Does SharePoint 2010 Mess With My Active Directory?

May 31 2010 16 comments

Before the launch SharePoint 2010 was advertised to come with “AD or LDAP writeback” capabilities. SP2010 ships with the the profile synchronization engine from ForeFront Identity Manager (FIM). This is a huge step from the simple profile import functionality of MOSS.

When hearing this, every IT administrator gasps. Will SP2010 mess with my Active Directory?  Suspicions arise when SharePoint guys come to visit and ask for “Replicating Directory Changes” permissions in AD.

Also after configuring the synchronization with default setttings, browsing through the profile synchronization log contains some interesting lines hinting automatic export:

But there is no need to worry, as the process is described in TechNet article:

1. “Authenticated users who have Replicate Directory Changes permissions will be granted read-access to AD DS objects.”  This is done by the AD administrator and is required also for one-way import.

2. “Additional permissions can be granted using access control lists (ACLs) in AD DS. SharePoint Server 2010 will not write profile data back to AD DS unless Write permission is explicitly set on the account that has Replicate Directory Changes permissions.” This is also done by the AD administrator and is required only for the two-way synchronization.

3. “By default, no user profile property is set to Export. You must explicitly define the user profile properties that you want to export back to the directory service from the user profile store.” This is done by SharePoint administrator and is required only for the two-way synchronization.

The last step is configurable in the profile property settings:

As a summary: SP2010 contains two-way profile synchronization with AD, but it has to be explicity enabled in both AD and SP2010.

Popularity: 4% [?]

16 comments to “Does SharePoint 2010 Mess With My Active Directory?”

  1. [...] I wrote earlier, SharePoint 2010 ships with a profile synchronization engine from ForeFront Identity Manager. After [...]

  2. Half says:

    I’m glad to read this. However, it would be useful to find a more comprehensive description of these permissions, in order to convince AD admins to assign it to a SharePoint account. You’re right, the first thing they say is “I have to check it, because if something wrong happens, AD might be irreversibly corrupted”.

  3. Arttu Arstila says:

    Thanks for the comment! Here is a great and detailed description of what is needed in order for the profile sync to work: http://www.harbar.net/articles/sp2010ups.aspx

  4. jcnet says:

    MS is telling us the Full version of FIM 2010 is not copatible with SP2010 (as of Today 3/1/2011). True?

    So what’s missing from the version of FIM 2010 that SharePoint installed and appears to be using?

    We have a simple requirement to allow users to change their own passwords? Will the version of FIM installed with SP2010 allow this, or do we need the full version of FIM 2010 and again, will that install and work with SP2010?

    Also, say we keep the above requirement on a seperate serve and only want to do user profile imports (no updating of AD), Can we remove privildeges from our Service account for Replication and Create Child on AD?

    And finally, the User profile Sync connection screens are very different, I’m not finding where to add filters. Is there another screen for Imports that’s not the Sync connection screen?

    Thanks.

  5. Wim says:

    Hi,

    is there any way we can use user profile synchronisation with only read rights in AD, i have a local sharepoint in a large international company and the right will be given to me.

  6. Madhu says:

    please let me know how to import data from LDAP to sp 2010 user profile store

  7. [...] http://www.sharepointblues.com/2010/05/31/does-sharepoint-2010-mess-with-my-active-directory/ This entry was posted in sharepoint and tagged user-profile-service by admin. Bookmark the permalink. [...]

  8. ” Consuming another 10 hours of their day for a 1-hour outing. If the clawfoot tub shower is second hand have a look at the device for anything important that you can search on Google with. Now I’m NOT talking about the urge to pee after being in warm water which causes a parasympathetic stimulation of the detrussor muscles of your bladder and relaxes you and makes you want to pee in the nice warm clawfoot tub shower (as many of you likely do).

  9. Hi there very nice web site!! Guy .. Excellent ..
    Wonderful .. I will bookmark your blog and take the feeds additionally?
    I am happy to seek out numerous useful information here within the publish, we’d like work
    out extra strategies on this regard, thank you for sharing.
    . . . . .

  10. A fascinating discussion is worth comment. I do believe
    that you need to write more about this issue, it might not be a
    taboo subject but usually people do not talk about these subjects.

    To the next! Many thanks!!

    Feel free to visit my web-site … snowblower service

  11. Fantastic website you have here but I was wanting to know if you knew of
    any message boards that cover the same topics discussed here?

    I’d really like to be a part of community where I can get comments from other knowledgeable people that
    share the same interest. If you have any suggestions, please let me know.
    Cheers!

  12. Herbert says:

    It’s been confirmed – Nikkole’s been lying about having a dead son.
    Thanks to awesome work from *The Real Teen Mom Speak,* commenters on TM blogs,
    and Samantha Diggs making the choice to talk out towards her
    friend’s lies, Nikkole Paulun has solely dug herself deeper into the pit
    of lies during which she has been squandering for 9 months.
    This Christmas journey is with pornactress Puma who is
    completely innocently on the lookout for a toy for her son.
    And it seems to be like a Christmas miracle nevertheless it is not, but one other porn actress Diana is
    holding the final instance of the toy they each need.

  13. They are the Community Financial Services Association of
    America, and for 14 years they have been helping consumers and making sure lenders follow the
    law. The companies that work in payday loans need certain numbers in order to receive their repayments.
    Most agencies will call to verify your employment but will not divulge
    that you are applying for a cash advance loan.

  14. I don’t even understand how I ended up right here, but I thought this
    put up used to be great. I do not recognize who you might be
    but definitely you’re going to a well-known blogger if you happen to
    aren’t already. Cheers!

  15. Woah! I’m really loving the template/theme of this site.
    It’s simple, yet effective. A lot of times it’s very hard to get
    that “perfect balance” between superb usability and visual
    appearance. I must say you have done a fantastic job with this.

    In addition, the blog loads very quick for me on Firefox.
    Exceptional Blog!

  16. Hi, Neat post. There’s an issue together with your web site in internet explorer, would test this?

    IE nonetheless is the market leader and a
    huge component of folks will leave out your wonderful writing because of this problem.

    my homepage: ร้านผ้าม่าน

Leave a Reply