To Create SharePoint 2013 User Profile Service, you need to have below prerequisites
- Configure Manage Meta Data Service
- Configure Search Service
- Business Data Connectivity Service (Optional)
- Farm account should be member of Local Administrators Group when Synchronization is start for first time.
- Service Account Should have Permission “Replicating Directory Changes” in Active Directory
Navigate to Active Directory Users and Computers
data:image/s3,"s3://crabby-images/ad32d/ad32d6a722ed5bbdeeedc7fb5040c12c6c0948b5" alt=""
Add Service User Account
data:image/s3,"s3://crabby-images/b7f05/b7f05d6401183598dddb97bc70f989e833a2f62e" alt=""
Click next and Select “Custom Task to Delegate” Option button
data:image/s3,"s3://crabby-images/90521/9052154f26466a5b419dc940c9f98281a970198e" alt=""
Click Next and again next.
In Permissions Page, Select “Replicating Directory Changes” Option in the list
data:image/s3,"s3://crabby-images/a42b0/a42b0b7e898e4d3ad85d16e6092db04d239f54c1" alt=""
Finish the wizard.
1. Replicating permission in AD. For this follow the below steps.
- Log on to AD Server as the domain administrator.
- Start Active Directory Users And Computers and enable Advance Features.
- Open the Properties for the domain and click the Security tab.
- Add the upc/upc.spuserprofilesyncacc to the list.
- Assign the following permissions to the upc/upc.spuserprofilesyncacc account:
- Replicating Directory Changes
- Replicating Directory Changes All
- Replicating Directory Changes In Filtered Set
Replication synchronization.
Configure User Profile Service
- Manage Service Applications within Application Management.
- In the Create group on the ribbon, from the new menu, select User Profile Service Application.
- Assign a name to the new UPA.
- In the Application Pool section, either select an existing application pool (one already created for services) or build a new application pool. Specify a managed account that should run this application pool (most often, this account runs all the service applications unless your security policy forbids it).
data:image/s3,"s3://crabby-images/3d212/3d21202f68abba108a9e73188908f40fa56b093a" alt=""
- Type the configuration values for the Profile, Synchronization, and Social Tagging databases, using the following choices: A. Select an appropriate database name, following the conventions of your environment.
- For the authentication section, select Windows Authentication (recommended).
- If you are using mirroring, specify the name of your failover server
data:image/s3,"s3://crabby-images/30edb/30edb932a1e6615c4718c0267c548db412565637" alt=""
- Type the My Site host address and My Site Manage Path information.
- You may not have this information yet. It’s covered shortly and can be added in to the configuration after the UPA is created.
- In the site naming section, choose a naming format that is best suited to your environment
- Specify whether you want to associate the UPA with the default proxy group.
Start Service
- Enable Fim Services ( by default they are disabled)
data:image/s3,"s3://crabby-images/0a5b8/0a5b80e176425a25b0fad0335ea4ba220820cd70" alt=""
- Navigate to Services on the Farm Server
- System Settings -> Services on the Server -> Start following Services
data:image/s3,"s3://crabby-images/fdd28/fdd287cea6187837973193e30d70bab31b06d000" alt=""
- For the first time when you start the Synchronization service, make sure Farm administrator is a member of Local Administrators group
- Better if u can restart the server once you start the User Profile Synchronization Service
Create Active Directory Connection
data:image/s3,"s3://crabby-images/7ec42/7ec42090d7c3fd455d8336e00f7749af3ec80e1a" alt=""
You need to use same account which you gave “Replicating Directory Changes” in previous step