
2a4bz (2a4bz) asked a question.
When you first integrate AD to Okta, and you activate the Agent..what happens? Since it is a preview environment I don't want to load 70,000 AD users and activate them. How do I just add one at a time at this point in the installation? What is a AD scan versus an AD load?

Thanks for reaching out to the Support Community today!
When integrating AD with Okta which requires installing the AD Agent and configuring the Active Directory settings in your Okta Admin tenant, an AD Import is required to be trigged in order to bring user and group objects into Okta. What happens upon import is all dependent on the settings that are configured under Directory >> Directory Integrations >> Active Directory >> Settings tab. Okta will only pull in User and Group objects based on the OUs that you have selected under the User and Group OUs Connected to Okta section
If you'd only like to Import users one at a time you have two options:
When an Import is triggered in Okta for the first time, all Users and Groups into Okta based on the OUs you have selected to sync will be loaded in Okta. For all subsequent Imports, if there are no changes detected from the previous import, 0 users and groups will be scanned. Otherwise, if any user or group objects have changed from the previous import, only those objects will be scanned by the AD Agent and updated accordingly in Okta.
The following articles provide a detailed description of each of the configurable Active Directory settings:
https://help.okta.com/en/prod/Content/Topics/Directory/okta-active-directory-agent.htm?Highlight=attribute%20level%20mastering
https://support.okta.com/help/s/article/Okta-AD-Agent
Thank you,
Aleks Bulajic
Technical Support Engineer
Okta Global Customer Care