Account unknown in user profiles

On all our domain controllers (server 2003 R2 and 2008) we have found an "account unknown" listed under My computer-properties advance-user profiles-settings. My
concern is that the Account Unknown profiles shows under all our Domain Controllers in the aforementioned place and it shows that that particular profiles is still being access. By being access I mean that the “Modified” date shows that it was
modified just a few days ago, and it changes a couple of days. Also, the option to delete the account is grayed out and I can not find any orphaned profiles under documents and Settings.
What I need to know is if that profile is being use by some system account, or have the servers been compromised.
Any assistance or clarification of this issue will be greatly appreciated. Thank you.

Hi,
A possible cause of the “Account Unknown” profile is that the domain account that the profile is mapped to was deleted but the profile was
not able to be deleted because some applications or services have open handle on the file. That’s also one of the reasons that the option to delete the account is grayed out.
I suggest that you have a look at the subkeys under HKEY_USERS key and check if there is any user has been deleted. The HKEY_USERS key lists all profiles
that are currently loaded on the computer. The PsGetSid utility (http://technet.microsoft.com/en-us/sysinternals/bb897417.aspx) can help you translate SIDs to their display name.
Meanwhile, you’d better perform a full virus scan to ensure that the computer is not infected by virus.
This posting is provided "AS IS" with no warranties, and confers no rights. Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can
be beneficial to other community members reading the thread.

Similar Messages

  • How to add Hotmail account to ProfileManager User Profile?

    Hi everyone!
    I was wondering how I can add a Hotmail account to a user profile in Profile Manager? I only see POP/IMAP settings, but haven't been able to find those settings for Hotmail by googling.
    Thanks!
    ~Mike

    You can configure Hotmail to work on the iPhone. It works very well, I have had no problems with it. After upgrading to a Hotmail plus account, follow the instructions-
    http://mailcall.spaces.live.com/Blog/cns!CC9301187A51FE33!44348.entry
    Account: On
    Account Information:
    Name: John Smith (note: enter your own name)
    Address: [email protected] (note: enter your full Hotmail email address)
    Description: Hotmail
    Incoming Mail Server:
    Host Name: pop3.live.com
    User Name: [email protected] (note: enter your full Hotmail email address)
    Password: password (note: enter your Hotmail password)
    Outgoing Mail Server (SMTP):
    Host Name: smtp.live.com
    User Name: [email protected] (note: enter your full Hotmail email address)
    Password: password (note: enter your Hotmail password)
    Advanced Settings:
    Incoming Uses SSL: On
    Outgoing Uses SSL: On
    Authentication: Password
    Delete from Server: When removed from Inbox (or your preferred option)
    I paid the $20 for the Hotmail plus account and was receiving mail on my Iphone within a half hour. It Rocks.

  • The CSCup62113 bug also removes Personal Conferencing accounts from disabled users' profiles

    It has been confirmed that the CSCup62113 bug that has been confirmed in MR4 (CWMS version 2.0.1.407B) also removes Personal Conferencing accounts from disabled users' profiles, if CWMS has been configured for synchronization with CUCM/LDAP. There is no way to restore the Personal Conferencing accounts; all affected end users need to be notified that their Personal Conferencing accounts and PINs need to be manually re-created (with host/participant codes being re-generated).

    It has been confirmed that the CSCup62113 bug that has been confirmed in MR4 (CWMS version 2.0.1.407B) also removes Personal Conferencing accounts from disabled users' profiles, if CWMS has been configured for synchronization with CUCM/LDAP. There is no way to restore the Personal Conferencing accounts; all affected end users need to be notified that their Personal Conferencing accounts and PINs need to be manually re-created (with host/participant codes being re-generated).

  • AD mobile account stores Mac user profile in Windows home directory

    My Windows Server 2003 AD accounts have roaming profiles and user home directories stored in different locations on Windows Server 2003 servers. How do I prevent my MacOS tiger clients from copying the local user profiles for AD mobile accounts to the respective remote home directories?
    This unwanted behavior is quite similar to using Windows 9x clients in similar AD environment.

