A hotfix rollup package (build 5.3.1003.0) is available for Microsoft Forefront Identity Manager 2010 and Microsoft Forefront Identity Manager 2010 R2. This hotfix rollup package resolves some Lotus Domino connector issues and adds some features and functionality. These are described in the "More Information" section.

Update information

A supported update is available from Microsoft. We recommend that all customers apply this update to their production systems.

This update is available on the following Microsoft websites.

Microsoft Download Center

Forefront Identity Manager Connector for Lotus Domino 8.x

Microsoft Support

If this update is available for download from Microsoft Support, there is a "Hotfix download available" section at the top of this Knowledge Base article. If this section does not appear, contact Microsoft Customer Service and Support to obtain the hotfix. Additionally, you can obtain the update from Microsoft Update or from Microsoft Update Catalog.

Note If additional issues occur or if any troubleshooting is required, you might have to create a separate service request. The usual support costs will apply to additional support questions and issues that do not qualify for this specific hotfix. For a complete list of Microsoft Customer Service and Support telephone numbers or to create a separate service request, go to the following Microsoft website: The "Hotfix download available" form displays the languages for which the hotfix is available. If you do not see your language, it is because a hotfix is not available for that language.


To apply this update, you must have the following components installed:

  • The Lotus Notes client

  • The Microsoft .NET Framework 4.0

  • The Forefront Identity Manager Synchronization Service in one of the following:

    • Microsoft Forefront Identity Manager 2010 R2

    • Microsoft Forefront Identity Manager 2010 Update 2 (build 4.0.3606.2 or a later build)

Additionally, a user account on the same server as the Lotus Domino connector service account must start Lotus Notes one time. And the default Lotus Domino Lightweight Directory Access Protocol (LDAP) schema database (Schema.nsf) must reside on the Domino Directory server.

Note You can install the default Lotus Domino LDAP schema database by running or restarting the LDAP service on the Domino server.

File information

The global version of this update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

File name

File size







lotusconnector\synchronization service\extensions





lotusconnector\synchronization service\extensions





lotusconnector\synchronization service\uishell\xmls\packagedmas

More Information

Important With the introduction of hotfix 2899874 (build 5.3.721.0), the Domino Connector is now a 64-bit Connector. If you did not apply hotfix 2899874, please refer to the steps in that hotfix article for how to convert an already installed Connector to be a 64-bit Connector.

Issues fixed

This hotfix rollup fixes the following issues that were not previously documented in the Microsoft Knowledge Base.

Issue 1

You export group members that are other groups (also known as nested groups) to Domino. If the groups are located in the root of the directory, the membership will be incorrect. To correctly export group members in this scenario, set the Enable Creation of _Contacts object option on the global page to None.

Issue 2

In a Domino system where records are updated by a back-end process, some records might not appear in a full import. This behavior occurs if search indexes are out-of-date in Domino. This causes some of the records in the FIM Synchronization Service to be deleted. If you experience this problem, change the new Perform Full Import By option from the default setting of Search to Views.

Issue 3

Password synchronization operations are always reported as successful even if the user is not present in Domino. An operation that fails because of a deleted user is now reported as Failed in the event log.


Learn about the terminology that Microsoft uses to describe software updates.

Need more help?

Expand your skills
Explore Training
Get new features first
Join Microsoft Insiders

Was this information helpful?

What affected your experience?

Thank you for your feedback!