Avec un peu de retard, le SP1 est disponible pour Microsoft Identity Manager 2016 (en_microsoft_identity_manager_2016_with_service_pack_1_x64_dvd_9656597.iso).
Téléchargement : https://msdn.microsoft.com/fr-fr/subscriptions
Le SP1 en détails :
MIM
-
MIM Portal cross-browser compatibility for end-user self-service: In this Service Pack we are introducing support for most major browsers. Users may now access and interact with the MIM Portal for self-service group and profile management from Edge, Chrome, and Safari.
-
MIM Service support for Exchange Online: The MIM Service has long supported sending and receiving emails for approvals and notifications. Prior to SP1 MIM only supported Exchange Server or SMTP. With service pack 1, the MIM Service can send and receive requests as well as email notifications using an Office365 Exchange online account.
-
Image file format validation on upload: MIM is now able to validate the file format of images when they are uploaded to the portal.
Privileged Access Management(PAM)
-
PAM "PRIV" (bastion) forest support for Windows Server 2016 functional level: The MIM PAM Service may be configured in an environment with domain controllers running at the Active Directory Domain Services forest functional level of Windows Server 2016. When configured, a user’s Kerberos ticket will be time-limited to the remaining time of their role activation.
Note
If you choose to maintain the forest functional level of Windows Server 2012 R2 in your CORP domain, it is recommended to install KB 2919442 and KB 2919355 on the CORP domain controller.
-
Privileged account elevation into groups exclusive to the “PRIV” (bastion) forest: Now, administrators can inform the MIM Service of groups and users exclusive to the “PRIV” forest. Doing this allows these groups and users to be included in PAM roles. They can then be activated for a role and assigned membership to groups in the “PRIV” forest.
-
PAM Deployment Scripts: PAM Deployment Scripts allow administrators to streamline the installation of the PAM environment.
-
PAM Cmdlets for Authentication Policy Silo configuration: Service pack 1 introduces new Cmdlets to harden the security of your bastion forest. These Cmdlets automatically create an Authentication Policy Silo, bound to an Authentication Policy Template.
Note
These Cmdlets run automatically as part of the deployments scripts.
Platform Support
Updated platform support information may be found in the document called Supported platforms for MIM 2016. New platforms supported in this service pack include SQL Server 2016, SharePoint 2016
Issues fixed in this release from MIM 2016 General Availability
PAM
- New-PAMGroup did not create MIM objects for domain local groups in the PRIV forest
- New-PAMDomainConfiguration would fail with a “netdom” error message
- PAM Monitoring Service logged warnings for groups in the PRIV forest
Joris