    I do need to automount the network home directory but do not desire to have it sync with the local home directoy. I disabled the "create mobile account at login" option and enabled "force local home directory on startup disk" and "use unc path from active directory ..." and these appear to have resolved the problem. Unfortunately the network home directory no longer automounts, nor do network accounts show up at the logon prompt (strangely enough, they can be configured to autologin.)

  • User Profile Service failed the logon. User profile cannot be loaded

    Hey
    when I try to log on to the computer using a domain account, I get "User Profile Service failed the logon. User profile cannot be loaded" it allows me to login using the local account. I have restored the computer as far
    back as it can go, I have taken it off the domain and re-joined it, I installed a program called 'Glary utilities 5' and ran a registry repair and that did not work either. I am now out of ideas :(
    Was hoping someone has any more ideas I could try before doing a fresh install.
    Thanks in advance

    Hi,
    Have you checked the solutions mentioned in the the followng link?
    You receive a "The User Profile Service failed the logon” error message
    http://support.microsoft.com/kb/947215/en-us
    Check your event viewer for detailed information, the following link can also be helpful
    http://blogs.technet.com/b/asiasupp/archive/2010/11/24/user-profile-cannot-be-loaded-with-event-id-1509-detail-the-filename-or-extension-is-too-long.aspx
    Yolanda Zhu
    TechNet Community Support

  • User Profile Service Not Syncing Membership Groups

    We have noticed that since moving to SharePoint 2013 user memberships and followed sites on users mysites are not updating to remove sites that no longer exist or add new sites into the list.  I tried the steps that used to fix this under 2010 outlined
    here: https://support.microsoft.com/kb/2703630 but they do not seem to resolve the issue anymore.  Has anyone had this happen to them in 2013 and figured out the steps to resolve it?  To me it looks like the UserProfileService is not able to find
    or refresh memberships into the user profile databases.  Normally this is a permissions issue but the farm account and the account running the user profile service both have full control to the content databases.
    If this post was helpful please mark it as helpful, if it solved your problem please mark it as
    answered.
    Visit my Blog: http://matthewchurilla.blogspot.com/

    Hi Matthew,
    Per my knowledge, the Memberships web part is not fully supported in SharePoint 2013, and the memberships in SharePoint sites cannot be updated.
    The links below is for Office 365, however it’s true for SharePoint 2013:
    http://support.microsoft.com/kb/2858263
    https://social.msdn.microsoft.com/Forums/office/en-US/76778087-60e3-4720-ae50-5d2d359f1be9/my-membership-web-part-cannot-be-use-for-my-site?forum=sharepointdevelopment
    As a workaround, you can use the new feature Following to follow the sites in SharePoint 2013:
    http://blogs.office.com/2013/02/21/following-in-sharepoint-2013/
    Thanks,
    Victoria
    Forum Support
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Victoria Xia
    TechNet Community Support

  • Temp-Contract Worker User Profile Synchronization in SharePoint 2013

    Hi All,
    I was wondering if anyone could provide some feedback on what is the best practice for configuring Temp or Contract worker user profile services in SharePoint 2013. We have had lot of issues within MySites when we make these types of workers AD account inactive
    and then active again when they come back on projects. The user profile synchronization does not work correctly and MySites has issues loading the profile etc. Also in the same context are there best practices for Name/Title/Department changes as well. 
    thank you for your feedback!
    AJ
    Ajay Mandal

    Given what you describe I assume you've created a user profile Sync connection filter to remove disabled AD accounts from the user profile sync.  That's why you are running into problems.  When a user is missing from the import their profile is
    deleted within an hour or so, but their MySite isn't deleted for 14 days (to allow time for a manager to clean it off).  If the user is reactivated within the 14 day period their old mySite is still there, but is no longer referenced by the new profile
    that is created.  So When the user goes to their profile it tries to create a new mySite where one already exists.  It can't do that.
    The same thing will happen if you delete the contractor's user account, but then recreate them in AD when they return.  The only way to fix it is to make sure both the profile and mySite site collection in /Personal/ have been deleted before re-adding
    an old contractor.
    Paul Stork SharePoint Server MVP
    Principal Architect: Blue Chip Consulting Group
    Blog: http://dontpapanic.com/blog
    Twitter: Follow @pstork
    Please remember to mark your question as "answered" if this solves your problem.

