In a SharePoint 2010 installation that I recently worked, got failures in the log when trying o perform User Profile Synchronization. While debugging, in the Event log, There was a clue:
The management agent “SharePoint-MyCompany” failed on run profile “DS_FULLIMPORT” because of connectivity issues.
I went through the checklists, guidelines, and what I’ve done, and everything looks perfect, But I had missed one step: Granting Replicate Directory Changes permission on the domain.
For the profile synchronization to work, our service account which is being used by UPS should have the “Replicate Directory Changes” permission on a domain. These rights for query change in the directory. This permission does not allow an account to make any changes in the directory. Refer: http://technet.microsoft.com/en-us/library/hh296982.aspx#RDCdomain
Steps to Fix:
- Open the Active Directory Users and Computers snap-in
- On the View menu, click Advanced Features.
- Right-click the domain object, such as “company.com”, and then click Properties.
- On the Security tab, if the desired user account is not listed, click Add; if the desired user account is listed, proceed to step 7.
- In the Select Users, Computers, or Groups dialog box, select the desired user account, and then click Add.
- Click OK to return to the Properties dialog box.
- Click the desired user account.
- Click to select the “Replicating Directory Changes” check box from the list.
- Click Apply, and then click OK.