Working with SQL aliases

In all FIM implementations you should use SQL aliases and not point to the actual SQL server instances or servers in your configuration. The problem is that SQL aliases have two versions, one for 64-bit (the default) and one for 32-bit.

One time you will hit the 32-bit is if you are working with Visual Studio (32-bit application) or 32-bit ODBC drivers.

To manage your aliases you need to use the correct version of cliconfg.exe. If you just start a command prompt and run cliconfg you will be able to manage the 64-bit aliases. The full path is C:\Windows\System32\cliconfg.exe.

But if you need to manage the 32-bit aliases you need to start the C:\Windows\SysWOW64\cliconfg.exe.

Another problem you might run into is having to copy your alias settings from one machine to another. For example from your test FIM to your production FIM. The easiest way I have found is to copy the two registry keys that holds this information between the machines.

  • HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSQLServer\Client\ConnectTo
  • HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\MSSQLServer\Client\ConnectTo

Hopefully this post will make it easier for you to work with your SQL aliases.

Deprecated Features and Planning for the Future of FIM

The product team has now started to reveal some news about the next version of FIM. First out is a list of deprecated features to prevent us from using them in our current projects. Making a transition to the next version easier.

Read about deprecated features in FIM on TechNet.

Server 2012 Unified Remote Access Book

Erez Ben Ari and Bala Natarajan have written a new book about Unified Remote Access in Windows Server 2012. This explains how Direct Access in Server 2008 R2, combined with Forefront UAG, might be replaced by Unified Remote Access in Windows Server 2012.

Server 2012 Unified Remote Access Book

Windows Server 2012 Unified Remote Access Planning and Deployment Book

You can get the book from Packt Publishing.

Positive feedback on my FIM 2010 R2 Book

I am getting lots of positive feedback from readers all over the world. Feedback that really warms my heart. I just can’t help sharing one with you.

Kent, I’m super impressed with your book. Authoritative information in combination with a collegial writing style is a rare find. One of the ways you distinguish your writing from other tech books is the way you inject little tips to help keep the boat pointed straight up the river:

FIMR2BookReferenceExample1

Looking forward to reading every page…
-Bill Boswell

Microsoft announcing UAG 2010 SP3

Microsoft have just announced that UAG 2010 SP3 will come in Q1 2013.

The SP3 will add support for:

  • Windows 8 with Internet Explorer 10 clients
  • Office 2013 clients (e.g. Outlook, Word, Excel, PowerPoint)
  • Publishing Exchange 2013
  • Publishing SharePoint 2013
  • RDP 8.0 client for Windows 7 SP1

Does UAG activation disconnect users?

A common question for all UAG administrators is if activating the configuration will affect users currently using the UAG.

Erez Ben-Ari (co-author of the books Microsoft Forefront UAG 2010 Administrator’s Handbook and Mastering Microsoft Forefront UAG 2010 Customization) have given a very clear answer to that question.

Normally, it does not. The exceptions are:

  1. SSL-VPN tunnels do get severed during an activation, so anyone using those will be disconnected and need to re-launch the tunnel.
  2. Occasionally, UAG might detect that IIS is not responding, and issue an IISRESET. That would effectively terminate all sessions. It’s pretty rare to happen, though.
  3. The labor involved with the process can make the servers less responsive to some degree. Usually, it’s barely noticeable, though.

Bottom line is that activating a new configuration should in normal case not affect the users running applications published in UAG.

Win A Free Copy of Packt’s FIM 2010 R2 Handbook

Win A Free Copy of Packt’s Microsoft Forefront Identity Manager 2010 R2 Handbook e-book.

I am pleased to announce that I have teamed up with Packt Publishing and are organizing a give away especially for you. All you need to do is just comment below the post and win a free copy of Microsoft Forefront Identity Manager 2010 R2 Handbook. Two lucky winners stand a chance to win an e-copy of the book. Keep reading to find out how you can be one of the Lucky One.

5368EN_FIM2010R2Handbook

Overview of Microsoft Forefront Identity Manager 2010 R2 Handbook eBook

  • Prerequisites for installing FIM 2010 R2
  • How to install and scale the solution
  • Implementation of User and Group Management including Self-Service

How to Enter?

[Competition is Closed: Congratulations to the Winners Paulo H. Campos and Joakim Ingesson!]

All you need to do is head on over to this page and look through the product description of these books and drop a line via the comments below to let us know what interests you the most about this book. It’s that simple.

DeadLine:

The contest will close on October 31 2012. Winners will be contacted by email, so be sure to use your real email address when you comment!

Hotfix rollups for FIM 2010 and FIM 2010 R2

Microsoft has released new hotfix rollups for both FIM 2010 and FIM 2010 R2. Among other things it is said to fix the “stopped-server” error in FIM 2010 Synchronization Service.

Read more at FIM 2010 hotfix rollup (build 4.0.3627.2) and at FIM 2010 R2 hotfix rollup (build 4.1.2515.0)

TMG available as SecureGuard appliance after Dec 1

In this Announcement Availability of Microsoft Forefront TMG 2010 on SecureGUARD Appliance Series from SecureGuard we can read that. “As announced by the Microsoft Server & Cloud Blog, Microsoft Forefront TMG 2010 will be discontinued and will be no longer available for purchase as of Dec. 1, 2012. Nevertheless SecureGUARD Appliances with TMG 2010 licenses will be available for purchase significantly longer than Dec. 1, 2012.”

My supplier tells me that SecureGuard at the moment plans to support their TMG appliances until 2023.

Read about all SecureGuard appliances and offerings on http://www.secureguard.de

Interested in buying SecureGuard appliances? Contact me at kent@xpservices.se or just comment on this post.

Thanks to ISA and TMG teams

I just want to take this opportunity to say thanks to everyone that over the years have worked with ISA and TMG. Having myself worked with ISA and TMG since beta of ISA 2000 I can only say… You all did a fantastic job, making ISA and TMG one the best firewalls on the market. Thank you!