<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>while (alive) { writeCode(); } - All Comments</title><link>http://blogs.msdn.com/b/brporter/</link><description /><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: How often will FillClaimsForEntity in my Custom Claims Provider be called?</title><link>http://blogs.msdn.com/b/brporter/archive/2010/11/30/how-often-will-fillclaimsforentity-in-my-custom-claims-provider-be-called.aspx#10246725</link><pubDate>Mon, 12 Dec 2011 13:28:09 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10246725</guid><dc:creator>Chun Liu</dc:creator><description>&lt;p&gt;Hi Bryan, a very nice post!&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10246725" width="1" height="1"&gt;</description></item><item><title>re: Trusted Identity Providers &amp; User Profile Synchronization</title><link>http://blogs.msdn.com/b/brporter/archive/2010/07/19/trusted-identity-providers-amp-user-profile-synchronization.aspx#10237000</link><pubDate>Mon, 14 Nov 2011 20:54:33 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10237000</guid><dc:creator>Trevor Seward</dc:creator><description>&lt;p&gt;Is it possible to implement your own synchronization source (I&amp;#39;m thinking AD LDS here) and bind the SPS-ClaimID behind the scenes?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10237000" width="1" height="1"&gt;</description></item><item><title>re: Trusted Identity Providers &amp; User Profile Synchronization</title><link>http://blogs.msdn.com/b/brporter/archive/2010/07/19/trusted-identity-providers-amp-user-profile-synchronization.aspx#10231727</link><pubDate>Mon, 31 Oct 2011 16:24:10 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10231727</guid><dc:creator>Bryan L. Porter</dc:creator><description>&lt;p&gt;@Glenn,&lt;/p&gt;
&lt;p&gt;Nope. FIM requires a domain trust to synch from an AD - and not only is a trust required, it must be a two-way trust, IIRC.&lt;/p&gt;
&lt;p&gt;Bryan&lt;/p&gt;
&lt;p&gt;==&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10231727" width="1" height="1"&gt;</description></item><item><title>re: Trusted Identity Providers &amp; User Profile Synchronization</title><link>http://blogs.msdn.com/b/brporter/archive/2010/07/19/trusted-identity-providers-amp-user-profile-synchronization.aspx#10231721</link><pubDate>Mon, 31 Oct 2011 16:14:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10231721</guid><dc:creator>Glenn</dc:creator><description>&lt;p&gt;Nice article, This helped alot, I do have a issue with the setup in our enviorment. Well not so much with this setup but a general question on the sync with a externla domain...&lt;/p&gt;
&lt;p&gt;I have set this all up, we have a external domain we want to sync profiles with but have notrust. &lt;/p&gt;
&lt;p&gt;The sharepoint farm is in one Domain (Domain ABC) and the user profile sync works just fine.&lt;/p&gt;
&lt;p&gt;There is a second Doamin, that we want to import users from (Domanin XYZ).&lt;/p&gt;
&lt;p&gt;We have NO trust between the Domains. But, we are using ADFS and a trustedclaimsprovider which allows users form the XYZ Domain log on to sharepoint.&lt;/p&gt;
&lt;p&gt;I can run the sync with the XYZ when I setup the connection, but the next day when it runs as per the schedualed sync, &amp;nbsp;the connection to the XYZ Domain fails.&lt;/p&gt;
&lt;p&gt;I have found that if I edit the connection by putting the password back in and reselecting the OU&amp;#39;s the connection will work for that day ( I need to do a full as it says the connetion has changed since the last incremental ) and then again it fails the next day with the same error.&lt;/p&gt;
&lt;p&gt;The servers Aplication event error logs show &amp;nbsp;FIMSynchronizationService erro event ID 6000 &amp;quot;The management agent &amp;quot;XYZ EXTERNAL&amp;quot; failed to run because the credentials were invalid&amp;quot;&lt;/p&gt;
&lt;p&gt;The MMIISCLIENT.EXE shows that the Sync witht e XYZ domain cannot be doen due a to: failed-authentication&lt;/p&gt;
&lt;p&gt;So it appears that the FIM service account cannot connect to the XYZ external domain, which I am assuming is due to the lack of the trust.&lt;/p&gt;
&lt;p&gt;How do I get around the FIM account requireing a TRUST? &lt;/p&gt;
