UPA Synchronization permission issue
Problem:
In SharePoint 2010, I started the User Profile Synchronization, but can't import users.
Check:
I created the Synchronization Connections using the system Account, check the process in miisclient.exe (C:\Program Files\Microsoft Office Servers\14.0\Synchronization Service\UIShell), you'll find the error message - Replication access denied.
If I use the account: administrator, the process works fine.
You should give "Replication" permission to the account you used in the Synchronization Connection.
How to add the Replication permission:
1. Open the DC server.
2. Run adsiedit.msc
3. Connect to the domain.
4. click the Properties of the DC
5. Add user and allow the "Replication " permission.
Conclusion:
1. Some problems about UPA, Check the miisclient and ULSLog.
2. Don't forget give the permission of replication.