> For the complete documentation index, see [llms.txt](https://docs.lithnet.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.lithnet.io/resource-management-powershell/installation/connecting-to-the-service.md).

# Connecting to the MIM service

Use [Set-ResourceManagementClient](/resource-management-powershell/usage/cmdlet-reference/set-resourcemanagementclient.md) to configure the connection before calling other cmdlets. If you do not call it, the client connects to the MIM service on the local computer using default settings.

```powershell
# Windows PowerShell 5.1, connecting directly to the MIM service
Set-ResourceManagementClient -BaseAddress http://mim-service:5725

# PowerShell 7 on Windows, using the built-in local proxy
Set-ResourceManagementClient -BaseAddress pipe://mim-service

# PowerShell 7 on any platform, using the remote proxy service installed on the MIM server
Set-ResourceManagementClient -BaseAddress rmc://mim-service
```

## Connection modes

The client library supports several connection modes. The mode is selected automatically from the scheme of the address, or you can force one with the `-ConnectionMode` parameter.

| Mode           | URI scheme               | Works in                     | Approval operations |
| -------------- | ------------------------ | ---------------------------- | ------------------- |
| `DirectWsHttp` | `http://` (port 5725)    | Windows PowerShell 5.1       | Supported           |
| `DirectNetTcp` | `net.tcp://` (port 5736) | Both editions, all platforms | Not supported       |
| `LocalProxy`   | `pipe://`                | PowerShell 7 on Windows      | Supported           |
| `RemoteProxy`  | `rmc://` (port 5735)     | Both editions, all platforms | Supported           |

## Windows

On Windows, no setup is needed. Windows PowerShell connects directly to the service, and PowerShell 7 launches a built-in local proxy when given a `pipe://` address or a plain hostname.

## Linux and macOS

PowerShell 7 on Linux and macOS cannot use the MIM service's default WS-Http endpoint, which relies on components that exist only on .NET Framework. Two connection modes work on these platforms. Choose based on whether you need to run approvals:

* **Remote proxy** (`rmc://`) supports every operation, including approvals, but requires a service to be installed on the MIM server. Use this in most cases.
* **Direct net.tcp** (`net.tcp://`) needs nothing installed on the client and connects straight to the MIM service, but it cannot run approvals. Use this when you cannot install the proxy service and do not need approvals.

Each option has a one-time server-side setup, described below.

## Setting up the remote proxy

The remote proxy is a Windows service that runs on the MIM server. The client connects to it over TCP using Negotiate (Kerberos) authentication, and the proxy makes the WS-Http calls to the local MIM service for you. It works from Windows, Linux, and macOS, and supports all operations. On Linux and macOS the client requires .NET 8 or later.

1. Download the Lithnet Resource Management Client Proxy installer from the [releases page](https://github.com/lithnet/resourcemanagement-client/releases).
2. Run the installer on the MIM server. It registers a Windows service named `LithnetRMCProxy` running as `NT AUTHORITY\NetworkService`, and starts it. The service listens on TCP port 5735. See the [proxy installation guide](https://github.com/lithnet/resourcemanagement-client/wiki/Proxy-installation-guide) for full details, including silent installation.
3. Allow inbound TCP 5735 through the server firewall.
4. Authorize the accounts that will connect by adding them to the **Lithnet RMC Proxy Users** local group on the server. The installer creates this group and seeds it with the local Administrators group. To authorize a different group instead, set the `AuthorizedUsers` value to that group's SID under `HKLM\SYSTEM\CurrentControlSet\Services\LithnetRMCProxy`, then restart the service.

Then connect:

```powershell
Set-ResourceManagementClient -BaseAddress rmc://mim-service
```

The listening port and the local MIM service port can be changed with the `ProxyPort` and `ResourceManagementServicePort` registry values under the same key (defaults 5735 and 5725).

The client authenticates to the proxy with the SPN `host/hostname`, which matches the service's default account. This only needs attention if you change the service to run under a custom account: in that case, pass an SPN held by that account using the `-ServicePrincipalName` parameter of `Set-ResourceManagementClient`.

## Setting up net.tcp endpoints

The MIM service does not expose net.tcp endpoints by default. Add them to the service configuration on the MIM server. This mode connects directly to the MIM service and needs nothing on the client, but it does not support approvals.

Edit `Microsoft.ResourceManagement.Service.exe.config` in the MIM Service installation folder on the server. Add these bindings inside `<system.serviceModel>`:

```xml
<bindings>
  <netTcpContextBinding>
    <binding name="NetTcpContextBinding5736">
      <security mode="Transport">
        <transport clientCredentialType="Windows"/>
      </security>
    </binding>
  </netTcpContextBinding>
  <netTcpBinding>
    <binding name="NetTcpBinding5736" transferMode="Streamed">
      <security mode="Transport">
        <transport clientCredentialType="Windows"/>
      </security>
    </binding>
  </netTcpBinding>
</bindings>
```

Add these endpoints to the `Microsoft.ResourceManagement.WebServices.ResourceManagementService` service:

```xml
<endpoint address="net.tcp://localhost:5736/ResourceManagementService/Enumeration" binding="netTcpBinding" bindingConfiguration="NetTcpBinding5736" contract="Microsoft.ResourceManagement.WebServices.WSEnumeration.IEnumeration"/>
<endpoint address="net.tcp://localhost:5736/ResourceManagementService/Resource" binding="netTcpContextBinding" bindingConfiguration="NetTcpContextBinding5736" contract="Microsoft.ResourceManagement.WebServices.WSTransfer.IResource"/>
<endpoint address="net.tcp://localhost:5736/ResourceManagementService/ResourceFactory" binding="netTcpContextBinding" bindingConfiguration="NetTcpContextBinding5736" contract="Microsoft.ResourceManagement.WebServices.WSTransfer.IResourceFactory"/>
```

Then make sure the `Net.Tcp Port Sharing Service` is running on the MIM server, allow inbound TCP 5736 through the server firewall, and restart the Forefront Identity Manager Service. A complete example is provided with the client as `sample.nettcp.config`.

Then connect:

```powershell
Set-ResourceManagementClient -BaseAddress net.tcp://mim-service
```

## More detail

The [connection guide](https://github.com/lithnet/resourcemanagement-client/wiki/Connection-guide) covers the automatic mode selection rules, authentication and credential options, timeouts, and the full configuration reference.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.lithnet.io/resource-management-powershell/installation/connecting-to-the-service.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