  • Restore "account unknown" user profile Windows7

    After accidentally remove user and  computer from domain controller (Windows Server 2003), i was create new user with same old name on DC and rejoin my client PC (Windows7) to domain.
    As result i have brand new profile, my old profile i see as: "account unknown"
    How can i restore my old user profile ?

    On Tue, 18 Feb 2014 18:58:11 +0000, SaeedShweiki wrote:
    Inadvertently i have been deleted an "unknown user" in Windows XP
    This forum is for Windows Server security related issues and not for
    Windows XP issues.
    Please repost to one of the forums here:
    http://answers.microsoft.com
    Paul Adare - FIM CM MVP
    "Bother," said Pooh, "Eeyore, ready two photon torpedoes and lock
    phasers on the Heffalump, Piglet, meet me in transporter room three."
    -- Robert Billing

  • Domain User Profiles Unknown??

    I have 6 Panasonic Toughpads and when plugged directly into the network they work fine. However, when disconnected from the network, they will only log into the last user account signed in. when I go to user profiles when connected to the network it shows
    all the user accounts. When I check user profiles while disconnected from the network it shows all profiles as unknown except for the one account I am logged into and the local account on the computer. if I log off after disconnecting the network and try to
    login as someone different it works but if i restart and try to login as someone else it says there are currently no logon servers available, I have to plug into the network sync the profiles and login then again. if i break from the network i cant login as
    any other profile until back on the network. Why aren't the profiles saving?

    Hi TOLITdept,
    We wonder if you are the administrator of your domain.
    "Account Unknown" means that the SID the profile has no longer in Active Directory and some applications or services have open handle on the file; or more simply, the user has been deleted from AD. It is by design. In your case obviously the first
    reason. After restart these account would need be re-verified by domain controller.
    And if you are damain administrator, you also could check if any related group policy has been applied.
    Regards
    D. Wu

  • 3 user profiles on mac book pro.  cant see one account in time machine - has it backed up? and for other users ''no permission'' to open folders - i just want to know that stuff IS backed up (before attempting upgrade to lion)

    We have 3 user profiles on mac book pro.  want to upgrade to lion but want to be sure that all users are backed up to ext hard drive via Time Machine.  When I go into Time Machine - I cant find anywhere my user account (1 of the 3) - loads of photos and documents. For other user accounts - if i go to open a folder i cant ''no permission'' is the message.  All I want to be sure of is that there is a back up and for these 2 reasons I am far from sure.

    famfran wrote:
    When I go into Time Machine - I cant find anywhere my user account (1 of the 3) - loads of photos and documents.
    Be sure they're not excluded in Time Machine Preferences > Options.
    Also, if iPhoto is open while a backup is running, Time Machine may not be able to back up the changes in the iPhoto Library. It will "catch up" the next time, if it can.
    For other user accounts - if i go to open a folder i cant ''no permission'' is the message.  All I want to be sure of is that there is a back up and for these 2 reasons I am far from sure.
    That's correct; one user, even an Admin user, doesn't normally have access to another user's files.  You should see the same behavior if you try to look at their data on your Mac.
    Log on as the other users (or have them do it) to see their backups.

  • How do I move all my files from one User Profile (account) into another? I needed to create a new account and want all of my files accessible in the new one.

