<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D50Z00008G7VQhSANOkta Classic EngineAdministrationAnswered2021-09-01T01:07:33.000Z2016-06-20T18:24:24.000Z2018-08-12T04:16:52.000Z
How does Okta Active Directory sync work?
Greetings All,

 

When I make a change in Active Directory on my local domain controller and the perform an Active Directory sync in Okta, the changes are not instantly reflected.

 

During a sync, where is Okta looking for AD information? And how long should a sync take?

 

I have an AD sync agent servers at each office location that contains a DC, if that helps any.

 

Thanks!

  • SSOS.08384 (Citrix)

    How many DC do you have and where are your AD Agents installed?

     

    We were seeing what we beleived was delayed synching, but after some investigation we realized all the changes were being made on AD Servers in EMEA, while all of our agents were in the US and usig US DCs. Synching between DCs can take up to 15 minutes in our environment, so that had to be accounted for.

    Expand Post
    Selected as Best
  • SSOS.08384 (Citrix)

    How many DC do you have and where are your AD Agents installed?

     

    We were seeing what we beleived was delayed synching, but after some investigation we realized all the changes were being made on AD Servers in EMEA, while all of our agents were in the US and usig US DCs. Synching between DCs can take up to 15 minutes in our environment, so that had to be accounted for.

    Expand Post
    Selected as Best
  • Rocky (Customer)

    We have 5 sites. 3 are in the US and 2 are in Europe. Each site has a DC and and Okta AD agent server.

     

    I thought that if I make my modifications on the local DC, updates would be handled by the local Okta AD agent server and the content would be reflected in Okta almost instantly. But this is not the case as it could take up to 15 minutes.

     

    Could this be a result of having too many Okta AD Agent servers? It almost seems like all the DCs and Agent servers must replicate before information is sent to Okta. Is this the case?

     

    Expand Post
This question is closed.
Loading
How does Okta Active Directory sync work?