Actions Processed by a Single Okta LDAP agent
Last Updated:
Overview
When multiple Okta LDAP agents are configured, actions will be processed by only a single agent in the environment. The Okta LDAP agents will not replicate or synchronize data between different LDAP servers. To ensure proper operation, the LDAP environment requires replication configuration directly between multiple LDAP servers within a single domain before Okta LDAP agent deployment. Despite the presence of multiple configured agents, Okta routes each specific action through only one agent to its connected directory server.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Directories
- Lightweight Directory Access Protocol (LDAP)
- Okta LDAP Agent
Cause
The Okta LDAP Agent does not perform any type of replication or synchronization between different LDAP servers within the same LDAP domain.
Solution
How does Okta process actions with multiple LDAP agents?
By design, a single agent processes each action from Okta and forwards it to the specific directory server associated with that agent. Okta does not support configuring the agent to perform replication in an environment with multiple directory servers.
Any available Okta LDAP agent processes authentication requests and connects to any LDAP server within the environment. Therefore, all directory server instances must contain replicated directory data to ensure proper operation.
Replication between multiple LDAP servers within a single domain must be configured in LDAP before deploying the Okta LDAP Agent.
