Okta Active Directory Import Error Occurs When Using the DirSync Feature
Last Updated:
Overview
An Active Directory (AD) import error occurs when using the DirSync feature because one or more AD agents run an unsupported version. Updating all AD agents to version 3.20.0 or later and configuring the DirSync feature resolves the issue. The following error occurs during AD import operations:
An error occurred during import
Agent version does not support imports with DirSync. Upgrade to the minimum supported version to run imports.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Active Directory (AD)
- Active Directory DirSync Feature
Cause
This error occurs when one or more AD agents for the integration run a version earlier than 3.20.0, which does not support imports with DirSync.
Solution
How is the AD DirSync error resolved?
Update the AD agents to a supported version, enable the DirSync feature in the Okta Admin Console, and perform a full import to generate the required tracking cookie.
- Grant the additional required permission to every service account running an AD agent, as detailed in the Okta service account permissions documentation.
- Deactivate or update all AD agents for the integration to version 3.20.0 or later.
- Choose Settings > Features in the Okta Admin Console, and enable the Active Directory DirSync feature.
- Choose Provisioning > To Okta > General in the AD integration settings, and select Imports with DirSync.
- Perform a full import to generate the required DirSync cookie for tracking changes in AD. Subsequent incremental imports automatically utilize the DirSync cookie for enhanced performance.
NOTE: All AD agents for the integration must run the same version to prevent the error from persisting.
