The purpose of this wiki is for the purposes of sharing knowledge on a Forefront Identity Manager 2010 R2 upgrade, and/or new installation issue that we ran into in support. We will be covering what we found in our troubleshooting, and how we went about resolving the issue. *DISCLAIMER: Please note. This is one possible solution for this issue. It may or may not resolve the issue that you are encountering.
During an upgrade and/or new installation of the Microsoft Forefront Identity Manager 2010 R2 product it is noticed that the FIM Services may not start. In review of the System Event Log, we discovered information pertaining to a registry key that the FIM Service was attempting to work with, but was still in use by other applications. (Review the below System Event Log Entry) SYSTEM EVENT LOG Event ID: 1530 Task Category: None Level: Warning Keywords: User: SYSTEM Computer: Description: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-4092936690-862222819-3731999215-1108: Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\TrustedPeople Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Control Panel\International Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\Root Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\SmartCardRoot Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\Windows\CurrentVersion\Explorer Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\My Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\trust Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\CA Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\Disallowed Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Policies\Microsoft\SystemCertificates
During an upgrade and/or new installation of the Microsoft Forefront Identity Manager 2010 R2 product it is noticed that the FIM Services may not start. In review of the System Event Log, we discovered information pertaining to a registry key that the FIM Service was attempting to work with, but was still in use by other applications. (Review the below System Event Log Entry)
Event ID: 1530 Task Category: None Level: Warning Keywords: User: SYSTEM Computer: Description: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL - 15 user registry handles leaked from \Registry\User\S-1-5-21-4092936690-862222819-3731999215-1108: Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108 Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\TrustedPeople Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Control Panel\International Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\Root Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\SmartCardRoot Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\Windows\CurrentVersion\Explorer Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\My Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\trust Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\CA Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Microsoft\SystemCertificates\Disallowed Process 4728 (\Device\HarddiskVolume2\Program Files\Microsoft Forefront Identity Manager\2010\Service\Microsoft.ResourceManagement.Service.exe) has opened key \REGISTRY\USER\S-1-5-21-4092936690-862222819-3731999215-1108\Software\Policies\Microsoft\SystemCertificates
To resolve the issue, add the FIM Service Account to the Local Administrators Group. Once the FIM Service Account was added to the Local Administrators Group, we noticed that two keys were added to the Windows Registry HKEY_USERS.