Supported recovery after LoadUserProfile owner exits without UnloadUserProfile
Draft only — NOT SUBMITTED
Subject: Supported recovery after LoadUserProfile owner exits without UnloadUserProfile
On Windows, an application successfully called LoadUserProfile for a local non-administrator account. The application process terminated before calling UnloadUserProfile. The returned PROFILEINFO.hProfile and the application's retained user-token handle are no longer available. A later read-only check reports Win32_UserProfile.Loaded=true and the user's HKU and HKU_Classes hives present.
Does Microsoft provide a supported, non-destructive recovery procedure for this case?
Specifically:
- Can an appropriate profile ownership/reference be reacquired through a documented API without a new logon/profile load? If so, which API, provenance checks, handles and access rights are required?
- Does any documented lifecycle mechanism release an outstanding profile load after its owning process has exited? How should completion be verified?
- If no such route exists, please identify the supported recovery options and their prerequisites explicitly.
We need to preserve the profile files/settings and existing evidence. We are not authorized to substitute a newly opened registry handle, directly unload registry hives, alter privileges/security policy, restart/log off, or perform a new logon/profile load as an experiment. Please distinguish a documented supported procedure from an undocumented workaround.
OS edition/build and relevant sanitized event records can be provided after separately approved collection. No live machine state is being changed while awaiting clarification.