXI 3.1 CMC
    .NT Authentication is enabled check box is selected.
    In the Mapped NT Member Groups area, entered the NT domain\group in the Add NT Group text box.
    like : secWindowsNT:
    BLRKEC148827D\BusinessObjects NT Users
    getting error like
    "The secWindowsNT security plugin is not enabled. Contact your system administrator for details. (FWB 00002) "

    You shouldn't be using the NT plugin in 3.1, is there a reason you are using this plugin over AD? If you really want to use it you may need to open a case with support and trace the CMS. Are there any groups currently mapped? if you hit update without adding/removing what happens? What if you remove the NT users group and hit update?
    Regards,
    Tim

  • How to create windows users and groups from Java

    Hi,
    Can any one please tell me, which Package/API will helps to create windows users and groups from Java.
    Thanks,
    M.Prem.

    You can't do it with pure Java, and it's not in the core API. You'd have to write a native function to do it, using whatever API Windows provides, and then call it with JNI. Or look for a third party native-based Java library that already does that.

  • I recently created an account and bought a movie. But any time I press "Play" iTunes freezes and will not respond at all.

    Windoes 7 64bit
    I recently created an account and bought a movie. But any time I press "Play" iTunes freezes and will not respond at all.
    I have tried both uninstalling the software and reinstalling it, I have tried to run the software in safemode, and I have tried to change the Quicktime settings to see if that helps.
    Nothing has worked. It always does the same thing, where it freezes the moment I tell it to "play".
    I have tried to use my other computer instead, going through the same process and I got the exact same result where it freezes.
    Therefore it has to be something to do with the software, because the computers use different graphics cards, yet it responds the same.

    Hi Canon-Thought!
    I have an article here for you that deals with this exact issue. You may have already completed many of the steps that this article will suggest, but look over it to see if it suggests something you haven't already tried:
    iTunes for Windows Vista or Windows 7: Troubleshooting unexpected quits, freezes, or launch issues
    http://support.apple.com/kb/ts1717
    Also, I suggest paying close attention to the list of programs that you would need to uninstall, in order, so that you can fully uninstall iTunes and all related components from your computer. If those programs and steps are not followed exactly, you may end up with issues using iTunes.
    If this issue only happens with one singular movie, you may need to report that there is an issue with your purchase. We have an article for doing that, and it can be found here:
    How to report an issue with your iTunes Store, App Store, Mac App Store, or iBookstore purchase
    http://support.apple.com/kb/HT1933
    Thanks for being a part of the Apple Support Communities!
    Regards,
    Braden

  • Hi .... I have created an account and do not receive the new apple email-lul confirmation

    Hi .... I have created an account and do not receive the new apple email-lul confirmation

    Hi Anghel,
    If you are having issues creating an Apple ID, you may find the following article helpful:
    OS X Mavericks: Create and use Apple IDs
    http://support.apple.com/kb/PH14326
    Regards,
    - Brenden

  • Creating management accounts for protected accounts and groups in Active Directory

    I'm following step-by-step instruction for creating management accounts for protected groups that I found in Microsoft book "Best Practise for Securing Active Directory", published april 2013.
    What is confusing me is the "Enabling management accounts to modify the membership of protected groups" step. When I use DSACLS command:
    Dsacls "CN=AdminSDHolder,CN=System,DC=MyDomain,DC=com"/G
    [email protected]:RPWP;member
    what I have to type insted of "member".
    When I use previous command with simple "member" at the end I dont get this:
    Verify that the account has been granted only Read Members and
    Write Members permissions on the DA group, and click OK.
    My account have flag on all properties.
    I hope You understand me.

    The last field is for the attribute to delegate. You can read about it here: https://technet.microsoft.com/en-us/library/cc772662%28v=ws.10%29.aspx
    You can also refer to this for updating AdminSDHolder container: http://social.technet.microsoft.com/wiki/contents/articles/22331.adminsdholder-protected-groups-and-security-descriptor-propagator.aspx
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • Group Chart Of Accounts and Group Account Number

    Hi SAP Gurus,
    For the sake of consolidated reporting, we are planning to create group chart of accounts and assign a Group account number to the GL account master. The structure is going to be like this:
    Operating Expenses (Group Account : 461000).
    Air Conditioning Exp   (GL account 461000001)
    Elevators                   (GL account 461000002)
    Coffee and snacks      (GL account 461000003)
    This is being done to achieve a detail level reporting at the company code level and a consolidated reporting at a group level where the reporting would be based on group account or FSIs. We would define a financial statement version based on FSIs.
    My question is : do we need to activate the consolidation (EC-CS) module to push the data to the FSIs or the data would flow automatically to the group account if we assign this to the GL master. If we go to fetch the data from the ECMCT table, do we need to have a consolidation unit?
    Any inputs are highly appreciated.
    thanks
    sri

    Hi,
    There are certain preliminary steps to be carried out in ECCS. You can find them under SPRO->Enterprise Controlling->Consolidation->Integration: Preparation for Consolidation.
    You need to choose the type of consolidation, create Company, link it to Cons Unit in ECCS, Creating/Copying FS Items (each account in Group COA will have an FS Item; 1:1),  etc.,
    After the setup, you actually need to carry out Rollup or Flexi Upload for importing FI data into ECCS FS Items. This is done to Data Monitor - CXCD.
    In ECMCT, typical selections would be Dimension, Cons Unit, Cons COA, FS Item.
    I suppose these preliminary steps are requried for the data to flow to FS Items.
    Hope this clarifies.
    Rgds.

Maybe you are looking for

  • Replicating GR custom fields from EBP to SAP R/3

    Dear SRM Gurus, We are using SRM 5.0, extended classic scenario.. We have created 3 custom fields for GR in SRM and we want to pass these custom field values to SAP R/3(4.6C). Is there any BAdI or function module to replicate these custom field value

  • OIM 11g - Mail Notification for multiple resources

    User will be provisioned to 5 target system through access policies.So instead of sending 5 different mail notifications to the manager on the Create User task about the account creation, is it possible to send one consolidated mail about the provisi

  • Unknown error (1417)

    I want to update my Ipod classic (30GB), but i always receive the message 'the ipod of .... cannot be updated. There is an unknown error (1417). My itunes is 7.5 and my system windows XP. I also want to synchronise my ipod, but then i get the message

  • Font not available in Photoshop CS6 or Illustrator CS6 (Mac)

    I have installed the Frutiger font family in the font library. It appears in the drop-down menu in InDesign, but not Photoshop or Illustrator. How can I make the font available in these programs?

  • Infotype not accesible after transporting to client 900

    I have created a new infotype 9000 which is a copy of infotype 0000 in client 100. it works fine in client 100 but while transporting to 400 and 900 it gives a warning message with return code 4 and the same infotype is not accesible in client 900. I