.NET Tutorials, Forums, Interview Questions And Answers
Welcome :Guest
Sign In
Win Surprise Gifts!!!

Top 5 Contributors of the Month
david stephan
Gaurav Pal
Post New Web Links

FIM -- User Profile Synchronization -- Please Settle This Once and for All

Posted By:      Posted Date: December 04, 2010    Points: 0   Category :SharePoint

I know this has been discussed in MANY other threads.  But, I need some definitive YES/NO answers on the following questions.  Some additional detail would be helpful too:

1. Should the Forefront Identity Manager Service (on the server [Administrative Tools > Services]) be running under the farm account?

2. Should the Forefront Identity Manager Synchronization Service (on the server [Administrative Tools > Services]) be running under the farm account?

3. Does the farm account need to be in the local Administrators group in order to START the services on the server?

4. If the farm account is used for these services, what is the need for the AD import account?

5. How come when I view the import/export process, using the Synchronization Service Manager (FIM), it shows that each process was executed using the farm account?  Shouldn't it be using the AD import account?

6. Why did M$FT make this so hard?  Do they hate me?

View Complete Post

More Related Resource Links

Unable to start user profile synchronization service

Hello, I have the following problem. user profile synchronization service doesn't start up, with the following error in log: The service encryption keys could not be found. User Action Verify that the service account has permissions to the following registry key: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Forefront Identity Manager\2010\Synchronization Service If the problem persists, run setup and restore the encryption keys from backup. Permissions for registry are availabele. Thank you.    

Critical Error with User Profile synchronization timer job

Hello! We are currently running SharePoint 2010 on Windows 2008 R2 servers. Our User Profile Service and User Profile Sync Service are currently running, and profile imports work fine when kicked off from Central Admin. However, the profile sync timer job always fails with the following Application Event error: Event 6398, SharePoint Foundation The Execute method of job definition Microsoft.Office.Server.UserProfiles.UserProfileImportJob (ID 340e8ca2-6f3b-4bd8-80f2-0fe011709805) threw an exception. More information is included below. Generic failure Looking at the ManageUserProfileServiceApplication.aspx log, indeed the only imports visible are ones which have been kicked off manually in Central Admin. The failed scheduled imports are not even recorded to this log. The ULS entry associated with this error is as follows: 08/31/2010 17:11:17.32  OWSTIMER.EXE (0x0CD0)                    0x0C04 SharePoint Foundation          Timer                          6398 Critical The Execute method of job definition Microsoft.Office.Server.UserProfiles.UserProfileImportJob (ID 340e8ca2-6f3b-4bd8-80f2-0fe

User Profile Synchronization Connection disappeared

So I had finally got User Profile Synchronization working by going down the path of using the Domain Admin Active Directory account for everything (SQL service account, SharePoint Farm account, Setup account) and the User Profiles worked based on the walk through I created on SharePointAdminWiki.com.  But now, the User Profile Synchronization Connection has disappeared from the list...and if I click Create to try and recreate it I get this error: "Cannot navigate to the requested page while User Profile Synchronization is running. Please wait for the current Synchronization run to finish." There are no jobs running, and I've left it for a while and still no joy. I even tried restarting the server and still nothing! I've tried this with a Windows Server 2008 SP1 build server AND a Windows Server 2008 R2 server. I have read @jiel's and David Pae's advice on this. Are User Profiles just well and truly broken in the Public Beta? SharePoint Solution Architect, Perth Australia - MCTS WSS Dev, WSS Adm, MOSS Dev, MOSS Adm - Readify - http://wss.made4the.net/- http://www.sharepointdevwiki.com/

Configure Synchronization connections with PowerShell (User Profile)

Hi, I was checking the Pshell cmdlets for SPS2010 and wasn't able to configure the sync connection after creating the User Profile SA. Do you know if it's possible to configure this part (AD, filters, etc) in PShell ? Is it done using the "SetupSynchronizationService" method of the User Profile Service Application object ? Thanks ! Wes  

User Profile Synchronization problems suddenly

I installed User Profle Sync and it was working for a few weeks just fine.  No issues with "starting".  I was able to syn the AD users to SharePoint. Now - for some reason, it has decided to stop working and my event viewer is filled with Event ID 5555 errors over and over again.  I have no clue why it decided to stop working or if I changed something that caused it (or what I changed) and I've tried to restart the service several times, but always end up in "Starting" mode now and the errors persist. I'm a beginner and would love some help here.  I followed this page http://www.harbar.net/articles/sp2010ups.aspx when setting it up the first time and it worked perfectly. So now what?  Do I have to do it all again?