    How do I move all my files from one User Profile (account) into another?
    I needed to create a new account and want all of my files accessible in the new one.

    ok, what you're learning right now is 101 unix, which is good. Unix is a good thing
    now: the way unix works, and macos (which uses unix underneath) the files and folders work like a hierarchy.
    the start of that tree is /
    so, if you were to do:
    cd /
    (cd means change directory)
    it will bring you at the highest branch of the file system.
    cd /Users
    will bring you to where all the users are.
    to see whats in /Users you can use your friend ls command
    ls means list files/directories
    so:
    cd /Users
    ls -la
    (the -la here means show all (even hidden) and long format (very verbose))  this flag is very optional.
    you will see
    fred
    user2
    for example.
    if you want to see the desktop of user2 you would change directory to it then list the files.
    for example:
    cd /Users/user2/Desktop
    Note that the files and directory are case sensitive, so, desktop is NOT the same as Desktop, or DESKTOP
    ls -la
    you should then be able to see everything in users2 desktop
    you could have done as well the same thing in smaller steps, for example:
    cd /
    cd Users
    cd user2
    cd Desktop
    this is the equivalent of cd /Users/user2/Desktop
    So, for your file, i don't know where it was, but know that if you log in as user2, it will directly put you in
    /Users/user2
    which most likely the file you had created from the other user was in /Users/user1
    if you copied all the files from /Users/original_user to /Users/secondUser
    most likely yes, all your mail, bookmarks etc would be copied over.
    so in your case.
    sudo chown -R seconduser:staff /Users/secondUser
    should work
    Remember that if you start a path with the character /  it means start from the root of the file system, at the highest top you can ever get.
    so
    cd /Users/fred
    is not the same as
    cd Users/fred
    unless you were in / already
    i know it may be confusing at first but it's actually very logical if you play with it.
    to simplify, think of it that / means C:\  on windows
    you can't go any higher than C:\  (in a way)
    if you're unsure which directory you're currently in, you can always type:
    pwd
    it will tell you where you are.
    for example:
    cd /
    pwd
    this shows  /
    cd Users
    pwd
    this now shows /Users
    cd /System/Library
    pwd will show /System/Library
    cd /
    cd /Users
    cd fred
    cd Library
    pwd will show /Users/fred/Library
    unix can look very scary but it's actually vital and very necessary to do tasks sometimes that would take for ever to do via the windows. This is good learning.
    so for the myfile you had created, i can't tell you where it is, at the time you created, if you can do a pwd command you'll know the path,
    ls -la  (this shows all the files where you are)
    if you see myfile in the list
    do a pwd
    whatever is return, the real location of the file would be:
    whatever pwd returned / myfile
    I hope that makes sense.

  • User profiles with multiple login accounts in SharePoint 2010

    Hello,
    Consider the following scenario:
    We have Active Directory that is accessible inside our network. Except the sites, accessible from the corporate network, we are exposing SharePoint sites from the same farm on the internet, using claims based authentication with ADFS 2.0 using the same
    AD instance as in the intranet.
    The problems is that the claims based accounts are not linked to the profiles, that are created for the users by the User Profiles Synchronisation service.
    Is there a way to configure the user profiles so if our users are signing in from internet, to access the same profiles that they have, when accessing the SharePoint sites from intranet?
    (I've searched a lot, I didn't find excat solution. I've found something related to SPCLaims properties and had confugred them to sync with the AD using the "claims" trusted connection, but the problem remains.)
    This is simmilar to allow our users to login using their Facebook, Google, OpenID identity or the identity in our AD. How can this be done?

    SharePoint user profiles are not populated automatically when using claims-based authentication methods. You must create and populate these profiles yourself, typically in code. Users that map to existing accounts when you migrate to claims-based authentication
    will use any existing profile information, but other users and new users will not have profile information. For information about how you can populate user profiles when using claims-based authentication, see "Trusted Identity Providers & User Profile
    Synchronization" at
    http://blogs.msdn.com/b/brporter/archive/2010/07/19/trusted-identity-providers-amp-user-profile-synchronization.aspx.
    The same limitation occurs when using SharePoint Audiences. You cannot use user-based audiences directly unless you create custom code to support this, but you can use property-based audiences that make use of claims values. For information, see "Using Audiences
    with Claims Auth Sites in SharePoint 2010" at
    http://blogs.technet.com/b/speschka/archive/2010/06/12/using-audiences-with-claims-auth-sites-in-sharepoint-2010.aspx.
    From: http://msdn.microsoft.com/en-us/library/hh446523.aspx

