<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00005wCNk0SAGOkta Classic EngineAdministrationAnswered2019-02-05T14:43:32.000Z2019-02-04T13:54:13.000Z2019-02-05T14:43:32.000Z
bjgjo likes this.
  • GabrielL.85945 (Customer)

    Yes, it's supported. Is it recommend? Kinda.

     

    It's always good to have redundancy and eliminate single points of failures. That's the value of running multiple AD Agents. While I may assume there would be fewer single points of failure when having multiple AD sites, that's not always inherently true. So regardless of whether you have multiple AD sites, you want to make sure you have separate physical servers, separate power, separate internet connections, separate location, etc.

    Expand Post
  • Haven't done it yet, but I expect problems related to replication, depending how you use AD with Okta. When Okta provisions to AD, user creation could happen through Agent1 in Site1, then a profile update could happen through Agent2 in Site2, but the created object hasn't replicated there yet. Again, I haven't put AD Agents in multiple sites yet, but since you can't control which AD Agent handles requests this seems problematic.

     

    Of course, if you only use AD for delegated auth or situations where you read from AD rather than writing to it, might be fine.

    Expand Post
  • Thank you both for your answers. I'm also concerned with potential issues coming from replication.

    I will stick to the same AD site for now with two AD agents in a distinct datacenter rooms.

This question is closed.
Loading
Okta Active Directory agents in distinct AD sites