User Profile Synchronization: Name of user account / id uses wrong Netbios domain name?!

I've got an interesting situation: I've got a domain e.g. FOOBAR.FI. The Netbios domain is due to historical reasons BARFOO. When I use UPS to import accounts from the FOOBAR.FI domain, the user account names in SharePoint are given the id of FOOBAR\<useraccount>. This works so and so. Users are identified and My Sites is fine. However the organizational chart and other fields where you can specify another user don't work as they should. If the manager is specified from AD, the organizational chart works. However, if I edit a profile and check the manager, it's in the form of FOOBAR\<useraccount>. SharePoint highlights this and a tooltip says that the account cannot be found. As a suggestion, it gives BARFOO\<useraccount>, which is found from the AD. All fine and dandy, until you check the organizational chart, which turns out to be empty at this point. This is because in SharePoint there's no user with the name BARFOO\<useraccount>, but only those FOOBAR\<useraccount> users who've been imported from the AD. So bottom line question is: How does UPS select and set the user account name?

User Profile Service Synchronization Connection: Client Timout

Hi, I have scenario on configuring User Profile Synchronization service on customer site as below. Window AD Server 2003 Domain NetBIOS: foo FDQN: foo.bar.com  User Account to connect: foo\ad-connect This account already set permission as describe in http://technet.microsoft.com/en-us/library/ee721049.aspx  when I try to create connection, system took long time to process then return error as "Client Timeout". I try to check FIM and it's seems to work fine (no error return and can get users data). So could anyone told me what's wrong? Since I've didn't have much knowledge on Network and AD, please advice.Theeraphat.P SharePoint Information Worker

User Profile Synchronization Problem


  Here I am, another person with the User Profile problem.  Of course mine is not failing like everyone elses.  Ok here goes.  I followed the following:

So I have installed the WCF from here: http://connect.microsoft.com/VisualStudio/Downloads/DownloadDetails.aspx?DownloadID=23806 as I am running Windows 2008 R2.

I set Replicating Directory Changes to SharePointDBA (Farm Account) and SharePointCAA (Administration Account)

From there I noticed that User Profile Service was started and User Profile Syncronization Service wasn't.  Stopped the User Profile Service and started it again.  Then started the User Profile Sysncronization Service.  Selected User Profile Service Application.  I then waited about 15 minutes.  Checked the services.mmc and noticed that Forefront Identity M

User Profile Synchronization service seems to stop on its own accord. What's usually the cause?


I've noticed in several environments that the UPS service stops every now and then. All I can do is go an restart it in Central Administration, and it usually retains all synchronization connection settings and works fine again. I've been too busy to examine the cause though.

Does this happen for others as well? What is the usual cause for it to stop?

User Profile Synchronization error MOSS MA not found


Configuration User Profile Synchronization  step by step Configure profile synchronization (SharePoint Server 2010) http://technet.microsoft.com/en-us/library/ee721049%28office.14%29.aspx#section0 but get error "MOSS MA not found"

User profile synchronization issue in SharePoint 2010 Enterprise


User profile is not getting sync.

We see warning events with following details each day before the schedule task starts.

"The credentials used for the account DC\soft.ac expired on 3/15/2008 1:20:42 AM, and need to be updated. If they are not updated, the system may stop working. The account is used by the following:

Farm Account

Microsoft SharePoint Foundation Sandboxed Code Service User Profile Synchronization Service etc..."

But the account is not expired.

Can anyone help?

User Profile Synchronization service is not designed to work on a stand-alone installation


There were tons of discussions and blog posts about User Profile Synch service never starting. And now it appears that this is not even supposed to work....



