http://technet.microsoft.com/en-us/library/ee721049.aspx
To grant the farm account the Remote Enable permission to Microsoft FIM 2010
- On the server that is running the synchronization service, click Start.
- Click Run, type wmimgmt.msc, and then click OK.
- Right click WMI Control, and then click Properties.
- In the WMI Control Properties dialog box, click the Security tab.
- Expand the Root list, and then select the Microsoft FIM 2010 namespace MicrosoftIdentityIntegrationServer.
- Click the Security button.
- Add the farm account to the list of groups and users, and then in the Permissions for Authenticated Users box, select Allow for the Remote Enable permission.
- Click OK to dismiss the Security for ROOT\MicrosoftIdentityIntegrationServer dialog box, and then click OK to dismiss the WMI Control Properties dialog box.









