{"id":39,"date":"2007-07-06T09:16:03","date_gmt":"2007-07-06T09:16:03","guid":{"rendered":"https:\/\/www.wapshere.com\/missmiis\/?p=39"},"modified":"2023-01-16T08:59:53","modified_gmt":"2023-01-16T08:59:53","slug":"a-dr-plan-for-password-sync","status":"publish","type":"post","link":"https:\/\/www.wapshere.com\/missmiis\/a-dr-plan-for-password-sync","title":{"rendered":"A DR Plan For Password Sync"},"content":{"rendered":"<p>The most time critical aspect of an MIIS installation is likely to be the Password Sync. There are always going to be delays in syncs through the MAs, and people should be used to that &#8211; but when a user changes their password they are going to expect it to go straight through.<\/p>\n<p>If you are regularly <a href=\"https:\/\/www.wapshere.com\/missmiis\/?p=37\">replicating MIIS to a failover server<\/a> then you can have password sync up and running within a matter of minutes after a failure of your primary server.<\/p>\n<p>I take the precaution of pre-registering my failover server with PCNS. When you installed Password Sync you would have run the SETSPN and PCNSCFG ADDTARGET commands to enable your MIIS server as a password sync target for PCNS. You should now also execute these commands for your failover server, adding an extra one to disable it until needed.<\/p>\n<p>This post is not intended to be an instruction on installing PCNS &#8211; for that you should refer to <a href=\"http:\/\/technet2.microsoft.com\/ILM\/en\/library\/e27c0bc6-c808-4fdb-9e59-58feeb4193081033.mspx?mfr=true\" target=\"_blank\" rel=\"noopener noreferrer\">this Technet document<\/a>. So, on the assumption that you&#8217;ve already got PCNS working for you primary MIIS server, you just need to run these extra commands to register your failover server.<\/p>\n<blockquote>\n<p>setspn.exe\u00a0 -A\u00a0 PCNSCLNT\/<em>failoverserverDN\u00a0 domain<\/em><em>svcaccount<\/em><\/p>\n<p>pcnscfg.exe addtarget\u00a0 \/n:miispw_<em>failoverserver<\/em>\u00a0 \/a:<em>failoverserverDN<\/em><br \/>\u00a0 \/s:PCNSCLNT\/<em>failoverserverDN<\/em>\u00a0 \/fi:&#8221;Domain Users&#8221; \/f:3<\/p>\n<p>pcnscfg disabletarget\u00a0 <em>failoverserverDN<\/em><\/p>\n<\/blockquote>\n<p>You now have the failover server registered, but disabled. To confirm this use the command<\/p>\n<blockquote>\n<p>pcnscfg list<\/p>\n<\/blockquote>\n<p>When you&#8217;re ready to switch from your primary to failover server all you need to do is execute these commands:<\/p>\n<blockquote>\n<p>pcnscfg disabletarget\u00a0 <em>primaryserverDN<\/em><\/p>\n<p>pcnscfg enabletarget\u00a0 <em>failoverserverDN<\/em><\/p>\n<\/blockquote>\n<p>The failover MIIS server should now be able to sync the passwords of <em>all the users it knows about.<\/em><\/p>\n<p>Of course, if new users have been created since the last time you replicated the MicrosoftIdentityIntegrationServer database then the failover server can&#8217;t be expected to know about them until you&#8217;ve done your re-sync&#8217;ing work. But at least, in the meantime, Password Sync will be working for the majority of your users. And that&#8217;s what I&#8217;d call a very successful DR plan!<\/p>\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The most time critical aspect of an MIIS installation is likely to be the Password Sync. There are always going to be delays in syncs through the MAs, and people should be used to that &#8211; but when a user changes their password they are going to expect it to go straight through. If you&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"footnotes":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":[]},"categories":[34,28,11],"tags":[],"class_list":["post-39","post","type-post","status-publish","format-standard","hentry","category-ilm2007","category-miis2003","category-password-sync"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pkp1o-D","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/39","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/comments?post=39"}],"version-history":[{"count":3,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/39\/revisions"}],"predecessor-version":[{"id":3374,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/posts\/39\/revisions\/3374"}],"wp:attachment":[{"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/media?parent=39"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/categories?post=39"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.wapshere.com\/missmiis\/wp-json\/wp\/v2\/tags?post=39"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}