<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Actions Processed by a Single Okta LDAP agent

Okta Classic Engine
Directories
Okta Identity Engine

Overview

When multiple Okta LDAP agents are configured, actions will be processed by only a single agent in the environment. The Okta LDAP agents will not replicate or synchronize data between different LDAP servers. To ensure proper operation, the LDAP environment requires replication configuration directly between multiple LDAP servers within a single domain before Okta LDAP agent deployment. Despite the presence of multiple configured agents, Okta routes each specific action through only one agent to its connected directory server.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Directories
  • Lightweight Directory Access Protocol (LDAP)
  • Okta LDAP Agent

Cause

The Okta LDAP Agent does not perform any type of replication or synchronization between different LDAP servers within the same LDAP domain.

Solution

How does Okta process actions with multiple LDAP agents?

By design, a single agent processes each action from Okta and forwards it to the specific directory server associated with that agent. Okta does not support configuring the agent to perform replication in an environment with multiple directory servers.

 

Any available Okta LDAP agent processes authentication requests and connects to any LDAP server within the environment. Therefore, all directory server instances must contain replicated directory data to ensure proper operation.

 

Replication between multiple LDAP servers within a single domain must be configured in LDAP before deploying the Okta LDAP Agent.

Loading
Okta Support - Actions Processed by a Single Okta LDAP agent