&lt;p&gt;Is this Possible?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10231721" width="1" height="1"&gt;</description></item><item><title>re: Stupid SharePoint PowerShell Tricks, Part I</title><link>http://blogs.msdn.com/b/brporter/archive/2010/06/02/stupid-sharepoint-powershell-tricks-part-i.aspx#10221645</link><pubDate>Fri, 07 Oct 2011 12:39:32 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10221645</guid><dc:creator>Smeikkie</dc:creator><description>&lt;p&gt;This does not work. a SPAuthenticationProvider does not have the property AllowAnonymous.&lt;/p&gt;
&lt;p&gt;[brporter: This works fine, the script assumes that your web application is already configured for Windows Authentication; in such a configuration, Get-SPAuthenticationProvider returns an instance of SPWindowsAuthenticationProvider (an SPAuthenticationProvider subclass) which does in fact posess an AllowAnonymous property.]&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10221645" width="1" height="1"&gt;</description></item><item><title>re: Excluding Disabled User Accounts from Profile Synchronization in SharePoint 2010</title><link>http://blogs.msdn.com/b/brporter/archive/2010/02/20/excluding-disabled-user-accounts-in-sharepoint-2010.aspx#10215728</link><pubDate>Fri, 23 Sep 2011 08:24:19 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10215728</guid><dc:creator>Loveleen</dc:creator><description>&lt;p&gt;This is not working for me inactive people are still coming from AD. Can anyone help please.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10215728" width="1" height="1"&gt;</description></item><item><title>re: Trusted Identity Providers &amp; User Profile Synchronization</title><link>http://blogs.msdn.com/b/brporter/archive/2010/07/19/trusted-identity-providers-amp-user-profile-synchronization.aspx#10168415</link><pubDate>Wed, 25 May 2011 21:24:37 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10168415</guid><dc:creator>Bryan L. Porter</dc:creator><description>&lt;p&gt;Mario - There is no way, using OOB synchronization, unless you have access to query the federated partners directory service (and assuming that directory service is one of the standard directory servers we support synchronization with). If you could address their AD instance, for example, you&amp;#39;d be good to go with the above.&lt;/p&gt;
&lt;p&gt;Otherwise, your challenge becomes synchronization of that external directory information. You could have the partner send you an LDIF file on a regular basis, or hand-craft some other custom process. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10168415" width="1" height="1"&gt;</description></item><item><title>re: Trusted Identity Providers &amp; User Profile Synchronization</title><link>http://blogs.msdn.com/b/brporter/archive/2010/07/19/trusted-identity-providers-amp-user-profile-synchronization.aspx#10168413</link><pubDate>Wed, 25 May 2011 21:18:38 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10168413</guid><dc:creator>Mario</dc:creator><description>&lt;p&gt;This is great info, but doesn&amp;#39;t appear to address the more common scenario where I am using ADFS for EXTERNAL AD providers. &amp;nbsp;So if my local AD is contoso.com but I am federated with wingtiptoys.com, is there a way to import user claims info for the users from wingtiptoys?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10168413" width="1" height="1"&gt;</description></item><item><title>re: Why Is Central Administration Broken?</title><link>http://blogs.msdn.com/b/brporter/archive/2010/06/11/why-is-central-administration-broken.aspx#10159857</link><pubDate>Sun, 01 May 2011 19:34:57 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10159857</guid><dc:creator>Spence</dc:creator><description>&lt;p&gt;www.harbar.net/articles/spca.aspx&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10159857" width="1" height="1"&gt;</description></item><item><title>re: Trusted Identity Providers &amp; User Profile Synchronization</title><link>http://blogs.msdn.com/b/brporter/archive/2010/07/19/trusted-identity-providers-amp-user-profile-synchronization.aspx#10156304</link><pubDate>Wed, 20 Apr 2011 17:17:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10156304</guid><dc:creator>Kim</dc:creator><description>&lt;p&gt;Thanks for sharing this entry; it is not always that easy to discover hidden details within SP2010. In case we had to write a custom connector due to some reason, how could we assign values to the Claim User Identifier, Claim Provider Identifier fields in a profile? These fields are not editable. Is there a work-around for this?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10156304" width="1" height="1"&gt;</description></item></channel></rss>