<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Active Directory Incremental Imports Fail to Capture Updated Profile Data When Custom LDAP Filters and DirSync Are Enabled

Okta Classic Engine
Okta Identity Engine
Directories

Overview

Certain incremental imports may fail to accurately capture updated profile data when both DirSync Incremental Imports and a custom Active Directory LDAP filter are configured together.

 

Resolve this issue by executing a full import, reviewing the import results, and adjusting settings on the Import and Provisioning tabs. Before concluding that the environment is affected, confirm that users are not awaiting confirmation in the import queue and allow one import cycle to complete after any recent AD change.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Active Directory (AD)
  • DirSync Incremental Imports
  • Custom AD Lightweight Directory Access Protocol (LDAP) filter

Cause

This potentially impacts customers who enabled both DirSync Incremental Imports and a custom Active Directory LDAP filter during EA self-serve. 

 

Starting in June 2026, Dirsync and Active Directory LDAP filters are now prevented from being enabled together for new orgs.

 

How is an affected configuration identified?

 

An affected configuration has DirSync incremental imports enabled alongside a custom Active Directory LDAP filter that is not the default Active Directory LDAP filter.

Standard Directory LDAP filters and default Active Directory LDAP filters are not impacted

Standard Directory LDAP filters and default Active Directory LDAP filters are not impacted 

Before concluding that the environment is affected, confirm that users are not awaiting confirmation in the import queue and allow one import cycle to complete after any recent Active Directory change.

 

Solution

How is the import corrected?

 

Correct the import by running a full import from the application, confirm the import results, and then disable DirSync Incremental Imports on the Provisioning tab or revert the custom Active Directory LDAP filter to the default Active Directory LDAP filter if discrepancies persist

  1. Run a full import from the Import tab.
  2. Confirm the import results.
  3. If discrepancies persist, disable DirSync Incremental Imports on the Provisioning tab.
  4. Consider reverting the custom Active Directory LDAP filter to the default Active Directory LDAP filter.

Imports with DirSync

 

 

How do imports function without DirSync Incremental Imports?

 

Imports revert to full scans after disabling DirSync Incremental Imports. Okta is addressing this issue as a priority to ensure AD imports capture changed profile data correctly when both DirSync Incremental Imports and a custom AD LDAP filter operate together.

 

 

Loading
Okta Active Directory Incremental Imports Fail to Capture Updated Profile Data When Custom LDAP Filters and DirSync Are Enabled | Okta Support