Provisioning The User Profile Service Application

July 9 2010 109 comments

As I wrote earlier, SharePoint 2010 ships with a profile synchronization engine from ForeFront Identity Manager. After performing several SharePoint 2010 environment installations, this seems also to be the most fragile part of the SharePoint 2010 architecture especially when using a least privileged accounts install model.

There are lots of content in the blogs and TechNet related to configuring user profile synchronization. In my experience, launching the services has to be done in the order described below. In most of the environments this is enough, but in some places I am still struggling to get this to work. The step 5 seems to be the most critical, as the FIM services create certificates and establish database connections, and there are several error-prone phases in that process.

1. Add the farm account into the local administrators group. This is stated in the TechNet article:

The Server Farm account, which is created during the SharePoint farm setup, must also be a member of the Administrators group on the server where the User Profile Synchronization service is deployed.

There seems to be some conflicting opinions about the correct permissions, as this will cause the SharePoint Health Analyzer to create a warning:

Accounts used by application pools or service identities are in the local machine Administrators group. Using highly-privileged accounts as application pool or as service identities poses a security risk to the farm, and could allow malicious code to execute.

Also grant the Replicate Directory Changes permission for the farm account account used in the synchronization connection. Reboot the server to make sure that all the services using the farm account run with the new privileges.

2. Start the User Profile System Service.

3.  Create User Profile Service Application by using the wizard or PowerShell. Remember that you need to have a site collection for the My Site Host even when you do not plan to use my sites yet.

4. Set the farm account to have full control of the Service Application: select SA from the SA list and use Administrators and Permissions actions in the ribbon.

5. Launch User Profile Synchronization system service. It make take several minutes for the service to move from the starting stated to started state. The system service starts two Windows services with the farm account: first the ForeFront Identity Manager Synchronization Service and then the ForeFront Identity Manager service. While these are launched, monitor the event log to see any errors related to these two services and use the Internet resources to find the answers.

For example if you get a warning event 1004:

Detection of product ‘{90140000-104C-0000-1000-0000000FF1CE}’, feature ‘PeopleILM’, component ‘{1C12B6E6-898C-4D58-9774-AAAFBDFE273C}’ failed. The resource ‘C:\Program Files\Microsoft Office Servers\14.0\Service\Microsoft.ResourceManagement.Service.exe’ does not exist.

grant the Network Service account access to the folder C:\Program Files\Microsoft Office Servers\14.0 as described here.

6. After the system service is in the started state, you should be able to access the SA administration page and configure the profile synchronization according to TechNet. As described in my earlier post, the SharePoint will not update anything in the Active Directory by default even though the synchronization has the export stages as well. Also note that the profile synchronization in SharePoint 2010 takes several minutes compared to 2007 where it was usually a matter of seconds.

As the RTM celebrations are over and Microsoft starts to patch the brand new 2010, I expect the user profile -related binaries to be among the top priority components where the stability and quality should be improved. The first step should be to make the error messages more verbose.

Popularity: 16% [?]

109 comments to “Provisioning The User Profile Service Application”

  1. 医薬部外品の化粧品で、フェイス部分のほうれい線の問題を解消することができます。ホワイトニングリフトケアジェルは、多くの商品の中でもクチコミ評価が高いクリームです。アンチエイジングには定番のアイテムです。

  2. Pretty section of content. I just stumbled upon your website and in accession capital to assert
    that I acquire actually enjoyed account your blog posts. Any way I’ll be subscribing to your augment
    and even I achievement you access consistently quickly.
    Lắp đặt camera quan sát tại

  3. mposport says:

    Terus berkarya ya, tulisannya enak di baca.

  4. Cassandra D. Everhart says:

    Well, this post is quite good! tree trimming

  5. Я сейчас же кину в закладки ваш rss, поскольку я бессилен найти ваш e-mail hyperlink или newsletter.
    Можно ли попросить ваши контакты?
    Пожалуйста, разрешите мне общаться с вами для того, чтобы я
    мог бы подписаться. Благодарю.

  6. Лично я немедленно запишу ваш rss
    адрес, поскольку я бессилен отыскать ваш
    e-mail link или e-newsletter. Можно ли попросить ваши контакты?
    Будьте добры, разрешите мне переговорить с вами для того, чтобы я мог
    бы подписаться. Благодарю.

  7. Esmeralda says:

    6. В интернет-казино большое разнообразие

    Here is my web page Esmeralda

  8. Visit ao hure frankfurt for your own free sexy chat pleasure with hot young local ladies!

  9. Technicoo says:

    Thanks for sharing your info. I truly appreciate your efforts and I
    am waiting for your further post thanks once again.

Leave a Reply