Problem with User profile synchronization using BCS connection.


I am facing a problem while updating user profile properties through BCS.

I couldnt perform a AD synchronization because the account did not have replication rights.So, i manually added a few user profiles and thought of updating few of their properties using BCS connection to SQL server.

I created a bcs connection and tested it by creating external lists and bcs profile page.It is working fine.

The problem is when i create a  user profile connection with using this bcs connection and do a full synch, the user properties are not updated.

Forefront identity manager shows values of the database being imported. however the mapped propertes are not updated.

Please help.

Thanks in advance.


How do we create new User Profile Synchronization connection so that we can import profiles from AD

We have a requirement to authenticate users against Active Directory LDS in our SP 2010 farm and also import their profiles in user profile store. We are able to setup FBA using AD membership provider to authenticate against AD LDS.

I am interested in importing the users in AD LDS to SharePoint user profile store. 

When I try to create a new connection the options that I am provided are 
1. Active Directory
2. Active Directory Logon Data
3. Active Directory Resource.
4.SunOne (LDAP) 5.2
5.Novell eDirectory (LDAP) 8.7.3
6.IBM Tivoli (LDAP) 6.2

If I select any of the options 1/2/3 I am asked to provide Forest Name and Domain Controller name. Since this is AD LDS there is no Forest or Domain Controller. It’s just a generic LDAP server.  

So the question I am struggling with  is: what are the steps required to create a User Profile Synchronization connection to import users from AD LDS and not from AD DS? 

We are not able to find any information how to do that in SP2010… From other blog entries I am assuming it was supported and documented for MOSS2007.

There is NO “LDAP Directory” connection type in SP2010.

I am wondering if this is supported in SP2010.


Sharepoint 2010 User Profile Synchronization Stuck On "Synchronizing"

I have configured my User Profile Synchronization. I have configured the synchronization connections, and started the synchronization service. My issue is when I "Start Profile Synchronization", the Profile Synchronization Status is stuck on "Synchronizing". There is no job listed in running jobs, and the job keeps running (I let it run for a daya and a half before I killed it). Nothing in logs or Event Viewer (That I could find). Any suggestions as to why this job never succeds or fails?

User Profile Synchronization, checking if NetBIOS Domain Names was enabled.


After multiple tries I finally got User Profile Synchronization setup... or so I thought.  I was down to the very last step of starting the sync...when I start the synchronization it never starts and the status remains "Idle".  The timer job is not giving me very helpful information and is reporting "Generic Error". 

I had fallowed two separate articles.  I did the Enable NetBIOS domain names but I am unsure which example I did it from or if it took.  Is there a way to check this?  Is there any harm in running it again?  Do I have to restart anything to pick up the changes?

Thank you very much for any information.

Starting User Profile Synchronization Service Fails


Hi All,

While performing a database attach upgrade from SharePoint Server 2007 to 2010 with this article http://technet.microsoft.com/nl-nl/library/cc263299(en-us).aspx as my guide, I'm stuck at the 'Start the User Profile Synchronisation Service' section. When I use Central Administration to start the service, after a few minutes being on the status 'Starting' it reverts back to 'Stopped'.

When reviewing the logs I find the following error message:

UserProfileApplication.SynchronizeMIIS: Failed to configure ILM, will attempt during next rerun. Exception: System.Data.SqlClient.SqlException: Specified collection 'StringSchemaCollection' cannot be dropped because it is used by object '<DOMAIN>\<FARM ACCOUNT>.GetObjectCurrent'. 

The account used is already added to the local administrators group.

One solution I did find is in the following thread: http://social.technet.microsoft.com/Forums/en-US/sharepoint2010setup/thread/58a404c0-af55-476c-84ad-8720de0a3292. The problem I have with this solution is that I should manually modify the user profile database, setting the correct default schem

ASP.NetWindows Application  .NET Framework  C#  VB.Net  ADO.Net  
Sql Server  SharePoint  Silverlight  Others  All   

Hall of Fame    Twitter   Terms of Service    Privacy Policy    Contact Us    Archives   Tell A Friend