Overview
This update is applicable for an Identity Manager Driver for Office 365 and Azure Active Directory running Identity Manager 4.7.x and 4.8.x. The driver version will be changed to 5.1.3.0 after the patch is applied.
System Requirements
Identity Manager 4.7.x or later
Identity Manager 4.8.x or later
Prerequisites for Support of Modern Authentication
As Microsoft Office 365 is deprecating the Basic authentication, you must now configure the driver with modern authentication method.
Refer to the steps shown in
Prerequisites for Support of Modern Authentication for the detailed procedure to set up this mandatory prerequisite.
Upgrading the Driver
The driver upgrade process involves the following tasks:
- Updating the driver files
Updating the Driver Files
- Take a back-up of the current driver configuration.
- (Conditional) If the driver is running locally, stop the driver instance and the Identity Vault.
- (Conditional) If the driver is running with a Remote Loader instance, stop the driver and the Remote Loader instance.
- Download and unzip the contents of the IDM_AzureAD_5130.zip file to a temporary location on your computer.
- (Conditional) To update the driver files as a root user:
- On the server where you want apply the driver patch, log in as root.
- Navigate to the extracted <IDM_AzureAD_5130.zip> directory and perform one of the following actions for your platform:
- Windows:
- If the driver is installed locally:
- Navigate to the <extracted IDM_AzureAD_5130.zip>/Windows folder.
- Copy and replace the AZDriverShim.jar, RestLib.jar, and OData.jar files in the C:\NetIQ\IDM\NDS\lib folder.
- If the driver is installed with Remote Loader:
- Navigate to the <extracted IDM_AzureAD_5130.zip>/Windows folder.
- Copy and replace the AZDriverShim.jar, RestLib.jar, and OData.jar files in the C:\NetIQ\IDM\RemoteLoader\64bit\lib.
- Update the Windows Exchange Service:
- Stop the IDMExchangeOnline service from Windows services console (services.msc).
- Navigate to windows/ExchangeService in the extracted <IDM_AzureAD_5130.zip> folder and copy the Microsoft.Identity.Client.dll, ExchServerHost.exe and IDMExchServer.dll files to the Windows Exchange Service installation folder in your file system. For example, C:\NetIQ\ExchangeServerHost.
Important: To support new APIs, you must mandatorily install the Microsoft Exchange Online PowerShell V2 module (EXO V2). For the prerequisites and installation procedure, see
About the Exchange Online PowerShell V2 module.
- (Conditional) To update the driver files as a non-root user:
- Verify that /rpm directory exists and contains _db.* file.
The _db.* file is created during a non-root installation of the Identity Manager engine. Absence of this file might indicate that Identity Manager is not properly installed. Reinstall Identity Manager to correctly place the file in the directory.
- To set the root directory to the location of non-root Identity Vault, enter the following command in the command prompt:
ROOTDIR=<non-root eDirectory location>
This will set the environmental variables to the directory where Identity Vault is installed as a non-root user.
- To install the driver files, enter the following command:
For example, to install the REST driver RPM, use this command:
rpm --dbpath $ROOTDIR/rpm -Uvh --relocate=/usr=$ROOTDIR/opt/novell/eDirectory --relocate=/etc=$ROOTDIR/etc --relocate=/opt/novell/eDirectory=$ROOTDIR/opt/novell/eDirectory --relocate=/opt/novell/dirxml=$ROOTDIR/opt/novell/dirxml --relocate=/var=$ROOTDIR/var --badreloc --nodeps --replacefiles /home/user/netiq-DXMLRESTAzure.rpm
where /opt/novell/eDirectory is the location where non-root eDirectory is installed and /home/user/ is the home directory of the non-root user.
- (Conditional) If the driver is running locally, start the Identity Vault and the driver instance.
- (Conditional) If the driver is running with a Remote Loader instance, start the Remote Loader instance and the driver instance.
Technical Support Information
Issues Fixed in this release
- ALM 230992 - Enhancement to support modern authentication with Exchange Online APIs for Office 365.
- ALM 230811 - Implemented a fix to restrict multiple query calls for owners and members from the connected system.
Issues Fixed in Previous Release (5.1.2.0)
- Bug 1130845 - The driver has been enhanced to check the class name before performing a restore operation which is supportd only for Users class.
- Bug 1135890 - Ability to force the driver to use the US locale for printing system time to avoide the Exchange polling issues.
- Bug 1133522 - Exchange service has been enhanced to notify if the server certificates do not contain the private key.
- Bug 1145835 - The driver does not fail to start anymore when Exchange service is enabled and Exchange online is disabled.
- Bug 1126239 - Ability to synchronize the description of the mailbox groups has been added on the subscriber channel.
- Bug 1145812 - The driver now supports creation of MES groups.
Issues Fixed in Driver Version 5.1.2
- Bug 1125734 - Ability to escape HTML characters for passwords when Graph or Exchange APIs are called
- Bug 1114633 - Powershell psexecute commands work properly when the driver is in Hybrid mode
- Bug 1114631 - Licenses in a "PendingInput" status are no longer removed
- Bug 1115732 - Irrelevant trace messages will no longer display for successful user add and user restoration using exchange service events
- Bug 1114635 - Ability to rename Mail-Enabled security groups on the Subscriber channel
- Enhancement 1114628 - Extended support for synchronizing the usercertificate attribute from the Identity Vault to Azure AD
- Enhancement 1125877 - Extended support for supporting the unified groups