  • How to provision multiple AD Accounts to a single User Profile in OIM

    Hi,
    We are using OIM 11g R2. We have implemented AD Provisioning/Reconciliation using Active Directory 11g Connector.
    The correlation rule for linking AD accounts with OIM during target recon is set as “Email ID”
    We have some business requirement where we want to provision multiple AD Accounts to a single User Profile in OIM.
    Issue we are facing:
    Suppose we have USERID1 in OIM which has email id as USERID1@ XYZ.COM .
    After that we have provisioned sAMAccountName=USERID1 (Email ID as USERID1@ XYZ.COM )& sAMAccountName=USERID2 (Email ID as [email protected]) to the user User Login = USERID1 in OIM.
    Both the AD User accounts can be seen as provisioned.
    After we run the AD Target Recon, the target recon is failing because of “Multiple Process Matches Found” issue.
    Question here is:
    Is it possible to maintain/manage multiple AD Accounts (Same AD is used for all the multiple AD Accounts) to a single OIM profile user ?
    Regards,
    J

    Hi,
    We have seen its working and linking multiple accounts when we have Key field as "User ID" in the Process Defn & RO and the recon matching rule has email ID as the matching rule.
    Please suggest, if we are having the above kind of rule/config...will it not cause any issue?
    Regards,
    J

  • Unknown user in user profile of ST03N

    Hi,
    We have observed that  there is an unknown user in user profile of ST03N.  This happens every day.
    Please let me know if anybody knows where this user comes from?
    Best Regards,
    Tushar

    Hi Markus,
    I  can see unknown user in below path :
    ST03N-->expert Mode ->workload>Total--->Day-->Select date
    below in Analysis View select User and Settlement Statistics -
    >user profile
    Here users will be listed with reponse time valuesetc. One of the user is unknown.
    I did not understand your previous answer.Can you please explain a bit.
    Best Regards,
    Tushar.

  • Exclude expired accounts in user profile synchronization

    Hi 
    I would like to exclude the expired accounts from the AD import in SharePoint 2013 user profile sync.
    I managed to exclude disabled accounts using userAccountControl bit equals on 2.
    Could you please suggest on how the exclusion filter can be used to exclude expired accounts.
    Thanks.

    Hi,
    When you say "expired accounts", do you mean the accounts with expired password? If that is the case, you could use
    userAccountControl Bit on equals 24 in exclusion filter.
    If not, let me know what do you mean by "expired accounts".
    Regards,
    Rebecca Tu
    TechNet Community Support
    Please remember to mark the replies as answers if they help, and unmark the answers if they provide no help. If you have feedback for TechNet Support, contact
    [email protected]

Maybe you are looking for

  • Can't sync PalmV with Imac

    I have been using a Palm V with my PC for several years without problems. I recently purchased a new Imac and would like to sync my handheld with it so that I don't have to totally recreate an address book with dozens of names, adddresses and phone n

  • BAPI/FM to confirm the Production Order

    Hi Friends, I have created the Production Order using the 'BAPI_PRODORD_CREATE'. I also have to confirm the production order. please provide if any BAPI/FM is available for confirming production order? Regards, xavier.P

  • R/3 Releases supported in a  VMWare REDHAT Linux virtualization environment

    Hi, I hope I have chosen the right Forum here? I am trying to find out information on whether 4.6B & 4.6C R/3 SAP Releases running the 4.6D Extended kernel with MaxDB is supported on virtualized REDHAT Linux environments using VMWARE. I have found a

  • How to setup a timed Task in 10.1

    Is there any way to setup a task with a date & time reminder in OS 10.1? Since Outlook does sync tasks or reminders with Blackberry link, what other app can do this?

  • Can't open mail in my MAC

    I can't open my mail on mac, support to my